Enhancing Cybersecurity for Industrial Control Systems: Innovations in Protecting PLC-Dependent Industrial Infrastructures
Not Available
SEARCH · Engineering Papers
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Not Available
An emerging trend in advanced manufacturing is printed electronics and sensors. The ability to print customized electronics and sensors integrated into functional packages is a growing need within a variety of growing markets such as smart manufacturing, internet of things (IoT), and the small satellite industry. Both Oak Ridge National Laboratory (ORNL) and the MITRE Corporation have seedling research efforts evaluating the potential for future printed electronic systems. High frequency, wide-bandwidth phased array antennas (i.e. >45 GHz) open the door to new applications. However, such sensors require currently prohibitively small feature sizes for commercial 3D printing technologies along with increasing challenges with connecting the driving electronics to such features. An additional finding with related advanced manufacturing challenges is the rapid production of 3D additive connectors for integration with commercial printed circuit boards (PCBs), primarily for advanced in-circuit inspection techniques. This work is developing additive manufacturing processes for producing connected and conductive fine scale 3D features. The primary focus was on aerosol-jet printing (AJP), which has a small minimum resolution (<50 µm) but is traditionally printed flat with small height/width aspect ratios <<1, and developing controls to enable fully 3D, high aspect ratio, and unsupported features. In Phase 1 of this effort, baselines of process performance were characterized, and test coupons produced for both ultra-high frequency antennas and microstructures to support reverse engineering of PCBs. In Phase 2, these efforts will be extended for system demonstration of ultra-high frequency antenna arrays, as well as reverse engineering circuitry for dense PCBs.
Cities, the world over, are fuelling economic growth. At the same time, rapid urbanization is a root cause of serious environmental damage. Recent WHO global air pollution guidelines highlight air pollution as a critical environmental threat along with climate change. To address these threats, smart cities and clean air programs are on a rise. In smart cities, data and Information and Communication Technologies (ICT) are major drivers of city transformations. The 4th Industrial Revolution (4IR) technologies such as the Internet of Things (IoT), big data, artificial intelligence (AI), and cloud computing have the potential to accelerate these transformations toward urban resilience. However, the success of smart cities and clean air programs depends on cohesive multi-sector stakeholder contributions. This study conducted interdisciplinary participative stakeholder analysis to understand the data, and sectorial challenges, to outline the technological opportunities to facilitate clean air programs in Indian smart cities. The research highlights gaps due to siloed stakeholder operations, lack of data calibration, non-alignment of smart city and air quality management services, non-availability of health exposure data, and difficulty in translating scientific data into implementable actions. Stakeholders expressed potential ‘fit for the purpose’ use of IoT devices, satellites, smartphones, and mobility data augmented by AI methods in bridging these gaps. In conclusion, the analysis points toward a need to develop an easily accessible and ubiquitous urban data governance ecosystem enabling seamless cross-sector data exchanges to build trusting relationships among the stakeholders across the air quality management value chain.
Thin-film thermoelectrics (TEs) with a thickness of a few microns present an attractive opportunity to power the internet of things (IoT). Here, we propose screen printing as an industry-relevant technology to fabricate TE thin films from colloidal PbSe quantum dots (QDs). Monodisperse 13 nm-sized PbSe QDs with spherical morphology were synthesized through a straightforward heating-up method. The cubic-phase PbSe QDs with homogeneous chemical composition allowed the formulation of a novel ink to fabricate 2 μm-thick thin films through robust screen printing followed by rapid annealing. A maximum Seebeck coefficient of 561 μV K -1 was obtained at 143 °C and the highest electrical conductivity of 123 S m -1 was reached at 197 °C. Power factor calculations resulted in a maximum value of 2.47 × 10 -5 W m -1 K -2 at 143 °C. To the best of our knowledge, the observed Seebeck coefficient value is the highest reported for TE thin films fabricated by screen printing. Thus, this study highlights that increased Seebeck coefficients can be obtained by using QD building blocks owing to quantum confinement.
In order to guarantee that a system meets adequate levels of reliability and availability, system performances are continuously monitored and analyzed thanks to the technological advancements driving the Industry 4.0 revolution. An Industry 4.0 approach is typically based on advanced statistical, big data mining, machine learning, and internet-of-things methods designed to detect anomalies in the behavior of system, detect the most likely failure modes, and provide indications to system engineers on when maintenance activities should be performed before system performance are deemed unacceptable (which can be generated by diagnostic and prognostic methods). However, these analyses, which are designed to automatize and increase the efficacy of the system maintenance program, require large amount of data which can come in various forms: numeric, textual, images, sounds etc. Such data constitutes the historic knowledge benchmark to track system performances and support system engineer decisions. Here we claim that data is not sufficient to support this kind of analyses when applied to systems characterized by complex architectures and behaviors. Robust system engineer decisions require the ability to understand the system operational context that lies behind the observed data elements. In this respect, system models are in fact necessary to “put data in context” and capture relationships between data elements. Industry 4.0 methods require in fact contextual knowledge as a basis upon which hypotheses can be generated and assumptions tested. In our view, for complex systems, model-based system engineering (MBSE) models can afford this contextual knowledge, as they are typically used to describe systems architecture and dynamic behaviors. System knowledge is here intended as the blending of collected data and system architecture which takes the form of a “knowledge graph”. A knowledge graph is a database which consists of a large set of nodes (in our case an entity can be either a data or an MBSE element) which are linked to each other. The types of nodes and links follow a pre-defined topology, sometimes also refers as an ontology, that is designed to fit the actual decisions that needs to be performed. We show here how a knowledge graph can be defined to support system engineer maintenance decisions and how the same graph can be built based on system MBSE models and pre-processed data from numeric (through anomaly detections and diagnostic methods) and textual elements (through technical language processing TLP).
The Internet of Things (IoT) encompasses a vast network of interconnected devices embedded with software, sensors, and network connectivity, enabling data collection and exchange. While IoT technology revolutionizes various industries, it also introduces significant security challenges. This research focuses on enhancing IoT security through the implementation of Zero Trust Architecture concepts, specifically targeting the Network and Device pillars of the Cybersecurity and Infrastructure Security Agency’s Zero Trust Maturity Model. By generating Codified Attack Surfaces (CAS) using custom Structured Threat Information eXpression bundles, this project aims to provide enhanced visibility into network communications, detect vulnerabilities in device firmware, and improve the overall security posture for IoT devices and networks. The methodology involves defining custom STIX schema and objects, collecting data from intra-IoT traffic, external network traffic, and firmware analysis, and automating the conversion and correlation of this data into STIX bundles. The automated generation of attack surfaces offers comprehensive insights into activity, vulnerabilities, and anomalies within an IoT environment, enabling proactive threat identification and mitigation.
As Internet of Things devices and cloud-based platforms become more mature, Energy Management and Information Systems (EMIS) are increasingly gaining momentum in the building industry. In large commercial buildings, Fault-Detection and Diagnostic (FDD) and energy information systems (EIS) are now established technologies with tens of providers and thousands of deployment sites across North America. The new frontier for the EMIS technology is now represented by control systems that use advanced system optimization (ASO) methods to improve the operations of the HVAC system. Given the complexity of the integration of such systems with the existing building automation systems (BAS) and the higher risk involved with direct control of the HVAC, these systems are still emerging in the market. This paper presents the results of a project in which a start-up company partnered with a research institution to develop a cloud-based software EMIS solution and deployed it in a university campus in California. The software system included advanced sensing, data acquisition, storage and advanced control and analytics applications developed on top of the native BAS. The new platform controls ten buildings on the campus and the FDD and the ASO applications deployed on this platform were able to generate energy savings of up to 35% and 25% in certain buildings for each functionality respectively. Where the platform did not save energy, it improved building service (air quality). Lessons learned include the importance of collaborating with and training the building operators and evaluating whether the legacy system can work reliably with the new technology.
Mitigation of methane emissions are a critical factor to limiting the impact of the natural gas industry on global climate change. Throughout the period of 2020-2024, the University of New Mexico and its commercialization partner and subcontractor, SensorComm Technologies, Inc. (SCT), have worked together to develop a low-cost Artificial Intelligence (AI)-driven Internet of Things (IoT)-based multi-gas sensor platform for methane emissions detection. In the final year of the project, we extended this work to include hydrogen detection in support of a transition to a hydrogen economy where hydrogen could be transported through existing natural gas infrastructure. Mixed potential electrochemical sensors were first prototyped by ceramic additive manufacturing and then transitioned to conventional ceramic manufacturing tape casting and screen-printing technologies in preparation for mass production. Demonstrated limits of detection of 5 ppm of methane in natural gas and 1 ppm of hydrogen were measured. These limits of detection are among the lowest of solid-state electrochemical sensors that have been reported in the literature or available in the industry. Machine learning algorithms were developed to identify natural gas mixtures with > 98% accuracy level and quantify methane concentrations at 97% accuracy. The presence of hydrogen could also be identified, and its concentration quantified at these accuracy levels. These algorithms were optimized for running on portable computing hardware which enabled > 1 Hz processing rates. A portable packaged IoT system was integrated with the electrochemical sensor in collaboration with SCT. The package consists of readout electronics with < 1 mV resolution, sensor temperature control, and data transmission over cellular wireless and/or Wi-Fi networks. Field testing was performed in two rounds at Colorado State University’s Methane Emissions Technology Evaluation Center (CSU METEC). The first round of testing demonstrated successful measurements of methane from an underground natural gas leak of 20 standard liters per minute (SLPM), which agreed with previously published literature using more sophisticated and expensive analytical equipment. The second round of testing showed that an above ground leak of 2 SLPM of hydrogen could be detected at 32 ft. This project has resulted in six published peer reviewed journal articles, over ten presentations at professional conferences, and one full patent application filed in 2023. Future work on this project includes increased sensitivity, higher production yields, and applications in the hydrogen safety and flare emissions monitoring spaces.
By the year 2020 it is estimated that there will be more than 50 billion devices connected to the Internet. These devices not only include traditional electronics such as smartphones and other mobile compute devices, but also eEnabled technologies such as cars, airplanes and smartgrids. The IoT brings with it the promise of efficiency, greater remote management of industrial processes and further opens the doors to world of vehicle autonomy. However, IoT enabled technology will have to operate and contend in the contested domain of cyberspace. This discussion will touch on the impact that cybersecurity has on IoT and the people, processes and technology required to mitigate cyber risks.
Halide perovskite indoor photovoltaics (PVs) are highly promising to autonomously power the billions of microelectronic sensors in the emerging and disruptive technology of the Internet of Things (IoT). However, how the wide range of different types of hole extraction layers (HELs) impacts the indoor light harvesting of perovskite solar cells is still elusive, which hinders the material selection and industrial–scale fabrication of indoor perovskite photovoltaics. In the present study, new insights are provided regarding the judicial selection of HELs at the buried interface of halide perovskite indoor photovoltaics. This study unravels the detrimental and severe light–soaking effect of metal oxide transport layer–based PV devices under the indoor lighting effect for the first time, which then necessitates the interface passivation/engineering for their reliant performance. This is not a stringent criterion under 1 sun illumination. By systematically investigating the charge carrier dynamics and sequence of measurements from dark, light–soaked, interlayer–passivated device, the bulk and interface defects are decoupled and reveal the gradual defect passivation from shallow to deep level traps. Thus, the present study puts forward a useful design strategy to overcome the deleterious effect of metal oxide HELs and employ them in halide perovskite indoor PVs.
Nanoscale materials possess distinct physical and chemical attributes including size-dependent properties, quantum confinement, high surface-to-volume ratio, and superior catalytic activity. These unique qualities enable sensors with high sensitivity, robustness, and fast time response. As the emergence of the Internet of Things (IoT) demands increased production of sensors, it also provides an impetus for concentrated nanomaterial-based sensor research. Meanwhile, additive manufacturing (AM) of nanomaterial-based sensors is critical to bridge the gap between one-off, lab-scale fabrication and cost-effective, industrial-scale production with high reproducibility. By applying the design flexibility and cost savings of AM techniques, a new generation of nanomaterial-based sensing platforms can be integrated with IoT devices in the consumer space. Furthermore, emergent research in human-machine interfaces, food safety, and point-of-care diagnostics will be expedited by the development of sensors that can be printed with irregular form factors. In this Review, the relative strengths and weaknesses of printed sensor systems based on zero-, one-, and two-dimensional nanomaterials are discussed. In addition, sensors enabled by printable soft nanomaterials, heterostructures, and nanocomposites are surveyed due to their synergistic advantages for wearable healthcare monitoring and soft robotics. Lastly, a roadmap for the next decade of research on this topic is provided.
The Modbus communication protocol is a widely adopted communication standard in industrial control systems. This communication protocol is known for being reliable and straightforward to implement while being versatile in terms of its operating parameters while supporting multiple formats over various hardware infrastructures and architectures. Many intelligent devices such as Programmable Logic Controllers (PLCs), Human-Machine Interfaces (HMIs), Internet-of-Things (IoT), and various Operational Technologies (OT) utilize Modbus for their communication systems. These types of systems must communicate with each other through a standardized and central communication process. To support the integration of these modular systems, a Field-Programmable Gate Array (FPGA) can act as an embedded central routing fabric for this communication to take place. Embedded systems are versatile enough to interface with various devices and systems to accomplish various goals. Additionally, embedded systems require relatively small physical designs to minimize the required resources to facilitate the intended application by providing low-level system access. This minimization of system resources goes hand in hand with reducing the financial cost of a proposed solution or system. As remotely collaborating researchers often use FPGAs to prototype designs that are required to have a method for data transmission among systems, it is imperative to provide a baseline standard for communications among devices and systems. A typical method of implementing the Modbus RTU communication protocol in an embedded environment is using integrated logic architectures within the FPGA called “Intellectual Property (IP) cores.” IP cores can be designed using integrated logic or circuit designs to function as an embedded processor. These IP cores can then perform the required computational actions to support the Modbus RTU communication protocol by utilizing high-level programming languages such as the C programming language. The hardware description language of Very High-Speed Integrated Circuit Hardware Description Language (VHDL) allows for the control of real hardware at the logic gate and signal level. These logic gates and signals can be designed and controlled to perform desired actions based on the system design. Programming an FPGA using VHDL allows an individual to access the lowest abstraction level of the system during FPGA development. This level of abstraction is referred to as the register-transfer level (RTL), which gives access to manipulating values and variables at the register level. This register-level manipulation provides precision over creating the logical circuit within the FPGA, thus minimizing the required code to perform desired operations. The Modbus RTU communication protocol can be implemented within an FPGA using VHDL programming to establish a standardized and embedded serial communication pathway. This implementation provides a standardized communication protocol to streamline research efforts among researchers, thus increasing the efficiency of research efforts. Additionally, this Modbus RTU implementation requires fewer resources when compared to typical communication protocol implementations that utilize an IP core, reducing the hardware requirement for effective research efforts.
Interconnectivity has become a substratum of technology as the benefits of data-driven functionality are being realized in nearly all industries. Increased connectivity of Operational Technology (OT) exacerbates cyber risks because Industrial Control Systems (ICS) are becoming exposed to the Internet. These exposures are often done inadvertently through misconfigurations as additional network devices come online. Attack surface management (ASM) platforms can be used to identify vulnerabilities by performing external network discovery over the Internet using web spiders. These web spiders enable big data analytics of Internet of Things (IoT) devices as identifiable information of Internet-exposed equipment are archived in searchable databases that are made publicly available. There are a multitude of ASM service providers on the market. Here, this study was conducted to evaluate several commonly known tools to determine the aggregate attack surface of control systems. Queries were crafted by targeting commonly known manufacturers and communication protocols found in OT networks. Identified devices were that categorized based on technology types. Each query was replicated between several tools to target identical ICS equipment. Findings in this paper suggested a significant variance in the exposures discovered by each tool, but unique contributions were identified for each tool when a merged attack surface was derived. Therefore, all tools should be used in aggregate.
The Conti Ransomware Attack on the Health Service Executive (HSE) of Ireland 2021 Precursor Analysis Report leverages publicly available information about the attack and catalogs anomalous observables for each technique employed by the adversary. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. The HSE provides public healthcare corporate services and operational services throughout Ireland, with critical functions including the acute national ambulance service, acute hospital service, and community healthcare service. On 14 May 2021, Conti ransomware encrypted 80 percent of the HSE’s Information Technology (IT) infrastructure across corporate, hospital, community, and electronic health record services. Conti is a ransomware-as-a-service operation that encrypts local files, uses double extortion against victims, and is facilitated by many intrusion tools. The attack forced the HSE to shut down its entire IT infrastructure to contain the ransomware, forcing employees to revert to pen and paper recordkeeping and leading to the cancellation of many appointments and procedures. The adversary also exfiltrated 700 GB of data, compromising the confidentiality of patients’ protected health information. Had the adversary targeted the COVID-19 cloud systems or operational technology assets, such as Internet of Medical Things medical devices or smart building management systems, the impact of the attack would almost certainly have been far more severe. Researchers and analysts identified 21 unique techniques (used in a sequence of 23 steps) likely utilized during the attack with a total of 1,185 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Twenty-one of the identified techniques used during the attack on the HSE were precursors to the triggering event. Analysis identified 1,086 observables associated with these precursor techniques, 850 of which were assessed to have an increased likelihood of being perceived in the 57 days preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.
The aviation industry is increasingly turning to modernize freight facilities by integrating electric Ground Support Equipment (eGSE) to enhance operational efficiency of freight facility moving vehicles and equipment. Airports worldwide are adopting eGSE to streamline cargo movement, reduce fuel and maintenance costs, and improve logistics coordination.1 North America, with its advanced aviation infrastructure, leads this transition, leveraging Internet of things (IoT)-enabled automation and zero emission technologies to boost reliability and reduce human errors.2 Electrification of freight facility moving vehicles and equipment boosts turnaround times, improves equipment reliability, and optimizes logistics coordination, giving operators a competitive advantage. With rising fuel price volatility and the pressure to meet stringent performance benchmarks, airports are focusing on cost-effective, scalable solutions for long-term financial and operational gains. To further accelerate electrification, airports are integrating Zero Emission Vehicles (ZEVs) into rental car fleets and deploying electric baggage carts, requiring strategic investments in charging infrastructure. 3 The shift, however, presents challenges, such as limited technical expertise, high capital costs, and complex procurement processes. By forging strategic partnerships, leveraging advanced technologies, and optimizing infrastructure investments, airports can create a resilient, future-ready ecosystem that enhances the movement of people and goods through electrification-driven efficiency. Supported by the U.S. Department of Energy (DOE) Vehicle Technologies Office (VTO), this electrification effort provides a scalable, cost-effective solution to improve airport freight operations. Through targeted investments and innovation, airports enhance efficiency, reduce costs, and meet performance benchmarks while advancing toward a resilient, electrified future.
Nuclear power plant (NPP) process equipment such as fans, motors, valves, and pumps generate frequent or continuous noise, and deviations from the normal operational sounds made by this equipment can indicate potential issues. These deviations can be identified via automated acoustic anomaly detection, which involves using acoustic sensors (i.e., microphones) alongside detection algorithms to continuously monitor for changes in acoustic signatures. This task is made challenging by the substantial background noise that exists, such as operators opening and closing doors, manipulating valves, and conversing—in addition to typical plant noises. In collaboration with a nuclear power utility partner, this effort assessed the efficacy of acoustic anomaly detection when using a specific acoustic sensor that compresses data into a fixed set of features that are transferable over a standard Internet of Things communication protocol, thereby improving usability but potentially degrading detection performance. Two methods of performing automated acoustic anomaly detection were evaluated: one-class support vector machine (OC-SVM) and isolation forest (iForest). To enable the use of high-quality acoustic data encompassing both normal and anomalous conditions, the study utilized the publicly available Malfunctioning Industrial Machine Investigation and Inspection dataset, which includes real measured acoustic sensor data for a range of equipment types, model numbers, and signal-to-noise ratios (SNRs), along with a benchmark set of detection results. Using this dataset, the methods were tested and then compared against the benchmark results. The results indicated that although the specific acoustic sensor did not enable as rich a feature set extraction, the proposed methods with the limited feature set performed just as well. This provides solid justification for both the methods and the use of the proposed acoustic sensor.
An emergent direct-write approach, aerosol-jet printing (AJP), is gaining attention for the deployment of rapid and affordable microadditively manufactured energy-efficient sensors and printed electronics. AJP enables a broad range of ink viscosities (0.001–1 Pa s) for printing diverse materials ranging from ceramics and metals to polymers and biological matter. Reproducible, high-spatial-resolution features (≈10 µm), and wide standoff distances (1–11 mm) between the nozzle and the substrate facilitate conformal printing of complex geometrical designs on nonplanar—e.g., stepped or curved—surfaces. Here this paper aims to provide a comprehensive overview of state-of-the-art AJP-based sensors (e.g., strain and temperature gauges, biosensors, photosensors, humidity and surface acoustic wave sensors, dielectric elastomer actuators, and motion, smoke, and hazardous gas detectors) and to discuss prospective applications. The drive toward cost-effective devices that are smaller, lighter, and better-performing remains a frontier challenge in the field of printed electronics. Consequently, as AJP becomes increasingly utilized in the high-volume manufacturing of miniaturized active and passive sensors, it opens a pathway for facile large-scale fabrication of devices for a wide range of consumer and industrial applications, including transportation, agriculture, infrastructure, aerospace, national defense, and healthcare.
Abstract The challenge of sustainably producing goods and services for healthy living on a healthy planet requires simultaneous consideration of economic, societal, and environmental dimensions in manufacturing. Enabling technology for data driven manufacturing paradigms like Smart Manufacturing (a.k.a. Industry 4.0) serve as the technological backbone from which sustainable approaches to manufacturing can be implemented. Unfortunately, these technologies are typically associated with broader and deeper factory automation that is often too expensive and complex for the small and medium sized manufacturers (SMMs) that comprise the majority of manufacturing business in the USA and for whom their most valuable asset are the people whose jobs automation while replace. This paper describes an edge intelligent platform to integrate internet‐of‐things technologies with computing hardware, software, computational workflows for machine learning, and data ingestion, enabling SMMs to transition into smart manufacturing paradigms by leveraging the intelligence of their people. The platform leverages consumer grade electronics and sensors (affordable and portable), customized software with open source software packages (accessible), and existing communication network infrastructures (scalable). The software systems are implemented via Kubernetes orchestration of Docker containerization to ensure scalability and programmability. The platform is adaptive via computational workflow engines that produce information from data by processing with low‐cost edge computing devices while efficiently accessing resources of cloud servers as needed. The proposed edge platform connects workers to technological resources that provide computational intelligence (i.e., silicon‐based sensing and computation for data collection and contextualization) to enable decision making at the edge of advanced manufacturing.