Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Authentication”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 199 records · Page 11

“Experimental investigation of the governing parameters of atmospheric ice nucleation using field-collected and laboratory generated aerosol particles and its application in cloud resolving models” (Final Report)

The objective of this research project is to improve our understanding of the role of aerosol particles acting as ice-nucleating particles (INPs) which in turn define the mixed-phase and cirrus cloud radiative properties and thus climate. The focus is placed on how the physicochemical particle population properties determine the particles’ ability to initiate ice nucleation. This research project combined micro-spectroscopic particle analysis, experimental ice nucleation studies, and model sensitivity studies to advance our predictive capability of the formation of mixed-phase and cirrus clouds. These project activities have led to new ice nucleation data from laboratory generated and ambient (authentic) aerosol particles furthering process-level understanding, insights in the role of organic aerosol in ice formation, and advancements in the interpretation and parameterization of ice nucleation.

54 ENVIRONMENTAL SCIENCES↗

Tribal Renewable Energy: Bishop Paiute Tribe Youth Solar Job Training Development (Final Report)

This Project provided workshops and hands on opportunities for young tribal adults to gain education,training,and employment in the solar industry; including 1 youth to meet the eligibility requirements for the NABCEP Solar Installer Exam. 10 tribal youth, ages 16-24, attended workshops focused on learning solar fundamentals and then applied those learned skills to hands on training, installing solar on 2 tribal homes. GRID provided certificates authenticating their volunteer hours and skills learned. This program of youth training really excited the tribal leadership as well as the tribal youth. This opportunity was in alignment with the tribe’s Strategic Energy Plan, and supported tribal self-sufficiency, a path to economic development and for the youth it also represented the environmental stewardship the tribe believes in.

14 SOLAR ENERGY↗

Investigating Secondary Aerosol Processes in the Amazon through Molecular-level Characterization of Semi-Volatile Organics

In areas where biogenic emissions are oxidized in the presence of anthropogenic pollutants, it has become increasingly apparent that secondary organic aerosol (SOA) formation from biogenic volatile organic compounds (BVOCs) is substantially enhanced. The Amazon forest is the dominant source of BVOCs globally, and the forest is rapidly being converted to urban and agricultural uses. We participated in a collaborative field study located in the Amazon region around Manaus, Brazil, in 2014 (Green Ocean Amazon; GoAmazon). This study was designed to comprehensively examine how BVOC emissions (specifically, the most highly emitted non-methane hydrocarbon, isoprene, and lesser studied sesquiterpenes) and their interaction with anthropogenic pollution (i.e., nitrogen oxides, sulfur dioxide, and black carbon) alter the atmosphere’s oxidative capacity, influence secondary aerosol formation, atmospheric composition and, ultimately, affect the earth’s radiation balance and climate. We provide the first hourly, in-situ measurement of 30 sesquiterpenes and 4 diterpenes, roughly estimating that sesquiterpene oxidation contributes to 10-14% of ozone reactive loss by terpenes and at least 0.4–5% (median 1 %) of total submicron OA mass. However, this is likely a low-end estimate, as evidence for additional unaccounted sesquiterpenes and their oxidation products clearly exists. We also provide new perspectives on sulfate, NO x , and particle acidity influencing isoprene-derived SOA, comparing the central Amazon environment with Southeastern U.S.A. summer, representing clean to polluted conditions, respectively. We find that summed concentrations of isoprene-derived SOA tracers correlated with particulate sulfate spanning three orders of magnitude, suggesting that 1 μg m -3 reduction in sulfate corresponds with at least ~0.5 μg m -3 reduction in isoprene-derived SOA. We also find that SOA mass derived from isoprene oxidation in the presence of NO x is primarily comprised of aerosol sulfate bound with isoprene oxidation products (i.e. organosulfates), ~97% in the Amazon and ~55% in the Southeastern U.S. We infer under natural conditions in high isoprene emission regions, preindustrial aerosol sulfate was almost exclusively isoprene-derived organosulfates, which are traditionally thought as representative of anthropogenic influence. We further report the first field observations showing that particle acidity impacts the distribution of isoprene oxidation tracers in the gas and particle phases, providing physicochemical insight into isoprene SOA formation chemistry. Coupled with other co-located measurements by the DOE Atmospheric Radiation Measurement (ARM) team and collaborating PIs at our measurement site (called T3), on the G1 aircraft, and at additional field sites (T0, T1, T2) this data set has been used to understand emission, oxidation, and particle formation pathways at the molecular level, to elucidate how these pathways change when influenced by anthropogenic sources, and to evaluate their importance for the atmospheric budget of aerosols and the earth’s radiation balance on regional scales. Recommendations: Further constraint of the role of sesquiterpenes on ozone (O 3 ) reactivity and SOA formation is limited by the availability of authentic standards and synthesized compounds of sesquiterpenes and their oxidation products. Future research efforts should focus on making such standards available via custom synthesis to allow for accurate quantification and focused oxidation experiments that will fully elucidate the chemistry of these compounds in the atmosphere. Further, reductions in aerosol sulfate (via SO 2 emissions control) continues to be one of the most effective methods to reduce SOA formation from isoprene, but the concerted role of ammonia (NH 3 ) gas emissions from (agricultural) industry and other sources requires more investigation to better understand the role of aerosol acidity in SOA formation and potential controls. As GoAmazon particles can be more acidic compared to areas with greater anthropogenic NH 3 emissions, this promotes relatively greater organosulfate (OS) formation from isoprene even in the presence of NO x . Because OS and inorganic sulfate differ in water uptake properties, this implies preindustrial aerosol sulfate (albeit less abundant) may have been less reflective than current earth system models assume. Further research should investigate the radiative impacts of organic vs inorganic sulfate in aerosols to improve model representation. Finally, future work (currently underway) should include constraint of the contributions of monoterpene (C 10 H 16 ) BVOCs and biomass burning VOCs as precursors to SOA formation in the region as well as their impacts on radiative forcing in the climate system.

54 ENVIRONMENTAL SCIENCES↗

Additively Manufactured Tamper Evident Container (TEC)

Researchers at Los Alamos National Laboratory have developed a tamper evident container (TEC) to secure a broad variety of items from adversarial disclosure and espionage accidents. The new technology uses additive-manufacturing (AM) techniques for the concurrent creation of a container and arbitrarily complex-shaped three-dimensional tamper-sensitive features within its walls that authenticate the package. Analog and encrypted digital boards safely stored inside the TEC permanently record the complete security history of the protected items. Los Alamos is seeking commercial partners interested in further development and engineering prototype work.

42 ENGINEERING↗

Recommendations for Distributed Energy Resource Access Control

Cybersecurity for internet - connected Distributed Energy Resources (DER) is essential for the safe and reliable operation of the US power system. Many facets of DER cybersecurity are currently being investigated within different standards development organizations, research communities, and industry committees to address this critical need. This report covers DER access control guidance compiled by the Access Controls Subgroup of the SunSpec/Sandia DER Cybersecurity Workgroup. The goal of the group was to create a consensus - based technical framework to minimize the risk of unauthorized access to DER systems. The subgroup set out to define a strict control environment where users are authorized to access DER monitoring and control features through three steps: (a) user is identified using a proof-of-identity, (b) the user is authenticated by a managed database, (c) and the user is authorized for a specific level of access. DER access control also provides accountability and nonrepudiation within the power system control environment that can be used for forensic analysis and attribution in the event of a cyber-attack. This paper covers foundational requirements for a DER access control environment as well as offering a collection of possible policy, model, and mechanism implementation approaches for IEEE 1547-mandated communication protocols.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Verification of Data-Driven Models of Physical Phenomena using Interpretable Approximation

Machine-learned models, specifically neural networks, are increasingly used as “closures” or “constitutive models” in engineering simulators to represent fine-scale physical phenomena that are too computationally expensive to resolve explicitly. However, these neural net models of unresolved physical phenomena tend to fail unpredictably and are therefore not used in mission-critical simulations. In this report, we describe new methods to authenticate them, i.e., to determine the (physical) information content of their training datasets, qualify the scenarios where they may be used and to verify that the neural net, as trained, adhere to physics theory. We demonstrate these methods with neural net closure of turbulent phenomena used in Reynolds Averaged Navier-Stokes equations. We show the types of turbulent physics extant in our training datasets, and, using a test flow of an impinging jet, identify the exact locations where the neural network would be extrapolating i.e., where it would be used outside the feature-space where it was trained. Using Generalized Linear Mixed Models, we also generate explanations of the neural net (à la Local Interpretable Model agnostic Explanations) at prototypes placed in the training data and compare them with approximate analytical models from turbulence theory. Finally, we verify our findings by reproducing them using two different methods.

42 ENGINEERING↗

Evaluation of Data Catalog Software for Hanford Site Environmental Datasets

Environmental information and data underpin achievement of the U.S. Department of Energy (DOE) Office of Environmental Management (EM) mission at the Hanford Site. The Hanford Environmental Data Management (HEDM) Program is the DOE Richland Operations Office (RL) approach to develop and implement a formal program for managing environmental data and the associated records, materials, and systems at the Hanford Site. The current project, contract, organization, and contractor-specific efforts at managing environmental data sets are insufficient to provide orderly, long-term, site-wide access. A vital element to be created within the HEDM program plan is a catalog of data sources, called the Hanford Environmental Information and Data Index (HEIDI), that will enable long-term access and retrievability for the multiple independent sources of data that might otherwise be difficult to discover. This report compares leading open source and commercial data catalog platforms using criteria to assess the functionality needed to develop the HEIDI catalog of Hanford data sources that connects and exchanges data with established Hanford Local Area Network (HLAN) enterprise information technology systems. Proprietary platforms evaluated included ArcGIS Enterprise Sites, Junar, OpenDataSoft, and Socrata, and non-proprietary platforms included Energy Data eXchange (EDX), Comprehensive Knowledge Archive Network (CKAN), and DKAN (a Drupal-based open data portal based on CKAN). Capabilities supporting data discoverability, retrieval, and archival, as well as metadata standard requirements and integration into the HLAN were rated as either failing to meet requirements (F), meeting requirements (M), or exceeding requirements by delivering additional desired features (E). The lowest rating for any capability area was assigned as the overall rating for the platform. These findings enable DOE-RL and the contractors implementing the HEDM plan to focus on candidate tools likely to meet the requirements for implementing HEIDI. All of the platforms receiving an overall rating of ‘F’ were unable to be deployed on Hanford infrastructure or within dedicated cloud resources. A propriety software-as-a-service (SaaS) model of delivering a data catalog (e.g., found in software such as Junar and OpenDataSoft) favors consistency across customers at the expense of customization and configurable roles that are needed for Hanford work. Hosting data on a shared commercial platform places limits on dataset size (maximum of 240 Mb for OpenDataSoft), a significant limitation for HEIDI implementation. EDX, a government data catalog based on CKAN, received the ‘F’ rating due to an inability to incorporate authentication from HLAN into the system. Among platforms rated ‘M’ or ‘E’, only the Socrata platform had a SaaS delivery model. In contrast to other SaaS platforms, Socrata provided custom roles and gateways that allow local datasets to be incorporated into an online catalog. Socrata also complies with the Federal Risk and Authorization Management Program, a significant benefit for cloud-based management of Hanford data. The other platforms rated ‘M’ or ‘E’, ArcGIS Enterprise Sites, CKAN, and DKAN, provide fully self-hosted options, allowing for greater control and flexibility with the HEIDI catalog. These widely used tools have supportive communities of practice, extensive customization options, and demonstrated deployments that provide evidence that they can meet requirements, often deliver additional desired features, and work well with federal government systems. Completely customized alternatives built on a collection of applications were not evaluated because achieving similar performance to CKAN or DKAN requires substantial resources, especially in the absence of the active communities that have grown to support these tools. ArcGIS Enterprise Sites, Socrata, CKAN, and DKAN were evaluated as strong candidates for successful implementation with HEIDI.

54 ENVIRONMENTAL SCIENCES↗

Cybersecurity Certification Recommendations for Interconnected Grid Edge Devices and Inverter Based Resources

Escalating deployment of PV and grid-edge devices on the distribution grid has increased the sustainability and efficiency of the electric grid. However, the increasing number of distributed energy resources (DERs) deployed creates a heightened cyber-physical interdependency on the distribution grid and thus creates more vectors for cyber-attacks to exploit through information and communication technology (ICT) systems and networks. For example, control signal packets can be modified, intercepted, or corrupted due to vulnerabilities in communication protocols used by microgrid controllers and grid edge devices for power control. Therefore, to mitigate and prevent cyber-attacks on grid edge devices and the inverter-based resources connected to the distribution grid, the U.S. Department of Solar Energy Technologies Office (SETO) awarded funding to the National Renewable Energy Laboratory and Sandia National Laboratory (SNL) to research, develop, and harmonize cybersecurity standards for Photovoltaic (PV) systems and for other kinds of DERs. To help develop a standard for DER cybersecurity, NREL established certification recommendations and test cases, in consensus with the solar industry and UL, for ensuring intrinsic design security for DERs. These recommendations were developed to bolster the cybersecure functionalities such as TLS, MAC, CRL, session resumption/renegotiation, and password, system, and service security management within the DER devices. The proposed test cases verify authentication, authorization, confidentiality, and data integrity for data and communications of DERs that use Transmission Control Protocol/Internet Protocol (TCP/IP). They were also developed to protect DER communications from eavesdropping, replay, man-in-the-middle, denial of service (DoS), spoofing through security certificates, least-privilege violation, and brute-force credentials. This report, which has been validated and reviewed by UL, expands upon those test cases to provide DER cybersecurity certification recommendations which increase DER resiliency and help to mitigate cyber-attacks. UL's collaboration with NREL and approval of this document will accelerate the adoption of a UL standard for DER cybersecurity.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Modular Security Apparatus for Managing Distributed Cryptography for Command-and-Control Messages on Operational Technology Networks (Module-OT)

Module-OT is a bump- in- the- wire solution acting as a secure conduit for data between devices or systems across a network. Using the latest in open-source cryptographic libraries, all defined communications undergo authentication, authorization, and encryption. The core system can be easily installed through industry standard processes, and the use of popular open-source packages allows for it to be customizable customized by the developer community or deployed in unique embedded environments.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Cybersecurity Threat Profile for a Connected Lighting System

In this paper we analyze a threat profile performed on a fault-detection use case for streetlights. A threat profile establishes security requirements, justifies security measures, yields actionable controls, and effectively communicates risk to stakeholders. This effort provides critical information for making threat-based decisions to increase security at a reasonable cost, and can effectively be used by development teams, software architects, and managers to make cybersecurity a part of their ongoing culture of awareness, training, and prevention. This leads to more secure systems and better-understood security. On-premise, cloud, and hybrid architectures with different authentication mechanisms were modeled and later categorized using the Microsoft STRIDE framework. An analysis of the recommended controls for each threat was performed to determine which controls could and should be put in place by manufacturers or third-party suppliers, and which controls need to be left up the end-user to implement.

97 MATHEMATICS AND COMPUTING↗

Assessment of the Electrical Substation-Grid Testbed with Inside/Outside Devices and Distributed Ledger Technology

The electrical substation-grid testbed was created to integrate the GOOSE and/or DNP (Distributed Network Protocol) messages with time synchronized sources and Distributed Ledger Technology (DLT). The objective was to study the impact of faults and cyber-events at an electrical substation with inside (protective relays) and outside (power meters) substation devices. The electrical substation-grid testbed was based on the design of a 34.5/ 12.47 kV electrical substation (sectionalized bus configuration) with two power transformers, connected to radial power lines and load feeders. The electrical substation-grid testbed was installed at 252 lab space (Advanced Power System Protection), Grid Research Integration and Deployment Center (GRID-C), Oak Ridge National Laboratory. This testbed was created for Task 5, DarkNet project. The electrical substation-grid testbed was created to simulate fault and/or cyber events that could potentially result in damage to the electrical infrastructure. In addition, tests were run that are usually not allowed to be performed in an operational electrical power grid, because these test scenarios could trip breakers and/or generate fault situations that could potentially damage equipment. The number of tests performed in the electrical substation-grid testbed were executed in a better way than in a real electrical substation and/or power grid, because multiple tests could be run in a short period of time, and complex permits, and safety/ schedule restrictions like in a real electrical substation environment were not needed. The electrical substation-grid testbed was created using real measurement, communication, and protection devices that are used by electrical utilities, to have same conditions that we could observe in a real power grid or electrical substation. The electrical substation-grid testbed was based on using a real time simulator and expansion box with amplifiers that were wired to electrical substation-grid devices. This hardware-in-the-loop (HIL) was provided by protective relays, power meters, ethernet switches, remote terminal units, synchronized timing network clock, DLT devices, workstations, and servers. This report includes the design, installation, and assessment of the electrical substation-grid testbed that was similar to an operational electrical substation, integrating the power system protection, communication, and control systems. The results for the electrical substation-grid testbed were based on:• verifying the analog signals for protective relays and power meters, • observing the synchronized time source frame at devices, • authenticating the GOOSE (IEC 61850) and DNP messages from power meters and protective relays, and • verifying the trip conditions of protective relays at fault tests with the power system fault event detection, using DLT devices. For future work, the electrical substation-grid testbed with protective relays and power meters, using DLT and synchronized time source from DarkNet, will be used to study the impact of cyber-events at inside and outside substation devices. Advanced algorithms for detecting cyber-events produced by non-desired protective relay settings will be studied, to improve the detection and reliability of protection, control, and communication systems at power grids.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Step Toward Working with Untrusted Ground Stations

We are witnessing a shift toward outsourcing satellite and ground station services to third-party commercial entities. As with any enterprise, these third parties can be vulnerable to cyber compromise, including image tampering and deepfake injection. The multimedia community is beginning to establish standards and technology to enable authenticity verification of multimedia created and edited by others. While appealing to the remote sensing domain, the nature of raw satellite imagery is incompatible with the proposed change verification tools, resulting in the need for a means to validate updates made to image products. We present a simple method for verifying a specific class of algorithms. Our inverse processing approach eliminates the need to see the original image as the reversed data can be checked against an original digital signature. We demonstrate our approach on basic image restoration routines and conclude with a discussion on open challenges and next steps.

97 MATHEMATICS AND COMPUTING↗

CTAP REPORT. Commercialization of Power Spectrum Analysis (PSA) Technology

Power Spectrum Analysis (PSA) is a Sandia-developed, non-intrusive, electrical technique that captures distinct frequency-domain signatures of microelectronics devices using an innovative, unconventional biasing scheme (off-normal biasing). PSA can identify subtle differences in devices and is applicable in various areas such as device screening, counterfeit identification, reliability assurance, and trust authentication. From October 2020 to April 2021, Sandia worked with entrepreneurs from a new start-up company, Chiplytics, to commercialize PSA technology through NNSA-sponsored FedTech Program. In September 2021, Sandia received funding through Covid-19 Technical Assistance Program (CTAP) to provide technical assistance to Chiplytics for commercialization. Under the CTAP Statement of Work, Sandia was tasked with providing technical assistance to Chiplytics in PSA pilot testing for Naval Surface Warfare Center (NSWC) at Crane and other pilot participants. Sandia was also tasked with assisting Chiplytics in hardware development and evaluation of Chiplytics prototype system.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Artificial Intelligence for Accelerating Nuclear Applications, Science, and Technology

Artificial intelligence (AI) and machine learning (ML) methods have had significant impacts in science and technology in recent years. These methods for generating models from datasets or logic-based algorithms that emulate aspects of human performance can similarly accelerate the fields of nuclear applications, science, and technology toward the IAEA goals of contributing to peace, health, and prosperity. In order to accomplish advances with AI in general and ML in particular across these fields, IAEA can play a significant role by establishing, hosting and curating centralised resources, including databases, adhering to FAIR (findable, accessible, interoperable and reusable) principles and Open Science best practices, providing stewardship of data sharing, supporting training efforts and development of relevant workforces, as well as enabling connections among the scientific, technology, mathematics, AI and ethics communities. Many areas can benefit from the use of AI in the realm of nuclear applications. In human health, these areas include clinical research, epidemiology, nutrition, medical imaging, radiotherapy and education of health professionals. AI-based tools are also being used to facilitate different clinical tasks in imaging, computer-assisted diagnosis in mammography and lung cancer screening programmes, and dose prediction in nuclear medicine procedures. ML methods in particular may also increase the efficiency and accuracy of the analysis of computerised tomography and dual-energy absorptiometry scans for body composition and bone analysis. The application of AI methods to nuclear and related technologies in food and agriculture can lead to significant advances and improved efficiency in the optimisation of agricultural production, food product development, management of supply chains, food safety and food authenticity control. In the water and environmental sector, AI can help inform policies to mitigate the world’s water problems. The application of AI techniques to hydrology and environmental sciences is expected to improve patterns identification and enable model predictions under a changing climate.

73 NUCLEAR PHYSICS AND RADIATION PHYSICS↗

Secure Data Logging and Processing with Blockchain and Machine Learning (Final Report)

Secure Data Logging and Processing with Blockchain and Machine Learning (ML) research is focused on the development of a platform to securely log and process sensor data in fossil power plants. The platform integrates two emerging technologies, blockchain and ML, and incorporates several innovative mechanisms to ensure the integrity, reliability, and resiliency of power systems. The goal is to protect the power plant from various cyberattacks such as false data injection and denial of service attacks using these technologies. The research goal was enabled by the following Research Project Objectives: 1) Secure authentication and identity verification of sensor nodes, actuators, and other equipment within a network. 2) Development of mechanisms that ensure only data sent by legitimate sensors are accepted and stored in the data repository. 3) Development of data aggregation methodologies using ML / Deep Learning (DL) algorithms to minimize noise / faulty data. 4) Implementation of the blockchain technologies to provide data security using secured IOTA framework & nodes.

20 FOSSIL-FUELED POWER PLANTS↗

Cyber and Physical Security Analysis of GSI and Noventum Application for IoT Communications

We present our findings of the red team exercise conducted on the device and application developed by Guardian Sensors, Inc. (GSI) and Noventum. The app is used for situational awareness and control of photovoltaics (PV) and microgrid energy systems. The assessments performed are practical case scenarios that assess the risks and vulnerabilities posed by the app through targeted activities that could be engaged by an adversary. The assessment team’s results and recommendations are provided to inform on and mitigate the identified weaknesses to improve secure user authentication, connections, and communications. The recommendations in this report are not intended to be a security panacea but will add the desired defense-in-depth layer to securing communication of such interconnected systems.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Evaluating Named Data Networking for Industrial Control System [Slides]

Current proposed work is: See if the inherent security that comes with Named Networking (NDN) can be applied to Industrial Control Systems; and, Every packet is required to be cryptographically signed which makes every single piece of data communicated in the system secure and authenticated.

42 ENGINEERING↗

Advanced Algorithms for Scrutiny of Mandatory State Reports Declarations to the IAEA (Final Project Report)

In compliance with their Comprehensive Safeguards Agreements, based on INFCIRC/153 (corrected) (International Atomic Energy Agency, 1972), States Party to the Treaty on the NonProliferation of Nuclear Weapons (NPT) are obligated to declare to the International Atomic Energy Agency (IAEA) all changes in their nuclear material inventory as well as movement of the material across boundaries of IAEA recognized material balance areas (MBA), inventories and nuclear material balances. This project addresses capabilities to detect irregularities in State reports, thus ensuring their accuracy and completeness, and in the broader context, States’ compliance with safeguards obligations of the NPT. A recent study (Henzl et al., 2022) (lead by this project’s PI) demonstrated how analysis of dynamic correlations in nuclear material movement within the entire fuel cycle of a State (viewed as a single system) can reveal variances consistent with and indicative of “irregular” activities. Expanding on this concept, novel ways to analyze State declarations themselves—again, for the State as a whole entity—will help the IAEA draw accurate safeguards conclusions and trust the validity and authenticity of Stategenerated declaration reports. Introducing new declaration analyses capabilities explored in this project will help to provide credible assurance of both the non-diversion of nuclear material from declared activities and of the absence of undeclared nuclear material and activities in the State in general.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗