Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “firmware analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

27 records · Page 2

Equipment Assessment Guide: A Technical Inspection and Hardening Guide for Devices in Power Grid Operations

This Equipment Assessment Guide, developed by Idaho National Laboratory (INL), provides a comprehensive framework designed to enhance the security of operational technology (OT) devices within power grid operations. The guide outlines essential steps for asset owners to conduct technical inspections and harden vulnerable hardware and firmware components commonly found in embedded systems. It focuses on components frequently targeted by cyber threats, offering valuable identification techniques for locating and recognizing critical components on devices. Additionally, the guide presents recommended secure configurations aimed at minimizing exposure and reinforcing defenses, along with impact analysis that highlights the potential consequences for grid operations if components are compromised. By implementing the recommendations outlined in this guide, asset owners can significantly enhance their cybersecurity posture, reduce the attack surface of field-deployed devices, and improve the resilience of grid services against emerging cyber threats.

42 - ENGINEERING↗

Report on ISR-1 High-Altitude Balloon Flight

To test small technologies at lower cost for space science applications, LANL has developed a small high altitude balloon payload that could, in the future, be regularly and inexpensively launched from LANL. A neutron detector, NEMO, was integrated to evaluate its performance in a space-like mixed-radiation environment and collect neutron data in the atmosphere. In collaboration with EES-14, a high-altitude balloon payload was launched from LANL Technical Area 51 on February 27, 2023 and April 17, 2023. For real-time geolocation, a SAM-M8Q M8 GNSS module was used to get position and time, and an Iridium RockBLOCK 9603 was used to communicate with the ground using the Iridium satellite fleet. These modules were all controlled using an Iteaduino Mega microcontroller board. Finally, a High Altitude Science Eagle Flight Computer with a temperature pressure sensor ran independently, writing data to an SD card. All of these modules were powered by a 5 mAh lithium polymer battery. The battery was attached to the bottom of the payload while the remaining electronics were embedded in the underside of the top of the payload. These modules were wired as seen in Figure 1-2. The Iteaduino Mega microcontroller board was programmed to use the RockBLOCK to send a message once every 10 minutes containing neutron and GPS data read off the NEMO and SAM M8Q, respectively. Once the message send attempt finished, the RockBLOCK would be slept for the rest of the 10 minute interval. The Eagle Flight Computer ran continuously throughout the flight, taking data every 6 seconds. The RockBLOCK message data was set up to be delivered from the Iridium satellite fleet to a website, where it was stored and parsed to create live maps and plots for analysis and balloon retrieval. The RockBLOCK message data was additionally configured to be sent to an email as a fail-safe. The payload was ground-tested successfully for over 50 hours, with multiple revisions occurring to best prepare for conditions at altitude and improve the software and firmware to fix any issues that cropped up with the data pipeline. Additional to the balloon payload, the flight had an attached iMet-4 radiosonde and Garmin T5 GPS Dog Collar. The radiosonde provided GPS and meteorological data. The T5 dog collar is used along with a Garmin Astro 430 to track the balloon at a range of up to 9 miles for retrieval. The balloon itself was initially a 1600 g meteorological balloon with an attached High Altitude Science parachute, both of which can be seen in Figure 1-3. After the first flight, the EES team swapped to a Rocketman parachute.

42 ENGINEERING↗

Towards a New Supply Chain Cybersecurity Risk Analysis Technique

Supply chain cyber-attacks, such as the SolarWinds Orion attack, are occurring with greater frequency. These attacks compromise a digital device before it is sent to customers, bypassing traditional security controls to remain persistent and undetected in operational environments. While supply chain attacks are prevalent, methods for analyzing the risk of these attacks are currently unavailable. This paper proposes new supply chain cyber-attack difficulty and risk metrics to evaluate the relative risk of an attack throughout the supply chain lifecycle. Difficulty metrics for each stakeholder in a digital device’s supply chain (e.g., hardware manufacturing, firmware development, software development, storage, and distribution entities) are calculated using scores from cybersecurity maturity questionnaires in a Bayesian Network leaky Noisy-MAX model. These difficulty metrics are then used to calculate an overall supply chain cyber-attack risk. Vulnerability and recoverability metrics are also proposed to evaluate the relative stakeholder influence in the attack risk. These proposed relative risk metrics enable continuous supply chain monitoring, provide decision-makers with information necessary for improved supplier selection, and help drive improvements in the cybersecurity posture of the stakeholders in their supply chain.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Commissioning of the Mu2e tracker DAQ, planning for the Vertical Slice Test and pre-pattern recognition studies

The primary objective of the Mu2e experiment at Fermilab is to search for the neutrino-less coherent $\mu \rightarrow e$ conversion in the field of an aluminum nucleus ($\mu^- \text{Al} \rightarrow e^- \text{Al}$). The signature of this process is a monochromatic Conversion Electron (CE) with an energy of approximately 104.97 MeV \cite{bartoszek2015mu2e}. Within the Standard Model (SM), the branching ratio for this process, including neutrino masses and oscillation, is expected to be less than $\mathcal{O}(10^{-50})$. This value is far beyond current experimental capabilities. However, models of physics beyond the SM predict much higher relative rates, approaching an observable level. The SINDRUM II experiment set an upper limit on muon conversion at $7 \times 10^{-13}$ (90\% CL) on Au target \cite{SINDRUMII:2006dvw}, and the Mu2e collaboration aims to improve this limit by four orders of magnitude. Observing this process would provide a clear evidence of physics beyond the Standard Model. A brief discussion of the theoretical and experimental aspects is provided in Chapter \ref{intr}. Mu2e adopts a sophisticated experimental setup to achieve its goals, further described in Chapter \ref{mu2echapter}. The central part of the Mu2e detector is the tracker, that consists of 18 tracking stations. The tracker must provide excellent momentum resolution, approximately 1 MeV/c, to distinguish the monochromatic CE signal from the background. To minimize the energy losses, a straw tube tracker will be used \cite{bobbb}. Chapter \ref{chaptertrk} provides an overview of the straw tracker design and its working principles. This Thesis presents a comprehensive study of the Mu2e tracker, covering complementary aspects from initial commissioning to optimization and first steps of the calibration processes. My work at Fermilab has been focused on the complete Data Acquisition (DAQ) testing from both hardware and software perspectives. I was involved in the commissioning of the Mu2e DAQ system and the Vertical Slice Test (VST) of the tracker. The VST encompasses the entire testing chain, from the straws to the readout, and to processed data on disk. I was also focused on the offline analysis, especially on pre-pattern recognition studies, to explore the best methods for identifying $\delta$-electrons during the data taking. Chapter \ref{commissioning} details the commissioning of the tracker DAQ system, emphasizing the importance of understanding of the readout process before the data acquisition. This includes validating the readout logic and firmware through Monte Carlo simulations to confirm functionality and buffering, monitoring the quality of the data from the tracker preamplifiers and front-end electronics, and assessing overall DAQ performance to ensure reliability during future calibration and data-taking. Chapter \ref{planning} discusses the initial steps towards the tracker calibration. The ultimate goal is to perform a time calibration of the first assembled station of the tracker using cosmic muons, aiming for a longitudinal hit position resolution better than 4 cm. This involves determining the signal propagation times and channel-to-channel delays. I performed a Monte Carlo study to determine the impact of the station orientation on the quality of the calibration, in particular on the cosmic track reconstruction, focusing on potential biases that could arise. These studies provide essential insights into the operation, optimization, and calibration of the Mu2e tracker system. Given the high data volume expected during Mu2e operations, estimated at approximately 7 PBytes per year, optimizing memory usage and minimizing CPU consumption are critical. A significant challenge lies in effectively flagging $\delta$-electron hits, which are the primary source of hits in the tracker, without compromising the efficiency of CE hit detection and track reconstruction. A detailed study of pre-pattern recognition and a thorough comparison of two $\delta$-electron flagging algorithms is provided in Chapter \ref{delta}. In Chapter \ref{conclusions}, the findings are concisely summarized, offering a comprehensive synthesis of the research and emphasizing the key insights derived from this study.

43 PARTICLE ACCELERATORS↗

Nanosecond Gated CMOS Camera (NSGCC) ICD (Rev. 2.1)

The Ultra-Fast X-ray Imager (UXI) program is an ongoing effort at Sandia National Laboratories to create high speed, multi-frame, time-gated Read Out Integrated Circuits (ROICs), and a corresponding suite of photodetectors to image a wide variety of High Energy Density (HED) physics experiments on both Sandia’s Z-Machine and LLNL’s National Ignition Facility (NIF). Several cameras have been designed over the length of the program; one of the most recent is the Icarus, which is an improvement on past imagers (Furi and Hippogriff). A second sensor that can be connected is the Daedalus sensor. The Icarus is a 1024 × 512-pixel array with either 25 μm or 8 µm spatial resolution containing four frames of storage per pixel and has improved timing generation and distribution components while achieved 2 ns time gating. The Daedalus sensor is also a 1024 x 512-pixel array with 25 µm special resolution containing three frames of storage per pixel and has an increased set of features for a wider variety of applications from interlacing of rows in each frame to configurability of all shutters. See Section 14 for details regarding the Icarus implementation of the firmware and Section 15 for details regarding the Daedalus implementation. Due to the unique test environments UXI sensors are targeted for, full custom hardware was required to physically mount an Icarus or Daedalus sensor, manage its various functions, and read out pixel data for transfer to a host computer. Beyond experimental functionality, the hardware also needed to accommodate sensor characterization requirements. Lawrence Livermore National Laboratory’s ‘Version 4.0 Board’ was the result of these efforts. It mounts all the components required to fully utilize the Icarus and Daedalus sensors including analog to digital converters to convert pixel data and various system voltages to digital form for readout and analysis, DAC channels for remote configuration of critical bias voltages, static random-access memories to buffer pixel data, RS422 and Gigabit Ethernet communications for remote access, and an FPGA to tie these components together. This document describes the FPGA electrical interfaces in detail to allow the reader a greater understanding of the device, and to facilitate implementation of custom software to control and manage it. The Version 4.0 Board is a continuation of the Nano-second Gated CMOS hardware design that retains much of the functionality of the Version 1.0 Board while adding features including a DAC instead of digital potentiometers, as well as sensors for pressure and radiation. The Version 4.0 board is intended for applications requiring tight form-factor enclosures. It is composed of two stacking boards; one holds the FPGA and regulators to power the various components of the board while the other contains the mating connector to the sensor, image-readoff ADCs, the DAC, and other components.

42 ENGINEERING↗

Dynamic Probabilistic Safety Assessment Studies for Advanced Reactor Using RAVEN

Probabilistic Safety Assessment (PSA) is used extensively to evaluate the risks associated with complex engineering systems like Nuclear Power Plants (NPPs). Current PSA models are based on the Event-Tree/Fault-Tree (ET/FT) methodology. ET and FT models are static and are based on Boolean logic approaches. In the past, concerns have been raised in the literature regarding the capability of the traditional static modelling approaches to adequately account for the impact of process, hardware, software, firmware and human interactions on the stochastic system behaviour. To overcome the limitations of the traditional approach to PSA, several dynamic PSA methodologies have been proposed. One of the dynamic PSA methodologies used for dynamic evaluations is Dynamic Event Tree (DET) framework which can be used to assess the impact of the parameter variability and scenario dynamics on the PSA model for the initiating event. The DET framework couples the stochastic model (number of component/trains that start on demand, operator action timing, etc.) with a Thermal-Hydraulic (TH) model of the plant. This paper explores the use of DET along with a case study on advanced reactor. The initiating event selected for the study was Class IV power supply failure event. The TH analysis considering uncertainty in various parameters was performed using RELAP5 and Reactor Analysis and Virtual control ENvironment (RAVEN) tool. Based on the uncertainty analysis, it is concluded that the peak clad temperatures (PCT) are within the limits in all the code runs implying a high-degree of safety margin. However, variation in time to reach the PCT was observed among the code runs and the mean time to reach the PCT was found to be around 8590sec (approximately 2.4 hours). Hence, sufficient time margin is available for human intervention and the operator might have a relatively stress-free state during such an accident scenario. Due to the static nature of the traditional PSA models, the safety margin available was lesser, whereas, with the help of dynamic PSA models, one can demonstrate that the actual available safety margin is more in the present case study and is valuable input from the design point of view.

99 GENERAL AND MISCELLANEOUS↗

EVSE Cybersecurity and Resilience

Consequence-driven Cybersecurity Analysis for Extreme Fast Charging Electric Vehicle Infrastructure Electric vehicle (EV) development and associated charging infrastructure are expected to advance rapidly. Thirty percent of all global vehicle sales may be EVs and hybrid EVs by 2025, and they will rely on increasingly sophisticated strategies for grid integration. Next-generation EV charging infrastructure is expected to include interconnected renewable resources, such as photovoltaic (PV) arrays and battery storage systems, along with grid-edge devices. Although distributed energy resources (DERs) are useful in several ways, such as peak shaving at high demand times and backup supply for added resilience, the integration of vehicle charging and DERs could create more avenues for cyberattack. Physical and/or remote access to EV charging station components, including charge ports, power electronics, controllers, and local generation (e.g., PV and energy storage) could be paths to cause power fluctuations, leading to altered operations at the charging station, escalated privileges to administrative systems, exfiltration of financial information (including personally identifiable information), and reduced grid stability. One compromised EV supply equipment component can open the door to a variety of exploitable vulnerabilities. Cloud computing and mobile application control have the potential to expand the threat surface to non-repudiation and firmware integrity challenges. Vendor clouds have access to hundreds of chargers, and if compromised, can scale the attack surface exponentially. The high power and voltage levels of xFC infrastructure (e.g., 400 kW at 1000- V DC) increase the hazards and ability to impact the grid and vehicles more than lower-power charging systems. Legacy communications systems and protocols could also put EV infrastructure at risk of cyberattacks requiring a robust patch management process. Communications networks link EVs and chargers to several stakeholders - including charging station operators, grid operators, vendors/manufacturers, and aggregators - who have both physical and network access to share information for control, monitoring, and analytics. Information in these networks that is vulnerable to compromise includes the state of charge, charging duration, payment information, electricity price, and load control. Analyzing and prioritizing these interconnections risks could help address cybersecurity related to data leakage and manipulation.

charging↗

Fast inference of Boosted Decision Trees in FPGAs for particle physics

We describe the implementation of Boosted Decision Trees in the hls4ml library, which allows the translation of a trained model into FPGA firmware through an automated conversion process. Thanks to its fully on-chip implementation, hls4ml performs inference of Boosted Decision Tree models with extremely low latency. With a typical latency less than 100 ns, this solution is suitable for FPGA-based real-time processing, such as in the Level-1 Trigger system of a collider experiment. These developments open up prospects for physicists to deploy BDTs in FPGAs for identifying the origin of jets, better reconstructing the energies of muons, and enabling better selection of rare signal processes.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

The data acquisition system of the LZ dark matter detector: FADR

The Data Acquisition System (DAQ) for the LUX-ZEPLIN (LZ) dark matter detector is described. The signals from 745 PMTs, distributed across three subsystems, are sampled with 100-MHz 32-channel digitizers (DDC-32s). A basic waveform analysis is carried out on the on-board Field Programmable Gate Arrays (FPGAs) to extract information about the observed scintillation and electroluminescence signals. This information is used to determine if the digitized waveforms should be preserved for offline analysis. The system is designed around the Kintex-7 FPGA. In addition to digitizing the PMT signals and providing basic event selection in real time, the flexibility provided by the use of FPGAs allows us to monitor the performance of the detector and the DAQ in parallel to normal data acquisition. Furthermore, the hardware and software/firmware of this FPGA-based Architecture for Data acquisition and Realtime monitoring (FADR) are discussed and performance measurements are described.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗