Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Critical Infrastructure Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 217 records · Page 12

Evaluation of IEC 62443 Standard Gaps for Electric Grid Substation Model Use Case

This report presents an evaluation of the IEC 62443 standards in the context of electric grid substations, as part of a collaborative effort among Sandia National Laboratories (SNL), Idaho National Laboratory (INL), and the National Renewable Energy Laboratory (NREL). The primary objective is to assess the applicability of these standards to enhance cybersecurity measures for industrial automation and control systems (IACS) within the energy sector. The evaluation identifies strengths, such as the scalability of security levels and the structured lifecycle guidance provided by IEC 62443. However, it also highlights significant gaps, including limited integration of physical security, insufficient guidance for legacy systems, and challenges in addressing emerging threats like supply chain vulnerabilities. Recommendations for refining the standards are proposed, including the need for tailored guidance for securing legacy systems, integrating physical security with cybersecurity frameworks, and enhancing interoperability across multi-vendor environments. By addressing these gaps, the IEC 62443 standards can be strengthened to ensure comprehensive cybersecurity for electric grid substations, thereby supporting the resilience and reliability of critical energy infrastructure.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Consequence and Resilience Modeling for Chemical Supply Chains

The U.S. chemical sector produces more than 70,000 chemicals that are essential material inputs to critical infrastructure systems, such as the energy, public health, and food and agriculture sectors. Disruptions to the chemical sector can potentially cascade to other dependent sectors, resulting in serious national consequences. To address this concern, the U.S. Department of Homeland Security (DHS) tasked Sandia National Laboratories to develop a predictive consequence modeling and simulation capability for global chemical supply chains. This paper describes that capability , which includes a dynamic supply chain simulation platform called N_ABLE(tm). The paper also presents results from a case study that simulates the consequences of a Gulf Coast hurricane on selected segments of the U.S. chemical sector. The case study identified consequences that include impacted chemical facilities, cascading impacts to other parts of the chemical sector. and estimates of the lengths of chemical shortages and recovery . Overall. these simulation results can DHS prepare for and respond to actual disruptions.

Stamber, Kevin L.↗

A Cryptographic Method for Defense Against MiTM Cyber Attack in the Electricity Grid Supply Chain

Critical infrastructures such as the electricity grid can be severely impacted by cyber-attacks on its supply chain. Hence, having a robust cybersecurity infrastructure and management system for the electricity grid is a high priority. This paper proposes a cyber-security protocol for defense against man-in-the-middle (MiTM) attacks to the supply chain, which uses encryption and cryptographic multi-party authentication. A cyber-physical simulator is utilized to simulate the power system, control system, and security layers. The correctness of the attack modeling and the cryptographic security protocol against this MiTM attack is demonstrated in four different attack scenarios.

Paul, Shuva↗

Cybersecurity Value-at-Risk Framework

As more variable renewable energy sources are added to the grid, the role of hydropower as a reliable baseline and firming resource is growing more critical. However, the U.S hydropower fleet is not fully prepared to face modern issues such as cybersecurity threats. Hydropower accounts for 37% of U.S. utility-scale renewable electricity but is challenged by diverse infrastructure and legacy devices that predate modern security practices. While new cybersecurity solutions cannot simply be added to current hydropower generation and operation technologies, custom cybersecurity assessments can reveal system-specific threats and risk probabilities and identify mitigating enhancements.

cybersecurity valuation methodology↗

Engineering Services in a Mission Critical Environment: Engineering Services - Science and Technology Operations’ Infrastructure Support at Los Alamos National Laboratory

As an engineering team within a facilities-driven organization, Engineering Services – Science and Technology Operations (ES-STO), supports Los Alamos National Laboratory (LANL), playing a pivotal role in the U.S. nuclear stockpile mission. This report outlines ES-STO’s contributions through the installation of crucial systems such as HVAC units, compressors, and scientific specialty equipment, as well as providing expert consultation to optimize laboratory operations. ES-STO’s goal is to ensure that LANL's infrastructure and research facilities are aligned with mission-critical needs, supporting both operational efficiency and safety in the nuclear stockpile management and maintenance. This report discusses the installation processes, ongoing consultations, and the significant impact of our efforts on national security objectives.

42 ENGINEERING↗

Cybersecurity Considerations for Hydrogen Infrastructure in Airport Environments

This report explores key cybersecurity concerns and best practices within environments that serve as reference points for the development of hydrogen fueling infrastructure for aviation. This cybersecurity analysis leverages prior NREL studies: 1) hydrogen fueling station component validation to identify vulnerabilities and failure events documented in physical equipment, and 2) electric aircraft charging infrastructure analysis to explore primary cybersecurity vulnerabilities. It reviews the criticality of digitized technologies in sustaining hydrogen fuel production, storage, and fueling systems, noting cybersecurity concerns that are universal to power systems and industrial control systems in general. In considering cybersecurity vulnerabilities within a future landscape of hydrogen energy for aviation applications, a reference architecture was intended to reveal the points of connection between assets and the potential sensors that are vulnerable to manipulation in the event of compromised access or communication within a SCADA system. A generalized reference architecture can help stakeholders, engineers, or strategists understand connections, criticalities, and standard practices when it comes to designing and planning for new systems. There are several gaps to account for in assessing the future of hydrogen production, storage, and fueling for aviation. Engaging stakeholders, including aircraft manufacturers, electric utilities, site property owners, and local communities, will inform decision-making around site structure, operations, and resources for future hydrogen fueling infrastructure to understand operational needs and cybersecurity awareness. Cybersecurity mitigation strategy must consider physical attack vectors that emerge with the integration of hydrogen systems into existing airport security requirements. The cybersecurity risk assessment contained in this report is an entry point into potential future granular-level analyses to be conducted as part of hazard and risk assessments for safe aviation hydrogen infrastructure, determining how the scale of hydrogen fuel infrastructure for aviation impacts the volume of cyber attack vectors, and what, if any, are the vulnerabilities associated with different types of on-board hydrogen systems. In this nascent development phase, assessing how best to integrate cybersecurity practices into an evolving U.S. aviation landscape provides critical insights into building increased awareness and stakeholder engagement to support a cyber-resilient infrastructure.

08 HYDROGEN↗

Secure, Autonomous, Intelligent Controller for Integrating Distributed Sensor Webs

This paper describes the infrastructure and protocols necessary to enable near-real-time commanding, access to space-based assets, and the secure interoperation between sensor webs owned and controlled by various entities. Select terrestrial and aeronautics-base sensor webs will be used to demonstrate time-critical interoperability between integrated, intelligent sensor webs both terrestrial and between terrestrial and space-based assets. For this work, a Secure, Autonomous, Intelligent Controller and knowledge generation unit is implemented using Virtual Mission Operation Center technology.

Ivancic, William D.↗

Small-Scale Irrigation: Improving Food Security under Changing Climate and Water Resource Conditions in Ethiopia

We develop a new systems modeling tool that integrates knowledge from hydrology, agriculture, and economics to understand the effect of small-scale irrigation on food security and groundwater sustainability in Ethiopia. Irrigation is an effective tool to mitigate climate impacts and improve agricultural yields. Small-scale irrigation, such as decentralized groundwater irrigation, is well suited for developing countries where smallholder farming communities are widely dispersed and can only afford small infrastructure investment. We study the underlying interdependencies between food and water systems in Ethiopia, where small-holder agriculture is the foundation of the nation’s economy and climate variability has led to great challenges to its food security. Our coupled market and crop model with groundwater module captures the interdependencies of climate, water availability (including irrigation), crop yield, farmland allocation, crop production, transport and consumption based on a system approach across multiple spatial scales. We study the implication of small-scale irrigation to Ethiopia’s food security and water resource conditions as a “what-if” question by comparing an irrigation scenario to the calibrated baseline in 2015, a year of significant drought and crop failure over a large portion of Ethiopia. Our model offers fresh insights into geographic disparities in outcomes that are driven by baseline climate variability, soil fertility, and market conditions. In general, we find that small-scale irrigation can potentially improve food security through increases in food consumption, but it requires policy support to direct the increases of production to domestic consumption while maintaining a sustainable groundwater condition. By using Ethiopia as an example, we show the strength of our model to study how water infrastructure resources support critical functions and service in water and food systems.

Zhang, Ying↗

Baylor University Campus-Wide Deep Dive

In January 2020, staff members from the Engagement and Performance Operations Center (EPOC) and the Lonestar Education And Research Network (LEARN) met with researchers and staff at Baylor University for the purpose of a Campus-Wide Deep Dive into research drivers. The goal of this meeting was to help characterize the requirements for five campus research use cases and to enable cyberinfrastructure support staff to better understand the needs of the researchers they support. Profiled scientific use cases included: - Experimental High Energy Physics (HEP) - Proton Computed Tomography (pCT) - Nutrition and Relation to Digestive Microbiome - Baylor University Core Research Facilities - Molecular Quantum-dot Cellular Automata (QCA), and Material Science of Quantum Computing - Modeling and Simulation of Low-Dimensional and Nano-Structured Materials - Computational Fluid Dynamics Material for this event included the written documentation from each of the research areas at Baylor University, documentation about the current state of technology support, and a write-up of the discussion that took place in person. The Case Studies highlighted the ongoing challenges that Baylor University has in supporting a cross-section of established and emerging research use cases. Each Case Study mentioned unique challenges which were summarized into common needs. These included: - Tradeoffs for network/software security, and usability of the resulting infrastructure. Better communication to set expectations and understand realities is required. - Computation use on campus is widespread and healthy. While no major problems were uncovered, upgrades to maintain current usage patterns and encourage growth will be required. - Storage is a critical need for enterprise use cases and research. In particular, a campus wide ‘storage architecture’ to support research use cases (e.g. instruments, data sharing) is required in the 2-5 year time window. - Instrumentation on campus is healthy and expanding. Technology must scale with this in the form of computation and storage. - Working with LEARN to upgrade network capacity (in multiples of 10G, or upgrades to 100G) will be required in the 1-3 year time frame. - Network monitoring and visibility will help to establish external science use cases. - Data sharing via portal systems is not currently a critical need, but growing in scope. EPOC can assist Baylor with options.

99 GENERAL AND MISCELLANEOUS↗

APPLICATION OF MATURITY MODELS FOR EVALUATING CYBERSECURITY PROGRAMS AT NUCLEAR AND RADIOLOGICAL FACILITIES

Maturity models can be used to provide government agencies, industry associations, and organizations operating nuclear facilities with the ability to quickly evaluate the maturity of their cybersecurity programs and identify areas to prioritize for improvement. The Cybersecurity Capability Maturity Model (C2M2) was developed by the U.S. Department of Energy to allow organizations in the energy sector to evaluate the programmatic capabilities of their cybersecurity programs in a consistent manner, communicate programmatic maturity information, prioritize cybersecurity investments in targeted areas of concern, and track how the maturity of their cybersecurity program evolves over time. The C2M2 is designed for use by any critical infrastructure organization regardless of ownership, structure, or size. The C2M2 can be easily fine-tuned to access the maturity of nuclear cybersecurity programs and their application at individual facilities. Built on a foundation of existing cybersecurity standards, frameworks, programs, and initiatives, the model features 10 security domains. Performance in each security domain is characterized using a structured set of cybersecurity practices that represent activities an organization can perform to improve cybersecurity in their domain. Each practice can be quickly evaluated as being either fully, largely, partially, or not implemented. Once practices are evaluated for each security domain, the model defines four maturity indicator levels that apply independently to each domain in the model. To earn a maturity level in a given domain, an organization must adequately perform all the practices for that maturity level and its predecessor level(s). A small assessment team can conduct a C2M2 assessment in a single day. A screening version of the C2M2 allows an initial look at the maturity of nuclear cybersecurity programs that could be completed in under an hour.

Cyber security, Nuclear security, maturity model↗

Engineering Against Digital Risk in CIP Applications: Cyber-Informed Engineering Use Cases

Cyber-Informed Engineering (CIE) addresses the reality that cyber attacks on engineered systems can have consequences far beyond data loss or disruption of digital networks. When control systems are compromised, safety, reliability, and performance of the physical process itself may be threatened. This presentation discusses engineered controls of 7 categories and the CIE database of controls that provides clear examples and guidance for defining and applying engineered controls in CIE. It explains what engineered controls are, how they differ from information security measures, and how they are integrated into system design.

99 - GENERAL AND MISCELLANEOUS↗

Primer: Physical Factors of Agricultural Production & Climate Change

This white paper is a primer on physical factors that influence agricultural production and associated touchpoints to climate change. Agricultural production (which includes both crop and livestock production) is critical for food security and supports other economic products, such as textiles and generation of fuels for energy. Various physical factors influence agricultural production, including the crop types being cultivated and livestock being raised; land area and quality; water access and control; fertilizers, pesticides, and antibiotics; labor; and infrastructure associated with processing, storage, and transportation. These factors are impacted by climate change in both chronic and acute ways, from changing temperatures and precipitation patterns to increased prevalence of extreme events and diseases. We draw on examples from around the world to show the complex ways that agricultural production factors and climate interact with local capacities to influence regions around the world.

54 ENVIRONMENTAL SCIENCES↗

Best Practices for Resilience Hub Development and Management

The Carbon League and its community partners in East St. Louis, Illinois, have identified five facilities to serve as resilience hubs. These hubs are intended to support the local community through a range of services and resources during blue-sky (everyday), gray-sky (pre-event), and black-sky (emergency) conditions. Transforming these facilities into fully functional resilience hubs requires a broad operational improvement and programmatic planning roadmap. This memo outlines best practices to guide the development of these resilience hubs in East St. Louis, including recommendations for infrastructure services; safety and physical protection; community services; operational protocols; and a phased implementation strategy aligned with realistic funding and capacity constraints. Infrastructure recommendations include strengthening electric power, communications, water, sanitation, and transportation/logistics capabilities, all of which are essential for hubs that may serve as cooling and warming centers, distribution points, and information hubs during emergencies. Safety recommendations focus on accessibility, emergency action planning, indoor air quality, and secure storage of critical equipment. A phased roadmap provides guidance from immediate, low-cost readiness actions to long-term optimization and community integration. Performance metrics and maintenance protocols ensure continuous improvement and operational readiness. This guidance draws on best practices that can be used to support the development of resilient, community-centered hubs capable of enhancing public safety, health, and well-being during everyday operations and emergencies alike.

99 GENERAL AND MISCELLANEOUS↗

Detection, Localization, and Tracking of Unauthorized UAS and Jammers

Small unmanned aircraft systems (UASs) are expected to take major roles in future smart cities, for example, by delivering goods and merchandise, potentially serving as mobile hot spots for broadband wireless access, and maintaining surveillance and security. Although they can be used for the betterment of the society, they can also be used by malicious entities to conduct physical and cyber attacks to infrastructure, private/public property, and people. Even for legitimate use-cases of small UASs, air traffic management (ATM) for UASs becomes of critical importance for maintaining safe and collusion-free operation. Therefore, various ways to detect, track, and interdict potentially unauthorized drones carries critical importance for surveillance and ATM applications. In this paper, we will review techniques that rely on ambient radio frequency signals (emitted from UASs), radars, acoustic sensors, and computer vision techniques for detection of malicious UASs. We will present some early experimental and simulation results on radar-based range estimation of UASs, and receding horizon tracking of UASs. Subsequently, we will overview common techniques that are considered for interdiction of UASs.

surveillance↗

Digital Assurance Checklist for Homeowners and Installers

This document provides a comprehensive Digital Assurance Checklist for securing behind-the-meter energy assets, focusing on both installers and homeowners. As distributed energy resources (DERs) such as solar PV and battery storage become integral to residential energy systems, cybersecurity emerges as a critical component of reliability and safety. The guide outlines actionable steps for installers during pre-installation, commissioning, and post-installation phases, emphasizing practices like network segmentation, credential management, firmware validation, and homeowner education. For homeowners, the document introduces a tiered approach to cyber hygiene—from essential measures like strong Wi-Fi credentials and automatic updates to advanced strategies such as network segmentation, DNS filtering, and intrusion detection. By adopting these practices, stakeholders can mitigate cyber risks, safeguard energy infrastructure, and ensure resilient, secure operation of DER systems. Additional resources and references to industry standards are included to support implementation.

99 - GENERAL AND MISCELLANEOUS↗

Digital Assurance Checklist for Homeowners and Installers

This document provides a comprehensive Digital Assurance Checklist for securing behind-the-meter energy assets, focusing on both installers and homeowners. As distributed energy resources (DERs) such as solar PV and battery storage become integral to residential energy systems, cybersecurity emerges as a critical component of reliability and safety. The guide outlines actionable steps for installers during pre-installation, commissioning, and post-installation phases, emphasizing practices like network segmentation, credential management, firmware validation, and homeowner education. For homeowners, the document introduces a tiered approach to cyber hygiene—from essential measures like strong Wi-Fi credentials and automatic updates to advanced strategies such as network segmentation, DNS filtering, and intrusion detection. By adopting these practices, stakeholders can mitigate cyber risks, safeguard energy infrastructure, and ensure resilient, secure operation of DER systems. Additional resources and references to industry standards are included to support implementation.

99 - GENERAL AND MISCELLANEOUS↗

An Alternative Timing and Synchronization Approach for Situational Awareness and Predictive Analytics

Accurate and synchronized timing information is required by power system operators for controlling the grid infrastructure (relays, Phasor Measurement Units (PMUs), etc.) and determining asset positions. Satellite-based global positioning system (GPS) is the primary source of timing information. However, GPS disruptions today (both intentional and unintentional) can significantly compromise the reliability and security of our electric grids. A robust alternate source for accurate timing is critical to serve both as a deterrent against malicious attacks and as a redundant system in enhancing the resilience against extreme events that could disrupt the GPS network. To achieve this, we rely on the highly accurate, terrestrial atomic clock-based network for alternative timing and synchronization. In this paper, we discuss an experimental setup for an alternative timing approach. The data obtained from this experimental setup is continuously monitored and analyzed using various time deviation metrics. We also use these metrics to compute deviations of our clock with respect to the National Institute of Standards and Technologys (NIST) GPS data. The results obtained from these metric computations are elaborately discussed. Finally, we discuss the integration of the procedures involved, like real-time data ingestion, metric computation, and result visualization, in a novel microservices-based architecture for situational awareness.

Chinthavali, Supriya↗

Next generation experimental data access at NSLS-II

The NSLS-II network and computing infrastructure has been significantly updated recently. The re-IP process in 2020-2021 enabled the NSLS-II network to be routable to the rest of the BNL campus. Then, standardization of the operating systems and deployment procedures helped to deliver a consistent environment to workstations and servers used by all NSLS-II beamlines. In particular, the RedHat Enterprise Linux 8 was deployed to 700+ machines using the RedHat Satellite infrastructure management product, and all critical services (IOCs, databases, etc.) were migrated to the new OS. NFS users’ home directories are consistent across all of the machines, which eliminates the need for the individual configuration of the user environment on each host. The standard suite of software packages is available to the beamline staff and users, which includes the system packages (deployed via RPM) as well as the conda environments for data acquisition and analysis. Security measures were implemented to comply with the industry standards, which include multi-factor authentication (using Duo), secure screen lock for the beamline machines, and advanced access control to the experimental data that is stored in shared central storage available on all hosts. These major enhancements facilitated sharing the experimental data (currently for a number of selected beamlines, with a plan to extend it to the whole facility in the nearest future) with the users via an externally facing JupyterHub instance. The beamlines keep using the Bluesky data acquisition framework to orchestrate their experiments, and the new infrastructure enabled them to use a next-generation data access library called tiled.

36 MATERIALS SCIENCE↗