Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Critical Infrastructure Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Communication-efficient certificate revocation management for Advanced Metering Infrastructure and IoT Integration

Advanced Metering Infrastructure forms a communication network for the collection of power data from smart meters in Smart Grid. As the communication between smart meters could be secured utilizing public-key cryptography, however, public-key cryptography still has certain challenges in terms of certificate revocation and management particularly related distribution and storage overhead of revoked certificates. To address this challenge, in this work, we propose a novel revocation management approach by utilizing cryptographic accumulators which reduces the space requirements for revocation information significantly and thus enables efficient distribution of such information to all smart meters. We implemented the proposed approach on both ns-3 network simulator and a testbed. We demonstrated its superior performance with respect to traditional methods for revocation management.

97 MATHEMATICS AND COMPUTING↗

Data transfer for STAR grid jobs

The Solenoidal Tracker at RHIC (STAR) is a multipurpose experiment at the Relativistic Heavy Ion Collider (RHIC) with the primary goal to study the formation and properties of the quark-gluon plasma. STAR is an international collaboration of member institutions and laboratories from around the world. Yearly data-taking period produces PBytes of raw data collected by the experiment. STAR primarily uses its dedicated facility at BNL to process this data, but has routinely leveraged distributed systems, both high throughput (HTC) and high performance (HPC) computing clusters, to significantly augment the processing capacity available to the experiment. The ability to automate the efficient transfer of large data sets on reliable, scalable, and secure infrastructure is critical for any large-scale distributed processing campaign. For more than a decade, STAR computing has relied upon GridFTP with its x509-based authentication to build such data transfer systems and integrate them into its larger production workflow. The end of support by the community for both GridFTP and the x509 standard requires STAR to investigate other approaches to meet its distributed processing needs. In this study we investigate two multi-purpose data distribution systems, Globus.org and XRootD, as alternatives to GridFTP. We compare both their performance and the ease by which each service is integrated into the type of secure and automated data transfer systems STAR has previously built using GridFTP. The presented approach and study may be applicable to other distributed data processing use cases beyond STAR.

73 NUCLEAR PHYSICS AND RADIATION PHYSICS↗

Authentication of smart grid communications using quantum key distribution

Smart grid solutions enable utilities and customers to better monitor and control energy use via information and communications technology. Information technology is intended to improve the future electric grid’s reliability, efficiency, and sustainability by implementing advanced monitoring and control systems. However, leveraging modern communications systems also makes the grid vulnerable to cyberattacks. Here we report the first use of quantum key distribution (QKD) keys in the authentication of smart grid communications. In particular, we make such demonstration on a deployed electric utility fiber network. The developed method was prototyped in a software package to manage and utilize cryptographic keys to authenticate machine-to-machine communications used for supervisory control and data acquisition (SCADA). This demonstration showcases the feasibility of using QKD to improve the security of critical infrastructure, including future distributed energy resources (DERs), such as energy storage.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Lithium-Ion Battery Supply Chain for E-Drive Vehicles in the United States: 2010–2020

Understanding the battery supply chain is particularly important for the strategic planning and development of a battery recycling infrastructure to secure critical materials supply and enable a circular economy. Argonne has been tracking plug-in electric vehicle (PEV) sales in the United States (U.S.) by make and model since December 2010, when the Chevrolet Volt and Nissan Leaf were first sold in the U.S. Building on detailed monthly sales data, this report summarizes the manufacturing and production locations of lithium-ion (Li-ion, or LIB) battery cells and packs by make and model for PEVs sold in the U.S. from 2010 to 2020. It also summarizes the annual and cumulative Li-ion battery capacity installed in hybrid electric vehicles (HEVs) sold in the U.S. Overall, there are about 20 different battery cell and pack manufacturers, which are currently supplying about 20 gigawatt-hours (GWh) of batteries annually for the U.S. PEV market. Panasonic and LG Chem are the largest cell suppliers to the U.S. market. Beyond the U.S, South Korea and Japan are major countries supplying PEV batteries to the U.S. market.

25 ENERGY STORAGE↗

Toward Common Weakness Enumerations in Industrial Control Systems

Here, the storyline of MITRE’s common weakness enumeration framework illustrates how the security and privacy technical community can collaborate/cooperate with policy makers to advance policy, giving it specifics and filling gaps of technical knowledge to improve security and resilience of critical infrastructure.

42 ENGINEERING↗

Implementation Aspects of Smart Grids Cyber-Security Cross-Layered Framework for Critical Infrastructure Operation

Communication networks in power systems are a major part of the smart grid paradigm. It enables and facilitates the automation of power grid operation as well as self-healing in contingencies. Such dependencies on communication networks, though, create a roam for cyber-threats. An adversary can launch an attack on the communication network, which in turn reflects on power grid operation. Attacks could be in the form of false data injection into system measurements, flooding the communication channels with unnecessary data, or intercepting messages. Using machine learning-based processing on data gathered from communication networks and the power grid is a promising solution for detecting cyber threats. In this paper, a co-simulation of cyber-security for cross-layer strategy is presented. The advantage of such a framework is the augmentation of valuable data that enhances the detection as well as identification of anomalies in the operation of the power grid. The framework is implemented on the IEEE 118-bus system. The system is constructed in Mininet to simulate a communication network and obtain data for analysis. A distributed three controller software-defined networking (SDN) framework is proposed that utilizes the Open Network Operating System (ONOS) cluster. According to the findings of our suggested architecture, it outperforms a single SDN controller framework by a factor of more than ten times the throughput. This provides for a higher flow of data throughout the network while decreasing congestion caused by a single controller’s processing restrictions. Furthermore, our CECD-AS approach outperforms state-of-the-art physics and machine learning-based techniques in terms of attack classification. The performance of the framework is investigated under various types of communication attacks.

cross-layered↗

RePOWERD: Restoration of Power Outage from Wide-area Severe Weather Disruptions

The purpose of the RePOWERD project is to develop a probabilistic and a simulation based power restoration forecasting model for tropical storms based on geographic utility service areas, impacts to energy infrastructures and transportation networks, time-varying customer outage number, crew information (i.e., crew size, crew staging requirements), and utility restoration plans. Energy infrastructure is a critical lifeline essential for the United States’ national and economic security. Like other critical infrastructures, this infrastructure is aging and is at a high risk of damages from extreme weather events. Based on the number of reported outages in EAGLE-I during 2020 and 2021, it is evident that the current energy infrastructure is not equipped to handle extreme event impacts and will contribute to significant outages. From a resilience perspective, it is essential to forecast restoration time in the event of a severe weather induced power outage to assist the US Department of Energy, emergency managers, and first responders with resource planning. This project contributes to this crucial need. This report details the models, that were developed in this pilot study, to determine the rate of restoration and estimated time of restoration (ETR) during tropical storm events within counties and utility service areas based on damage to energy infrastructures and total number of customers experiencing outages.

24 POWER TRANSMISSION AND DISTRIBUTION↗

CI-MOR Final Report: Analysis and Validation of Critical Infrastructure Models using Model Order Reduction

This report summarizes the research and capabilities developed as part of the project “Analysis and Validation of Critical Infrastructure Models using Model Order Reduction” (CI-MOR) LDRD project. CI-MOR research enables the solution of large, complex optimization models that naturally arise in national security challenges involving critical infrastructures. Specifically, CI-MOR researchers developed methods to (1) rigorously approximate complex, nonlinear optimization formulations, (2) identify alternative near-optimal solutions, (3) accelerate optimization workflows used for complex applications, and (4) rigorously integrate domain knowledge in stochastic-process models. This report provides an overview of the research done in CI-MOR, and we describe application exemplars used to illustrate CI-MOR capabilities. Furthermore, we describe the software developed by CI-MOR that researchers can leverage to analyze new applications.

97 MATHEMATICS AND COMPUTING↗

Building Cybersecurity Educational Materials for Students: The Windfarm Capture-The-Flag Exercise

Securing and protecting critical infrastructure in an increasingly digital world is vital but it is all too often an afterthought. It is especially important that students become aware of internet safety and security at an early age. However, the availability of interactive and educational cybersecurity material targeted toward students is minimal in the United States. Here we show an example of interactive cyber security educational material that an educator can use in their classroom to encourage students to think about the interaction between real-world physical objects, cyber security, and information security. By putting together a “capture-the-flag” exercise, students can see in real time how hackers and cybercriminals exploit vulnerabilities and gain access information. The students try to “capture” the “flag” (i.e., information) in the wind farm by looking for oddities in the code or by taking advantage of weaknesses in everyday protocols. Students can also see how cybersecurity interacts with the power grid through the wind farm project scenario and how a hacker could cause serious problems to a critical infrastructure sector. Our goal for the project is getting students interested in cybersecurity and help them develop an awareness of how important having robust security systems is. We also hope that this project demonstrates the importance of introducing these concepts early and inspires others to create similar projects geared toward students.

97 MATHEMATICS AND COMPUTING↗

End-to-End Encryption for Cyber-Physical Systems Using Fully Homomorphic Encryption

Cyber-physical systems require reliable, safe, and secure control of critical infrastructure, combining computational and networking capabilities, which heighten the risk of cyber attacks. These attacks can disrupt the physical process, causing unforeseen consequences. One solution is the use of fully homomorphic encryption (FHE) to protect the control loop, allowing for secure computations and communications without compromising signal and control system privacy. The challenge with FHE, however, is its requirement for inputs to be integers. This presentation introduces a modified Learning With Errors (LWE) FHE approach that encodes control system dynamics and signals into integers. Our proposed scheme leverages a generalized LWE encoding function and modifies the Gentry-Sahai-Waters gadget decomposition tool to encrypt the control system. Using the modified LWE scheme, we formalize a fully encrypted control system, supported by simulated results.

97 MATHEMATICS AND COMPUTING↗

Encrypted Control Using Modified Learning With Errors-based Schemes

Cyber-physical systems (CPSs) require reliable, safe, and secure control of critical infrastructure, combining computational and networking capabilities, which heighten the risk of cyber attacks. These attacks can disrupt the physical process, causing unforeseen consequences. One solution is the use of fully homomorphic encryption (FHE) to protect the control loop, allowing for secure computations and communications without compromising signal and control system privacy. The challenge with FHE, however, is its requirement for inputs to be integers. This paper introduces a modified Learning With Errors (LWE) FHE approach that encodes control system dynamics and signals into integers. Our proposed scheme leverages a generalized LWE encoding function and modifies the Gentry-Sahai-Waters (GSW) gadget decomposition tool to encrypt the control system. Using the modified LWE scheme, we formalize a fully encrypted control system, supported by simulated results.

42 - ENGINEERING↗

Cyber Informed Engineering (CIE) Principles Slide Presentation [Slides]

This document describes the concept and application of Cyber-Informed Engineering (CIE), a methodology that integrates cyber threat awareness into all stages of the systems engineering life cycle. It delineates how CIE enhances the security posture of critical infrastructure systems, which are increasingly targeted by sophisticated cyber threats. The exposition proceeds to methodically walk through the twelve foundational principles of CIE, each serving as a strategic guidepost for embedding cybersecurity into the fabric of system design, development, operation, and maintenance. The principles highlight the importance of proactive and comprehensive security measures that span from risk assessment to continuous improvement, ensuring that systems are not only designed with security in mind but are also resilient in the face of evolving cyber threats.

42 ENGINEERING↗

Cybersecurity Framework Tool

The Cybersecurity Framework Tool is a web-based tool that provides five (5) concurrent and continuous functions to identify, detect, protect, respond and recover from cyber security threats to critical infrastructure.

Mylrea, Michael↗

Reverse Engineering of Medical Devices for Innovation and Advancement in Healthcare

• Medical technology is rapidly evolving and introducing new functionality and methodologies that suggest a higher risk for common vulnerability exposures (CVE) • Introduction of functionalities like Wi-Fi, Bluetooth, and internet connectivity require devices to be rigorously evaluated for vulnerabilities • Subsequently like many other fields cell-phone interconnectivity suggests a significantly higher level of risk to critical infrastructure and data security

Baldwin, David [Savannah River National Laboratory↗

Project: Corbomite - Product: ConsoleWorks REACT

TDi Technologies presents ConsoleWorks REACT, an advanced platform designed to tackle the complexities of cyber and operational risk assessment. This comprehensive solution goes beyond asset-focused approaches by considering the impact of both assets and people have on the security and operation of critical infrastructure, specifically targeting preventing gird mis-operation by evaluating real-time human interaction or commands with critical assets. The hypothesis suggests that by integrating the assessment of user commands into the overall risk assessment process, organizations can make more informed decisions, prioritize resources effectively, and respond promptly to potential threats. This hypothesis forms the basis for the development of a proactive and holistic risk management approach that is more comprehensive and context aware than traditional models which only look at assets, patch levels, configuration and threat intel by collecting that information off the network vs directly from the asset, human, and human interaction all in real-time. ConsoleWorks' unique man-in-the-middle architecture is a key feature that sets it apart in the cybersecurity landscape. This architecture enables the real-time observation, enforcement, and commands or interaction risk transparency of user interaction with critical infrastructure to be risk mitigated and audited as they are aggregated with device and human risk factors for a more comprehensive risk threat score across a device or group of devices. This architecture allows ConsoleWorks to act as a secure intermediary between users and critical assets, monitoring all interactions and ensuring that only authorized commands are sent to the asset to be executed. This not only enhances security but also provides a comprehensive audit trail of all user activities, contributing to compliance efforts and facilitating incident investigation and risk management. By integrating this unique architecture with our comprehensive risk assessment methodology, ConsoleWorks REACT provides a powerful solution for managing cyber and operational risks, enabling organizations to maintain a robust security posture and effectively mitigate potential threats. To that end, the primary objective of this project was to research and develop a robust solution that enables the energy industry to mitigate the risks associated with human actions that can compromise the security or operations of assets critical to energy delivery, generation, transmission and operation. ConsoleWorks REACT plays a pivotal role in achieving this goal by leveraging its unique capabilities to monitor and track all user activity. Through its Zero Trust approach, which emphasizes continuous verification, the platform ensures secure access to assets and serves as the centralized human response and notification platform for addressing cyber and operational issues.

97 MATHEMATICS AND COMPUTING↗

Cyber Resilience and Social Equity: Twin Pillars of a Sustainable Energy Future

This paper examines the intersection of security and accessibility within energy systems amidst the rise of grid modernization and digitization, especially considering the regulatory changes and the imperatives of inclusive energy strategies. It addresses the dual need for secure, resilient infrastructure and a commitment to mitigate energy poverty while maintaining equitable access to energy. Amid escalating cybersecurity and physical threats, the paper advocates for sustainable energy delivery systems that ensure robust defenses without compromising the goals of reducing energy poverty and ensuring energy security. This paper identifies the pressing need for Cyber-Informed Engineering (CIE) and Secure-by-Design (SbD) principles, highlighting how these strategies can protect critical infrastructure and democratize access to secure energy, particularly for disadvantaged communities. The analysis underscores the challenges presented by the expansion of attack surfaces, interoperability requirements, and grid-edge analytics, offering innovative solutions that leverage advanced technologies and data-driven insights. Furthermore, this paper addresses the workforce development gap, emphasizing the necessity for public-private partnerships and vendor engagement in creating a skilled cybersecurity workforce. This paper has a dual focus on both the technological aspect of cybersecurity and the social dimension of equity within the context of sustainable energy development. It suggests a comprehensive examination of how these two critical elements interact and support the overarching goal of a sustainable energy future.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗