Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Secure by Design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 181 records · Page 10

Design of Defensive Cybersecurity Architectures for High Temperature, Gas-Cooled Reactors

This report presents the design of defensive cybersecurity architectures (DCSAs) for High Temperature, Gas-Cooled Reactors (HTGRs). A DCSA is a cybersecurity design feature that places systems into security zones in a graded approach according to the importance of the functions performed by the systems. DCSA design efforts for advanced reactors may commence as early as the system-level design phase. This design approach is consistent with the draft regulatory guide for advanced reactor cybersecurity programs (DG-5075) and enables advanced reactor designers to consider the effects of security-by-design (SeBD) features on their DCSAs. Integration of DCSA design and other cybersecurity activities with the traditional design process as part of a SeBD framework may enable advanced reactor designers to improve the security posture of their plants while reducing implementation and operating costs. This report provides a DCSA template for an exemplar HTGR and describes a DCSA design process using event tree analysis so that the template may be optimized for a given HTGR design.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Design of Defensive Cybersecurity Architectures for Sodium-Cooled Fast Reactors

This report presents the design of defensive cybersecurity architectures (DCSAs) for Sodium-Cooled Fast Reactors (SFRs). A DCSA is a cybersecurity design feature that places systems into security zones in a graded approach according to the importance of the functions performed by the systems. DCSA design efforts for advanced reactors may commence as early as the system-level design phase. This design approach is consistent with the draft regulatory guide for advanced reactor cybersecurity programs (DG-5075) and enables advanced reactor designers to consider the effects of security-by design (SeBD) features on their DCSAs. Integration of DCSA design and other cybersecurity activities with the traditional design process as part of a SeBD framework may enable advanced reactor designers to improve the security posture of their plants while reducing implementation and operating costs. This report provides a DCSA template for an exemplar SFR and how the template may be optimized for a given SFR design.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Hypothetical Nuclear Reactor Facility Modeling Simulation Data Scenario Comparison

This document evaluates a hypothetical nuclear powerplant and associated protective force personnel using modern modeling and simulation tools. The facility incorporates security early in the design to consider and integrate methods to resolve security issues and vulnerabilities via the facility’s inherent design characteristics before construction. The evaluation in this document is an example only. It is not intended to recommend or evaluate the effectiveness of existing physical security requirements or identify any method that the U.S. Nuclear Regulatory Commission staff may find acceptable for complying with existing requirements.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

An Intelligent Distributed Ledger Construction Algorithm for IoT

Blockchain is the next generation of secure data management that creates near-immutable decentralized storage. Secure cryptography created a niche for blockchain to provide alternatives to well-known security compromises. However, design bottlenecks with traditional blockchain data structures scale poorly with increased network usage and are extremely computation-intensive. This made the technology difficult to combine with limited devices, like those in Internet of Things networks. In protocols like IOTA, replacement of blockchain's linked-list queue processing with a lightweight dynamic ledger showed remarkable throughput performance increase. However, current stochastic algorithms for ledger construction suffer distinct trade-offs between efficiency and security. This work proposed a machine-learning approach with a multi-arm bandit that resolved these issues and was designed for auditing on limited devices. This algorithm was tested in a reinforcement-learning environment simulating the IOTA ledger's construction with a decision tree. This study showed through regret analysis and experimentation that this approach was secure against impulse manipulation attacks while remaining energy-efficient. Although the IOTA protocol was a pioneer for lightweight distributed ledgers, it is expected that future blockchain protocols will adopt techniques similar to those presented in this work.

multi-arm bandit↗

Design and Development of a Flight Route Modification, Logging, and Communication Network

There is an overwhelming desire to create and enhance communication mechanisms between entities that operate within the National Airspace System. Furthermore, airlines are always extremely interested in increasing the efficiency of their flights. An innovative system prototype was developed and tested that improves collaborative decision making without modifying existing infrastructure or operational procedures within the current Air Traffic Management System. This system enables collaboration between flight crew and airline dispatchers to share and assess optimized flight routes through an Internet connection. Using a sophisticated medium-fidelity flight simulation environment, a rapid-prototyping development, and a unified modeling language, the software was designed to ensure reliability and scalability for future growth and applications. Ensuring safety and security were primary design goals, therefore the software does not interact or interfere with major flight control or safety systems. The system prototype demonstrated an unprecedented use of in-flight Internet to facilitate effective communication with Airline Operations Centers, which may contribute to increased flight efficiency for airlines.

Merlino, Daniel K.↗

Revealing conductivity of p-type delta layer systems for novel computing applications

This project uses a quantum simulation technique to reveal the true conducting properties of novel atomic precision advanced manufacturing materials. With Moore's law approaching the limit of scaling for the CMOS technology, it is crucial to provide the best computing power and resources to National Security missions. Atomic precision advanced manufacturing-based computing systems can become the key to the design, use, and security of modern weapon systems, critical infrastructure, and communications. We will utilize the state-of-the-art computational methodology to create a predictive simulator for p-type atomic precision advanced manufacturing systems, which may also find applications in counterfeit detection and anti-tamper.

97 MATHEMATICS AND COMPUTING↗

Cyber-Informed Engineering Research and Development Guide

This document provides guidance on incorporating Cyber Informed Engineering (CIE) principles into the research and development (R&D) of operational technology systems and tools, facilitating the creation and adoption of innovative technologies that are secure and resilient by design. As technological innovation and research are becoming pivotal for economic and national security, cybersecurity has emerged as a paramount concern across industries and sectors. The challenge of integrating robust cybersecurity measures is imperative to safeguard critical infrastructure, protect sensitive data, and preserve national security interests.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Effects of Hydrogen Redistribution at High Temperatures in Yttrium Hydride Moderator Material

We report advanced materials development, manufacturing, and modeling capabilities for innovative reactor designs support nuclear security and mission-focused science through enhanced technology for safer and more efficient and secure production of nuclear energy. The high temperature moderator material yttrium hydride poses a significant enhancement in small reactor design by thermalizing (slowing down) neutrons and decreasing the required fuel mass for a system. The research presented here supports understanding hydrogen distribution in yttrium hydride through: (1) the development of neutron-based hydrogen imaging and crystallographic characterization that allows us to understand fundamental diffraction behaviors and to observe changes in hydrogen distribution as a function of temperature and (2) subsequent neutron multiplication (reactivity) effects of changes in hydrogen distribution using measurement-based cross sections in a sample microreactor design. The main conclusions from the work are that: (1) hydrogen does not redistribute significantly below temperatures of 800°C in yttrium hydride and (2) hydrogen redistribution affects the reactivity slightly but not significantly.

36 MATERIALS SCIENCE↗

Ares V: Game Changer for National Security Launch

NASA is designing the Ares V cargo launch vehicle to vastly expand exploration of the Moon begun in the Apollo program and enable the exploration of Mars and beyond. As the largest launcher in history, Ares V also represents a national asset offering unprecedented opportunities for new science, national security, and commercial missions of unmatched size and scope. The Ares V is the heavy-lift component of NASA's dual-launch architecture that will replace the current space shuttle fleet, complete the International Space Station, and establish a permanent human presence on the Moon as a stepping-stone to destinations beyond. During extensive independent and internal architecture and vehicle trade studies as part of the Exploration Systems Architecture Study (ESAS), NASA selected the Ares I crew launch vehicle and the Ares V to support future exploration. The smaller Ares I will launch the Orion crew exploration vehicle with four to six astronauts into orbit. The Ares V is designed to carry the Altair lunar lander into orbit, rendezvous with Orion, and send the mated spacecraft toward lunar orbit. The Ares V will be the largest and most powerful launch vehicle in history, providing unprecedented payload mass and volume to establish a permanent lunar outpost and explore significantly more of the lunar surface than was done during the Apollo missions. The Ares V consists of a Core Stage, two Reusable Solid Rocket Boosters (RSRBs), Earth Departure Stage (EDS), and a payload shroud. For lunar missions, the shroud would cover the Lunar Surface Access Module (LSAM). The Ares V Core Stage is 33 feet in diameter and 212 feet in length, making it the largest rocket stage ever built. It is the same diameter as the Saturn V first stage, the S-IC. However, its length is about the same as the combined length of the Saturn V first and second stages. The Core Stage uses a cluster of five Pratt & Whitney Rocketdyne RS-68B rocket engines, each supplying about 700,000 pounds of thrust. Its propellants are liquid hydrogen and liquid oxygen. The two solid rocket boosters provide about 3.5 million pounds of thrust at liftoff. These 5.5-segment boosters are derived from the 4-segment boosters now used on the Space Shuttle, and are similar to those used in the Ares I first stage. The EDS is powered by one J-2X engine. The J-2X, which has roughly 294,000 pounds of thrust, also powers the Ares I Upper Stage. It is derived from the J-2 that powered the Saturn V second and third stages. The EDS performs two functions. Its initial suborbital burns will place the lunar lander into a stable Earth orbit. After the Orion crew vehicle, launched separately on an Ares I, docks with the lander/EDS stack, EDS will ignite a second time to put the combined 65-metric ton vehicle into a lunar transfer orbit. When it stands on the launch pad at Kennedy Space Center late in the next decade, the Ares V stack will be approximately 381 feet tall and have a gross liftoff mass of 8.1 million pounds. The current point-of-departure design exceeds Saturn V s mass capability by approximately 40 percent. Using the current payload shroud design, Ares V can carry 315,000 pounds to 29-degree low Earth orbit (LEO) or 77,000 pounds to a geosynchronous orbit. Another unique aspect of the Ares V is the 33-foot-diameter payload shroud, which encloses approximately 30,400 cubic feet of usable volume. A larger hypothetical shroud for encapsulating larger payloads has been studied. While Ares V makes possible larger payload masses and volumes, it may alternately make possible more cost-effective mission design if the relevant payload communities are willing to consider an alternative to the existing approach that has driven them to employ complexity to solve current launch vehicle mass and volume constraints. By using Ares V s mass and volume capabilities as margin, payload designers stand to reduce development risk and cost. Significant progress has been made on the Ares V to support a plaed fiscal 2011 authority-to-proceed (ATP) milestone. The Ares V team is actively reaching out to external organizations during this early concept phase to ensure that the Ares V vehicle can be leveraged for national security, science, and commercial development needs. This presentation will discuss Ares V vehicle configuration, the path to the current concept, accomplishments to date, and potential payload utilization opportunities.

Sumrall, Phil↗

Advanced Utilization of the Payload Executive Processor (PEP) Ethernet Port to Support JSL Based Payloads

Increased interest by Payload Developers in utilization of the Joint Station LAN (Local Area Network) (JSL) for command and data transactions has driven the investigation of providing bi-directional Ethernet communication with PEP (Payload Executive Processor). Ethernet-only payload developers are interested in taking advantage of the services provided by PEP. Enabling Ethernet communications within PEP requires more than just turning on the hardware. PEP contains no Operating System (OS) or Ethernet stack so it does not inherit any built in functionality for Ethernet support. Both hardware drivers and application software must be developed from scratch. In the absence of an OS (Operating System) the design must address security issues in terms of access and data transferred, i.e. blocking unauthorized users and preventing denial of service. Developing a design to process Ethernet data within the existing real-time constraints of PEP requires a few compromises: data rates, supported protocols, custom packet format and limited client connections to name a few. Integration of the light weight internet protocol (LwIP). Ethernet stack provides a customizable solution for the embedded real-time environment. As utilization of the JSL increases, the successful implementation of an Ethernet interface enhances the utilization of PEP, and provides a new path for future Ethernet-only payloads to gain access to around the clock command and data services.

Guyette, Greg↗

Proposed Classifications of Remote Operations for Nuclear Reactors Based on Physical and Cybersecurity Considerations

The incorporation of remote operations into reactor operations is a topic of high interest among advanced and small modular reactor (A/SMR) vendors, with some considering it essential to the success of their business models. However, remote operations are a concept novel to the nuclear industry. While various technical aspects of remote operations have been explored, a significant gap remains in understanding the security implications of integrating remote operations into reactor designs, particularly concerning the security requirements for remote-operations facilities and infrastructure. This report aims to address this gap by first defining classes of remote operation based on the extent of remote access to reactor control systems and grounded in the existing regulatory framework with compatible terminology. Secondly, the report outlines the physical and cybersecurity requirements applicable to remote-operations facilities and infrastructure at each defined class. These requirements are based on existing licensing frameworks provided by 10 Code of Federal Regulations (CFR) Part 50 and 10 CFR Part 52, as well as the upcoming A/SMR licensing framework in the proposed Part 53. The assessment focuses specifically on security regulations, such as 10 CFR Part 73, which includes provisions for both cybersecurity (§ 73.54) and physical security (§ 73.55). This report proposes five classes of remote reactor operations. Class 1 involves remote monitoring only, with no control over reactor systems. Class 2 allows for the remote issuance of allowlisted commands to the reactor facility. Class 3 extends control to non-safety-significant, non-safety-related, or not important to safety systems and equipment. Class 4 permits remote control of safety-significant systems. Finally, Class 5 allows remote control of safety-related systems. It is important to note that these classes were defined purely with functionality in mind, without considering the practicality or feasibility of implementation for each class under current or upcoming regulatory guidance. The intention behind this approach is to enable an assessment of which security requirements apply to each class, allowing readers to evaluate the implementation possibilities for their specific use cases. Following the definition of remote-operation classes, the report assesses the specific physical and cybersecurity requirements applicable to the remote-operations facility and infrastructure within each defined class. This includes defining the types and locations of operators that are possible at each class of operation and, based on operator type and location, as well as functionality within each class, outlining the physical and cybersecurity requirements. By detailing the security requirements by class, the report provides readers with the information needed to determine the type of security program they may need to implement for their desired concept of operation. The next contribution of this report was to assess the practicality of implementing each proposed class of remote operations based upon the security requirement assessment. In short, three of the five proposed remote-operation classes were found to possibly have a practical path forward to implementation under the U.S. regulatory framework. Class 1 remote operations are currently in use in the U.S. while Class 2 and 3 remote operations may be logistically possible to implement under the U.S. regulatory framework. The final two Classes, 4 and 5, would likely be logistically difficult, if not infeasible to implement within the current U.S. physical- and cybersecurity regulatory framework. Given the results of the feasibility assessment, an example architecture is proposed for both Class 2, remote allowlisted commands, and Class 3, remote control of non-safety systems as well as security implication assessments of each architecture. These example implementations are not meant to be prescriptive in terms of how Class 2 or Class 3 remote operations should be deployed; instead, they are intended to be informative to stakeholders on how Class 2 or Class 3 could potentially be applied in order to inform their system design. An example architecture for Class 1 remote monitoring was not provided as Class 1 in already in use in U.S. nuclear operations. Example architectures for Class 4 and Class 5 were not provided due to their assessment of being likely infeasible to implement. The final contribution is an assessment of the physical- and cybersecurity implications of introducing autonomous operations into an A/SMR. What was found was that the security implications can be separated into two cases. Autonomous operations supported by SSCs located only at the reactor site, and autonomous operations supported by SSCs outside of the reactor site. For the first case, the introduction of autonomous systems will likely not change the facility’s requirement to comply with existing cyber and physical security regulation

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Feasibility study of an Integrated Program for Aerospace vehicle Design (IPAD). Volume 4: IPAD system design

The computing system design of IPAD is described and the requirements which form the basis for the system design are discussed. The system is presented in terms of a functional design description and technical design specifications. The functional design specifications give the detailed description of the system design using top-down structured programming methodology. Human behavioral characteristics, which specify the system design at the user interface, security considerations, and standards for system design, implementation, and maintenance are also part of the technical design specifications. Detailed specifications of the two most common computing system types in use by the major aerospace companies which could support the IPAD system design are presented. The report of a study to investigate migration of IPAD software between the two candidate 3rd generation host computing systems and from these systems to a 4th generation system is included.

Goldfarb, W.↗

Enabling Secure and Resilient XFC: A Software/Hardware-Security Co-Design Approach

Extremely fast charging (XFC) has the potential to reduce the charging time of battery electric vehicles (BEV) to be equivalent to the filling time of internal combustion engine vehicles (ICEV), thus eliminating one of the few advantages ICEV still poses for light- and heavy-duty vehicles. Enabling XFC will, however, require coordination and cooperation between the grid, charging stations, and the vehicles themselves, which leads to an inevitable increase in the attack surface for all systems combined. In securing the overall system, we must not only embrace traditional cybersecurity, which is chiefly concerned with communications and the operation of digital systems, but also cyber-physical systems security as the proper operation of XFC is critically dependent on systems’ abilities to know about (sense) and interact with (actuate) the physical world. The project team consists of academic and industry researchers with backgrounds in cybersecurity, cyber-physical systems security, learning in adversarial environments, transportation security, grid security and resilience, wireless power transfer, converter design, and battery management systems.

33 ADVANCED PROPULSION SYSTEMS↗

Assembling a Cyber Range to Evaluate Artificial Intelligence / Machine Learning (AI/ML) Security Tools

In this case study, we will describe the design and assembly of a cyber security test range we have built at Oak Ridge National Laboratory in Oak Ridge, TN, USA. The range is designed to provide a flexible environment to evaluate cyber security tools—particularly those involving AI/ML—in a way that provides realistic environments and where we can control the experiments to determine the strengths and weaknesses of the tools. We have designed in the ability to repeat the evaluations, so additional tools can be evaluated and compared at a later time. The system is one that can be scaled up or down for experiment sizes. At the time of the conference we will have completed two full-scale, national, government challenges on this range. These challenges are evaluating the performance and operating costs for AI/ML-based cyber security tools for application into large, government-sized environments. These evaluations will be described, in order to provide motivation and context for various design decisions and adaptations we have made. The first challenge measured end-point security tools against 100K malware samples chosen across a range of types. The second is network detection of attempted penetration and exploitations with varying levels of covertness in a high-volume, business network. The scale of each of these challenges is requiring us to create automation systems to repeat the experiments identically for each tool. Preventing there being easy signs of malicious activity for the AI/ML tools to focus on has been a particularly interesting and challenging aspect of designing and executing these challenge events. After the events, the range continues to be used for other research such as adversarial machine learning where the repeatability, scale, and automation required for the national challenge events become essential elements for research.

Nichols, Jeff↗

Expanding the Scope of Genomic Security: Targeted Genome Editing within Microbiomes through Designer Bacteriophage Vectors

The ability to engineer the genome of a bacterial strain, not as an isolate, but while present among other microbes in a microbiome, would open new technological possibilities in the areas of medicine, energy and biomanufacturing. Our approach is to develop sets of phages (bacterial viruses) active on the target strain and themselves engineered to act not as killers but as vectors for gene delivery. This approach is rooted in our bioinformatic tools that map prophages accurately within bacterial genomes. We present new bioinformatic results in cross-contig search, design of phage genome assemblies, satellites that embed within prophages, alignment of large numbers of biological sequences, and improvement of reference databases for prophage discovery. We targeted a Pseudomonas putida strain within a lignin-degrading microbiome, but were unable to obtain active phages, and turned toward a defined microbiome of the mouse gut.

59 BASIC BIOLOGICAL SCIENCES↗