Engineering PapersSearch

SEARCH · Engineering Papers

Results for “Security Awareness”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Cybersecurity for the Operational Technology Environment (CyOTE) (Final Technical Report)

Electric grids have historically been susceptible to both physical attacks and environmental hazards but the implementation of smart grids, remote management, and self-healing networks, has now made the grid vulnerable to cyber attacks. To address risks introduced by routable connectivity, utilities must establish dynamic solutions to identify, protect, detect, respond to, and recover from cyber security threats and vulnerabilities. In response to the evolving threat landscape U.S. Department of Energy-Office of Cybersecurity, Energy Security, and Emergency Response (DOE CESER) initiated the Cybersecurity for the OT Environment (CyOTE) pilot program, a U.S. Department of Energy (DOE) effort designed to leverage U.S. intelligence capabilities to prevent, detect, or mitigate a cyber attack on utility operational technology (OT) networks. As part of the CyOTE pilot, The Southern Company (Southern Company or Southern) researched, evaluated and deployed emerging Commercial off the Shelf (COTS) technologies and cyber security monitoring architectures to provide previously unrealized network visibility and situational awareness through deep packet inspection and data analytics. This Final Scientific/Technical Report documents the objectives, methodology, lessons learned, and results of Southern Company’s participation in the CyOTE pilot from December 2018 to September 2023.

24 POWER TRANSMISSION AND DISTRIBUTION

Joint scheduling of energy, fast and primary frequency response reserves in integrated transmission–distribution networks

Inverter-based distributed energy resources (DERs) connected to distribution networks (DNs) can provide fast frequency support, but their reserve deliverability depends on feeder constraints and differs from synchronous primary frequency response (PFR). Existing transmission–distribution coordination studies usually treat reserve generically or neglect feeder-level feasibility, while frequency-security scheduling studies rarely represent distribution feeders explicitly. This paper develops a bi-level day-ahead scheduling framework for integrated transmission–distribution networks that jointly clears energy, transmission-side PFR, and distribution-side fast frequency response (FFR) under exogenous hourly inertia and largest-loss inputs from an external unit commitment (UC) schedule. The transmission problem is modeled with DC-optimal power flow (OPF) and closed-form second-order cone (SOC) frequency-security constraints, whereas each DN is represented by a reserve-aware branch-flow AC-OPF so that scheduled fast reserves remain deliverable during activation. The bi-level problem is reformulated through Karush–Kuhn–Tucker (KKT) conditions into a mixed-integer SOC program, and a penalty term is used to tighten the distribution-network relaxation. In the reduced test system, lower exogenous inertia increased the required primary response from 179.64 MW to 191.08 MW, distribution-side fast response reduced total frequency-response procurement by up to 4.9%, and neglecting distribution constraints overstated the combined distribution-side energy and reserve award by up to 18%. In the expanded study, the largest case was solved in 2.02 s with a 0.00% optimality gap. Time-domain simulations kept the frequency nadir above 59.0 Hz in all tested hours. These results demonstrate the value of fast-response modeling and distribution-feasible reserve delivery in coordinated market clearing.

Noh, Seung-Gil

Automated Theorem Proving in High-Quality Software Design

The amount and complexity of software developed during the last few years has increased tremendously. In particular, programs are being used more and more in embedded systems (from car-brakes to plant-control). Many of these applications are safety-relevant, i.e. a malfunction of hardware or software can cause severe damage or loss. Tremendous risks are typically present in the area of aviation, (nuclear) power plants or (chemical) plant control. Here, even small problems can lead to thousands of casualties and huge financial losses. Large financial risks also exist when computer systems are used in the area of telecommunication (telephone, electronic commerce) or space exploration. Computer applications in this area are not only subject to safety considerations, but also security issues are important. All these systems must be designed and developed to guarantee high quality with respect to safety and security. Even in an industrial setting which is (or at least should be) aware of the high requirements in Software Engineering, many incidents occur. For example, the Warshaw Airbus crash, was caused by an incomplete requirements specification. Uncontrolled reuse of an Ariane 4 software module was the reason for the Ariane 5 disaster. Some recent incidents in the telecommunication area, like illegal "cloning" of smart-cards of D2GSM handies, or the extraction of (secret) passwords from German T-online users show that also in this area serious flaws can happen. Due to the inherent complexity of computer systems, most authors claim that only a rigorous application of formal methods in all stages of the software life cycle can ensure high quality of the software and lead to real safe and secure systems. In this paper, we will have a look, in how far automated theorem proving can contribute to a more widespread application of formal methods and their tools, and what automated theorem provers (ATPs) must provide in order to be useful.

Schumann, Johann

Harnessing Virtual Power Plants Reliably: Enabling tools for increased observability, controllability, operation, and aggregation of distributed energy resources

Harnessing virtual power plants enhances the integration of distributed energy resources into utility grids for a sustainable energy future. Virtual power plants (VPPs) aggregate DERs to enhance resource adequacy and reduce emissions. U.S. utilities are exploring various technologies to manage DERs effectively. FERC Order 2222 allows DERs to participate in both wholesale and retail markets. Enhancing observability and controllability of behind-the-meter (BTM) DERs is essential for reliable grid operations. A hierarchical control architecture can improve coordination among residential energy resources. Field tests showed nearly 20% energy savings and 30% peak power reduction during grid events. Effective management of DERs requires enhanced situational awareness to prevent grid congestion. Integrating DER management systems (DERMS) with existing planning tools can improve operational security. Near-real-time grid models can validate optimal resource set points against resource uncertainty. Traditional uninterruptible power supplies (UPS) can be upgraded to support grid services and become part of VPPs. Upgrading UPS systems can reduce costs by 75% and unlock significant battery capacity. New battery management systems and grid-aware controllers are essential for optimizing UPS performance. Continued research and development are necessary to address challenges in integrating DERs into utility grids. Encouraging customer participation in pilot programs is vital for the evolution of VPPs. Here, the shift towards price-responsive DERs and VPPs is expected to enhance energy distribution efficiency.

24 POWER TRANSMISSION AND DISTRIBUTION

Secure State Estimation with Asynchronous Measurements for Coordinated Cyber Attack Detection in Active Distribution Systems

Coordinated cyber attacks tamper with measurement data to disrupt the situational awareness of active distribution systems. Various sensors report measurements asynchronously at different rates, which introduces challenges during state estimation. In addition, this forces cyber intruders to exert greater effort to compromise multiple communication channels and launch coordinated attacks. Therefore, multi-channel and asynchronous measurements could be harnessed to develop more secure cyber defense strategies. In this paper, a prediction-correction-based multi-rate observer is designed to exploit the value of asynchronous measurements for the detection of coordinated false data injection (FDI) attacks. First, a time-function-dependent prediction-correction strategy is proposed to adjust the sampling interval for each sensor’s measurement. Then, an observer is designed based on the trade-off between estimation error and the optimal period of the most recent sampling instant, with the convergence of estimation error with the maximum permitted sampling interval. Moreover, the conditions for exponential stability are developed using the Lyapunov–Krasovskii functional technique. Next, a coordinated FDI attack detection strategy is developed based on the dual nonlinear minimization problem. The proposed attack detection and secure state estimation strategies are tested on the IEEE 13-node system. Simulation results show that these schemes are effective in enhancing attack detection based on asynchronous measurements or compromised data.

asynchronous measurements

Beyond the Bridge: Contention-Based Covert and Side Channel Attacks on Multi-GPU Interconnect

Recently, high-speed interconnects like NVLink have become a standard integration in modern multi-GPU systems, serving as a crucial bridge between CPUs and GPUs. This study highlights the vulnerability of multi-GPU systems to covert and side-channel attacks arising from congestion on these interconnects. An adversary, operating without special permissions, can extract private information about a victim's activities by monitoring NVLink congestion. Specifically, we leverage this insight to develop a covert channel attack across two GPUs, achieving a respectable bandwidth of 33 Kbps. Additionally, we introduce a side-channel attack that allows attackers to fingerprint applications on a remote GPU by probing the shared NVLink interconnect. We underscore the urgent nature of the threats posed by these attacks and advocate for heightened awareness within both industry and academia to implement multi-GPU interconnects with enhanced security measures.

Zhang, Yicheng

Single Step to Orbit; a First Step in a Cooperative Space Exploration Initiative

At the end of the Cold War, disarmament planners included a recommendation to ease reduction of the U.S. and Russian aerospace industries by creating cooperative scientific pursuits. The idea was not new, having earlier been suggested by Eisenhower and Khrushchev to reduce the pressure of the "Military Industrial Complex" by undertaking joint space exploration. The Space Exploration Initiative (SEI) proposed at the end of the Cold War by President Bush and Premier Gorbachev was another attempt to ease the disarmament process by giving the bloated war industries something better to do. The engineering talent and the space rockets could be used for peaceful pursuits, notably for going back to the Moon and then on to Mars with human exploration and settlement. At the beginning of this process in 1992 staff of the Stanford Center for International Cooperation in Space attended the International Space University in Canada, met with Russian participants and invited a Russian team to work with us on a joint Stanford-Russian Mars Exploration Study. A CIA student and Airforce and Navy students just happened to join the Stanford course the next year and all students were aware that the leader of the four Russian engineers was well versed in Russian security. But, as long as they did their homework, they were welcome to participate with other students in defining the Mars mission and the three engineers they sent were excellent. At the end of this study we were invited to give a briefing to Dr. Edward Teller at Stanford's Hoover Institution of War and Peace. We were also encouraged to hold a press conference on Capitol Hill to introduce the study to the world. At a pre-conference briefing at the Space Council, we were asked to please remind the press that President Bush had asked for a cooperative exploration proposal not a U.S. alone initiative. The Stanford-Russian study used Russia's Energia launchers, priced at $300 Million each. The mission totaled out to $71.5 Billion, to send a six-person crew to establish a Mars base and return. It was an on going international venture with plans for new crews, base expansion, and extended exploration at every two year opportunity. The $71.5 Billion international approach contrasted with NASA's own 90-day U.S. - alone study that proposed a package topping $500 Billion by some admissions. NASA's approach was also challenged by an internal D.O.E. proposal at much lower cost, described to the Mars Society last year by Lowell Wood and, of course, by Bob Zubrin's "Mars Direct" proposal.

Lusignan, Bruce

Geographical Database Integrity Validation

Airport Safety Modeling Data (ASMD) was developed at the request of a 1997 White House Conference on Aviation Safety and Security. Politicians, military personnel, commercial aircraft manufacturers and the airline industry attended the conference. The objective of the conference was to study the airline industry and make recommendations to improve safety and security. One of the topics discussed at the conference was the loss of situational awareness by aircraft pilots. Loss of situational awareness occurs when a pilot loses his geographic position during flight and can result in crashes into terrain and obstacles. It was recognized at the conference that aviation safety could be improved by reducing the loss of situational awareness. The conference advised that a system be placed in the airplane cockpit that would provide pilots with a visual representation of the terrain around airports. The system would prevent airline crashes during times of inclement weather and loss of situational awareness. The system must be based on accurate data that represents terrain around airports. The Department of Defense and the National Imagery and Mapping Agency (NIMA) released ASMD to be used for the development of a visual system for aircraft pilots. ASMD was constructed from NIMA digital terrain elevation data (DTED).

Jacobs, Derya

Cyber Informed Engineering Cie Analysis Tool

Main Benefits: • Collaborate on assessment via the web and access and share assessments on your mobile device. • Helps you maximize your cybersecurity investment and resources • Saves you significant time and money by eliminating the requirement to research each government and industry standard in order to understand your cybersecurity posture • Contains easy to follow, step by step instructions to guide you through the process of identifying the cybersecurity posture of your organization • Provides a place to begin with cybersecurity improvement and a way to prioritize your tasks and budgets. • Covers all major cyber relevant topic areas for a comprehensive assessment of your organization’s cybersecurity posture. • Dives deep into the details of each topic area. • Contributes to the organization's risk management and decision-making process • Highlights vulnerabilities and gaps in your organization's IT and control systems. • Raises awareness and facilitates discussion on cybersecurity within your organization • Educates the controls system community on cyber security.

Hansen, Barry [Idaho National Laboratory (INL), Id

Cybersecurity Considerations for Hydrogen Infrastructure in Airport Environments

This report explores key cybersecurity concerns and best practices within environments that serve as reference points for the development of hydrogen fueling infrastructure for aviation. This cybersecurity analysis leverages prior NREL studies: 1) hydrogen fueling station component validation to identify vulnerabilities and failure events documented in physical equipment, and 2) electric aircraft charging infrastructure analysis to explore primary cybersecurity vulnerabilities. It reviews the criticality of digitized technologies in sustaining hydrogen fuel production, storage, and fueling systems, noting cybersecurity concerns that are universal to power systems and industrial control systems in general. In considering cybersecurity vulnerabilities within a future landscape of hydrogen energy for aviation applications, a reference architecture was intended to reveal the points of connection between assets and the potential sensors that are vulnerable to manipulation in the event of compromised access or communication within a SCADA system. A generalized reference architecture can help stakeholders, engineers, or strategists understand connections, criticalities, and standard practices when it comes to designing and planning for new systems. There are several gaps to account for in assessing the future of hydrogen production, storage, and fueling for aviation. Engaging stakeholders, including aircraft manufacturers, electric utilities, site property owners, and local communities, will inform decision-making around site structure, operations, and resources for future hydrogen fueling infrastructure to understand operational needs and cybersecurity awareness. Cybersecurity mitigation strategy must consider physical attack vectors that emerge with the integration of hydrogen systems into existing airport security requirements. The cybersecurity risk assessment contained in this report is an entry point into potential future granular-level analyses to be conducted as part of hazard and risk assessments for safe aviation hydrogen infrastructure, determining how the scale of hydrogen fuel infrastructure for aviation impacts the volume of cyber attack vectors, and what, if any, are the vulnerabilities associated with different types of on-board hydrogen systems. In this nascent development phase, assessing how best to integrate cybersecurity practices into an evolving U.S. aviation landscape provides critical insights into building increased awareness and stakeholder engagement to support a cyber-resilient infrastructure.

08 HYDROGEN

NA-22 Quarterly Report: IST for Extended Deterrence (Q4FY24)

Department of Energy (DOE) scientists have long enjoyed technical collaboration with Japanese colleagues – valuing their technical and scientific prowess in materials science and engineering, large-scale, scientific computing, and many other areas. In particular, NNSA’s laboratories are attractive partners for this effort because they have a heritage of performing high quality, basic research; they work with an awareness of the dual use nature of emerging science and technology; and, importantly, they work with deep national security sensibilities through engagement with NNSA and other national security mission responsibilities. Other DOE laboratories with significant national security bona fides are also significant collaborators. In FY23 a Trilateral Leaders Summit was convened at Camp David. The DOE was given responsibility for “Trilateral National Laboratories Cooperation: The United States, Japan, and the ROK will drive new trilateral cooperation between the U.S. Department of Energy’s National Laboratories and counterpart laboratories—supported by a budget of at least $6 million—to advance knowledge, strengthen scientific collaboration, and spearhead innovation in support of the three countries’ shared interests. Scientists and innovators from the three countries will advance collaborative projects on priority critical and emerging technology areas; potential areas of cooperation include advanced computing, artificial intelligence, materials research, and climate and earthquake modeling among other technology areas.”

36 MATERIALS SCIENCE

Connecting Space to Village: Tethys Adoption Within SERVIR

The SERVIR program, a joint development initiative of National Aeronautics and Space Administration (NASA) and United States Agency for International Development (USAID), works in partnership with leading regional organizations world-wide to help developing countries use information provided by Earth observing satellites and geospatial technologies for managing climate risks and land use. SERVIR empowers decision-makers with tools, products, and services to act locally on critical issues related to four key areas: Food Security and Agriculture, Water and Water-related Disasters, Land Use/Land Cover and Ecosystems, Weather and Climate. SERVIR is improving awareness, increasing access to information, and supporting analysis to help people in West Africa, Eastern and Southern Africa, Hindu Kush-Himalaya (HKH), the Lower Mekong, South America and Mesoamerica. NASA funds an Applied Sciences Team (AST), composed of experts from universities and research institutions around the United States. Through AST, SERVIR adopted the Tethys platform introduced by Brigham Young University (BYU) for the implementation of tools to deliver scientific data to stakeholders in the Hindu Kush-Himalaya region. Several Tethys applications developed within SERVIR have raised interest amongst decision makers in the countries served by our regional hubs. They see these new apps as key vehicles to disseminate complex information related to weather models, hydrological models, and air quality monitoring, and as such the scope of our Tethys efforts continue to expand to other regions. As of July 2019, each one of the SERVIR hubs (with the exception of Amazonia, which has only recently started), have stood up Tethys portals and have at least one individual trained in the implementation and maintenance of a Tethys portal and in the creation of basic applications. HKH, with BYU's valuable support, has implemented very sophisticated applications that showcase the possibilities and the benefits that the Tethys platform brings.

Tethys

Small Satellite Industrial Base Study: Foundational Findings

This report documents findings from a Small Satellite (SmallSat) Industrial Base Study conducted by The Aerospace Corporation between November 2018 and September 2019. The primary objectives of this study were a) to gain a better understanding of the SmallSat community’s technical practices, engineering approaches, requirements flow-downs, and common processes and b) identify insights and recommendations for how the government can further capitalize on the strengths and capabilities of SmallSat offerings. In the context of this study, SmallSats are understood to weigh no more than 500 kg, as described in “State of the Art Small Spacecraft Technology, NASA/TP-2018- 220027, December 2018. CubeSats were excluded from this study to avoid overlap and duplication of recently completed work or other studies already under way. The team also touched on differences between traditional space-grade and the emerging “mid-grade” and other non-space, alternate-grade EEEE (electrical, electronic, electromechanical, electro-optical) piece part categories. Finally, the participants sought to understand the potential effects of increased use of alternate-grade parts on the traditional space-grade industrial base. The study team was keenly aware that there are missions for which non-space grade parts currently are infeasible for the foreseeable future. National security, long-duration and high-reliability missions intolerant of risk are a few examples. The team sought to identify benefits of alternative parts and approaches that can be harnessed by the government to achieve greater efficiencies and capabilities without impacting mission success.

Allyson D Yarbrough

The Space Superhighway: Space Infrastructure for the 21st Century

This paper introduces a concept for space infrastructure developed with input from multiple U.S. government agencies called the Space Superhighway, which could support civil, commercial, and national security space activities. The Space Superhighway is a commercial-first space infrastructure that contains three primary components: regional hubs, a sustainable transportation network, and Earth-to-orbit logistics. Civil, commercial, and national security space sectors could use this common infrastructure to support missions such as satellite servicing, Earth science, and space domain awareness, among others. It utilizes a commercial-first, “infrastructure-as-a-service” approach which contains industry-owned and operated assets with government anchor tenants for commercial services, enabling extended mission lifetime, on-orbit repair, maneuver without regret, and debris mitigation and removal. The Space Superhighway is the space infrastructure needed for the 21st century.

space superhighway

The Space Superhighway: Space Infrastructure for the 21st Century

This poster introduces a concept for space infrastructure developed with input from multiple U.S. government agencies called the Space Superhighway, which could support civil, commercial, and national security space activities. The Space Superhighway is a commercial-first space infrastructure that contains three primary components: regional hubs, a sustainable transportation network, and Earth-to-orbit logistics. Civil, commercial, and national security space sectors could use this common infrastructure to support missions such as satellite servicing, Earth science, and space domain awareness, among others. It utilizes a commercial-first, “infrastructure-as-a-service” approach which contains industry-owned and operated assets with government anchor tenants for commercial services, enabling extended mission lifetime, on-orbit repair, maneuver without regret, and debris mitigation and removal. The Space Superhighway is the space infrastructure needed for the 21st century.

space infrastructure

Spinoff 1995

Recognizing the great potential of the technology bank, Congress charged NASA with stimulating the widest possible use of this valuable resource in the national interest. NASA's instrument of that purpose is the Technology Transfer Program, which seeks to broaden and accelerate the spinoff process. Its intent is to spur expanded national benefit, in terms of new products and new jobs, by facilitating the commercial application of the technology; it encourages greater use of the storehouse of knowledge by providing a channel linking the technology and those who might be able to put it to advantageous use. In July 1994, NASA implemented an Agenda for Change - a new way of doing business in partnership with the private sector. This Agenda marks the beginning of a new focus to further improve our contributions to America's economic security through the pursuit of aeronautics and space missions. This publication is an implement of the Technology Transfer Program intended to heighten awareness among potential users of the technology available for transfer and the economic and social benefits that might be realized by applications of NASA technology to US commercial interests. Spinoff 1995 is organized in three sections. Section 1 outlines NASA's mainline effort, the major programs that generate new technology and therefore replenish and expand the bank of technical knowledge available for application. Section 2, the focal point of this volume, contains a representative sampling of spinoff products and processes that resulted from applications of technology originally developed to meet NASA aerospace goals. Section 3, describes the various mechanisms NASA employs to stimulate technology transfer and lists, in an appendix, contact sources for further information about the Technology Transfer Program.

Haggerty, James J.

Prognostics As-A-Service (PaaS)

Deep awareness of aircraft system health-state is critical for maintaining safe, efficient growth in global operations and enabling autonomy. Maintainers, operators, controllers, dispatchers, pilots, and autonomous systems must have reliable real-time predictions of vehicle health to preserve safety and efficiency. We will explore the feasibility and challenges of cloud enhanced prognostics. Aircraft request PaaS in flight to supplement onboard systems or provide complete health awareness. We will explore and demonstrate the ability to address six major challenges of PaaS: Generality, Environmental Complexity, Utility, Trust, Communications, and Security. We will also explore the factors in the decision to host prognostics onboard vs As-A-Service.

Prognostics As A Service