Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 181 records · Page 10

Closure Report for Corrective Action Unit 366: Area 11 Plutonium Valley Dispersion Sites, Nevada National Security Site, Nevada with ROTC 1

This Closure Report presents information supporting closure of Corrective Action Unit (CAU) 366, Area 11 Plutonium Valley Dispersion Sites, and provides documentation supporting the completed corrective actions and confirmation that closure objectives for CAU 366 were met. CAU 366 consists of the following six Corrective Action Sites (CASs), located in Area 11 of the Nevada National Security Site: • CAS 11-08-01, Contaminated Waste Dump #1 • CAS 11-08-02, Contaminated Waste Dump #2 • CAS 11-23-01, Radioactively Contaminated Area A • CAS 11-23-02, Radioactively Contaminated Area B • CAS 11-23-03, Radioactively Contaminated Area C • CAS 11-23-04, Radioactively Contaminated Area D

54 ENVIRONMENTAL SCIENCES↗

Calendar Year 2024 Underground Test Area Annual Sampling Letter Report, Nevada National Security Site, Nevada, Rev. 1

The Underground Test Area (UGTA) Sampling Plan for Corrective Action Units (CAUs) 101 and 102: Central and Western Pahute Mesa, Nevada National Security Site (NNSS), Nevada (referred to herein as “the Plan”) (DOE/EMNV, 2025) describes the approach for collecting and analyzing groundwater samples to meet the objectives of the U.S. Department of Energy (DOE), Environmental Management (EM) Nevada Program’s UGTA Activity. The Plan is designed to ensure compliance with the UGTA Quality Assurance Plan (QAP) (DOE/EMNV, 2024), and the Federal Facility Agreement and Consent Order (FFACO) (1996, as amended).

54 ENVIRONMENTAL SCIENCES↗

Submittal of The Final Calendar Year (Cy) 2025 Post-Closure Monitoring Letter Report, Nevada National Security Site, Nevada, Revision 1, April 2026

This letter serves as the annual post-closure letter for CAU 98, Frenchman Flat; CAU 97, Yucca Flat/Climax Mine; and CAU 99, Rainier Mesa/Shoshone Mountain for calendar year 2025. This letter will discuss the post-closure monitoring activities that occurred during CY 2025, identify any triggers reached, and summarize water usage on the Nevada National Security Site and surrounding hydrographic basins at the three CAUs.

54 ENVIRONMENTAL SCIENCES↗

Non-Resource Conservation and Recovery Act Corrective Action Unit (CAU) Post-Closure Inspection Report, Nevada National Security Site, Nevada For Calendar Year 2025

This report includes visual inspection results, descriptions of maintenance and repair activities, and recommendations for CY 2025 for use restrictions (URs) at corrective action sites (CASs) located on the Nevada National Security Site and on the Nevada Test and Training Range (NTTR) that are accessed through the NNSS Main Gate. This document is arranged by project activity (i.e., Industrial Sites, Soils, and Defense Threat Reduction Agency [DTRA]); then by corrective action unit (CAU); and then by CAS. Post-closure UR inspections are performed on an annual basis, unless as noted in text. Post-closure UR inspections verify the condition of physical controls required by each UR, which may include the following activities: • Visual verification of the legibility of signs • Visual inspection of fencing, signs, monuments, and/or markers for indications of wear • Visual inspection of soil covers for indications of subsidence, erosion, or unauthorized use Deficiencies in UR requirements that were identified during CY 2024 inspections and not addressed in the CY 2024 report are addressed in this CY 2025 report.

54 ENVIRONMENTAL SCIENCES↗

Deny-by-Default Network Port Security: SPaRC Technical Bulletin #002

Operational Technology (OT) networks [e.g., industrial control systems (ICS) and supervisory control and data acquisition (SCADA) systems] have unique cyber security challenges due to their decades long service life, high availability requirements, and limited visibility. OT networks often take credit for being “air gapped” (i.e. disconnected from the Internet) and all devices within the OT network can “talk” to each other—even if they should not. This SPaRC Technical Bulletin describes how the unique limitations of OT networks can become strengths when it comes to cybersecurity.

Cybersecurity↗

Exponential Backoff and Its Security Implications for Safety-Critical OT Protocols over TCP/IP Networks

The convergence of Operational Technology (OT) and Information Technology (IT) networks has become increasingly prevalent with the growth of Industrial Internet of Things (IIoT) applications. This shift, while enabling enhanced automation, remote monitoring, and data sharing, also introduces new challenges related to communication latency and cybersecurity. Oftentimes, legacy OT protocols were adapted to the TCP/IP stack without an extensive review of the ramifications to their robustness, performance, or safety objectives. To further accommodate the IT/OT convergence, protocol gateways were introduced to facilitate the migration from serial protocols to TCP/IP protocol stacks within modern IT/OT infrastructure. However, they often introduce additional vulnerabilities by exposing traditionally isolated protocols to external threats. This study investigates the security and reliability implications of migrating serial protocols to TCP/IP stacks and the impact of protocol gateways, utilizing two widely used OT protocols: Modbus TCP and DNP3. Our protocol analysis finds a significant safety-critical vulnerability resulting from this migration, and our subsequent tests clearly demonstrate its presence and impact. A multi-tiered testbed, consisting of both physical and emulated components, is used to evaluate protocol performance and the effects of device-specific implementation flaws. Through this analysis of specifications and behaviors during communication interruptions, we identify critical differences in fault handling and the impact on time-sensitive data delivery. The findings highlight how reliance on lower-level IT protocols can undermine OT system resilience, and they inform the development of mitigation strategies to enhance the robustness of industrial communication networks.

DNP3↗

Nevada National Security Site Environmental Report 2024 with Attachment A Site Description and Summary Report

This Nevada National Security Site Environmental Report (NNSSER) summarizes actions taken in 2024 to protect the environment and the public while achieving the NNSA/NFO mission goals. It is prepared for the public and our stakeholders in hopes that it is readily understandable and usable. It is a key component in our efforts to keep the public informed of environmental conditions at the NNSS and its support facilities in Las Vegas, Nevada.

54 ENVIRONMENTAL SCIENCES↗

Nevada National Security Site Environmental Report 2024 - Summary Report

This Nevada National Security Site Environmental Report (NNSSER) summarizes actions taken in 2024 to protect the environment and the public while achieving the NNSA/NFO mission goals. It is prepared for the public and our stakeholders in hopes that it is readily understandable and usable. It is a key component in our efforts to keep the public informed of environmental conditions at the NNSS and its support facilities in Las Vegas, Nevada. This supplemental Summary report provides an abbreviated version of the full report.

54 ENVIRONMENTAL SCIENCES↗

Transportation Secure Data Center: Frequently Asked Questions for Data Owners/Contributors

The Transportation Secure Data Center is a centralized repository for detailed transportation data from travel and transit surveys and studies conducted across the nation. It makes vital transportation data broadly available to users while preserving the privacy of survey participants. Hundreds of datasets from surveys and studies of household travel and transit passenger travel are archived in the TSDC, including surveys and studies conducted by state departments of transportation, metropolitan planning organizations, transit agencies, cities, and other public agencies. Detailed data from travel surveys and studies are extremely valuable for research purposes. However, the fine-grained information they contain could potentially be misused to identify individual travelers, so access to these data should only be granted with safeguards in place to protect participant privacy. The TSDC was created to address this challenge and to relieve public agencies from the burden of archiving their data and responding to data requests.

33 ADVANCED PROPULSION SYSTEMS↗

Security Analysis of a Class of Spread Spectrum Systems Presentation

A method of adding physical layer security to a class of spread spectrum systems has been recently proposed. In this paper, we look into the rate at which an eavesdropper may gain information about the system to decipher the data symbols. The Shannon mutual information is used to measure the rate of information that may be gained by an eavesdropper. The k-nearest neighbors (k-NN) method is used to obtain estimates of relevant entropy values, which will then be used to quantify the rate of information recovery as more data is transmitted. It turns out that such information recovery requires the adoption of special methods that avoid any destructive bias in the estimates. Details of these methods are also presented.

97 - MATHEMATICS AND COMPUTING↗

Security of quantum position-verification limits Hamiltonian simulation via holography

We investigate the link between quantum position-verification (QPV) and holography established in [1] using holographic quantum error correcting codes as toy models. By inserting the “temporal” scaling of the AdS metric by hand via the bulk Hamiltonian interaction strength, we recover a toy model with consistent causality structure. This leads to an interesting implication between two topics in quantum information: if position-based verification is secure against attacks with small entanglement then there are new fundamental lower bounds for resources required for one Hamiltonian to simulate another.

AdS-CFT Correspondence↗

Impact of drought on global food security by 2050

Drought is a major driver of crop production loss, threatening global food security as the population rises toward 9 billion by 2050. Using a process-based crop model within an Earth system model, we assess drought-related impacts on maize, soybean, rice, and wheat production at global and country levels. We then develop a food insecurity index combining drought impacts with socio-economic factors. Our results indicate that by 2050, globally averaged drought losses for combined maize, soybean, rice, and wheat production are <2%, though soybean losses reach 3.6%. Despite these small average changes at the global scale, 62 countries experience maximum production losses over 10%, and 24 countries over 20%. Our index identifies regions at greatest risk, including large parts of South America, Africa, Eastern Europe, and Southeast Asia. These results illustrate the need for drought adaptation to mitigate future drought impacts on crop production.

54 ENVIRONMENTAL SCIENCES↗

Securing Smart Manufacturing: Detection of Cyber-Physical Attacks in CNC-Based Systems

As Industry 4.0 advances, the integration of computer numerical control (CNC) machines and advanced manufacturing technologies is transforming production into smart manufacturing systems that blend physical and digital processes as cyber-physical systems. However, this increased cyber-physical connectivity exposes manufacturing systems to cyber threats that can cause severe operational and financial disruptions. This paper presents a comparative study on cyber attacks and anomaly detection techniques in manufacturing, focusing on network traffic from CNC machines. The data extracted from network packets includes machine commands and control signals exchanged between the machine's interface and control system, crucial for maintaining operational integrity. We explore two types of cyber attacks, design modification and command injection, which pose substantial risks to CNC machine productivity and system integrity. Our investigation involves experiments on a real CNC system, highlighting the urgent need for effective detection mechanisms. To address these threats, we evaluate three anomaly detection methods: dynamic time warping (DTW), rolling average, and a deep learning, long short-term memory (LSTM) time-series-based autoencoder. Each is assessed for its effectiveness in identifying anomalous behaviors caused by the attacks. Our findings demonstrate the unique strengths and limitations of each detection technique, providing a deeper understanding of their applicability in realworld manufacturing environments. The comparative analysis indicates that while certain methods are highly effective against specific attack types, others offer broader applicability across different attacks. This study contributes to the accurate detection of anomalies in CNC machining processes, thereby enhancing the reliability and security of smart manufacturing systems against diverse cyber threats.

Williams, Bethanie [Tennessee Technological Univer↗

An Introduction to the Federated Architecture for Secure and Transactive Distributed Energy Management Solutions (FAST-DERMS)

Deployment and capability of distributed energy resources (DER) in power systems is growing rapidly. These resources present an opportunity for low-cost provision of energy and grid services. The Federal Energy Regulatory Commission recently provided rulings to enable market participation of these distribution-connected resources, but the prevailing strategies for their management may not scale well to meet future needs. This paper introduces the Federated Architecture for Secure and Transactive Distributed Energy Management Solutions (FAST-DERMS) which was designed to address this need. In it we describe the architectural features of the approach, and a reference controls implementation employing a hierarchical coordination that includes stochastic optimization, model predictive control, and a simple real-time management scheme. Sample results from simulation show firm transmission-level service provision measured at the distribution substation.

grid architecture↗

Securing 3D NAND Without Density Loss via In-Situ Encryption Using a Single Transistor XOR Cell

In this article, we push lightweight XOR-based in-situ encryption to extreme density by proposing a singletransistor XOR memory cell and applying it to 3D NAND, enabling secure data storage without density loss. Using a ferroelectric field-effect transistor (FeFET) as an example technology, we demonstrate that: i) a single-transistor memory can realize the XOR function by exploiting the ability to charge the source and drain separately and control current flow direction, eliminating the need for conventional encrypted cells that rely on complementary devices; ii) with a XOR-based cipher, encryption and decryption can be mapped to in-situ array operations, where ciphertext is stored as the threshold voltage (VTH) states of FeFETs in a NAND string, and decryption is achieved through read operations using key-dependent complementary source/drain bias; iii) the proposed technique is scalable to multi-level cell (MLC) storage by encrypting and decrypting data bit by bit; iv) using an integrated NAND FeFET array, we experimentally demonstrate encryption and decryption operations for both single-level cell (SLC) and MLC storage; v) systemlevel benchmarking shows that the proposed technique achieves 48× and 278× improvements in encryption and decryption throughput, respectively, compared to AES.

36 MATERIALS SCIENCE↗

Deciphering Discrepancies: A Comparative Analysis of Docker Image Security

As the use of microservices continues to grow and become a foundational approach to architecting software solutions, ensuring the security of microservices is paramount. Docker images have emerged as the predominant solution to containerize microservices–and thus, Docker images are becoming a large attack surface. Thus, reducing vulnerabilities in Docker images will reduce microservice cyberattacks. A common way to find vulnerabilities in Docker images employs static analysis tools like Trivy and Grype. However, these tools frequently generate disparate vulnerability reports when analyzing the same Docker image, thus causing uncertainty in tool selection. We collected 927 Docker images, analyzed them with Trivy and Grype, and compared the vulnerabilities reported in each image. Among the 865 images found to have vulnerabilities, Trivy and Grype disagreed on both the number of vulnerabilities and the vulnerability IDs found therein. Since both tools interface with external vulnerability databases, some discrepancies can be attributed to how the tools interface with these external resources. The external vulnerability databases partially overlap and frequently contradict one another, thereby creating challenges for static analysis tool developers and end users alike. This New Ideas and Emerging Results (NIER) study contains new and critical information that practitioners need for selecting and using static analysis tools–given that increases in the use of Docker technologies means increases in the size of the attack surfaces.

Boles, Brittany [Montana State University]↗

Aviation Security Screening Optimizer for Risk and ThroughputASSORT

The Aviation Security Screening Optimizer for Risk and Throughput (ASSORT) is designed to assess risk-based approaches for passenger screening and checkpoint operations. Additionally, ASSORT is exploring various traveler categories — general, trusted, and trusted-plus — along with different checkpoint screening Concept of Operations tailored to each traveler type

Brigantic, Robert [Pacific Northwest National Labo↗