Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Authentication”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 253 records · Page 14

Dynamic Role-Based Access Control Policy for Smart Grid Applications: An Offline Deep Reinforcement Learning Approach

Role-based access control (RBAC) is adopted in the information and communication technology domain for authentication purposes. However, due to a very large number of entities within organizational access control (AC) systems, static RBAC management can be inefficient, costly, and can lead to cybersecurity threats. In this paper, a novel hybrid RBAC model is proposed, based on the principles of offline deep reinforcement learning (RL) and Bayesian belief networks. The considered framework utilizes a fully offline RL agent, which models the behavioral history of users as a Bayesian belief-based trust indicator. Thus, the initial static RBAC policy is improved in a dynamic manner through off-policy learning while guaranteeing compliance of the internal users with the security rules of the system. By deploying our implementation within the smart grid domain and specifically within a Distributed Energy Resources (DER) ecosystem, we provide an end-to-end proof of concept of our model. Finally, detailed analysis and evaluation regarding the offline training phase of the RL agent are provided, while the online deployment of the hybrid RL-based RBAC model into the DER ecosystem highlights its key operation features and salient benefits over traditional RBAC models.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Fast Local Spatial Verification for Feature-Agnostic Large-Scale Image Retrieval

Images from social media can reflect diverse viewpoints, heated arguments, and expressions of creativity, adding new complexity to retrieval tasks. Researchers working on Content-Based Image Retrieval (CBIR) have traditionally tuned their algorithms to match filtered results with user search intent. However, we are now bombarded with composite images of unknown origin, authenticity, and even meaning. With such uncertainty, users may not have an initial idea of what the search query results should look like. For instance, hidden people, spliced objects, and subtly altered scenes can be difficult for a user to detect initially in a meme image, but may contribute significantly to its composition. It is pertinent to design systems that retrieve images with these nuanced relationships in addition to providing more traditional results, such as duplicates and near-duplicates — and to do so with enough efficiency at large scale. In this work, we propose a new approach for spatial verification that aims at modeling object-level regions using image keypoints retrieved from an image index, which is then used to accurately weight small contributing objects within the results, without the need for costly object detection steps. We call this method the Objects in Scene to Objects in Scene (OS2OS) score, and it is optimized for fast matrix operations, which can run quickly on either CPUs or GPUs. It performs comparably to state-of-the-art methods on classic CBIR problems (Oxford 5K, Paris 6K, and Google-Landmarks), and outperforms them in emerging retrieval tasks such as image composite matching in the NIST MFC2018 dataset and meme-style imagery from Reddit.

42 ENGINEERING↗

Module-OT: A Hardware Security Module for Operational Technology

Increased penetration levels of renewable energy and other types of distributed energy resources (DERs) on the modern electric grid-combined with technological advancements for electric system monitoring and control-introduce new cyberattack vectors and increase the cyberattack surface of energy systems. According to the IEEE Std. 1547-2018, DERs must use Modbus, Distributed Network Protocol 3 (DNP3), or Smart Energy Profile 2.0 (SEP2) as their communication protocol. Previous research identified several vulnerabilities and security breaches in each one of these communication protocols; despite this, existing standards for DERs do not recommend cybersecurity measures. In order to reduce vulnerabilities in power distribution systems, this paper presents a novel open-source hardware security module that improves both information and operational security to better protect data and communications on the distribution grid. The security hardware is called “module for operational technology,” or simply Module-OT, and it has been validated and tested in an emulated distribution system application. Module-OT is integrated within a communication system in the transport layer of the Open Systems Interconnection (OSI) model. It improves system security through encryption, authentication, authorization, certificate management, and user access control. The main advancement of Module-OT is the addition of hardware cryptographic acceleration that improves the overall communication performance in terms of end-to-end latency.

70 PLASMA PHYSICS AND FUSION TECHNOLOGY↗

A Privacy-Preserving Cyber Threat Intelligence Sharing System

Cyber Threat Intelligence (CTI) is a key resource for developing defensive strategies against potential cyber adversaries. Entities typically access CTI through open-source platforms, national agencies, or specialized commercial services. However, the bi-directional exchange of CTI is hindered by organizational trust boundaries, which complicate the sharing processes between entities and CTI providers. Centralized CTI services benefit from receiving suspicious cyber observables such as IP addresses, domain names, and email addresses from various entities. The aggregation allows for the correlation of widespread adversarial activities to enhance the alert and response mechanisms across the network of involved parties. Despite these benefits, openly sharing such observables incurs potential legal, regulatory, and reputational risks for the disclosing entities.This paper introduces a system designed to facilitate the secure exchange of cyber observables across trust boundaries without compromising the anonymity of the sharing entities. Here, we propose an architecture that leverages common web protocols alongside zero-knowledge proofs to authenticate members while maintaining anonymity. Additionally, we outline a privacy model tailored for STIX (Structured Threat Information eXpression) cyber observables to minimize the risk of inadvertently disclosing private information. Through our threat models, we assess the privacy implications of our proposed system and demonstrate its potential to enhance collaborative cyber defense efforts without exposing entities to undue risk.

BBS+ Signatures↗

Synchronized Waveforms – A Frontier of Data-Based Power System and Apparatus Monitoring, Protection, and Control

Voltage and current waveforms contain the most authentic and granular information on the behaviors of power systems. In recent years, it has become possible to synchronize waveform data measured from different locations. Thus large-scale coordinated analyses of multiple waveforms over a wide area are within our reach. This development could unleash a set of new concepts, strategies, and tools for monitoring, protecting, and controlling power systems and apparatuses. This paper presents an in-depth review and analysis of the advancements in synchronized waveform data, including measurement devices, data characteristics, use cases, and comparisons with synchrophasor data. Based on the findings, five strategies are proposed to discover and develop synchronized waveform based applications over multiple application areas. The paper also presents three complementary measurement platforms and two data screening algorithms for application implementation. It further discusses committee activities and standard developments useful to explore the full potential of the data.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Perturbation-Based Diagnosis of False Data Injection Attack Using Distributed Energy Resources

Modern smart grid relies on various sensor measurements for its operational control. In a successful false data injection attack, the attacker manipulates the measurements from the grid sensors such that undetected errors are introduced into the estimates of the system parameters leading to catastrophic situations. This paper proposes a novel perturbation based false data injection attack detection mechanism that utilizes inverter based distributed energy resources (DERs) to create low magnitude perturbation signal in the distribution system voltage that is inconsequential to the normal grid operation. Two voltage sensitivity analysis based algorithms are designed to identify the optimal set of DERs that can create the voltage perturbation signal of desired magnitude. An analytical method of voltage sensitivity analysis is used to compute the magnitude of voltage perturbation signal at each node in a computationally efficient manner. Then, a detection mechanism is developed that checks for the presence of the perturbation sequence in each sensor measurement. A sensor measurement is deemed authentic if the voltage perturbation signal is present in the data. In case of sensor malfunction or cyber-attack, the perturbation signal will not be present in the measurement data. Performance of the proposed attack detection mechanism is validated via simulation of the IEEE 69 bus test system.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Multifractal Characterization of Distribution Synchrophasors for Cybersecurity Defense of Smart Grids

“Source ID Mix” spoofing emerged as a new type of cyber-attack on Distribution Synchrophasors (DS) where adversaries have the capability to swap the source information of DS without changing the measurement values. Accurate detection of such a highly-deceptive attack is a challenging task especially when the spoofing attack happens on short fragments of DS recorded within a relatively small geographical scale. Herein this letter proposes an effective approach to detect this cyber-attack by realizing the multifractal characteristics of DS measurements. First, the multifractal cross-correlation of DS measured at multiple intra-state locations is revealed. Then the derived correlation is integrated with weighted two-dimensional multifractal surface interpolation to reconstruct quasi high-resolution signals. Finally, informative location-specific signatures are extracted from the high-resolution DS and they are integrated with advanced machine learning techniques for source authentication. Experiments using the real-life DS are performed to verify the proposed method.

24 POWER TRANSMISSION AND DISTRIBUTION↗

The reactivity of experimentally reduced lunar regolith simulants: Health implications for future crewed missions to the lunar surface

Crewed missions to the Moon may resume as early as 2026 with NASA's Artemis III mission, and lunar dust exposure/inhalation is a potentially serious health hazard that requires detailed study. Current dust exposure limits are based on Apollo-era samples that spent decades in long-term storage on Earth; their diminished reactivity may lead to underestimation of potential harm that could be caused by lunar dust exposure. In particular, lunar dust contains nanophase metallic iron grains, produced by “space weathering”; the reactivity of this unique component of lunar dust is not well understood. Herein, we employ a chemical reduction technique that exposes lunar simulants to heat and hydrogen gas to produce metallic iron particles on grain surfaces. We assess the capacity of these reduced lunar simulants to generate hydroxyl radical (OH*) when immersed in deionized (DI) water, simulated lung fluid (SLF), and artificial lysosomal fluid (ALF). Lunar simulant reduction produces surface-adhered metallic iron “blebs” that resemble nanophase metallic iron particles found in lunar dust grains. Reduced samples generate ~5–100× greater concentrations of the oxidative OH* in DI water versus non-reduced simulants, which we attribute to metallic iron. SLF and ALF appear to reduce measured OH*. The increase in observed OH* generation for reduced simulants implies high oxidative damage upon exposure to lunar dust. Low levels of OH* measured in SLF and ALF imply potential damage to proteins or quenching of OH* generation, respectively. Reduction of lunar dust simulants provides a quick cost-effective approach to study dusty materials analogous to authentic lunar dust.

54 ENVIRONMENTAL SCIENCES↗

Information theory and machine learning illuminate large‐scale metabolomic responses of Brachypodium distachyon to environmental change

SUMMARY Plant responses to environmental change are mediated via changes in cellular metabolomes. However, <5% of signals obtained from liquid chromatography tandem mass spectrometry (LC‐MS/MS) can be identified, limiting our understanding of how metabolomes change under biotic/abiotic stress. To address this challenge, we performed untargeted LC‐MS/MS of leaves, roots, and other organs of Brachypodium distachyon (Poaceae) under 17 organ–condition combinations, including copper deficiency, heat stress, low phosphate, and arbuscular mycorrhizal symbiosis. We found that both leaf and root metabolomes were significantly affected by the growth medium. Leaf metabolomes were more diverse than root metabolomes, but the latter were more specialized and more responsive to environmental change. We found that 1 week of copper deficiency shielded the root, but not the leaf metabolome, from perturbation due to heat stress. Machine learning (ML)‐based analysis annotated approximately 81% of the fragmented peaks versus approximately 6% using spectral matches alone. We performed one of the most extensive validations of ML‐based peak annotations in plants using thousands of authentic standards, and analyzed approximately 37% of the annotated peaks based on these assessments. Analyzing responsiveness of each predicted metabolite class to environmental change revealed significant perturbations of glycerophospholipids, sphingolipids, and flavonoids. Co‐accumulation analysis further identified condition‐specific biomarkers. To make these results accessible, we developed a visualization platform on the Bio‐Analytic Resource for Plant Biology website ( https://bar.utoronto.ca/efp_brachypodium_metabolites/cgi‐bin/efpWeb.cgi ), where perturbed metabolite classes can be readily visualized. Overall, our study illustrates how emerging chemoinformatic methods can be applied to reveal novel insights into the dynamic plant metabolome and stress adaptation.

59 BASIC BIOLOGICAL SCIENCES↗

Biomimetic oxidative copolymerization of hydroxystilbenes and monolignols

Hydroxystilbenes are a class of polyphenolic compounds that behave as lignin monomers participating in radical coupling reactions during the lignification. Here, we report the synthesis and characterization of various artificial copolymers of monolignols and hydroxystilbenes, as well as low-molecular-mass compounds, to obtain the mechanistic insights into their incorporation into the lignin polymer. Integrating the hydroxystilbenes, resveratrol and piceatannol, into monolignol polymerization in vitro, using horseradish peroxidase to generate phenolic radicals, produced synthetic lignins [dehydrogenation polymers (DHPs)]. Copolymerization of hydroxystilbenes with monolignols, especially sinapyl alcohol, by in vitro peroxidases notably improved the reactivity of monolignols and resulted in substantial yields of synthetic lignin polymers. The resulting DHPs were analyzed using two-dimensional NMR and 19 synthesized model compounds to confirm the presence of hydroxystilbene structures in the lignin polymer. The cross-coupled DHPs confirmed both resveratrol and piceatannol as authentic monomers participating in the oxidative radical coupling reactions during polymerization.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

Broadly neutralizing antibodies against sarbecoviruses generated by immunization of macaques with an AS03-adjuvanted COVID-19 vaccine

The rapid emergence of severe acute respiratory syndrome coronavirus 2 (SARS-CoV-2) variants that evade immunity elicited by vaccination has placed an imperative on the development of countermeasures that provide broad protection against SARS-CoV-2 and related sarbecoviruses. Here, we identified extremely potent monoclonal antibodies (mAbs) that neutralized multiple sarbecoviruses from macaques vaccinated with AS03-adjuvanted monovalent subunit vaccines. Longitudinal analysis revealed progressive accumulation of somatic mutation in the immunoglobulin genes of antigen-specific memory B cells (MBCs) for at least 1 year after primary vaccination. Antibodies generated from these antigen-specific MBCs at 5 to 12 months after vaccination displayed greater potency and breadth relative to those identified at 1.4 months. Fifteen of the 338 (about 4.4%) antibodies isolated at 1.4 to 6 months after the primary vaccination showed potency against SARS-CoV-2 BA.1, despite the absence of serum BA.1 neutralization. 25F9 and 20A7 neutralized authentic clade 1 sarbecoviruses (SARS-CoV, WIV-1, SHC014, SARS-CoV-2 D614G, BA.1, and Pangolin-GD) and vesicular stomatitis virus–pseudotyped clade 3 sarbecoviruses (BtKY72 and PRD-0038). 20A7 and 27A12 showed potent neutralization against all SARS-CoV-2 variants and multiple Omicron sublineages, including BA.1, BA.2, BA.3, BA.4/5, BQ.1, BQ.1.1, and XBB. Crystallography studies revealed the molecular basis of broad and potent neutralization through targeting conserved sites within the RBD. Prophylactic protection of 25F9, 20A7, and 27A12 was confirmed in mice, and administration of 25F9 particularly provided complete protection against SARS-CoV-2, BA.1, SARS-CoV, and SHC014 challenge. These data underscore the extremely potent and broad activity of these mAbs against sarbecoviruses.

60 APPLIED LIFE SCIENCES↗

Improve Learning from Crowds via Generative Augmentation

Crowdsourcing provides an efficient label collection schema for supervised machine learning. However, to control annotation cost, each instance in the crowdsourced data is typically annotated by a small number of annotators. This creates a sparsity issue and limits the quality of machine learning models trained on such data. In this paper, we study how to handle sparsity in crowdsourced data using data augmentation. Specifically, we propose to directly learn a classifier by augmenting the raw sparse annotations. We implement two principles of high-quality augmentation using Generative Adversarial Networks: 1) the generated annotations should follow the distribution of authentic ones, which is measured by a discriminator; 2) the generated annotations should have high mutual information with the ground-truth labels, which is measured by an auxiliary network. Extensive experiments and comparisons against an array of state-of-the-art learning from crowds methods on three real-world datasets proved the effectiveness of our data augmentation framework. It shows the potential of our algorithm for low-budget crowdsourcing in general.

96 KNOWLEDGE MANAGEMENT AND PRESERVATION↗

The LCLStream Ecosystem for Multi-Institutional Dataset Exploration

We describe a new end-to-end experimental data streaming framework designed from the ground up to support new types of applications – AI training, extremely high-rate X-ray time-of-flight analysis, crystal structure determination with distributed processing, and custom data science applications and visualizers yet to be created. Throughout, we use design choices merging cloud microservices with traditional HPC batch execution models for security and flexibility. This project makes a unique contribution to the DOE Integrated Research Infrastructure (IRI) landscape. By creating a flexible, API-driven data request service, we address a significant need for high-speed data streaming sources for the X-ray science data analysis community. With the combination of data request API, mutual authentication web security framework, job queue system, high-rate data buffer, and complementary nature to facility infrastructure, the LCLStreamer framework has prototyped and implemented several new paradigms critical for future generation experiments.

Rogers, David [ORNL] (ORCID:0000000251871768)↗

A multimodal and integrated approach to interrogate human kidney biopsies with rigor and reproducibility: guidelines from the Kidney Precision Medicine Project

Comprehensive and spatially mapped molecular atlases of organs at a cellular level are a critical resource to gain insights into pathogenic mechanisms and personalized therapies for diseases. The Kidney Precision Medicine Project (KPMP) is an endeavor to generate three-dimensional (3-D) molecular atlases of healthy and diseased kidney biopsies by using multiple state-of-the-art omics and imaging technologies across several institutions. Obtaining rigorous and reproducible results from disparate methods and at different sites to interrogate biomolecules at a single-cell level or in 3-D space is a significant challenge that can be a futile exercise if not well controlled. Here we describe a “follow the tissue” pipeline for generating a reliable and authentic single-cell/region 3-D molecular atlas of human adult kidney. Our approach emphasizes quality assurance, quality control, validation, and harmonization across different omics and imaging technologies from sample procurement, processing, storage, shipping to data generation, analysis, and sharing. We established benchmarks for quality control, rigor, reproducibility, and feasibility across multiple technologies through a pilot experiment using common source tissue that was processed and analyzed at different institutions and different technologies. A peer review system was established to critically review quality control measures and the reproducibility of data generated by each technology before their being approved to interrogate clinical biopsy specimens. The process established economizes the use of valuable biopsy tissue for multiomics and imaging analysis with stringent quality control to ensure rigor and reproducibility of results and serves as a model for precision medicine projects across laboratories, institutions and consortia.

59 BASIC BIOLOGICAL SCIENCES↗

ModuleOT

ModuleOT is an open hardware security platform which provides all features necessary for securing remote energy resources. The platform consists of a physical bump in-the wire device which runs a custom-built application built with Go and Python and leverages AES-NI Instruction set available on modern hardware for cryptographic acceleration. By combining these features, ModuleOT acts as an all-in-one low-cost solution to enable cryptographically secured communications to any critical remote servers or devices. Because the software application has been built using Golang, this source can be easily compiled for different hardware platforms. The module is designed to provide the following core features: (1) encrypted communications across an untrusted network, (2) certificate-based authentication with secure storage, (3) hardware cryptographic acceleration, (4) IP-based whitelisting, (5) local firewall management, and (6) legacy (RS485) device support.

Hasandka, Adarsh↗

Ncrc-client

This is a simple wrapper script that will be used to enable the use of a two-factor authentication mechanism for downloading NCRC controlled codes through the popular "Conda" distribution mechanism.

Permann, Cody↗

PAM module for OAuth 2.0 Device flow

This is a PAM module that lets you log in via SSH to servers using OpenID Connect credentials, instead of SSH Keys or a username and password combination. It uses the OAuth2 Device Flow, which means that during the login process, you will click a link and log in to your OpenID Connect Provider, which will then authenticate you for the SSH session. This module will then check if you're in the right group(s) or have a specified username, and allow or deny access.

Surkont, Jarosław↗

IViz-OT (Intrusion Detection Visualizer for Operational Technology Network) [SWR-22-63]

The Visualizer dashboard provides grid operator highly-trusted alarming environment for an ongoing or potential cyber-attack based on system anomalies and network-based verification. Once anomalies are detected by the IDS tool (HIDES, NREL SWR-19-65), this platform stores the signatures or alert logs that are generated by the intrusion detector, lays out the detailed summary of the possible alerts, and maps these attacks with high-level scenarios. These scenarios are later combined to define a final event using a decision tree approach and a final report is generated out of this tool for further forensic analysis. It also supports authentication and authorization to support roles-based access control (RBAC) for users and a group of people.

Singh, Vivek Kumar↗