Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “hardware security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Hamilton: Flexible, Open Source $10 Wireless Sensor System for Energy Efficient Building Operation

Sensors for improving building performance are rapidly populating the market, driven in part by the drive to reduce greenhouse gas emissions resulting from energy production as well as improve the interior environment for healthy and more productive spaces. UC Berkeley has led wireless sensor development over the past 25 years (e.g., Telos mote), with the Hamilton (named after Alexander Hamilton on the US $10 bill) as the most recent. The Hamilton sensor was designed as a low-cost high-performance sensor that is modular and interoperable. The objective of the Hamilton project was to create, evaluate and establish the technological foundations for secure and easy to deploy building energy efficiency applications utilizing pervasive, low-cost wireless sensors integrated with traditional Building Management Systems (BMS), consumer-sector building components, and powerful data analytics. The project included iterative hardware design, incorporating a high-performance database (BTrDb, http://btrdb.io/), creating and iterating the development of secure data middleware (BOSSwave, WAVE/WAVEMQ), working with and pushing the development of an open-source tiny operating system RiotOS, and implementing and improving protocols such as Thread/OpenThread and TCP/IP. The hardware benefited from careful design to drive down the cost; the design included a System-on-a-Chip (SoC), chip antenna, single crystal and five passive components. Careful design of the operating system created a low-power design to enable a long life with small batteries. The hardware included several sensors: temperature, radiant temperature, relative humidity, magnetometer, accelerometer, and light, with an optional occupancy (Passive InfraRed) sensor. The project was the basis of several applications, both internal to the research team and other researchers and professionals at other institutions. Several applications used the sensor hardware as the basis for other complex devices. Other applications used the sensors to improve building performance through interoperating with the building Heating Ventilation and Air-Conditioning (HVAC) system, such as using occupancy and/or distributed temperature sensing to reduce HVAC zone energy while still providing thermal comfort and to reduce peak loads in small commercial buildings. We demonstrated cloud-based energy analytics, implemented a schedule and a Model Predictive Controller in a small commercial building to optimize HVAC energy, occupancy and electricity price. Initial integration of these technological innovations was performed through the creation of execution containers containing the WAVE agent and various driver, proxy, or building system function logic. The research added to the understanding of efficient sensor hardware, secure middleware, time-series data management (high performance database), efficient communication protocols, and interoperating with applications and building systems. The project showed the technical effectiveness and economic feasibility of creating a low-cost, modular, and easy-to-deploy sensor. Through conversations with multiple end users, the research team discovered that many customers wanted data management and services in addition to the sensors. HamiltonIOT developed packages of sensors, border router, and data services to provide a seamless “plug-and-play” sensor deployment. Some customers were willing to pay for higher quality sensors (such as light); some customers wanted a robust enclosure (waterproof).

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

A Perspective on the Impact of Group Delay Dispersion in Future Terahertz Wireless Systems

This article discusses the challenges and opportunities of managing group delay dispersion (GDD), and its relation to the performance standards of future sixth-generation (6G) wireless communication systems utilizing terahertz frequency waves. The unique susceptibilities of 6G systems to GDD are described, along with a quantitative description of the sources of GDD, including multipath, rough surface scattering, intelligent reflecting surfaces, and propagation through the atmosphere. An experimental case-study is presented that confirms previous models quantifying the impact of atmospheric GDD. Several GDD manipulation strategies are presented, illustrating their hindered effectiveness in the 6G context. Conversely, some benefits of leveraging GDD to enhance 6G systems, such as improved security and simplified hardware, are also discussed. Finally, a perspective on using photonic GDD control devices is provided, revealing quantitative benefits that may unburden existing equalization schemes. Here, the article argues that GDD will uniquely and significantly impact some 6G systems, but that its careful consideration along with new mitigation strategies, including photonic devices, will help optimize system performance. The conclusion provides a perspective to guide future research in this area.

Strecker, Karl↗

Development of A Hardware-In-the-Loop (HIL) Testbed for Cyber-Physical Security in Smart Buildings

As smart buildings move towards open communication technologies, providing access to the Building Automation System (BAS) through the building's intranet, or even remotely through the Internet, has become a common practice. However, BAS was historically developed as a closed environment and designed with limited cyber-security considerations. Thus, smart buildings are vulnerable to cyber-attacks with the increased accessibility. This study introduces the development and capability of a Hardware-in-the-Loop (HIT) testbed for testing and evaluating the cyber-physical security of typical BASs in smart buildings. The testbed consists of three subsystems: (1) a real-time HIL emulator simulating the behavior of a virtual building as well as the Heating, Ventilation, and Air Conditioning (HVAC) equipment via a dynamic simulation in Modelica; (2) a set of real HVAC controllers monitoring the virtual building operation and providing local control signals to control HVAC equipment in the HIL emulator; and (3) a BAS server along with a web-based service for users to fully access the schedule, setpoints, trends, alarms, and other control functions of the HVAC controllers remotely through the BACnet network. The server generates rule-based setpoints to local HVAC controllers. Based on these three subsystems, the HIL testbed supports attack/fault-free and attack/fault-injection experiments at various levels of the building system. The resulting test data can be used to inform the building community and support the cyber-physical security technology transfer to the building industry.

Li, Guowen↗

Hardware-in-the-Loop Testbed for Cyber-Physical Security of Photovoltaic Farms

In the last decades, modem grids with distributed energy resources, such as photovoltaic (PV) farms, are increasingly vulnerable to cyber-attacks that seriously affect the stability and performance of the power system. While cyber-physical security of smart grids is extensively studied, most of the existing work focuses on the grid level and neglects the modeling and features of device-level power electronics converters (PECs). Furthermore, establishing a high-fidelity simulation testbed that can simulate harmonic frequencies of the PV farm is in urgent need. In this paper, a high-fidelity and real-time hardware-in- the-loop testbed is built to simulate the harmonics of power electronics converters for cyber-physical security of PEC-enabled PV farms. Based on this testbed, the impact of typical cyber-attacks and physical faults on the PV converter can be analyzed, thus providing a foundation for cyber-attack detection, root cause diagnosis, and resilient control to mitigate the adverse effects of cyber-attacks.

14 SOLAR ENERGY↗

Reimagining Codesign for Advanced Scientific Computing: Report for the ASCR Workshop on Reimagining Codesign

In March 2021, the U.S. Department of Energy’s Advanced Scientific Computing Research program convened the Workshop on Reimagining Codesign. The workshop, also known as ReCoDe, was organized around discussions on eight topic areas: (1) codesign for traditional high-performance computing workloads; (2) codesign of memory/storage systems; (3) codesign of machine learning, neuromorphic, quantum, and other non-von Neumann accelerators; (4) codesign for edge computing and processing at experimental instruments; (5) codesign for security and privacy; (6) hardware design tools and open-source hardware for high-productivity codesign; (7) tools, software stack, and programming languages for high-productivity codesign; and (8) quantitative tools and data collection for modeling and simulation for codesign. The panels identified four Priority Research Directions from these deliberations: (1) breakthrough computing capabilities with targeted heterogeneity and rapid design; (2) software and applications that embrace radical architecture diversity; (3) engineered security and integrity, from transistors to applications; and (4) design with data-rich processes.

97 MATHEMATICS AND COMPUTING↗

Performance Analysis of Scientific Computing Workloads on Trusted Execution Environments

Scientific computing sometimes involves computation on sensitive data. Depending on the data and the execution environment, the HPC (high-performance computing) user or data provider may require confidentiality and/or integrity guarantees. To study the applicability of hardware-based trusted execution environments (TEEs) to enable secure scientific computing, we deeply analyze the performance impact of AMD SEV and Intel SGX for diverse HPC benchmarks including traditional scientific computing, machine learning, graph analytics, and emerging scientific computing workloads. We observe three main findings: 1) SEV requires careful memory placement on large scale NUMA machines (1x -3.4x slowdown without and 1x -1.15x slowdown with NUMA aware placement), 2) virtualization - a prerequisite for SEV - results in performance degradation for workloads with irregular memory accesses and large working sets (1x -4x slowdown compared to native execution for graph applications) and 3) SGX is inappropriate for HPC given its limited secure memory size and inflexible programming model (1.2x -126x slowdown over unsecure execution). Finally, we discuss forthcoming new TEE designs and their potential impact on scientific computing.

97 MATHEMATICS AND COMPUTING↗

Investigating Formal Methods Tools and their Applicability for Hardware Vulnerability Remediation

Formal methods use mathematical logic and equations to prove that a system or code is secure. In this poster, I examine existing formal methods tools and their application for projects working to remediate vulnerabilities in hardware and hardware description language. This poster is focused on the tools ReWire and AutoGenILA and I hope to evaluate their benefits and weaknesses with the intention of creating an internal report on the application and weaknesses of existing formal methods tools and identifying gaps for future formal methods tool creation.

97 - MATHEMATICS AND COMPUTING↗

3D printed graphene-based self-powered strain sensors for smart tires in autonomous vehicles

The transition of autonomous vehicles into fleets requires an advanced control system design that relies on continuous feedback from the tires. Smart tires enable continuous monitoring of dynamic parameters by combining strain sensing with traditional tire functions. Here, we provide breakthrough in this direction by demonstrating tire-integrated system that combines direct mask-less 3D printed strain gauges, flexible piezoelectric energy harvester for powering the sensors and secure wireless data transfer electronics, and machine learning for predictive data analysis. Ink of graphene based material was designed to directly print strain sensor for measuring tire-road interactions under varying driving speeds, normal load, and tire pressure. A secure wireless data transfer hardware powered by a piezoelectric patch is implemented to demonstrate self-powered sensing and wireless communication capability. Combined, this study significantly advances the design and fabrication of cost-effective smart tires by demonstrating practical self-powered wireless strain sensing capability.

33 ADVANCED PROPULSION SYSTEMS↗

NA-IM TGESC Mobile Device Secure Sled [Slides]

SafeCase provides essential controls such as: 1) Audio masking and 2) camera blocking capabilities if a mobile device has been compromised. This exoskeleton phone case provides a solution in secure spaces at a hardware level providing key attack surface reductions and potential exposures from an audio and visual standpoint.

47 OTHER INSTRUMENTATION↗

A Real-Time Testbed for Smart Inverter Cyber Security Studies

Distributed energy resources (DER) have become a popular solution to modern-day issues surrounding the efficiency and reliability of power generation, as well as climate change concerns. Energy centers are shifting towards incorporating smart inverters with embedded functionalities such as high voltage ride through (HVRT), low voltage ride through (LVRT), active and reactive power compensation. However, the integration of smart inverters leave DER systems highly vulnerable to cybersecurity threats. The distributed network protocol 3 (DNP3) is a common method of communication between grid-tied hardware. Despite its popularity, the level of security leaves all hardware connected to the grid at risk of severe cyber-attacks. Thus, it is important to study any potential cybersecurity threats towards grid-tied smart inverters to mitigate cybersecurity vulnerabilities and refine existing cyber-security protections. This report describes the proposed testbed design to study cybersecurity threats to smart inverters. The testbed utilizes a real-time simulation case in RSCAD that includes a grid-tied wind turbine (WT) topology featuring two back-to-back two-level voltage source converters (BTB,2L-VSCs) and a permanent magnet synchronous machine (PMSM). The simulated case runs within the NovaCor real time digital simulator (RTDS). This report focuses on the design and implementation of a single module of the GTNETx2 card as a distributed network protocol and the configuration of an IEEE 1518 DNP database file that includes input and output variables mapped to different connection points in the grid that transmit and receive discrete, analog, and binary signals on command. This allows realistic emulation of the communication between the smart inverter and the grid for cybersecurity studies.

97 MATHEMATICS AND COMPUTING↗

A Multi-Site Networked Hardware-in-Loop Platform for Evaluation of Interoperability and Distributed Intelligence at Grid-Edge

Electric power systems have experienced large increases in the number of intelligent, connected and controllable devices being deployed, leading to a high degree of distributed intelligence at the grid-edge. These devices, both utility-owned and consumer-owned, include but are not limited to: renewable generation sources, energy storage, remote switches, voltage regulators, and smart controllable loads such as electric vehicles. These new devices provide significant potential for increased operational flexibility that can be leveraged to achieve system reconfiguration, resiliency improvements, power quality improvements, and distribution system automation. However, there are two significant challenges that must be addressed before these assets can be leveraged for operations: interoperability and system level validation prior to deployment. Because of the complexity of distributed control systems, and their interactions with legacy centralized controls, a purely simulations-based approach for pre-deployment validation is not sufficient. It requires hardware-in-loop testing to emulate the operational hardware devices and evaluate their performance. Additionally, securely integrating multiple test facilities at utility operators and vendors might enable rapid scale-up of evaluation platforms, and remove the need for multiple expensive standalone installations. Presented in this paper, is the development of a multi-site evaluation platform that employs Advanced Distribution Management Systems (ADMS), distributed control devices, real-time hardware-in-loop assets, secure communication links, and protocol adapters. This platform uses standards-based approaches and open-source tools, and hence can serve as a template for other researchers and institutions to implement their multi-site evaluation frameworks for pre-deployment testing.

Essakiappan, Somasundaram↗

A Scalable Quantum Cryptography Network for Protected Automation Communication (Final Report)

This is the final report for a CEDS-funded project aimed at developing a new quantum technology for securing utility communication networks used to control and monitor electrical grid equipment. Securing these control networks represents a unique challenge as the performance of the security solution has a direct impact on the stability and reliability of the electrical grid. Traditional, software-based solutions - developed for information networks - are not suitable for utility control networks because they introduce latency, require burdensome maintenance and upgrades, are often incompatible with legacy equipment, and introduce operational complexity that reduces grid reliability. Consequently, many U.S. utilities do not use existing solutions and, instead, protect their critical control networks through the careful isolation and obscuration of their networked equipment. With more utilities embracing grid automation, the attack surface that utilities must defend from hackers has grown to an unmanageable size. To address this situation, Qubitekk and its partners proposed and developed a hardware-based solution that can secure critical control networks without negatively impacting grid performance. This new solution is based on quantum key distribution (QKD) techniques that guarantee secure key generation and distribution across a utility control network. Through deployment and field testing of a prototype QKD system, we have shown that this solution delivers long-term network security, is technically feasible to implement and maintain on a utility’s distribution substation network and does not negatively impact grid operations. In addition, the project has identified and solved key challenges associated with generating, transmitting, and measuring coherent photonic quantum states on a real-world fiber optic network. These additional findings are playing a critical role in advancing quantum networks for quantum computing applications. An overview of the QKD prototype development effort, field testing activities and results, and additional findings relevant to emerging quantum networks are presented in this report.

71 CLASSICAL AND QUANTUM MECHANICS, GENERAL PHYSIC↗

Service-Based, Segmented, 5G Network-Based Architecture for Securing Distributed Energy Resources: Preprint

As the number of connected devices in the energy grid increase exponentially, so too are the cybersecurity risks. With the development of modern communications standards such as 5G and beyond the extent to which devices will continue to connect will continue to increase exponentially along with the inherent risks. However, 5G also includes features to help address cybersecurity concerns and therefore helping to mitigate many of these risks. This paper proposes a new service-based network architecture implementing network-slicing capabilities for connected systems and devices to improve performance, availability, security, and reliability of the grid devices and services. This paper considers the quality of service requirements and criticality of services needed for securely monitoring, operating, and securing Distributed Energy Resource (DER) devices. From developed use cases, network slicing is implemented based on these requirements and resource allocations. This work then highlights examples of how slicing can help prevent standard existing attack methods such as a denial-of-service or similar attack which limits resource availability and network bandwidth to the service and thus limiting its ability to affect other services by misbehaving. The designed network architecture use case will be further tested on a local virtualized testbed to verify secure operation and availability of services. Using hardware-in-the-loop devices and systems on this local testbed, this fully segmented, secure network may be realized and evaluated. Finally, this paper presents the results of this testing.

5G↗

Hardware-Based Randomized Encoding for Sensor Authentication in Power Grid SCADA Systems

Supervisory Control and Data Acquisition (SCADA) systems are utilized extensively in critical power grid infrastructures. Modern SCADA systems have been proven to be susceptible to cyber-security attacks and require improved security primitives in order to prevent unwanted influence from an adversarial party. One section of weakness in the SCADA system is the integrity of field level sensors providing essential data for control decisions at a master station. In this paper we propose a lightweight hardware scheme providing inferred authentication for SCADA sensors by combining an analog to digital converter and a permutation generator as a single integrated circuit. Through this method we encode critical sensor data at the time of sensing, so that unencoded data is never stored in memory, increasing the difficulty of software attacks. We show through experimentation how our design stops both software and hardware false data injection attacks occurring at the field level of SCADA systems.

42 ENGINEERING↗

Vedizar Fingerprinter

SAND2025-03289O Vedizar Fingerprinter simplifies the process of identifying devices on a network by analyzing traffic data. It uses a unique library to recognize different devices, making it easier for users to understand what is happening on their networks. This software is ideal for IT and operational technology environments, helping organizations monitor their networks effectively. By saving results in a database, it allows for easy access and review of device information. Users can enhance their network security and optimize performance without needing specialized hardware or technical expertise. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Jacobellis, John [Sandia National Lab. (SNL-CA), L↗

Tikiri—Towards a lightweight blockchain for IoT

Internet of Things (IoT) platforms have been deployed in several domains to enhance efficiency of business process and improve productivity. Most IoT platforms comprise of heterogeneous software and hardware components which can potentially introduce security and privacy challenges. Blockchain technology has been proposed as one of the solutions to realize IoT security by leveraging the (a) Immutable ledger, (b) Decentralized architecture and (c) Strong cryptography primitives. However, integrating blockchain platforms with IoT based applications presents several challenges due to lack of (a) acceptable performance on resource-constrained devices, (b) high transaction throughput, (c) keyword-based search and retrieve, (d) transaction back pressure operations, and (e) real-time response. In this paper, we propose a lightweight blockchain platform, “Tikiri”, for resource-constrained IoT devices. Tikiri uses Apache Kafka for the consensus and proposes new blockchain architecture to handle real-time transaction execution on the blockchain. Tikiri is characterized by functional programming and actor-based smart contract platform that realizes concurrent execution of transactions in the blockchain. Tikiri realizes a lightweight and scalable blockchain that can provides performance on the resource-constrained IoT devices.

97 MATHEMATICS AND COMPUTING↗

Ransomware Security Threat Modeling for Photovoltaic Systems

Ransomware attacks are one of the most dangerous cyber-attacks which can disrupt the operation of photovoltaic (PV) systems and incur an enormous economic loss. This paper introduces a ransomware security threat modeling method that identifies potential vulnerabilities, threats, and impacts of ransomware attacks targeting a PV system. Here, the security threat modeling consists of three steps: 1) system identification, 2) threat modeling that finds existing vulnerabilities, 3) attack modeling that designs attack profiles to succeed ransomware attacks, and 4) penetration testing that performs authorized cyber-attacks and analyzes impacts of the ransomware attack profiles using a real-time hardware-in-the-loop (HIL) PV system security testbed.

attack modeling↗