Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Security Information and Event Management”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

63 records · Page 4

Facilitating Data Collection of Maintenance Events to Populate the Hydrogen Component Reliability Database (HyCReD)

The Hydrogen Component Reliability Database (HyCReD) is a collaborative project between the National Renewable Energy Laboratory, the University of Maryland, and hydrogen stakeholders to improve safety and reliability for hydrogen facilities by implementing component reliability data taxonomies that support hydrogen infrastructure failure rate analysis. The project aims to quantify failure rates of hydrogen components through high-quality data collection and analysis on root causes and maintenance needed. HyCReD provides a common database for cataloging hydrogen component failures which exists for reliability research in many other mature industries [2]. The database fills a gap for the hydrogen community by providing a scientifically rigorous approach to quantitative risk assessment (QRA), prognostic health management (PHM), and reliability-centered maintenance (RCM) analysis. High level results will be aggregated and anonymized to protect company sensitive information; detailed results will be used to help address issues of hydrogen components. These advanced analytics will support accelerated deployment of hydrogen infrastructure by enabling better: design and safety of projects (safety codes and standards development), infrastructure reliability and cost (component failure rates, maintenance protocols), and component R&D needs (robust supply chain). A key to a successful HyCReD implementation is facilitating the ease of reporting and data quality in the database that can be used for analysis. Maintenance data was a previously identified gap in initial efforts to populate and validate the database taxonomies [3]. Collection of maintenance data will be instrumental in identifying failure modes and rates, identifying incipient component failures or reduced performance, cataloging best practices for maintenance routines and methods for prognostic health management, and quantifying the risk and effect of different failure modes. Several key priorities are identified for streamlined data collection to achieve quality and detailed failure data: Applicability, Ease of Use, Accessibility, and Information Security. The HyCReD team has now begun deployment of the database to several companies and groups that have signed non-disclosure agreements to facilitate the data collection of failures in industry hydrogen refueling station infrastructure. This paper will provide an update into the process of HyCReD deployment including the development of a coding guide for facility personnel to reference and ensure data quality and consistency from one station to another as well as implementation of contextually dependent data fields of system taxonomy and formatted entries to provide ease of use. The goal is to communicate the lessons learned from the roll-out to technicians and engineers in the field, and the addition of need for high level of security to protect all stakeholders.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Cybersecurity for Distance Relay Protection

This project is a DOE follow-up effort on the CREDC workshop held on September 13, 2018 in Cambridge, MA to discuss cybersecurity of distance relays, which considered the benefits, vulnerabilities and risk mitigations for the use of communication systems in power system protection. The objectives of this project are to define the taxonomy of relay protection and associated communications; define use cases describing approaches to reduce the cyber-attack surface on those protective relays; and evaluate the loss of operational functional capability from changes to communication coverage. Mitigating controls will also be evaluated to understand if there are other approaches to reduce attack surfaces while maintaining communications or partial communications. Distance relays are used to protect transmission lines of approximately 10 to 300 miles in length, by detecting short circuits (i.e., faults) on the lines and then tripping circuit breakers in the substation. Such protection systems are a subset of the power system and they incorporate sensing, logic and communication functions. Protection system exposure to cyberattack could be drastically limited by disconnecting relays from all vulnerable communication systems, but this may adversely impact overall power system performance in the absence of cyberattack. This project began with a use case analysis of protection systems with communications, as summarized in this report. It continued with modeling, testing and evaluation in a miniature power system (MPS), located in the Western Area Power Administration (WAPA) Electric Power Training Center (EPTC). The project also incorporated feedback from two industry meetings held in February and September 2019. The suggested next steps account for and complement the work already underway with DOE/CESER funding: 1. Study the performance of LCD and PC vs. PUTT, which is less reliant on communication system performance and GPS timing references. The PUTT scheme could prove to be more resilient to cyberattack or communications-related disruption. It could also be more tolerant of message re-routing with SDN/SDR communication systems. On the other hand, it will be more vulnerable to false tripping during dynamic events or to loss of the voltage signal. The optimum choice of scheme may depend on the specific power system and risk assessment. This study could provide a new template for evaluation based on business functions. 2. Research and develop new methods to detect and monitor distributed physical attacks, possibly using drones, video sensors, thermal sensors, machine learning and other advanced techniques. This will help mitigate the impact of cyberattack on the protection system, and will also help mitigate the impact of wild fires. 3. Implement a scalable PKI for use in electric utility protection systems. This will encourage widespread adoption of secure authentication methods that are already available, but not widely used at present. This will help secure engineering access to the relays. 4. Investigate the use of SDN in combination with SDR to achieve better cybersecurity and electromagnetic security of the network, incorporating path variability. This would help secure both engineering access and peer-to-peer GOOSE messaging. 5. Perform additional testing, with operator evaluation of “red button” scenarios, PUTT vs. LCD, relay mis-operations, and other cyberattacks in the EPTC. This is an important advantage of testing in the EPTC rather than by computer simulation or even hardware-in-the-loop simulation; the EPTC is already dedicated to managing the situational awareness, operator response times and other human impacts. One of the project objectives was to settle on a common nomenclature for this problem space. We have concluded that the OSI layer model, supplemented by ANSI device numbers and other IEEE standards, is already well-accepted by the industry. The IEEE PSRC knowledge base provides a great deal of public information

24 POWER TRANSMISSION AND DISTRIBUTION↗

Evaluation of the Radioactive Material Released in the Harborview Research and Training Building and Some Implications for Emergency Response

On 2 May 2019, during the 137 Cs source recovery operation, a source capsule in a research irradiator containing approximately 77.1 TBq was breached. Based on a geometric reconstruction analysis of the damage to the capsule, approximately 46.3 GBq (0.04%) was impacted by the chop saw (grinder) inside a mobile hot cell on the loading dock at the University of Washington Harborview Research and Training (HRT) Building. A very small fraction of the material impacted, less than 1%, was released from the mobile hot cell and then to the rest of the HRT Building. The objectives of this project were to assess the accidental release of 137 CsCl and its implications related to emergency response methods and the ramifications of 137 CsCl transport. The phenomenology of this event was also compared with past alkali halide dispersal events. The vast number of measurements and samples collected by the remediation contractors, the Department of Energy’s Nuclear Emergency Support Team, and the small number of retrospective samples collected by the authors informed the analysis. The techniques included (1) autoradiography and electron microscopy of samples collected from the HRT Building and the irradiator, (2) 3D visualization of deposition on surfaces and within the ventilation system, and (3) a study of the damage to the source capsule to evaluate the Cs particle size and particle composition due to the grinding accident. Subsequently, the cesium contaminant transport through the numerous pathways in the building was reconstructed to assess the deposition on surfaces as a function of particle size. Furthermore, the implications for emergency response are relevant to data quality and management. A Data Quality Objective guides data collection methods so that they have appropriate accuracy and precision for the intended application. Recommendations were made with respect to the sample collection protocols and archiving of samples.

46 - INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AN↗

2020 Exascale Computing Project Annual Meeting (Executive Summary Report)

The Exascale Computing Project (ECP) delivers specific applications, software products, and outcomes on DOE computing facilities. Integration across these elements for specific hardware technologies for exascale system instantiations is fundamental to ECP success. The outcome of the ECP is the delivery of a capable exascale computing ecosystem to provide breakthrough solutions addressing our most critical challenges in scientific discovery, energy assurance, economic competitiveness, and national security. This outcome is not a matter of ensuring more powerful computing systems. The ECP is designed to create more valuable and rapid insights from a wide variety of applications (“capable”), which requires a much higher level of inherent efficacy in all methods, software tools, and ECP-enabled computing technologies to be acquired by DOE laboratories (“ecosystem”). The ECP annual meeting provides a unique opportunity for the core technical expertise in the United States focused on achieving this next plateau of computational science and computing performance to engage in direct discussions on project execution. Face-to-face gatherings in technical communities like this are common and needed for the exchange of scientific ideas and technical performance. The ECP annual meeting stands apart from other technical conferences and meetings in the computing community as it is uniquely and solely focused on the execution of the ECP and the integration of technical activities leading to the creation of the exascale computing ecosystem for the future. The direct interaction of key critical technical staff, who are leaders in their respective fields, and the resulting give-and-take between software, applications, and hardware and the technical co-design therein, is unique and essential to the effective execution of the ECP. The first annual meeting was held in Knoxville, Tennessee, January 31 – February 2, 2017 and brought together, for the first time, a diverse collection of researchers from 16 DOE national laboratories as well as university computer and computational science researchers to discuss shared problems and joint solutions for the development of a capable exascale computing ecosystem. These interactions resulted in focused technical plans and an energized community centered on advances for ECP. The second annual meeting was held in Knoxville, Tennessee, February 5–9, 2018. It included 643 individual thought leaders and performers in application development, software research and deployment, and hardware research and integrators, all of whom are part of the multifaceted, billion dollar HPC community. This meeting provided a platform to discuss and disseminate numerous examples where researchers with common goals and synergistic solutions came together for the first time to deliver tangible results. Additionally, at the 2018 meeting, ECP researchers had the opportunity to digest all US HPC vendor R&D product roadmaps pointing to exascale – not only to learn how their research can play a role, but, more importantly, to influence those roadmaps to ensure successful delivery on DOE applications that will contribute to (if not solve) problems of national interest in national security, science, energy, and health, as well as growing security threats. The third annual meeting was held in Houston, Texas, January 14–17, 2019. With a 19% increase in the number of registrations (768 people), and the change in location, the third annual meeting was considered the most impactful of the three at the time. The new website provided a better platform for the dissemination of the content, the new venue as a meeting hotel instead of a conference center facilitated interactions and discussions after event hours, and the addition of an award-winning mobile event conference app (Whova) transformed dramatically the attendee experience at the event. This fourth annual meeting was held in Houston, Texas, February 3-7, 2020. This meeting had an increase in the number of attendees for a total of 824 people registered (782 attendees) and included numerous enhancements based on feedback and lessons learned from previous meetings, some of which are listed here: Improved quality of the sessions, their material and the whole program.; Had more industry participation and addition of external collaborators from overseas.; Published the full agenda earlier to better accommodate attendance and travel plans based on schedule.; Centralized all sessions in one venue.; Provided additional hotels and room blocks for the attendees.; Improved communication with the audience (links, material, directions, notifications, etc.) to go paperless.; Enhanced side meeting scheduling, management and user experience.; Made available additional space and tables for impromptu meetings and side discussions.; Improved IT and A/V solutions for speakers. In addition, our final survey captured the following points as opportunities for improvement in future meetings: consider a different meeting location that is more pedestrian friendly, reduce talks during working meals to allow more collaboration and informal time, adapt the agenda to acknowledge attendees from different timezones, consider recording some of the tutorials and/or sessions to share broadly with the HPC community, have a larger poster room, provide additional power strips, and improve the WiFi.

97 MATHEMATICS AND COMPUTING↗

Resilient U.S. Land Ports of Entry

The continued operation of Land Ports of Entry (LPOE), managed by the Customs and Border Protection (CBP) and General Services Administration% is vital to the U.S. economy and security. Border faculties are included in the Department of Homeland Security (DHS) Government Facilities Sector2, one of the 16 critical infrastructures "whose assets, systems, and networks, whether physical or virtual, are considered so vital to the United States that their incapacitation or destruction would have a debilitating effect on security, national economic security, national public health or safety, or any combination thereof.'" Specifically, disruptions to the flow of border crossing traffic, in the form of closures or increased border crossing wait times, impact the economy and security of all countries involved. This paper describes a process for analyzing and improving the resilience of U.S. Land Ports of Entry. For LPOE, the team believes that energy resilience is the primary objective due to the complete reliance on the e-manifest system and the increasing use of Multi-Energy Portals (MEPs). Emanifests are part of CPB's Automated Commercial Environment (ACE). They document several key pieces of information about cargo vehicles wishing to cross the border into the United States and are submitted before arriving at the port. Vehicles can be flagged for more invasive inspection based on the content of the e-manifest. MEPs are a non-intrusive inspection (NII) technology used to scan the contents of the cargo. Together MEPs and ACE serve an important role in aiding CBP with their mission to protect "the public from dangerous people and materials", and "enabling legitimate trade and travel.'" To analyze resilience of a port, the team would need to understand the port's current energy usage, which systems depend on energy and what backup systems exist, and any emergency operation plans that dictate how systems are operated in the event of a power outage. The team would also need to determine the design basis threats (DBTs) for the LPOE which could include natural disasters, manmade events, and accidents. The magnitudes of the DBTs are calculated and are then translated to expected impacts on the infrastructure and systems at the port. With this information gathered, existing LPOE models developed here at Sandia National Laboratories could be extended to support decisions about resilience. Current models are implemented in FlexSim, a 3rd party discrete event simulator. FlexSim provides 3-D visuals of physical layout that can reveal valuable insights, allows input to be variable (e.g. time it takes to interact with the CBP officer at primary inspection can vary) so that a whole range of possibilities can be captured in the results, and can be used to collect user-defined output metrics. Current LPOE models focus on cargo vehicle traffic, and process changes caused by the installation of new drive-through MEPs. Extending them to address resilience questions would require the addition of key pieces of information learned during the resilience analysis including critical systems, failure rates, and process changes for when failures occur. The primary output metric for current models is border crossing wait time. Additional metrics would also be added to the model to gain a more complete understanding of impacts related to resilience, for example, MEP scan rate. Once complete, the model could be used to analyze the effectiveness of mitigation strategies representing some future state.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Evaluating Process Effectiveness to Reduce Risk

It is well documented that government agencies do not have the same incentive as the private sector to focus on process effectiveness and continual improvement of those processes. It is also well documented whenever government agencies fail to deliver efficient, effective, consistent, and fair services to the citizens. In spite of the various "reinventing government" and "effectiveness initiatives" of the past decades, and in spite of the efforts on the part of many agencies to improve, government in general still lags behind industry in creating a culture of effective processes and systems. While the tragic events that unfolded recently in Flint, Michigan, teach us that running government "like a business" does not always take the needs of the citizenry into account, there are many lessons and techniques from the private sector that government agencies can use to improve. The incentive to improve, while mandated by various administrations1, needs to come from within the workforce, in order to effectively take root. The best, most effective incentive is to reduce, control or eliminate risk. Government agencies face some of the same risks as the private sector, while some are unique. While ISO 310002 has been around since 2009, risk has taken on increased visibility within the private sector with the advent of the emphasis on risk-based thinking in ISO 9001:20153. The relationship between risk-based thinking and effective processes is simple and direct. Those processes that are well thought out and standardized (i.e. Plan-Do-Check-Act), will have taken into account the applicable policy, statutory, regulatory, safety, quality and technical parameters, which may not occur to someone performing the process with minimal experience or training; and thus protect the employees, the public and the agency from statutory and regulatory violations; delay in providing services; non-delivery of services; harm to public or employee safety and health; cost overruns; breaches in security; loss of confidence in government; failure of publicly funded projects; damage to the environment; ethics violations, and the list goes on; with local, national and even international consequences. The Plan-Do-Check-Act process, also known as the "process approach" can be used at any time to establish and standardize a process, and it can also be used to check periodically for "process creep" (i.e., informal, unauthorized changes that have occurred over time), any necessary updates and improvements. While ISO 9001 compliance is not mandated for all government agencies, if interpreted correctly, it can be useful in establishing a framework and implementing effective management systems and processes.4 Another method that can be used to evaluate effectiveness is the scorecard definitions in Mallory's Process Management Standard5 as a basis for evaluating work on the process level on effective, and continuously improved and improving processes. With processes on the lower end of the scale, agencies are vulnerable to a great many risks, with employees and managers making up many of the rules as they go, leading to the above listed negative results. Without clear guidance for nominal operations, off-nominal situations can, and do, increase the likelihood of chaos. In an increasingly technical environment, with inter-agency communication and collaboration becoming the norm, agencies need to come to grips with the fact that processes can become rapidly outdated, and that the technical community should take on an increased role in the maturation of the agency's processes. Industry has long known that effective processes are also efficient, and process improvement methods such as Kaizen, Lean, Six Sigma, 5S, and mistake proofing lead to increased productivity, improved quality, and decreased cost. Again, government agencies have different concerns, but inefficiencies and mistakes can have dire and wide reaching consequences for the public that they serve. While no one goes to work planning to cause harm, it is up to agencies to establish upper level systems, which make establishment and compliance with processes possible. Again, Mallory provides us with a Systems Management Standard6, similar to the Process Management Standard, with a scale of 0-5 for systems effectiveness and maturity. Deming determined that "eighty-five percent of the reasons for failure are deficiencies in the systems and process rather than the employee. The role of management is to change the process rather than badgering individual employees to do better." 7 It is not just the working level employees who need effective processes, but the mid-and upper level managers as well. A disciplined management culture sets the tone for the employees, aids both routine and off-nominal decision-making, and incorporates risk -based thinking into the systems and processes as a matter of normal activity. Figure 1, illustrates the relationship between ineffective and effective processes and risk, through the use of the "stoplight" colors that are commonly used to show serious situations (red), situations which may be improving or deteriorating depending on trends (yellow), and situations that are under control and continuously improved (green).

Shepherd, Christena C.↗

Repository-Scale Performance Assessment Incorporating Postclosure Criticality

A key objective of the United States Department of Energy’s (DOE) Office of Nuclear Energy’s Spent Fuel and Waste Science and Technology Campaign is to better understand the technical basis, risks, and uncertainty associated with the safe and secure disposition of spent nuclear fuel (SNF) and high-level radioactive waste. Commercial nuclear power generation in the United States has resulted in thousands of metric tons of SNF, the disposal of which is the responsibility of the DOE (Nuclear Waste Policy Act of 1982, as amended). Any repository licensed to dispose of SNF must meet requirements regarding the long-term performance of that repository. For an evaluation of the long-term performance of the repository, one of the events that may need to be considered is the SNF achieving a critical configuration during the postclosure period. Of particular interest is the potential behavior of SNF in dual-purpose canisters (DPCs), which are currently licensed and being used to store and transport SNF but were not designed for permanent geologic disposal. A study has been initiated to examine the potential consequences, with respect to long-term repository performance, of criticality events that might occur during the postclosure period in a hypothetical repository containing DPCs. The first phase (a scoping phase) consisted of developing an approach to creating the modeling tools and techniques that may eventually be needed to either include or exclude criticality from a performance assessment (PA) as appropriate; this scoping phase is documented in Price et al. (2019a). In the second phase, that modeling approach was implemented and future work was identified, as documented in Price et al. (2019b). This report gives the results of a repository-scale PA examining the potential consequences of postclosure criticality, as well as the information, modeling tools, and techniques needed to incorporate the effects of postclosure criticality in the PA.

12 MANAGEMENT OF RADIOACTIVE AND NON-RADIOACTIVE W↗

STOCHASTIC OPTIMAL POWER FLOW FOR REAL-TIME MANAGEMENT OF DISTRIBUTED RENEWABLE GENERATION AND DEMAND RESPONSE (Final Report)

To meet the grand challenge of a sustainable energy future, there has been a surge of interest in renewable energy. Today, the uncertainty associated with renewable resources is handled by using operating reserves. The high penetration of renewable resources, however, introduces difficult-to-control dynamics and challenges for power system operation. Decision support tools are necessary at the bulk system operational level to recognize and efficiently utilize renewable resources and distributed demand response products in concert with traditional grid resources. It is envisaged that responsive load can potentially have very significant cost advantages over either spinning or non-spinning ramping reserve. Critical decisions are made during hour(s)-ahead and real-time power system operation regarding the commitment and dispatch of generators to ensure power delivery is both reliable and economic. These decisions are typically made by a security constrained optimal flow, which determines future generator commitments, dispatches, and ensures adequate reserves are available in the event of a contingency (unexpected outage) or if future system conditions deviate from forecasts. However, security has been always based on a pre-specified subset of contingency constraints whose enforcement does not guarantee security under all possible future possibilities while also giving little or no weight to the likelihood of each contingent event or the severity of its consequences. Existing tools, which are based exclusively on deterministic optimization models, do not yield optimal operational decisions to address these new challenges, in terms of both reliability and cost-effectiveness. This project has focused on developing a stochastic optimal power flow (SOPF) framework, which integrates renewable resource uncertainty, load uncertainty, distributed storage (DS), demand response (DR) products, in a holistic manner to address the uncertainty associated with ever-increasing renewable resources, along with the inclusion of distributed demand response products in future power systems. A proof-of-concept problem was created using the Pennsylvania-Jersey-Maryland (PJM) power system network. Synthetic wind generation was added to the system to simulate 50% wind penetration. A 1-hour test of SOPF operation indicated more than 6% operational cost savings. The project continued by adding the Midwestern Independent System Operator (MISO) as a partner, with focus shifting from SOPF to Stochastic Look-Ahead Unit Commitment (SLAC). Unlike PJM, MISO is faced with significant renewable energy resources within its footprint and is challenged with substantial uncertainty in its operations. The SLAC distinguishes itself from existing tools that operators use. At best, today’s tools solve two to three cases independently, where one or two system parameters, such as forecasted load level (e.g., a low, base, and high forecast), are varied and the resulting scenarios are analyzed independently. The stochastic-based optimization of SLAC leverages statistical information from an ensemble of potential operational scenarios and their respective likelihood. The SLAC output can be translated into valuable information to the operator such as suggested commitments, optimal scheduling and dispatch of resources, reserve requirements at both locational and zonal resolutions, ramping availability and requirements, availability of demand response including operational guidance concerning the near-term and real-time coordination between distributed energy resources, and utilization of distributed storage resources. The developed SOPF/SLAC tool, a stand-alone tool compatible with existing EMSs, will provide system operators with unprecedented visibility, flexibility and predictability to these resources and operational guidance concerning the real-time coordination between DERs and DR/DS products. The game changing and practical impact of this disruptive technology will be dramatic and will usher in a new era in the electric power industry, wherein green energy concepts are fully embraced, and electric power costs are lowered throughout the nation.

42 ENGINEERING↗

Innovating the next generation of commercial smart building software

Nearly 30% of commercial building energy use is wasted due to equipment faults and HVAC controls problems. The result is increased emissions, compromised comfort and productivity, and less reliable coordination of building power needs with a clean grid. The energy impact alone represents $17 billion in potential savings. Today’s smart building software provides a robust solution to address these operational deficiencies. Energy management and information systems (EMIS) are saving up to 9% on average, with two-year paybacks. They are being incorporated into energy management processes, commissioning services, and utility programs. As effective as they are, two barriers prevent even deeper benefits; limited personnel to fix problems once they are identified, and the expense and time to manually implement changes in control systems. In partnership with the research community, the EMIS industry is developing new capabilities to overcome these barriers. Moving beyond siloed products for either fault detection and diagnostics, or optimal control, these new capabilities empower users to not only automatically identify faults, but also to push corrective action, and control improvements to their buildings. In this paper, several areas for enhancements are documented: ‘one-time’ correction of faults such as setpoints, schedules, and economizer lockouts; short-term active testing for automated proportional integral derivative (PID) loop tuning and functional testing; and continuous supervisory control for demand flexibility and year-round efficiency. Results are presented from a pair of partner implementations out of a dozen providers integrating these enhancements into their products, including field tests from across the country, and insights into operator acceptance and integration into operations and maintenance practices.

Casillas, Armando↗