Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Security by design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Cyber Threat Assessment of Uplink and Commanding System for Mission Operation

Most of today's Mission Operations Systems (MOS) rely on Ground Data System (GDS) segment to mitigate cyber security risks. Unfortunately, IT security design is done separately from the design of GDS' mission operational capabilities. This incoherent practice leaves many security vulnerabilities in the system without any notice. This paper describes a new way to system engineering MOS, to include cyber threat risk assessments throughout the MOS development cycle, without this, it is impossible to design a dependable and reliable MOS to meet today's rapid changing cyber threat environment.

ground data↗

A Framework for Building Security into the Design Process

This report presents guidance to support the implementation of security objectives during the design process for nuclear facilities using an organization’s quality management system. The guidance in this document is intended for design vendors and operators of nuclear power facilities. Additionally, this guidance document can be beneficial to regulatory bodies, industry partners, customers, and other stakeholders within the nuclear power market. This report aims to ensure security consequences are identified before designs are completed, which may lead to reduced costs and higher security effectiveness and efficiency.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

A Framework for Building Security into the Design Process

This report presents guidance to support the implementation of security objectives during the design process for nuclear facilities using an organization’s quality management system. The guidance in this document is intended for design vendors and operators of nuclear power facilities. Additionally, this guidance document can be beneficial to regulatory bodies, industry partners, customers, and other stakeholders within the nuclear power market. This report aims to ensure security consequences are identified before designs are completed, which may lead to reduced costs and higher security effectiveness and efficiency.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Xenith Scalable Security Economics

These slides present a high level overview of an ongoing project sponsored by NNSA. The project is focused on economic analysis of physical security design of micro reactors. The slides will be presented to NNSA's office of International Nuclear Security (INS) at a program update meeting on May 28th, 2025.

98 - NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL↗

High-Altitude ADS-B Flight Tests on a NASA ER-2 Research Airplane

Researchers at the National Aeronautics and Space Administration (NASA) Armstrong Flight Research Center (Edwards, California); the Federal Aviation Administration (FAA); and Regulus Group, LLC (Atlantic City, New Jersey) collaborated for the flight-test demonstration of an Automatic Dependent Surveillance-Broadcast (ADS-B) system equipped on a high-altitude Earth Resources-2 (ER-2) research airplane. The unique ER-2 airplane is a NASA-owned and operated airborne science version of the United States Air Force / Lockheed Martin Aeronautics (Bethesda, Maryland) U-2S airplane. The FAA has mandated that by the year 2020, aircraft operating within certain sections of the United States National Airspace system be equipped with ADS-B Out technology; the research presented in this paper is the first to show how the NASA ADS-B architecture satisfies the mandate for a unique high-altitude aircraft. An exceptional military aircraft design, security protocols, and the performance envelope of the ER-2 airplane made the avionics integration remarkably challenging. The design required the ADS-B avionics to survive the harsh flight environment of the ER-2 airplane. The most prominent challenge was the functional integration of modern civilian avionics into federated military legacy avionics. Flight-test objectives were to certify an ADS-B Out (1090ES) passive surveillance integrated with a Traffic Alert and Collision Avoidance System (TCAS) I active surveillance system on an ER-2 platform for high-altitude cruise operations. In April 2022, NASA conducted three flights at Edwards Air Force Base (Edwards, California) - each greater than one-hour flight reaching altitudes above 60,000 ft.

ADS-B↗

Smart Inverters, Dumb Risk: Taking Control of IBR Security in the Digital Age

This presentation addresses the security challenges posed by Inverter-Based Resources (IBRs) in the modern energy landscape. The presentation highlights the vulnerabilities and risks associated with IBRs, including the potential for cyber-attacks, the impact of insecure defaults, and the systemic risks posed by supply chain dependencies. Key topics covered include: 1) The increasing digital transformation in energy systems and the associated security risks. 2) Specific vulnerabilities in IBRs, including weak passwords, hardcoded credentials, and insecure web application interfaces. 3) The implications of persistent connectivity and the strategic risks posed by foreign-manufactured components. 4) The role of regulatory frameworks, such as NERC CIP, in addressing these challenges and the limitations of current oversight. 5) Practical solutions for mitigating risks, including secure design practices, vendor risk assessments, and the importance of strong passwords and role-based access control. The presentation underscores the necessity of a comprehensive, system-of-systems approach to securing IBRs, emphasizing the need for collaboration across various stakeholders, including operators, developers, and regulators, to ensure the resilience and security of the energy grid.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Physical Safety and Security at Electric Vehicle Charging Sites

This help sheet provides an overview of physical safety and security design elements for public EV charging stations and general best practices that can be considered for the safety and comfort of charging station customers.

ADVANCED PROPULSION SYSTEMS,ENERGY PLANNING, POLIC↗

Security Vulnerability Profiles of NASA Mission Software: Empirical Analysis of Security Related Bug Reports

NASA develops, runs, and maintains software systems for which security is of vital importance. Therefore, it is becoming an imperative to develop secure systems and extend the current software assurance capabilities to cover information assurance and cybersecurity concerns of NASA missions. The results presented in this report are based on the information provided in the issue tracking systems of one ground mission and one flight mission. The extracted data were used to create three datasets: Ground mission IVV issues, Flight mission IVV issues, and Flight mission Developers issues. In each dataset, we identified the software bugs that are security related and classified them in specific security classes. This information was then used to create the security vulnerability profiles (i.e., to determine how, why, where, and when the security vulnerabilities were introduced) and explore the existence of common trends. The main findings of our work include:- Code related security issues dominated both the Ground and Flight mission IVV security issues, with 95 and 92, respectively. Therefore, enforcing secure coding practices and verification and validation focused on coding errors would be cost effective ways to improve mission's security. (Flight mission Developers issues dataset did not contain data in the Issue Category.)- In both the Ground and Flight mission IVV issues datasets, the majority of security issues (i.e., 91 and 85, respectively) were introduced in the Implementation phase. In most cases, the phase in which the issues were found was the same as the phase in which they were introduced. The most security related issues of the Flight mission Developers issues dataset were found during Code Implementation, Build Integration, and Build Verification; the data on the phase in which these issues were introduced were not available for this dataset.- The location of security related issues, as the location of software issues in general, followed the Pareto principle. Specifically, for all three datasets, from 86 to 88 the security related issues were located in two to four subsystems.- The severity levels of most security issues were moderate, in all three datasets.- Out of 21 primary security classes, five dominated: Exception Management, Memory Access, Other, Risky Values, and Unused Entities. Together, these classes contributed from around 80 to 90 of all security issues in each dataset. This again proves the Pareto principle of uneven distribution of security issues, in this case across CWE classes, and supports the fact that addressing these dominant security classes provides the most cost efficient way to improve missions' security. The findings presented in this report uncovered the security vulnerability profiles and identified the common trends and dominant classes of security issues, which in turn can be used to select the most efficient secure design and coding best practices compiled by the part of the SARP project team associated with the NASA's Johnson Space Center. In addition, these findings provide valuable input to the NASA IVV initiative aimed at identification of the two 25 CWEs of ground and flight missions.

vulnerability↗

ILLICIT TRANSIT INTERDICTION GLOBAL ANALYSIS

This study aims to enhance the security of radioactive materials during transport by analyzing commonalities in cargo thefts conducted by non-state groups such as thieves and terrorists. This research focuses on identifying patterns and trends in the methods used to steal high-value cargo, with the goal of applying these insights to improve transport security of radioactive materials. Key questions addressed include the frequency of specific tools, techniques, and insider involvement in thefts, as well as the use of weapons, electronic jamming equipment, and specialized tools. Findings will inform security design improvements and industry practices to mitigate vulnerabilities. The study involves a comprehensive review of literature and case studies, utilizing data sources from 2018 to 2023. Articles will be selected based on their relevance to thefts of valuable cargo in transit, with a focus on incidents involving non-state actors. The methodology will include statistical and inferential analysis to identify trends, with results visualized through pie charts, frequency analyses, and terrain maps. The discussion will highlight the implications of findings and provide actionable recommendations for strengthening security measures. Limitations such as data availability and reporting inconsistencies will be acknowledged. Suggestions for future improvements will be constructed using existing case studies and expert feedback. The study’s outcomes aim to raise awareness within the industry, inform policy decisions, and enhance security protocols for radioactive material transport. Metrics for impact include the potential publication of findings, presentations at conferences to raise awareness, and the subsequent actions taken by stakeholders based on the research. By identifying trends and vulnerabilities and suggesting improvements, this research contributes to preventing the illicit use of nuclear and radiological materials.

Zineddin, Dr. Z. [ORNL] (ORCID:0009000848740725)↗

UAS IMPLEMENTATION CONSIDERATIONS FOR NUCLEAR SECURITY

Uncrewed aerial systems (UAS) have been an area of focus for the Office of International Nuclear Security within the US Department of Energy’s National Nuclear Security Administration and other foreign and domestic organizations for several years. This emerging technology provides significant capabilities to the nuclear security realm, but there are many things to consider when implementing them into an established security design or network. The goal of this paper is to discuss some of the benefits, challenges, and lessons learned with using UAS at nuclear facilities and during transport of material. Generic examples of UAS implementation will be used to facilitate a publicly releasable paper and presentation. The paper will start with a summary of the types and capabilities of UAS to provide a better understanding for people unfamiliar with current and new capabilities of these systems. Since there are many different types and sizes of UAS, this paper will focus on drones 55 lb and smaller. Then some of the use cases of UAS for security and challenges of employing them will be covered. Finally, lessons learned and some best practices that Oak Ridge National Laboratory has discovered from research, development, testing, and evaluation will be summarized.

Stockwell, Brandon↗

Advanced-Research-on-Integrated-Energy-Systems-Based Analysis to Support Resilient System Upgrades: Energy to Communities Energyshed In-Depth Partnership with Molokai, Hawaii

The Molokai, Hawaii, Energy to Communities (E2C) Energyshed project represents a collaborative effort between the National Laboratory of the Rockies, Shake Energy Collaborative, the Molokai Clean Energy Hui, Sustainable Molokai, and Ho'ahu Energy Cooperative Molokai to advance Molokai's Community Energy Resilience Action Plan (CERAP). Supported by Hawaiian Electric Company and the Hawaii State Energy Office, the initiative aims to develop a community-defined portfolio of renewable energy solutions that enhance energy resilience while aligning with the Hawaiian Electric Integrated Grid Plan (IGP) and Molokai's energy goals. Phase 1 focused on technical analyses and community engagement to co-design feasible energy scenarios. Challenges such as grid upgrades, storage sizing, and inverter ride-through standards were addressed to align technical and operational requirements with community preferences. The project equips Molokai with actionable data and insights to implement energy initiatives while ensuring resilient and culturally informed solutions. Future efforts aim to finalize project designs, secure interconnection agreements, and deploy energy projects that reflect community priorities and technical feasibility.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Digital risk analysis in nuclear engineering projects: Designing for safety, performance, reliability, and security

Cyber-informed engineering and security-by-design frameworks are important in promoting the need to identify cybersecurity concerns early in the systems engineering lifecycle so risks from adversarial cyber-attacks can be eliminated or reduced through engineering design practices. In addition to adversarial risk, risk in operational technology systems also includes non-adversarial and unintentional risk from other factors such as human performance errors, environmental conditions, design flaws, and device degradation or failure. This paper introduces a new concept for characterizing digital risk, both adversarial and non-adversarial, and provides the basis for initial research into a novel digital risk analysis approach focused on incorporating attack difficulty into a multi-attribute analysis technique using robust decision-making. This digital risk characterization is also used to frame a discussion on the challenges of competing objectives and competing stakeholder requirements in an integrated energy system project that incorporates a small modular reactor and industrial facility.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗