Engineering Papers⌕ Search

Engineering topics

Nemouchi, Yakoub

Publications and source records attributed to Nemouchi, Yakoub.

Formally Verified ZTA Requirements for OT/ICS Environments with Isabelle/HOL

The clean energy transformation includes the integration of distributed energy resources with the power grid, which has led to a substantial increase in the complexity of power grids infrastructure and the underlying operational technology environment. Power grids infrastructure represents an operational technology environment that has become a system of systems, integrating heterogeneous devices which are both software-and hardware-intensive; as a result, there are increasing demands to exploit advances in the commodity of software-hardware infrastructures to improve energy systems requirements such as cybersecurity and resilience. In such a setting, system requirements at different levels mix, which leads to vulnerabilities and undesirable outcomes. The use of formal methods to characterize and prove system requirements removes ambiguity, increases automation, and provides high levels of assurance and reliability. In this paper, we contribute a methodology and a framework for the system-level verification of zero trust architecture requirements in operational technology environments. We define a formal specification for the core functionalities of operational technology environments, the corresponding invariants, and security proofs. Of particular note is our modular approach for the formal verification of asynchronous interactions in operational technology environments. The formal specification and the proofs have been mechanized using the interactive theorem proving environment Isabelle/HOL.

formal methods↗

Cyber-Resilient Distributed Autonomous Energy Grid

The DARPA Assured Micropatching (AMP) program focuses on creating the capability for rapid patching of legacy binaries in mission critical systems leveraging the field of formal methods. NREL's Cyber Resilient TLDRD effort, focuses on leveraging the field of formal methods to develop tools and methods for formally verifiable implementations of security architectures such as Zero Trust Architecture. The presentation at the DARPA AMP PI meeting is primarily inspired by common interests and ongoing work on leveraging Formal Methods for OT cybersecurity.

cybersecurity↗