Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Authentication”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 235 records · Page 13

Document-Based Nuclear Archaeology

Deeper reductions in the nuclear arsenals will require better understanding of historic fissile material management and production. The concept of “nuclear archaeology” has been considered since the 1990s to provide the tools and methods to develop independent production estimates, primarily based on nuclear forensic techniques. Here, we propose to add a framework for reconstructing the history of a nuclear program that complements traditional nuclear archaeology techniques by examining the role of operating records to support such an effort. As a test case, we use the JEEP II reactor, a 2 MW civilian research reactor at Norway’s Institute for Energy Technology (IFE), in operation for more than fifty years, however, recently shut down permanently. We have collected, analyzed, and started to preserve the reactor’s operating records, which exist on both analog and digital media, and to simulate parts of its history using OpenMC/ONIX neutronics calculations. Here, a particular focus of this project has been on digital data curation and preservation to confirm and maintain the integrity, authenticity, and provenance of these records. In developing guidelines for best practices that conform to existing standards for long-term digital preservation and curation, we hope this project can help lay the basis for future nuclear archaeology efforts to support nuclear arms control and disarmament.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Demonstration and Concept of Operations for a Zero-Knowledge Protocol Passive Imaging Measurement for Arms Control

Here, we present an imaging system that employs zero-knowledge protocols to protect sensitive geometrical information, along with procedures to increase confidence in the result. The goal of this work is to enable the inclusion of warhead confirmation measurements in future arms control treaties. We present a demonstration of both true positive and true negative measurements that validate models and establish authenticating procedures toward meeting acceptance requirements for use in nuclear facilities. We use a two-dimensional time-encoded fast neutron imaging system with an anti-symmetric mask pattern; the fast neutron count values exceeding minimum or maximum thresholds indicate that two measured items are not identical. Laboratory measurements over twenty trials show that alarm rates for negative confirmation measurements are within uncertainties of model predictions. Positive confirmation measurements indicate that alarm rates are large enough to encourage treaty compliance.

Sweany, Melinda Dominique [Sandia National Laborat↗

RNA nanotechnology to build a dodecahedral genome of single-stranded RNA virus

The quest for artificial RNA viral complexes with authentic structure while being non-replicative is on its way for the development of viral vaccines. RNA viruses contain capsid proteins that interact with the genome during morphogenesis. The sequence and properties of the protein and genome determine the structure of the virus. For example, the Pariacoto virus ssRNA genome assembles into a dodecahedron. Virus-inspired nanotechnology has progressed remarkably due to the unique structural and functional properties of viruses, which can inspire the design of novel nanomaterials. RNA is a programmable biopolymer able to self-assemble sophisticated 3D structures with rich functionalities. RNA dodecahedrons mimicking the Pariacoto virus quasi-icosahedral genome structures were constructed from both native and 2'-F modified RNA oligos. The RNA dodecahedron easily self-assembled using the stable pRNA three-way junction of bacteriophage phi29 as building blocks. The RNA dodecahedron cage was further characterized by cryo-electron microscopy and atomic force microscopy, confirming the spontaneous and homogenous formation of the RNA cage. The reported RNA dodecahedron cage will likely provide further studies on the mechanisms of interaction of the capsid protein with the viral genome while providing a template for further construction of the viral RNA scaffold to add capsid proteins for the assembly of the viral nucleocapsid as a model. Understanding the self-assembly and RNA folding of this RNA cage may offer new insights into the 3D organization of viral RNA genomes. Finally, the reported RNA cage also has the potential to be explored as a novel virus-inspired nanocarrier.

59 BASIC BIOLOGICAL SCIENCES↗

Next generation experimental data access at NSLS-II

The NSLS-II network and computing infrastructure has been significantly updated recently. The re-IP process in 2020-2021 enabled the NSLS-II network to be routable to the rest of the BNL campus. Then, standardization of the operating systems and deployment procedures helped to deliver a consistent environment to workstations and servers used by all NSLS-II beamlines. In particular, the RedHat Enterprise Linux 8 was deployed to 700+ machines using the RedHat Satellite infrastructure management product, and all critical services (IOCs, databases, etc.) were migrated to the new OS. NFS users’ home directories are consistent across all of the machines, which eliminates the need for the individual configuration of the user environment on each host. The standard suite of software packages is available to the beamline staff and users, which includes the system packages (deployed via RPM) as well as the conda environments for data acquisition and analysis. Security measures were implemented to comply with the industry standards, which include multi-factor authentication (using Duo), secure screen lock for the beamline machines, and advanced access control to the experimental data that is stored in shared central storage available on all hosts. These major enhancements facilitated sharing the experimental data (currently for a number of selected beamlines, with a plan to extend it to the whole facility in the nearest future) with the users via an externally facing JupyterHub instance. The beamlines keep using the Bluesky data acquisition framework to orchestrate their experiments, and the new infrastructure enabled them to use a next-generation data access library called tiled.

36 MATERIALS SCIENCE↗

Data transfer for STAR grid jobs

The Solenoidal Tracker at RHIC (STAR) is a multipurpose experiment at the Relativistic Heavy Ion Collider (RHIC) with the primary goal to study the formation and properties of the quark-gluon plasma. STAR is an international collaboration of member institutions and laboratories from around the world. Yearly data-taking period produces PBytes of raw data collected by the experiment. STAR primarily uses its dedicated facility at BNL to process this data, but has routinely leveraged distributed systems, both high throughput (HTC) and high performance (HPC) computing clusters, to significantly augment the processing capacity available to the experiment. The ability to automate the efficient transfer of large data sets on reliable, scalable, and secure infrastructure is critical for any large-scale distributed processing campaign. For more than a decade, STAR computing has relied upon GridFTP with its x509-based authentication to build such data transfer systems and integrate them into its larger production workflow. The end of support by the community for both GridFTP and the x509 standard requires STAR to investigate other approaches to meet its distributed processing needs. In this study we investigate two multi-purpose data distribution systems, Globus.org and XRootD, as alternatives to GridFTP. We compare both their performance and the ease by which each service is integrated into the type of secure and automated data transfer systems STAR has previously built using GridFTP. The presented approach and study may be applicable to other distributed data processing use cases beyond STAR.

73 NUCLEAR PHYSICS AND RADIATION PHYSICS↗

Beyond Solanaceae: incorporation of feruloyltyramine and feruloyloctopamine into Cannabaceae lignins

The ferulic acid amides, feruloyltyramine and feruloyloctopamine, have been widely reported as integral constituents in the lignins in several species of Solanaceae in which they function as authentic lignin monomers. In the present study, we demonstrate that these ferulic acid amides are likewise incorporated into the lignins of species within Cannabaceae, including hemp (Cannabis sativa), hops (Humulus lupulus), and European nettle tree (Celtis australis). Structural analyses using derivatization followed by reductive cleavage (DFRC) and two-dimensional nuclear magnetic resonance (2D-NMR) spectroscopy revealed that these ferulic acid amides are incorporated via 4−O- and 8−O-ether linkages, as well as through 8−5′ linkages forming phenylcoumaran structures. Examination of a broad phylogenetic range of plant families demonstrated the absence of these ferulic acid amides from the lignins of all families studied except Solanaceae and Cannabaceae. Given the distant phylogenetic relationship between Solanaceae and Cannabaceae, the recruitment of these ferulic acid amides as lignin monomers in both lineages likely constitutes a case for convergent evolution at the level of lignin biosynthetic pathways. The significance of these ferulic acid amides lies in their unique role as the sole nitrogen-containing phenolic compounds known to participate in lignin formation.

Cannabaceae↗

Orbital Ingredients and Persistent Dirac Surface State for the Topological Band Structure in FeTe 0.55 Se 0.45

FeTe 0.55 Se 0.45 (FTS) occupies a special spot in modern condensed matter physics at the intersections of electron correlation, topology, and unconventional superconductivity. The bulk electronic structure of FTS is predicted to be topologically nontrivial due to the band inversion between the d x z and p z bands along Γ − Z . However, there remain debates in both the authenticity of the Dirac surface states (DSSs) and the experimental deviations of band structure from the theoretical band inversion picture. Here we resolve these debates through a comprehensive angle-resolved photoemission spectroscopy investigation. We first observe a persistent DSS independent of k z . Then, by comparing FTS with FeSe, which has no band inversion along Γ − Z , we identify the spectral weight fingerprint of both the presence of the p z band and the inversion between the d x z and p z bands. Furthermore, we propose a renormalization scheme for the band structure under the framework of a tight-binding model preserving crystal symmetry. Our results highlight the significant influence of correlation on modifying the band structure and make a strong case for the existence of topological band structure in this unconventional superconductor. Published by the American Physical Society 2024

75 CONDENSED MATTER PHYSICS, SUPERCONDUCTIVITY AND↗

Nuclear Quadrupole Resonance for Substance Detection

This review paper provides a comprehensive overview of recent advances in nuclear quadrupole resonance (NQR) spectroscopy for substance detection, highlighting its principles, methodologies, and applications. The paper elucidates the fundamental physics underlying NQR spectroscopy, emphasizing the interaction between nuclear quadrupole moments and electric field gradients. It explores the various experimental techniques and instrumentation developments that have enabled the sensitive detection and precise characterization of substances containing quadrupolar nuclei. A significant portion of the survey is dedicated to discussing the diverse applications of NQR spectroscopy, including the detection of explosives, drug pharmaceuticals, and material authentication. Furthermore, the survey examines the challenges and limitations associated with NQR spectroscopy, including issues related to signal-to-noise ratio (SNR), temperature dependency, and substance restrictions. Strategies to overcome these challenges are discussed, offering insights into the future directions of NQR spectroscopy research that includes artificial intelligence (AI), internet of things (IoT) integration, incorporating a cloud database for NQR parameter storage, and multi-modal analysis.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Incremental Threshold Scheme Enabled IoT Group Key Management

Cyber landscape evolves rapidly. Internet of Things (IoT) and Edge Computing (EC) have rapidly become an integral part of the modern computing infrastructure. It is expected that there will be more than 50 billion active and connected IoT devices by 2025 [1]. Pervasive IoT/EC creates unprecedented opportunities bridging the gap between previously segregated cyber and physical spaces. However, this progress also brings along new security challenges. IoT devices typically have limited computation, communication, and storage resources. This leads to security architecture designs such as using symmetric keys for group communication. While secure and efficient in stable network settings, symmetric key solutions are ill-adapted for IoT's highly dynamic device mobility behavior and frequent group membership turnover. Whenever IoT members leave a group, the known symmetric keys cannot be made forgotten, posing a serious vulnerability. This leads to frequent re-groupings that require expensive re-authentication, key regeneration, and key redistribution in order to maintain IoT/EC security. We present a novel symmetric key management framework that integrate an Incremental Threshold Scheme (ITS) cryptographical function into communication protocol's key rotation mechanism to allow for secure and efficient symmetric key communication group member node revocation. This ITS-enabled key management framework alleviates the need of frequent and expensive re-grouping and re-keying needed by today's large and dynamic IoT/EC operations. We further applied this ITS-enabled key management framework to a distributed IoT/EC-integrated publish and subscribe framework for applicability validation.

Li, Mingyan↗

Cyber Protection of Grid-Connected Devices Through Embedded Online Security

Cybersecurity research regarding the electric power grid has primarily been focused on protecting the communication layer of grid-connected devices against cyber-attack threats. Although many developed methods have greatly reduced the effects of a cyber-attack on the vulnerabilities of grid-connected devices, discovering new vulnerabilities is inevitable and a constant threat. As a result, the overall reliability and security of network communications with regard to grid-connected devices is a concern. Here, this paper proposes a method that further secures a system by focusing on the control and hardware layer of grid-connected devices. The device’s controller firmware will be validated and authenticated using integrated device emulation resources prior to being activated to control the grid-connected device. This verification process is performed while the controller is online and actively controlling power flows related to the device. Therefore, an attack to the system through a malicious firmware patch would be detected by the online security and rejected while safely maintaining continuous and stable control of the device. This method integrates the concepts of firmware hot-patching, digital twins, and active monitoring into an overall cybersecurity protection system.

cybersecurity↗

Rapid Event Detection via Synchro-Waveform Based Temporal Attention Network in Distributed Grid

Compared with the information collected from phasor measurement units, synchro-waveforms contain high-fidelity disturbances of the grid, which can be a granular and authentic representation of measurements in the modern power system. However, the dynamic changing morphology makes it challenging to effectively capture various disturbance information from the synchro-waveforms. To tackle this issue, this paper proposes a Synchro-waveform based Temporal Attention (STA) network to achieve rapid event detection. First, a multi-scenario distributed model with renewable integration is established to generate synchro-waveforms under various uncertainties. Then, three typical temporal features are extracted directly from the synchro-waveform measurements. Additionally, the lightweight STA network is deployed to identify the most common event types in renewable energy systems via the self-attention based vision transformer module. The results from simulated experiments demonstrate that the proposed approach can achieve rapid and real-time detection within 0.81 ms and over 96.27 % accuracy.

Dong, Yuqing [University of Tennessee (UT)]↗

Disruption of Commercial Solar Inverter System by TLS Proxy Man-in-the-Middle Attack

Transport Layer Security (TLS) is a cryptographic protocol that encrypts communication data, providing end-to-end communication encryption and authentication. Currently, TLS is widely adopted for securing communication between servers and end devices, including solar inverter systems. Therefore, users/operators can securely access the solar inverters through a web user interface (WebUI) application programmable interface (API) on a PC or server over TLS-enabled Wi-Fi or Ethernet. However, the security of the TLS-based network becomes compromised if it is breached by a TLS proxy man-in-the-middle (MITM) exploit. This report explores potential vulnerabilities in a commercial solar inverter system that leverages a TLS proxy MITM and discusses the impacts through assume-breached penetration testing. Furthermore, the paper explores recommended mitigation methods against the TLS proxy MITM exploit in solar inverters.

97 MATHEMATICS AND COMPUTING↗

Attack on Grid Event Cause Analysis: An Adversarial Machine Learning Approach

With the ever-increasing reliance on data for data-driven applications in power grids, such as event cause analysis, the authenticity of data streams has become crucially important. The data can be prone to adversarial stealthy attacks aiming to manipulate the data such that residual-based bad data detectors cannot detect them, and the perception of system operators or event classifiers changes about the actual event. This paper investigates the impact of adversarial attacks on convolutional neural network-based event cause analysis frameworks. We have successfully verified the ability of adversaries to maliciously misclassify events through stealthy data manipulations. The vulnerability assessment is studied with respect to the number of compromised measurements. Furthermore, a defense mechanism to robustify the performance of the event cause analysis is proposed. The effectiveness of adversarial attacks on changing the output of the framework is studied using the data generated by real-time digital simulator (RTDS) under different scenarios such as type of attacks and level of access to data.

Niazazari, Iman↗

A Cryptographic Method for Defense Against MiTM Cyber Attack in the Electricity Grid Supply Chain

Critical infrastructures such as the electricity grid can be severely impacted by cyber-attacks on its supply chain. Hence, having a robust cybersecurity infrastructure and management system for the electricity grid is a high priority. This paper proposes a cyber-security protocol for defense against man-in-the-middle (MiTM) attacks to the supply chain, which uses encryption and cryptographic multi-party authentication. A cyber-physical simulator is utilized to simulate the power system, control system, and security layers. The correctness of the attack modeling and the cryptographic security protocol against this MiTM attack is demonstrated in four different attack scenarios.

Paul, Shuva↗

Integrating AEAD Ciphers into Software-Defined-Storage Systems

The use of software-defined storage (SDS) systems to store sensitive data is becoming increasingly prevalent. However, these systems primarily implement security measures to ensure the confidentiality and availability of stored data, with limited consideration for the protection of its integrity. This paper outlines why this is a harmful development, as well as how integrity-protecting measures can be included into SDS systems. To demonstrate the practical challenges and opportunities of such measures, we integrated "authenticated encryption with associated data" (AEAD) ciphers into the widely used SDS system Ceph, specifically, into its block storage interface, to secure the integrity of stored data and metadata. Ultimately, we identify the characteristics that an SDS system should possess to adopt our methodology.

Mohren, David [University of New Brunswick, Canada↗

An Extensible Software and Communication Platform for Distributed Energy Resource Management

This paper introduces a novel Distributed Extensible Grid Control (DEGC) software and communication platform to facilitate the control of distributed energy resources on electric grids. The DEGC software platform leverages state-of-the-art advances in secure, distributed communication and decentralized authorization and authentication. We discuss how these advances enable the kind of robust and secure communication required for a distributed grid control platform, and show how DEGC applies these technologies to the agile development and deployment of grid software through an extensible and flexible API. Here, we describe how DEGC can implement both Volt-VAR voltage magnitude control and Phasor-Based Control as sample applications and demonstrate the DEGC platform in hardware with the demanding Phasor-Based Control test case, and provide performance metrics.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Achieving Runtime State Verification Assurance in Critical Cyber-Physical Infrastructures

Industrial Cyber-Physical Systems (ICPS) are an essential backbone of national critical infrastructures. They help monitor and control crucial cyber-enabled services such as energy generation. Commonly ICPS monitors the physical process through Supervisory Control and Data Acquisition (SCADA) systems. The SCADA ecosystem takes critical real-time and future system operational decisions based on the runtime state behavior of field sensors. Traditional SCADA systems use legacy and insecure communication protocols such as the Modbus protocol that lack adequate security mechanisms to provide robust runtime state behavior assurance of constrained field sensors. Therefore, constrained field sensors are commonly vulnerable to standard semantic attacks that gradually change the behavior state of infected devices. This paper discusses process integrity assurance techniques necessary to enhance the security of behavior-based protocols such as the Modbus protocol. The Runtime State Verification (RSV) protocol proposed in this paper aims to address semantic attacks in the SCADA ecosystem by integrating behavior-based Mandatory Results Automata (MRA) and a Hyperledger Fabric (HLF) network. The RSV protocol provides high process integrity assurance through enhanced behavior-based MRA suitable for the constrained field devices. A proof of concept of the RSV protocol has been evaluated in an emulated water-tube boiler. Preliminary evaluations of the RSV protocol aimed to measure the efficiency of the proposed protocol by monitoring an Combustion Efficiency (CE) process necessary to preserve optimal combustion, thus minimizing costs and future maintenance of water-tube boilers. We analyze the overall network overhead and latency of the proposed RSV protocol by evaluating the HLF network performance and comparing the proposed RSV protocol with the state-ofart BloSPAI protocol. Through the preliminary evaluations of the proposed RSV protocol, this paper demonstrates that the proposed RSV protocol overcomes the shortcomings and network overhead of the BloSPAI protocol by integrating behavior-based authentication through novel MRAs and HLF networks.

Rivera, Abel Gomez↗

Alerga: Alert Aggregation and Reasoning in GOOSE Simulation Pipeline

IEC 61850 specifies the Generic Object Oriented Substation Event (GOOSE) protocol as one option for low latency communication of substation-related events. Due to its strict timing requirements, GOOSE lacks any form of encryption or authentication and has only minimal integrity guarantees. These absences render the protocol vulnerable to a variety of communication anomalies, including adversarial action. In particular, an adversary with access to the substation network can launch man in the middle (MITM) attacks. We propose Alerga, a set of tools to allow operators to mitigate some of the risks of the protocol while retaining its strengths. To that end, we have developed first a GOOSE simulation pipeline including data generation, anomaly detection, alert handling, causal reasoning and data visualization components. The simulator is designed to be modular, allowing operators to swap components to better fit their network capabilities. The volume of alert traffic on a substation network threatens operators with alert fatigue. In order to combat this, we secondly present a novel form of alert aggregation and processing, offering operators a condensed view of any threats to the system. Thirdly, to facilitate the handling of these threats, our causal reasoning system traces the alerts back to their most likely cause, generating an initial hypothesis for operators to investigate.

alert aggregation↗