Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Authentication”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 271 records · Page 15

Systematization of Password Manager Use Cases and Design Paradigms

Despite efforts to replace them, passwords remain the primary form of authentication on the web. Password managers seek to address many of the problems with passwords by helping users generate, store, and fill strong and unique passwords. Even though experts frequently recommend password managers, there is limited information regarding their usability. To aid in designing such usability studies, we systematize password manager use cases, identifying ten essential use cases, three recommended use cases, and four extended use cases. We also systematize the system designs employed to satisfy these use cases, designs that should be examined in usability studies to understand their relative strengths and weaknesses. Finally, we describe observations from 136 cognitive walkthroughs exploring the identified essential use cases in eight popular managers. Ultimately, we expect that this work will serve as the foundation for an explosion of new research into the usability of password managers.

Simmons, James↗

Methods for communicating data utilizing sessionless dynamic encryption

The present disclosure is directed to methods that provide a secure communication protocol by utilizing one step process of authenticating and encrypting data without having to exchange symmetric keys or needing to renew or re-issue digital identities fundamental to asymmetric encryption methodology.

Choi, Sung Nam↗

Deconstructing the Nuclear Supply Chain Cyber-Attack Surface

The nuclear supply chain cyber-attack surface is a large, complex network of interconnected stakeholders and activities. The global economy has widened and deepened the supply chain resulting in larger numbers of geographically dispersed locations and increased difficulty ensuring the authenticity and security of digital assets. Although the nuclear industry has made significant strides in securing facilities from cyber-attacks, the supply chain remains vulnerable. This paper provides further details on each of the elements in the Digital I&C System Supply Chain Cyber-Attack Surface, including supply chain lifecycle activities, key stakeholders, touchpoints, and attack types. Deconstructing this attack surface provides insights into supply chain threats, vulnerabilities, and consequences. These insights will lead to improvements in cybersecurity supply chain risk analysis, development of new cybersecurity supply chain processes and tools, and enhancement of overall supply chain resilience.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Community Energy Planning: Best Practices and Lessons Learned in NREL's Work with Communities

The clean energy transition is accelerating due to local, state, and national actions combined with external market forces. Regardless of where goals are set and decisions are made, clean energy deployment occurs on the ground in communities. As a result, communities increasingly need technical expertise and assistance with planning for and managing the energy transition. Building on decades of work with state, local, and tribal jurisdictions, the National Renewable Energy Laboratory (NREL) increasingly provides community-driven modeling, analysis, and technical assistance to enable more data-driven and equitable community energy planning. To inform and enhance NREL's capabilities in community energy planning and provide a resource for others working in this space, the Joint Institute for Strategic Energy Analysis (JISEA) Sustainable Communities Catalyzer supported this best-practices presentation based on interviews with seasoned NREL practitioners and a literature review on equitable community energy planning. Findings include five best practices for community energy planning that NREL practitioners and others can apply to strengthen their impact: 1) do your homework in preparation for community interactions; 2) be humble, authentic, and honest in your interactions with community members; 3) respect community agency in every step of the process; 4) meet the community where they are; 5) democratize participation.

best practices↗

Module-OT: A Turnkey Solution for Securing Energy Systems

The Modular Security Apparatus for Managing Distributed Cryptography for Command-and-Control Messages on Operational Technology Networks (Module-OT) is a flexible and lightweight solution for grid-edge devices focusing on end-to-end security. It is a bump- in- the-wire solution acting as a secure conduit for data between devices or systems across a network. It improves the cybersecurity posture of DER systems by providing authentication, authorization, and data integrity to secure DER communications. Additionally, it performs key management, provides data security through whitelisting Internet Protocol addresses and ports, blocks unauthorized connections, controls user access, and allows serial or Ethernet connections for added flexibility. The core software is portable to various Linux-based operating systems and is developed to be customized by the developer and researcher communities. Module-OT has been validated in the lab, has been demonstrated at a 500-KW PV-plus-storage site, and has been proven ready to secure operational technology devices. Its core functionality meets current standards, including validation procedures of the NIST Cryptographic Algorithm Validation Program (CAVP) and the Federal Information Processing Standard (FIPS 140-2). Because of its capability to provide an accessible and affordable option for stepping up security across modern energy systems, Module-OT can serve as an effective technological option to standardize cybersecurity moving forward.

cryptography↗

Luminescent group 1A copper halides and uses thereof

High photoluminescence, high stability, inorganic perovskite compounds comprising an alkali metal selected from potassium (K), rubidium (Rb), and cesium (Cs); copper (Cu); and at least one halogen selected from chlorine (Cl), bromine (Br), and iodine (I). The perovskites may be free of lead (Pb). The inorganic perovskite compound may be used in an optoelectronic device. The optoelectronic device optionally contains a phosphor such as a blue-emitting phosphor. The inorganic perovskite compound may be used as an anti-counterfeiting nanotaggant applied on or within an object that susceptible to counterfeiting to enable confirmation of an authentic object.

Saparov, Bayram↗

Methods for communicating data utilizing sessionless dynamic encryption

The present disclosure is directed to methods that provide a secure communication protocol by utilizing one step process of authenticating and encrypting data without having to exchange symmetric keys or needing to renew or re-issue digital identities fundamental to asymmetric encryption methodology.

Choi, Sung Nam↗

Optical tags comprising rare earth metal-organic frameworks

Optical tags provide a way to identify assets quickly and unambiguously, an application relevant to anti-counterfeiting and protection of valuable resources or information. The present invention is directed to a tag fluorophore that encodes multilayer complexity in a family of heterometallic rare-earth metal-organic frameworks (RE-MOFs) based on highly connected polynuclear clusters and carboxylic acid-based linkers. Both overt (visible) and covert (near infrared, NIR) properties with concomitant multi-emissive spectra and tunable luminescence lifetimes impart both intricacy and security. Tag authentication can be validated with a variety of orthogonal detection methodologies. The relationships between structure, composition, and optical properties of the family of RE-MOFs can be used to create a large library of rationally designed, highly complex, difficult to counterfeit optical tags.

Sava Gallis, Dorina F.↗

Disrupting EV Charging Sessions and Gaining Remote Code Execution with DoS, MITM, and Code Injection Exploits using OCPP 1.6

Open Charge Point Protocol (OCPP) 1.6 is widely used in the electric vehicle (EV) charging industry to communicate between Charging System Management Services (CSMSs) and Electric Vehicle Supply Equipment (EVSE). Unlike OCPP 2.0.1, OCPP 1.6 uses unencrypted websocket communications to exchange information between EVSE devices and an onpremise or cloud-based CSMS. In this work, we demonstrate two machine-in-the-middle (MITM) attacks on OCPP sessions to terminate charging sessions and gain root access to the EVSE equipment via remote code execution (RCE). Second, we demonstrate a malicious firmware update with a code injection payload to compromise an EVSE. Lastly, we demonstrate two methods to prevent availability of the EVSE or CSMS. One of these, originally reported by SaiFlow, prevents traffic to legitimate EVSE equipment using a DoS-like attack on CSMSs by repeatedly connecting and authenticating several CPs with the same identities as the legitimate CP. These vulnerabilities were demonstrated with proof-of-concept exploits in a virtualized Cyber Range at Wright State University and/or with a 350 kW Direct Current Fast Charger (DCFC) at Idaho National Laboratory. The team found that OCPP 1.6 could be protected from these attacks by adding secure shell (SSH) tunnels to the protocol, if upgrading to OCPP 2.0.1 was not an option. Index Terms—Electric vehicle charging, cybersecurity, OCPP, cyberattack, cyber-resilience. INSPEC Accession Number: 23981565

99 GENERAL AND MISCELLANEOUS↗

A Real-Time ANPC Inverter Digital Twin with Integrated Design-For-Trust

The demand for renewable energy has increased over the last few years, and so has the demand for greater expectations within the energy market. This increasing trend has been accompanied by more significant usage of internet-connected devices (IoT), leading to critical electrical infrastructure being connected to the internet. Implementing internet connectivity with such devices and systems provides benefits such as improving the system's performance, facilitating irregularity and anomaly mitigation, and providing additional situational awareness for enhanced decision-making. However, enhancing the connected system with IoT introduces a drawback – a greater vulnerability to cyber-attacks. Cyber-attacks targeting critical infrastructure in the electrical sector have occurred in the United States and Ukraine. These cyber-attacks highlight and expose vulnerabilities that a system inherits when connecting to the internet. These attacks left thousands of customers without electricity for hours until operators could regain control of the electric utility grid. Therefore, to address the vulnerabilities of an internet-connected power electronic device, this work focused on the hardware layer of the system. Implementing a cyber-control system inside the hardware layer can significantly reduce the possibility of an attacker patching malicious controller firmware into a photovoltaic grid-connected inverter, thus mitigating the likelihood that the inverter becomes inactive a cyber-attack scenario. With this mitigation technique, if a cyberattack is successful and an attacker gains control of the network, a cyber-defense technique is in place to mitigate the impact of the cyber-attack. This additional protection layer was developed based on an innovative concept known as Digital Twin (DT). A DT, in this case, replicates an Active-Neutral Point Clamped (ANPC) inverter and was designed using a hardware language known as VHDL (Very High-Speed Integrated Circuit Hardware Description Language) and applied to Field-Programmable-GateArray (FPGA). The DT is embedded within the FPGA and contained in a controller board, the UCB (Unified Controller Board), developed by the University of Arkansas electrical engineering team. This UCB also contains two Digital Signal Processors (DSPs) responsible for generating associated signals to control an authentic physical inverter. These DSP signals are received and processed by the FPGA that implements the DT of an ANPC; in other words, it simulates in realtime the expected output of an actual ANPC inverter using the signals from the DSP. When a new firmware is ready to be patched, the DT provides output signals simulating behavior that a real ANPC inverter would generate with the new firmware. The new firmware is tested to check if it meets all the operational requirements established using a Design-For-Trust technique (DFTr). If the new firmware fails in at least one of the DFT tests, it is considered malicious and must be rejected. This work is divided into sections, such as Background, which explains the pieces that were used and the strategy behind this work; Process and Procedure, which explains the methodology that was adopted to prove the reliability and effectiveness of this work; Results and Discussion, where the simulations and results are described and explained; followed by Conclusion and Future work section, which concludes this work and adds possible future projects to continue this work further.

do Amaral Custodio, Paulo Vitor↗

Development of a Reference Design for a Cyber-Physical System

The purpose of this thesis is to develop a reference design to assist in the selection of security practices in power electronics design. A prototype will be developed from this reference design for evaluation. This evaluation will include a brief cost/benefit analysis to gauge the efficacy of implementing each layer of security throughout the power electronics design process. This thesis will also describe the obstacles and effectiveness of integrating a Trusted Platform Module (TPM) into a cyber-hardened grid-connected device. The TPM device is a secured crypto processor that assists in generating, storing, and restricting the use of cryptographic keys. The emphasis of this research is to establish integrity, authenticity, and confidentiality within a system by providing a baseline of security concerns for segments of the system. This research considers communication, control, and hardware level securities. The scope of this thesis will review the necessary security methods as well as consider the effects these methods have on the embedded system, to assess the desired security to responsiveness trade off. Applying this approach to a design process will alleviate various unknowns of appending security to a power electronics design. This thesis describes the specific vulnerabilities introduced within this grid-edge environment, and how the liabilities within the system can be mitigated. Initially, common security techniques will be considered to establish a guideline to benchmark performance and resource costs of the system. The foundation will be a non-hardened power electronic system platform with industry standard communication protocols. Several security techniques and attack vectors will then be evaluated to contribute to the base level platform. Other fail-safe features take place to gauge progress of the selected approach, non-inclusive to the TPM. Collectively, this investigation will determine a valid experiment by appraising and categorizing resource allocation, performance overhead, and monetary cost analysis results into a reference design. The prototype will then demonstrate methods to relieve common threats that are purposefully implemented into the design.

Blair, Nicholas Paul↗

Developing an AI-Powered Zero-Trust Cybersecurity Framework for Malware Prevention in Nuclear Power Plants

This study presents the development of an AI-powered Zero-Trust cybersecurity framework for malware prevention in nuclear power plants. The framework aims to enhance the security of critical systems within nuclear power plants by adopting the principles of Zero-Trust and leveraging artificial intelligence (AI) technologies. By assuming no implicit trust in any user or device and continuously authenticating and authorizing access, the framework ensures a robust defense against malware attacks. The integration of AI allows for the detection and prevention of malware through behavioral analytics, endpoint protection, network segmentation, and continuous monitoring. The paper discusses the key considerations, steps, and technologies involved in developing this framework, emphasizing the importance of regular updates, training, compliance, and auditing. The proposed framework serves as a comprehensive approach to safeguarding nuclear power plants from sophisticated malware threats and protecting the integrity and safety of critical infrastructure.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Laser Based Ultrasound for Verification of Circuit Card Assemblies

This IR is a follow-up conference Paper to the IR approved abstract; PNNL-SA-194096. --- Verification that equipment is authentic and not changed; even at the circuit card assembly (CCA) level will likely be an important component of future arms control treaties. This effort was an initial evaluation of the potential for laser-based ultrasound (LBU) as an inspection tool for Unique Identification (UID) of Circuit Card Assembly (CCA) boards and CCA components. The LBU system used a laser pulse for ultrasound generation and an Optical Microphone for ultrasound detection to image subsurface structures without physical contact and in a dry state. This paper described the selected CCA surrogate, CCA components that were examined, the LBU system, LBU images of the CCA components, and the initial development of UID algorithms. Receiver operating characteristics (ROC) curves indicated good performance for two algorithms as a potential means for UID of CCA boards and CCA components.

Laser Ultrasound, Equipment Verification, Arms Con↗

Novel Photonuclear Methods to Produce an Argon-37 Standard

The mission of this research is to explore novel photonuclear-based pathways into the production of 37Ar. Above-background detection levels of 37Ar uniquely indicates the occurrence of an underground nuclear explosion, produced from fission neutrons interacting in the surrounding environment through the 40Ca(n,a)37Ar reaction. The half-life of 35 days allows on-site inspectors (OSI) adequate time following the nuclear event to detect 37Ar and verify compliance or defiance of non-proliferation treaties such as the Comprehensive Nuclear-Test-Ban Treaty (CTBT). An 37Ar standard would give OSI the ability to calibrate their detectors and measure detector efficiency allowing for the quantification of detected activity, give OSI authentic samples to test detectors in field exercises, and improve models predicting diffusion pathways of 37Ar through the underground environment.

43 PARTICLE ACCELERATORS↗

Verifying Cyber Implementation Best Practices With Malcolm

Network traffic analysis can reveal a lot about what's right or wrong with a network's cybersecurity footing. Using Malcolm, a powerful open-source network traffic analysis tool suite for network security monitoring, cyber analysts and asset owners can validate cybersecurity best practices and uncover red flags in network configuration, including: proper network segmentation east-west (cross-segment) and north-south traffic unsecure or outdated network protocols authentication using clear text credentials rogue devices and services unexpected protocols (e.g., IPv6, DNS, DHCP, update checks, etc.) suspicious file transfers

99 GENERAL AND MISCELLANEOUS↗

A Managed Tokens Service for Securely Keeping and Distributing Grid Tokens

Fermilab is transitioning authentication and authorization for grid operations to using bearer tokens based on the WLCG Common JWT (JSON Web Token) Profile. One of the functionalities that Fermilab experimenters rely on is the ability to automate batch job submission, which in turn depends on the ability to securely refresh and distribute the necessary credentials to experiment job submit points. Thus, with the transition to using tokens for grid operations, we needed to create a service that would obtain, refresh, and distribute tokens for experimenters' use. This service would avoid the need for experimenters to be experts in obtaining their own tokens and would better protect the most sensitive long-lived credentials. Further, the service needed to be widely scalable, as Fermilab hosts many experiments, each of which would need their own credentials. To address these issues, we created and deployed a Managed Tokens Service. The service is written in Go, taking advantage of that language's native concurrency primitives to easily be able to scale operations as we onboard experiments. The service uses as its first credentials a set of kerberos keytabs, stored on the same secure machine that the Managed Tokens service runs on. These kerberos credentials allow the service to use htgettoken via condor_vault_storer to store vault tokens in the HTCondor credential managers (credds) that run on the batch system scheduler machines (HTCondor schedds); as well as downloading a local, shorter-lived copy of the vault token. The kerberos credentials are then also used to distribute copies of the locally-stored vault tokens to experiment submit points.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Shape Optimization of Header Pipes in Power Plants for Enhanced Efficiency and Environmental Sustainability

In a power plant, the header pipe plays a pivotal role in optimizing the performance of diverse systems by serving as a central conduit for the collection and distribution of steam within the plant. This paper investigates the significance of header pipes within power plant setups, highlighting their critical influence on reliability, efficiency, and the performance of the power plant as a whole. The concept of shape optimization emerges as a crucial factor in power plant design and operation, with the potential to maximize performance while minimizing the use of materials. Shape optimization not only enhances efficiency but also contributes to reducing the environmental footprint of power plant installations. In this paper, we initially developed a methodology designed for optimizing header shapes with the primary goal of reducing the usage of costly new alloy materials and lowering the overall maintenance operation expenses. Secondly, we conducted a case study based on an authentic header sourced from an operational power plant.

20 FOSSIL-FUELED POWER PLANTS↗

Improving Cyber Situational Understanding

Effective cybersecurity operations require the ability to analyze large amounts of information to assess security risks and formulate defensive strategies against adversaries. This has become more complex in recent years as the sprawl and interconnectivity of devices grows through implementation of virtualization, cloud computing, and Internet of Things (IoT). The amount of data and analysis required for effective cybersecurity command and control decisions far exceeds humans’ capacity to perform manually. We characterize the analysis problem as cyber situational understanding. The research presented to improve cyber situational understanding focuses on vulnerability analysis and threat intelligence. Regarding vulnerabilities, entities must analyze and plan work for between thousands and tens of thousands of software vulnerabilities annually. Entities heavily use network firewalls to limit vulnerability exposure. As a result, some of these vulnerabilities permit exposure to adversarial exploitation, whereas others are inaccessible and therefore present negligible risk of exploitation. Distinguishing between high and low risk software vulnerabilities requires a deep understanding of the vulnerability, network firewall protection, and characteristics of the targeted device. This problem is solved by extracting network service features from vulnerability data features using both machine-learning and natural language processing. Then, the network firewall topology is parsed to determine which vulnerabilities are reachable by adversaries. Ultimately, a state-based safety analysis ascertains which vulnerabilities are unsafe. A related vulnerability analysis problem occurs in cybersecurity operations when associating an entity’s hardware and software assets to public vulnerability databases. Assets often reveal hardware and software through installation artifacts and network service identification, and entities store these artifacts in inventory databases. However, software and hardware vendors apply a standard Common Platform Enumeration (CPE) naming convention when publicly reporting vulnerabilities. Associating these two datasets often requires many hours to days of manual inspection. The proposed solution automates the mapping approach of human analysts using fuzzy matching techniques, natural language processing, and, ultimately, machine learning to present a small set of recommendations for mapping the two datasets. The result significantly reduces human analysis time and reduces the occurrence of false positives in vulnerability notifications. Finally, cyber threat intelligence (CTI) requires associating cyber observable artifacts, such as IP addresses, URIs, and file hashes, with cyber threat tactics, techniques, and procedures. Unfortunately, most CTI data is compartmentalized across multiple organizations and cannot be shared due to the legal and reputational risk with cyber threat being associated with the entity. The approach to solving this problem inovlves using a distributed ledger with anonymous token spending and authentication. This allows a consortium of semi-trusted entities to share the workload of curating CTI for a threat sharing community’s cooperative benefit.

Huff, Philip↗