Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “data authentication”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

DER Cybersecurity Standards: Assessment and Gap Analysis

The purpose of this report is to share the comprehensive gap analysis of existing cybersecurity standards applicable to Distributed Energy Resources (DERs) within the electric power sector. This analysis aims to identify critical deficiencies in current standards, assess their alignment with industry needs, and provide actionable recommendations for enhancing cybersecurity measures. The scope encompasses various DER technologies, including solar, wind, energy storage, and hydrogen fuel cells, and emphasizes the significance of establishing robust cybersecurity frameworks and standards to safeguard these increasingly integrated systems. The report provides valuable insights for stakeholders in the DER ecosystem, including manufacturers, utilities, and regulators. It underscores the importance of continued development and refinement of cybersecurity standards to keep up with the technical advances in DERs and associated cybersecurity challenges. The analysis evaluated IEC, IEEE, ISA, ISO, and UL standards relevant to DER cybersecurity. Standards were assessed on their coverage of key requirements including data availability, integrity, confidentiality, access control, authentication, encryption, and system hardening. For each standard, the analysis assessed its alignment with current industry practices, regulatory compliance, effectiveness in addressing known risks, coverage of emerging risks, and how it promotes interoperability. The evaluation also considered potential integration challenges and barriers to adoption.

97 MATHEMATICS AND COMPUTING↗

Source Authentication of Distribution Synchrophasors for Cybersecurity of Microgrids

This letter proposes a hybrid approach combining Self-Adaptive Mathematical Morphology (SAMM) and Time-Frequency (TF) techniques to authenticate the source information of Distribution Synchrophasors (DS) within near-range locations. The SAMM can adaptively regulate the synchrophasors variations which are representatives of local environmental characteristics. Subsequently, TF mapping is employed to extract informative signatures from the regulated synchrophasors variation. Finally, Random Forest Classification (RFC) is used to correlate the extracted signatures with the source information based on the derived TF mapping. Experiment results using DS collected at multiple small geographical scales validated the proposed methodology.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Evaluating Named Data Networking for Industrial Control System [Slides]

Current proposed work is: See if the inherent security that comes with Named Networking (NDN) can be applied to Industrial Control Systems; and, Every packet is required to be cryptographically signed which makes every single piece of data communicated in the system secure and authenticated.

42 ENGINEERING↗

Synchronized Waveforms – A Frontier of Data-Based Power System and Apparatus Monitoring, Protection, and Control

Voltage and current waveforms contain the most authentic and granular information on the behaviors of power systems. In recent years, it has become possible to synchronize waveform data measured from different locations. Thus large-scale coordinated analyses of multiple waveforms over a wide area are within our reach. This development could unleash a set of new concepts, strategies, and tools for monitoring, protecting, and controlling power systems and apparatuses. This paper presents an in-depth review and analysis of the advancements in synchronized waveform data, including measurement devices, data characteristics, use cases, and comparisons with synchrophasor data. Based on the findings, five strategies are proposed to discover and develop synchronized waveform based applications over multiple application areas. The paper also presents three complementary measurement platforms and two data screening algorithms for application implementation. It further discusses committee activities and standard developments useful to explore the full potential of the data.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Precoder Design for Physical-Layer Security and Authentication in Massive MIMO UAV Communications

Supporting reliable and seamless wireless connectivity for unmanned aerial vehicles (UAVs) has recently become a critical requirement to enable various different use cases of UAVs. Due to their widespread deployment footprint, cellular networks can support beyond visual line of sight (BVLOS) communications for UAVs. In this paper, we consider cellular connected UAVs (C-UAVs) that are served by massive multiple input-multiple-output (MIMO) links to extend coverage range, while also improving physical layer security and authentication. Here, we consider Rician channel and propose a novel linear precoder design for transmitting data and artificial noise (AN). We derive the closed-form expression of the ergodic secrecy rate of CUAVs for both conventional and proposed precoder designs. In addition, we obtain the optimal power splitting factor that divides the power between data and AN by asymptotic analysis. Then, we apply the proposed precoder design in the fingerprint embedding authentication framework, where the goal is to minimize the probability of detection of the authentication tag at an eavesdropper. In simulation results, we show the superiority of the proposed precoder in both secrecy rate and the authentication probability considering moderate and large number of antenna massive MIMO scenarios.

99 GENERAL AND MISCELLANEOUS↗

Dynamic signature generation from keystroke dynamics

Described herein are various technologies pertaining to extracting cryptographic keys from user behavioral biometrics, specifically keystroke dynamics. Such cryptographic keys can be used for, among other things, user authentication throughout computer sessions. Keystroke dynamics are timing data indicating when keys were pressed and when they were released.

97 MATHEMATICS AND COMPUTING↗

Computing system operational methods and apparatus

Computing system operational methods and apparatus are described. According to one aspect, a computing system operational method includes accessing user information regarding a user logging onto a computing device of the computing system, processing the user information to determine if the user information is authentic, as a result of the processing determining that the user information is authentic, first enabling the computing device to execute an application segment, and as a result of the processing determining that the user information is authentic, second enabling the application segment to communicate data externally of the computing device via one of a plurality of network segments of the computing system.

Edgar, Thomas W.↗

DeepLynx Ecosystem 2025

Poor data integration and governance continue to plague complex engineering projects, resulting in missed cost, schedule, and performance targets. Departments operate in isolated systems with manual data exchange, creating fragmented information that compounds errors and leads to significant delays and cost overruns. The DeepLynx ecosystem addresses these challenges through an open-source, modular data management platform that transforms fragmented project data into an integrated digital thread. Built on a federated microservice architecture, the ecosystem comprises seven specialized tools centered around DeepLynx Nexus, a unified data catalog with hierarchical organization and graph-based navigation capabilities. The ecosystem includes: DeepLynx Stream for real-time timeseries data ingestion from industrial sources; DeepLynx Ingest for governed data uploads with formal review workflows; DeepLynx Lattice for ontology-based entity and relationship extraction; DeepLynx Run for workflow orchestration and secure AI/ML compute; DeepLynx Visualize for 3D digital twin visualization; and DeepLynx Insight for AI-assisted document analysis with traceable, grounded responses. Deployable in cloud, on-premise, or hybrid environments using containerized Docker applications and Helm charts, the DeepLynx ecosystem provides flexible infrastructure that adapts to organizational requirements. By consolidating project data into a unified data lake with role-based access controls and OAuth2 authentication, DeepLynx enables digital thread and digital twin capabilities that improve decision-making, reduce risk, and support complex engineering workflows throughout the project lifecycle.

42 - ENGINEERING↗

Next generation experimental data access at NSLS-II

The NSLS-II network and computing infrastructure has been significantly updated recently. The re-IP process in 2020-2021 enabled the NSLS-II network to be routable to the rest of the BNL campus. Then, standardization of the operating systems and deployment procedures helped to deliver a consistent environment to workstations and servers used by all NSLS-II beamlines. In particular, the RedHat Enterprise Linux 8 was deployed to 700+ machines using the RedHat Satellite infrastructure management product, and all critical services (IOCs, databases, etc.) were migrated to the new OS. NFS users’ home directories are consistent across all of the machines, which eliminates the need for the individual configuration of the user environment on each host. The standard suite of software packages is available to the beamline staff and users, which includes the system packages (deployed via RPM) as well as the conda environments for data acquisition and analysis. Security measures were implemented to comply with the industry standards, which include multi-factor authentication (using Duo), secure screen lock for the beamline machines, and advanced access control to the experimental data that is stored in shared central storage available on all hosts. These major enhancements facilitated sharing the experimental data (currently for a number of selected beamlines, with a plan to extend it to the whole facility in the nearest future) with the users via an externally facing JupyterHub instance. The beamlines keep using the Bluesky data acquisition framework to orchestrate their experiments, and the new infrastructure enabled them to use a next-generation data access library called tiled.

36 MATERIALS SCIENCE↗

Disruption of Commercial Solar Inverter System by TLS Proxy Man-in-the-Middle Attack

Transport Layer Security (TLS) is a cryptographic protocol that encrypts communication data, providing end-to-end communication encryption and authentication. Currently, TLS is widely adopted for securing communication between servers and end devices, including solar inverter systems. Therefore, users/operators can securely access the solar inverters through a web user interface (WebUI) application programmable interface (API) on a PC or server over TLS-enabled Wi-Fi or Ethernet. However, the security of the TLS-based network becomes compromised if it is breached by a TLS proxy man-in-the-middle (MITM) exploit. This report explores potential vulnerabilities in a commercial solar inverter system that leverages a TLS proxy MITM and discusses the impacts through assume-breached penetration testing. Furthermore, the paper explores recommended mitigation methods against the TLS proxy MITM exploit in solar inverters.

97 MATHEMATICS AND COMPUTING↗

Security Evaluation of Smart Cards and Secure Tokens: Benefits and Drawbacks for Reducing Supply Chain Risks of Nuclear Power Plants

The supply chain attack pathway is being increasingly used by adversaries to bypass security controls and gain unauthorized access to sensitive networks and equipment (e.g., Critical Digital Assets). Cyber-attacks targeting supply chain generally aim to compromise the environments, products, or services of vendors and suppliers to inject, add, or substitute authentic software and hardware with malicious elements. These malicious elements are deemed to be authentic as they arise from the vendor or supplier (i.e., the supply chain). This research aims to leverage findings and assumptions made from the previous report to determine the security benefits and drawbacks of a smart card- based hardware root of trust. Smart cards can provide devices inside Nuclear Power Plants (NPP) with a secure environment to store keys in and perform sensitive operations such as digital signature generation. These abilities can be leveraged to increase supply chain cybersecurity by autonomously providing NPP Licensees with reports on device integrity, authenticity and measurements of executable and non-executable data.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Perturbation-Based Diagnosis of False Data Injection Attack Using Distributed Energy Resources

Modern smart grid relies on various sensor measurements for its operational control. In a successful false data injection attack, the attacker manipulates the measurements from the grid sensors such that undetected errors are introduced into the estimates of the system parameters leading to catastrophic situations. This paper proposes a novel perturbation based false data injection attack detection mechanism that utilizes inverter based distributed energy resources (DERs) to create low magnitude perturbation signal in the distribution system voltage that is inconsequential to the normal grid operation. Two voltage sensitivity analysis based algorithms are designed to identify the optimal set of DERs that can create the voltage perturbation signal of desired magnitude. An analytical method of voltage sensitivity analysis is used to compute the magnitude of voltage perturbation signal at each node in a computationally efficient manner. Then, a detection mechanism is developed that checks for the presence of the perturbation sequence in each sensor measurement. A sensor measurement is deemed authentic if the voltage perturbation signal is present in the data. In case of sensor malfunction or cyber-attack, the perturbation signal will not be present in the measurement data. Performance of the proposed attack detection mechanism is validated via simulation of the IEEE 69 bus test system.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Document-Based Nuclear Archaeology

Deeper reductions in the nuclear arsenals will require better understanding of historic fissile material management and production. The concept of “nuclear archaeology” has been considered since the 1990s to provide the tools and methods to develop independent production estimates, primarily based on nuclear forensic techniques. Here, we propose to add a framework for reconstructing the history of a nuclear program that complements traditional nuclear archaeology techniques by examining the role of operating records to support such an effort. As a test case, we use the JEEP II reactor, a 2 MW civilian research reactor at Norway’s Institute for Energy Technology (IFE), in operation for more than fifty years, however, recently shut down permanently. We have collected, analyzed, and started to preserve the reactor’s operating records, which exist on both analog and digital media, and to simulate parts of its history using OpenMC/ONIX neutronics calculations. Here, a particular focus of this project has been on digital data curation and preservation to confirm and maintain the integrity, authenticity, and provenance of these records. In developing guidelines for best practices that conform to existing standards for long-term digital preservation and curation, we hope this project can help lay the basis for future nuclear archaeology efforts to support nuclear arms control and disarmament.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

VISTA

SAND2025-14753O VISTA Image Management is a tool that serves as a thin wrapper around S3 storage, enabling teams to create projects, upload images, and add labels to data. It uses standard open-source libraries, employs conventional authentication and authorization methods, and is expected to run behind a reverse proxy that handles authentication. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Garland, Anthony [Sandia National Lab. (SNL-CA), L↗

Secure Data Logging and Processing with Blockchain and Machine Learning (Final Report)

Secure Data Logging and Processing with Blockchain and Machine Learning (ML) research is focused on the development of a platform to securely log and process sensor data in fossil power plants. The platform integrates two emerging technologies, blockchain and ML, and incorporates several innovative mechanisms to ensure the integrity, reliability, and resiliency of power systems. The goal is to protect the power plant from various cyberattacks such as false data injection and denial of service attacks using these technologies. The research goal was enabled by the following Research Project Objectives: 1) Secure authentication and identity verification of sensor nodes, actuators, and other equipment within a network. 2) Development of mechanisms that ensure only data sent by legitimate sensors are accepted and stored in the data repository. 3) Development of data aggregation methodologies using ML / Deep Learning (DL) algorithms to minimize noise / faulty data. 4) Implementation of the blockchain technologies to provide data security using secured IOTA framework & nodes.

20 FOSSIL-FUELED POWER PLANTS↗

Authentication of smart grid communications using quantum key distribution

Smart grid solutions enable utilities and customers to better monitor and control energy use via information and communications technology. Information technology is intended to improve the future electric grid’s reliability, efficiency, and sustainability by implementing advanced monitoring and control systems. However, leveraging modern communications systems also makes the grid vulnerable to cyberattacks. Here we report the first use of quantum key distribution (QKD) keys in the authentication of smart grid communications. In particular, we make such demonstration on a deployed electric utility fiber network. The developed method was prototyped in a software package to manage and utilize cryptographic keys to authenticate machine-to-machine communications used for supervisory control and data acquisition (SCADA). This demonstration showcases the feasibility of using QKD to improve the security of critical infrastructure, including future distributed energy resources (DERs), such as energy storage.

24 POWER TRANSMISSION AND DISTRIBUTION↗

System and method for selective transmission and reception for stationary wireless networks

A system and methods for selective transmission and reception for stationary wireless networks. The system and method include an end user equipment, a primary base station, a core network, and a selective server. The end user equipment transmits a request for transmission to the primary base station receiver. The primary base station authenticates the end user equipment using a cellular network authentication process. The primary base station then searches for a time slot data for the end user equipment from the selective server and determines whether the time slot is open for transmission, steers a beam towards the end user equipment when time slot is open for transmission. The primary base station then enables transmission from the end user equipment, wherein the enabling is performed by the primary base station. The core network receives the transmission from the end user equipment.

Bhuyan, Arupjyoti↗

Evaluation of Data Catalog Software for Hanford Site Environmental Datasets

Environmental information and data underpin achievement of the U.S. Department of Energy (DOE) Office of Environmental Management (EM) mission at the Hanford Site. The Hanford Environmental Data Management (HEDM) Program is the DOE Richland Operations Office (RL) approach to develop and implement a formal program for managing environmental data and the associated records, materials, and systems at the Hanford Site. The current project, contract, organization, and contractor-specific efforts at managing environmental data sets are insufficient to provide orderly, long-term, site-wide access. A vital element to be created within the HEDM program plan is a catalog of data sources, called the Hanford Environmental Information and Data Index (HEIDI), that will enable long-term access and retrievability for the multiple independent sources of data that might otherwise be difficult to discover. This report compares leading open source and commercial data catalog platforms using criteria to assess the functionality needed to develop the HEIDI catalog of Hanford data sources that connects and exchanges data with established Hanford Local Area Network (HLAN) enterprise information technology systems. Proprietary platforms evaluated included ArcGIS Enterprise Sites, Junar, OpenDataSoft, and Socrata, and non-proprietary platforms included Energy Data eXchange (EDX), Comprehensive Knowledge Archive Network (CKAN), and DKAN (a Drupal-based open data portal based on CKAN). Capabilities supporting data discoverability, retrieval, and archival, as well as metadata standard requirements and integration into the HLAN were rated as either failing to meet requirements (F), meeting requirements (M), or exceeding requirements by delivering additional desired features (E). The lowest rating for any capability area was assigned as the overall rating for the platform. These findings enable DOE-RL and the contractors implementing the HEDM plan to focus on candidate tools likely to meet the requirements for implementing HEIDI. All of the platforms receiving an overall rating of ‘F’ were unable to be deployed on Hanford infrastructure or within dedicated cloud resources. A propriety software-as-a-service (SaaS) model of delivering a data catalog (e.g., found in software such as Junar and OpenDataSoft) favors consistency across customers at the expense of customization and configurable roles that are needed for Hanford work. Hosting data on a shared commercial platform places limits on dataset size (maximum of 240 Mb for OpenDataSoft), a significant limitation for HEIDI implementation. EDX, a government data catalog based on CKAN, received the ‘F’ rating due to an inability to incorporate authentication from HLAN into the system. Among platforms rated ‘M’ or ‘E’, only the Socrata platform had a SaaS delivery model. In contrast to other SaaS platforms, Socrata provided custom roles and gateways that allow local datasets to be incorporated into an online catalog. Socrata also complies with the Federal Risk and Authorization Management Program, a significant benefit for cloud-based management of Hanford data. The other platforms rated ‘M’ or ‘E’, ArcGIS Enterprise Sites, CKAN, and DKAN, provide fully self-hosted options, allowing for greater control and flexibility with the HEIDI catalog. These widely used tools have supportive communities of practice, extensive customization options, and demonstrated deployments that provide evidence that they can meet requirements, often deliver additional desired features, and work well with federal government systems. Completely customized alternatives built on a collection of applications were not evaluated because achieving similar performance to CKAN or DKAN requires substantial resources, especially in the absence of the active communities that have grown to support these tools. ArcGIS Enterprise Sites, Socrata, CKAN, and DKAN were evaluated as strong candidates for successful implementation with HEIDI.

54 ENVIRONMENTAL SCIENCES↗