Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Hardware Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

A Real-Time Testbed for Smart Inverter Cyber Security Studies

Distributed energy resources (DER) have become a popular solution to modern-day issues surrounding the efficiency and reliability of power generation, as well as climate change concerns. Energy centers are shifting towards incorporating smart inverters with embedded functionalities such as high voltage ride through (HVRT), low voltage ride through (LVRT), active and reactive power compensation. However, the integration of smart inverters leave DER systems highly vulnerable to cybersecurity threats. The distributed network protocol 3 (DNP3) is a common method of communication between grid-tied hardware. Despite its popularity, the level of security leaves all hardware connected to the grid at risk of severe cyber-attacks. Thus, it is important to study any potential cybersecurity threats towards grid-tied smart inverters to mitigate cybersecurity vulnerabilities and refine existing cyber-security protections. This report describes the proposed testbed design to study cybersecurity threats to smart inverters. The testbed utilizes a real-time simulation case in RSCAD that includes a grid-tied wind turbine (WT) topology featuring two back-to-back two-level voltage source converters (BTB,2L-VSCs) and a permanent magnet synchronous machine (PMSM). The simulated case runs within the NovaCor real time digital simulator (RTDS). This report focuses on the design and implementation of a single module of the GTNETx2 card as a distributed network protocol and the configuration of an IEEE 1518 DNP database file that includes input and output variables mapped to different connection points in the grid that transmit and receive discrete, analog, and binary signals on command. This allows realistic emulation of the communication between the smart inverter and the grid for cybersecurity studies.

97 MATHEMATICS AND COMPUTING↗

IT Security Support for Spaceport Command and Control System

During the fall 2013 semester, I worked at the Kennedy Space Center as an IT Security Intern in support of the Spaceport Command and Control System under the guidance of the IT Security Lead Engineer. Some of my responsibilities included assisting with security plan documentation collection, system hardware and software inventory, and malicious code and malware scanning. Throughout the semester, I had the opportunity to work on a wide range of security related projects. However, there are three projects in particular that stand out. The first project I completed was updating a large interactive spreadsheet that details the SANS Institutes Top 20 Critical Security Controls. My task was to add in all of the new commercial of the shelf (COTS) software listed on the SANS website that can be used to meet their Top 20 controls. In total, there are 153 unique security tools listed by SANS that meet one or more of their 20 controls. My second project was the creation of a database that will allow my mentor to keep track of the work done by the contractors that report to him in a more efficient manner by recording events as they occur throughout the quarter. Lastly, I expanded upon a security assessment of the Linux machines being used on center that I began last semester. To do this, I used a vulnerability and configuration tool that scans hosts remotely through the network and presents the user with an abundance of information detailing each machines configuration. The experience I gained from working on each of these projects has been invaluable, and I look forward to returning in the spring semester to continue working with the IT Security team.

computer security↗

The Earth Observing System (EOS) Ground System: Leveraging an Existing Operational Ground System Infrastructure to Support New Missions

The Earth Observer System (EOS) was officially established in 1990 and went operational in December 1999 with the launch of its flagship spacecraft Terra. Aqua followed in 2002 and Aura in 2004. All three spacecraft are still operational and producing valuable scientific data. While all are beyond their original design lifetime, they are expected to remain viable well into the 2020s. The EOS Ground System is a multi-mission system based at NASA Goddard Space Flight Center that supports science and spacecraft operations for these three missions. Over its operational lifetime to date, the EOS Ground System has evolved as needed to accommodate mission requirements. With an eye towards the future, several updates are currently being deployed. Subsystem interconnects are being upgraded to reduce data latency and improve system performance. End-of-life hardware and operating systems are being replaced to mitigate security concerns and eliminate vendor support gaps. Subsystem hardware is being consolidated through the migration to Virtual Machine based platforms. While mission operations autonomy was not a design goal of the original system concept, there is an active effort to apply state-of-the-art products from the Goddard Mission Services Evolution Center (GMSEC) to facilitate automation where possible within the existing heritage architecture. This presentation will provide background information on the EOS ground system architecture and evolution, discuss latest improvements, and conclude with the results of a recent effort that investigated how the current system could accommodate a proposed new earth science mission.

Earth Science Mission Operations (ESMO)↗

A Multi-Site Networked Hardware-in-Loop Platform for Evaluation of Interoperability and Distributed Intelligence at Grid-Edge

Electric power systems have experienced large increases in the number of intelligent, connected and controllable devices being deployed, leading to a high degree of distributed intelligence at the grid-edge. These devices, both utility-owned and consumer-owned, include but are not limited to: renewable generation sources, energy storage, remote switches, voltage regulators, and smart controllable loads such as electric vehicles. These new devices provide significant potential for increased operational flexibility that can be leveraged to achieve system reconfiguration, resiliency improvements, power quality improvements, and distribution system automation. However, there are two significant challenges that must be addressed before these assets can be leveraged for operations: interoperability and system level validation prior to deployment. Because of the complexity of distributed control systems, and their interactions with legacy centralized controls, a purely simulations-based approach for pre-deployment validation is not sufficient. It requires hardware-in-loop testing to emulate the operational hardware devices and evaluate their performance. Additionally, securely integrating multiple test facilities at utility operators and vendors might enable rapid scale-up of evaluation platforms, and remove the need for multiple expensive standalone installations. Presented in this paper, is the development of a multi-site evaluation platform that employs Advanced Distribution Management Systems (ADMS), distributed control devices, real-time hardware-in-loop assets, secure communication links, and protocol adapters. This platform uses standards-based approaches and open-source tools, and hence can serve as a template for other researchers and institutions to implement their multi-site evaluation frameworks for pre-deployment testing.

Essakiappan, Somasundaram↗

A Scalable Quantum Cryptography Network for Protected Automation Communication (Final Report)

This is the final report for a CEDS-funded project aimed at developing a new quantum technology for securing utility communication networks used to control and monitor electrical grid equipment. Securing these control networks represents a unique challenge as the performance of the security solution has a direct impact on the stability and reliability of the electrical grid. Traditional, software-based solutions - developed for information networks - are not suitable for utility control networks because they introduce latency, require burdensome maintenance and upgrades, are often incompatible with legacy equipment, and introduce operational complexity that reduces grid reliability. Consequently, many U.S. utilities do not use existing solutions and, instead, protect their critical control networks through the careful isolation and obscuration of their networked equipment. With more utilities embracing grid automation, the attack surface that utilities must defend from hackers has grown to an unmanageable size. To address this situation, Qubitekk and its partners proposed and developed a hardware-based solution that can secure critical control networks without negatively impacting grid performance. This new solution is based on quantum key distribution (QKD) techniques that guarantee secure key generation and distribution across a utility control network. Through deployment and field testing of a prototype QKD system, we have shown that this solution delivers long-term network security, is technically feasible to implement and maintain on a utility’s distribution substation network and does not negatively impact grid operations. In addition, the project has identified and solved key challenges associated with generating, transmitting, and measuring coherent photonic quantum states on a real-world fiber optic network. These additional findings are playing a critical role in advancing quantum networks for quantum computing applications. An overview of the QKD prototype development effort, field testing activities and results, and additional findings relevant to emerging quantum networks are presented in this report.

71 CLASSICAL AND QUANTUM MECHANICS, GENERAL PHYSIC↗

Prestressed Thermal-Protection Panels

Panels held securely with minimum of mounting hardware. Each panel held in place by single screw that pulls it into flat shape from its original shallow-dish shape. Shape and prestressing make panel stiff: resists vibration and withstands large mechanical loads. Panel shape and mounting arrangement not limited to thermal-protection systems but also used on aircraft, building walls, or wherever large surfaces must be covered with stiff, flat sheets easily removed for maintenance.

Dunn, T. J.↗

Security System Software

C Language Integration Production System (CLIPS), a NASA-developed expert systems program, has enabled a security systems manufacturer to design a new generation of hardware. C.CURESystem 1 Plus, manufactured by Software House, is a software based system that is used with a variety of access control hardware at installations around the world. Users can manage large amounts of information, solve unique security problems and control entry and time scheduling. CLIPS acts as an information management tool when accessed by C.CURESystem 1 Plus. It asks questions about the hardware and when given the answer, recommends possible quick solutions by non-expert persons.

Source record↗

Hardware-Based Randomized Encoding for Sensor Authentication in Power Grid SCADA Systems

Supervisory Control and Data Acquisition (SCADA) systems are utilized extensively in critical power grid infrastructures. Modern SCADA systems have been proven to be susceptible to cyber-security attacks and require improved security primitives in order to prevent unwanted influence from an adversarial party. One section of weakness in the SCADA system is the integrity of field level sensors providing essential data for control decisions at a master station. In this paper we propose a lightweight hardware scheme providing inferred authentication for SCADA sensors by combining an analog to digital converter and a permutation generator as a single integrated circuit. Through this method we encode critical sensor data at the time of sensing, so that unencoded data is never stored in memory, increasing the difficulty of software attacks. We show through experimentation how our design stops both software and hardware false data injection attacks occurring at the field level of SCADA systems.

42 ENGINEERING↗

Virtualized Multi-Mission Operations Center (vMMOC) and its Cloud Services

His presentation will cover, the current and future, technical and organizational opportunities and challenges with virtualizing a multi-mission operations center. The full deployment of Goddard Space Flight Centers (GSFC) Virtualized Multi-Mission Operations Center (vMMOC) is nearly complete. The Space Science Mission Operations (SSMO) organizations spacecraft ACE, Fermi, LRO, MMS(4), OSIRIS-REx, SDO, SOHO, Swift, and Wind are in the process of being fully migrated to the vMMOC. The benefits of the vMMOC will be the normalization and the standardization of IT services, mission operations, maintenance, and development as well as ancillary services and policies such as collaboration tools, change management systems, and IT Security. The vMMOC will also provide operational efficiencies regarding hardware, IT domain expertise, training, maintenance and support.The presentation will also cover SSMO's secure Situational Awareness Dashboard in an integrated, fleet centric, cloud based web services fashion. Additionally the SSMO Telemetry as a Service (TaaS) will be covered, which allows authorized users and processes to access telemetry for the entire SSMO fleet, and for the entirety of each spacecrafts history. Both services leverage cloud services in a secure FISMA High and FedRamp environment, and also leverage distributed object stores in order to house and provide the telemetry. The services are also in the process of leveraging the cloud computing services elasticity and horizontal scalability. In the design phase is the Navigation as a Service (NaaS) which will provide a standardized, efficient, and normalized service for the fleet's space flight dynamics operations. Additional future services that may be considered are Ground Segment as a Service (GSaaS), Telemetry and Command as a Service (TCaaS), Flight Software Simulation as a Service, etc.

Ido, Haisam Kassim↗

Quantum Technologies for UAS (QTech)

Recent advances in small Unmanned Aerial System (sUAS) technologies lower the barriers for use by both private and commercial entities. However, these advances are also likely to lead to greater vehicle densities, a more heterogenous mix of vehicles and equipment and greater levels of vehicle autonomy, which can increase the chance for communications disruptions. For the safe and secure operation of these vehicles, it is essential to have a robust communications network. This work is focused on harnessing the power of quantum technologies to enable this robust communications network by: (1) utilizing quantum optimization algorithms to design robust network with routing redundancy that can respond adaptively to dynamically changing real-time environment and disruptions, (2) utilize quantum optimization algorithms resource allocation for detection, localization, and tracking of mobile communication disruption agents and (3) utilize quantum key distribution (QKD) to execute secure key sharing in anti-jamming protocols for secure radio frequency (RF) communication. Efforts to map these quantum optimization algorithms to commercially available quantum annealers and soon to be available general-purpose gate-model quantum hardware architectures will be reviewed, and plans for testing the solutions to these algorithms through indoor sUAS flight tests will be discussed. Lastly, efforts to miniaturize and practically deploy Quantum Key Distribution (QKD) hardware, which could ultimately be used to securely exchange encryption keys, in sUAS networks will be reviewed.

Quantum Computing↗

Vedizar Fingerprinter

SAND2025-03289O Vedizar Fingerprinter simplifies the process of identifying devices on a network by analyzing traffic data. It uses a unique library to recognize different devices, making it easier for users to understand what is happening on their networks. This software is ideal for IT and operational technology environments, helping organizations monitor their networks effectively. By saving results in a database, it allows for easy access and review of device information. Users can enhance their network security and optimize performance without needing specialized hardware or technical expertise. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Jacobellis, John [Sandia National Lab. (SNL-CA), L↗

R2U2: Monitoring and Diagnosis of Security Threats for Unmanned Aerial Systems

We present R2U2, a novel framework for runtime monitoring of security properties and diagnosing of security threats on-board Unmanned Aerial Systems (UAS). R2U2, implemented in FPGA hardware, is a real-time, REALIZABLE, RESPONSIVE, UNOBTRUSIVE Unit for security threat detection. R2U2 is designed to continuously monitor inputs from the GPS and the ground control station, sensor readings, actuator outputs, and flight software status. By simultaneously monitoring and performing statistical reasoning, attack patterns and post-attack discrepancies in the UAS behavior can be detected. R2U2 uses runtime observer pairs for linear and metric temporal logics for property monitoring and Bayesian networks for diagnosis of security threats. We discuss the design and implementation that now enables R2U2 to handle security threats and present simulation results of several attack scenarios on the NASA DragonEye UAS.

Formal Methods↗

Enabling Earth Science: The Facilities and People of the NCCS

The NCCS's mass data storage system allows scientists to store and manage the vast amounts of data generated by these computations, and its high-speed network connections allow the data to be accessed quickly from the NCCS archives. Some NCCS users perform studies that are directly related to their ability to run computationally expensive and data-intensive simulations. Because the number and type of questions scientists research often are limited by computing power, the NCCS continually pursues the latest technologies in computing, mass storage, and networking technologies. Just as important as the processors, tapes, and routers of the NCCS are the personnel who administer this hardware, create and manage accounts, maintain security, and assist the scientists, often working one on one with them.

Source record↗

Ransomware Security Threat Modeling for Photovoltaic Systems

Ransomware attacks are one of the most dangerous cyber-attacks which can disrupt the operation of photovoltaic (PV) systems and incur an enormous economic loss. This paper introduces a ransomware security threat modeling method that identifies potential vulnerabilities, threats, and impacts of ransomware attacks targeting a PV system. Here, the security threat modeling consists of three steps: 1) system identification, 2) threat modeling that finds existing vulnerabilities, 3) attack modeling that designs attack profiles to succeed ransomware attacks, and 4) penetration testing that performs authorized cyber-attacks and analyzes impacts of the ransomware attack profiles using a real-time hardware-in-the-loop (HIL) PV system security testbed.

attack modeling↗

Sentinel

Network intrusion detection systems (NIDS) are commonplace in network security but they frequently employ algorithms that are computational demanding requiring hardware and software with significant power requirements. Two examples of such resource-intensive algorithms used for network security are regular expression matching and broader signature pattern matching which are commonly used in deep packet inspection (DPI). Network security algorithms that have large power requirements may be a challenge for low-power internet-of-things (IoT) environments, which generally lack the power resources to implement complex security measures like computationally expensive DPI at the edge. Furthermore, IoT environments incorporating 5G standalone networks have network latency constraints beyond just power that make DPI at the edge even more difficult. Programmable logic is ideally suited for machine learning inference for DPI because of its deep instruction level parallelism and single-cycle memory access. Machine learning approaches for DPI have been explored before using the programmable logic of field programmable gate arrays (FPGA) as a potential solution for NIDS approaches that would be power-suitable for IoT. However, those previous programmable logic NIDS approaches utilize either a supervised or unsupervised learning model. Sentinel utilizes the ensemble of these two machine learning approaches known as a semi-supervised approach which has shown promise in NIDS implementations. Sentinel provides a programmable logic implementation of a semi-supervised approach for DPI which operates at much lower power and latency than a GPU implementation with negligible loss of accuracy due to quantization through a logistic regressor.

Anderson, MatthewW [Idaho National Laboratory (INL↗

Designing FAIR Workflows at OLCF: Building Scalable and Reusable Ecosystems for HPC Science

High Performance Computing (HPC) centers, such as the Oak Ridge Leadership Computing Facility (OLCF), provide advanced infrastructure that enables scientific research at extreme scale. These centers operate with unique hardware configurations, specialized software environments, and elevated security re quirements that differ substantially from what most users encounter on their local systems. As a result, users often develop customized digital artifacts that are tightly coupled to the specific configuration of a given HPC center. Although necessary, this practice can lead to significant duplication of effort as multiple users independently create similar solutions to common problems.

97 MATHEMATICS AND COMPUTING↗

Ethernet for Space Flight Applications

NASA's Goddard Space Flight Center (GSFC) is adapting current data networking technologies to fly on future spaceflight missions. The benefits of using commercially based networking standards and protocols have been widely discussed and are expected to include reduction in overall mission cost, shortened integration and test (I&T) schedules, increased operations flexibility, and hardware and software upgradeability/scalability with developments ongoing in the commercial world. The networking effort is a comprehensive one encompassing missions ranging from small University Explorer (UNEX) class spacecraft to large observatories such as the Next Generation Space Telescope (NGST). Mission aspects such as flight hardware and software, ground station hardware and software, operations, RF communications, and security (physical and electronic) are all being addressed to ensure a complete end-to-end system solution. One of the current networking development efforts at GSFC is the SpaceLAN (Spacecraft Local Area Network) project, development of a space-qualifiable Ethernet network. To this end we have purchased an IEEE 802.3-compatible 10/100/1000 Media Access Control (MAC) layer Intellectual Property (IP) core and are designing a network node interface (NNI) and associated network components such as a switch. These systems will ultimately allow the replacement of the typical MIL-STD-1553/1773 and custom interfaces that inhabit most spacecraft. In this paper we will describe our current Ethernet NNI development along with a novel new space qualified physical layer that will be used in place of the standard interfaces. We will outline our plans for development of space qualified network components that will allow future spacecraft to operate in significant radiation environments while using a single onboard network for reliable commanding and data transfer. There will be a brief discussion of some issues surrounding system implications of a flight Ethernet. Finally, we will show an onboard network architecture for a proposed new mission using Ethernet for science data transport.

Webb, Evan↗

Cyber Protection of Grid-Connected Devices Through Embedded Online Security

Cybersecurity research regarding the electric power grid has primarily been focused on protecting the communication layer of grid-connected devices against cyber-attack threats. Although many developed methods have greatly reduced the effects of a cyber-attack on the vulnerabilities of grid-connected devices, discovering new vulnerabilities is inevitable and a constant threat. As a result, the overall reliability and security of network communications with regard to grid-connected devices is a concern. Here, this paper proposes a method that further secures a system by focusing on the control and hardware layer of grid-connected devices. The device’s controller firmware will be validated and authenticated using integrated device emulation resources prior to being activated to control the grid-connected device. This verification process is performed while the controller is online and actively controlling power flows related to the device. Therefore, an attack to the system through a malicious firmware patch would be detected by the online security and rejected while safely maintaining continuous and stable control of the device. This method integrates the concepts of firmware hot-patching, digital twins, and active monitoring into an overall cybersecurity protection system.

cybersecurity↗