Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “security and privacy”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Investigating Users’ Privacy Concerns of Internet of Things (IoT) Smart Devices

Although the number of smart Internet of Things (IoT) devices has grown in recent years, the public's perception of how effectively these devices secure IoT data has been questioned. Many IoT users do not have a good level of confidence in the security or privacy procedures implemented within IoT smart devices for protecting personal IoT data. Moreover, determining the level of confidence end users have in their smart devices is becoming a major challenge. In this paper, we present a study that focuses on identifying privacy concerns IoT end users have when using IoT smart devices. We investigated multiple smart devices and conducted a survey to identify users’ privacy concerns. Furthermore, we identify five IoT privacy-preserving (IoTPP) control policies that we define and employ in comparing the privacy measures implemented by various popular smart devices. Results from our study show that the over 86% of participants are very or extremely concerned about the security and privacy of their personal data when using smart IoT devices such as Google Nest Hub or Amazon Alexa. In addition, our study shows that a significant number of IoT users may not be aware that their personal data is collected, stored or shared by IoT devices.

Joy, Daniel↗

K-anonymity applied to the energy grid of things distributed energy resource management system

Smart grid infrastructure relies on information exchange between multiple actors in order to ensure system reliability. These actors include but are not limited to smart loads, grid control, and energy management technologies. As information exchange between these actors is susceptible to cyber-attacks, security and privacy issues are indispensable to ensure a reliable and stable grid. This position paper proposes a privacypreserving, trust-augmented secure scheme for a smart grid implementation.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Are System Baselines within OT Environments Feasible?

Critical infrastructure stakeholders need to baseline their systems to understand expected protocol communications.Baseline behaviors may vary based on operational context.Expected operations during a maintenance window, for example, may be different from normal operations.Furthermore, constructing system baselines for Industrial Control Systems (ICS) is difficult and time-consuming.ICS processes generate artifacts expressed across heterogeneous data sources such as network and device logs. There needs to be a corpus of data in order to develop and compare methods that evaluate the feasibility, performance, and generality of approaches to construct baselines for ICS events. Standalone repositories of network packet captures are insufficient to develop methods to classify or recognize operational events expressed across multiple data sources. Moreover, static data corpora do not enable researchers to compare the impact of changing the underlying system for which a baseline is being constructed and this limits the ability to evaluate the performance of system baselines given system changes (e.g. patches, configuration, maintenance events). In order to address these limitations within the community, this talk intends to promote discussion about the state of the practice of constructing baselines. In this manner, we can continue to understand requirements within industry that are not being met by current approaches to baseline construction. This talk builds on two previous talks on the topic of system baselines for OT environments. First, Weaver co-presented at the RSA Conference ICS Sandbox with Dan Gunter. The talk confirmed the need within industry to construct baselines across multiple types of data sources relative to the semantics of specific business processes. Second, Weaver presented at IEEE Security and Privacy Workshop on Language-Theoretic Security.

02 PETROLEUM↗

Securing Environmental IoT Data Using Masked Authentication Messaging Protocol in a DAG-Based Blockchain: IOTA Tangle

The demand for the digital monitoring of environmental ecosystems is high and growing rapidly as a means of protecting the public and managing the environment. However, before data, algorithms, and models can be mobilized at scale, there are considerable concerns associated with privacy and security that can negatively affect the adoption of technology within this domain. In this paper, we propose the advancement of electronic environmental monitoring through the capability provided by the blockchain. The blockchain’s use of a distributed ledger as its underlying infrastructure is an attractive approach to counter these privacy and security issues, although its performance and ability to manage sensor data must be assessed. We focus on a new distributed ledger technology for the IoT, called IOTA, that is based on a directed acyclic graph. IOTA overcomes the current limitations of the blockchain and offers a data communication protocol called masked authenticated messaging for secure data sharing among Internet of Things (IoT) devices. We show how the application layer employing the data communication protocol, MAM, can support the secure transmission, storage, and retrieval of encrypted environmental sensor data by using an immutable distributed ledger such as that shown in IOTA. Finally, we evaluate, compare, and analyze the performance of the MAM protocol against a non-protocol approach.

Gangwani, Pranav (ORCID:0000000159226002)↗

An Ethics-Based Review of Generative Artificial Intelligence: Assuring Responsible Use (Version 1.0)

The rapid expansion of generative artificial intelligence (GenAI) has generated excitement regarding its potential benefits and concern over its ethical implications. Governments, corporations, and standards organizations have described ethical principles to direct GenAI's development and use; however, practical guidance for implementing these principles is limited. Addressing this gap is critical, especially considering the array of risks associated with GenAI, such as legal liabilities, privacy concerns, security threats, and potential misuse. Robust policies and procedures are critical to support responsible deployment of GenAI. This report examines Pacific Northwest National Laboratory (PNNL)’s approach to promoting responsible GenAI use. Proposed initiatives include developing policies based on ethical principles, creating a governance process to review projects relative to those principles, and implementing onboarding processes for training staff. The governance framework described in this report adapts the structure and principles of Institutional Review Boards (IRBs), traditionally used in human subjects research, for GenAI ethical review, providing oversight. Ethical principles guiding responsible GenAI usage include transparency and accountability, privacy, fairness, safety, security, and validity and reliability. To operationalize these principles, we propose forming a GenAI Assurance Council (GAC) that mirrors the IRB's structure. The GAC will evaluate GenAI projects across privacy, accountability, transparency, safety, security, fairness, and validity dimensions. Complementing policy and governance is AI literacy training to support staff understanding of GenAI's ethical implications. An initial training effort for AI Incubator Chat—a GenAI tool deployed at PNNL—showed promising results, underscoring the importance of clear guidelines and user accountability. Collaborative efforts and the dissemination of best practices are also discussed. The proposed GAC model and AI literacy training provide a blueprint for establishing ethical GenAI use and governance, offering practical tools to bridge the gap between ethical principles and real-world applications. The responsible integration of GenAI at PNNL entails a multifaceted approach involving policy development, ethical governance, and AI literacy training. The positive initial feedback and collaborative opportunities position PNNL to lead by example in GenAI's responsible use, reflecting a proactive stance in addressing the ethical, legal, and societal challenges associated with this emerging technology. PNNL's systematic and ethical approach to GenAI offers a model for other institutions to emulate, promoting safe and responsible technological advancements in the AI domain.

97 MATHEMATICS AND COMPUTING↗

Optimal vocabulary selection approaches for privacy-preserving deep NLP model training for information extraction and cancer epidemiology

With the use of artificial intelligence and machine learning techniques for biomedical informatics, security and privacy concerns over the data and subject identities have also become an important issue and essential research topic. Without intentional safeguards, machine learning models may find patterns and features to improve task performance that are associated with private personal information. The privacy vulnerability of deep learning models for information extraction from medical textural contents needs to be quantified since the models are exposed to private health information and personally identifiable information. The objective of the study is to quantify the privacy vulnerability of the deep learning models for natural language processing and explore a proper way of securing patients’ information to mitigate confidentiality breaches. The target model is the multitask convolutional neural network for information extraction from cancer pathology reports, where the data for training the model are from multiple state population-based cancer registries. This study proposes the following schemes to collect vocabularies from the cancer pathology reports; (a) words appearing in multiple registries, and (b) words that have higher mutual information. We performed membership inference attacks on the models in high-performance computing environments. The comparison outcomes suggest that the proposed vocabulary selection methods resulted in lower privacy vulnerability while maintaining the same level of clinical task performance.

59 BASIC BIOLOGICAL SCIENCES↗

Tikiri—Towards a lightweight blockchain for IoT

Internet of Things (IoT) platforms have been deployed in several domains to enhance efficiency of business process and improve productivity. Most IoT platforms comprise of heterogeneous software and hardware components which can potentially introduce security and privacy challenges. Blockchain technology has been proposed as one of the solutions to realize IoT security by leveraging the (a) Immutable ledger, (b) Decentralized architecture and (c) Strong cryptography primitives. However, integrating blockchain platforms with IoT based applications presents several challenges due to lack of (a) acceptable performance on resource-constrained devices, (b) high transaction throughput, (c) keyword-based search and retrieve, (d) transaction back pressure operations, and (e) real-time response. In this paper, we propose a lightweight blockchain platform, “Tikiri”, for resource-constrained IoT devices. Tikiri uses Apache Kafka for the consensus and proposes new blockchain architecture to handle real-time transaction execution on the blockchain. Tikiri is characterized by functional programming and actor-based smart contract platform that realizes concurrent execution of transactions in the blockchain. Tikiri realizes a lightweight and scalable blockchain that can provides performance on the resource-constrained IoT devices.

97 MATHEMATICS AND COMPUTING↗

Emerging Technologies for Privacy Preservation in Energy Systems

This study explores the intersection of digitalization and privacy within the energy sector, focusing on the emerging challenges and opportunities presented by integrating Distributed Energy Resources (DERs) and advanced metering infrastructure. The need for robust digital privacy measures has become crucial as the energy industry evolves towards a more decentralized, digitalized, and decarbonized future. This study delves into four cutting-edge privacy-preserving technologies—Homomorphic Encryption (HE), Secure Multiparty Computation (SMPC), Differential Privacy (DP), and Federated Learning (FL)—each offering unique solutions to safeguard consumer data by increasing digital connectivity and data exchange. Through a detailed examination of these methods, the study explains how each technology operates, its applications within the energy sector, and the specific privacy challenges it addresses. Homomorphic Encryption allows for secure computations on encrypted data, enabling data analysis without compromising privacy. Secure Multiparty Computation enables collaborative data analysis across different entities while protecting the confidentiality of the inputs. Differential Privacy introduces randomness into the assembled data set, preventing the identification of individual records in statistical databases. Lastly, Federated Learning offers a paradigm shift in data analysis, where machine learning models are trained at the edge, minimizing the centralization of sensitive data. The research underscores the significance of implementing these privacy-enhancing technologies to comply with strict data protection regulations, foster consumer trust, and enhance the security of the energy infrastructure. By providing a comprehensive overview of these methodologies and their practical implications for the energy sector, this study aims to contribute to the ongoing discourse on digital privacy, offering insights into how the energy industry can navigate the complexities of data privacy in the digital age.

Cali, Umit↗

Toward Common Weakness Enumerations in Industrial Control Systems

Here, the storyline of MITRE’s common weakness enumeration framework illustrates how the security and privacy technical community can collaborate/cooperate with policy makers to advance policy, giving it specifics and filling gaps of technical knowledge to improve security and resilience of critical infrastructure.

42 ENGINEERING↗

Designing Secure and Resilient Cyber-Physical Systems Using Formal Models

This work-in-progress paper proposes a design methodology that addresses the complexity and heterogeneity of cyber-physical systems (CPS) while simultaneously proving resilient control logic and security properties. The design methodology involves a formal methods-based approach by translating the complex control logic and security properties of a water flow CPS into timed automata. Timed automata are a formal model that describes system behaviors and properties using mathematics-based logic languages with precision. Due to the semantics that are used in developing the formal models, verification techniques, such as theorem proving and model checking, are used to mathematically prove the specifications and security properties of the CPS. This work-in-progress paper aims to highlight the need for formalizing plant models by creating a timed automata of the physical portions of the water flow CPS. Extending the time automata with control logic, network security, and privacy control processes is investigated. The final model will be formally verified to prove the design specifications of the water flow CPS to ensure efficacy and security.

42 ENGINEERING↗

A Privacy First Path Analysis using Clickstream Data

In the modern digital economy, data-driven decision making is crucial for effectively meeting the ever-evolving demands of consumer engagement and satisfaction. Clickstream data has become invaluable for understanding customer behavior, yet concerns over privacy and security persist, especially with some internet service providers profiting from its sale. This article introduces an innovative methodology that blends experiential learning with advanced cryptographic techniques, including differential privacy and graph analytics. The core objective of this methodology is to estimate Customer Lifetime Value (CLV) by analyzing clickstream data, achieving an average prediction accuracy of 92.4% in user engagement levels while ensuring user anonymity through Recency, Frequency, and Monetary (RFM) analysis. Our study introduces the concept of a “data depositor” and a privacy manager, employing the composition theorem to merge non-adaptive queries effectively. Privacy budgets (? = 1.0, d = 10-5), sensitivity-specific techniques, and data partitioning were applied. Randomization and noise addition protect data integrity, with special handling for categorical values. This approach, differing from prior studies, offers a 12.6% improvement in privacy-preserving targeting accuracy while maintaining strict confidentiality, presenting a novel path forward in data-driven decision-making.

Frequency and Monetary (RFM) analysis↗

Privacy-Preserving Knowledge Transfer with Bootstrap Aggregation of Teacher Ensembles

There is a need to transfer knowledge among institutions and organizations to save effort in annotation and labeling or in enhancing task performance. However, knowledge transfer is difficult because of restrictions that are in place to ensure data security and privacy. Institutions are not allowed to exchange data or perform any activity that may expose personal information. With the leverage of a differential privacy algorithm in a high-performance computing environment, we propose a new training protocol, Bootstrap Aggregation of Teacher Ensembles (BATE), which is applicable to various types of machine learning models. The BATE algorithm is based on and provides enhancements to the PATE algorithm, maintaining competitive task performance scores on complex datasets with underrepresented class labels.We conducted a proof-of-the-concept study of the information extraction from cancer pathology report data from four cancer registries and performed comparisons between four scenarios: no collaboration, no privacy-preserving collaboration, the PATE algorithm, and the proposed BATE algorithm. The results showed that the BATE algorithm maintained competitive macro-averaged F1 scores, demonstrating that the suggested algorithm is an effective yet privacy-preserving method for machine learning and deep learning solutions.

Yoon, Hong-Jun↗

Dependable classical-quantum computing systems engineering

Increasing evidence suggests quantum computing (QC) complements traditional High-Performance Computing (HPC) by leveraging its unique capabilities, leading to the emergence of a new, hybrid paradigm, QHPC. However, this integration introduces new challenges, with dependability–defined by reproducibility, resiliency, and security and privacy–emerging as a central concern for building trustworthy systems that provide an advantage to the users. This paper proposes a framework for dependable QHPC system design, organized around these three pillars. We identify integration challenges, anticipate roadblocks, and highlight productive synergies across QC, HPC, cloud platforms, and network security. Drawing from both classical computing principles and quantum-specific insights, we present a roadmap for co-design that supports robust hybrid architectures. Our approach offers concrete metrics for assessing dependability, provides design guidance for engineers working at the QC-HPC interface, and surfaces new engineering questions around complexity, scale, and fault tolerance. Ultimately, designing for dependability is key to realizing practical, scalable QHPC systems and accelerating the broader quantum ecosystem capable of translating quantum promises into actual application delivery.

HPC↗

Inventory of Public Key Cryptography in US Electric Vehicle Charging

Electric vehicles (EVs) and charging infrastructure are networked systems, which employ high-level communications in support of charging and grid service decisions. Public key cryptography (PKC) underlies much of the security and privacy protections of the information exchange. We are entering a new epoch where quantum computing threats must be seriously considered. A sufficiently large quantum computer, so named Cryptographically Relevant Quantum Computer (QRQC), will be able to perform the mathematical operations to efficiently attack the underpinnings of traditional PKC, thus jeopardizing the digital foundations for trust, communications security, and data security. Estimates suggest a QRQC can break public key encryption and digital signatures in the manner of tens to hundreds of hours, compared to traditional computing that would demand more than 10 18 years in a brute force-style attack. A consensus belief of quantum theorists, quantum experimenters, and cryptographers suggest that the quantum threat will be likely realized in the next twenty years. To address the threat, post-quantum cryptography, which is cryptosystems that are designed to be secure against both traditional and quantum computing threats, must be adopted. Migration from traditional PKC to quantum-resilient cryptography is a global undertaking and likely represents the largest transition in computing history. The nascent state of EV public key infrastructure, combined with limited adoption of the vehicle secure charging features, presents an opportunity to establish a preference for quantum-resistant cryptography as a step on the migration path. Delays will stunt the efforts as rapidly accelerating EVs sales and huge infrastructure investments will create large growing bases of long-lived vehicles and infrastructure. Migration preparations can commence while NIST continues the process to standardize post-quantum cryptography (PQC), which are quantum-resilient algorithms designed to be secure against traditional and quantum computing threats. The first step in preparing EV charging is to identify the presence of traditional public key cryptography algorithms and applications. With this objective in mind, this report is intended to advise the vehicle manufacturers, charging station manufacturers, charging station operators, charge network providers and other EV charging stakeholders with information on traditional PKC application and the potential risks when PKC becomes insecure. This report, the first in a series of reports discussing the topics existing at the confluence of post-quantum cryptography adoption and EV charging, identifies traditional public key applications employed and identifies potential consequences of leaving EV charging infrastructure vulnerable to quantum computing. The focus remains squarely on the of EV charging and infrastructure with respect to PKC and is believed by the authors to complement the NIST SP 1800-38 Migration to Post-Quantum Cryptography. While the report is centered on infrastructure, there are implications to vehicles.

33 ADVANCED PROPULSION SYSTEMS↗

Reimagining Codesign for Advanced Scientific Computing: Report for the ASCR Workshop on Reimagining Codesign

In March 2021, the U.S. Department of Energy’s Advanced Scientific Computing Research program convened the Workshop on Reimagining Codesign. The workshop, also known as ReCoDe, was organized around discussions on eight topic areas: (1) codesign for traditional high-performance computing workloads; (2) codesign of memory/storage systems; (3) codesign of machine learning, neuromorphic, quantum, and other non-von Neumann accelerators; (4) codesign for edge computing and processing at experimental instruments; (5) codesign for security and privacy; (6) hardware design tools and open-source hardware for high-productivity codesign; (7) tools, software stack, and programming languages for high-productivity codesign; and (8) quantitative tools and data collection for modeling and simulation for codesign. The panels identified four Priority Research Directions from these deliberations: (1) breakthrough computing capabilities with targeted heterogeneity and rapid design; (2) software and applications that embrace radical architecture diversity; (3) engineered security and integrity, from transistors to applications; and (4) design with data-rich processes.

97 MATHEMATICS AND COMPUTING↗

The Distributed Energy Resource Risk Manager

Organizations need a comprehensive approach to managing security and privacy risks, especially for energy resources that are becoming increasingly distributed. A tool by the National Renewable Energy Laboratory (NREL) makes it possible to manage these risks and maintain the highest standards of cybersecurity. To simplify risk management for facilities and distributed energy resources, NREL has created the Distributed Energy Resource Risk Manager, an automated, user-friendly tool that helps navigate and implement one of the most widely trusted frameworks for information security, the National Institute of Standards and Technology Risk Management Framework.

compliance↗

Privacy-preserving federated learning: Application to behind-the-meter solar photovoltaic generation forecasting

Here, the growing usage of decentralized renewable energy sources has made accurate estimation of their aggregated generation crucial for maintaining grid flexibility and reliability. However, the majority of distributed photovoltaic (PV) systems are behind-the-meter (BTM) and invisible to utilities, leading to three challenges in obtaining an accurate forecast of their aggregated output. Firstly, traditional centralized prediction algorithms used in previous studies may not be appropriate due to privacy concerns. There is therefore a need for decentralized forecasting methods, such as federated learning (FL), to protect privacy. Secondly, there has been no comparison between localized, centralized, and decentralized forecasting methods for BTM PV production, and the trade-off between prediction accuracy and privacy has not been explored. Lastly, the computational time of data-driven prediction algorithms has not been examined. This article presents a FL power forecasting method for PVs, which uses federated learning as a decentralized collaborative modeling approach to train a single model on data from multiple BTM sites. The machine learning network used to design this FL-based BTM PV forecasting model is a multi-layered perceptron, which ensures privacy and security of the data. Comparing the suggested FL forecasting model to non-private centralized and entirely private localized models revealed that it has a high level of accuracy, with an RMSE that is 18.17% lower than localized models and 9.9% higher than centralized models.

14 SOLAR ENERGY↗