Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Authentication”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 217 records · Page 12

Modular Security Apparatus for Managing Distributed Cryptography for Command-and-Control Messages on Operational Technology Networks (Module-OT)

Module-OT is a bump- in- the- wire solution acting as a secure conduit for data between devices or systems across a network. Using the latest in open-source cryptographic libraries, all defined communications undergo authentication, authorization, and encryption. The core system can be easily installed through industry standard processes, and the use of popular open-source packages allows for it to be customizable customized by the developer community or deployed in unique embedded environments.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Cybersecurity Threat Profile for a Connected Lighting System

In this paper we analyze a threat profile performed on a fault-detection use case for streetlights. A threat profile establishes security requirements, justifies security measures, yields actionable controls, and effectively communicates risk to stakeholders. This effort provides critical information for making threat-based decisions to increase security at a reasonable cost, and can effectively be used by development teams, software architects, and managers to make cybersecurity a part of their ongoing culture of awareness, training, and prevention. This leads to more secure systems and better-understood security. On-premise, cloud, and hybrid architectures with different authentication mechanisms were modeled and later categorized using the Microsoft STRIDE framework. An analysis of the recommended controls for each threat was performed to determine which controls could and should be put in place by manufacturers or third-party suppliers, and which controls need to be left up the end-user to implement.

97 MATHEMATICS AND COMPUTING↗

Assessment of the Electrical Substation-Grid Testbed with Inside/Outside Devices and Distributed Ledger Technology

The electrical substation-grid testbed was created to integrate the GOOSE and/or DNP (Distributed Network Protocol) messages with time synchronized sources and Distributed Ledger Technology (DLT). The objective was to study the impact of faults and cyber-events at an electrical substation with inside (protective relays) and outside (power meters) substation devices. The electrical substation-grid testbed was based on the design of a 34.5/ 12.47 kV electrical substation (sectionalized bus configuration) with two power transformers, connected to radial power lines and load feeders. The electrical substation-grid testbed was installed at 252 lab space (Advanced Power System Protection), Grid Research Integration and Deployment Center (GRID-C), Oak Ridge National Laboratory. This testbed was created for Task 5, DarkNet project. The electrical substation-grid testbed was created to simulate fault and/or cyber events that could potentially result in damage to the electrical infrastructure. In addition, tests were run that are usually not allowed to be performed in an operational electrical power grid, because these test scenarios could trip breakers and/or generate fault situations that could potentially damage equipment. The number of tests performed in the electrical substation-grid testbed were executed in a better way than in a real electrical substation and/or power grid, because multiple tests could be run in a short period of time, and complex permits, and safety/ schedule restrictions like in a real electrical substation environment were not needed. The electrical substation-grid testbed was created using real measurement, communication, and protection devices that are used by electrical utilities, to have same conditions that we could observe in a real power grid or electrical substation. The electrical substation-grid testbed was based on using a real time simulator and expansion box with amplifiers that were wired to electrical substation-grid devices. This hardware-in-the-loop (HIL) was provided by protective relays, power meters, ethernet switches, remote terminal units, synchronized timing network clock, DLT devices, workstations, and servers. This report includes the design, installation, and assessment of the electrical substation-grid testbed that was similar to an operational electrical substation, integrating the power system protection, communication, and control systems. The results for the electrical substation-grid testbed were based on:• verifying the analog signals for protective relays and power meters, • observing the synchronized time source frame at devices, • authenticating the GOOSE (IEC 61850) and DNP messages from power meters and protective relays, and • verifying the trip conditions of protective relays at fault tests with the power system fault event detection, using DLT devices. For future work, the electrical substation-grid testbed with protective relays and power meters, using DLT and synchronized time source from DarkNet, will be used to study the impact of cyber-events at inside and outside substation devices. Advanced algorithms for detecting cyber-events produced by non-desired protective relay settings will be studied, to improve the detection and reliability of protection, control, and communication systems at power grids.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Step Toward Working with Untrusted Ground Stations

We are witnessing a shift toward outsourcing satellite and ground station services to third-party commercial entities. As with any enterprise, these third parties can be vulnerable to cyber compromise, including image tampering and deepfake injection. The multimedia community is beginning to establish standards and technology to enable authenticity verification of multimedia created and edited by others. While appealing to the remote sensing domain, the nature of raw satellite imagery is incompatible with the proposed change verification tools, resulting in the need for a means to validate updates made to image products. We present a simple method for verifying a specific class of algorithms. Our inverse processing approach eliminates the need to see the original image as the reversed data can be checked against an original digital signature. We demonstrate our approach on basic image restoration routines and conclude with a discussion on open challenges and next steps.

97 MATHEMATICS AND COMPUTING↗

CTAP REPORT. Commercialization of Power Spectrum Analysis (PSA) Technology

Power Spectrum Analysis (PSA) is a Sandia-developed, non-intrusive, electrical technique that captures distinct frequency-domain signatures of microelectronics devices using an innovative, unconventional biasing scheme (off-normal biasing). PSA can identify subtle differences in devices and is applicable in various areas such as device screening, counterfeit identification, reliability assurance, and trust authentication. From October 2020 to April 2021, Sandia worked with entrepreneurs from a new start-up company, Chiplytics, to commercialize PSA technology through NNSA-sponsored FedTech Program. In September 2021, Sandia received funding through Covid-19 Technical Assistance Program (CTAP) to provide technical assistance to Chiplytics for commercialization. Under the CTAP Statement of Work, Sandia was tasked with providing technical assistance to Chiplytics in PSA pilot testing for Naval Surface Warfare Center (NSWC) at Crane and other pilot participants. Sandia was also tasked with assisting Chiplytics in hardware development and evaluation of Chiplytics prototype system.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Artificial Intelligence for Accelerating Nuclear Applications, Science, and Technology

Artificial intelligence (AI) and machine learning (ML) methods have had significant impacts in science and technology in recent years. These methods for generating models from datasets or logic-based algorithms that emulate aspects of human performance can similarly accelerate the fields of nuclear applications, science, and technology toward the IAEA goals of contributing to peace, health, and prosperity. In order to accomplish advances with AI in general and ML in particular across these fields, IAEA can play a significant role by establishing, hosting and curating centralised resources, including databases, adhering to FAIR (findable, accessible, interoperable and reusable) principles and Open Science best practices, providing stewardship of data sharing, supporting training efforts and development of relevant workforces, as well as enabling connections among the scientific, technology, mathematics, AI and ethics communities. Many areas can benefit from the use of AI in the realm of nuclear applications. In human health, these areas include clinical research, epidemiology, nutrition, medical imaging, radiotherapy and education of health professionals. AI-based tools are also being used to facilitate different clinical tasks in imaging, computer-assisted diagnosis in mammography and lung cancer screening programmes, and dose prediction in nuclear medicine procedures. ML methods in particular may also increase the efficiency and accuracy of the analysis of computerised tomography and dual-energy absorptiometry scans for body composition and bone analysis. The application of AI methods to nuclear and related technologies in food and agriculture can lead to significant advances and improved efficiency in the optimisation of agricultural production, food product development, management of supply chains, food safety and food authenticity control. In the water and environmental sector, AI can help inform policies to mitigate the world’s water problems. The application of AI techniques to hydrology and environmental sciences is expected to improve patterns identification and enable model predictions under a changing climate.

73 NUCLEAR PHYSICS AND RADIATION PHYSICS↗

Secure Data Logging and Processing with Blockchain and Machine Learning (Final Report)

Secure Data Logging and Processing with Blockchain and Machine Learning (ML) research is focused on the development of a platform to securely log and process sensor data in fossil power plants. The platform integrates two emerging technologies, blockchain and ML, and incorporates several innovative mechanisms to ensure the integrity, reliability, and resiliency of power systems. The goal is to protect the power plant from various cyberattacks such as false data injection and denial of service attacks using these technologies. The research goal was enabled by the following Research Project Objectives: 1) Secure authentication and identity verification of sensor nodes, actuators, and other equipment within a network. 2) Development of mechanisms that ensure only data sent by legitimate sensors are accepted and stored in the data repository. 3) Development of data aggregation methodologies using ML / Deep Learning (DL) algorithms to minimize noise / faulty data. 4) Implementation of the blockchain technologies to provide data security using secured IOTA framework & nodes.

20 FOSSIL-FUELED POWER PLANTS↗

Cyber and Physical Security Analysis of GSI and Noventum Application for IoT Communications

We present our findings of the red team exercise conducted on the device and application developed by Guardian Sensors, Inc. (GSI) and Noventum. The app is used for situational awareness and control of photovoltaics (PV) and microgrid energy systems. The assessments performed are practical case scenarios that assess the risks and vulnerabilities posed by the app through targeted activities that could be engaged by an adversary. The assessment team’s results and recommendations are provided to inform on and mitigate the identified weaknesses to improve secure user authentication, connections, and communications. The recommendations in this report are not intended to be a security panacea but will add the desired defense-in-depth layer to securing communication of such interconnected systems.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Evaluating Named Data Networking for Industrial Control System [Slides]

Current proposed work is: See if the inherent security that comes with Named Networking (NDN) can be applied to Industrial Control Systems; and, Every packet is required to be cryptographically signed which makes every single piece of data communicated in the system secure and authenticated.

42 ENGINEERING↗

Advanced Algorithms for Scrutiny of Mandatory State Reports Declarations to the IAEA (Final Project Report)

In compliance with their Comprehensive Safeguards Agreements, based on INFCIRC/153 (corrected) (International Atomic Energy Agency, 1972), States Party to the Treaty on the NonProliferation of Nuclear Weapons (NPT) are obligated to declare to the International Atomic Energy Agency (IAEA) all changes in their nuclear material inventory as well as movement of the material across boundaries of IAEA recognized material balance areas (MBA), inventories and nuclear material balances. This project addresses capabilities to detect irregularities in State reports, thus ensuring their accuracy and completeness, and in the broader context, States’ compliance with safeguards obligations of the NPT. A recent study (Henzl et al., 2022) (lead by this project’s PI) demonstrated how analysis of dynamic correlations in nuclear material movement within the entire fuel cycle of a State (viewed as a single system) can reveal variances consistent with and indicative of “irregular” activities. Expanding on this concept, novel ways to analyze State declarations themselves—again, for the State as a whole entity—will help the IAEA draw accurate safeguards conclusions and trust the validity and authenticity of Stategenerated declaration reports. Introducing new declaration analyses capabilities explored in this project will help to provide credible assurance of both the non-diversion of nuclear material from declared activities and of the absence of undeclared nuclear material and activities in the State in general.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

The New GlideinWMS Credentials Model and the New Challenges It Presents

The new credentials implementation of GlideinWMS and the recent migration from Grid Proxies to SciTokens presents new challenges in how we handle credentials and authenticate with grid resources. This presentation summarizes the features of the new model and explains the challenges we will have to address moving forward.

72 PHYSICS OF ELEMENTARY PARTICLES AND FIELDS↗

The Synchronic Web

The Synchronic Web is a distributed network for securing data provenance on the World Wide Web. By enabling clients around the world to freely commit digital information into a single shared view of history, it provides a foundational basis of truth on which to build decentralized and scalable trust across the Internet. Its core cryptographical capability allows mutually distrusting parties to create and verify statements of the following form: “I commit to this information—and only this information—at this moment in time.” The backbone of the Synchronic Web infrastructure is a simple, small, and semantic-free blockchain that is accessible to any Internet-enabled entity. The infrastructure is maintained by a permissioned network of well-known servers, called notaries, and accessed by a permissionless group of clients, called journals. Through an evolving stack of flexible and composable semantic specifications, the parties cooperate to generate synchronic commitments over arbitrary data. When integrated with existing infrastructures, adapted to diverse domains, and scaled across the breadth of cyberspace, the Synchronic Web provides a ubiquitous mechanism to lock the world’s data into unique points in discrete time and digital space. This document provides a technical description of the core Synchronic Web system. The distinguishing innovation in our design—and the enabling mechanism behind the model—is the novel use of verifiable maps to place authenticated content into canonically defined locations off-chain. While concrete specifications and software implementations of the Synchronic Web continue to evolve, the information covered in the body of this document should remain stable. We aim to present this information clearly and concisely for technical non-experts to understand the essential functionality and value proposition of the network. In the interest of promoting discourse, we take some liberty in projecting the potential implications of the new model.

97 MATHEMATICS AND COMPUTING↗

The Design and Evaluation of Zero Trust Architecture for Electric Vehicle Charging Infrastructure: EVs @ Scale Series on EV Charging Station Cybersecurity

Implementing a zero trust architecture can significantly bolster the security of electric vehicle (EV) charging infrastructure. EV charging infrastructure includes numerous networked interfaces, each of which can present potential vulnerabilities. When these vulnerabilities are exploited, they can compromise the entire system, leading to severe operational and security risks. Zero trust is a security model that operates on the principle of "never trust, always verify," which helps manage the attack surface and limit the scope of any potential compromises. Fundamentally, this model ensures that no entity, whether inside or outside the network, is trusted by default. The design principles of zero trust include continuous verification, strict deny-by-default access controls, and micro-segmentation. Continuous verification ensures that every request is thoroughly checked, regardless of its origin. Strict access controls enforce the principle of least privilege, allowing users and devices only the minimum necessary access to perform their functions. Micro-segmentation involves dividing the network into smaller, isolated segments to prevent lateral movement in case of a breach. In the context of EV charging infrastructure, zero trust can be implemented through various strategies. For example, multi-factor authentication (MFA) can be required for engineers to access the management interfaces and control systems of charging stations. Real-time monitoring and analysis of network traffic can help detect and respond to anomalies. Systems that do not need to communicate with each other can be micro-segmented to enhance security. All communications should adhere to predefined policies to be permitted. Additionally, encrypting communications can protect sensitive information exchanged between chargers and management systems. This paper presents a zero trust architecture specifically designed for EV charging infrastructure. Implementing zero trust not only mitigates risks but also builds a resilient infrastructure capable of withstanding and quickly recovering from cyber threats. The architecture addresses six defined security objectives. A comprehensive test plan is developed to assess the architecture against these objectives, and the results of the evaluation are reported. This approach is essential for maintaining the reliability and integrity of EV charging services in an increasingly interconnected and vulnerable digital landscape. This is the first in a planned series of papers exploring the implementation of zero trust in EV charging infrastructure. Each paper will delve into different aspects and applications of zero trust, highlighting how various work processes and requirements can lead to distinct architectural designs. These architectures will be tailored to address specific security challenges and operational needs within the EV charging ecosystem, ensuring a robust and adaptable security framework.

33 ADVANCED PROPULSION SYSTEMS↗

A Managed Tokens Service for Securely Keeping and Distributing Grid Tokens

Fermilab is transitioning authentication and authorization for grid operations to using bearer tokens based on the WLCG Common JWT (JSON Web Token) Profile. One of the functionalities that Fermilab experimenters rely on is the ability to automate batch job submission, which in turn depends on the ability to securely refresh and distribute the necessary credentials to experiment job submit points. Thus, with the transition to using tokens for grid operations, we needed to create a service that would obtain, refresh, and distribute tokens for experimenters’ use. This service would avoid the need for experimenters to be experts in obtaining their own tokens and would better protect the most sensitive long-lived credentials. Further, the service needed to be widely scalable, as we are currently keeping credentials active for approximately 15 experiments, each with 1-3 different credentials, and distributing those credentials to 2-20 submit points per experiment, with those numbers steadily increasing. To address these issues, we created and deployed a Managed Tokens service. The service is written in Go, taking advantage of that language’s native concurrency primitives to easily be able to scale operations as we onboard experiments. The service uses as its first credentials a set of kerberos keytabs, stored on the same secure machine that the Managed Tokens service runs on. These kerberos credentials allow the service to use htgettoken via condor_vault_storer to store vault tokens in the HTCondor credential managers (credds) that run on the batch system scheduler machines (HTCondor schedds); as well as downloading a local, shorter-lived copy of the vault token. The kerberos credentials are then also used to distribute copies of the locally-stored vault tokens to experiment submit points. When experimenters schedule jobs to be submitted, these distributed vault tokens are used to access a Hashicorp Vault instance (run separately from the Managed Tokens service), and previously-stored refresh tokens there are used to obtain the bearer token that is submitted with the job. We will discuss here the design of the Managed Tokens service, including elaborating on certain choices we made with regards to concurrent operations, configuration, monitoring, and deployment.

Bhat, Shreyas↗

Analyzing Risks of Virtual Private Network Connections

The use of Splunk for analyzing VPN logs is an effective approach for identifying vulnerabilities in network endpoints. Splunk, a powerful platform for searching, monitoring, and analyzing machine-generated data, enables organizations to aggregate VPN logs in real-time, providing insights into network activity, user behavior, and potential security risks. By indexing VPN traffic and authentication logs, security teams can track abnormal patterns such as multiple failed login attempts, unusual IP addresses, or unexpected changes in bandwidth usage, all of which could indicate potential vulnerabilities or breaches. With Splunk’s advanced search and reporting capabilities, users can create custom dashboards and alerts to detect suspicious activities. Automated searches can flag endpoints exhibiting unusual behavior, while correlation analysis can identify links between compromised devices and broader network vulnerabilities. In particular, Splunk's machine learning capabilities can be leveraged to predict and prevent threats by identifying trends that might otherwise be missed in traditional log analysis. This proactive approach to monitoring VPN logs allows for the early detection of security weaknesses, enabling rapid response and minimizing potential damage to network integrity. By enhancing endpoint visibility, Splunk plays a crucial role in securing remote connections and safeguarding sensitive information. Additionally, Splunk’s automation and alerting features allow teams to create custom workflows that notify them of vulnerable or misconfigured endpoints identified through Shodan. This synergy between Splunk’s log analysis and Shodan’s device intelligence enhances an organization’s ability to proactively identify and mitigate security risks, improving the overall resilience of their VPN infrastructure.

97 MATHEMATICS AND COMPUTING↗

A Taxonomy and Feature set for Server-Side Identification of Proxies

Malicious actors frequently use proxies and VPNs to evade detection and hide their origin. Current challenges to information security include the use of residential proxies to blend in with normal traffic and Man-in-the-Middle phishing proxies that are used to compromise accounts protected with mult-factor authentication. We advance a taxonomy and feature set for the identification of proxied traffic based on the network layer where proxying occurs. We describe how these features apply to common proxy types and how to use these features in the classification of the proxied traffic. Collection of these additional features is feasible using existing network sensors and web servers, while only adding about 30% volume to commonly deployed network sensor logs.

97 MATHEMATICS AND COMPUTING↗

Enabling Innovative Analysis on Heterogeneous Clusters through HTCdaskgateway

High energy particle (HEP) physics research is going through fundamental changes as we move to collect larger amounts of data from the Large Hadron Collider (LHC). Analysis facilities and distributed computing, through HTCs, have come together to create the next pythonic generation of analysis by utilizing HTCdaskgateway, a Dask gateway extension, allowing users to spawn workers compatible with both their analysis and heterogeneous clusters in line with authentication requirements. This is enabling physicists to engage with scientific python in ways they had not before because of domain specific C++ tools. An example of HTCdaskgateway’s use is Fermilab’s Elastic Analysis Facility.

Chavez, Elise [U. Wisconsin, Madison (main)]↗

Watchmen v3.1.0 Release Notes

This document describes the changes to Watchmen. This includes improvements to stability, search features, display of more detailed sample information and user access via authentication.

97 MATHEMATICS AND COMPUTING↗