Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Secure by Design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 217 records · Page 12

A model of security monitoring

A model of security monitoring is presented that distinguishes between two types of logging and auditing. Implications for the design and use of security monitoring mechanisms are drawn from this model. The usefulness of the model is then demonstrated by analyzing several different monitoring mechanisms.

Bishop, Matt↗

A model of security monitoring

A model of security monitoring is presented that distinguishes between two types of logging and auditing. Implications for the design and use of security monitoring mechanisms are drawn from this model. The usefulness of the model is then demonstrated by analyzing several different monitoring mechanisms.

Bishop, Matt↗

Cyber Threat Assessment Methodology for Autonomous and Remote Operations for Advanced Reactors (Conference Presentation)

The next generation of Advanced Reactors include planned capabilities for both Autonomous (operating without human interaction for a set period-of-time) and Remote (operating with human interaction from a separate physical location) Operations. Existing Nuclear Reactor architectures include a set of safety and security constraints tightly coupled with personnel policies and procedures. As Advanced Reactors are fielded with these new Autonomous and Remote operational capabilities, the architectures and associated infrastructure services and components will perceivably expand the overall attack surface and risk calculations with regards to safe and secure operations. This paper is part of an FY21 work program focused on ensuring Advanced Reactor designs are informed with threat-based guidance on design and operation of Secure Architectures with a specific focus on the deployment of Autonomous Systems in support of Advanced Reactor Operations. The next phase of this research program is to complement produce a methodology for assessment of the cyber threat against these architectures as well as a catalogue of Use Cases to support the Advanced Reactor community in their implementation of Autonomous and Remote Operations.

97 MATHEMATICS AND COMPUTING↗

Reimagining Codesign for Advanced Scientific Computing: Report for the ASCR Workshop on Reimagining Codesign

In March 2021, the U.S. Department of Energy’s Advanced Scientific Computing Research program convened the Workshop on Reimagining Codesign. The workshop, also known as ReCoDe, was organized around discussions on eight topic areas: (1) codesign for traditional high-performance computing workloads; (2) codesign of memory/storage systems; (3) codesign of machine learning, neuromorphic, quantum, and other non-von Neumann accelerators; (4) codesign for edge computing and processing at experimental instruments; (5) codesign for security and privacy; (6) hardware design tools and open-source hardware for high-productivity codesign; (7) tools, software stack, and programming languages for high-productivity codesign; and (8) quantitative tools and data collection for modeling and simulation for codesign. The panels identified four Priority Research Directions from these deliberations: (1) breakthrough computing capabilities with targeted heterogeneity and rapid design; (2) software and applications that embrace radical architecture diversity; (3) engineered security and integrity, from transistors to applications; and (4) design with data-rich processes.

97 MATHEMATICS AND COMPUTING↗

Analyzing the security of an existing computer system

Most work concerning secure computer systems has dealt with the design, verification, and implementation of provably secure computer systems, or has explored ways of making existing computer systems more secure. The problem of locating security holes in existing systems has received considerably less attention; methods generally rely on thought experiments as a critical step in the procedure. The difficulty is that such experiments require that a large amount of information be available in a format that makes correlating the details of various programs straightforward. This paper describes a method of providing such a basis for the thought experiment by writing a special manual for parts of the operating system, system programs, and library subroutines.

Bishop, M.↗

The Impact of Cultural Values and Organizational Processes on Nuclear Security Operations

Human performance is a pivotal factor in the design, testing, maintenance, and operation of security systems. The effectiveness of these systems relies not only on the capabilities, limitations, motives, and attitudes of the individuals involved, but also on the quality of training, instructional content, and evaluation methods provided. To uphold security standards, seamless integration between technologies and operators necessitates reliable human input. In security operations, human errors, often attributed to blame, sanctions, low motivation, individual accountability, or complacency, are primary causes of system failures. Complacency, characterized by a false sense of security, reflects a lack of awareness of potential threats and is a significant contributing factor to lapses in security. Security incidents arise from various factors, many extend beyond individual control, highlighting the need for a holistic approach to human performance that integrates organizational processes and team collaboration. Historically, errors have been attributed to individual moral or cognitive failures. However, insights from Operational Experiences (OEs) suggest that organizational processes weakness and deficiencies in nuclear cultural values contribute more significantly to security failures than individual mistakes. This paper consolidates lessons learned from diverse international nuclear security cultures and aims to highlight the importance of security culture in shaping global perspectives on nuclear security. It underscores the role of cultural values in shaping nuclear security practices and enhancing the resilience of security systems in the nuclear sector.

Zineddin, Dr. Z. [ORNL] (ORCID:0009000848740725)↗

Requirements for a network storage service

Sandia National Laboratories provides a high performance classified computer network as a core capability in support of its mission of nuclear weapons design and engineering, physical sciences research, and energy research and development. The network, locally known as the Internal Secure Network (ISN), was designed in 1989 and comprises multiple distributed local area networks (LAN's) residing in Albuquerque, New Mexico and Livermore, California. The TCP/IP protocol suite is used for inner-node communications. Scientific workstations and mid-range computers, running UNIX-based operating systems, compose most LAN's. One LAN, operated by the Sandia Corporate Computing Directorate, is a general purpose resource providing a supercomputer and a file server to the entire ISN. The current file server on the supercomputer LAN is an implementation of the Common File System (CFS) developed by Los Alamos National Laboratory. Subsequent to the design of the ISN, Sandia reviewed its mass storage requirements and chose to enter into a competitive procurement to replace the existing file server with one more adaptable to a UNIX/TCP/IP environment. The requirements study for the network was the starting point for the requirements study for the new file server. The file server is called the Network Storage Services (NSS) and is requirements are described in this paper. The next section gives an application or functional description of the NSS. The final section adds performance, capacity, and access constraints to the requirements.

Kelly, Suzanne M.↗

IRAD-MPE Radiological and Nuclear Security Threats (Day 1) [Slides]

This module is designed to enhance awareness regarding radiological and nuclear security threats and the types of radioactive materials that can be used for criminal purposes or terrorist acts. The goals are to: (1) Review the Threat Assessment Process for MPEs, (2) Recognize Potential Radiological and Nuclear Security Threats, (3) Understand the basics of Radiological Dispersal Devices (RDD) and Radiological Exposure Devices (RED), (4) Learn about Medical, Commercial, and Naturally Occurring Radioactive Materials (NORM) sources, and (5) Understand the term Material Out of Regulatory Control (MORC).

61 RADIATION PROTECTION AND DOSIMETRY↗

A Four-Layer Cyber-Physical Security Model for Electric Machine Drives Considering Control Information Flow

Despite the IEEE Power Electronics Society (PELS) establishing Technical Committee 10 on Design Methodologies with a focus on the cyber-physical security of power electronics systems, a holistic design methodology for addressing security vulnerabilities remains underdeveloped. This gap largely stems from the limited integration of computer science and power/control engineering studies in this interdisciplinary field. Addressing the inadequacy of unilateral cyber or control perspectives, this article presents a novel four-layer cyber-physical security model specifically designed for electric machine drives. Central to this model is the innovative control information flow (CIF) model, residing within the control layer, which serves as a pivotal link between the cyber layer's vulnerable resources and the physical layer's state-space models. By mapping vulnerable resources to control variable space and tracing attack propagation, the CIF model facilitates accurate impact predictions based on tainted control laws. The effectiveness and validity of this proposed model are demonstrated through hardware experiments involving two typical cyber-attack scenarios, underscoring its potential as a comprehensive framework for multidisciplinary security strategies.

97 MATHEMATICS AND COMPUTING↗

Cyber-Informed Engineering Adoption in University Engineering Programs: An Overview of CIE Integration Successes at Nine U.S. Educational Institutions

This report examines the adoption of Cyber-Informed Engineering (CIE) in university engineering programs, driven by the need to protect critical energy infrastructure from adversarial threats. CIE equips current and future engineers and technicians with the necessary mindset, skills, and competencies to enhance the resilience of engineered systems against cyber attacks. This report highlights nine academic partners who are incorporating CIE into their curricula through various approaches, including lectures, courses, and certificates.

42 ENGINEERING↗

Genomics and Proteomics Based Security Protocols for Secure Network Architectures

A hardware design that integrates live and algorithmic inhabitants to produce patterns of gene expression in vivo and in silico Protocols and algorithms based upon the processes of regulation of gene expression to produce cryptographic representations of genes, RNA, proteins, and gene expression to perform authentication and confidentiality functions for computers and networks. A network concept of operations integrating all of the above into existing legacy networks.

Security Genomics↗

R2U2: Monitoring and Diagnosis of Security Threats for Unmanned Aerial Systems

We present R2U2, a novel framework for runtime monitoring of security properties and diagnosing of security threats on-board Unmanned Aerial Systems (UAS). R2U2, implemented in FPGA hardware, is a real-time, REALIZABLE, RESPONSIVE, UNOBTRUSIVE Unit for security threat detection. R2U2 is designed to continuously monitor inputs from the GPS and the ground control station, sensor readings, actuator outputs, and flight software status. By simultaneously monitoring and performing statistical reasoning, attack patterns and post-attack discrepancies in the UAS behavior can be detected. R2U2 uses runtime observer pairs for linear and metric temporal logics for property monitoring and Bayesian networks for diagnosis of security threats. We discuss the design and implementation that now enables R2U2 to handle security threats and present simulation results of several attack scenarios on the NASA DragonEye UAS.

Formal Methods↗

Securing mechanism for the deployable column of the Hoop/Column antenna

The Column Longeron Latch (CLL) was designed and developed as the securing mechanism for the deployable, telescoping column of the Hoop/Column antenna. The column is an open lattice structure with three longerons as the principal load-bearing members. It is divided into telescoping sections that are deployed after the antenna is place in Earth orbit. The CLL provides a means to automatically lock the longeron sections into position during deployment as well as a means of unlocking the sections when the antenna is to be restowed. The CLL is a four bar linkage mechanism using the over center principle for locking. It utilizes the relative movement of the longeron sections to activate the mechanism during antenna deployment and restowing. The CLL design is one of the first mechanisms developed to meet the restowing requirements of spacecraft which will utilize the STS retrieval capability.

Ahl, E. L., Jr.↗

Universal Utility Data Exchange (UUDEX) Functional Design Requirements - Rev 1

This document provides a set of high-level functional design requirements for Universal Utility Data Exchange (UUDEX). These requirements include a set of use cases, data exchanges supported by UUDEX, both for grid operations and for cyber security data, functional requirements for data exchange, data models used by UUDEX, data exchange architectures, and security considerations. These functional design requirements are intended to be used in more detailed design documents.

97 MATHEMATICS AND COMPUTING↗

Innovation in Radiological Security, Part 1 of 2 – Using a Cloud Solution to Compress the Timely Detection Model

The design and implementation of new security technologies must account for numerous and complex operational challenges. For example, traditionally isolated systems must now survive amid the proliferation of network connectivity and endure the dynamic environments created by organizations tolerating bring-your-own-device policies. When evaluating the cyber, physical, or cyber-physical security of an asset, a common practice in the security industry is to apply the Timely Detection Model (TDM)—a versatile concept that relates the security functions of detection, delay, and response to the progression of an oppositional force’s attack timeline. If implemented correctly, security enhancements can compress the TDM to offer efficiencies to the stakeholders responsible for adjudicating threat scenarios. The efficiencies gained by the response force allow for more effective protection strategies to be realized. One such enhancement, deployed within the radiological security domain—the Sentry-Remote Monitoring System (Sentry-RMS)—is a stand-alone security system that detects, assesses, and communicates priority alarms as a means of thwarting internal and external threats. The SEntry-RMS CommUnications and REsponse (Sentry-SECURE) platform—an optional feature of the Sentry-RMS—is being developed to facilitate more efficient alarm adjudication by site stakeholders and, if necessary, a faster response by law enforcement. This Cloud-hosted platform receives protected information from deployed Sentry-RMS units and relays it to stakeholders that have vested interests in maintaining an elevated level of situational awareness. Operationally, this enables real-time delivery of high-priority alarm and video imagery directly to an identified response stakeholder, such as local law enforcement or site management, via natively developed mobile applications or full platform integration. The Sentry-SECURE platform, as implemented by the U.S. Department of Energy’s Office of Radiological Security, is an example of an innovative security technology that compresses the TDM by (1) enabling a more efficient time to target and (2) better informing a response force’s predetermined tactics, techniques, and procedures. This paper explores the platform’s operational roles, highlights its principal functions, and presents a use case that demonstrates how the platform provides enhanced situational awareness when adjudicating priority alarms.

Sentry-RMS, Timely Detection Model, Sentry-SECURE↗

Integrating Safety, Security, and Nuclear Operations for Advanced Reactors

The traditional separation between safety, security, and operations teams has created significant barriers to achieving optimal outcomes. When security considerations are introduced late in the design process, they often conflict with already-established architectural, operational, or engineering parameters. Retrofitting security measures can lead to increased costs, schedule delays, and compromises in security effectiveness. For instance, the need to retrofit physical barriers or surveillance systems often results in trade-offs that could have been avoided with earlier input from security professionals. Delayed integration can also affect regulatory processes and result in licensing delays. Security reviews conducted at later stages frequently identify gaps that necessitate significant redesign efforts, impacting not only scope, schedule, and budget, but also adding risk and lowering stakeholder confidence in the project. This paper aims to address these challenges by identifying practical opportunities for integrating security considerations seamlessly with design and operations teams throughout the entire lifecycle of nuclear facilities—from conceptual design to commissioning and beyond. The research emphasizes the value of early and continuous collaboration among stakeholders to ensure that security measures are robust, operationally effective, and cost-efficient. By examining case studies, analyzing past incidents, and leveraging best practices from other high-security industries, this study highlights actionable strategies for bridging the gap between safety, security, and operations teams.

Zineddin, Dr. Z. [ORNL] (ORCID:0009000848740725)↗

The CYBER security – Competency Health and Maturity Progression (CYBER-CHAMP) model: Extending the National Initiative for Cybersecurity Education (NICE) Framework Across Organizational Security

Problem Statement: There is a pervasive talent deficit in the cybersecurity industry that prevents employers from being able to fill their open positions efficiently. A holistic approach to security is required to ensure organizations have adequate prevention and response capabilities in case of a cyberattack. Specifically, industrial control systems (ICS’s) and their operational technology (OT) components have become a constant target for cyberattacks. Research Questions: It is proposed that the NICE Framework should be extended in the following areas: 1) Include guidance regarding the job roles and competencies for both IT and OT professionals. 2) Offer step-by-step solutions, based on the work role mappings from the NICE Framework, to increase cybersecurity through employee training and education. 3) Provide a streamlined, lifecycle approach to building a cybersecurity program. Contribution: The CYBER security – Competency Health and Maturity Progression (CYBER-CHAMP©) model provides a customized solution for businesses to understand their education gaps in organizational security and target areas for improvement. Rationale: The Framework for Improving Critical Infrastructure Cybersecurity v1.1 addresses ICS but does not offer a measurement of cybersecurity maturity or clear methods to ascertain an organization’s current risk profile. In Phases 1 and 5 of the model, measurements are provided to help an organization build their current and target risk profiles. The NICE framework provides a structure for planning an IT cybersecurity workforce, but the OT aspects of cybersecurity are only briefly discussed. The model uses Phases 2-3 to examine the competencies of an organization’s workforce, which includes both IT and OT roles. Current frameworks do not offer next steps to increase an organization’s cybersecurity. During Phase 4, employees’ roles are mapped to training, education, and/or certifications from common vendors. Investigative Approach: The model provides measurements and metrics for both an organization’s status and continual improvement. This improvement methodology includes guidance for creating an overall strategic plan for security improvement via products designed to increase an organization’s operational readiness through workforce competency health. Lessons Learned: Depending on who was participating, there were contradicting answers given in Phase 1 due to different security cultures in the organization. This revelation has influenced the steps listed in the User’s Guide, where Phase 1’s first recommended step is to assemble a team that champions the facilitation and implementation of the model in the organization. During Phase 2, the discovery was made that organizations may be missing roles that are necessary to perform critical cybersecurity functions. By understanding the functional roles and competencies needed, they can contract or hire cybersecurity help to fill these gaps. Implications: Using the model, organizations can discuss quantitative measures for improvement as a business case for advancing their security program. Future research can validate and extend the present theory and model to a variety of environments. It is of interest to investigate additional security roles and knowledge domains that are used to build standardized cybersecurity curriculum.

97 MATHEMATICS AND COMPUTING↗

Integrating Cyber-Informed Engineering into Enterprise Risk Management

This document supports the application of Cyber-Informed Engineering (CIE) within the context of Enterprise Risk Management (ERM) to enhance cyber-resilience. It highlights that many critical infrastructure organizations use ERM to manage business risks and emphasizes the importance of evaluating critical systems and assets. The proposed approach can be adopted independently of formal ERM processes and offers a starting point for integrating CIE alongside existing or new ERM practices. Both CIE and ERM are iterative, and their alignment fosters continuous improvement and supports the engineering and operations cultures of an organization.

42 ENGINEERING↗