Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Secure by Design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

Protecting intellectual property in space; Proceedings of the Aerospace Computer Security Conference, McLean, VA, March 20, 1985

The primary purpose of the Aerospace Computer Security Conference was to bring together people and organizations which have a common interest in protecting intellectual property generated in space. Operational concerns are discussed, taking into account security implications of the space station information system, Space Shuttle security policies and programs, potential uses of probabilistic risk assessment techniques for space station development, key considerations in contingency planning for secure space flight ground control centers, a systematic method for evaluating security requirements compliance, and security engineering of secure ground stations. Subjects related to security technologies are also explored, giving attention to processing requirements of secure C3/I and battle management systems and the development of the Gemini trusted multiple microcomputer base, the Restricted Access Processor system as a security guard designed to protect classified information, and observations on local area network security.

Source record↗

Precoder Design for Physical-Layer Security and Authentication in Massive MIMO UAV Communications

Supporting reliable and seamless wireless connectivity for unmanned aerial vehicles (UAVs) has recently become a critical requirement to enable various different use cases of UAVs. Due to their widespread deployment footprint, cellular networks can support beyond visual line of sight (BVLOS) communications for UAVs. In this paper, we consider cellular connected UAVs (C-UAVs) that are served by massive multiple input-multiple-output (MIMO) links to extend coverage range, while also improving physical layer security and authentication. Here, we consider Rician channel and propose a novel linear precoder design for transmitting data and artificial noise (AN). We derive the closed-form expression of the ergodic secrecy rate of CUAVs for both conventional and proposed precoder designs. In addition, we obtain the optimal power splitting factor that divides the power between data and AN by asymptotic analysis. Then, we apply the proposed precoder design in the fingerprint embedding authentication framework, where the goal is to minimize the probability of detection of the authentication tag at an eavesdropper. In simulation results, we show the superiority of the proposed precoder in both secrecy rate and the authentication probability considering moderate and large number of antenna massive MIMO scenarios.

99 GENERAL AND MISCELLANEOUS↗

Renewable Energy and Storage Cybersecurity Research (RESCue) Pilot Final Report

The Renewable Energy and Storage Cybersecurity Research (RESCue) project is a collaborative effort aimed at securing the rapidly growing deployment of distributed energy resources (DERs) and transmission-connected hybrid renewable energy systems against escalating cyber threats. This project brings together major original equipment manufacturers (OEMs) of wind, solar, and energy storage, along with major asset owners and DOE National Laboratories, to collectively identify cyber threats, assess risks, and develop robust cybersecurity strategies and solutions. This publication the final report for the first year of the project.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Advanced Transmission Technologies – GETs and HPCs Session 1: ATT Foundations and Dynamic Line Ratings (DLRs)

The INL TADA GETs Cohort Session 1, held on November 4, 2025, convened experts to address the integration of advanced transmission technologies, including Grid-Enhancing Technologies (GETs) and High Performance Conductors (HPCs), with a focus on digital assurance challenges. The session highlighted the growing importance of cybersecurity, supply chain transparency, reliability, and business risk management in deploying GETs, especially Dynamic Line Ratings (DLRs). Participants examined how expanded attack surfaces, limited vendor pools, and new regulatory requirements—such as FERC Orders 881, 2023, and 1920—are influencing utilities and technology providers. The workshop underscored the need for cyber-informed engineering, secure-by-design principles, and practical risk management strategies, while fostering collaboration and knowledge sharing among industry peers. Technical discussions covered the evolution from static to dynamic line ratings, complexities of cloud-based architectures, and NERC CIP compliance challenges. The session concluded with a collaborative risk exercise and a preview of future workshops on advanced power flow control and transmission topology optimization, reinforcing the cohort’s commitment to advancing digital assurance in the energy sector.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Development of a Dynamically Configurable, Object-Oriented Framework for Distributed, Multi-modal Computational Aerospace Systems Simulation

The following reports are presented on this project:A first year progress report on: Development of a Dynamically Configurable,Object-Oriented Framework for Distributed, Multi-modal Computational Aerospace Systems Simulation; A second year progress report on: Development of a Dynamically Configurable, Object-Oriented Framework for Distributed, Multi-modal Computational Aerospace Systems Simulation; An Extensible, Interchangeable and Sharable Database Model for Improving Multidisciplinary Aircraft Design; Interactive, Secure Web-enabled Aircraft Engine Simulation Using XML Databinding Integration; and Improving the Aircraft Design Process Using Web-based Modeling and Simulation.

Afjeh, Abdollah A.↗

Recommendations for Secure Transport: Material Conveyance Physical Protection Technology

Nuclear material is at higher risk of theft and sabotage during transport than during any other phase of the nuclear fuel lifecycle. Nuclear materials are transported in the public domain where adversaries have an upper hand by taking advantage of the time and location of the theft or sabotage attempt. As such, even modest threat profiles for transport of nuclear and radioactive material can require substantial detection and delay measures to support timely response. Conveyance tracking augmented with technology that improves on-the-scene situational awareness at a remote monitoring center has been adopted as a de-facto standard approach for transportation security. At present, the extended tracking and situational awareness capabilities needed for a nuclear material shipment, as is provided by the purpose designed, Transportation – Security, Tracking and Reporting (T-STAR) System, do not exist in a single commercial off-the-shelf (COTS) solution. Typically, the COTS systems that excel in one area are deficient in other areas, presenting challenges to designing well-rounded, robust systems. Still, COTS solutions can offer the basic set of tracking and situational awareness capabilities by indicating last update time, current location, and route taken. By incorporating vehicle and driver performance measures via the vehicle’s controller area network (CAN bus) and video alongside other data streams allows telemetry and other shipment information to be assessed in novel ways.This paper describes the operation, capabilities and features of various conveyance protection systems and approaches, assesses emerging technologies and how they could be used through a unified interface, and enumerates additional ways to provide early detection using vehicle, onboard technologies, effective delay technologies and approaches and simple equipment to improve protection during transport.

Shannon, Michael↗

Space-based Science Operations Grid Prototype

Grid technology is the up and coming technology that is enabling widely disparate services to be offered to users that is very economical, easy to use and not available on a wide basis. Under the Grid concept disparate organizations generally defined as "virtual organizations" can share services i.e. sharing discipline specific computer applications, required to accomplish the specific scientific and engineering organizational goals and objectives. Grids are emerging as the new technology of the future. Grid technology has been enabled by the evolution of increasingly high speed networking. Without the evolution of high speed networking Grid technology would not have emerged. NASA/Marshall Space Flight Center's (MSFC) Flight Projects Directorate, Ground Systems Department is developing a Space-based Science Operations Grid prototype to provide to scientists and engineers the tools necessary to operate space-based science payloads/experiments and for scientists to conduct public and educational outreach. In addition Grid technology can provide new services not currently available to users. These services include mission voice and video, application sharing, telemetry management and display, payload and experiment commanding, data mining, high order data processing, discipline specific application sharing and data storage, all from a single grid portal. The Prototype will provide most of these services in a first step demonstration of integrated Grid and space-based science operations technologies. It will initially be based on the International Space Station science operational services located at the Payload Operations Integration Center at MSFC, but can be applied to many NASA projects including free flying satellites and future projects. The Prototype will use the Internet2 Abilene Research and Education Network that is currently a 10 Gb backbone network to reach the University of Alabama at Huntsville and several other, as yet unidentified, Space Station based science experimenters. There is an international aspect to the Grid involving the America's Pathway (AMPath) network, the Chilean REUNA Research and Education Network and the University of Chile in Santiago that will further demonstrate how extensive these services can be used. From the user's perspective, the Prototype will provide a single interface and logon to these varied services without the complexity of knowing the where's and how's of each service. There is a separate and deliberate emphasis on security. Security will be addressed by specifically outlining the different approaches and tools used. Grid technology, unlike the Internet, is being designed with security in mind. In addition we will show the locations, configurations and network paths associated with each service and virtual organization. We will discuss the separate virtual organizations that we define for the varied user communities. These will include certain, as yet undetermined, space-based science functions and/or processes and will include specific virtual organizations required for public and educational outreach and science and engineering collaboration. We will also discuss the Grid Prototype performance and the potential for further Grid applications both space-based and ground based projects and processes. In this paper and presentation we will detail each service and how they are integrated using Grid

Bradford, Robert N.↗

Securing Future Energy Supplies: From Renewables to Microreactors

This session will provide insight into how future energy deployments, critical to national-level programs focused on reducing carbon emissions, can be secured-by-design using lessons learned from current energy infrastructure. It will begin with an overview of current threats and risks associated with renewable energy assets and systems, primarily wind and solar, focusing on their control architecture and key system functions for both efficient and safe operations. This talk will then translate the key takeaways from current renewable infrastructure into applications for securing future energy systems, including microreactors and small modular reactors (SMRs), based on planned concepts of operations and control. Microreactors and SMRs are intended to be factory-assembled with commercially available components and deployed in more remote or distributed environments, necessitating centralized control centers, remote monitoring, and offsite maintenance and technical support. All of these factors lead these assets to a security posture and controls more similar to today's renewable energy assets than today's nuclear reactors, which represents a significant shift in mindset for the nuclear industry. This talk will provide justification for this shift as well as a path forward to motivate securing these groundbreaking technologies from the outset of their design and deployment.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Universal Utility Data Exchange (UUDEX) – Security and Administration: Cybersecurity of Energy Delivery Systems (CEDS) Research and Development

A critical component of the Universal Utility Data Exchange (UUDEX) approach is the integrated security contained within its processing. This document describes how that security is designed and expected to be implemented by UUDEX Implementations (U-Implementations), including the UUDEX Server (U-Server) and UUDEX Clients (U-Clients). The UUDEX security hierarchy consists of three levels: 1. The UUDEX Instance (U-Instance) itself, which sits at the top of the hierarchy and contains the U-Server, the UUDEX Identity Authority (U-Identity Authority), and the UUDEX Administrator (U-Administrator) functions; 2. A group of one or more UUDEX Participants (U-Participants) that present “organizations” that participate in the U-Instance and contains the UUDEX Administrator Participant (U-U-Administrator Participant) function; 3. A group of one or more UUDEX Endpoints (U-Endpoints) that represent the individual UUDEX Publish Clients (U-Publish Client) responsible for supplying data to the U-Instance that is consumed by UUDEX Subscriber Clients (U-Subscriber Clients). U-Endpoints can be either autonomous devices that publish and subscribe data such as data exchange servers found in supervisory control and data acquisition and energy management systems, or they can be tied to users of applications that, for example, submit DOE OE-417 disturbance reports. U-Participants and U-Endpoints can be organized into UUDEX Groups (U-Groups). Any number of U-Participants or U-Endpoints can be members of a U-Group. A given U-Participant or U-Endpoint can be a member of multiple U-Groups, but a U-Group cannot contain other U-Groups. For example, a U-Group could be created to contain all U-Participant Transmission Operators within the purview of a Reliability Coordinator, and another U-Group could be created to contain all U-Participant Generator Operators within the purview of a Reliability Coordinator. U-Participants that are both Transmission Operators and Generator Operators would be members of both U-Groups. U-Participants, U-Endpoints, and U-Groups are used in the access control structures to provide access to individual UUDEX Subjects (U-Subjects). U-Groups are created by the U-Administrator and are managed by the U-Administrator or the designated U-Group Managers. U-Endpoints can be assigned UUDEX Roles (U-Roles) that can be used to further restrict access. U-Roles are assigned to individual U-Endpoints. For example, a U-Role of “Security Analyst” could be used to restrict which U-Endpoints can publish or subscribe security incident reports and vulnerability notifications, while a U-Role of “Transmission Planner” can be used to restrict which U-Endpoints can publish power system model updates. U-Role definitions are created by the U-Administrator, but the U-Roles are assigned to U-Endpoints by their respective UUDEX Participant Administrators (U-Participant Administrator). Because all information required to make security decisions is either included within the U-Endpoint’s X.509 digital certificate or stored in a datastore on the U-Server, all security decisions are performed and enforced within the U-Server. This reduces the complexity of the U-Client code and minimizes the chance for compromise of the integrity of the UUDEX security features.

97 MATHEMATICS AND COMPUTING↗

The Neutral Mass Spectrometer on the Lunar Atmosphere and Dust Environment Explorer Mission

The Neutral Mass Spectrometer (NMS) of the Lunar Atmosphere and Dust Environment Explorer (LADEE) Mission is designed to measure the composition and variability of the tenuous lunar atmosphere. The NMS complements two other instruments on the LADEE spacecraft designed to secure spectroscopic measurements of lunar composition and in situ measurement of lunar dust over the course of a 100-day mission in order to sample multiple lunation periods. The NMS utilizes a dual ion source designed to measure both surface reactive and inert species and a quadrupole analyzer. The NMS is expected to secure time resolved measurements of helium and argon and determine abundance or upper limits for many other species either sputtered or thermally evolved from the lunar surface.

Moon↗

Orbital Transfer Vehicle Engine Technology High Velocity Ratio Diffusing Crossover

High speed, high efficiency head rise multistage pumps require continuous passage diffusing crossovers to effectively convey the pumped fluid from the exit of one impeller to the inlet of the next impeller. On Rocketdyne's Orbital Transfer Vehicle (OTV), the MK49-F, a three stage high pressure liquid hydrogen turbopump, utilizes a 6.23 velocity ratio diffusing crossover. This velocity ratio approaches the diffusion limits for stable and efficient flow over the operating conditions required by the OTV system. The design of the high velocity ratio diffusing crossover was based on advanced analytical techniques anchored by previous tests of stationary two-dimensional diffusers with steady flow. To secure the design and the analytical techniques, tests were required with the unsteady whirling characteristics produced by an impeller. A tester was designed and fabricated using a 2.85 times scale model of the MK49-F turbopumps first stage, including the inducer, impeller, and the diffusing crossover. Water and air tests were completed to evaluate the large scale turbulence, non-uniform velocity, and non-steady velocity on the pump and crossover head and efficiency. Suction performance tests from 80 percent to 124 percent of design flow were completed in water to assess these pump characteristics. Pump and diffuser performance from the water and air tests were compared with the actual MK49-F test data in liquid hydrogen.

Lariviere, Brian W.↗

Edge ML for CAN bus intrusion detection in AVs

Autonomous Vehicles (AVs) are revolutionizing transportation, but their reliance on interconnected cyber-physical systems exposes them to unprecedented cybersecurity risks. This study addresses the critical challenge of detecting real-time cyber intrusions in self-driving vehicles by leveraging a dataset from the Udacity self-driving car project. We simulate four high-impact attack vectors, Denial of Service (DoS), spoofing, replay, and fuzzy attacks, by injecting noise into spatial features (e.g., bounding box coordinates) to replicate adversarial scenarios. We develop and evaluate two lightweight neural network architectures (NN-1 and NN-2) alongside a logistic regression baseline (LG-1) for intrusion detection. The models achieve exceptional performance, with NN-2 attaining an AUC score of 93.15% and 93.15% accuracy, demonstrating their suitability for edge deployment in AV environments. Through explainable AI techniques, we uncover unique forensic fingerprints of each attack type, such as spatial corruption in fuzzy attacks and temporal anomalies in replay attacks, offering actionable insights for feature engineering and proactive defense. Visual analytics, including confusion matrices, ROC curves, and feature importance plots, validate the models' robustness and interpretability. This research sets a new benchmark for AV cybersecurity, delivering a scalable, field-ready toolkit for Original Equipment Manufacturers (OEMs) and policymakers. By aligning intrusion fingerprints with SAE J3061 automotive security standards, we provide a pathway for integrating machine learning into safety-critical AV systems. Our findings underscore the urgent need for security-by-design AI, ensuring that AVs not only drive autonomously but also defend autonomously. This work bridges the gap between theoretical cybersecurity and life-preserving engineering, offering a leap toward safer, more secure autonomous transportation.

97 MATHEMATICS AND COMPUTING↗

The evolution of a release-engage mechanism for use on the orbiter

The Release-Engage Mechanism (REM) is designed to secure a deployable payload in the orbiter during launch and to enable the payload to be released, deployed, and reattached for re-entry. This paper presents the following: (1) the initial design concepts of the Release-Engage Mechanism; (2) the problems encountered during assembly, (3) the abnormalities that occurred during vibration testing, (4) the incompatibility of the Remote Manipulator System and REM operation, and (5) the resulting modifications to the REM that assured its successful performance on two Shuttle flights.

Calvert, J.↗

Retaining Device for the Interior Structure of a Spacecraft Payload

A device denoted as a bumper assembly for a spacecraft payload container comprises an interior structure surrounded by skin or some other protective enclosure (see figure). When arranged with three or more like assemblies, this bumper assembly is designed to secure the interior structure within a payload s protective enclosure during the stresses endured in flight and, if required, recovery of the payload. Furthermore, proper use of this innovation facilitates the ability of designers and engineers to maximize the total placement area for components, thus increasing utilization of very valuable and limited space.

Fleming. Orville N., Jr.↗

Using Cosmic Ray Muons to Assess Geological Characteristics in the Subsurface

Cosmic rays are energetic nuclei and elementary particles that originate from stars and intergalactic events. The interaction of these particles with the upper atmosphere produces a wide range of secondary particles that reach the surface of the earth, of which muons are the most prominent. With enough energy, muons can travel up to a few kilometers beneath the surface of the earth before being stopped completely. The terrestrial muon flux profile and associated zenith angle can be utilized to determine geological characteristics of a location (e.g., rock overburden and density) without having to use conventional methods such as boreholes. This work uses a low-power plastic scintillator-based muon detection system as a prototype for this non-destructive geological assay methodology. Four custom designed 102 cm x 51 cm x 5 cm plastic scintillation panels are used to realize two orthogonal detection planes. Optical photons from each scintillation panel are read using OnSemi J-Series 4x4 silicon photomultiplier (SiPM) arrays in conjunction with preamplifiers. Simultaneous triggers between detectors from two planes indicate a coincidence event which is recorded using the QuarkNet data acquisition system (DAQ) from Fermi National Accelerator Laboratory. A custom detector holder was designed to securely mount the detection system and rotate the panels along the zenith to collect data at variable angles. In order to quantify the systematic uncertainties associated with the detector, such as energy depositions and angular resolution of the detector design, a Monte Carlo (MC) simulation using Geant4 is being developed. Cosmic ray flux prediction will be included in the project by adding the CORSIKA MC code to the simulation toolchain. Simulated and experimental data will drive the development and validation of a reconstruction algorithm that, upon completion, is expected to predict average overburden and rock density. Extended detector exposure to muons can be used as a means to understand changes in the surrounding environment like rock porosity. On the experimental front, muons will initially be measured at the surface, establishing the baseline flux. This is followed by recording the muon flux at variable depths and zenith angles, where the data will be used by the reconstruction algorithm to predict the overburden. The result will be benchmarked against geological surveys. The measured flux data will also be used to benchmark independent and established models. Successful proof-of-concept demonstration of this technology can open doors for long term non-invasive geological monitoring. The detector design, experimental methodology, and the benchmarking efforts are detailed in this work.

Gadey, Harish Reddy↗

Developing a Cybersecurity Architecture for Extensible Traffic Management (xTM)

This paper explores the development of a cybersecurity architecture tailored for Extensible Traffic Management (xTM) to address emerging challenges in managing diverse aerial vehicles within the National Airspace System (NAS). Driven by technological advances and the rise of uncrewed aerial systems (UAS), urban air mobility (UAM), and high-altitude traffic (ETM), the NAS is undergoing a paradigm shift. Traditional air traffic management, reliant on traditional Federal Aviation Administration (FAA) control, will give way to decentralized coordination among autonomous and semi-autonomous systems. The proposed xTM Security Architecture, designed as a high-level framework, focuses on ensuring the confidentiality, integrity, and availability of data and operations in this evolving ecosystem. Utilizing threat modeling, the research identifies potential risks across key flight phases, operations and use cases to offer security control recommendations. Key objectives include analyzing interactions between novel airspace entrants and existing NAS traffic, cataloging vulnerabilities, and developing mitigative strategies to ensure safety, operational stability, and secure data exchanges. This research lays the groundwork for regulatory and industry adaptation, providing critical insights into managing cybersecurity risks in this complex, multi-domain environment.

UAM↗

5G Communications in Nuclear: Potential Use Cases and Security Considerations

As fifth-generation (5G) communications continues to revolutionize the future of wireless technology, there is growing demand to utilize its benefits for critical infrastructures such as nuclear power plants (NPPs). In regard to achieving full automation and control in the operation of existing and future nuclear reactors, the unique capabilities of 5G can bring several potential advantages over other wireless technologies. However, a deep investigation is needed for the availability and security of 5G communications under various NPP operational scenarios. This article examines how 5G security capabilities can be architecturally deployed in nuclear applications so as to replace existing communication infrastructures. We discuss the current use of all wireless technologies in NPPs with their key features. Consequently, we investigated several NPP use cases in which 5G offers potential advantages but entails specific security considerations. The present article covers the characteristics of 5G communications, general challenges to its application in nuclear, and the security gaps that need to be addressed. We also highlight certain 5G security-by-design features that can help addressing current stringent NPP requirements. In addition, we discuss some future research direction that can facilitate the implementation of 5G in a nuclear facility. The findings presented herein can help foster 5G deployment in NPPs, thus enabling secured data transmission, cost savings, and increased operational efficiency with enhanced reliability.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗