Engineering PapersSearch

SEARCH · Engineering Papers

Results for “secure communications”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Programmable low-coherence wavefronts for enhanced localization

Engineering the properties of electromagnetic wavefronts has become essential to imaging, wireless security, sensing, and wireless communication. In particular, wavefronts that exhibit low spatial coherence can enable sensing functionalities with high accuracy and low latency. The typical use of such wavefronts cannot take advantage of these possibilities, as they require the ability to dynamically reconfigure the wavefront in a controllable and repeatable fashion, over a broad spectral bandwidth. Here, we propose a new approach for generating broadband reconfigurable wavefronts which not only exhibit low spatial coherence at a particular frequency, but are also decorrelated with the wavefronts simultaneously generated at other frequencies. We demonstrate that this frequency-domain decorrelation is a key feature that, in combination with dynamic reconfigurability, enables localization measurements with an order-of-magnitude improvement in accuracy compared to the state of the art.

36 MATERIALS SCIENCE

Defensive Cybersecurity Architecture Design Using Force-on-Force Cyber-Physical Modeling

Currently, nuclear power plant physical security systems are highly dependent on air-gaps as a protective measure against cyber-threats. Cyber-physical threats become more likely as advanced cyber-threat capabilities to jump air-gaps transition into common use. Defending against the emerging threat of cyber-enabled physical intrusions is poorly understood. The consequence of these cyber-physical attacks has no quantitative analysis method to inform risk-informed, performance-based cybersecurity approaches. By modifying the physical security simulation tool Dante, cyber-physical threat consequence was able to be analyzed on a notional facility. The results of this analysis are used to design a Defensive Cybersecurity Architecture (DCSA) for the physical security system to produce example resilience measures for this notional facility. A DCSA defines security levels to provide a graded approach for defending plant functions, and security zones for trusted communication between systems. This approach can be applied to real world systems to produce physical protection systems and response measures that are resilient to cyber-physical threats.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF

Synopsis of NREL's Automated Mobility District (AMD) Research Program and Associated Publications

An automated mobility district (AMD) envisions a system of integrated mobility options that serves major activity centers such as campuses, central business districts, and large medical facilities. The National Renewable Energy Laboratory (NREL) has been investigating the implementation prospects for fully automated passenger transport systems that are deployed to operate within dense urban settings. This document provides a synopsis of findings revealed over the last three phases of work, which have yielded insights into the creation and management of AMDs anticipated to use automated vehicle (AV) technology over the next decade. Phase I and Phase II tracked the deployment and lessons learned from 10 early-stage demonstrations of automated shuttle deployments, and their associated insights into the challenges for automated driving systems to achieve safe operations within district-scale deployments. Phase III began in-depth investigations of critical subsystem components, as automation, electrification, and on-demand service continue to converge within initial AMD operations. These directed studies focus on elements of electrification, curbfront/station management, the role of infrastructure sensing, and overall integration of AMD safety management in central, simultaneous coordination of multiple AMD fleets. Future research in AMDs includes systems engineering methodology (more frequently referred to as "digital twins") for planning, design, testing, and ongoing operation of AMDs; location (or co-location) of management functions; and human supervision and passenger communications for safety and security in unattended vehicles. The synopsis references the foundational research products (papers and presentations) that have been published through conference proceedings, journal articles, and NREL reports.

33 ADVANCED PROPULSION SYSTEMS

Emerging Threats in Transportation Security Related to Intelligent Transportation Systems (ITS)

Transport of high-consequence shipments requires a resilient and robust systems of systems to guarantee cargo arrival. Furthermore, rising adoption of technologies such as connected and automated vehicles (CAVs), intelligent infrastructure, and vehicle-to-everything (V2X) communication presents unique challenges for securing transportation systems. Within these Intelligent Transportation Systems (ITS), several additional vulnerabilities exist that create pathways for adversarial attacks and cargo interception. For example, connectivity provides cyber pathways directly into vehicle systems and infrastructure for malicious actors. Furthermore, advanced vehicle automation exposes additional vehicle control necessary for shipment interception otherwise unavailable to adversaries. Within this paper, we will discuss the specific threats introduced by ITS-enabled technologies currently deployed and in development. These include those mentioned related to connectivity and automation, but will be expanded into grid, infrastructure, and vehicle specific threats. In addition, we will discuss how to potentially mitigate these emerging challenges as well as how to safeguard transportation systems from next generation attacks.

Cook, Adian [ORNL] (ORCID:0000000160825395)

Virtual Power Plant Architecture and Resilient Design

Virtual Power Plants (VPPs) represent a fundamental shift in electric grid operations, aggregating distributed energy resources (DERs) such as solar panels and battery storage to deliver utility-scale grid services traditionally provided by centralized power plants. This report examines the unique architectural, operational, and digital assurance considerations that distinguish VPPs from conventional utility infrastructure as they scale from pilot projects to mainstream deployment across the United States. While VPPs offer significant opportunities for grid modernization and enhanced flexibility, their distributed, multi-stakeholder architecture introduces distinct security challenges that differ fundamentally from traditional generation facilities. The analysis identifies risks in VPP operations, including device-level security gaps, platform vulnerabilities, and communication protocol weaknesses that create expanded attack surfaces compared to centralized power plants. Through examination of real-world incidents and emerging threat patterns, the report demonstrates how some VPPs' reliance on consumer-owned devices, public internet infrastructure, and complex vendor ecosystems require new approaches to digital assurance and operational security. The findings provide practical guidance for utilities, regulators, and aggregators to implement robust security frameworks and operational best practices essential for maintaining grid reliability as VPP deployment accelerates under the Federal Energy Regulatory Commission (FERC) Order 2222 and related regulatory initiatives.

24 - POWER TRANSMISSION AND DISTRIBUTION

Enabling end-to-end secure federated learning in biomedical research on heterogeneous computing environments with APPFLx

Facilitating large-scale, cross-institutional collaboration in biomedical machine learning (ML) projects requires a trustworthy and resilient federated learning (FL) environment to ensure that sensitive information such as protected health information is kept confidential. Specifically designed for this purpose, this work introduces APPFLx - a low-code, easy-to-use FL framework that enables easy setup, configuration, and running of FL experiments. APPFLx removes administrative boundaries of research organizations and healthcare systems while providing secure end-to-end communication, privacy-preserving functionality, and identity management. Furthermore, it is completely agnostic to the underlying computational infrastructure of participating clients, allowing an instantaneous deployment of this framework into existing computing infrastructures. Experimentally, the utility of APPFLx is demonstrated in two case studies: (1) predicting participant age from electrocardiogram (ECG) waveforms, and (2) detecting COVID-19 disease from chest radiographs. Here, ML models were securely trained across heterogeneous computing resources, including a combination of on-premise high-performance computing and cloud computing facilities. By securely unlocking data from multiple sources for training without directly sharing it, these FL models enhance generalizability and performance compared to centralized training models while ensuring data remains protected. In conclusion, APPFLx demonstrated itself as an easy-to-use framework for accelerating biomedical studies across organizations and healthcare systems on large datasets while maintaining the protection of private medical data.

Biomedical Research

Zero-day Attack Detection in Digital Substations Using In-Context Learning

In this paper, we address the critical challenge of detecting zero-day attacks in digital substations that employ the IEC-61850 communication protocol to ensure the security and reliability of modern power systems. While many heuristic and machine learning (ML)-based methods have been proposed for attack detection in IEC-61850 digital substations, generalization to unknown or zero-day attacks remains a challenge. We propose an approach that leverages the in-context learning ability of transformer architecture, which enables the model to learn from a few examples of a new task without explicit retraining. Our experiments on the IEC-61850 dataset demonstrate that the proposed method achieves more than 87% detection accuracy on zero-day attacks while the existing baselines fail. We believe this work has the potential to enhance the security of digital substations by enabling the effective detection of zero-day attacks.

LIu, Chen-Ching [Virginia Tech] (ORCID:00000002894

Lightfall v0.0.1

Lightfall is a desktop application for synchrotron beamline instrument control, data acquisition, and live analysis at the Advanced Light Source (ALS). Built on Python and Qt, it provides a native graphical interface for operating beamline hardware, configuring and executing experimental scans, and visualizing results in real time. Key features include direct integration with EPICS control systems, a built-in electronic logbook, remote beamline access over secure tunnels, and an interprocess communication (IPC) architecture that coordinates with external analysis applications via ZMQ and EPICS process variables. This IPC approach allows Lightfall to orchestrate specialized analysis tools—including GPU-accelerated streaming correlators—without embedding them, avoiding the dependency conflicts common in monolithic scientific software platforms. Compared to prior approaches such as Xi-CAM's plugin-based architecture, Lightfall's design cleanly separates instrument control from domain-specific analysis, enabling feedback-driven acquisition where live analysis results can adjust scan parameters during an experiment. Its native Qt interface provides responsive performance for real-time data visualization that web-based alternatives struggle to match. Lightfall is designed for use by beamline scientists and staff operating synchrotron instruments at national user facilities.

Pandolfi, Ronald [Lawrence Berkeley National Labor

Exponential Backoff and Its Security Implications for Safety-Critical OT Protocols over TCP/IP Networks

The convergence of Operational Technology (OT) and Information Technology (IT) networks has become increasingly prevalent with the growth of Industrial Internet of Things (IIoT) applications. This shift, while enabling enhanced automation, remote monitoring, and data sharing, also introduces new challenges related to communication latency and cybersecurity. Oftentimes, legacy OT protocols were adapted to the TCP/IP stack without an extensive review of the ramifications to their robustness, performance, or safety objectives. To further accommodate the IT/OT convergence, protocol gateways were introduced to facilitate the migration from serial protocols to TCP/IP protocol stacks within modern IT/OT infrastructure. However, they often introduce additional vulnerabilities by exposing traditionally isolated protocols to external threats. This study investigates the security and reliability implications of migrating serial protocols to TCP/IP stacks and the impact of protocol gateways, utilizing two widely used OT protocols: Modbus TCP and DNP3. Our protocol analysis finds a significant safety-critical vulnerability resulting from this migration, and our subsequent tests clearly demonstrate its presence and impact. A multi-tiered testbed, consisting of both physical and emulated components, is used to evaluate protocol performance and the effects of device-specific implementation flaws. Through this analysis of specifications and behaviors during communication interruptions, we identify critical differences in fault handling and the impact on time-sensitive data delivery. The findings highlight how reliance on lower-level IT protocols can undermine OT system resilience, and they inform the development of mitigation strategies to enhance the robustness of industrial communication networks.

DNP3

Electric Utility Communications Standards Landscape 2025 Edition

Historically, challenges to managing electric utility data exchange have been addressed through dedicated communication solutions, enabling the transmission of data with both speed and security. Protocols have been deployed in a relatively uniform fashion; for example, field communications for Supervisory Control and Data Acquisition (SCADA) are commonly implemented using IEEE 1815 (DNP3).

24 POWER TRANSMISSION AND DISTRIBUTION

Cyber-Informed Engineering (CIE) Workbook: End-of-Train (EoT) / Head-of-Train (HoT) Communications

This workbook presents a vulnerability (CVE-2025-1727 ) found in train applications and guides a digital risk assessment and mitigation analysis and application of Cyber-Informed Engineering principles to mitigate the potential consequences and ultimately the hazard through the engineering discipline because of exploiting this vulnerability. Workshop participants are encouraged to use the workbook to capture insights and lessons learned. The workbook guides the participant to: • Understand the HE communication vulnerability • Map digital threats to physical consequences • Use bowtie analysis to illustrate both “security” and “engineering” barriers • Apply CIE principles to ensure that even if communications are compromised, the physical engineered system still behaves safely. • Produce an actionable set of engineered and infosec controls for implementation

42 - ENGINEERING

Entropy of the Quantum–Classical Interface: A Potential Metric for Security

Hybrid quantum–classical systems are emerging as key platforms in quantum computing, sensing, and communication technologies, but the quantum–classical interface (QCI)—the boundary enabling these systems—introduces unique and largely unexplored security vulnerabilities. This position paper proposes using entropy-based metrics to monitor and enhance security, specifically at the QCI. We present a theoretical security outline that leverages well-established information-theoretic entropy measures, such as Shannon entropy, von Neumann entropy, and quantum relative entropy, to detect anomalous behaviors and potential breaches at the QCI. By linking entropy fluctuations to scenarios of practical relevance—including quantum key distribution, quantum sensing, and hybrid control systems—we promote the potential value and applicability of entropy-based security monitoring. While explicitly acknowledging practical limitations and theoretical assumptions, we argue that entropy-based metrics provide a complementary approach to existing security methods, inviting further empirical studies and theoretical refinements that can strengthen future quantum technologies.

97 MATHEMATICS AND COMPUTING

Draft Prototype Microreactor Transportation Safety Program

Microreactors are compact reactors capable of producing less than 50 megawatts of electrical energy. Typically, these reactors are factory-fabricated and designed to be easily transportable by truck, rail, vessel, or air. Microreactor designs often assume that the unit can be transported containing either unirradiated or irradiated fuel. The interest in microreactors is driven by several factors, including the need to generate power on at remote locations, at military installations, at facilities such as data centers, and in areas recovering from natural disasters. The U.S. Department of Defense is actively pursuing the microreactor concept to meet the increasing energy demands of military operations that require portable and dense power sources. Commercial vendors are also exploring microreactor concepts. The report Microreactor Transportation Emergency Planning Challenges (Maheras et al. 2024) outlined the emergency planning challenges associated with the transportation of microreactors by road, rail, and by barge/ship. The successful commercial deployment and redeployment of microreactors will also require the development of microreactor transportation safety programs. The elements in these safety programs are not specific to microreactors; however, the transport of microreactors may pose unique challenges in these areas. This report builds on the report Microreactor Transportation Emergency Planning Challenges (Maheras et al. 2024) and develops the elements of a prototype microreactor transportation safety program that describes the elements that should be contained vendor-developed microreactor transportation safety programs, identifying the unique elements associated with microreactor transport. This will provide vendors and their transportation contractors a basis for their transportation planning and will accelerate the commercial deployment and redeployment of microreactors by identifying those issues unique to microreactor transport. The emphasis of this report is on highway transport of microreactors. This is based on a U.S. Nuclear Regulatory Commission transportation package approval strategy of crawl-walk-run, where transport by highway is evaluated first (Coles et al. 2021, 2024, Maheras et al. 2021), then other surface modes (rail and barge/ship), and finally air transport. Evaluation of maritime transport of microreactors was recently initiated (Rigato et al. 2024, Maheras et al. 2025). The report first discusses microreactors in general and microreactor transportation safety program planning assumptions. The report then provides a description of the transportation safety planning process and provides an extensive discussion of the elements of transportation safety programs. Specific elements examined included transportation roles and responsibilities, transportation planning, transportation mode and route selection, carrier selection, transportation packaging, advance notification of shipments, public information and communications, emergency response plans and procedures, inspections, security, safe parking, shipment tracking, weather and road conditions, medical preparedness, training and exercises, and program evaluation. The report then identifies the unique elements of a transportation safety program associated with microreactor transport. These unique elements were in the areas of: the unusual nature of microreactor designs, compensatory measures, increased radiation dose rates in the vicinity of microreactors, transportation package approval versus 10 CFR 50.59, and the use of a risk-informed transportation package approval process.

22 GENERAL STUDIES OF NUCLEAR REACTORS

Enabling Secure and Resilient XFC: A Software/Hardware-Security Co-Design Approach

Extremely fast charging (XFC) has the potential to reduce the charging time of battery electric vehicles (BEV) to be equivalent to the filling time of internal combustion engine vehicles (ICEV), thus eliminating one of the few advantages ICEV still poses for light- and heavy-duty vehicles. Enabling XFC will, however, require coordination and cooperation between the grid, charging stations, and the vehicles themselves, which leads to an inevitable increase in the attack surface for all systems combined. In securing the overall system, we must not only embrace traditional cybersecurity, which is chiefly concerned with communications and the operation of digital systems, but also cyber-physical systems security as the proper operation of XFC is critically dependent on systems’ abilities to know about (sense) and interact with (actuate) the physical world. The project team consists of academic and industry researchers with backgrounds in cybersecurity, cyber-physical systems security, learning in adversarial environments, transportation security, grid security and resilience, wireless power transfer, converter design, and battery management systems.

33 ADVANCED PROPULSION SYSTEMS

Privacy-Aware RAG-Enabled LLMs for Collaborative AI in Organizations

Recent advancements in Large Language Models (LLMs) based on Transformer architectures have significantly improved capabilities in natural language processing and generation. However, deploying LLMs for inter-organizational communication poses challenges, in ensuring privacy and facilitating effective collaboration. This paper introduces a novel decentralized inference meta-agent chatbot that leverages privacy-aware Retrieval-Augmented Generation (RAG)-enabled LLMs for collaborative AI communication across organizations. Built on Microsoft’s Autogen, the platform enables LLMs to autonomously refine responses, enhancing accuracy and relevance. It incorporates advanced hallucination mitigation techniques using Uptrain and a privacy-focused RAG framework that employs synthetic document generation to protect sensitive information. Comprehensive evaluations demonstrate the platform’s effectiveness in maintaining contextual relevance and stringent privacy standards, effectively addressing critical challenges in LLM-enhanced collaborative AI communication. This work represents a significant step toward secure and efficient inter-organizational collaboration using advanced generative AI technologies.

97 - MATHEMATICS AND COMPUTING

Braxton Marlatt Intern Poster

The Internet of Things (IoT) encompasses a vast network of interconnected devices embedded with software, sensors, and network connectivity, enabling data collection and exchange. While IoT technology revolutionizes various industries, it also introduces significant security challenges. This research focuses on enhancing IoT security through the implementation of Zero Trust Architecture concepts, specifically targeting the Network and Device pillars of the Cybersecurity and Infrastructure Security Agency’s Zero Trust Maturity Model. By generating Codified Attack Surfaces (CAS) using custom Structured Threat Information eXpression bundles, this project aims to provide enhanced visibility into network communications, detect vulnerabilities in device firmware, and improve the overall security posture for IoT devices and networks. The methodology involves defining custom STIX schema and objects, collecting data from intra-IoT traffic, external network traffic, and firmware analysis, and automating the conversion and correlation of this data into STIX bundles. The automated generation of attack surfaces offers comprehensive insights into activity, vulnerabilities, and anomalies within an IoT environment, enabling proactive threat identification and mitigation.

24 - POWER TRANSMISSION AND DISTRIBUTION

Cybersecurity Center for Offshore Wind Energy (Final Project Report)

This project establishes a Cybersecurity Center for Offshore Wind Energy with the objective of designing and operating a cyber-physical testbed for wind energy farms (WEFs) that enables comprehensive cybersecurity research. The testbed incorporates a Supervisory Control and Data Acquisition (SCADA) system connected to turbine models via industrial-grade programmable logic controllers (PLCs) and remote terminal units (RTUs). It supports side-channel data acquisition, implementation and analysis of various cyberattack scenarios, and development of attack detection, mitigation, and best-practice guidance tailored to wind energy systems. During the project, the team expanded the number and fidelity of mathematical turbine models (MTMs), integrated these models with SCADA infrastructure, and deployed a scaled physical turbine and associated sensors. High-resolution operational and side-channel data streams were collected and used to refine machine-learning (ML)-based attack detection systems and to extend the WindCRAFT framework to multi-turbine threat scenarios. The project demonstrated a realistic, scalable environment for evaluating cyber threats, validated attack detection approaches using enriched datasets, and identified new multi-turbine and inter-turbine communication attack vectors. The resulting testbed, models, and security mechanisms provide a foundation for ongoing R&D and deployment of cyber-resilient offshore wind energy systems.

17 WIND ENERGY

Compliance of NNSS Activities with P322-4 Issues Management and NNSSWAC Requirements

The Institutional Quality and Performance Assurance Division's Quality Support Services Group conducted a surveillance of the compliance of Waste Management Program activities to Issues Management/Corrective Action requirements communicated in P322-4 and the Nevada National Security Site Waste Acceptance criteria (NNSSWAC). All corrective actions reviewed and records examined were found to be compliant with appropriate and relevant procedures. There were no Findings or Opportunities for Improvement noted.

12 MANAGEMENT OF RADIOACTIVE AND NON-RADIOACTIVE W