Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “information security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

CIEPAT for Photovoltaic System Resilience

The Cyber-Informed Engineering Photovoltaic Analysis Tool (CIEPAT) was developed in collaboration with the U.S. Department of Energy's Office of Cybersecurity, Energy Security, and Emergency Response (CESER). This tool is an energy source subcomponent integrated into the CIEMAT ecosystem and is developed to enhance the security and resilience of Photovoltaic installations by incorporating Cyber-Informed Engineering (CIE) principles into the deployment of PV systems.

14 SOLAR ENERGY↗

Federal Facility Agreement and Consent Order: Nevada National Security Site Use Restriction Management Plan with ROTC 1

This Use Restriction Management Plan (URMP) provides the information needed to create, modify, and manage use restrictions (URs) for sites on the Nevada National Security Site (NNSS), and sites accessed through the NNSS main gate, that were closed using the corrective action alternative (CAA) of closure in place under the Federal Facility Agreement and Consent Order (FFACO) (1996, as amended). (Note: This pertains to those FFACO sites not managed by the U.S. Department of Energy [DOE], Legacy Management.) The closure in place alternative is used for sites closed with residual contamination at levels requiring corrective action as determined using the FFACO process. The URs contain and control all requirements for long-term monitoring. This URMP also serves as the single repository of the URs implemented under the FFACO that identify use restricted areas and contain the current requirements for inspections, maintenance, and monitoring of the UR. The requirements in these URs replace all requirements listed in previous documentation. This consolidates post-closure monitoring requirements into a single source that ensures completeness and consistency of UR requirements and information. Standardized UR forms were developed to clearly document post-closure requirements that are consistent with current protocols and to ensure consistent information is contained in the URs. Standard notification, summary, and site controls statements were developed for all URs with provisions to insert site-specific options in the text. Current protocols for Industrial Sites and Soils URs are defined in this document and in the Soils Risk-Based Corrective Action (RBCA) Evaluation Process (DOE/EMNV, 2018). The standardized UR forms that have been approved to date are listed in Appendix A. Additional UR forms will be added once the review and approval process has been completed.

54 ENVIRONMENTAL SCIENCES↗

CIEPAT (Cyber-Informed Engineering Photovoltaic Analysis Tool) [SWR-25-171]

The Cyber-Informed Engineering Photovoltaic Analysis Tool (CIEPAT) was developed in collaboration with the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER). This tool is a energy source subcomponent integrated into the CIEMAT ecosystem and is developed to enhance the security and resilience of Photovoltaic installations by incorporating Cyber-Informed Engineering (CIE) principles into the deployment of PV systems.

Etigowni, Sriharsha [National Laboratory of the Ro↗

Efficient Anomaly Detection Driven By Different Machine Learning Architectures And Models

The rapid growth and ubiquitous adoption of the internet and cyber-physical systems (CPS) have fundamentally transformed modern communication, work, and human-system interactions. While networks now form the backbone of critical digital ecosystems, enabling seamless data transmission across diverse, interconnected systems, this increased connectivity also expands the attack surface, making real-time detection of network intrusions and anomalies a pressing challenge. Detecting unusual activities within network infrastructure requires advanced data traffic analysis to differentiate between legitimate and malicious interactions. Traditional approaches to network anomaly detectionâ??such as rule-based and signature-based systemsâ??often depend on predefined patterns to identify known anomalies, limiting their effectiveness against emerging, stealthy, or previously unseen threats. These conventional methods suffer from high false alarm rates and fail to adapt to the ever-evolving nature of network traffic, particularly in large-scale, decentralized environments where data volume, velocity, and variety are constantly increasing. This dissertation presents artificial intelligence (AI)-driven approaches to anomaly detection that leverage graphics processing unit (GPU)-enabled high-performance computing (HPC) platforms for processing massive network traffic data and monitoring the components of cyber-physical systems (CPS) for potentially hazardous conditions. The research advances several key contributions: (1) Designing efficient machine learning techniques for CPS condition monitoring and anomaly detection; (2) enabling federated learning (FL) frameworks that enable distributed detection while preserving data privacy and system resilience; (3) exploring graph-based methodologies combining graph neural networks (GNN) and graph machine learning (ML) approaches for the Internet of Things (IoT) and automotive network security, and (4) performing distributed edge computing optimizations that integrate FL with scalable technologies for reduced communication overhead. Through extensive experiments, these methodologies demonstrate that complex anomaly detection and condition monitoring tasks can be achieved while balancing computational efficiency and detection accuracy through fine-grained network information processing. The frameworks developed in this research establish a robust foundation for network anomaly detection, providing scalable, adaptive, and privacy-preserving solutions for safeguarding CPS and IoT networks in an increasingly interconnected digital landscape. The practical implications of these research findings are significant, as they can inform the development of next-generation network security systems and contribute to the protection of critical infrastructure against sophisticated cyber attacks.

Marfo, William↗

CIECAT (Cyber-Informed Engineering Commercial Buildings Analysis Tool) [SWR-25-172]

The Cyber-Informed Engineering Commercial Buildings Analysis Tool (CIECAT) was developed in collaboration with the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER). This tool is a energy source subcomponent integrated into the CIEMAT ecosystem and is developed to enhance the security and resilience of Commercial Buildings by incorporating Cyber-Informed Engineering (CIE) principles into the Commercial Buildings.

Etigowni, Sriharsha [National Laboratory of the Ro↗

CIE Curriculum Guide (V.2.0)

The Cyber-Informed Engineering (CIE) Curriculum Guide offers a comprehensive framework, guidance, and resources for integrating CIE into university-level engineering programs and related educational activities. The primary goal is to help educators adopt CIE principles into their teaching to produce future engineers and technicians who understand digital risks in modern engineered systems, thereby addressing the nation’s infrastructure resilience needs. This guide outlines practical integration examples, links to resources to accelerate CIE adoption, and shares insights from partner academic institutions on various implementation strategies. CIE is a framework for embedding engineered controls that mitigate the impact of cyber-attacks in any cyber-physical system used in critical energy infrastructure and other sectors. Developed by the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER), the National Cyber-Informed Engineering Strategy emphasizes embedding CIE into formal education, training, and credentialing. This guide supports this strategic objective by providing examples of integrating CIE concepts into engineering curricula, from class activities to new courses and certificate programs. The importance of educating cyber-informed engineers is underscored by the evolving cybersecurity threats facing engineered systems. As industrial control systems (ICS) increasingly incorporate digital technologies, the responsibility for security extends to both cyber professionals and engineers. CIE addresses critical gaps in designing and protecting physical systems with digital components against cyber risks, ensuring engineers consider digital risk throughout the engineering design lifecycle. Currently, engineering education does not routinely include cyber-informed principles, highlighting a gap in addressing modern engineering system risks. This guide advocates for updating engineering curricula to include digital risk management as a fundamental element. By doing so, future engineers will be equipped to design resilient systems that mitigate digital risks from the outset. Through this guide, engineering faculty can integrate CIE into their curricula, bridging the gap between digital risk and engineering. This approach prepares a cyber-informed workforce capable of safeguarding the cyber-physical systems crucial to national security and public welfare. By embedding CIE into education and training, institutions can produce engineers and technicians who can effectively mitigate cyber impacts throughout the engineering design lifecycle, resulting in more secure critical infrastructures.

42 - ENGINEERING↗

A Deep Learning-Aided Workflow for Decoding the Stress Regime of Southern Nevada

The Rock Valley fault zone in southern Nevada has a notable history of seismic activity and is the site of a future direct comparison experiment of explosion and earthquake sources. This study aims to gain insight into regional tectonic processes by leveraging recent advances in seismic monitoring capabilities to elucidate the local stress regime. A crucial step in this investigation is the accurate determination of P-wave first-motion polarities, which play a vital role in resolving earthquake focal mechanisms of small earthquakes. Here, we deploy a deep learning-based method for automatic determination of first-motion polarities to vastly expand the polarity dataset beyond what has been reviewed by human analysts. By the integrating P-wave polarities with new measurements of S/P amplitude ratios, we obtain robust focal mechanism estimates for 1306 earthquakes with a local magnitude of 1 and above occurring between 2010 and 2023 in southern Nevada. We then use the focal mechanism catalog to examine the regional stress orientation, confirming an overall trans-tensional stress regime with smaller scale complexities illuminated by individual earthquake sequences. These findings demonstrate how detailed analyses of small earthquakes can provide fundamental information for understanding earthquake processes in the region and inform future experiments at the Nevada National Security Site.

58 GEOSCIENCES↗

Study on Application of Distributed Network of Sensors with List Mode for NMAC Literature Review

Nuclear material accounting and control (NMAC) for nuclear security detects, deters, and resolves questions related to unauthorized removal (i.e. theft) or misuse of nuclear material. NMAC also serves as a key insider threat mitigation measure and aids in recovery of nuclear material that is missing. Effective nuclear security depends on NMAC for timely and accurate information about nuclear material types, quantities, and locations. Bulk nuclear material processing facilities, however, present unique challenges for effective NMAC due to the presence of large quantities of material in-process and the accumulation of residual material holdup within process equipment. These holdup accumulations can obscure accurate physical inventory taking and complicate efforts to resolve NMAC irregularities at the facility level. Bulk material monitoring systems often rely on material balance calculations and indirect measurement techniques, which may mask protracted theft of smaller amounts of nuclear material. These monitoring limitations have generated increased interest in continuous monitoring technologies, including distributed non-destructive assay (NDA) sensor networks capable of providing real-time or near-real-time measurement of material movement and accumulation within bulk processing environments. Recent advancements in distributed networks of NDA radiation detectors and sensing technologies provide an opportunity to address these limitations. Although such distributed sensor networks have been implemented in select facilities for IAEA Safeguards applications, their potential for supporting NMAC functions specifically tailored to nuclear security objectives remains largely unexplored. Furthermore, emerging list-mode data acquisition technologies have reached high technology readiness levels, enabling time-correlated detection of nuclear events across multiple temporal scales. These capabilities provide enhanced opportunities for accurate holdup measurement, continuous process monitoring, and improved detection of material theft or misuse over time. The increasing global expansion of civil nuclear power and development of related bulk material processing facilities, including those supporting high-assay low-enriched uranium (HALEU) and other advanced reactor fuel fabrication, further increases the need for advanced measurement and monitoring strategies for NMAC.

73 NUCLEAR PHYSICS AND RADIATION PHYSICS↗

Elucidating molecular scale interactions underlying the freezing behavior of salt solutions in silica nanopores

Elucidating the influence of nanoscale confinement on the freezing behavior of salt solutions is of fundamental interest to environmental security and materials science and engineering. Specific structural information such as the coordination environment of ions in confined aqueous medium, effects on the extended hexagonal network of water molecules and their mutual non-bonding interactions in confinement are sparse in the literature along with the change in the dynamical characteristics of water in the presence of ions. To address these knowledge gaps, the current study is focused on investigating the influence of reduced dimensionality arising from nanoscale confinement on the structural evolution of salt solutions on freezing and the associated fluid–surface interactions. In this regard, operando wide-angle X-ray scattering (WAXS) measurements and classical molecular dynamics (MD) simulations are conducted with water and 0.5 M CaCl 2 , MgCl 2 and KCl solutions confined in 4 nm sized SBA-15 silica pores upon cooling from 300 K to 200 K. The freezing point of the salt solutions is depressed to 235 K which is about 10 K lower than that of confined water. The translational dynamics of confined salt solutions indicates shifts in the fragile-to-strong dynamical crossover to a lower temperature compared to pure water. The strong electrostatic attraction between the cations and the surrounding water molecules contributes to the freezing point depression in confined salt solutions. These insights unlock the molecular-scale basis and mechanisms underlying the freezing behavior of confined salt solutions.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

Asi Nuclear Energy Sensors Data Portal Chatbot And Data Structuring Tool

The Idaho National Laboratory (INL) is advancing the development of an AI-powered chatbot and data structuring tool specifically designed to accelerate data mining processes for sensor-related information and seamlessly integrate the results into the ASI Sensors Data Portal (https://nes.energy.gov/). By doing so, the software aims to enhance the accessibility, usability, and organization of sensor data for nuclear energy applications. The software initial phase focuses on retrieving comprehensive datasets, prioritizing the past five years of publicly available information from the Office of Scientific and Technical Information (OSTI). These datasets will be meticulously processed to ensure compatibility, employing cleaning and preprocessing steps to eliminate irrelevant, incomplete, or corrupted information, thus establishing a robust foundation for subsequent AI use. The data will serve as the backbone for training an AI model and chatbot, which will act as an interactive tool enabling users to ask complex, context-specific questions and receive accurate, validated answers derived from constrained literature. In parallel, the project incorporates a data structuring process supported by AI to organize sensor information from multiple sources into a standardized format. This structured data will include detailed sensor specifications, such as measurement range, applications, accuracy, and operating conditions, generated and documented with AI. These specifications will be systematically integrated into the sensor portal. To maintain the highest levels of accuracy and relevance, all AI-generated outputs will be reviewed and validated by subject matter experts (SMEs), with additional fields or parameters added as needed. Future stages of the project aim to expand the dataset beyond OSTI to include other sources and potentially incorporate unclassified controlled information (UCI) with restricted access protocols to address security and confidentiality requirements.

Mapes, NormanJ. [Idaho National Laboratory (INL), ↗

Draft Prototype Microreactor Transportation Safety Program

Microreactors are compact reactors capable of producing less than 50 megawatts of electrical energy. Typically, these reactors are factory-fabricated and designed to be easily transportable by truck, rail, vessel, or air. Microreactor designs often assume that the unit can be transported containing either unirradiated or irradiated fuel. The interest in microreactors is driven by several factors, including the need to generate power on at remote locations, at military installations, at facilities such as data centers, and in areas recovering from natural disasters. The U.S. Department of Defense is actively pursuing the microreactor concept to meet the increasing energy demands of military operations that require portable and dense power sources. Commercial vendors are also exploring microreactor concepts. The report Microreactor Transportation Emergency Planning Challenges (Maheras et al. 2024) outlined the emergency planning challenges associated with the transportation of microreactors by road, rail, and by barge/ship. The successful commercial deployment and redeployment of microreactors will also require the development of microreactor transportation safety programs. The elements in these safety programs are not specific to microreactors; however, the transport of microreactors may pose unique challenges in these areas. This report builds on the report Microreactor Transportation Emergency Planning Challenges (Maheras et al. 2024) and develops the elements of a prototype microreactor transportation safety program that describes the elements that should be contained vendor-developed microreactor transportation safety programs, identifying the unique elements associated with microreactor transport. This will provide vendors and their transportation contractors a basis for their transportation planning and will accelerate the commercial deployment and redeployment of microreactors by identifying those issues unique to microreactor transport. The emphasis of this report is on highway transport of microreactors. This is based on a U.S. Nuclear Regulatory Commission transportation package approval strategy of crawl-walk-run, where transport by highway is evaluated first (Coles et al. 2021, 2024, Maheras et al. 2021), then other surface modes (rail and barge/ship), and finally air transport. Evaluation of maritime transport of microreactors was recently initiated (Rigato et al. 2024, Maheras et al. 2025). The report first discusses microreactors in general and microreactor transportation safety program planning assumptions. The report then provides a description of the transportation safety planning process and provides an extensive discussion of the elements of transportation safety programs. Specific elements examined included transportation roles and responsibilities, transportation planning, transportation mode and route selection, carrier selection, transportation packaging, advance notification of shipments, public information and communications, emergency response plans and procedures, inspections, security, safe parking, shipment tracking, weather and road conditions, medical preparedness, training and exercises, and program evaluation. The report then identifies the unique elements of a transportation safety program associated with microreactor transport. These unique elements were in the areas of: the unusual nature of microreactor designs, compensatory measures, increased radiation dose rates in the vicinity of microreactors, transportation package approval versus 10 CFR 50.59, and the use of a risk-informed transportation package approval process.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Green Button Extensibility Assessment

In September 2011, the federal government announced a “call to action” to create a mechanism to enable utility consumers to download their energy usage history from their utilities’ secure websites in a standardized electronic format. That effort was christened the Green Button initiative, drawing on the success of the Blue Button initiative delivered by the US Department of Defense in 2009 as a secure, online access mechanism to download patient health information through the TriCare online portal.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Trends and Effects of Changes in Business Cases for Petroleum Refineries

This study investigates trends and effects in business cases for petroleum refineries with a focus on effects for the state of Oregon for finished gasoline. Recently, the Oregon Department of Energy released the 2024 Oregon Energy Security Plan (ESP) which highlighted the reliance on out of state gasoline imports primarily from refineries located in the state of Washington. This study compiled a list of recent refinery closures in the United States and analyzed the drivers and impacts each refinery closure had to its respective region. The study dives into exploring three refinery closure business cases and past events that impacted gasoline prices in Oregon. Lastly, the paper outlines a potential framework of indicators to analyze the risk of future refinery closures based on the findings. This study hopes to inform stakeholders about the vulnerabilities in Oregon’s fuel supply chain and provide information that can guide strategic planning for future energy security.

02 PETROLEUM↗

Commercialization of the Transportation-Security, Tracking, and Reporting System (T-STAR)

The Transportation-Security, Tracking, and Reporting System (T-STAR) was developed by the National Nuclear Security Administration, NA-21, Office of Radiological Security (ORS) to provide a transportation security system for detection and tracking during transport of Category 1 and Category 2 radiological material. Few off-the-shelf systems for conveyance tracking offer detection of a cargo compartment breach or a removal of the cargo. Systems that do offer this capability often require permanent installation through modifying of the conveyance itself. This is not sustainable in many countries where ORS is building use, storage, and transport security capacity. The development of T-STAR has moved from fielding robust prototypes deployed in countries ranging from North America, Latin America and Central Asia to a commercially produced product that can now be deployed to provide enhanced security during transit. Each prototype deployment resulted in important lessons learned, which informed the requirements for the final commercial product. T-STAR uses both cellular and Iridium satellite modems to provide redundant communications to provide the configuration, status, and alerts to a server monitoring the shipment, which is accessible using a multilanguage browser-based user interface. A wireless security system employing using Z-wave sensors for intrusion detection located in the conveyance provide low cost but effective solution for a wide range of conveyance types. Additional capabilities include the ability to monitor a vehicles’ CANBUS (Controller Area Network) system, an ethernet port for high throughput sensor information such as video cameras, and the ability to power and use advanced external sensor payloads. These features make the T-STAR a capable and expandable security gateway that can be deployed on a variety of conveyances from box trucks to open trailers. The ability to provide tracking, monitoring, and detection provide a key component in overall best practices designed to protect shipments of radioactive material.

Schultze, Michael [ORNL] (ORCID:0000000283205671)↗

Enhancing Security and Resiliency in Operational Technology Environments Through Network Slicing and Federated Learning

The growing convergence of Information Technology (IT) and Operational Technology (OT) within Industry 4.0 environments has introduced new demands on industrial network infrastructure. As cyber-physical systems become increasingly interconnected, ensuring the secure, timely, and efficient exchange of critical data is essential. This thesis explores how network slicing, a method of creating isolated virtual network segments, can be applied within OT environments to address challenges such as latency, security, and resource allocation. The first research question addressed in this thesis is: How can OT networks take advantage of NFV and SDN technology to become cyber resilient? This study examines the operational, security, and architectural implications of introducing network slicing into traditionally static OT infrastructures such as Industrial Control Systems (ICS) and SCADA. Through simulated deployments and case studies, the research demonstrates how slicing enables better isolation between critical and non-critical services, thereby improving response time, throughput, and security in sensitive environments. The second question considers: How to dynamically implement network slicing and take advantage of network resources towards integrating decentralized machine learning? In response, this thesis proposes a framework that combines Software-Defined Networking (SDN), Network Function Virtualization (NFV), and Federated Learning (FL) to enable real-time analytics while maintaining data locality. The proposed approach reduces the burden on centralized infrastructure and minimizes privacy risks by supporting on-site training of models across distributed OT nodes, coordinated through dynamically allocated network slices. The third focus explores: How slicing helps to increase the resiliency of OT networks through the orchestration of a dynamic DMZ? To answer this, the thesis presents a method for creating and managing Dynamic Demilitarized Zones (DMZs) using network slicing. This enables flexible and automated isolation of sensitive subsystems during threat scenarios or high-risk operations. Coupled with intelligent orchestration and containerized security services, the dynamic DMZ significantly enhances the system's ability to respond to cyber incidents without halting production. Ultimately, this thesis contributes a comprehensive architecture that blends network slicing with machine learning, secure segmentation, and automation, paving the way for resilient, adaptive, and intelligent OT environments. Performance evaluations across multiple scenarios show improvements in system reliability, threat response time, model accuracy, and resource utilization, providing a strong foundation for future industrial automation systems.

Rodiles Delgado, Brian G↗

Defensive Cybersecurity Architecture Design Using Force-on-Force Cyber-Physical Modeling

Currently, nuclear power plant physical security systems are highly dependent on air-gaps as a protective measure against cyber-threats. Cyber-physical threats become more likely as advanced cyber-threat capabilities to jump air-gaps transition into common use. Defending against the emerging threat of cyber-enabled physical intrusions is poorly understood. The consequence of these cyber-physical attacks has no quantitative analysis method to inform risk-informed, performance-based cybersecurity approaches. By modifying the physical security simulation tool Dante, cyber-physical threat consequence was able to be analyzed on a notional facility. The results of this analysis are used to design a Defensive Cybersecurity Architecture (DCSA) for the physical security system to produce example resilience measures for this notional facility. A DCSA defines security levels to provide a graded approach for defending plant functions, and security zones for trusted communication between systems. This approach can be applied to real world systems to produce physical protection systems and response measures that are resilient to cyber-physical threats.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Synergies Between Nuclear Security and Critical Infrastructure: National Legal and Regulatory Frameworks

Nuclear reactors and other nuclear facilities are part of a nation's critical infrastructure assets. Key cross-sector interdependencies, in relation to energy, transportation systems, communications, emergency services, water, information technologies and others, result in inevitable synergies between legal frameworks for the security of nuclear facilities and legal frameworks for the protection of critical infrastructure. The protection of nuclear facilities against sabotage and other malicious acts is paramount in ensuring energy security and thus ensuring uninterrupted energy supply. The protection of other sectors, such as uninterrupted communications, secure water supply, and others, supports a safe and secure operation of nuclear facilities. Some countries rely on broader critical infrastructure frameworks to impose security requirements on nuclear facilities, or to achieve robust cybersecurity systems. This paper will analyze the interdependencies and synergies between the legal and regulatory frameworks for critical infrastructure protection and nuclear facilities' security by comparing various national frameworks. The paper will also propose modalities to leverage the best practices and requirements from each framework towards energy security goals and stronger national nuclear security regimes.

Man, Madalina-Anca↗

ChatGPT and Other Large Language Models for Cybersecurity of Smart Grid Applications

Cybersecurity breaches targeting electrical substations constitute a significant threat to the integrity of the power grid, necessitating comprehensive defense and mitigation strategies. Any anomaly in information and communication technology (ICT) should be detected for secure communications between devices in digital substations. This paper proposes large language models (LLMs), e.g., ChatGPT, for the cybersecurity of IEC 61850-based communications. Multi-cast messages such as generic object oriented system events (GOOSE) and sampled values (SV) are used for case studies. The proposed LLM-based cybersecurity framework includes, for the first time, data pre-processing of communication systems and human-in-the-loop (HITL) training (considering the cybersecurity guidelines recommended by humans). The results show a comparative analysis of detected anomaly data carried out based on the performance evaluation metrics for different LLMs. A hardware-in-the-loop (HIL) testbed is used to generate and extract a dataset of IEC 61850 communications.

ChatGPT↗