Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “network security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Secure Time Synchronization in Power Grids and Network HIL Synchrophasor Testing

Reliable and secure time synchronization underpins the monitoring and control functions of modern power grids. As GPS-based timing infrastructures grow more susceptible to spoofing and jamming, their vulnerabilities pose escalating risks to grid stability. This work investigates a secure, resilient timing framework that can serve as an alternative or redundant source for power grids, with a particular focus on synchrophasorbased applications. A candidate timing system architecture is evaluated to guarantee trustworthy time dissemination, even in degraded conditions. A network hardware-in-the-loop testing of two synchrophasors validates the concepts, demonstrating enhanced timing integrity, improved detection of timing anomalies, and sustained observability during adverse timing events.

Wu, Ori [ORNL] (ORCID:0000000326723410)↗

Port scanner and Testing Suite

This project addresses the challenge of identifying and managing open network ports across physical and virtual hosts. The current form of verifying ports in use required manually searching individual ports - a process that was both time- consuming and a potential bottleneck for deployment timelines. To resolve this, an automated port scanning tool was developed in Python. The tool supports simultaneous multiple port scans. To ensure functionality and long-term maintainability, a comprehensive testing suite was implemented using Python’s unittest framework. Edge cases, including valid port numbers, reversed ranges, and closed ports, were explicitly tested to ensure robust handling of real-world scenarios. The resulting tool reduces the time required to verify port security across a network, supporting both targeted and host checks and broader Classless Inter-Domain Routing (CIDR) -based network scans. This work demonstrates the value of automation and test-driven development in strengthening network security practices, and provides a foundation for future enhancements.

Rivera, Linda [Fermilab]↗

Hybrid classical-quantum communication networks

Over the past several decades, the proliferation of global classical communication networks has transformed various facets of human society. Concurrently, quantum networking has emerged as a dynamic field of research, driven by its potential applications in distributed quantum computing, quantum sensor networks, and secure communications. This prompts a fundamental question: rather than constructing quantum networks from scratch, can we harness the widely available classical fiber-optic infrastructure to establish hybrid quantum–classical networks? This paper aims to provide a comprehensive review of ongoing research endeavors aimed at integrating quantum communication protocols, such as quantum key distribution, into existing lightwave networks. This approach offers the substantial advantage of reducing implementation costs by allowing classical and quantum communication protocols to share optical fibers, communication hardware, and other network control resources—arguably the most pragmatic solution in the near term. In the long run, classical communication will also reap the rewards of innovative quantum communication technologies, such as quantum memories and repeaters. Accordingly, our vision for the future of the Internet is that of heterogeneous communication networks thoughtfully designed for the seamless support of both classical and quantum communications.

Fiber-optic communication↗

A technique to make an enterprise network a Darknet on the Internet, while providing required services to authorized users

In a well-designed and secure enterprise network, the hosts inside the network are not directly accessible from the Internet. The enterprise firewall blocks direct access to hosts inside the enterprise network and also blocks any attempts to probe or discover information about those hosts from the Internet. However, access to the enterprise network from the Internet is a must in today’s day and age. Hence, specialized mechanisms to allow secure access are implemented.

97 MATHEMATICS AND COMPUTING↗

Blockchain-Based Man-in-the-Middle (MITM) Attack Detection for Photovoltaic Systems

Cybersecurity of photovoltaic (PV) systems entails a much larger scope than just encryption and firewall of communications. For instance, integrity of data in transit between inverters and a cloud server can be compromised by authorized third-party, devices, and internal network within security perimeter (i.e., man-in-the-middle (MITM) attack). To address this challenge, this paper proposes a blockchain-based MITM attack detection method for a PV system. A breakthrough method includes screening network data, network intrusion detection, and hash comparison of in-transit data using distributed ledgers. Furthermore, the proposed method is implemented in Internet-of-Thing (IoT) security modules as clients of a blockchain network and validated by experiments.

blockchain↗

Sustaining Nuclear Security Education Through INSEN

The International Nuclear Security Education Network (INSEN) was established in 2010 with a mission to enhance global nuclear security through nuclear security-focused educational initiatives. INSEN is a partnership through which the International Atomic Energy Agency (IAEA), academic and research institutions, and other stakeholders cooperate to promote effective and sustainable nuclear security education. INSEN currently comprises 206 members (institutions) from 72 member states and 14 observers. This paper provides an overview of its role in developing and promoting nuclear security education

Metwally, Walid↗

Secure Roaming with 5G

This invited talk in the 2023 6th IEEE 5G Workshop on First Responder and Tactical Networks discusses security improvement introduced by the 3GPP standards to the 5G roaming capabilities over 4G/LTE (Long Term Evolution) standards.

5G↗

A Scalable Quantum Cryptography Network for Protected Automation Communication (Final Report)

This is the final report for a CEDS-funded project aimed at developing a new quantum technology for securing utility communication networks used to control and monitor electrical grid equipment. Securing these control networks represents a unique challenge as the performance of the security solution has a direct impact on the stability and reliability of the electrical grid. Traditional, software-based solutions - developed for information networks - are not suitable for utility control networks because they introduce latency, require burdensome maintenance and upgrades, are often incompatible with legacy equipment, and introduce operational complexity that reduces grid reliability. Consequently, many U.S. utilities do not use existing solutions and, instead, protect their critical control networks through the careful isolation and obscuration of their networked equipment. With more utilities embracing grid automation, the attack surface that utilities must defend from hackers has grown to an unmanageable size. To address this situation, Qubitekk and its partners proposed and developed a hardware-based solution that can secure critical control networks without negatively impacting grid performance. This new solution is based on quantum key distribution (QKD) techniques that guarantee secure key generation and distribution across a utility control network. Through deployment and field testing of a prototype QKD system, we have shown that this solution delivers long-term network security, is technically feasible to implement and maintain on a utility’s distribution substation network and does not negatively impact grid operations. In addition, the project has identified and solved key challenges associated with generating, transmitting, and measuring coherent photonic quantum states on a real-world fiber optic network. These additional findings are playing a critical role in advancing quantum networks for quantum computing applications. An overview of the QKD prototype development effort, field testing activities and results, and additional findings relevant to emerging quantum networks are presented in this report.

71 CLASSICAL AND QUANTUM MECHANICS, GENERAL PHYSIC↗

Blockchain-Enabled Secure Device-to-Device Communication in Software-Defined Networking

The Internet of Things (IoT) continues to increase the demand for seamless communication among IoT devices. The rapid growth of IoT devices has led to an exponential increase in device-to-device (D2D) communication within the Software-Defined Networking (SDN), though it enables a flexible archi-tecture for managing network resources. However, traditional security models face challenges (e.g., Security, privacy, and trust) in addressing the dynamic and decentralized nature of these communications. Despite of these challenges, this paper proposes a novel approach that leverages blockchain technology to enhance the security, privacy, and trustworthiness of D2D communication within an SDN environment. The proposed approach integrates blockchain nodes in sDN components to establish a decentralized ledger for transparent and verifiable records. Smart contracts enforce authentication rules to ensure that only authenticated devices can access the network and engage in transactions securely. It also automates the security policies to ensure temper resistance execution using the cryptographic mechanism for data integrity and authentic communication. The Implementation of the proposed algorithms validates the resilience of the proposed approach against cyberattacks. Overall, the proposed approach enables efficient and secure D2D communication for resilient SDN infrastructure in IoT ecosystems.

Das, Debashis↗

Cyber Protection of Grid-Connected Devices Through Embedded Online Security

Cybersecurity research regarding the electric power grid has primarily been focused on protecting the communication layer of grid-connected devices against cyber-attack threats. Although many developed methods have greatly reduced the effects of a cyber-attack on the vulnerabilities of grid-connected devices, discovering new vulnerabilities is inevitable and a constant threat. As a result, the overall reliability and security of network communications with regard to grid-connected devices is a concern. Here, this paper proposes a method that further secures a system by focusing on the control and hardware layer of grid-connected devices. The device’s controller firmware will be validated and authenticated using integrated device emulation resources prior to being activated to control the grid-connected device. This verification process is performed while the controller is online and actively controlling power flows related to the device. Therefore, an attack to the system through a malicious firmware patch would be detected by the online security and rejected while safely maintaining continuous and stable control of the device. This method integrates the concepts of firmware hot-patching, digital twins, and active monitoring into an overall cybersecurity protection system.

cybersecurity↗

Encrypted model predictive control design for security to cyberattacks

Abstract In recent years, cyber‐security of networked control systems has become crucial, as these systems are vulnerable to targeted cyberattacks that compromise the stability, integrity, and safety of these systems. In this work, secure and private communication links are established between sensor–controller and controller–actuator elements using semi‐homomorphic encryption to ensure cyber‐security in model predictive control (MPC) of nonlinear systems. Specifically, Paillier cryptosystem is implemented for encryption‐decryption operations in the communication links. Cryptosystems, in general, work on a subset of integers. As a direct consequence of this nature of encryption algorithms, quantization errors arise in the closed‐loop MPC of nonlinear systems. Thus, the closed‐loop encrypted MPC is designed with a certain degree of robustness to the quantization errors. Furthermore, the trade‐off between the accuracy of the encrypted MPC and the computational cost is discussed. Finally, two chemical process examples are employed to demonstrate the implementation of the proposed encrypted MPC design.

Suryavanshi, Atharva↗

Communication systems and methods

A communication system is provided that include one or more processors that are configured to instruct computing devices that communicate messages with each other via a time-sensitive network to securely exchange the messages using secret information, ad direct the computing devices to exchange the secret information via a dedicated quantum channel in the time-sensitive network. The one or more processors are also configured to determine a quantum channel synchronization time associated with the secret information exchanged via the dedicated quantum channel, and modify a local classical oscillator based on the quantum channel synchronization time, the local classical oscillator configured to provide a current time.

Bush, Stephen Francis↗

A Secure and Adaptive Hierarchical Multi-Timescale Framework for Resilient Load Restoration Using a Community Microgrid

Distribution system integrated community microgrids (CMGs) can partake in restoring loads during extended duration outages. At such times, the CMGs are challenged with limited resource availability, absence of robust grid support, and heightened demand-supply uncertainty. Here, this paper proposes a secure and adaptive three-stage hierarchical multi-timescale framework for scheduling and real-time (RT) dispatch of CMGs with hybrid PV systems to address these challenges. The framework enables the CMG to dynamically expand its boundary to support the neighboring grid sections and is adaptive to the changing forecast error impacts. The first stage solves a stochastic extended duration scheduling (EDS) problem to obtain referral plans for optimal resource rationing. The intermediate near-real-time (NRT) scheduling stage updates the EDS schedule closer to the dispatch time using new obtained forecasts, followed by the RT dispatch stage. To make the decisions more secure and robust against forecast errors, a novel concept called delayed recourse is designed. The approach is evaluated via numerical simulations on a modified IEEE 123-bus system and validated using OpenDSS and hardware-in-loop simulations. The results show superior performance in maximizing load supply and continuous secure distribution network operation under different operating scenarios.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cybersecurity Resiliency of Marine Renewable Energy Systems Part 2: Cybersecurity Best Practices and Risk Management

Marine renewable energy (MRE) is an emerging source of power for marine applications, marine devices, and coastal communities. This energy source relies on industrial control systems and IT to support operations and maintenance activities, which create a pathway for an adversary to gain unauthorized access to systems and data and disrupt operations. Incorporating cybersecurity risk prevention measures and mitigation capabilities from inception, development, operation, to decommissioning of the MRE system and components is paramount to the protection of energy generation and the security of network architecture and infrastructure. To improve the resilience of MRE systems as a predictable, affordable, and reliable source of energy, cybersecurity guidance was developed to enable operators to assess cybersecurity risks and implement security measures commensurate with the risk. This publication is the second of a two-part series, with Part 1 addressing a framework to determine cybersecurity risk by assessing the vulnerability of an MRE system to potential cyber threats and the consequences a cyberattack would have on the end user. This Part 2 publication describes an approach to select appropriate cybersecurity best practices commensurate with the MRE system's cybersecurity risk. The guidance includes 86 cybersecurity best practices, which are associated with 36 cybersecurity domains and grouped into nine categories. The best practices follow the core functions of the National Institute of Science and Technology Cybersecurity Framework (e.g., identify, detect, protect, respond, and and recover) and insights from both maritime and energy industry guidance documents to identify security measures effective in protecting information and operational technology assets prevalent in MRE systems.

97 MATHEMATICS AND COMPUTING↗

A Trilevel Model for Segmentation of the Power Transmission Grid Cyber Network

Network segmentation of a power grid's communication system can make the grid more resilient to cyberattacks. Here we develop a novel trilevel programming model to optimally segment a grid communication system, taking into account the actions of an information technology (IT) administrator, attacker, and grid operator. The IT administrator is allowed to segment existing networks, and the attacker is given a budget to inflict damage on the grid by attacking the segmented communication system. Finally, the grid operator can redispatch the grid after the attack to minimize damage. The resulting problem is a trilevel interdiction problem that we solve using a branch and bound algorithm for bilevel problems. We demonstrate the benefits of optimal network segmentation through case studies on the 9-bus Western System Coordinating Council (WSCC) system and the 30-bus IEEE system. These examples illustrate that network segmentation can significantly reduce the threat posed by a cyberattacker.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Threat Hunt Guide for BESS Environments

The rapid digitalization of the electric grid - driven by the integration of inverter-based resources (IBRs), battery energy storage systems (BESS), and advanced grid control platforms - has significantly enhanced grid efficiency, visibility, and flexibility. However, this evolution also introduces new cybersecurity risks, particularly through supply chain dependencies and operational blind spots at the grid edge. To address these challenges, Idaho National Laboratory (INL), through the Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) Rapid Risk initiative, conducted a series of rapid risk assessment engagements with energy organizations across the United States. Drawing on lessons learned from these engagements, INL developed the following threat hunting guide for asset owners and operators (AOOs) to enhance their cybersecurity visibility within BESS and IBR systems. The guide demonstrates how to use passive network monitoring to baseline device behavior, detect adversarial activity, and investigate anomalies without disrupting operations. By implementing these practices, energy sector stakeholders can improve coordination between cybersecurity and operations teams and strengthen the resilience of distributed energy resources (DERs) within the modern power grid. Prior to implementing any network monitoring, packet capture, or threat hunting activity described in this guide, AOOs are strongly advised to review applicable governance frameworks, legal requirements, and organizational policies. This guide is intended for informational and educational purposes only. It does not replace compliance with any federal, state, or local cybersecurity mandates or industry standards. Implementation of described configurations, technologies, or analytic workflows is performed at the discretion and responsibility of the asset owner and operator.

25 - ENERGY STORAGE↗

Revisiting Current Paradigms: Subject Matter Expert Views on High Consequence Facility Security Assessments

Security assessments support decision-makers' ability to evaluate current capabilities of high consequence facilities (HCF) to respond to possible attacks. However, increasing complexity of today's operational environment requires a critical review of traditional approaches to ensure that implemented assessments are providing relevant and timely insights into security of HCFs. Using interviews and focus groups with diverse subject matter experts (SMEs), this study evaluated the current state of security assessments and identified opportunities to achieve a more "ideal" state. The SME-based data underscored the value of a systems approach for understanding the impacts of changing operational designs and contexts (as well as cultural influences) on security to address methodological shortcomings of traditional assessment processes. These findings can be used to inform the development of new approaches to HCF security assessments that are able to more accurately reflect changing operational environments and effectively mitigate concerns arising from new adversary capabilities.

36 MATERIALS SCIENCE↗