Engineering PapersSearch

SEARCH · Engineering Papers

Results for “Physical Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

2025 Intern Poster

The Hot Fuel Examination Facility (HFEF) at the Materials and Fuels Complex (MFC) houses the largest U.S. inert atmosphere hot cell for nuclear material research. Key features include the precision gamma scanning (PGS), Fuel Accident Condition Simulator (FACS), Neutron Radiography Reactor (NRAD), and the focus of this project, the Metallograph Loading Cell (MET Cell). The MET Cell performs tests on spent nuclear fuel, such as microhardness testing, microscopy, and neutron radiography. However, the MET Cell’s existing pressure and lighting control systems are outdated and inefficient, with inadequate documentation for system changes over time. This project aims to design a new automated control system for the MET Cell, ensuring longevity (minimum ten years), ease of troubleshooting/repair, and integration into the building monitoring system. The design process addressed challenges such as space restrictions, varied voltages within enclosures, sourcing new components, and security limitations. Compliance with NFPA 70, UL508A, MFC Physical Security, and INL Engineering standards was essential. The project involves repurposing an existing PLC to manage lighting and pressure control using digital and analog signals, simplifying wiring, and ensuring thorough documentation for future reference.

42 - ENGINEERING

Xenith Scalable Security Economics

These slides present a high level overview of an ongoing project sponsored by NNSA. The project is focused on economic analysis of physical security design of micro reactors. The slides will be presented to NNSA's office of International Nuclear Security (INS) at a program update meeting on May 28th, 2025.

98 - NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL

Security Licensing Basis Framework Development

This report summarizes a technology-inclusive and performance-based method to determine the physical security licensing basis for a commercial nuclear reactor under the proposed 10 CFR 73.100 for Part 53 licensees. The method focuses on the identification of security functions, the contributing security systems and programs to meet those functions, the identification of security events that will provide the foundation for the security licensing basis and includes a risk-informed performance-based defense in depth adequacy method. The method can also be employed to justify performance-based alternative measures to traditional security requirements found in 10 CFR 73.55.

98 - NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL

Capability Building Progression of an Insider Threat Mitigation Program at an International Research Reactor

The nuclear industry recognizes the difficulties involved in developing effective managerial and leadership skills in a highly technical and proficient workforce such as that found in nuclear facilities. Implementing an insider threat mitigation program (ITMP) within the nuclear industry is a complex and ongoing process that demands a comprehensive understanding of human behavior, an organization’s security culture, and rigorous regulatory requirements yet also accounts for facility characteristics, physical security, material flow, and activities involving nuclear material. Given the high-consequence nature of research reactor operations, even minor lapses can lead to safety, security, and reputational risks. An effective ITMP requires a defense-in-depth approach that incorporates behavioral analysis, robust vetting procedures, continuous monitoring, and cross-disciplinary coordination. It must also promote a culture of vigilance and accountability at all levels up to and including executive leadership but be flexible enough to adapt to evolving global threats and technological advances. Insider threat mitigation is not a one-time effort but rather a sustained commitment to excellence in safety and security. Establishing a culture in which personnel proactively report incidents and issues that could affect nuclear safety and security is vital to maintaining a safe and secure operational environment. This document was developed to guide senior management and research reactor organizations in creating comprehensive programs to effectively manage and mitigate insider threat behaviors and actions. It focuses on the key pillars of an effective ITMP, including the national legal framework, security culture, preventive and protective measures, cyber security, and performance evaluation. By using a systematic approach during implementation, facilities can foster environments conducive to insider threat detection and support long-term program sustainability. The document also provides strategies for improving communication across all levels of an organization, helping to eliminate barriers that hinder the development of robust ITMPs and enhance overall security culture. In today’s organizations, the concept of leveraging safety and security culture lessons to facilitate knowledge transfer is rapidly evolving to expedite insider threat management and security culture improvements. This document outlines the rationale for evaluating an ITMP based on national customs, culture, and stakeholders. The elements are all germane to reliability and trustworthiness and relate to security concerns that states may encounter. The document focuses not only on individual perceptions regarding security issues and capability building but also on team building and how to resolve concerns. The implementers of a facility’s ITMP may zero in on indicators of insider threats within their enterprise. This material will benefit organizations when it is applied using a systematic and structured approach as demonstrated throughout the document.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P

Integrated Security-Safety Consequence Study of a Heat Pipe Reactor

This report presents a preliminary demonstration of integrated security/safety consequence modeling to support potential physical security exemption justifications under the new Title 10 Code of Federal Regulations Part 53 licensing pathway, which allows exemptions if sabotage-induced radiological consequences do not exceed 25 rem at the site boundary two hours after release without mitigative actions. A hypothetical heat pipe microreactor subjected to direct sabotage by a 150 lbs. TNT-equivalent high-explosive device was analyzed using a simplified radionuclide release estimate based on DOE-HDBK-3010-94, implemented in the MELCOR severe accident analysis code to model release transport and attenuation through reactor/building compartments, with MELCOR outputs coupled to MACCS to compute offsite doses and the distance-to-threshold metric D 25rem . Six scenarios were evaluated to examine sensitivities to release pathway/building configuration and radionuclide form (vapor versus aerosols with different size distributions). Results show a positive correlation between leak path factor and D 25rem and indicate that reactor building compartmentalization can substantially reduce consequences (a single-story configuration reduced D 25rem by roughly an order of magnitude relative to a cavity-only configuration), while vapor versus aerosol assumptions had limited impact for the modeled two-story case on the spatial grid used.

22 GENERAL STUDIES OF NUCLEAR REACTORS

Radiological Releases from Novel Fuel Forms in Advanced Reactors During Severe Accidents for Consequence Analyses

Various advanced reactor developers are exploring the potential for reductions in the size of physical security forces and emergency planning zones. These reductions are based on robust fuel forms and inherently safe reactor designs. However, such reductions in physical protection measures could increase the risk of sabotage. To assess the possibility of reducing these measures, sabotage-induced radiological consequence analyses were carried out. These analyses considered accident scenarios that were beyond design basis accidents and overly conservative (Shah, 2025a; Shah, 2025b; Shah and Hartanto, 2026), yielding very large release fractions. These fractions, which can be used to evaluate physical protection and emergency planning requirements, have been crudely determined and applied as demonstrations for a sodium-cooled fast reactor (SFR) (Shah and Hartanto, 2025a), a high-temperature gas-cooled reactor (HTGR) (Shah and Hartanto, 2025b), a heat pipe–cooled reactor (HPR) (Shah and Hartanto, 2025c), and a molten salt–cooled reactor (MSR) (Shah et al., 2026). A Sandia National Laboratories (SNL) team used MELCOR—a fully integrated severe accident analysis code—to demonstrate the code’s capability to analyze advanced (i.e., not light water–cooled) reactors (including a fluoride salt–cooled high-temperature reactor [FHR]) and calculate radiological releases to the environment during severe accidents (Wagner et al., 2022a, 2022b, 2022c, 2023a, and 2023b). Although the analyses were carried out to demonstrate MELCOR’s growing capability, the release source terms were estimated for advanced reactors, providing valuable insights into the accident progression and radiological releases. These findings from prior SNL studies, including estimated source terms and related sensitivity studies, were leveraged to derive source terms for postulated sabotage-induced accidents. Insights from these sensitivity studies informed the scaling of SNL’s estimated source terms for the defined accident scenarios. The derived release fractions for the severe accident scenarios for the respective reactor designs can be used to perform more nuanced dose consequence analyses to evaluate the reactors’ physical protection and emergency planning zone requirements. These analyses are in accordance with the risk-informed, performance-based approach proposed under 10 CFR Part 53. This study builds on the prior source term analyses and associated sensitivity studies by SNL to derive time-dependent and design-informed release fractions. Section 2 describes the diverse advanced reactor designs analyzed by the SNL team. Section 3 discusses the severe accident analyses, the release fractions calculated, and the limitations and assumptions of the demonstration project. Section 4 presents the release percentages derived for the hypothetical sabotage-induced severe accidents at the advanced reactors. Section 5 summarizes the study’s findings and conclusions.

22 GENERAL STUDIES OF NUCLEAR REACTORS

Hypothetical Nuclear Reactor Facility Modeling Simulation Data Scenario Comparison

This document evaluates a hypothetical nuclear powerplant and associated protective force personnel using modern modeling and simulation tools. The facility incorporates security early in the design to consider and integrate methods to resolve security issues and vulnerabilities via the facility’s inherent design characteristics before construction. The evaluation in this document is an example only. It is not intended to recommend or evaluate the effectiveness of existing physical security requirements or identify any method that the U.S. Nuclear Regulatory Commission staff may find acceptable for complying with existing requirements.

22 GENERAL STUDIES OF NUCLEAR REACTORS

URC/HRC Selection Guidance

Given the importance of the URC and HRC thresholds as part of a physical security program that is designed to protect against radiological sabotage, it is important to provide guidance on how to assign those thresholds consistent with a State’s level of risk tolerance. Without such guidance, most States will be challenged to establish appropriate thresholds or appropriately establish regulations. This document provides guidance on establishing dose limits and where they apply, as well as the timeframe for which the dose limits should be measured. For dose limits, it offers examples of established thresholds based on safety and emergency response thresholds. Whereas, for timeframes, a process to identify possible timeframes is offered.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF

SDN-Based Dynamic Cybersecurity Framework of IEC-61850 Communications in Smart Grid

In recent years, critical infrastructure and power grids have experienced a series of cyber-attacks, leading to temporary, widespread blackouts of considerable magnitude. Since most substations are unmanned and have limited physical security protection, cyber breaches into power grid substations present a risk. Nowadays, the susceptibility of SDN architecture to cyber-attacks has exhibited a notable increase in recent years, as indicated by research findings. This suggests a growing concern regarding the potential for cybersecurity breaches within the SDN framework. In this paper, we propose a hybrid intrusion detection system (IDS)-integrated SDN architecture for detecting and preventing the injection of malicious IEC 61850-based generic object-oriented system event (GOOSE) messages in a digital substation. Additionally, this program locates the fault’s location and, as a form of mitigation, disables a certain port. Furthermore, implementation examples are demonstrated and verified using a hardware-in-the-loop (HIL) testbed that mimics the functioning of a digital substation.

Liu, Chen-Ching [Virginia Tech] (ORCID:00000002894

Operational Guidelines for Use of Radiation Portal Monitors in Nuclear Facilities

This article provides guidelines (not requirements) for the testing, operation, and maintenance of radiation portal monitors used to scan pedestrian and vehicular traffic entering or exiting nuclear facilities to prevent unauthorized removal of nuclear material. The intended audience is facility managers, supervisors, and operators who are responsible for establishing and maintaining radiation detection systems, who are likely well acquainted with physical security procedures, but may not have a familiarity with the operation of radiation detection.

Enders, Alexander [Oak Ridge National Laboratory (

Energy Sector Threat Brief: Trends and Incidents

This is a threat brief of cyber incidents and trends affecting the global energy sector over the last 12 months and resources for threat sharing, targeting an audience of utility cyber and physical security stakeholders.

24 - POWER TRANSMISSION AND DISTRIBUTION

Deep Cyber-Physical Situational Awareness for Energy Systems: A Secure Foundation for Next-Generation Energy Management

This document provides the final report for the CYPRES project. The purpose is (1) to highlight and summarize its major accomplishments and (2) to provide guidance on how its outcomes have informed and can inform important additional research and technology transfer. The goal of CYPRES was the research, development, and demonstration of a security-oriented next generation cyber-physical EMS for electric power systems that detects malicious and abnormal events through the fusion of cyber and physical data. To achieve this, the CYPRES project team researched, developed, and built a prototype of the solution, referred to as the CYPRES EMS. The CYPRES EMS is a proof-of-concept cyber-physical platform that demonstrates the management of the energy system, communications, security, and cyber-physical grid modeling and analytics. As part of the capabilities of the CYPRES EMS, the team designed and developed a suite of power system applications for monitoring, risk analyses, detection, and control that are inherently cyberaware. At its core, the project aimed to research, develop, and demonstrate a security-oriented next-generation cyber-physical Energy Management System (EMS) capable of detecting malicious and abnormal events through the innovative fusion of cyber and physical data. This approach represents a fundamental shift from traditional EMS, reimagining how critical infrastructure can be protected through unified cyber-aware and physics-aware secure data flow pipelines. The project’s cornerstone deliverable, the CYPRES EMS, serves as a proof-of-concept cyber-physical platform that revolutionizes the management of energy systems, communications, security, and cyber-physical grid modeling and analytics. This prototype implements a comprehensive suite of power system applications for monitoring, risk analyses, detection, and control, all designed with inherent cyber awareness. The system’s architecture extends from end-devices in the field through to control center applications, establishing a secure and resilient control framework that addresses the challenges posed by diverse devices of unknown trustworthiness connecting to modern power systems. Through this innovative approach to deep cyber-physical situational awareness, the CYPRES project not only advances the state-of-the-art in energy infrastructure protection but also establishes a new paradigm for how EMS can be designed, deployed, and operated in an increasingly complex threat landscape. The findings and developments from this project provide crucial insights for stakeholders across the energy sector, offering a blueprint for enhancing the reliability and resilience of our nation’s critical energy infrastructure in the face of evolving cyber threats.

24 POWER TRANSMISSION AND DISTRIBUTION

Enabling Secure and Resilient XFC: A Software/Hardware-Security Co-Design Approach

Extremely fast charging (XFC) has the potential to reduce the charging time of battery electric vehicles (BEV) to be equivalent to the filling time of internal combustion engine vehicles (ICEV), thus eliminating one of the few advantages ICEV still poses for light- and heavy-duty vehicles. Enabling XFC will, however, require coordination and cooperation between the grid, charging stations, and the vehicles themselves, which leads to an inevitable increase in the attack surface for all systems combined. In securing the overall system, we must not only embrace traditional cybersecurity, which is chiefly concerned with communications and the operation of digital systems, but also cyber-physical systems security as the proper operation of XFC is critically dependent on systems’ abilities to know about (sense) and interact with (actuate) the physical world. The project team consists of academic and industry researchers with backgrounds in cybersecurity, cyber-physical systems security, learning in adversarial environments, transportation security, grid security and resilience, wireless power transfer, converter design, and battery management systems.

33 ADVANCED PROPULSION SYSTEMS

Security Analysis of a Class of Spread Spectrum Systems Presentation

A method of adding physical layer security to a class of spread spectrum systems has been recently proposed. In this paper, we look into the rate at which an eavesdropper may gain information about the system to decipher the data symbols. The Shannon mutual information is used to measure the rate of information that may be gained by an eavesdropper. The k-nearest neighbors (k-NN) method is used to obtain estimates of relevant entropy values, which will then be used to quantify the rate of information recovery as more data is transmitted. It turns out that such information recovery requires the adoption of special methods that avoid any destructive bias in the estimates. Details of these methods are also presented.

97 - MATHEMATICS AND COMPUTING

Security Analysis of a Class of Secured Spread Spectrum Systems

Abstract—A method of adding physical layer security to a class of spread spectrum systems has been recently proposed. In this paper, we look into the rate at which an eavesdropper may gain information about the system to decipher the data symbols. The Shannon mutual information is used to measure the rate of information that may be gained by an eavesdropper. The k-nearest neighbors (k-NN) method is used to obtain the estimates of relevant entropy values which will be then used to quantify the rate of information recovery as more data are being transmitted. It turns out that such information recovery requires adoption of special methods that avoid any destructive bias in the estimates. Details of these methods are also presented.

97 - MATHEMATICS AND COMPUTING

Dual-Phase Malicious User Detection Scheme for IM-OFDMA Systems Using IQ Imbalance

Physical-layer security techniques have contributed to the achievement of various security objectives in an efficient and lightweight manner. Thus, these techniques have been widely considered for limited-resource networks such as Internet of Things networks. Among the different security objectives, malicious user detection by exploiting physical-layer parameters has demonstrated efficient performance. In this work, malicious user detection in the recently proposed index modulation-based orthogonal frequency division multiple access (IM-OFDMA) is addressed. The proposed malicious user detection scheme exploits the hardware impairments, especially the in-phase and quadrature imbalance parameters, for both legitimate and malicious users to design a dual-phase efficient detection scheme. The proposed scheme accounts for the special characteristics of IM-OFDMA transmission that are different from other multiple-access techniques. The performance of the proposed scheme was evaluated considering detection probability and false alarm probability performance metrics. Moreover, closed-form expressions of these metrics were derived for both phases and were validated by Monte Carlo simulation results under different configurations of IM-OFDMA systems.

Alaca, Ozgur [ORNL] (ORCID:0000000153713758)

Resilient State Recovery Using Prior Measurement Support Information

Resilient state recovery of cyber-physical systems has attracted much research attention due to the unique challenges posed by the tight coupling between communication, computation, and the underlying physics of such systems. By modeling attacks as additive adversary signals to a sparse subset of measurements, this resilient recovery problem can be formulated as an error correction problem. To achieve exact state recovery, most existing results require less than 50% of the measurement nodes to be compromised, which limits the resiliency of the estimators. In this paper, we show that observer resiliency can be further improved by incorporating data-driven prior information. Here, we provide an analytical bridge between the precision of prior information and the resiliency of the estimator. By quantifying the relationship between the estimation error of the weighted ℓ 1 observer and the precision of the support prior, this quantified relationship provides guidance for the estimator’s weight design to achieve optimal resiliency. Several numerical simulations and an application case study are presented to validate the theoretical claims.

24 POWER TRANSMISSION AND DISTRIBUTION