Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Secure by Design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 217 records · Page 12

IMAGINE BioSecurity: Mesocosm-Based Methods to Evaluate Biocontainment Strategies and Impact of Industrial Microbes Upon Native Ecosystems

Project Goals: The Integrative Modeling and Genome-scale Engineering for Biosystems Security (IMAGINE BioSecurity) SFA project seeks to establish an understanding of the behavior of engineered microbes in controlled versus environmental conditions to predictively devise new strategies for responding to biological escape. To this end, the IMAGINE Team has established a plant-soil mesocosm platform to track and quantify the fate of industrial microbes in environmental systems and assess the efficacy of biocontainment constraints upon genetically engineered microbe escape frequency and the impact of industrial microbes upon native ecological microbiomes. Abstract Text: Genetically modified industrial production microbes and their associated bioproducts have emerged as an integral component of a sustainable bioeconomy. However, the rapid development of these innovative technologies raises biosecurity concerns, namely, the risk of environmental escape. Thus, the realization of a bioeconomy hinges not only on the development and deployment of microbial production hosts, but also on the development of secure biosystems and biocontainment designs. Current laboratory-based biocontainment testing systems do not accurately reflect complexities found in natural environments, necessitating an environmentally relevant analysis pipeline that allows for the detection of rare escapees, the effect of associated bio-products, and the impact on native ecologies. To this end, we have developed an approach that utilizes soil mesocosms and integrated systems analyses to evaluate the efficacy of novel biocontainment strategies and to assess the impact of production systems upon terrestrial microbiome dynamics. We demonstrate the utility of this approach by modeling a contamination with industrial microbial chasses versus their biocontained counterparts. Here we demonstrate the broad utility of this system by highlighting findings from both strains of Saccharomyces cerevisiae that are contained with an inducible toxin anti-toxin system, and stains of Escherichia coli that are contained via genomic recoding. The resultant data demonstrate that this system has broad utility across diverse microbial chassis and biocontainment strategies, enables us to track the fate of our contaminating microbe with high sensitivity in the soil, as well as monitor broader impacts of the perturbation on the underlying soil system. The findings presented here support the use of this mesocosm-based approach to assess the environmental impact of industrial microbes and to validate biocontainment strategies.

BASIC BIOLOGICAL SCIENCES,INORGANIC, ORGANIC, PHYS↗

Advanced Transmission Technologies – GETs and HPCs Session 2: Advanced Power Flow Control and Transmission Topology Optimization

The INL TADA GETs Cohort Session 2, held on November 7, 2025, conducted in collaboration with ScottMadden, focused on two core Advanced Transmission Technologies (ATTs): Advanced Power Flow Control (APFC) and Transmission Topology Optimization (TTO). These technologies are pivotal in enhancing grid flexibility, reliability, and cybersecurity resilience. APFC, particularly through modular FACTS devices like Modular Static Synchronous Series Compensators (M-SSSCs), enables dynamic voltage injection to reroute power flows. The session highlighted the deployment benefits of APFC, such as rapid installation, minimal civil works, and re-deployability. Regulatory drivers like FERC Order 2023 mandate the inclusion of Grid-Enhancing Technologies (GETs) in interconnection studies. Case studies from Central Hudson, CAISO, and National Grid (UK) demonstrated APFC’s effectiveness in congestion relief and cost savings. The session also addressed cybersecurity concerns, including firmware vulnerabilities, SCADA integration risks, and supply chain dependencies. Participants engaged in interactive exercises to rank cybersecurity and supply chain risks, emphasizing the need for robust digital assurance strategies. TTO involves software-based reconfiguration of transmission networks to optimize power flow without new infrastructure. The session showcased its operational value, with examples from SPP, PJM, and MISO showing significant congestion cost reductions. Cybersecurity vulnerabilities were discussed, particularly in API security and software supply chains, referencing incidents like SolarWinds and attacks on Danish utilities. Digital assurance exercises explored worst-case scenarios, attack paths, and mitigation responsibilities between vendors and utilities. Reliability challenges such as algorithm stability, vendor dependency, and operator trust were also examined. Cross-cutting themes emphasized the importance of digital assurance tools, including Software Bills of Materials (SBOMs) and hardware-in-loop testing. Human performance, training, and operational confidence were identified as critical enablers of technology adoption. The session concluded with a preview of Session 3, which will focus on High Performance Conductors (HPCs) and risk-based cybersecurity tools. Session 2 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Advanced Transmission Technologies –GETs and HPCs Session 3: HPCs and Building Actions Plans to Digital Assurance Risks

The third session of the Idaho National Laboratory’s (INL) Technical Assistance for Digital Assurance (TADA) program, held on November 11, 2025, centered on High Performance Conductors (HPCs) and the formulation of action plans to address digital assurance risks associated with Grid-Enhancing Technologies (GETs). This session convened experts from utilities, vendors, and government agencies to examine the technical, operational, and cybersecurity aspects of HPC deployment. Discussions highlighted the benefits of HPCs, such as their ability to rapidly increase transmission capacity using existing corridors, improve grid resilience, reduce system losses, and align with FERC Orders 2023 and 1920. Participants evaluated supply chain and digital assurance risks, including reliance on imported materials, limited domestic manufacturing capacity, workforce shortages, and traceability issues. The session also emphasized the importance of digital trust, integration-layer cybersecurity, and unified risk frameworks, introducing tools like intrusion detection systems, encryption, zero trust networking, and firmware integrity. Recaps of earlier workshops on Dynamic Line Ratings (DLRs), Advanced Power Flow Control (APFC), and Transmission Topology Optimization (TTO) underscored institutional barriers and integration challenges. Action plans were proposed to mitigate issues such as inconsistent cybersecurity practices, SBOM usage, supply chain visibility, operator trust, and misaligned incentives. Additionally, INL presented its supply chain risk management tools and Cyber-Informed Engineering (CIE) principles to support secure procurement and system design. The session concluded with a commitment to share key takeaways, incorporate cohort feedback into future policy development, and continue collaborative engagement through upcoming pilot activities. Session 3 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Data Centers and Digital Assurance Workshop 3 – Mitigations for Digital Assurance Risks

The third session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort, held on November 18, 2025, focused on developing mitigation strategies for digital assurance risks identified in previous workshops. Hosted by Idaho National Laboratory (INL) and ScottMadden, the session emphasized the application of Cyber-Informed Engineering (CIE) to data center infrastructure, particularly at the utility–data center interface. Participants revisited and ranked key digital assurance risks, including architecture and interface weaknesses, governance gaps, and AI-enabled threats. The workshop introduced the 12 principles of CIE, advocating for consequence-focused design, engineered controls, and secure information architecture to proactively reduce cyber-physical vulnerabilities. These principles were applied to critical data center systems such as power distribution, UPS, cooling, SCADA/BMS, and grid-forming batteries. The session also addressed governance challenges at the interconnection boundary, highlighting the need for clear roles in telemetry sharing, firmware management, and trip settings. Special attention was given to emerging risks from behind-the-meter (BTM) generation, including reverse-power flow and the integration of small modular reactors (SMRs), which shift data centers from large loads to complex generation nodes. Participants explored how interconnection agreements can serve as enforceable instruments for digital assurance, and reviewed gaps in current standards such as NERC CIP, IEC 62443, and IEEE 1547. The workshop concluded with pathways to standardization, including model agreement language, state-level programs, and expanded NERC guidance. INL also presented tools and frameworks for secure procurement and supplier risk management, reinforcing the need for integrated engineering and policy solutions to secure the evolving data center–grid ecosystem. Session 3 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

The research challenges in security and safeguards for nuclear fission batteries

This paper discusses the nuclear security and safeguards research challenges presented by the development and deployment of nuclear fission batteries. These are defined as easily transportable and deployable nuclear systems which are designed to operate either unattended or autonomously. We start by defining the current landscape of domestic and international safeguards and security and discuss how it can be affected by the introduction these new nuclear systems. We then specifically discuss the technology gaps and technologies to be developed to facilitate their practical deployment. We find that, as expected, we can leverage conclusions from existing security and safeguards studies for small modular rectors and develop bespoke target set analyses to inform security postures based on probabilistic risk assessment. We find also that specific fission battery security economic analysis tools are needed and security by design must be applied early. However, the most important finding is that these new systems will require a new comprehensive set of cyber tools covering transportation, installation, operation, maintenance security of the fission battery systems. Altogether, we find that the development of the necessary security and safeguards requirements at the design phase of such a technology will be of great benefit in the smooth deployment of this modern nuclear energy system.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Technical report Letter: RAFM, ODS steels and MMLC for Nuclear energy application

The lifetime, thermodynamic efficiency, safety and economic viability of new generation fission and fusion reactor concepts can largely be tied to the mechanical performance and stability of structural alloys under extreme environments. In this context, engineered nano materials could have broad-reaching impact on the future of advanced nuclear fuel-cycle and reactors. These systems are characterized by a large number density of interfaces which are efficient sinks for point defects and moderately biased; therefore limiting the deleterious effects of irradiation. Broadly, nuclear nano-technology deals with the use of the latest engineered-nanomaterials for improving the nuclear power performances and safety in all areas of nuclear energy production to bring new generations of nuclear power units. New advanced fuel assembly designs also have implications for securities and safeguards. To support the readiness for potential future license applications, an understanding of the technologies that would enable new reactor designs in the areas of component performance and domestic safeguards is necessary. This technical report letter work explores the technical issues and potential regulatory considerations associated with developing and adopting fuel claddings made of advanced nano- materials. Specifically three classes of nanomaterials are considered: (i) reduced activation ferritic/martensitic (RAFM) steels, (ii)oxide dispersed steels (ODS) and (iii) multi-metallic layered composites (MMLC).

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Power System Resilience Considering Hurricane Storms and Generator Step-up Transformers

Power system resilience describes the system’s ability to withstand and recover quickly from unexpected power outages due to extreme events. As society’s electrification continues at a rapid rate, it is imperative electric infrastructure is designed and operated with extra security. This work studies the impact of severe hurricane storms on the power system located along the United States’ Eastern Seaboard. Specific focus is designated to steady state system operation and loss of large generation step up power transformers. A series of phasor domain power system simulations are conducted to determine the critical point at which the system loses steady state operability. Additionally, active power load shedding and generator dispatching are studied as mitigation and recovery strategies. Results indicate generator dispatching as an effective proactive mitigation strategy and load shedding as an effective recovery strategy.

Liu, Yilu↗

Cyber Resilient Design and Controls for Energy Systems

As the grid of today is evolving into a highly distributed and autonomous cyber-physical system with higher penetration of Distributed Energy Resources (DERs) and autonomous controls that are dependent on the cyber infrastructure, there are novel and increasing challenges to cyber-resilient operation of the grid. While the traditional mechanisms take a "bolt on" approach to cybersecurity and resiliency, this talk presents two novel technologies developed at NREL that "bake in" security and resilience into the design and control of the grid. An Adaptive Resilience Metrics framework is a novel mechanism for system owners and operators to understand the impact of cyber and physical system design and topology on the resilient operation, while also helping determine optimal policies in response to adverse cyber events. Along with that a zero-knowledge proof-based technique helps incorporate security into the controls layer by focusing on computational integrity rather than data integrity. By leveraging design and control properties unique to Operational Technology systems these technologies will not only help enhance cyber-resilience for the grid of today, but a highly distributed and autonomous grid of tomorrow.

cyber resilience↗

Cyber Informed Engineering (CIE) Principles Slide Presentation [Slides]

This document describes the concept and application of Cyber-Informed Engineering (CIE), a methodology that integrates cyber threat awareness into all stages of the systems engineering life cycle. It delineates how CIE enhances the security posture of critical infrastructure systems, which are increasingly targeted by sophisticated cyber threats. The exposition proceeds to methodically walk through the twelve foundational principles of CIE, each serving as a strategic guidepost for embedding cybersecurity into the fabric of system design, development, operation, and maintenance. The principles highlight the importance of proactive and comprehensive security measures that span from risk assessment to continuous improvement, ensuring that systems are not only designed with security in mind but are also resilient in the face of evolving cyber threats.

42 ENGINEERING↗

Dynamics of Water, Climate, and Infrastructure

Climate and its impacts on the natural environment, and on the ability of the natural environment to support population and the built environment, stands as a threat multiplier that impacts national and global security. The Water Intersections with Climate Systems Security (WICSS) Strategic Initiative is designed to improve understanding of water’s role in, among other topics, the connection of critical infrastructure to climate in light of competing national and global security interests (including transboundary issues and stability), and identifying research gaps aligned with Sandia, and Federal agency priorities. With this impetus in mind, the WICSS Strategic Initiative team conceptualized a causal loop diagram (CLD) of the relationship between and among climate, the natural environment, population, and the built environment, with an understanding that any such regionally focused system must have externalities that influence the system from beyond its’ control, and metrics for better understanding the consequences of the set of interactions. These are discussed in light of a series of worldviews that focus on portions of the overall systems relationship. The relationships are described and documented in detail. A set of reinforcing and balancing loops are then highlighted within the context of the model. Finally, forward-looking actions are highlighted to describe how this conceptual model can be turned into modeling to address multiple problems described under the purview of the Strategic Initiative.

54 ENVIRONMENTAL SCIENCES↗

MITR Low-Enriched Uranium Conversion Fluid-Structure Interaction Preliminary Design Verification

The U.S. National Nuclear Security Administration (NNSA) Office of Material Management and Minimization (M 3 ) has developed and is pursuing an integrated approach to address the persistent threat posed by unintentional proliferation of nuclear materials. The NNSA M 3 approach reduces the risk of highly enriched uranium (HEU) and plutonium falling into the hands of non-state actors by minimizing the use of and, when possible, eliminating weapons-usable nuclear material around the world. In this geopolitical context, most research and test reactors, both domestic and international, have completed or started a program of conversion from the use of HEU to low-enriched uranium (LEU) as fuel. Conversion of civilian research reactors from HEU to LEU, and the return of the HEU to the country of origin, are important components of the NNSA non-proliferation program. Worldwide, 71 reactors have been converted to the use of LEU fuel, and an additional 32 have been confirmed to be permanently shut down. The U.S., with 20 reactor conversions, is among the 39 countries on six continents where conversions have occurred. With recent conversions in Ghana and Nigeria, an important milestone was reached in completing conversion of all reactors on the continent of Africa to LEU fuel. Africa thus becomes the third continent to have completed conversion of all HEU reactors to LEU, following Australia and South America

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Next-Generation Intensity-Duration-Frequency Curves for Climate-Resilient Infrastructure Design: Advances and Opportunities

National and international security communities (e.g., U.S. Department of Defense) have shown increasing attention for innovating critical infrastructure and installations due to recurring high-profile flooding events in recent years. The standard infrastructure design approach relies on local precipitation-based intensity-duration-frequency (PREC-IDF) curves that do not account for snow process and assume stationary climate, leading to high failure risk and increased maintenance costs. This paper reviews the recently developed next-generation IDF (NG-IDF) curves that explicitly account for the mechanisms of extreme water available for runoff including rainfall, snowmelt, and rain-on-snow under nonstationary climate. The NG-IDF curve is an enhancement to the PREC-IDF curve and provides a consistent design approach across rain- to snow-dominated regions, which can benefit engineers and planners responsible for designing climate-resilient facilities, federal emergency agencies responsible for the flood insurance program, and local jurisdictions responsible for developing design manuals and approving subsequent infrastructure designs. Further, we discuss the recent advances in climate and hydrologic science communities that have not been translated into actional information in the engineering community. To bridge the gap, we advocate that building climate-resilient infrastructure goes beyond the traditional local design scale where engineers rely on recipe-based methods only; the future hydrologic design is a multi-scale problem and requires closer collaboration between climate scientists, hydrologists, and civil engineers.

54 ENVIRONMENTAL SCIENCES↗

MARVEL 90% Final Design Report

This document provides documentation of the Microreactor Applications Research Validation and Evaluation Project’s (MARVEL) 90% Final Design, as required by U.S. Department of Energy (DOE) Standard-1189, “Integration of Safety into the Design Process." Per DOE-STD-1189-2016, the 90% Final Design documentation focuses on design completion, at a level capable of supporting procurement, construction, testing, and operation. At this phase, the design organization finalizes the hazards and accident analyses, Fire Hazard Analysis (FHA), security vulnerability assessments, and other supporting analyses for design completion. The objective of this report is to provide a high-level summary of the design thus far and provide references including, but not limited to, the following design deliverables: • Complete final drawings, specifications and commercial grade dedications that may be released for bid and/or construction. • Clearly defined testing plans for the safety and functionality of all subsystems. • Quality Assurance Program for Design, Testing and Procurement. • Software Quality Assurance Plan. • Code of Record (COR), applicable design requirements including codes and standards. • Final design that meets all the requirements stipulated in the COR. • Final design review, consisting of final validation of comment resolution from previous reviews, and a review of any additional developments since the last review. • Updated Safety Design Strategy. • Hazard Analysis. • Fire Hazard Analysis. • Accident analysis. • Security vulnerability assessment. • Current and detailed cost estimate. • Current construction schedule, and • Risk & Opportunities Assessment.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

DEVELOPMENT OF AN INTEGRATED SECURITY AND SAFETY MONITORING SYSTEM FOR SPENT NUCLEAR FUEL AND HIGH-LEVEL WASTE TRANSPORTATION

This paper provides an overview of the progress to date, and discussion of the path forward, related to designing, fabricating, and testing an integrated security and safety monitoring system (ISSMS) for railcars used to transport spent nuclear fuel (SNF) and high-level radioactive waste (HLW) in the United States. The system will comply with the US Department of Energy’s (DOE) Order 460.2B “Departmental Materials Transportation Management” and the Association of American Railroads’ (AAR) standard S-2043 “Performance Specification for Trains Used to Carry High-level Radioactive Material” [1] developed specifically for railcars used to transport high-level radioactive material (HLRM). DOE is in the process of developing and testing an ISSMS that will satisfy both DOE requirements and AAR standards. DOE has already developed railcar designs for transportation of HLRM. In 2024, DOE’s Atlas railcar project completed the design, fabrication and testing of three railcar types: transportation cask-carrying, buffer, and security escort, resulting in AAR conditional approval to operate on freight rail networks in North America. DOE decided to combine the required security and safety systems into one system, and this combined system is the subject of the current effort. DOE is developing and proposes to implement the ISSMS for these railcars as part of the build out of the railcar fleet. DOE began planning for development of the ISSMS in February 2020. The project is divided into seven phases starting with conceptual design and continuing through production design, as shown in Figure 1. An earlier version of the system was tested as part of the Atlas railcar consist demonstration test run in 2023. This paper describes the design features and system testing using the Atlas project railcars, and laboratory testing completed to date. The paper will also describe the activities planned to support the DOE project to ship the High Burn-Up Research Cask (HBRC) in 2027.

Schultze, Michael [ORNL] (ORCID:0000000283205671)↗

Advanced Reactor Safeguards & Security 2024 Program Roadmap

The Advanced Reactor Safeguards and Security (ARSS) program was established to provide research support addressing near term challenges that advanced nuclear reactor vendors face in meeting domestic Material Control and Accounting (MC&A), Physical Protection System (PPS), and Cybersecurity requirements for U.S. construction. The technical work in the program is meant to (1) support nuclear reactor vendors with advanced MC&A, PPS, and Cybersecurity designs for next generation reactors, (2) provide technical bases for the regulator, and (3) promote the integration of Safeguards and Security by Design early in the design process. Existing domestic regulations for safeguards and security, as outlined in the Code of Federal Regulations, were written for large light water reactors, and rule-making efforts are underway to develop regulations more suited to different reactor designs. The ARSS program seeks to remove roadblocks in the deployment of new and advanced reactors by solving regulatory challenges, reducing safeguards and security costs, and utilizing the latest technologies and approaches for robust plant monitoring and protection. This roadmap discusses the goals of the ARSS program, current research, and program plan for the next five years.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Development of A Hardware-In-the-Loop (HIL) Testbed for Cyber-Physical Security in Smart Buildings

As smart buildings move towards open communication technologies, providing access to the Building Automation System (BAS) through the building's intranet, or even remotely through the Internet, has become a common practice. However, BAS was historically developed as a closed environment and designed with limited cyber-security considerations. Thus, smart buildings are vulnerable to cyber-attacks with the increased accessibility. This study introduces the development and capability of a Hardware-in-the-Loop (HIT) testbed for testing and evaluating the cyber-physical security of typical BASs in smart buildings. The testbed consists of three subsystems: (1) a real-time HIL emulator simulating the behavior of a virtual building as well as the Heating, Ventilation, and Air Conditioning (HVAC) equipment via a dynamic simulation in Modelica; (2) a set of real HVAC controllers monitoring the virtual building operation and providing local control signals to control HVAC equipment in the HIL emulator; and (3) a BAS server along with a web-based service for users to fully access the schedule, setpoints, trends, alarms, and other control functions of the HVAC controllers remotely through the BACnet network. The server generates rule-based setpoints to local HVAC controllers. Based on these three subsystems, the HIL testbed supports attack/fault-free and attack/fault-injection experiments at various levels of the building system. The resulting test data can be used to inform the building community and support the cyber-physical security technology transfer to the building industry.

Li, Guowen↗

Innovation in Radiological Security, Part 2 of 2 – Insights into Developing a Cloud-hosted Security Technology

A Sentry Remote Monitoring System (Sentry-RMS) is a stand-alone security system that provides detection, assessment, and communication of priority alarms as an additional means of thwarting internal and external threats to sites that maintain radiological material. The SEntry-RMS CommUnications and REsponse (Sentry-SECURE) platform is an optional feature of the Sentry-RMS that relays priority alarm information to the identified response stakeholders. Sentry-SECURE is hosted in a cloud environment that abstracts the data owner’s and data consumer’s platforms to allow for greater information sharing. This promotes situational awareness amongst authorized users and enables future innovation among modern response platforms. When securely architecting a cloud solution such as this, the use of design paradigms can be an effective tool to increase the accuracy and reliability of cyber- and information-security-related decisions made throughout the development process. This approach also supports the categorization of design considerations into three levels: industry concepts, project approaches, and data protections for digital processes. Industry concepts consist of the notional underpinnings that guide or motivate a security process, system, or design but often lack any tangible attributes. Project approaches represent decisions made during the design and development process to prioritize a solution, method, or practice above another that may provide a comparable functional output but lacks a desired security benefit. Data protections for digital processes represent the selection, integration, and implementation of specific controls for a given asset. This paper will explore specific examples of how Sentry-SECURE has been designed to account for considerations at each of these three levels, while balancing the operational intent of the platform with the security enhancements necessary to maintain data integrity, availability, and confidentiality.

assessment, RMS, security, physical, cloud, Cyber ↗

Cyber-Informed Engineering (CIE) Integration into Model- Based Systems Engineering (MBSE)

Engineering design in the field of industrial engineering, such as designing automated factories or warehouses, is critical for the effective operation of facilities. Any design flaws introduced early can result in significant capital expenses to correct. However, early-stage engineering design is inherently complex. The systems are not yet built, requiring designers to integrate various aspects, including digital engineering and cybersecurity, to support virtual representations throughout the design process. In this study, we propose an approach to integrate Cyber-Informed Engineering (CIE) principles into model-based systems engineering (MBSE). This approach facilitates the development of a digital thread for engineering systems, ensuring secure digital artifacts in the design of industrial engineering systems.

42 - ENGINEERING↗