Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Computer security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 397 records · Page 22

An Introduction to Los Alamos National Laboratory [Slides]

The Weapon Systems Engineering Division (W) provides the system engineering and program management necessary to sustain the safety, reliability, and security of the Los Alamos National Laboratory’s assets in the active United States nuclear stockpile - the B61, W76, W78 and W88. The Division generates key certification data for Annual Assessment supporting the Laboratory Director's letter to the President on the health of those warheads. This role demands ongoing surveillance of the active stockpile and evaluation of the potential impact of any issues through design, engineering, fabrication, testing using state-of-the-art computational simulation tools and engineering test facilities. The Division works in close liaison with the several production facilities across the nuclear security complex as well as with the customers in the US Navy and Air Force.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Continuous variable quantum secret sharing

Continuous variable quantum secret sharing (CV-QSS) technologies are described that use laser sources and homodyne detectors. Here, a Gaussian-modulated coherent state (GMCS) prepared by one device passes through secure stations of other devices sequentially on its way to a trusted device, and each of the other devices coherently adds a locally prepared, independent GMCS to the group of propagating GMCSs. Finally, the trusted device measures both the amplitude and the phase quadratures of the received group of coherent GMCSs using double homodyne detectors. The trusted device suitably uses the measurement results to establish a secure key for encoding secret messages to be broadcast to the other devices. The devices cooperatively estimate, based on signals corresponding to their respective Gaussian modulations, the trusted device's secure key, so that the cooperative devices can decode the broadcast secret messages with the secure key.

97 MATHEMATICS AND COMPUTING↗

Security Analysis of a Class of Spread Spectrum Systems Presentation

A method of adding physical layer security to a class of spread spectrum systems has been recently proposed. In this paper, we look into the rate at which an eavesdropper may gain information about the system to decipher the data symbols. The Shannon mutual information is used to measure the rate of information that may be gained by an eavesdropper. The k-nearest neighbors (k-NN) method is used to obtain estimates of relevant entropy values, which will then be used to quantify the rate of information recovery as more data is transmitted. It turns out that such information recovery requires the adoption of special methods that avoid any destructive bias in the estimates. Details of these methods are also presented.

97 - MATHEMATICS AND COMPUTING↗

Overview of the MCNP6® SQA Plan and Requirements [Memorandum]

For all X Computational Physics Division (XCP) software under the Associate Laboratory Directorate for Weapons Physics (ALDX), the Weapons Research Services Secure Networks and Assurance Group (WRS-SNA) manages the software quality assurance (SQA) plan, requirements and guidance with respect to development processes and tools to meet the broader LANL SQA requirements. Each XCP software product is categorized into one of three software types: Safety Software, Non-Safety Risk Significant Software, and Non-Safety Commercially Controlled Software. In 2018, using LANL Form 2033, the MCNP6 code was categorized by the XCP division as Non-Safety Commercially Controlled Software, provided in Appendix A. Using WRSFORM- 0001U, the MCNP6 code was graded as a Medium Impact software product, provided in Appendix B. Given these determinations, the WRS-AD-0010U SQA plan is followed for all MCNP6 developments, documentation and code releases.

97 MATHEMATICS AND COMPUTING↗

Universal Utility Data Exchange (UUDEX) Functional Design Requirements - Rev 1

This document provides a set of high-level functional design requirements for Universal Utility Data Exchange (UUDEX). These requirements include a set of use cases, data exchanges supported by UUDEX, both for grid operations and for cyber security data, functional requirements for data exchange, data models used by UUDEX, data exchange architectures, and security considerations. These functional design requirements are intended to be used in more detailed design documents.

97 MATHEMATICS AND COMPUTING↗

Nuclear Computational Resource Center Progress and Status Report

The Nuclear Computational Resource Center (NCRC) at Idaho National Laboratory (INL), supported by the United States Department of Energy Office of Nuclear Energy (DOE-NE), provides access to supercomputer systems and protected software in support of nuclear energy research and development. The NCRC vision recognizes the central role modeling and simulation plays in nuclear energy innovation as well as ensuring the safe, secure, and efficient operations of existing nuclear energy systems. To accomplish this vision, the NCRC supports processes and systems which provide access to computational tools, supercomputing systems, and training in support of nuclear energy innovation.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Hardware-in-the-Loop Testbed for Cyber-Physical Security of Photovoltaic Farms

In the last decades, modem grids with distributed energy resources, such as photovoltaic (PV) farms, are increasingly vulnerable to cyber-attacks that seriously affect the stability and performance of the power system. While cyber-physical security of smart grids is extensively studied, most of the existing work focuses on the grid level and neglects the modeling and features of device-level power electronics converters (PECs). Furthermore, establishing a high-fidelity simulation testbed that can simulate harmonic frequencies of the PV farm is in urgent need. In this paper, a high-fidelity and real-time hardware-in- the-loop testbed is built to simulate the harmonics of power electronics converters for cyber-physical security of PEC-enabled PV farms. Based on this testbed, the impact of typical cyber-attacks and physical faults on the PV converter can be analyzed, thus providing a foundation for cyber-attack detection, root cause diagnosis, and resilient control to mitigate the adverse effects of cyber-attacks.

14 SOLAR ENERGY↗

Seamless Wireless Communication Platform for Internet of Things Applications

The rapid growth of the Internet of Things (IoT) devices resulted in the proliferation of wireless technologies to cater to their increasing data rate requirements and support multiple applications. However, such ever-increasing wireless technologies present numerous challenges such as incompatible wireless standards, increased energy consumption, and insecure communication. The traditional gateways proposed in the literature suffers from limitations such as computational complexity, resource requirements, increased cost, and device size. We vision an era of seamless wireless communication to alleviate the aforementioned challenges in IoT applications. through three inter-dependent functionalities namely detection and identification of wireless technologies, energy-efficient transmit power control, and secure end-to-end communication. To prove the concept, a new gateway is proposed to achieve these three functionalities with only physical layer measurements so that the different communication protocols in the higher layers can be avoided. Novel schemes are conceptualized for resource-limited seamless IoT applications. Moreover, the conceptual seamless IoT platform is validated through software-based computer simulation and software-defined radio-based testbed implementation. Finally, the preliminary analysis demonstrates that the proposed platform has great potential in advancing seamless IoT applications.

97 MATHEMATICS AND COMPUTING↗

Cyber-Secure and Safe Operation of Solar Photovoltaic Power Distribution Systems

Solar photovoltaic (PV)-rich power distribution systems are networked Cyber-Physical Systems (CPS). These are control systems where multiple computing nodes and diverse intelligent agents interact with the physical world in real-time. However, the presence of networked components renders them vulnerable to potential cyber-attacks, cyber-intrusions, and other malicious events. This is because these systems depend on the measurements reported from their heterogeneous sensors. This makes them vulnerable to potential cyber-attacks where malicious agents can compromise the sensors or the communication networks carrying the sensor measurements. This paper proposes a novel methodology for enhancing the cyber-security and cyber-resilient post-attack safe operation of solar PV-rich power distribution systems against potential cyber-attacks through the Dynamic Watermarking (DW), using online system identification. The resiliency of the proposed technique is tested and validated with several attack scenarios on both a lab-scale 3kW grid-connected PV inverter and a Hardware-in-the-Loop (HiL) system. The proposed approach can be applied to other types of power distribution systems to enhance their cyber-secure and cyber-resilient safe operation. This paper thereby contributes to the field of cyber-security of Cyber-Physical Energy Systems (CPES).

Kim, Jaewon↗

Assessing DER Network Cybersecurity Defences in a Power-Communication Co-Simulation Environment

Increasing penetrations of interoperable distributed energy resources (DER) in the electric power system are expanding the power system attack surface. Maloperation or malicious control of DER equipment can now cause substantial disturbances to grid operations. Fortunately, many options exist to defend and limit adversary impact on these newly-created DER communication networks, which typically traverse the public internet. However, implementing these security features will increase communication latency, thereby adversely impacting real-time DER grid support service effectiveness. In this work, a collection of software tools called SCEPTRE were used to create a co-simulation environment where SunSpec-compliant PV inverters were deployed as virtual machines and interconnected to simulated communication network equipment. Network segmentation, encryption, and moving target defence security features were deployed on the control network to evaluate their influence on cybersecurity metrics and power system performance. The results indicated that adding these security features did not impact DER-based grid control systems but improved the cybersecurity posture of the network when implemented appropriately.

97 MATHEMATICS AND COMPUTING↗

Cyber-Power Co-Simulation for End-to-End Synchrophasor Network Analysis and Applications

The resiliency, reliability and security of the next generation cyber-power smart grid depend upon efficiently leveraging advanced communication and computing technologies. Also, developing real-time data-driven applications is critical to enable wide-area monitoring and control of the cyber-power grid given high-resolution data from Phasor Measurement Units (PMUs). North American Synchrophasor Initiative Network (NASPlnet) provides guidance for PMU data exchanges. With the advancement in networking and grid operation, it is necessary to evaluate the performance of different data flow architectures suggested by NASPInet and analyze the impact on applications. Therefore, we need a cyber-power co-simulation framework that supports very large-scale co-simulation capable of running in parallel, high-performance computing platforms and capturing real-life network behavior. This work presents an end-to-end automated and user-driven cyber-power co-simulation using NS3 to model communication networks, GridPACK to model the power grid, and HELICS as a co-simulation engine. Comparative analysis of latency in synchrophasor networks and a performance evaluation of a power system stabilizer application utilizing PMU data in an IEEE 39 bus test system is presented using this cosimulation testbed.

Mustafa, Hussain M.↗

Side-channel Leakage Assessment Metrics: A Case Study of GIFT Block Ciphers

Determination of an adequate level of security and providing subsequent mechanisms to achieve it, is one of the most pressing problems regarding embedded computing devices. While there are some solutions available for resource-rich computer systems, direct application of these solutions to resource-constrained environments are often unfeasible. The fundamental problem for such resource-constrained systems is the fact that current cryptographic algorithms utilize significant energy consumption and storage overhead. Both the cryptographic algorithm and its physical implementation affect the resilience of a cryptosystem against side-channel attacks. A side-channel attack represents a process that exploits leakages in order to extract sensitive information such as the key. This paper focuses on Correlation Power Analysis (CPA) which is side-channel attack based on the power consumption leakage. In 2016 the U.S. Commerce Department’s National Institute of Standards and Technology (NIST) initiated the call for proposals of new cryptographic algorithms to strengthen the cryptographic defense of networked devices against cyberattacks and to protect the data created by those innumerable device. This work evaluates S-boxes used by NIST candidates PICCOLO, GIFT, and PRESENT, as well as several S-box variants that demonstrated sufficient weaknesses against classical cryptanalysis, for a quantitative comparison in terms of resiliency to CPA attack. Three well-known theoretical metrics are evaluated: transparency order (TO and RTO), nonlinearity, and signal-to-noise (SNR) ratio, aiming to characterize the resistance of these S-boxes against adversaries exploiting physical leakages. Experimental results from attacks on an 8- bit XMEGA were obtained via the ChipWhisperer platform and of all the S-boxes evaluated, GIFT64 with a PICCOLO S-box was found to be the most susceptible to CPA. Results showed that variations in TO and RTO were not sufficient to ensure practical CPA resistance and that among S-boxes with equal non-linearity there were no significant differences in the TO and SNR variants.

97 MATHEMATICS AND COMPUTING↗

Side-channel Leakage Assessment Metrics: A Case Study of GIFT Block Ciphers

Determination of an adequate level of security and providing subsequent mechanisms to achieve it, is one of the most pressing problems regarding embedded computing devices. While there are some solutions available for resource-rich computer systems, direct application of these solutions to resource-constrained environments are often unfeasible. The fundamental problem for such resource-constrained systems is the fact that current cryptographic algorithms utilize significant energy consumption and storage overhead. Both the cryptographic algorithm and its physical implementation affect the resilience of a cryptosystem against side-channel attacks. A side-channel attack represents a process that exploits leakages in order to extract sensitive information such as the key. This paper focuses on Correlation Power Analysis (CPA) which is side-channel attack based on the power consumption leakage. In 2016 the U.S. Commerce Department’s National Institute of Standards and Technology (NIST) initiated the call for proposals of new cryptographic algorithms to strengthen the cryptographic defense of networked devices against cyberattacks and to protect the data created by those innumerable device. This work evaluates S-boxes used by NIST candidates PICCOLO, GIFT, and PRESENT, as well as several S-box variants that demonstrated sufficient weaknesses against classical cryptanalysis, for a quantitative comparison in terms of resiliency to CPA attack. Three well-known theoretical metrics are evaluated: transparency order (TO and RTO), nonlinearity, and signal-to-noise (SNR) ratio, aiming to characterize the resistance of these S-boxes against adversaries exploiting physical leakages. Experimental results from attacks on an 8- bit XMEGA were obtained via the ChipWhisperer platform and of all the S-boxes evaluated, GIFT64 with a PICCOLO S-box was found to be the most susceptible to CPA. Results showed that variations in TO and RTO were not sufficient to ensure practical CPA resistance and that among S-boxes with equal non-linearity there were no significant differences in the TO and SNR variants.

97 MATHEMATICS AND COMPUTING↗

Quantum Key Distribution for Critical Infrastructures: Towards Cyber-Physical Security for Hydropower and Dams

Hydropower facilities are often remotely monitored or controlled from a centralized remote control room. Additionally, major component manufacturers monitor the performance of installed components, increasingly via public communication infrastructures. While these communications enable efficiencies and increased reliability, they also expand the cyber-attack surface. Communications may use the internet to remote control a facility’s control systems, or it may involve sending control commands over a network from a control room to a machine. The content could be encrypted and decrypted using a public key to protect the communicated information. These cryptographic encoding and decoding schemes become vulnerable as more advances are made in computer technologies, such as quantum computing. In contrast, quantum key distribution (QKD) and other quantum cryptographic protocols are not based upon a computational problem, and offer an alternative to symmetric cryptography in some scenarios. Although the underlying mechanism of quantum cryptogrpahic protocols such as QKD ensure that any attempt by an adversary to observe the quantum part of the protocol will result in a detectable signature as an increased error rate, potentially even preventing key generation, it serves as a warning for further investigation. In QKD, when the error rate is low enough and enough photons have been detected, a shared private key can be generated known only to the sender and receiver. We describe how this novel technology and its several modalities could benefit the critical infrastructures of dams or hydropower facilities. The presented discussions may be viewed as a precursor to a quantum cybersecurity roadmap for the identification of relevant threats and mitigation.

97 MATHEMATICS AND COMPUTING↗

Digital Droplet PCR and Mesocosm-Based Methods to Evaluate Biocontainment Strategies in a Native Soil Ecosystem

Genetically modified industrial production microbes and their associated bioproducts have emerged as an integral component of a sustainable bioeconomy. However, the rapid development of these innovative technologies raises biosecurity concerns, namely, the risk of environmental escape. Thus, the realization of a bioeconomy hinges not only on the development and deployment of microbial production hosts, but also on the development of secure biosystems and biocontainment designs. Current laboratory-based biocontainment testing systems do not accurately reflect the complexities found in natural environments, necessitating an environmentally relevant analysis pipeline that allows for the detection of rare escapees within a complex soil microbiome and differentiation between closely related strains. To this end, we have developed an approach that utilizes soil mesocosms and integrated digital droplet PCR (ddPCR) system to evaluate the efficacy of novel biocontainment strategies. We demonstrate the utility of this approach by modeling contamination with industrial microbial chasses versus their biocontained counterparts. Here we demonstrate the broad utility of this system by highlighting findings from strains of Saccharomyces cerevisiae that are contained with an inducible toxin anti-toxin system, strains of Synechocystis sp. PCC 6803 contained via gene knockout or toxin anti-toxin system, and strains of Escherichia coli that are contained via genomic recoding. We also show that ddPCR can be used to detect gene copies from E. coli equal to those counted by traditional spot plating assays. The resultant data demonstrates that this system has broad utility across diverse microbial chassis and biocontainment strategies and enables researchers to track the fate of our contaminating microbe with high sensitivity in the soil. The findings presented here support the use of this mesocosm-based approach to assess the environmental impact of industrial microbes and to validate biocontainment strategies.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

Mnemosyne

SAND2024-08570O Mnemosyne is an interactive tool for finding, retrieving, and exploring information about U.S. nuclear tests documented in the National Nuclear Security Administration’s NV-209 report. It also acts as an information architecture and codebase for integrating additional information and computational tools related to these tests at the unclassified and classified levels. Users can search by any number of nuclear test attributes—name, yield range, altitude ranges, purpose of a test—and find all matching tests. Users can also retrieve specific test information published in NV-209. The tool displays geospatial and topological data about test location, and it provides an information architecture for storing additional contextual material, such as photographs. Mnemosyne provides a capability of interfacing with HYCHEM, Sandia's nuclear detonation optical waveform tool. The software is designed for use by government, academia, military, and research institutions. The software will likely be advanced to integrate seismic data and the nuclear detonation optical signal simulation code radCTH. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Fisher, Dustin↗