Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Secure by Design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Incorporating the Role(s) of Human Actors in Complex System Design for Safety and Security

Traditional systems engineering demonstrates the importance of customer needs in scoping and defining design requirements; yet, in practice, other human stakeholders are often absent from early lifecycle phases. Human factors are often omitted in practice when evaluating and down-selecting design options due to constraints such as time, money, access to user populations, or difficulty in proving system robustness through the inclusion of human behaviors. Advances in systems engineering increasingly include non-technical influences into the design, deployment, operations, and maintenance of interacting components to achieve common performance objectives. Furthermore, such advances highlight the need to better account for the various roles of human actors to achieve desired performance outcomes in complex systems. Many of these efforts seek to infuse lessons and concepts from human factors (enhanced decision-making through Crew Resource Management), systems safety (Rasmussen's “drift toward danger”) and organization science (Giddens' recurrent human acts leading to emergent behaviors) into systems engineering to better understand how socio-technical interactions impact emergent system performance. Safety and security are examples of complex system performance outcomes that are directly impacted by varying roles of human actors. Using security performance of high consequence facilities as a representative use case, this article will outline the System Context Lenses to understand how to include various roles of human actors into systems engineering design. Several exemplar applications of this organizing lenses will be summarized and used to highlight more generalized insights for the broader systems engineering community.

42 ENGINEERING↗

DESIGN & DEVELOPMENT OF A SECURE SELF-LEVELING WIRELESS RECHARGING PLATFORM FOR AN AERIAL DRONE ON AN UNMANNED SURFACE VESSEL

The Design and Development of an automated recharging station for an aerial drone, onboard a small, unmanned surface vessel, is described. Drones require a landing surface that is level within five degrees of the surrounding terrain for repeated reliable landing and takeoff. System constraints and at-sea application necessitate a compact, lightweight, and secure solution. A passive self-leveling platform and an accompanying automated parallel-pusher drone restraint mechanism have been designed and fabricated to aid in achieving a level landing surface and holding the drone in place while it charges. The self-leveling mechanism has been analyzed and subjected to initial laboratory tests. The testing of the drone restraint mechanism to verify its weight capacity and closing time, and the integration of the platform with a custom conductive contact wireless charging pad are identified as future work. The resulting cohesive unit will be tested for performance optimization and implementation onboard the unmanned surface vehicle.

McKinney, Adriana↗

Multi-Fidelity Bayesian Optimization with Gaussian Processes for Double Shell Inertial Confinement Fusion Target Design

Reliable, secure access to energy is a major focus for national security efforts. One potential route to such energy is through fusion reactions in inertial confinement fusion (ICF) experiments. Such experiments are carried out at facilities such as the National Ignition Facility (NIF) in Livermore, California, where high powered lasers are used to compress a DT fuel-containing target to the necessary high temperature, high pressure conditions. These experiments are limited in number, which creates a heavy dependence on high fidelity predictive physics simulations and analysis performed “pre shot,” or before the experiment occurs. Many of these simulations in higher dimensions (2D and 3D) are computationally expensive, so finding optimal simulation-based designs presents its own challenges. In this work, we present our multi-fidelity Bayesian optimization with Gaussian processes (GPs) for ICF double shell targets, where a 1D surrogate model is used to help find a 2D surrogate model, enabling us to find optimal targets in the higher fidelity (2D), while saving computational cost.

70 PLASMA PHYSICS AND FUSION TECHNOLOGY↗

On the Application of Cyber-Informed Engineering (CIE)

The 2023 National Cybersecurity Strategy has recommended a transition to secure-by-design methodologies in critical infrastructure. This paper presents the adoption of the National Cyber-Informed Engineering (CIE) Strategy as initiated by the U.S. DOE’s CESER office, advocating for the integration of cybersecurity at the earliest stages of system design. The strategy targets design engineers responsible for energy infrastructure to embed CIE principles within the engineering lifecycle, thus enhancing cyber resilience. This paper discusses the expansion of secure-by-design concepts to cyber-physical systems, moving beyond traditional IT security to include engineering considerations that can mitigate cyber risks through design choices. The paper introduces Digital Risk Management, balancing traditional cybersecurity with CIE to reduce both likelihood and impact of cyber threats. A set of CIE starter questions derived from 12 core principles is detailed, aiding engineers to consider cybersecurity in their designs and highlights the importance of CIE in anticipating and reducing the impacts of cyber attacks, suggesting that such integration is essential for national security and infrastructure resilience.

42 ENGINEERING↗

Digital Engineering and Cybersecurity Decision Analysis in Early Phases of SMR-Driven IES Projects

Considerable efforts are underway to ensure cybersecurity is integrated into the systems engineering lifecycle. Cyber-informed engineering and security-by-design frameworks are intended to identify and engineer out cybersecurity risks throughout the lifecycle. While these approaches are valuable for promoting the need to include cybersecurity considerations in early design phases to create more secure systems, they may not consider the entirety of digital risks. Digital risks in a digital instrumentation and control system include adversarial and unintentional risks from internal and external factors, such as human performance errors, design flaws, environmental conditions, and equipment degradation or failure. This report provides a detailed discussion on digital risk prior to describing the background and concept of operations for a small modular reactor-driven integrated energy system connected to industrial applications. The challenges of competing objectives and competing stakeholder requirements are discussed and the impacts on digital engineering, security considerations, and interdependencies are evaluated for mission-level, facility-level, and system-level decisions.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Motivation and Design of the OCPP Security Service

Pacific Northwest National Laboratory is conducting in-depth research aimed at exploring how zero trust security principles can be effectively applied to electric vehicle charging infrastructure. This investigation seeks to enhance the resilience and reliability of these systems against cyber threats, ensuring secure and uninterrupted access to charging services for electric vehicle users and electric supply. Zero trust is a security concept centered on the belief that system operators should not automatically trust users or systems based on their location, whether inside or outside the organization, but instead must verify everything trying to connect to their systems before granting access. A key aspect of the project is to demonstrate and validate zero trust approaches targeted to electric vehicle (EV) charging infrastructure. It has been observed that both open-source and commercial solutions often overlook the specific protocols employed in managing EV charging stations and proceeded with a general, protocol-agnostic approach. While these strategies effectively block non-authorized routes to the charging infrastructure, they do not tackle the situations where attackers may exploit legitimate access channels, such as the inattentive operator model posited by the Idaho National Laboratory. To address this gap, this paper proposes and discusses a new security service targeted to the Open Charge Point Protocol (OCPP), which is the de facto protocol for the management of charging stations and serves a critical role in the broader adoption of electric vehicles. The design and architecture of the proposed OCPP security service are discussed in detail, outlining how it aims to safeguard charging station management system (CSMS) functions. The service is particularly important in scenarios where the charging station operator (CSO), responsible for the maintenance and operation of charging stations, and the charging network provider (CNP), which manages the charging network's accessibility and billing, are separate entities. This distinction is crucial because CSOs and CNPs often have different priorities, objectives, and operational responsibilities, which may not always align perfectly. For instance, a CSO might prioritize uptime and customer satisfaction, while a CNP might focus on maximizing revenue and network utilization. Such misalignment can create security vulnerabilities, as each entity might implement different policies and standards, potentially leaving gaps in the overall security posture.

33 ADVANCED PROPULSION SYSTEMS↗

Integration of Safety, Security, and Safeguards During Design and Operations: A Technical Assessment and Regulatory Considerations for Advanced Reactor and Advanced Fuel Fabrication Facilities

This report presents the current state of knowledge, technology, methodologies, and tools that could be implemented to realize the robust integration of safety, security, and safeguards (3S) for advanced nuclear reactors (ARs) and advanced nuclear fuel cycle facilities. This report was motivated by the global development of ARs which are expected to play a key role in meeting domestic energy and climate objectives. Domestically, with many ARs in the early design phase, the integration of 3S provides an opportunity to achieve risk reduction while using less resources than traditional light water reactors by leveraging interdependencies and synergies between each domain. In addition, domestic policy considerations encourage the convergence of each 3S domain through facility design and operations. Therefore, there is a need to better understand the interdependencies and integration between 3S across ARs and advanced reactor fuel cycle facilities’ lifecycles including design, construction, and operational phases.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Rapid Design and Engineering of Smart and Secure Microbiological Systems (Final Report)

The design and application of successfully engineered biosystems requires an understanding of how engineered microbes will interact with other organisms – either as one-on-one competitors or in the context of microbial consortia. Engineering microorganisms from first principles for non-laboratory, environmental applications is inherently challenging because: (1) engineered systems tend to quickly revert back to their wild-type behaviors; and (2) these systems typically pay a price in reduced fitness, making them uncompetitive against invasive contaminating species (i.e., metabolic burden). For this project, we used a synthetic biology-based strategy to investigate the organization, control, stabilization, and destabilization of natural and engineered microbes. This approach enabled development of (1) single-strain systems capable of detecting and responding to target organisms in the environment; (2) a pipeline for refining and engineering biological constructs in new, non-model host organisms; and (3) improved systems for rapidly designing, engineering, and assaying new biological modules. This coupled approach to safeguard system design is predictable and portable across bacterial species and is focused on microbes that are part of the beneficial plant microbiome. A long-term goal beyond the proposed research is to enable the rational engineering of microbial communities based on first principles of biological design that mimic the smart performance of microorganisms observed in natural systems.

59 BASIC BIOLOGICAL SCIENCES↗

Acoustic Measurements of Solvent Extraction Processes in Support of Safeguards

The proposed poster focuses on using acoustic monitoring to advance detection techniques for reprocessing equipment in support of nuclear safeguards. The usage of free air acoustic monitoring has been previously demonstrated at Idaho National Laboratory (INL) at facilities such as the Advanced Test Reactor and the National Security Test Range. However, this work focuses on a deployment environment dedicated to monitoring separation processes, using solvent extraction equipment such as centrifugal contactors. This environment offers an opportunity for signal discovery and in characterizing acoustic signatures of the equipment in operation. This data can support the development of safeguards by design and security by design measures for aqueous reprocessing facilities. Furthermore, this type of monitoring can aid in early detection and identification of removed materials indicating diversion, which is essential for initiating material recovery and actor identification. The results of this work include data from nine low-frequency acoustic sensors used to investigate potential acoustic characteristics of centrifugal contactors used in multi-stage processes. The results also discuss the correlation between the signatures and the operation of the contactor banks.

98 - NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL↗

Cyber Resilience and Social Equity: Twin Pillars of a Sustainable Energy Future

This paper examines the intersection of security and accessibility within energy systems amidst the rise of grid modernization and digitization, especially considering the regulatory changes and the imperatives of inclusive energy strategies. It addresses the dual need for secure, resilient infrastructure and a commitment to mitigate energy poverty while maintaining equitable access to energy. Amid escalating cybersecurity and physical threats, the paper advocates for sustainable energy delivery systems that ensure robust defenses without compromising the goals of reducing energy poverty and ensuring energy security. This paper identifies the pressing need for Cyber-Informed Engineering (CIE) and Secure-by-Design (SbD) principles, highlighting how these strategies can protect critical infrastructure and democratize access to secure energy, particularly for disadvantaged communities. The analysis underscores the challenges presented by the expansion of attack surfaces, interoperability requirements, and grid-edge analytics, offering innovative solutions that leverage advanced technologies and data-driven insights. Furthermore, this paper addresses the workforce development gap, emphasizing the necessity for public-private partnerships and vendor engagement in creating a skilled cybersecurity workforce. This paper has a dual focus on both the technological aspect of cybersecurity and the social dimension of equity within the context of sustainable energy development. It suggests a comprehensive examination of how these two critical elements interact and support the overarching goal of a sustainable energy future.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

IP Protection in TinyML

Tiny machine learning (TinyML) is an essential component of emerging smart microcontrollers (MCUs). How- ever, the protection of the intellectual property (IP) of the model is an increasing concern due to the lack of desktop/server-grade resources on these power-constrained devices. In this paper, we propose STML, a system and algorithm co-design to Secure IP of TinyML on MCUs with ARM TrustZone. Our design jointly optimizes memory utilization and latency while ensuring the security and accuracy of emerging models. We implemented a prototype and benchmarked with 7 models, demonstrating STML reduces 40% of model protection runtime overhead on average.

42 ENGINEERING↗

Incremental Threshold Scheme Enabled IoT Group Key Management

Cyber landscape evolves rapidly. Internet of Things (IoT) and Edge Computing (EC) have rapidly become an integral part of the modern computing infrastructure. It is expected that there will be more than 50 billion active and connected IoT devices by 2025 [1]. Pervasive IoT/EC creates unprecedented opportunities bridging the gap between previously segregated cyber and physical spaces. However, this progress also brings along new security challenges. IoT devices typically have limited computation, communication, and storage resources. This leads to security architecture designs such as using symmetric keys for group communication. While secure and efficient in stable network settings, symmetric key solutions are ill-adapted for IoT's highly dynamic device mobility behavior and frequent group membership turnover. Whenever IoT members leave a group, the known symmetric keys cannot be made forgotten, posing a serious vulnerability. This leads to frequent re-groupings that require expensive re-authentication, key regeneration, and key redistribution in order to maintain IoT/EC security. We present a novel symmetric key management framework that integrate an Incremental Threshold Scheme (ITS) cryptographical function into communication protocol's key rotation mechanism to allow for secure and efficient symmetric key communication group member node revocation. This ITS-enabled key management framework alleviates the need of frequent and expensive re-grouping and re-keying needed by today's large and dynamic IoT/EC operations. We further applied this ITS-enabled key management framework to a distributed IoT/EC-integrated publish and subscribe framework for applicability validation.

Li, Mingyan↗

Advanced Reactor Safeguards: 2022 Program Roadmap

The Advanced Reactor Safeguards (ARS) program was established in 2020 as part of appropriations for the Advanced Reactor Demonstration Program (ARDP) through the Office of Nuclear Energy in the Department of Energy. The goal of this program is to help address near term challenges that advanced nuclear reactor vendors face in meeting domestic Material Control and Accountancy (MC&A) and Physical Protection System (PPS) requirements for U.S. construction. The technical work in the program is meant to (1) support nuclear reactor vendors with advanced MC&A and PPS designs for next generation reactors, (2) provide technical bases for the regulator, and (3) promote the integration of Safeguards and Security by Design early in the design process. Existing domestic regulations for safeguards and security, as outlined in the Code of Federal Regulations, were written for large light water reactors, and rule-making efforts are underway to develop regulations more suited to different reactor designs. The ARS program seeks to remove roadblocks in the deployment of new and advanced reactors by solving regulatory challenges, reducing safeguards and security costs, and utilizing the latest technologies and approaches for robust plant monitoring and protection. This roadmap discusses the goals of the ARS program, current research, and program plan for the next five years.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Test and Evaluation of Radiofrequency Tamper Indicating Devices for Remote Monitoring of Advanced/Small Modular Reactors

Advanced and small modular reactors (A/SMRs), due to their versatile nature, are likely to be used in remote locations to provide electrical power or other services in regions that are difficult to access or have limited transportation infrastructure. This will result in limited on-site staff, therefore driving A/SMR vendors to consider remote monitoring as a solution to support nuclear security. Maintaining Continuity of Knowledge (CoK) of nuclear material quantities and locations is vital to nuclear security, and remote monitoring of active tamper indicating devices (TIDs) has been well established as a component of International Atomic Energy Agency (IAEA) Safeguards since the early 2000s. Active TIDs, such as radiofrequency TIDs (RFTIDs), immediately alarm upon unauthorized access attempts, promoting timely detection. In contrast, passive TIDs require a surveillance regime and offer delayed detection. Active TIDs deter insiders and enable prompt detection of malicious acts. They can be used on nuclear material containers and controlled entry points like vaults and toolboxes. Therefore, the implementation of RFTIDs into security programs bolsters overall nuclear material control, and provides a visible deterrent, with primary efficacy in mitigating the insider threat and potentially allowing for Security by Design considerations. They are a strong candidate technology for maintaining nuclear security of A/SMRs but need to be evaluated for feasibility and implementation into the wider physical protection system.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Precoder Design for Physical-Layer Security and Authentication in Massive MIMO UAV Communications

Supporting reliable and seamless wireless connectivity for unmanned aerial vehicles (UAVs) has recently become a critical requirement to enable various different use cases of UAVs. Due to their widespread deployment footprint, cellular networks can support beyond visual line of sight (BVLOS) communications for UAVs. In this paper, we consider cellular connected UAVs (C-UAVs) that are served by massive multiple input-multiple-output (MIMO) links to extend coverage range, while also improving physical layer security and authentication. Here, we consider Rician channel and propose a novel linear precoder design for transmitting data and artificial noise (AN). We derive the closed-form expression of the ergodic secrecy rate of CUAVs for both conventional and proposed precoder designs. In addition, we obtain the optimal power splitting factor that divides the power between data and AN by asymptotic analysis. Then, we apply the proposed precoder design in the fingerprint embedding authentication framework, where the goal is to minimize the probability of detection of the authentication tag at an eavesdropper. In simulation results, we show the superiority of the proposed precoder in both secrecy rate and the authentication probability considering moderate and large number of antenna massive MIMO scenarios.

99 GENERAL AND MISCELLANEOUS↗

Renewable Energy and Storage Cybersecurity Research (RESCue) Pilot Final Report

The Renewable Energy and Storage Cybersecurity Research (RESCue) project is a collaborative effort aimed at securing the rapidly growing deployment of distributed energy resources (DERs) and transmission-connected hybrid renewable energy systems against escalating cyber threats. This project brings together major original equipment manufacturers (OEMs) of wind, solar, and energy storage, along with major asset owners and DOE National Laboratories, to collectively identify cyber threats, assess risks, and develop robust cybersecurity strategies and solutions. This publication the final report for the first year of the project.

24 POWER TRANSMISSION AND DISTRIBUTION↗