Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Critical Infrastructure Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 199 records · Page 11

Extreme-scale stochastic optimization and simulation via learning-enhanced decomposition and parallelization (Final Technical Report)

Stochastic optimization and simulation models ubiquitously arise in designing and operating complex service/engineering systems. They can be extreme in scale due to high-dimensional data and decisions, and can also involve decisions made sequentially in response to newly revealed data, both causing significant computational challenge. The objective of this research is to explore a unified framework that integrates machine learning with discrete optimization and risk-averse modeling, to improve the efficiency of decomposition paradigms for stochastic optimization and simulations at extreme scale. The models we consider represent a broad class of complex decision-making problems, where 0-1 or continuous decisions are made before and/or after knowing multiple sources of uncertainties that could be correlated. We will employ machine learning methods to dynamically decide and prioritize computational procedures, including cut generation, branching, and bounding of the optimal objective. Furthermore, the research will shed new lights on the traditional decomposition algorithms for extreme-scale computing. Deliverables of the research include new modeling and computational methods for advancing the state-of-the-art research in optimization and simulation, bringing many relevant risk-averse, data-driven optimization problems in practice within the range of tractability. Examples include distributed computing server scheduling and sensor deployment for monitoring critical infrastructures. Success in this effort will enable progress in solving multiple extreme-scale problems in the complex system design and operations arising from DoE missions in energy, environment, and national security.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Extreme Scale Infrasound Inversion and Prediction for Weather Characterization and Acute Event Detection

Accurate and timely weather predictions are critical to many aspects of society with a profound impact on our economy, general well-being, and national security. In particular, our ability to forecast severe weather systems is necessary to avoid injuries and fatalities, but also important to minimize infrastructure damage and maximize mitigation strategies. The weather community has developed a range of sophisticated numerical models that are executed at various spatial and temporal scales in an attempt to issue global, regional, and local forecasts in pseudo real time. The accuracy however depends on the time period of the forecast, the nonlinearities of the dynamics, and the target spatial resolution. Significant uncertainties plague these predictions including errors in initial conditions, material properties, data, and model approximations. To address these shortcomings, a continuous data collection occurs at an effort level that is even larger than the modeling process. It has been demonstrated that the accuracy of the predictions depends on the quality of the data and is independent to a certain extent on the sophistication of the numerical models. Data assimilation has become one of the more critical steps in the overall weather prediction business and consequently substantial improvements in the quality of the data would have transformational benefits. This paper describes the use of infrasound inversion technology, enabled through exascale computing, that could potentially achieve orders of magnitude improvement in data quality and therefore transform weather predictions with significant impact on many aspects of our society.

58 GEOSCIENCES↗

Recommendations for Distributed Energy Resource Patching

While computer systems, software applications, and operational technology (OT)/Industrial Control System (ICS) devices are regularly updated through automated and manual processes, there are several unique challenges associated with distributed energy resource (DER) patching. Millions of DER devices from dozens of vendors have been deployed in home, corporate, and utility network environments that may or may not be internet-connected. These devices make up a growing portion of the electric power critical infrastructure system and are expected to operate for decades. During that operational period, it is anticipated that critical and noncritical firmware patches will be regularly created to improve DER functional capabilities or repair security deficiencies in the equipment. The SunSpec/Sandia DER Cybersecurity Workgroup created a Patching Subgroup to investigate appropriate recommendations for the DER patching, holding fortnightly meetings for more than nine months. The group focused on DER equipment, but the observations and recommendations contained in this report also apply to DERMS tools and other OT equipment used in the end-to-end DER communication environment. The group found there were many standards and guides that discuss firmware lifecycles, patch and asset management, and code-signing implementations, but did not singularly cover the needs of the DER industry. This report collates best practices from these standards organizations and establishes a set of best practices that may be used as a basis for future national or international patching guides or standards.

97 MATHEMATICS AND COMPUTING↗

Base Station Antenna Uptilt Optimization for Cellular-Connected Drone Corridors

Reliable wireless coverage in drone corridors is critical to enable a connected, safe, and secure airspace. To support beyond visual line of sight (BVLOS) operations of aerial vehicles in a drone corridor, cellular base stations (BSs) can serve as a convenient infrastructure as they are widely deployed to provide seamless wireless coverage. However, antennas in the existing cellular networks are down-tilted to optimally serve their ground users, which results in coverage holes at higher altitudes when they are used to serve drones. In this paper, we consider the use of additional uptilted antennas at each cellular BS and optimize the uptilt angle to maximize the wireless coverage probability across a given drone corridor. Through numerical results, we can characterize the optimal value of the antenna uptilt angle for a given antenna pattern as well as the minimum/maximum altitudes of the drone corridor.

42 ENGINEERING↗

Bridge Seismic Screening Tool (BSST), Version 2.0

The Regional Resiliency Assessment Program (RRAP) is a cooperative assessment of specific critical infrastructure within a designated geographic area and a regional analysis of the surrounding infrastructure that addresses a range of infrastructure resilience issues that could have regionally and nationally significant consequences. In 2018, DHS’s Cybersecurity and Infrastructure Security Agency (CISA) sponsored the Oregon Transportation Systems RRAP project in coordination with the Office of the Governor (under the oversight of the state resilience officer), the Oregon Office of Emergency Management (OEM), the Oregon Department of Transportation (ODOT), and other regional stakeholders (CISA 2021). This project focuses on assessing the impacts of a Cascadia Subduction Zone (CSZ) earthquake on state transportation systems and, in particular, how those impacts may affect the ability of emergency response efforts to move supplies into the region. The intended outcome of this analysis is the prioritization of transportation routes and modes for additional planning, investment, hardening, or other activities to enhance their resilience—and therefore, to enhance their ability to support response and recovery efforts following a CSZ earthquake. An important part of this transportation system-level assessment has been to assess the seismic vulnerability of the state highway system. In doing so, the RRAP project team used the Bridge Seismic Screening Tool (BSST) to assess, at a system-level, the potential impacts that a CSZ earthquake could have on state highway bridges (Bergerson et al. 2019).1 Argonne National Laboratory (Argonne), in collaboration with the Washington State Department of Transportation (WSDOT), originally developed the BSST as part of the 2017 Washington State Transportation Systems RRAP project, a sister project to the 2018 Oregon Transportation Systems RRAP project. Argonne updated the BSST during this more recent project in Oregon based on feedback from stakeholders and subject matter experts (SMEs) on the original version of the tool. The first step in the BSST is to assess the seismic vulnerability of roadway bridges following a CSZ earthquake to determine a projected or potential damage state. Damage states then help determine approximate reopening times for bridge crossings.2 This document provides details on the BSST methodology, the implementation of that tool to analyze the projected damage incurred in a CSZ earthquake scenario, and the determination of corresponding reopening times of interstate, state highway, and local bridges following such an event.

58 GEOSCIENCES↗

Energy Resilience for Mission Assurance: Agile Co-simulation for Cyber Energy System Security (ACCESS), Model Advancements for Resilience Analysis

Agile Co-simulation for Cyber Energy System Security (ACCESS) is a co-simulation platform developed by Lawrence Livermore National Laboratory (LLNL). The primary high-level use-case for ACCESS is to study existing or new cyber-physical critical infrastructure systems, with a heavy emphasis on 1) systems that utilize communication networks, and 2) studies that seek to understand cyber-related system impacts. ACCESS is currently used for several energy system resilience projects at LLNL. In the Energy Resilience for Mission Assurance (ERMA) project, ACCESS is used in the Modeling for Metric Calculation task (specifically, subtask 4.3, Communications and Cyber Modeling) to model and simulate the cyber and communication system aspects of Defense Critical Electric Infrastructure (DCEI) systems, with a focus on computing specific communication system metrics that can impact system resilience and mission performance. Simulated communication system performance will be fed back to other ERMA system components so that mission performance can be evaluated holistically. This report describes several enhancements to the ACCESS platform that were implemented during the execution of the ERMA project in support of reslience analysis. This includes the addition of new models and subsystems, enhancements to existing models, and integration with external systems. The remainder of this report is structured as follows. In Section 2, a brief background description of the ACCESS platform is provided, including an outline of ACCESS components, example usecases, and a set of communication network resilience metrics that can be computed with ACCESS. Section 3 describes the ACCESS model enhancements for ERMA in detail. Finally, Section 4 briefly outlines future integration opportunities between ACCESS and project participant capabilities identified during the progression of the project.

97 MATHEMATICS AND COMPUTING↗

Energy Resilience for Mission Assurance, Agile Co-simulation for Cyber Energy System Security (ACCESS) Model Advancements for Resilience Analysis (Version 3, July 2023)

Agile Co-simulation for Cyber Energy System Security (ACCESS) is a co-simulation platform developed by Lawrence Livermore National Laboratory (LLNL). The primary high-level use-case for ACCESS is to study existing or new cyber-physical critical infrastructure systems, with a heavy emphasis on 1) systems that utilize communication networks, and 2) studies that seek to understand cyber-related system impacts. ACCESS is currently used for several energy system resilience projects at LLNL. In the Energy Resilience for Mission Assurance (ERMA) project, ACCESS is used in the Mod eling for Metric Calculation task (specifically, subtask 4.3, Communications and Cyber Modeling) to model and simulate the cyber and communication system aspects of Defense Critical Electric Infrastructure (DCEI) systems, with a focus on computing specific communication system metrics that can impact system resilience and mission performance. Simulated communication system per formance will be fed back to other ERMA system components so that mission performance can be evaluated holistically. This report describes several enhancements to the ACCESS platform that were implemented during the execution of the ERMA project in support of reslience analysis. This includes the addition of new models and subsystems, enhancements to existing models, and integration with external systems. The remainder of this report is structured as follows. In Section 2, a brief background description of the ACCESS platform is provided, including an outline of ACCESS components, example use cases, and a set of communication network resilience metrics that can be computed with ACCESS. Section 3 describes the ACCESS model enhancements for ERMA in detail. Finally, Section 4 briefly outlines future integration opportunities between ACCESS and project participant capabilities identified during the progression of the project.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Reusable launch vehicle: Technology development and test program

The National Aeronautics and Space Administration (NASA) requested that the National Research Council (NRC) assess the Reusable Launch Vehicle (RLV) technology development and test programs in the most critical component technologies. At a time when discretionary government spending is under close scrutiny, the RLV program is designed to reduce the cost of access to space through a combination of robust vehicles and a streamlined infrastructure. Routine access to space has obvious benefits for space science, national security, commercial technologies, and the further exploration of space. Because of technological challenges, knowledgeable people disagree about the feasibility of a single-stage-to-orbit (SSTO) vehicle. The purpose of the RLV program proposed by NASA and industry contractors is to investigate the status of existing technology and to identify and advance key technology areas required for development and validation of an SSTO vehicle. This report does not address the feasibility of an SSTO vehicle, nor does it revisit the roles and responsibilities assigned to NASA by the National Transportation Policy. Instead, the report sets forth the NRC committee's findings and recommendations regarding the RLV technology development and test program in the critical areas of propulsion, a reusable cryogenic tank system (RCTS), primary vehicle structure, and a thermal protection system (TPS).

Source record↗

BioSecure Digital Twin: Manufacturing Innovation and Cybersecurity Resilience

U.S. national security, prosperity, economy, and well-being require secure, flexible, and resilient Biopharmaceutical Manufacturing. The COVID-19 pandemic reaffirmed that the biomedical production value-chain is vulnerable to disruption and has been under attack from sophisticated nation-state adversaries. Current cyber defenses are inadequate, and the integrity of critical production systems and processes are inherently vulnerable to cyber-attacks, human error, and supply chain disruptions. The following chapter explores how a BioSecure Digital Twin will improve U.S. manufacturing resilience and preparedness to respond to these hazards by significantly improving monitoring, integrity, security, and agility of our manufacturing infrastructure and systems. The BioSecure Digital Twin combines a scalable manufacturing framework with a robust platform for monitoring and control to increase U.S. biopharma manufacturing resilience. Then, the chapter discusses some of the inherent vulnerabilities and challenges at the nexus of health and advanced manufacturing. Next, the chapter highlights that as the Pandemic evolves, we need agility and resilience to overcome significant obstacles. This section highlights an innovative application of Cyber Informed Engineering to developing and deploying a BioSecure Digital Twin to improve the resilience and security of the biopharma industrial supply chain and production processes. Finally, the chapter concludes with a process framework to complement the Digital Twin platform, called the Biopharma (Observe, Orient, Decide, Act) OODA Loop Framework (BOLF), a four-step approach to decision-making outputs from the Digital Twin. The BOLF will help end users leverage twin technology by distilling the available information, focusing the data on context, and rapidly making the best decision while remaining cognizant of changes that can be made as more data becomes available.

99 GENERAL AND MISCELLANEOUS↗

Cyber–Physical System Security of Distribution Systems

The Information and Communications Technology (ICT) for control and monitoring of power systems is a layer on top of the physical power system infrastructure. The cyber system and physical power system components form a tightly coupled Cyber–Physical System (CPS). Sources of vulnerabilities arise from the computing and communication systems of the cyber–power grid. Cyber intrusions targeting the power grid are serious threats to the reliability of electricity supply that is critical to society and the economy. In a typical Information Technology environment, numerous attack scenarios have shown how unauthorized users can access and manipulate protected information from a network domain. The need for cyber security has led to industry standards that power grids must meet to ensure that the monitoring, operation, and control functions are not disrupted by cyber intrusions. Cyber security technologies such as encryption and authentication have been deployed on the CPS. Intrusion or anomaly detection and mitigation tools developed for power grids are emerging. Furthermore, this survey paper provides the basic concepts of cyber vulnerabilities of distribution systems and CPS security. The important ICT subjects for distribution systems covered in this paper include Supervisory Control And Data Acquisition, Distributed Energy Resources, including renewable energy and smart meters.

97 MATHEMATICS AND COMPUTING↗

Layered virus protection for the operations and administrative messaging system

NASA's Deep Space Network (DSN) is critical in supporting the wide variety of operating and plannedunmanned flight projects. For day-to-day operations it relies on email communication between the three Deep Space Communication Complexes (Canberra, Goldstone, Madrid) and NASA's Jet Propulsion Laboratory. The Operations & Administrative Messaging system, based on the Microsoft Windows NTand Exchange platform, provides the infrastructure that is required for reliable, mission-critical messaging. The reliability of this system, however, is threatened by the proliferation of email viruses that continue to spread at alarming rates. A layered approach to email security has been implemented across the DSN to protect against this threat.

IT security antivirus↗

Cybersecurity Operational Research, Experimentation, Innovation, and Integration (COREII)

The Department of Energy’s Cybersecurity, Energy Security, and Emergency Response Office (CESER) has partnered with Idaho National Laboratory (INL) and energy companies to develop COREII. This research initiative aims to align with the national cybersecurity strategy, enhance the resilience of critical energy infrastructure, facilitate efforts to improve grid-enhancing technologies (GET) and major effects from other critical and emerging technologies, and to enable discovery of innovative solutions for emerging cybersecurity challenges

99 GENERAL AND MISCELLANEOUS↗

AOI-2, A Novel Access Control Blockchain Paradigm for Cybersecure Sensor Infrastructure in Fossil Power Generation Systems

Fossil power generation systems are increasingly vulnerable to attack from both cybercriminals as well as internal threats. These vulnerabilities demand that emerging technologies such as blockchains be utilized to secure the data involved in the information flows within the Supervisory Control and Data Acquisition (SCADA) systems of the fossil power generation plants. The publicly accessible blockchain protocols, although secure, are visible to everyone. Even private blockchains currently are unable to support different levels of access to different participants, which is a critical requirement for the existing SCADA systems running the power plants. In light of the above, novel blockchain protocols that are specifically adapted to fossil power generation environments need to be developed in order to achieve the goal of cybersecure sensor networks. In this work, we address this question by creating a novel blockchain technology, namely smart private ledger, for cybersecure communication within the fossil power generation systems. A lab-scale sensor network consisting of strain and temperature sensors is constructed to develop the ledger. The technology has hierarchical access control which is compatible with the existing SCADA systems in fossil power plants. The sensor data is used with cryptographic digital signatures and secret sharing protocols within the nodes of the blockchain technology. The research results will lead to cybersecurity for machine-to-machine interactions, infrastructure for secure data logging for sensors, decentralized data storage, and second-layer technologies for high volume machine-to-machine interactions in the power plants. The work aims to largely address the concerns for the security of distributed sensor networks in such systems that can be compromised by insider threats and by cybercriminals. The research has led to the training of the next generation of engineers and scientists in the important areas of sensor engineering and blockchain technology.

01 COAL, LIGNITE, AND PEAT↗

Leveraging graph clustering techniques for cyber‐physical system analysis to enhance disturbance characterisation

Abstract Cyber‐physical systems have behaviour that crosses domain boundaries during events such as planned operational changes and malicious disturbances. Traditionally, the cyber and physical systems are monitored separately and use very different toolsets and analysis paradigms. The security and privacy of these cyber‐physical systems requires improved understanding of the combined cyber‐physical system behaviour and methods for holistic analysis. Therefore, the authors propose leveraging clustering techniques on cyber‐physical data from smart grid systems to analyse differences and similarities in behaviour during cyber‐, physical‐, and cyber‐physical disturbances. Since clustering methods are commonly used in data science to examine statistical similarities in order to sort large datasets, these algorithms can assist in identifying useful relationships in cyber‐physical systems. Through this analysis, deeper insights can be shared with decision‐makers on what cyber and physical components are strongly or weakly linked, what cyber‐physical pathways are most traversed, and the criticality of certain cyber‐physical nodes or edges. This paper presents several types of clustering methods for cyber‐physical graphs of smart grid systems and their application in assessing different types of disturbances for informing cyber‐physical situational awareness. The collection of these clustering techniques provide a foundational basis for cyber‐physical graph interdependency analysis.

97 MATHEMATICS AND COMPUTING↗

Companion Assisted Software Based Remote Attestation in SCADA Networks

Critical infrastructure such as power generation and water distribution systems have become a priority target in cyber warfare because of their recent computerization and introduction to the internet. As a result, Supervisory Control and Data Acquisition (SCADA) system security has become a hot topic in academic and industrial research. Among these topics, Remote Attestation is a security method intended to detect the presence of fileless malware in remote devices as they continue to operate. This allows for the detection of malware in the absence of long-term storage artifacts before symptoms of compromise begin to appear. In general, a trusted device (the verifier) makes a request for evidence of innocence from the untrusted device (the prover). In software-based schemes, the verifier can then measure the delay between its request and the prover’s response. If this delay is greater than the known computational time of the evidence gathering algorithm performed by the prover, then evidence may have been forged. Multi-hop networks often introduce too much network jitter to allow accurate measurement of prover response time, which limits the effectiveness of software based Remote Attestation in a real-world setting. In this work, we introduce a companion device that the verifier can trust to perform a subset of attestation, thereby removing any network jitter. This device is a Field Programmable Gate Array (FPGA) that is physically connected to the prover. We provide a communication protocol between the verifier, prover, and companion. To evaluate our scheme, we simulate it in a common SCADA network environment under normal and heavy traffic loads. Our simulations are performed in the discrete event network simulator NS-3, and we perform statistical analysis over our results to show that our scheme allows for tight timing constraints to be placed on the prover such that the verifier can more easily determine the validity of the evidence that it receives.

Johnson, William A.↗

Building Blocks for Secure and Prosperous Defense Critical Supply Chains: A Case Study from Microelectronics

Securing defense-critical supply chains, built on resilient and sustainable microelectronics fabrication and deployment, is a national imperative and one that requires an investment in basic and applied research, development, and deployment into industries in (and out of) the Defense Industrial Base (DIB). Critical next steps include the development of pilots for revolutionary concepts in a new formal verification model and the Cyber-Physical Passport (CPP) concept for chain of custody. Critical infrastructure leadership should take action with a sense of urgency. Working in conjunction with the Under Secretary for Acquisition and Sustainment, the Assistant Secretary of Defense for Research and Engineering should establish pilot programs with the Defense Advanced Research Projects Agency and the service labs to build and test both concepts in legacy and new system development.. Additionally, the Pentagon may be aware that an existing Manufacturing Innovation Institute is piloting, with the semiconductor industry, cyber innovations to provide verifiable security properties and guarantees of physical functions to build a more cyber secure, resilient and efficient micro-electronics supply chain.

99 GENERAL AND MISCELLANEOUS↗

Enhancing Power Resilience for Remote Communities: A Comprehensive Renewable Energy Solution for Itbayat Island

The island of Itbayat, Philippines, faces significant challenges in maintaining a reliable and resilient power supply due to its current reliance on a vulnerable power distribution system managed by a local electric cooperative. The existing infrastructure, which includes diesel generators and a radial network configuration with some above-ground lines, is highly susceptible to frequent typhoons and adverse weather conditions. These factors, combined with inadequate staffing and high operational costs, result in frequent power outages that disrupt daily life and hinder economic development. This white paper proposes a comprehensive solution to enhance the resilience and reliability of Itbayat's power system by integrating renewable energy sources, specifically solar photovoltaic (PV) systems, battery storage, and a microgrid controller. The proposed solution aims to reduce dependency on diesel fuel, optimize energy use, and provide a sustainable and robust power supply for the island. Key components of the solution include: 1. Solar PV Installation: Deploying solar PV panels to harness abundant solar energy, reducing reliance on diesel fuel. 2. Battery Storage Systems: Installing battery storage to store excess solar energy and ensure a continuous power supply during low solar generation periods. 3. Microgrid Controller: Implementing a microgrid controller to manage and optimize the integration of solar PV, battery storage, and existing diesel generators. The proposed solution addresses several critical issues, including system vulnerability, generator dependency, and operational inefficiencies. By adopting this innovative approach, Itbayat Island can achieve a more resilient, efficient, and sustainable energy infrastructure, ensuring a stable power supply for its residents and enhancing overall energy security.

14 SOLAR ENERGY↗

Bringing Alaska's Carbon Ore, Rare Earth, and Critical Minerals (CORE-CM) into Perspective

The final report outlines the outcomes of the Alaska CORE-CM Program, funded by the U.S. Department of Energy under award DE-FE0032050. Led by the University of Alaska Fairbanks and the Alaska Division of Geological and Geophysical Surveys, with assistance from other organizations, the project assessed Alaska's potential for Carbon Ore, Rare Earth Elements, and Critical Minerals (CORE-CM). Leveraging advanced analytical techniques, the project identified high-potential resource basins, evaluated geochemical and satellite data, and conducted targeted field investigations. Findings revealed promising concentrations of critical minerals in legacy samples and newly collected materials. The project also investigated innovative extraction technologies, including BioExtraction and use of supercritical CO2, which show significant promise for sustainable resource recovery. Additionally, the study explored the reuse of waste streams from active mining operations and coal byproducts such as using alkali-activated coal ash to manufacture concrete. Infrastructure and logistical challenges in Alaska’s remote regions are discussed, alongside strategies to establish a Technology Innovation Center aimed at advancing CORE-CM development in Alaska. The report includes actionable insights to support Alaska’s critical role in securing domestic supplies of essential minerals while addressing economic, environmental, and technological challenges.

01 COAL, LIGNITE, AND PEAT↗