Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “network protocols”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 199 records · Page 11

Precursor Analysis Report: Industroyer Targeting Ukraine Electric Power Transport Utility (Ukrenergo) 2016

The Industroyer Targeting Ukraine Electric Power Transport Utility (Ukrenergo) 2016 Precursor Analysis Report leverages publicly available information about the December 2016 cyber attack against the Ukrainian Ukrenergo electric transmission utility and catalogs anomalous observables for each technique employed in the attack. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. Industroyer is a modular malware framework designed to deploy several Industrial Control System (ICS) protocol-specific attack payloads to disrupt electricity distribution. Adversaries deployed Industroyer within the target network on a Microsoft Windows endpoint capable of directly manipulating or communicating with ICS. Industroyer abuses the functionality of a targeted ICS’s legitimate control system to achieve its intended impact. Adversaries likely first gained access to Ukrenergo enterprise networks in early 2016 after a successful spearphishing campaign against organizations in the electric power sector. Adversaries then began capturing credentials beginning on 1 December 2016. This allowed access to the ICS environment at the Pivnichna electric transmission substation outside Kyiv through a device dual-homed on the Information Technology (IT) and ICS networks. Adversaries conducted discovery, targeting, and access to this device using information and previously captured credentials from compromised enterprise IT machines. Finally, the adversaries deployed and launched the Industroyer malware just before midnight on 17 December. By midnight, Ukrenergo had lost control of a targeted substation, resulting in electric power outages for over an hour in the city of Kyiv and the Kyiv region. Researchers and analysts identified 31 unique techniques (used in a sequence of 33 steps) utilized during the attack with a total of 846 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Twenty-nine of the identified techniques used during the Industroyer cyber attack were precursors to the triggering event. Analysis identified 548 observables associated with these precursor techniques, 353 of which were assessed to have an increased likelihood of being perceived in the 300 days preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Centralized and Decentralized Distributed Energy Resource Access Control Implementation Considerations.

A global transition to power grids with high penetrations of renewable energy generation is being driven in part by rapid installations of distributed energy resources (DER). New DER equipment includes standardized IEEE 1547-2018 communication interfaces and proprietary communications capabilities. Interoperable DER provides new monitoring and control capabilities. The existence of multiple entities with different roles and responsibilities within the DER ecosystem makes the Access Control (AC) mechanism necessary. In this paper, we introduce and compare two novel architectures, which provide a Role-Based Access Control (RBAC) service to the DER ecosystem’s entities. Selecting an appropriate RBAC technology is important for the RBAC administrator and users who request DER access authorization. The first architecture is centralized, based on the OpenLDAP, an open source implementation of the Lightweight Directory Access Protocol (LDAP). The second approach is decentralized, based on a private Ethereum blockchain test network, where the RBAC model is stored and efficiently retrieved via the utilization of a single Smart Contract. We have implemented two end-to-end Proofs-of-Concept (PoC), respectively, to offer the RBAC service to the DER entities as web applications. Finally, an evaluation of the two approaches is presented, highlighting the key speed, cost, usability, and security features.

42 ENGINEERING↗

AOI-2, A Novel Access Control Blockchain Paradigm for Cybersecure Sensor Infrastructure in Fossil Power Generation Systems

Fossil power generation systems are increasingly vulnerable to attack from both cybercriminals as well as internal threats. These vulnerabilities demand that emerging technologies such as blockchains be utilized to secure the data involved in the information flows within the Supervisory Control and Data Acquisition (SCADA) systems of the fossil power generation plants. The publicly accessible blockchain protocols, although secure, are visible to everyone. Even private blockchains currently are unable to support different levels of access to different participants, which is a critical requirement for the existing SCADA systems running the power plants. In light of the above, novel blockchain protocols that are specifically adapted to fossil power generation environments need to be developed in order to achieve the goal of cybersecure sensor networks. In this work, we address this question by creating a novel blockchain technology, namely smart private ledger, for cybersecure communication within the fossil power generation systems. A lab-scale sensor network consisting of strain and temperature sensors is constructed to develop the ledger. The technology has hierarchical access control which is compatible with the existing SCADA systems in fossil power plants. The sensor data is used with cryptographic digital signatures and secret sharing protocols within the nodes of the blockchain technology. The research results will lead to cybersecurity for machine-to-machine interactions, infrastructure for secure data logging for sensors, decentralized data storage, and second-layer technologies for high volume machine-to-machine interactions in the power plants. The work aims to largely address the concerns for the security of distributed sensor networks in such systems that can be compromised by insider threats and by cybercriminals. The research has led to the training of the next generation of engineers and scientists in the important areas of sensor engineering and blockchain technology.

01 COAL, LIGNITE, AND PEAT↗

Constant-Overhead Fault-Tolerant Bell-Pair Distillation Using High-Rate Codes

We present a fault-tolerant Bell-pair distillation scheme achieving constant overhead through high-rate quantum low-density parity-check (qLDPC) codes. Our approach maintains a constant distillation rate equal to the code rate while requiring no additional overhead beyond the physical qubits of the code. Full circuit-level analysis demonstrates fault-tolerance for input Bell-pair infidelities below a threshold ∼10%, readily achievable with near-term capabilities. Unlike previous proposals, our scheme keeps the output Bell pairs encoded in qLDPC codes at each node, eliminating unencoding overhead and enabling direct use in distributed quantum applications through recent advances in qLDPC computation. These results establish qLDPC-based distillation as a practical route toward resource-efficient quantum networks and distributed quantum computing.

quantum communication, protocols & technology↗

Less Is More: Oligomer Extraction and Hydrothermal Annealing Increase PDMS Adhesion Forces for Materials Studies and for Biology-Focused Microfluidic Applications

Cues in the micro-environment are key determinants in the emergence of complex cellular morphologies and functions. Primary among these is the presence of neighboring cells that form networks. For high-resolution analysis, it is crucial to develop micro-environments that permit exquisite control of network formation. This is especially true in cell science, tissue engineering, and clinical biology. We introduce a new approach for assembling polydimethylsiloxane (PDMS)-based microfluidic environments that enhances cell network formation and analyses. We report that the combined processes of PDMS solvent-extraction and hydrothermal annealing create unique conditions that produce high-strength bonds between solvent-extracted PDMS (E-PDMS) and glass—properties not associated with conventional PDMS. Extraction followed by hydrothermal annealing removes unbound oligomers, promotes polymer cross-linking, facilitates covalent bond formation with glass, and retains the highest biocompatibility. Herein, our extraction protocol accelerates oligomer removal from 5 to 2 days. Resulting microfluidic platforms are uniquely suited for cell-network studies owing to high adhesion forces, effectively corralling cellular extensions and eliminating harmful oligomers. We demonstrate the simple, simultaneous actuation of multiple microfluidic domains for invoking ATP- and glutamate-induced Ca 2+ signaling in glial-cell networks. These E-PDMS modifications and flow manipulations further enable microfluidic technologies for cell-signaling and network studies as well as novel applications.

36 MATERIALS SCIENCE↗

QUANT-NET Control Plane Framework (QNCP) v1.0.0

The QUANT-NET Control Plane (QNCP) provides a software framework for expressing and managing quantum network resources. It may be used to orchestrate a physical quantum testbed with real device driver implementations, or it may be used as a proving ground when developing new protocols and management functions. In practice, both approaches may be useful when undertaking research and development in emerging quantum testbeds. While a number of control systems have been developed for specific quantum platform demonstrations, an openly available and general solution for operating quantum networks has not emerged. QNCP is designed to fill this gap. The framework has been designed to provide extensible, modular capabilities that include scheduling, routing, monitoring, and pluggable protocols. A number of reference implementations in each module category have been included in the installable packages; however, the intent is that each of these modules may be extended or re-implemented to meet the needs of the particular deployment or research need. The software is currently being used in the QUANT-NET testbed project, which spans resources between LBNL and UC Berkeley Physics.

Zhang, Liang [Lawrence Berkeley National Laborator↗

Local rules for fabricating allosteric networks

Mechanical properties of disordered networks can be significantly tailored by modifying a small fraction of their bonds. This procedure has been used to design and build mechanical metamaterials with a variety of responses. A long-range “allosteric” response, where a localized input strain at one site gives rise to a localized output strain at a distant site, has been of particular interest. This work presents an approach to incorporating allosteric responses in experimental systems by pruning disordered networks in situ. Previous work has relied on computer simulations to design and predict the response of such systems using a cost function where the response of the entire network to each bond removal is used at each step to determine which bond to prune. It is not feasible to follow such a design protocol in experiments where one has access only to local response at each site. This paper presents design algorithms that allow determination of what bonds to prune based purely on the local forces in the network without employing a cost function; using only local information, allosteric networks are designed in simulations and then built out of real materials. The results show that some pruning strategies work better than others when translated into an experimental system. A method is presented to measure local stresses experimentally in disordered networks. This approach is then used to implement pruning methods to design desired responses in situ. Results from these experiments confirm that the pruning methods are robust and work in a real laboratory material.

36 MATERIALS SCIENCE↗

Distributed Detection of Malicious Attacks on Consensus Algorithms with Applications in Power Networks

Consensus-based distributed algorithms are well suited for coordination among agents in a cyber-physical system. These distributed schemes, however, suffer from their vulnerability to cyber attacks that are aimed at manipulating data and control ow. In this article, we present a novel distributed method for detecting the presence of such intrusions for a distributed multi-agent system following ratio consensus. We employ a Max-Min protocol to develop low cost, easy to implement detection strategies where each participating node detects the intrusion independently, eliminating the need for a trusted certifying agent in the network. The effectiveness of the detection method is demonstrated by numerical simulations on a 1000 node network to demonstrate the efficacy and simplicity of implementation.

27 ARPA - Advanced Research Projects Agency-Energy↗

Generation of scalable genuine multipartite Gaussian entanglement with a parametric amplifier network

Genuine multipartite entanglement is a valuable resource in quantum information science, as it exhibits inseparability across all possible bipartitions of a multimode quantum state. The large degree of quantum correlations can be exploited in various quantum information protocols, such as teleportation, dense coding, and quantum interferometry. Here, in this study, we propose a scheme to generate scalable genuine multipartite continuous-variable entangled states of light using a parametric amplifier network. We verify the presence of genuine quadripartite, hexapartite, and octapartite entanglement through a violation of the positive partial transpose criteria. Additionally, we use 𝛼-entanglement of formation to demonstrate the scalability of our approach to an arbitrary number of 2⁢𝑁 genuinely entangled parties by taking advantage of the symmetries present in our scheme.

Kim, Saesun [Univ. of Oklahoma, Norman, OK (United↗

Network traffic control for multi-homed end-hosts via SDN

Software-defined networking (SDN) is an emerging technology of efficiently controlling and managing computer networks, such as in data centres, wide-area networks, as well as in ubiquitous communication. In this study, the authors explore the idea of embedding the SDN components, represented by SDN controller and virtual switch, in end-hosts to improve network performance. In particular, the authors consider load balancing across multiple network interfaces on end-hosts with different link capacity scenarios. The authors have explored and implemented different SDN-based load-balancing approaches based on OpenFlow software switches, and have demonstrated the feasibility and the potential of this approach. The proposed system has been evaluated with MultiPath transmission control protocol (MPTCP). Furthermore, the proposed results demonstrated the potential of applying the SDN concepts on multi-homed devices resulting in an increase in achieved throughput of 55% compared to the legacy single network approach and 10% compared to the MPTCP.

97 MATHEMATICS AND COMPUTING↗

Implementation and Demonstration of P4 Software for Improving ICS Protocol Visibility and Control [Slides]

No prior enabling funded work applicable to this proposal. Programming Protocol-independent Packet Processors (P4) is an open source, domain-specific programming language for network switching devices. P4 complements traditional Software Defined Networking (SDN) which is primarily concerned with the management of packets (e.g. routing/dropping decisions) rather than how each packet is processed. The introduction of P4 provided new capabilities (e.g. firewall, load balancing, enhanced security) but has primarily been deployed in data centers. This effort investigates ways to expand P4 into other niches such as ICS networks.

97 MATHEMATICS AND COMPUTING↗

Power and Communications Hardware-in-the-Loop CPS Architecture and Platform for DER Monitoring and Control Applications: Preprint

The rapid growth of distributed energy resources (DERs) has prompted increasing interest in the monitoring and control of DERs through hybrid smart grid communications. The deployment of communications and computation has transformed the traditional physical power grid into a smart cyber-physical system (CPS). To fully understand the interdependency between physical grid and cyber netowrks, this study designed a power and communications hardware-in-the-loop (PCommHIL) CPS architecture, which enables the flexible verification of DER monitoring and control with hybrid communications architectures and Internet protocols. Design, development and case study of a PCommHIL testbed for the DER coordination are discussed in detail, and the proposed platform integrates DER devices, Advanced Metering Infrastructures (AMIs), and a suite of hybrid communications networks for distribution automation applications. Case study on DER situational awareness and Volt-Var control validates the efficacy of this proposed PCommHIL platform with hybrid communications designs. Results show that the HAN communication technologies play a critical role in hybrid designs and it is the bottleneck for DER applications. High performance communication technologies are highly recommended to be applied in the HAN for enhanced monitoring and real-time control of DERs.

AMIs↗

Integrating 5G Technology for Improved Process Monitoring and Network Slicing in ICS

Industrial Control Systems (ICS) are crucial for monitoring physical processes that support essential cyber-enabled services like power generation. The use of proprietary communication and lack of effective intrusion detection mechanisms pose constraints for efficient operation. Therefore, there is a need to modernize these systems with decentralized technologies like Edge Computing and 5G. However, integrating 5G and Edge Computing into large-scale ICS networks presents implementation and performance challenges. To address these challenges, this paper proposes an integrated ICS architecture that combines 5G and Edge Computing technologies with traditional ICS protocols. The objective is to minimize implementation and operational difficulties while improving the monitoring of physical processes and enabling robust intrusion detection. The proposed architecture outlines the necessary components, services, and communication protocols required for the integration of 5G and Edge Computing.

Aguayo, Jared M.↗

Entanglement Traffic Engineering in Quantum Optical Fiber Networks based on High-Dimensional Kerr Optical Frequency Combs

The purpose of the project was to explore the performance of entanglement protocols based on microresonator Kerr optical frequency combs. We have addressed these challenges by developing a rigorous frequency-bin approach that allowed us to determine an explicit steady-state density operator for quantum microcombs below threshold. Our novel approach has allowed us to derived an explicit formula for the density operator on the frequency-bin basis, and to propose a complete description of quantum Kerr combs regardless of the number of sidemodes or loss-induced coupling to the environment. This formalism also allows for the explicit determination of their fidelity, purity, and entropy. These results are expected to permit the exploitation of the full potential of entangled microcombs for quantum technology.

42 ENGINEERING↗

Artificial Diversity and Defense Security (ADDSec)

Artificial Diversity and Defense Security (ADDSec) machine learning algorithms are used to classify and cluster threats so that an appropriate response can be initiated as a mitigation strategy. The package includes an ensemble of machine learning algorithms such as Support Vector Machines, naïve bayes, logistic regression, and random forest that evolve with the data to recognize anomalous behavior at the host and network levels. Inputs into the machine learning algorithms include end host system calls, system utilization, packet captures, and syslog messages. The machine learning algorithms can be retrained based on user defined intervals or on the number of packets received. ADDSEC's threat responses include Internet Protocol (IP) Address randomization, application port number randomization, and application library randomization. The IP randomization implementation is built on top of a Software Defined Networking (SDN) framework. The SDN controller installs flows on each of the SDN switches with randomized source and destination IP addresses. The application port numbers are randomized using iptables. The application library randomization is created with a LLVM compiler. All randomization schemes are transparent to the endpoints on the network. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525. SAND2021-3379 O

Cox, RebeccaE.↗

Deep compressed seismic learning for fast location and moment tensor inferences with natural and induced seismicity

Fast detection and characterization of seismic sources is crucial for decision-making and warning systems that monitor natural and induced seismicity. However, besides the laying out of ever denser monitoring networks of seismic instruments, the incorporation of new sensor technologies such as Distributed Acoustic Sensing (DAS) further challenges our processing capabilities to deliver short turnaround answers from seismic monitoring. In response, this work describes a methodology for the learning of the seismological parameters: location and moment tensor from compressed seismic records. In this method, data dimensionality is reduced by applying a general encoding protocol derived from the principles of compressive sensing. The data in compressed form is then fed directly to a convolutional neural network that outputs fast predictions of the seismic source parameters. Thus, the proposed methodology can not only expedite data transmission from the field to the processing center, but also remove the decompression overhead that would be required for the application of traditional processing methods. An autoencoder is also explored as an equivalent alternative to perform the same job. We observe that the CS-based compression requires only a fraction of the computing power, time, data and expertise required to design and train an autoencoder to perform the same task. Implementation of the CS-method with a continuous flow of data together with generalization of the principles to other applications such as classification are also discussed.

54 ENVIRONMENTAL SCIENCES↗

A Proxy Signature-Based Drone Authentication in 5G D2D Networks

5G is the beginning of a new era in cellular communication, bringing up a highly connected network with the incorporation of the Internet of Things (IoT). To flexibly operate all the IoT devices over a cellular network, Device-toDevice (D2D) communication standard was developed. However, IoT devices such as drones utilizing 5G D2D services could be a perfect target for malicious attacks as they pose several safety threats if they are compromised. Furthermore, there will be heavy traffic with an increased number of IoT devices connected to the 5G core. Therefore, we propose a lightweight, fast, and reliable authentication mechanism compatible with the 5G D2D ProSe standard mechanisms. Specifically, we propose a distributed authentication with a delegation-based scheme instead of the repeated access to the 5G core network key management functions. Hence, a legitimate drone is authorized by the core network via offering a proxy signature to authenticate itself to other drones. We implemented the proposed protocol in ns-3 that supports 5G D2D-based communication. We also conducted computational calculations on the RaspberryPi3 IoT device to mimic the drone calculation process and delays. The results demonstrate that the proposed protocol is lightweight and reliable

5G security↗

Combining genome-wide association studies and expression quantitative trait nucleotide mapping with molecular and genetic validations to identify transcriptional networks regulating drought tolerance in Populus

Objectives: (i). To deploy a large-scale experimental drought trial for up to 1000 unique genotypes of Populus equipping the sites with controlled irrigation and drought treatments that are fully automated and monitored. FULLY COMPLETED (ii) To test the hypothesis that a suite of traits identified for drought tolerance in P. nigra can be measured in drought and control treatments in the wide germplasm collection of P. trichocarpa. FULLY COMPLETED (iii) To use established and novel GWAS model approaches to identify gene loci linked to drought tolerance traits on interest in P. trichocarpa. FULLY COMPLETED (iv) To undertake comparative analysis of GWAS results for drought tolerance traits in P. nigra and P. trichocarpa. PARTIALLY COMPLETED – remains active (v) Using RNAseq in P. trichocarpa, in droughted and control treatments to identify cis- and trans-regulated eQTN. FULLY COMPLETED (vi) Validate up to 50 cis-QTNs, from network hubs using transient protoplast assays. FULLY COMPLETED (vii) To establish Agrobacterium-based gene editing protocols in Populus. FULLY COMPLETED (viii) To utilize early leads from previous research to investigate at least 6 candidate genes for drought tolerance in Populus. FULLY COMPLETED (ix) To validate up to 20 candidate genes for drought tolerance in P. trichocarpa refined from the long-list tested in the transient assays for cis-acting hub gene targets. PARTIALLY COMPLETED- remains active.

60 APPLIED LIFE SCIENCES↗