ENHANCING A SYSTEMS ENGINEERING AND REGULATORY LIFECYCLE-BASED FRAMEWORK FOR SECURITY-BY-DESIGN
Explore the source record for details and available documents.
SEARCH · Engineering Papers
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Explore the source record for details and available documents.
Explore the source record for details and available documents.
Explore the source record for details and available documents.
Explore the source record for details and available documents.
Explore the source record for details and available documents.
Slides created to discuss the report "Approach and Model Used to Represent a Timeline Analysis for Security Design Enhancements" (August 2022 INL/ RPT-22-68664) for an upcoming DOE security workshop. Advanced reactors will be able to use risk insights for many design aspects. We need realistic scenarios for input into the licensing basis safety-case. These scenarios must include timing and physics. We need to automate the safety-case creation as much as possible.
This report presents guidance to support the implementation of security objectives during the design process for nuclear facilities using an organization’s quality management system. The guidance in this document is intended for design vendors and operators of nuclear power facilities. Additionally, this guidance document can be beneficial to regulatory bodies, industry partners, customers, and other stakeholders within the nuclear power market. This report aims to ensure security consequences are identified before designs are completed, which may lead to reduced costs and higher security effectiveness and efficiency.
This report presents guidance to support the implementation of security objectives during the design process for nuclear facilities using an organization’s quality management system. The guidance in this document is intended for design vendors and operators of nuclear power facilities. Additionally, this guidance document can be beneficial to regulatory bodies, industry partners, customers, and other stakeholders within the nuclear power market. This report aims to ensure security consequences are identified before designs are completed, which may lead to reduced costs and higher security effectiveness and efficiency.
These slides present a high level overview of an ongoing project sponsored by NNSA. The project is focused on economic analysis of physical security design of micro reactors. The slides will be presented to NNSA's office of International Nuclear Security (INS) at a program update meeting on May 28th, 2025.
This presentation addresses the security challenges posed by Inverter-Based Resources (IBRs) in the modern energy landscape. The presentation highlights the vulnerabilities and risks associated with IBRs, including the potential for cyber-attacks, the impact of insecure defaults, and the systemic risks posed by supply chain dependencies. Key topics covered include: 1) The increasing digital transformation in energy systems and the associated security risks. 2) Specific vulnerabilities in IBRs, including weak passwords, hardcoded credentials, and insecure web application interfaces. 3) The implications of persistent connectivity and the strategic risks posed by foreign-manufactured components. 4) The role of regulatory frameworks, such as NERC CIP, in addressing these challenges and the limitations of current oversight. 5) Practical solutions for mitigating risks, including secure design practices, vendor risk assessments, and the importance of strong passwords and role-based access control. The presentation underscores the necessity of a comprehensive, system-of-systems approach to securing IBRs, emphasizing the need for collaboration across various stakeholders, including operators, developers, and regulators, to ensure the resilience and security of the energy grid.
This help sheet provides an overview of physical safety and security design elements for public EV charging stations and general best practices that can be considered for the safety and comfort of charging station customers.
This report presents the regulatory requirements and directions on the physical security of advanced nuclear reactors in USA. Presently, a rule is being proposed that allows for a performance-based analysis. In determining the physical security requirements for an advanced reactor, new tools may be desired to conduct a performance-based analysis. These tools should incorporate dynamic analysis methods to provide as much realism as possible. In comparison, the security requirements for existing light water reactors (LWRs) are much more prescriptive and the analysis conducted to establish the required physical security strategies were more easily performed with static analysis. In order to achieve the cost goals that advanced reactors require for adoption; the nuclear security force required should not be excessive. Dynamic physical security analysis methods and tools have been developed by the US Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) program. This report details how the dynamic risk analysis tools developed in the LWRS program using the dynamic risk modelling tool, EMRALD, may be adapted for use in analyzing the physical security designs for advanced reactors accounting for variable performance-based requirements. This report provides an example analysis of a hypothetical SFR using publicly available information and generic assumptions to demonstrate the methods and potential presentation and analysis of the results. No actual plant information is used in this example analysis. Future work in this area will create additional models that can be adapted for any advanced reactor concept and use various security features to create a physical security system that provides adequate protection from radiological theft and sabotage.
This study aims to enhance the security of radioactive materials during transport by analyzing commonalities in cargo thefts conducted by non-state groups such as thieves and terrorists. This research focuses on identifying patterns and trends in the methods used to steal high-value cargo, with the goal of applying these insights to improve transport security of radioactive materials. Key questions addressed include the frequency of specific tools, techniques, and insider involvement in thefts, as well as the use of weapons, electronic jamming equipment, and specialized tools. Findings will inform security design improvements and industry practices to mitigate vulnerabilities. The study involves a comprehensive review of literature and case studies, utilizing data sources from 2018 to 2023. Articles will be selected based on their relevance to thefts of valuable cargo in transit, with a focus on incidents involving non-state actors. The methodology will include statistical and inferential analysis to identify trends, with results visualized through pie charts, frequency analyses, and terrain maps. The discussion will highlight the implications of findings and provide actionable recommendations for strengthening security measures. Limitations such as data availability and reporting inconsistencies will be acknowledged. Suggestions for future improvements will be constructed using existing case studies and expert feedback. The study’s outcomes aim to raise awareness within the industry, inform policy decisions, and enhance security protocols for radioactive material transport. Metrics for impact include the potential publication of findings, presentations at conferences to raise awareness, and the subsequent actions taken by stakeholders based on the research. By identifying trends and vulnerabilities and suggesting improvements, this research contributes to preventing the illicit use of nuclear and radiological materials.
Uncrewed aerial systems (UAS) have been an area of focus for the Office of International Nuclear Security within the US Department of Energy’s National Nuclear Security Administration and other foreign and domestic organizations for several years. This emerging technology provides significant capabilities to the nuclear security realm, but there are many things to consider when implementing them into an established security design or network. The goal of this paper is to discuss some of the benefits, challenges, and lessons learned with using UAS at nuclear facilities and during transport of material. Generic examples of UAS implementation will be used to facilitate a publicly releasable paper and presentation. The paper will start with a summary of the types and capabilities of UAS to provide a better understanding for people unfamiliar with current and new capabilities of these systems. Since there are many different types and sizes of UAS, this paper will focus on drones 55 lb and smaller. Then some of the use cases of UAS for security and challenges of employing them will be covered. Finally, lessons learned and some best practices that Oak Ridge National Laboratory has discovered from research, development, testing, and evaluation will be summarized.
With enigmatic observations of enhanced reactivity of wet CO 2 -rich fluids with metal silicates, the mechanistic understanding of molecular processes governing carbonation proves critical in designing secure geological carbon sequestration and economical carbonated concrete technologies. Here, we use the first principle and classical molecular simulations to probe the impact of nanoconfinement on physicochemical processes at the rock–water–CO 2 interface. We choose nanoporous calcium–silicate–hydrate (C–S–H) and forsterite (Mg 2 SiO 4 ) as model metal silicate surfaces that are of significance in cement chemistry and geochemistry communities, respectively. We show that while a nanometer-thick interfacial water film persists at unsaturated conditions consistent with in situ infrared spectroscopy, the phase behavior of the water–CO 2 mixture changes from its bulk counterpart depending on the surface chemistry and nanoconfinement. We also observe enhanced solubility at the interface of water and CO 2 phases, which could amplify the CO 2 speciation rate. Additionally, through free energy calculations, we show that CO 2 could be found in a metastable state near the C–S–H surface, which can potentially react with surface water and hydroxyl groups to form carbonic acid and bicarbonate. These findings support the explicit consideration of nanoconfinement effects in reactive and non-reactive pore-scale processes.
An important challenge for smart grid security is designing a secure and robust smart grid communications architecture to protect against cyber-threats, such as Denial-of-Service (DoS) attacks, that can adversely impact the operation of the power grid. Researchers have proposed using Software Defined Network frameworks to enhance cybersecurity of the smart grid, but there is a lack of benchmarking and comparative analyses among the many techniques. In this work, a distributed three-controller software-defined networking (D3-SDN) architecture, benchmarking, and comparative analysis with other techniques is presented. The selected distributed flat SDN architecture divides the network horizontally into multiple areas or clusters, where each cluster is handled by a single Open Network Operating System (ONOS) controller. A case study using the IEEE 118-bus system is provided to compare the performance of the presented ONOS-managed D3-SDN, against the POX controller. In addition, the proposed architecture outperforms a single SDN controller framework by a tenfold increase in throughput; a reduction in latency of > 20%; and an increase in throughput of approximately 11% during the DoS attack scenarios.
Presentation Hosted at Device Assembly Facility (DAF). Joint collaboration by Atomic Weapons Establishment (AWE) and Lawrence Livermore National Laboratory (LLNL). Multiple measurements were recorded through a two-week period with 12 unique objects measured. LLNL deployed Machine learning software program for diagnostic assessments. Current status notes the dedicated DAF team LLNL maintains. Additionally, LLNL is compiling a report on the AWE-LLNL measurements and designing security benchmark experiments. The presentation concludes with future work envisioned.
In this paper, we present a secure datastore based on an Ethereum smart contract. Our research is guided by three research questions. First, we will explore to what extend a smart-contract-based datastore should resemble a traditional database system. Second, we will investigate how to store the data in a smart-contract-based datastore for maximum flexibility while minimizing the gas consumption. Third, we seek answers regarding whether or not a smart-contract-based datastore should incorporate complex processing such as data encryption and data analytic algorithms. The proposed smart-contract-based datastore aims to strike a good balance between several constraints: (1) smart contracts are publicly visible, which may create a confidentiality concern for the data stored in the datastore; (2) unlike traditional database systems, the Ethereum smart contract programming language (i.e., Solidity) offers very limited data structures for data management; (3) all operations that mutate the blockchain state would incur financial costs and the developers for smart contracts must make sure sufficient gas is provisioned for every smart contract call, and ideally, the gas consumption should be minimized. Our investigation shows that although it is essential for a smart-contract-based datastore to offer some basic data query functionality, it is impractical to offer query flexibility that resembles that of a traditional database system. Furthermore, we propose that data should be structured as tag-value pairs, where the tag serves as a non-unique key that describes the nature of the value. We also conclude that complex processing should not be allowed in the smart contract due to the financial burden and security concerns. The tag-based secure datastore designed this way also defines its applicative perimeter, i.e., only applications that align with our strategy would find the proposed datastore a good fit. Those that would rather incur higher financial cost for more data query flexibility and/or less user burden on data pre- and post-processing would find the proposed database too restrictive.