Project

# Title Team Members TA Documents Sponsor
4 Secure Chain-of-Custody Container
Alp Oguz
Selim Mamak
Sena Tiryaki
**Team Members:**

- Selim Mamak (smamak2)
- Serdar Alp Oguz (soguz2)
- Sena Bahar Tiryaki (stiry2)

## Problem

Confidential engineering prototypes may need to be transported between labs, offices, and authorized employees before they are publicly released. A standard locked case can restrict access, but it provides little information about who opened it, when it was opened, or whether someone attempted to bypass the lock or tamper with the enclosure.

Paper custody logs depend on users recording every interaction and can be modified after the fact. Shipping data loggers may record events such as impact or temperature but generally do not control access, while electronic lockboxes primarily focus on restricting entry rather than maintaining a detailed physical tamper and custody history. A reusable system that combines controlled access, tamper detection, and persistent event logging could provide a more complete electronic chain-of-custody record.

## Solution Overview

We will build a battery-powered secure container that opens only for authorized NFC credentials and records access and physical tamper events. An electronic latch will control access, while a lid sensor, conductive tamper loop, and accelerometer will monitor the enclosure for unauthorized opening, physical damage, and significant impact events.

Each event will be time stamped and stored in nonvolatile memory. Event records will be hash-linked so that modification of previously stored records can be detected when the log is exported and verified.

Low-power operation will be a major engineering focus of the project. Because the container may remain unused for long periods, the design will minimize standby consumption using low-power sensing components and power gating. Higher-power components such as the NFC reader and electronic latch circuit will normally remain disabled and will only be powered when needed.

The complete system will be implemented using a custom PCB containing the microcontroller, power-management circuitry, sensor interfaces, storage, NFC interface, and latch-control circuitry.

## Solution Components

### 1. Power Subsystem

The container will use a protected rechargeable Li-Po battery with USB-C charging. Low-quiescent-current regulation and power gating will be used to reduce standby power consumption.

The NFC reader and electronic latch circuit will normally remain powered off. A low-power wake mechanism, such as a Hall-effect sensor or pushbutton, will activate the main system when a user wants to authenticate without requiring the NFC reader to continuously scan.

Low-power sensors used for enclosure monitoring will remain active while the rest of the system is in standby. The firmware will control transitions between standby, wake, authentication, latch actuation, event logging, and return to standby.

Battery voltage and current consumption will be measured so that standby and active-state power consumption can be experimentally characterized.

### 2. Access Control and Tamper Sensing Subsystem

An NFC reader and enrolled credentials will identify authorized users. The exact NFC reader and credential pair will be selected through early compatibility testing. The design will use authenticated credentials rather than relying only on a card UID, which would provide weaker access control.

An electronically controlled latch will remain mechanically locked when unpowered and will only consume significant power during lock or unlock actuation.

A Hall-effect sensor will determine whether the container lid is open or closed. A conductive tamper loop routed through protected portions of the enclosure will detect interruption caused by cutting, drilling, or other physical penetration. A low-power accelerometer will detect significant impacts above a defined threshold.

Tamper and lid events will wake the control system so that suspicious activity can be time stamped and recorded even while the system is normally operating in its low-power state.

### 3. Control, Logging, and Readout Subsystem

A low-power microcontroller will coordinate access control, sensing, power management, latch control, and event logging.

A real-time clock with backup power will maintain accurate timestamps if the main battery is disconnected or replaced. Nonvolatile FRAM will store event records containing the event type, timestamp, and user identity when applicable.

The event records will be hash-linked so that altering a previously stored record can be detected when the history is verified.

A USB-C connection will allow the event history to be transferred to a computer. A simple desktop program will display the stored chain-of-custody record and indicate whether the log passes its integrity check.

## Criterion for Success

1. **Authorized Access:** The container remains locked until an enrolled NFC credential is successfully authenticated. An authorized access is recorded with the user identity and timestamp, while an unenrolled credential is denied access.

2. **Tamper Detection:** Opening the lid without authorization, breaking the conductive tamper loop, and producing a predefined significant-impact event are individually detected and recorded with timestamps.

3. **Low-Power Operation:** The completed system achieves a measured standby current below **100 µA** while the NFC reader and latch circuitry are inactive. Standby, authentication, and latch-actuation current will be measured and documented.

4. **Reliable Locking:** The electronic latch performs at least **20 consecutive authorized lock/unlock cycles** without resetting or disrupting the control electronics.

5. **Persistent Event Logging:** Stored event records remain available after complete loss of the main battery, and modifying an existing stored record causes the log-integrity verification software to report an error.

6. **Timestamp Preservation:** The real-time clock continues to maintain time during a main-battery removal and provides correct timestamps after the main system is powered again.

## Alternatives

A standard mechanical lockbox provides physical access restriction but does not automatically identify users or maintain an electronic record of access and tamper events.

Electronic lockboxes can provide credential-based access control, but their primary purpose is generally controlling entry rather than monitoring multiple forms of physical tampering and maintaining a persistent chain-of-custody history.

Shipping data loggers provide another alternative and can measure events such as shock or environmental conditions during transportation, but they generally do not physically control access to the protected contents.

Our project combines **identity-linked access control, physical tamper detection, persistent timestamped logging, and low-power battery operation** in a single reusable container intended for maintaining the custody history of confidential engineering prototypes.

ATTITUDE DETERMINATION AND CONTROL MODULE FOR UIUC NANOSATELLITES

Shamith Achanta, Rick Eason, Srikar Nalamalapu

Featured Project

Team Members:

- Rick Eason (reason2)

- Srikar Nalamalapu (svn3)

- Shamith Achanta (shamith2)

# Problem

The Aerospace Engineering department's Laboratory for Advanced Space Systems at Illinois (LASSI) develops nanosatellites for the University of Illinois. Their next-generation satellite architecture is currently in development, however the core bus does not contain an Attitude Determination and Control (ADCS) system.

In order for an ADCS system to be useful to LASSI, the system must be compliant with their modular spacecraft bus architecture.

# Solution

Design, build, and test an IlliniSat-0 spec compliant ADCS module. This requires being able to:

- Sense and process the Earth's weak magnetic field as it passes through the module.

- Sense and process the spacecraft body's <30 dps rotation rate.

- Execute control algorithms to command magnetorquer coil current drivers.

- Drive current through magnetorquer coils.

As well as being compliant to LASSI specification for:

- Mechanical design.

- Electrical power interfaces.

- Serial data interfaces.

- Material properties.

- Serial communications protocol.

# Solution Components

## Sensing

Using the Rohm BM1422AGMV 3-axis magnetometer we can accurately sense 0.042 microTesla per LSB, which gives very good overhead for sensing Earth's field. Furthermore, this sensor is designed for use in wearable electronics as a compass, so it also contains programable low-pass filters. This will reduce MCU processing load.

Using the Bosch BMI270 3-axis gyroscope we can accurately sense rotation rate at between ~16 and ~260 LSB per dps, which gives very good overhead to sense low-rate rotation of the spacecraft body. This sensor also contains a programable low-pass filter, which will help reduce MCU processing load.

Both sensors will communicate over I2C to the MCU.

## Serial Communications

The LASSI spec for this module requires the inclusion of the following serial communications processes:

- CAN-FD

- RS422

- Differential I2C

The CAN-FD interface is provided from the STM-32 MCU through a SN65HVD234-Q1 transceiver. It supports all CAN speeds and is used on all other devices on the CAN bus, providing increased reliability.

The RS422 interface is provided through GPIO from the STM-32 MCU and uses the TI THVD1451 transceiver. RS422 is a twisted-pair differential serial interface that provides high noise rejection and high data rates.

The Differential I2C is provided by a specialized transceiver from NXP, which allows I2C to be used reliably in high-noise and board-to-board situations. The device is the PCA9615.

I2C between the sensors and the MCU is provided by the GPIO on the MCU and does not require a transceiver.

## MCU

The MCU will be an STM32L552, exact variant and package is TBD due to parts availability. This MCU provides significant processing power, good GPIO, and excellent build and development tools. Firmware will be written in either C or Rust, depending on some initial testing.

We have access to debugging and flashing tools that are compatible with this MCU.

## Magnetics Coils and Constant Current Drivers

We are going to wind our own copper wire around coil mandrels to produce magnetorquers that are useful geometries for the device. A 3d printed mandrel will be designed and produced for each of the three coils. We do not believe this to be a significant risk of project failure because the geometries involved are extremely simple and the coil does not need to be extremely precise. Mounting of the coils to the board will be handled by 3d printed clips that we will design. The coils will be soldered into the board through plated through-holes.

Driving the inductors will be the MAX8560 500mA buck converter. This converter allows the MCU to toggle the activity of the individual coils separately through GPIO pins, as well as good soft-start characteristics for the large current draw of the coils.

## Board Design

This project requires significant work in the board layout phase. A 4-layer PCB is anticipated and due to LASSI compliance requirements the board outline, mounting hole placement, part keep-out zones, and a large stack-through connector (Samtec ERM/F-8) are already defined.

Unless constrained by part availability or required for other reasons, all parts will be SMD and will be selected for minimum footprint area.

# Criterion For Success

Success for our project will be broken into several parts:

- Electronics

- Firmware

- Compatibility

Compatibility success is the easiest to test. The device must be compatible with LASSI specifications for IlliniSat-0 modules. This is verifiable through mechanical measurement, board design review, and integration with other test articles.

Firmware success will be determined by meeting the following criteria:

- The capability to initialize, configure, and read accurate data from the IMU sensors. This is a test of I2C interfacing and will be tested using external test equipment in the LASSI lab. (We have approval to use and access to this equipment)

- The capability to control the output states of the magnetorquer coils. This is a test of GPIO interfacing in firmware.

- The capability to move through different control modes, including: IDLE, FAULT, DETUMBLE, SLEW, and TEST. This will be validated through debugger interfacing, as there is no visual indication system on this device to reduce power waste.

- The capability to self-test and to identify faults. This will be validated through debugger interfacing, as there is no visual indication system on this device to reduce power waste.

- The capability to communicate to other modules on the bus over CAN or RS422 using LASSI-compatible serial protocols. This will be validated through the use of external test equipment designed for IlliniSat-0 module testing.

**Note:** the development of the actual detumble and pointing algorithms that will be used in orbital flight fall outside the reasonable scope of electrical engineering as a field. We are explicitly designing this system such that an aerospace engineering team can develop control algorithms and drop them into our firmware stack for use.

Electronics success will be determined through the successful operation of the other criteria, if the board layout is faulty or a part was poorly selected, the system will not work as intended and will fail other tests. Electronics success will also be validated by measuring the current consumption of the device when operating. The device is required not to exceed 2 amps of total current draw from its dedicated power rail at 3.3 volts. This can be verified by observing the benchtop power supply used to run the device in the lab.