Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “data authentication”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Methods for communicating data utilizing sessionless dynamic encryption

The present disclosure is directed to methods that provide a secure communication protocol by utilizing one step process of authenticating and encrypting data without having to exchange symmetric keys or needing to renew or re-issue digital identities fundamental to asymmetric encryption methodology.

Choi, Sung Nam↗

Module-OT: A Turnkey Solution for Securing Energy Systems

The Modular Security Apparatus for Managing Distributed Cryptography for Command-and-Control Messages on Operational Technology Networks (Module-OT) is a flexible and lightweight solution for grid-edge devices focusing on end-to-end security. It is a bump- in- the-wire solution acting as a secure conduit for data between devices or systems across a network. It improves the cybersecurity posture of DER systems by providing authentication, authorization, and data integrity to secure DER communications. Additionally, it performs key management, provides data security through whitelisting Internet Protocol addresses and ports, blocks unauthorized connections, controls user access, and allows serial or Ethernet connections for added flexibility. The core software is portable to various Linux-based operating systems and is developed to be customized by the developer and researcher communities. Module-OT has been validated in the lab, has been demonstrated at a 500-KW PV-plus-storage site, and has been proven ready to secure operational technology devices. Its core functionality meets current standards, including validation procedures of the NIST Cryptographic Algorithm Validation Program (CAVP) and the Federal Information Processing Standard (FIPS 140-2). Because of its capability to provide an accessible and affordable option for stepping up security across modern energy systems, Module-OT can serve as an effective technological option to standardize cybersecurity moving forward.

cryptography↗

Blockchain-Enabled Secure Device-to-Device Communication in Software-Defined Networking

The Internet of Things (IoT) continues to increase the demand for seamless communication among IoT devices. The rapid growth of IoT devices has led to an exponential increase in device-to-device (D2D) communication within the Software-Defined Networking (SDN), though it enables a flexible archi-tecture for managing network resources. However, traditional security models face challenges (e.g., Security, privacy, and trust) in addressing the dynamic and decentralized nature of these communications. Despite of these challenges, this paper proposes a novel approach that leverages blockchain technology to enhance the security, privacy, and trustworthiness of D2D communication within an SDN environment. The proposed approach integrates blockchain nodes in sDN components to establish a decentralized ledger for transparent and verifiable records. Smart contracts enforce authentication rules to ensure that only authenticated devices can access the network and engage in transactions securely. It also automates the security policies to ensure temper resistance execution using the cryptographic mechanism for data integrity and authentic communication. The Implementation of the proposed algorithms validates the resilience of the proposed approach against cyberattacks. Overall, the proposed approach enables efficient and secure D2D communication for resilient SDN infrastructure in IoT ecosystems.

Das, Debashis↗

The LCLStream Ecosystem for Multi-Institutional Dataset Exploration

We describe a new end-to-end experimental data streaming framework designed from the ground up to support new types of applications – AI training, extremely high-rate X-ray time-of-flight analysis, crystal structure determination with distributed processing, and custom data science applications and visualizers yet to be created. Throughout, we use design choices merging cloud microservices with traditional HPC batch execution models for security and flexibility. This project makes a unique contribution to the DOE Integrated Research Infrastructure (IRI) landscape. By creating a flexible, API-driven data request service, we address a significant need for high-speed data streaming sources for the X-ray science data analysis community. With the combination of data request API, mutual authentication web security framework, job queue system, high-rate data buffer, and complementary nature to facility infrastructure, the LCLStreamer framework has prototyped and implemented several new paradigms critical for future generation experiments.

Rogers, David [ORNL] (ORCID:0000000251871768)↗

Oak Ridge National Laboratory Technical Input for the Nuclear Regulatory Commission Review of the 2017 Edition of ASME Section III, Division 5, ‘High Temperature Reactors’

To assist the Nuclear Regulatory Commission in its decision making on endorsement of the American Society for Mechanical Engineers Boiler and Pressure Vessel Code Section III, Division 5 (2017 Edition) for development of advanced non-light water reactors, the following Division 5 portions were reviewed: Article HBB-2000 Material; Article HCB-2000 Material; Article HGB-2000 Material; Mandatory Appendix HBB-I-14 Tables and Figures; and, Nonmandatory Appendix HBB-U Guidelines for Restricted Material Specifications to Improve Performance in Certain Service Applications. In addition to the 2017 Edition, the same parts of the 2019 Edition have also been reviewed as indicated in various sections of the report. This review was conducted by a collaboration of national laboratory and private sector participants with significant industrial experience, including some heavy lifting and deep diving from Clarus Consulting, LLC., all intended to achieve an objective, independent, and practical perspective. The report provides recommendations, descriptions of the evaluation methods, and the source references for the data used. To build confidence required for endorsement of the Code, this review was conducted as a verification and validation of the above Code contents. The objective of verification is to ensure that the Code is free of error – direct or implied; contains the information needed for its use, including proper coverage of the Code-specified materials for the intended application, and completeness and adequacy of references to other portions of the Code. The objective of validation is to authenticate that the Code tabulations and graphs represent design inputs consistent with what are determined using rules and methods specified by the Code. The authentication process used data that were assembled and/or generated independent of Code development, while the methods of analysis followed Code-specified methods where appropriate. The designated portions for this review cover the five alloys codified for high temperature reactor applications in Division 5, i.e. 316 SS, 304 SS, 800H, 2¼Cr-1Mo, and 9Cr-1Mo-V, regarding their general requirements, permitted specifications and design stress intensity values for pressure-retaining applications, deterioration in service, fatigue acceptance test, permissible weld materials, tensile and yield strength, expected minimum stress-to-rupture values (including for Alloy 718), weld stress rupture factors, permissible materials for bolting use, and restricted specifications in certain service applications. Additionally, stress intensity values for bolting materials including 316 SS, 304 SS and alloy 718 were reviewed. Analysis and discussion are also provided on contents outside of these designated Code portions where it was deemed relevant and necessary to develop a technically sound understanding of issues relating to the designated portions. Due to unavailability of sufficient test data on welds during the review period, the weld stress rupture factors in Tables HBB-I-10.14A to E, which cover a total of ten tables for the five alloys welded with twenty-eight different weld metals (some with similar properties), have been deferred to a future review effort. The review identified mainly two types of issues. The first type includes instances where the Code is found factually incomplete or incorrect, such as obsolete materials specifications listings, missing tabulation of stresses for bolting. Changes to the Code are recommended in these cases. The second type of issue includes instances where the Code tabulations and graphs are found to be less conservative than the review analysis results. In these cases, recommendations are made for further review and consideration where the difference in conservatism exceeds 10%, which is our threshold for questioning technical adequacy, meriting a risk assessment by the Nuclear Regulatory Commission and/or reactor designers. It is noted that this effort has been executed using all available data and established methods of analysis, including methods and criteria specified and used by the Code. As such, the findings that are presented in quantitative detail, in a format for convenient comparison with the Code, and with identification of where further review is recommended, should provide a sound technical basis for decisions about quantifying the implications of the reduced design margins and technical adequacy/inadequacy to form a basis for conditioning specific Code tabulation values on endorsement. Recommendations for specific changes to the Code, however, entail design conservatism considerations beyond the scope of this review effort, and are not made in this report.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

A holistic cyber-physical security protocol for authenticating the provenance and integrity of structural health monitoring imagery data

Modern infrastructure systems, such as bridges, dams, power generation stations, and buildings increasingly have an intrinsic cyber-physical nature to them. Infrastructure now commonly, includes actuators, network connections, sensors, control systems, and computational resources. It is of increasing concern that modern infrastructure is vulnerable to cyber-attacks that can damage both the cyber and physical nature of the infrastructure. To date, the physical and cyber health of infrastructure has been considered separately. However, the increasing concerns associated with the cyber-physical security of infrastructure coupled with the emergence of 5G networks made using components that are not universally considered trustworthy, and the emergence of techniques for creating deepfakes and adversarial examples suggests the time has come to begin considering cyber health and structural health with a more holistic approach. In this work, a protocol is developed for ensuring the imagery data captured by a structural health monitoring system can be unambiguously attributed to legitimate sensors associated with the structural health monitoring system. A computer vision approach based on the idea of mutual information is then presented to detect damage in an image. This work presents the protocol for authenticating the provenance of imager data and demonstrates that this protocol does not have overly adverse effects when used with the mutual information-based technique for detecting damage in the resulting imagery data.

Jung, HweeKwon↗

Open Radiation Monitoring: Conceptual System Design

The Open Radiation Monitoring (ORM) Project seeks to develop and demonstrate a modular radiation detection architecture designed specifically for use in arms control treaty verification (ACTV) applications that will facilitate rapid development of trusted systems to meet the needs of potential future treaties. Development of trusted systems to support potential future treaties is a complex and costly endeavor that typically results in a purpose-built system designed to perform one specific task. The majority of prior trusted system development efforts have relied on the use of commercial embedded computers or microprocessors to control the system and process the acquired data. These processors are complex, making authentication and certification of measurement systems and collected data challenging and time consuming. We believe that a modular architecture can be used to reduce more complex systems to a series of single-purpose building blocks that could be used to implement a variety of detection modalities with shared functionalities. With proper design, the functionality of individual modules can be confirmed through simple input/output testing, thereby facilitating equipment inspection and in turn building trust in the equipment by all treaty parties. Furthermore, a modular architecture can be used to control data flow within the measurement system, reducing the risk of "hidden switches" and constraining the amount of sensitive information that could potentially be inadvertently leaked. This report documents a conceptual modular system architecture that is designed to facilitate inspection in an effort to reduce overall authentication and certification burden. As of publication, this architecture remains in a conceptual phase and additional funding is required to prove out the utility of a modular architecture and test the assumptions used to rationalize the design.

61 RADIATION PROTECTION AND DOSIMETRY↗

Secure hierarchical processing using a secure ledger

Disclosed is a system and method for processing data using blockchain technology. The system includes a memory having programmable instructions stored thereon that, when executed by a processor, cause the system to: authenticate one or more sensors in anticipation of receiving component data; receive component data, upon successful authentication; store the component data locally or to a cloud-based server and/or calculate a root value for the component data; store or embed the root value with the stored component data; condense the component data and link the condensed component data to the stored component data via the root value. The system further includes instructions to log the condensed data, including the root value, to a ledger, and to identify a tag or transaction id corresponding to the logging event for subsequent retrieval of the condensed data using the tag or transaction id.

Zhao, Wenbing↗

Data transfer for STAR grid jobs

The Solenoidal Tracker at RHIC (STAR) is a multipurpose experiment at the Relativistic Heavy Ion Collider (RHIC) with the primary goal to study the formation and properties of the quark-gluon plasma. STAR is an international collaboration of member institutions and laboratories from around the world. Yearly data-taking period produces PBytes of raw data collected by the experiment. STAR primarily uses its dedicated facility at BNL to process this data, but has routinely leveraged distributed systems, both high throughput (HTC) and high performance (HPC) computing clusters, to significantly augment the processing capacity available to the experiment. The ability to automate the efficient transfer of large data sets on reliable, scalable, and secure infrastructure is critical for any large-scale distributed processing campaign. For more than a decade, STAR computing has relied upon GridFTP with its x509-based authentication to build such data transfer systems and integrate them into its larger production workflow. The end of support by the community for both GridFTP and the x509 standard requires STAR to investigate other approaches to meet its distributed processing needs. In this study we investigate two multi-purpose data distribution systems, Globus.org and XRootD, as alternatives to GridFTP. We compare both their performance and the ease by which each service is integrated into the type of secure and automated data transfer systems STAR has previously built using GridFTP. The presented approach and study may be applicable to other distributed data processing use cases beyond STAR.

73 NUCLEAR PHYSICS AND RADIATION PHYSICS↗

Optical authentication of images

Systems and methods performed for generating authentication information for an image using optical computing are provided. When a user takes a photo of an object, an optical authentication system receives light reflected and/or emitted from the object. The system also receives a random key from an authentication server. The system converts the received light to plenoptic data and uploads it to the authentication server. In addition, the system generates an optical hash of the received light using the random key, converts the generated optical hash to a digital optical hash, and uploads the digital optical hash to the authentication server. When the authentication server receives the upload, it verifies whether the time of the upload is within a certain threshold time from the sending of the random key and whether the digital optical hash was generated from the same light as the plenoptic data.

97 MATHEMATICS AND COMPUTING↗

Optical authentication of images

Systems and methods performed for generating authentication information for an image using optical computing are provided. When a user takes a photo of an object, an optical authentication system receives light reflected and/or emitted from the object. The system also receives a random key from an authentication server. The system converts the received light to plenoptic data and uploads it to the authentication server. In addition, the system generates an optical hash of the received light using the random key, converts the generated optical hash to a digital optical hash, and uploads the digital optical hash to the authentication server. When the authentication server receives the upload, it verifies whether the time of the upload is within a certain threshold time from the sending of the random key and whether the digital optical hash was generated from the same light as the plenoptic data.

Murialdo, Maxwell R.↗

Integrating AEAD Ciphers into Software-Defined-Storage Systems

The use of software-defined storage (SDS) systems to store sensitive data is becoming increasingly prevalent. However, these systems primarily implement security measures to ensure the confidentiality and availability of stored data, with limited consideration for the protection of its integrity. This paper outlines why this is a harmful development, as well as how integrity-protecting measures can be included into SDS systems. To demonstrate the practical challenges and opportunities of such measures, we integrated "authenticated encryption with associated data" (AEAD) ciphers into the widely used SDS system Ceph, specifically, into its block storage interface, to secure the integrity of stored data and metadata. Ultimately, we identify the characteristics that an SDS system should possess to adopt our methodology.

Mohren, David [University of New Brunswick, Canada↗

Cybersecurity Certification Recommendations for Interconnected Grid Edge Devices and Inverter Based Resources

Escalating deployment of PV and grid-edge devices on the distribution grid has increased the sustainability and efficiency of the electric grid. However, the increasing number of distributed energy resources (DERs) deployed creates a heightened cyber-physical interdependency on the distribution grid and thus creates more vectors for cyber-attacks to exploit through information and communication technology (ICT) systems and networks. For example, control signal packets can be modified, intercepted, or corrupted due to vulnerabilities in communication protocols used by microgrid controllers and grid edge devices for power control. Therefore, to mitigate and prevent cyber-attacks on grid edge devices and the inverter-based resources connected to the distribution grid, the U.S. Department of Solar Energy Technologies Office (SETO) awarded funding to the National Renewable Energy Laboratory and Sandia National Laboratory (SNL) to research, develop, and harmonize cybersecurity standards for Photovoltaic (PV) systems and for other kinds of DERs. To help develop a standard for DER cybersecurity, NREL established certification recommendations and test cases, in consensus with the solar industry and UL, for ensuring intrinsic design security for DERs. These recommendations were developed to bolster the cybersecure functionalities such as TLS, MAC, CRL, session resumption/renegotiation, and password, system, and service security management within the DER devices. The proposed test cases verify authentication, authorization, confidentiality, and data integrity for data and communications of DERs that use Transmission Control Protocol/Internet Protocol (TCP/IP). They were also developed to protect DER communications from eavesdropping, replay, man-in-the-middle, denial of service (DoS), spoofing through security certificates, least-privilege violation, and brute-force credentials. This report, which has been validated and reviewed by UL, expands upon those test cases to provide DER cybersecurity certification recommendations which increase DER resiliency and help to mitigate cyber-attacks. UL's collaboration with NREL and approval of this document will accelerate the adoption of a UL standard for DER cybersecurity.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Latency Analysis of the Nexus Digital Twin Framework

Real-time digital catalogs are increasingly relied upon to track metadata and connect disparate data sources for cloud-based data integration efforts. One such tool, Deeplynx Nexus is supporting real-time digital twin efforts through event-driven data integration and time-series queries. Nexus’s usefulness for these applications depends critically on how quickly individual records can be uploaded and downloaded, since delays directly affect the responsiveness of any system built on top of it. However, the actual latency a user should expect from Nexus has not been systematically measured before, particularly for the small, frequent transactions typical of live sensor feeds. Here we show that single-record round-trip latency is 61.1 ms on a local Nexus instance and 391.7 ms on the hosted production infrastructure, a roughly 6.4x difference driven primarily by fixed per-request overhead rather than data volume. This overhead dominates at small scale: comparing single-record and ten-record trials suggests approximately 56 ms of each single-record request is fixed connection and authentication cost rather than data-transfer time, meaning batching even a handful of records is substantially more efficient than transmitting them individually. At large batch sizes, this pattern reverses for uploads, which converge to near parity between local and hosted environments by 25,000-50,000 records, while download latency remains persistently 5.7-6.4x slower on hosted infrastructure even at scale. These results suggest that Nexus deployments intended for real-time digital twin applications should prioritize record batching over single-record transactions, and that download-path optimization on hosted infrastructure offers the largest remaining opportunity to reduce latency at scale. We anticipate these baseline measurements will serve as a reference point for future digital twin projects evaluating whether Nexus’s latency profile meets their real-time requirements, and as a benchmark for tracking the effect of future infrastructure or API changes.

99 - GENERAL AND MISCELLANEOUS↗

Hardware-Based Randomized Encoding for Sensor Authentication in Power Grid SCADA Systems

Supervisory Control and Data Acquisition (SCADA) systems are utilized extensively in critical power grid infrastructures. Modern SCADA systems have been proven to be susceptible to cyber-security attacks and require improved security primitives in order to prevent unwanted influence from an adversarial party. One section of weakness in the SCADA system is the integrity of field level sensors providing essential data for control decisions at a master station. In this paper we propose a lightweight hardware scheme providing inferred authentication for SCADA sensors by combining an analog to digital converter and a permutation generator as a single integrated circuit. Through this method we encode critical sensor data at the time of sensing, so that unencoded data is never stored in memory, increasing the difficulty of software attacks. We show through experimentation how our design stops both software and hardware false data injection attacks occurring at the field level of SCADA systems.

42 ENGINEERING↗

Assessing the Impact of Measurement Precision on Metabolite Identification Probability in Multidimensional Mass Spectrometry-Based, Reference-Free Metabolomics

Identification of compounds with minimal ambiguity remains a central challenge in mass spectrometry-based metabolomics. Conventional compound identification relies on comparing analytical signatures (e.g., mass-to-charge ratio, collision cross section, tandem mass spectra) against reference data obtained from measurements of authentic chemical standards. The breadth of annotatable compounds using this approach is necessarily limited by availability of authentic standards, analytical throughput, and resolving power of the separations that underly the measurements. The maturation of computational methods, both theory-driven and artificial intelligence/machine learning-based, for prediction of various molecular properties relevant to multidimensional mass spectrometry measurements has opened the door to a new “reference-free” paradigm of compound annotation. Through augmenting existing reference data for molecular properties with computational predictions, the universe of identifiable chemical species can be expanded significantly beyond its current limits. An unexplored aspect of this novel approach is understanding how to gauge confidence in resulting annotations, especially as the compound search space is expanded. Intuitively, the confidence of a compound annotation is related to the inherent discriminatory power of the molecular properties used for identification, as well as the precision with which the properties are measured or predicted. In this work, we characterize this relationship between measurement precision and identification probability in a systematic and quantitative fashion for a defined region of chemical space that includes organic small molecule metabolites. Importantly, this work establishes a framework for conducting metabolite identification probability analysis that enables others to quantify this relationship for their own compounds and properties of interest.

Metabolite Identification↗

TrustDER: Trusted, Private and Scalable Coordination of Distributed Energy Resources

In this project, the Stanford and SLAC Teams have developed a Trusted, Private and Scalable platform for coordinating Coordination of Distributed Energy Resources (TrustDER). This is a layered system that ensures private, trusted and scalable coordination and monitoring of DERs. It accommodates a variety of resources, such as solar generation, gensets and loads, with a particular focus on battery systems-based resources, as they are a transformational technology experiencing fast growth in adoption by large critical facilities. The platform can be used as standalone or added to existing aggregation systems to enable trust, privacy and resilience. TrustDER consists of layers that address each of the shortcomings of the existing state of the art. Each layer in the platform can operate independently but provides information to the layers above it to enable a novel form of overall coordination architecture. The project consists of several tasks, with each task dedicated to the design of each layer. Task 2 Resource Virtualization defined a software abstraction layer for distributed energy resources (DERs). The goal of this abstraction was to simplify the implementation of algorithms utilizing cooperation of DERs resources in a variety of use cases. Task 3 is on Secure ID for Asset Authentication. Identity Management Systems (IDMS) are a foundational infrastructure for interactions between entities (organizations, users, devices, and services). Secure ID is blockchain-based a distributed identity management system allowing (1) identity provisioning, (2) authentication, (3) authorization, and (4) identity data sharing for IoT-enabled assets on the electricity grid. In this project, the SLAC team focused on designing and testing Keymaker, a protocol for authenticating device identity managed by Secure ID. Task 5 Private and Safe Integration is focused on the design and evaluation of a DER cooperation scheme which allows for the aggregation of DERs without impacting network reliability. The approach is designed based on realistic assumptions regarding data availability, communication infrastructure limitations, and privacy. Task 6 Scalable Distributed Privacy for Information explored how virtualized batteries could be managed privately. Specifically, it examined the case in which a principal provides a partitioned battery to multiple clients. Task 7 Use Cases was to ensure that this technology was applied in relevant situations and scenarios. Primarily, this means that virtualization needed to be employed in a manner that either improved flexibility, bolstered security or privacy, or decreased costs.

25 ENERGY STORAGE↗

“Experimental investigation of the governing parameters of atmospheric ice nucleation using field-collected and laboratory generated aerosol particles and its application in cloud resolving models” (Final Report)

The objective of this research project is to improve our understanding of the role of aerosol particles acting as ice-nucleating particles (INPs) which in turn define the mixed-phase and cirrus cloud radiative properties and thus climate. The focus is placed on how the physicochemical particle population properties determine the particles’ ability to initiate ice nucleation. This research project combined micro-spectroscopic particle analysis, experimental ice nucleation studies, and model sensitivity studies to advance our predictive capability of the formation of mixed-phase and cirrus clouds. These project activities have led to new ice nucleation data from laboratory generated and ambient (authentic) aerosol particles furthering process-level understanding, insights in the role of organic aerosol in ice formation, and advancements in the interpretation and parameterization of ice nucleation.

54 ENVIRONMENTAL SCIENCES↗