Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Control Systems Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 325 records · Page 18

Evaluation of Digital Twin Modeling and Simulation

A digital twin has intelligent modules that continuously monitor the condition of the individual components and the whole of a system. Digital twins can provide nuclear power plants (NPP) operators an unprecedented level of monitoring, control, supervision, and security by contributing a greater volume of data for more comprehensive data analysis and increased accuracy of insights and predictions for decision making throughout the entire NPP lifecycle. NPP operators and managers have historically relied on limited, second hand or incomplete data. With proper implementation, digital twins can provide a central hub of all intel that allows for a multidisciplinary view of an NPP. This equips operators and managers with the ability to have more information, context, and intel that can be used for greater granularity during planning and decision making. Digital twins can be used in many activities as the technology has many different concepts surrounding it. From the various definitions of a digital twin within the industry, digital twins can be differentiated by levels of integration/automation. The three main models include digital model, digital shadow, and digital twin. Digital twins offer many potential advancements to the nuclear industry that could reduce costs, improve designs, provide safer operation, and improve their overall security.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Proceedings of the NASA Aerospace Technology Symposium 2002

Reports are presented from the NASA Aerospace Technology Symposium 2002 on the following: Geo-Referenced Altitude Hold For Latex Ballons; NASA Spaceport Research: Opportunities For space Grant and EPSCoR Involvement; Numerical Simulation Of The Combustion Of Fuel Droplets: Applications, Aircraft/Spacecraft Flight Control, Guidance Navigation; Expertise In System Dynamics and Control, Control Theory and Aerospace Education Ooutreach Opportunities; and Technology For The Improvement Of General Aviation Security: A Needs Assessmemt.

Bowen, Brent D.↗

[Network Design of the Spaceport Command and Control System]

I helped the Launch Control System (LCS) hardware team sustain the network design of the Spaceport Command and Control System. I wrote the procedure that will be used to satisfy an official hardware test for the hardware carrying data from the Launch Vehicle. I installed hardware and updated design documents in support of the ongoing development of the Spaceport Command and Control System and applied firewall experience I gained during my spring 2017 semester to inspect and create firewall security policies as requested. Finally, I completed several online courses concerning networking fundamentals and Unix operating systems.

Teijeiro, Antonio↗

Cyber-Physical Power Systems Protection: The Byzantine Cybersecurity Framework

Cybersecurity of smart grids have been topic of much interest in recent years. As this critical infrastructure operation increases dependency on automated processes and controls, exposure to cyber-physical threats become inevitable. Considering cyber-physical security of the grid, much focus of attention has been made towards smart grids real-time monitoring solutions, including the state estimation process. Analyzing the relevant literature, one can note though that seldom research has been done on cyber-physical security of smart grids protection systems. Protection systems have intangible value towards grid reliability. This paper presents a cybersecurity framework for smart grids protection systems. A physics-based inspired machine learning solution is at the core process of the framework. Processed relay inputs and outputs are used by a deep predictive coding network. Formal models, a quasi-static state estimator, provides an oracle when low confidence decision is reached. Evolving knowledge is derived through reinforcement learning. Implementation aspects considering the Pacific Northwest National Laboratory Electricity Infrastructure Operations Center are presented. Built as an extra control layer to protection systems, without hard-to-derive parameters, highlights potential aspects towards real-life applications.

Bretas, Arturo Suman↗

Dynamic verification of very large space structures

The dynamic verification of spacecraft relies heavily on ground-based tests. These tests usually simulate flight environments or validate analytical models used in establishing design loads and in designing control algorithms. They also provide security against failures resulting from unanticipated or unmodeled hardware behavior. Future orbital antennas, space stations, and solar power systems are likely to be of sizes difficult to test using current ground test technology. In addition to size, other factors such as low natural frequencies, lightweight construction, and the presence of many structural joints, cause significant sensitivity of the test process to the earth-gravity environment. Yet, accuracy requirements on the verification process will be more stringent because of modern flexible-structure control approaches. This paper describes some of the problems and discusses research on potential solutions. The importance of an integrated ground test, analysis, and flight test program is emphasized. An ongoing research program of this type focusing on a 60-meter, deployable, truss-beam test article is described.

Hanks, B. R.↗

Autonomous System Subversion Tactics: Prototypes and Recommended Countermeasures

One of the fielding requirements for Advanced and Small Modular Reactors (AR/SMR) is the ability to support remote and autonomous operations. Autonomous Control Systems (ACS) are found on platforms such as Autonomous Space Vehicles, Cruise Missiles, and advanced driver-assistance systems. Each of these ACS implementations depends upon a set of decision support subsystems responsible for supporting Autonomous Mission Managers (names vary based upon field and author preferences). These Autonomous Mission Managers receive inputs from system sensors (e.g., LIDAR collection from an automobile travelling down a street; transients from a nuclear reactor), and perform a set of classifications (e.g., Red Traffic Light; Small Pedestrian at 10m; Load Rejection; Single Coolant Pump Trip), and then use these classifications in combination with recommendation algorithms to achieve platform goals (e.g., Stop the Vehicle at the Traffic Light, Avoid the Small Pedestrian; Trip the Reactor to prevent a Safety Event). The design, implementation, and fielding of an ACS capability will alter the cyber-attack surface such that existing risk management plans will need to be updated to include how to protect and defend against data-science and decision-support-system attack classes. These attack classes would include protection of the design and training environments where algorithm selection and testing and training data would be obvious attack vectors. These attack classes would also require an informed set of detection and response procedures to identify anomalous behaviors and document best practices for anomaly assessment and vulnerability mitigation and remediation. Last year we published a Cyber Threat Assessment Methodology for Autonomous and Remote Operations for AR/SMRs along with a companion publication on Cyber Attack and Defense Use Cases. The focus of the methodology was on describing and enumerating ACS processes, components, and functions such that security engineers could: evaluate subversion options against the target; identify threat actor attributes and capabilities derived from each subversion option; and identify security controls and response countermeasures. The Use Cases document offered detailed methodology examples including an assessment of a Military Base SMR, an Autonomous System Decision Loop, and implementation of AR/SMR Machine Learning algorithms. Our proposal at the end of last year was to focus on implementation of subversion prototypes related to the last Use Case area: AR/SMR Machine Learning (ML) Algorithms. We included six attack scenarios in our Use Cases paper: a Poisoning Attack against ML functions implemented using an FPGA; a Trojaning Attack against ML classifiers exploiting the excitability of Nuclear Engineers; a Backdooring Attack against ML Training environments to ensure persistence of an attack vector; a False Positive Evasion Attack against multi-factor Access Control Systems using clever inputs; an Inference Attack against ML models by an Insider with access to the Operational environment; and an Adversarial Reprogramming Attack against a Material Access Control Video Surveillance System. At the beginning of this year these six attack scenarios were provided to our research teams at Georgia Tech and Idaho State University and each team successfully implemented a subversion attack against a ML implementation to include transient misclassifications. While this is a notable outcome from this type of research, this paper offers the reader insight into not only how to structure and execute these types of attacks, but into the thought process behind how the researcher investigated the problem space, performed initial algorithm implementation, and the trial-and-error behind arriving at the successful subversion prototypes. We include in this paper a set of associated Scenarios on how these subversion prototypes could be implemented and an initial set of guidance for AR/SMR architects, Nuclear Regulators, and Cyber Defenders to implement awareness and defense capabilities into their current operational portfolios.

42 ENGINEERING↗

A Solar-assisted Voltage Optimization Method for Transmission Solar Network Power System

This paper proposes a new formulation and solution algorithm that uses transmission level solar inverters to address the security-constrained optimal power flow (SCOPF) problem. The goal is to stabilize voltage fluctuations in transmission networks in base case and contingency scenarios, by using bulk solar power plant with a minimal number of post-contingency corrections. To achieve this goal, a two-stage volt/var optimization method is proposed to first correct all voltage violations with the volt-var alternating current optimal power flow (ACOPF) algorithm for a base case. Then a linearized SCOPF volt-var control algorithm is proposed to identify the corrective actions for all potential voltage violations in all contingency scenarios. The proposed method was tested and validated on a modified IEEE 118-bus system with solar photovoltaic (PV) data.

Photovoltaic, Volt/Var Control↗

Cybersecurity Methods for Grid-Connected Power Electronics

The present work shows a secure-by-design process, defense-in-depth method, and security techniques for a secure distributed energy resource. The distributed energy resource is a cybersecure, solar inverter and battery energy storage system prototype, collectively called the Cybersecure Power Router. Consideration is given to the use of the Smart Green Power Node for a foundation of the present work. Metrics for controller security are investigated to evaluate firmware security techniques. The prototype's ability to mitigate, respond to, and recover from firmware integrity degradation is examined. The prototype shows many working security techniques within the context of a grid-connected, distributed energy resource. Further work is expected in the Cybersecure Power Router project. Consideration is also provided for the migration of the present research and the Smart Green Power Node to realize a pre-production prototype.

Moquin, Stephen Joe↗

Facility Cybersecurity Framework Best Practices

Federal facilities are increasingly adopting automation and connecting to the Internet creating an energy-internet-of-things environment that converges operational technology (OT) and information technology (IT). Today's buildings increasingly weave together networked sensors and cyber and physical systems that enable data to be collected, aggregated, exchanged, stored and monetized in new ways. Building technological advances have created new energy technology, services, markets and value creation opportunities (e.g. transactive energy, two-way grid communications, machine learning, and increased use of renewable and distributed energy resources). But as larger data sets are being exchanged at faster speeds between an increasing number of OT systems, it becomes more difficult to protect the security of the data lifecycle and the physical equipment it interacts with. These challenges are especially difficult to overcome because the economic and environmental gain (interoperability, big data, social networks and ubiquitous information sharing) are driving these prominent trends in the digital age. Often cybersecurity is an afterthought. The U.S. Department of Energy’s (DOE) Federal Energy Management Program (FEMP) funded the Pacific Northwest National Laboratory (PNNL) to develop various cybersecurity tools, trainings, and reports to aid federal facility managers – and other building owners and operators – in better applying frameworks and lessons learned from the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF), risk management framework (RMF), DOE’s cybersecurity capability maturity model (C2M2), and a wide variety of industry best practices and guidance documents (i.e., NIST 800 series, Department of Defense United Facilities Criteria). This set of tools, collectively known as the FEMP Facility-Related Control System Cyber Toolkit (FRCS Cyber Toolkit)2, is focused on cybersecurity concerns from facility-related control systems and other operational technology (OT), such as industrial control systems (ICS). The FRCS Cyber Toolkit can be applied across six of the sixteen critical infrastructure sectors designated by the Department of Homeland Security, including government facilities, healthcare and public health, commercial facilities (e.g., public assembly, offices, lodging), financial services (e.g., banking and insurance), emergency services (e.g., fire and police stations), and information technology. With increasingly converged IT and OT systems, it is crucial to address OT cybersecurity considerations and assess how the seam of these two systems could impact the overall cybersecurity posture of a facility. The objective of this report is to provide an overview of the best possible method to use FRCS Cyber Toolkit (section 2.0) and distilled cybersecurity best practices for the federal facilities to address growing non-linear cyber threats (section 3.0). Recommendations in this document are aggregated from several NIST and other documents (see Appendix A for additional details).

97 MATHEMATICS AND COMPUTING↗

ModuleOT: A Hardware Security Module for Operational Technology: Preprint

With increasing penetration levels of distributed energy resources (DERs) on the distribution grid, as well as new technological advancements in the cyber space, new cyberattack vectors are being introduced, and the available attack surface is constantly increasing. Despite this increasing risk, the standard IEEE 1547-2018 does not yet recommend cybersecurity measures for DERs. To address this and to better protect data on the distribution grid - from the standpoints information security as well as operational security - ModuleOT has been developed. The module aims to significantly reduce cyberattack vectors by improving data privacy for user applications. This is accomplished by performing the core functions of encryption, authentication, authorization, certificate management, and user access control. The module integrates a custom security application with hardware cryptographic acceleration. The application secures all communications using Transmission Control Protocol over Internet Protocol (TCP/IP). These include the three most commonly used communications protocols for power systems information exchange: Modbus, Distributed Network Protocol 3 (DNP3), and Smart Energy Profile 2.0 (SEP2.0). These three protocols are also supported by IEEE 1547-2018 for all DER devices. This paper tests the data encryption/decryption feature on a physical networking test bed with emulated Modbus devices reporting grid data and presents the results.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cybersecurity Considerations for Grid-Connected Batteries with Hardware Demonstrations

The share of renewable and distributed energy resources (DERs), like wind turbines, solar photovoltaics and grid-connected batteries, interconnected to the electric grid is rapidly increasing due to reduced costs, rising efficiency, and regulatory requirements aimed at incentivizing a lower-carbon electricity system. These distributed energy resources differ from traditional generation in many ways including the use of many smaller devices connected primarily (but not exclusively) to the distribution network, rather than few larger devices connected to the transmission network. DERs being installed today often include modern communication hardware like cellular modems and WiFi connectivity and, in addition, the inverters used to connect these resources to the grid are gaining increasingly complex capabilities, like providing voltage and frequency support or supporting microgrids. To perform these new functions safely, communications to the device and more complex controls are required. The distributed nature of DER devices combined with their network connectivity and complex controls interfaces present a larger potential attack surface for adversaries looking to create instability in power systems. To address this area of concern, the steps of a cyberattack on DERs have been studied, including the security of industrial protocols, the misuse of the DER interface, and the physical impacts. These different steps have not previously been tied together in practice and not specifically studied for grid-connected storage devices. In this work, we focus on grid-connected batteries. We explore the potential impacts of a cyberattack on a battery to power system stability, to the battery hardware, and on economics for various stakeholders. We then use real hardware to demonstrate end-to-end attack paths exist when security features are disabled or misconfigured. Our experimental focus is on control interface security and protocol security, with the initial assumption that an adversary has gained access to the network to which the device is connected. We provide real examples of the effectiveness of certain defenses. This work can be used to help utilities and other grid-connected battery owners and operators evaluate the severity of different threats and the effectiveness of defense strategies so they can effectively deploy and protect grid-connected storage devices.

25 ENERGY STORAGE↗

Frequency Support From Electric Vehicles for Advancing Renewable Energy Integration

The integration of renewable energy resources (RERs) in the modern power grid is increasing rapidly because of aggressive decarbonization goals, lower costs, and increased government investment. However, higher penetrations of inverter-based generation can lead to frequency stability issues because of reduced system inertia. This paper develops a framework for quantifying the contribution of electric vehicles (EVs) toward providing frequency support to the grid and thus increasing the penetration limit of renewable energy resources (RERs). EVs are considered to provide both inertial response and primary frequency response support to the grid. A stochastic approach incorporating the uncertainties associated with the behavior of EVs is developed to derive the discharge limit of EV aggregators. A multi-machine system frequency response (MM-SFR) model is developed, which incorporates the dynamic virtual inertia and droop coefficients of EV aggregators derived from the EV control modules. Frequency security constraints are developed from this MM-SFR model, which, along with the converter voltage security and low voltage ride-through constraints, are integrated within a nonlinear optimization framework to determine the RER integration limit. Here, the efficacy of the proposed approach is validated using the RTS-GMLC test system.

25 ENERGY STORAGE↗

Microgrid Modeling for Stability Analysis

Here this document is a summary of a report prepared by the IEEE PES Task Force (TF) on Microgrid (MG) Dynamic Modeling, IEEE Power and Energy Society, Tech. Rep. PES-TR106, 2023. In this paper, the major issues and challenges in microgrid modeling for stability analysis are discussed, and a review of state-of-the-art modeling approaches and trends is presented. In the context of the IEEE 1547 standard, the document covers issues associated with component models for MG dynamic studies and simulations, including generator and grid modeling, full and average converter models, unbalanced and balanced system conditions, dynamic and static loads, protection requirements, and detailed and simplified controls considering communications delays, packet losses, and security issues. Considering the future integration of grids and MGs to form broad integrated networks, a discussion is presented of the use of phasor vis-à-vis electromagnetic transient simulation tools for MG dynamic stability studies, as well as modeling scale-up issues and MG equivalent models. Specifically white-, grey-, and black-box models, are presented. This TF paper and companion report constitute a modeling guide for R&D groups working on developments and standards of MGs with a focus on stability issues.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Advanced Reactor Safeguards Program Roadmap

The Advanced Reactor Safeguards (ARS) program was established in 2020 as part of appropriations for the Advanced Reactor Demonstration Program (ARDP) through the Office of Nuclear Energy in the Department of Energy. The goal of this program is to help address near term challenges that advanced nuclear reactor vendors face in meeting domestic Material Control and Accountancy (MC&A) and Physical Protection System (PPS) requirements for U.S. construction. Existing regulations for safeguards and security, as outlined in the Code of Federal Regulations, were written for large light water reactors, and some of the requirements are not suited to smaller, safer advanced reactor designs. The ARS program seeks to remove roadblocks in the deployment of new and advanced reactors by solving regulatory challenges, reducing safeguards and security costs, and utilizing the latest technologies and approaches for robust plant monitoring and protection. Safeguards and Security by Design (SSBD), or the consideration of safeguards and security requirements early in the design process, is an overarching principle that guides this program. This roadmap discusses the goals of the ARS program, current research, and program plan for the next five years.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

FY 2025 Multidimensional Data Correlation Platform: Unified Software Architecture for Advanced Materials and Manufacturing Technologies Data Management and Processing

The Advanced Materials and Manufacturing Technologies (AMMT) program continues to advance a data-driven approach to demonstrate the utility of additive manufacturing for fabricating components for nuclear applications. A key scientific goal is to leverage data to better understand manufacturing outcomes and thereby improve the performance, reliability, and lifespan of nuclear components. Ultimately, this effort supports the development of standards for certification and qualification of additively manufactured components, enabling broader industry adoption. In support of this objective, the AMMT program is building and deploying a data management platform to record, index, analyze, and make available the manufacturing data generated across the AMMT program. In FY 2023, the team conceptualized the architecture of the platform and, in FY 2024, deployed the first functional version at the Oak Ridge National Laboratory (ORNL) Manufacturing Demonstration Facility (MDF). In FY 2025, the platform was officially opened to all AMMT members. To enable this expansion, core modifications and enhancements were developed, including improvements to the user interface and workflows for data entry and retrieval. Most notably, robust security and access control mechanisms were implemented to protect data and manage information sharing. This effort featured a logging system, protected views, and controlled access mechanisms. This report documents these enhancements and the transition of the platform into program-wide use.

36 MATERIALS SCIENCE↗

Aeronautics and Space Report of the President: Fiscal Year 1996 Activities

Topics considered include: (1) Space launch activities: space shuttle missions; expendable launch vehicles. (2) Space science: astronomy and space physics; solar system exploration. (3) Space flight and technology: life and microgravity sciences; space shuttle technology; reuseable launch vehicles; international space station; energy; safety and mission assurance; commercial development and regulation of space; surveillance. (4) Space communications: communications satellites; space network; ground networks; mission control and data systems. (5) Aeronautical activities: technology developments; air traffic control and navigation; weather-related aeronautical activities; flight safety and security; aviation medicine and human factors. (6) Studies of the planet earth: terrestrial studies and applications: atmospheric studies: oceanographic studies; international aeronautical and space activities; and appendices.

Source record↗

Architecture of High-Altitude Operations (HAO) Discovery and Synchronization Service (DSS)

The aviation industry is evolving at an unprecedented pace, necessitating the development of efficient, secure, and interoperable systems to manage increasingly complex air traffic. Moreover, the demand for High-Altitude Operations (HAO) is increasing. Furthermore, air traffic control services are limited in HAO environments. HAO industry participants will need airspace access and flexibility to perform their missions in this airspace that provides provisions for scalability. The Discovery and Synchronization Service (DSS) will be a cornerstone of the HAO ecosystem, enabling the effective sharing of critical airspace data, including operational intent, aircraft trajectories, and airspace usage among various stakeholders and operators. The DSS architecture addresses these challenges with a distributed, decentralized, and interoperable system that facilitates seamless integration across diverse airspaces. It prioritizes secure data exchange while safeguarding data ownership. This white paper presents the vision, architecture, and benefits of the DSS for HAO, underscoring its potential to streamline operations, reduce redundancies, and establish a foundation for safe and efficient airspace management.

HAO↗