Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “encryption”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

Assessing DER Network Cybersecurity Defences in a Power-Communication Co-Simulation Environment

Increasing penetrations of interoperable distributed energy resources (DER) in the electric power system are expanding the power system attack surface. Maloperation or malicious control of DER equipment can now cause substantial disturbances to grid operations. Fortunately, many options exist to defend and limit adversary impact on these newly-created DER communication networks, which typically traverse the public internet. However, implementing these security features will increase communication latency, thereby adversely impacting real-time DER grid support service effectiveness. In this work, a collection of software tools called SCEPTRE were used to create a co-simulation environment where SunSpec-compliant PV inverters were deployed as virtual machines and interconnected to simulated communication network equipment. Network segmentation, encryption, and moving target defence security features were deployed on the control network to evaluate their influence on cybersecurity metrics and power system performance. The results indicated that adding these security features did not impact DER-based grid control systems but improved the cybersecurity posture of the network when implemented appropriately.

97 MATHEMATICS AND COMPUTING↗

Entanglement Purification and Protection in a Superconducting Quantum Network

High-fidelity quantum entanglement is a key resource for quantum communication and distributed quantum computing, enabling quantum state teleportation, dense coding, and quantum encryption. Any sources of decoherence in the communication channel, however, degrade entanglement fidelity, thereby increasing the error rates of entangled state protocols. Entanglement purification provides a method to alleviate these nonidealities by distilling impure states into higher-fidelity entangled states. In this work, we demonstrate the entanglement purification of Bell pairs shared between two remote superconducting quantum nodes connected by a moderately lossy, 1-meter long superconducting communication cable. We use a purification process to correct the dominant amplitude damping errors caused by transmission through the cable, with fractional increases in fidelity as large as 25%, achieved for higher damping errors. The best final fidelity the purification achieves is 94.09 ± 0.98%. In addition, we use both dynamical decoupling and Rabi driving to protect the entangled states from local noise, increasing the effective qubit dephasing time by a factor of 4, from 3 to 12 μs. These methods demonstrate the potential for the generation and preservation of very high-fidelity entanglement in a superconducting quantum communication network.

75 CONDENSED MATTER PHYSICS, SUPERCONDUCTIVITY AND↗

Topological spin memory of antiferromagnetically coupled skyrmion pairs in Co/Gd/Pt multilayers

Antiferromagnetically (AFM) coupled skyrmions offer potential advantages for spintronic devices, including reduced dipolar fields that may enable smaller skyrmion sizes and a reduction of the skyrmion Hall effect. However, the topological stability of AFM-coupled skyrmions subjected to dramatic spin deformation through low-temperature cycling has not been investigated. We report the discovery of a topological spin memory effect for AFM-coupled skyrmion pairs in [Co/Gd/Pt](10) multilayered films. Photoemission electron microscopy imaging shows that bubble skyrmions in the multilayer that are stable at room temperature evolve into complex in-plane spin textures as the temperature is lowered and reform completely when the sample is warmed back up. Simulations demonstrate that Dzyaloshinskii-Moriya interactions play a key role in this spin memory effect, and furthermore reveal that the topological charge is preserved throughout the dramatic spin texture rearrangement and recovery. These results highlight a key aspect of topological protection-the preservation of the topological properties under continuous deformation-and also provide a promising avenue for information encryption and recovery.

71 CLASSICAL AND QUANTUM MECHANICS, GENERAL PHYSIC↗

Fail-Safe Logic Design Strategies Within Modern FPGA Architectures

Fail-safe computing refers to computing systems that revert to a non-operational safe state when a fault occurs. In this paper, we investigate a circuit level technique as mitigation for single event upsets (SEUs) and fault injection attacks on field programmable gate arrays (FPGAs), and analyze the effectiveness of the technique as a fail-safe monitor for an encryption algorithm. The propagation of fault effects through FPGA primitives including lookup tables (LUTs) and programmable interconnect points (PIPs) is assessed within an FPGA architecture created using an open source tool, and validated using fault injection experiments on an FPGA. The analysis reveals additional vulnerabilities exist within reconfigurable architectures over those in equivalent fail-safe application specific integrated circuit (ASIC), thus requiring a more elaborate network of redundant circuits and checking logic. The configuration memory bits (CMBs), which configure routing and designate logic functions within the LUTs of the FPGA, add complexity to fail-safe design strategies by introducing additional fault conditions and fault propagation paths. A resource-efficient fail-safe circuit design technique called DEsign for Fail-safe in reCONfigurable systems (DEFCON) is proposed. The benefits and limitations associated with DEFCON are described in the context of fault injection experiments carried out as simulations and in FPGA hardware.

Bhakta, Priya A. [Univ. of New Mexico, Albuquerque↗

Secure and Cost-Effective Micro Phasor Measurement Unit (PMU)-Like Metering for Behind-the-Meter (BTM) Solar Systems using Blockchain-Assisted Smart Inverters

Recently, there is increasing interest in using behind-the-meter (BTM) solar systems for grid services. However, providing visibility and operational situational awareness of BTM solar systems mainly operated by small-scale solar inverters is challenging due to the requirement of relatively expansive networked observation tools (e.g., micro phasor measurement units (µPMUs)) and consequent cybersecurity threats through networks. This paper presents a secure, cost-effective, µPMUs-like metering method using a blockchain-assisted smart (BAS) inverters for a BTM solar system. The proposed BAS inverter consisting of an internet of things device as a node of a local blockchain network enables the secure provision of inverter measurement data for grid services. The BAS inverter sends the encrypted local measurement data with a timestamp to a local blockchain miner. Once the blockchain miner generates a tamper-resistant metering ledger including the measurements, it is used to assess the situational awareness of the BTM solar system. The concept of the proposed metering using the BAS inverters is validated by experimental studies.

behind the meter↗

Blockchain-Based Man-in-the-Middle (MITM) Attack Detection for Photovoltaic Systems

Cybersecurity of photovoltaic (PV) systems entails a much larger scope than just encryption and firewall of communications. For instance, integrity of data in transit between inverters and a cloud server can be compromised by authorized third-party, devices, and internal network within security perimeter (i.e., man-in-the-middle (MITM) attack). To address this challenge, this paper proposes a blockchain-based MITM attack detection method for a PV system. A breakthrough method includes screening network data, network intrusion detection, and hash comparison of in-transit data using distributed ledgers. Furthermore, the proposed method is implemented in Internet-of-Thing (IoT) security modules as clients of a blockchain network and validated by experiments.

blockchain↗

A Cryptographic Method for Defense Against MiTM Cyber Attack in the Electricity Grid Supply Chain

Critical infrastructures such as the electricity grid can be severely impacted by cyber-attacks on its supply chain. Hence, having a robust cybersecurity infrastructure and management system for the electricity grid is a high priority. This paper proposes a cyber-security protocol for defense against man-in-the-middle (MiTM) attacks to the supply chain, which uses encryption and cryptographic multi-party authentication. A cyber-physical simulator is utilized to simulate the power system, control system, and security layers. The correctness of the attack modeling and the cryptographic security protocol against this MiTM attack is demonstrated in four different attack scenarios.

Paul, Shuva↗

Testbed and Experiments for Quantum-Conventional Networking

The realization of quantum networks requires the development of devices and methods unprecedented in conventional networks, and yet they critically depend on the latter for implementing foundational blocks and essential operations. We describe a testbed to support the development and testing of their functionality and performance by providing quantum and conventional data planes and devices, together with a secure conventional control plane. It incorporates a variety of entangled photon sources, qubit technologies, detector technologies, photonic components, and supporting conventional switches and workstations. It implements a novel fiber telescoping scheme that provides suites of connections using fiber spools and inground-aerial fiber loops. We briefly summarize a variety of experiments conducted over this testbed including: (i) flex-grid quantum connection experiments, (ii) quantum state and channel tomography, (iii) utilization of quantum key distribution keys to secure conventional encryption and firewall devices, (iv) comparative study of analytical capacity estimates and entanglement throughput, (v) deployed squeezing coexisting with conventional communications, and (iv) measurement of polarization time variation.

Rao, Nageswara [ORNL] (ORCID:0000000234085941)↗

Integrating AEAD Ciphers into Software-Defined-Storage Systems

The use of software-defined storage (SDS) systems to store sensitive data is becoming increasingly prevalent. However, these systems primarily implement security measures to ensure the confidentiality and availability of stored data, with limited consideration for the protection of its integrity. This paper outlines why this is a harmful development, as well as how integrity-protecting measures can be included into SDS systems. To demonstrate the practical challenges and opportunities of such measures, we integrated "authenticated encryption with associated data" (AEAD) ciphers into the widely used SDS system Ceph, specifically, into its block storage interface, to secure the integrity of stored data and metadata. Ultimately, we identify the characteristics that an SDS system should possess to adopt our methodology.

Mohren, David [University of New Brunswick, Canada↗

Alerga: Alert Aggregation and Reasoning in GOOSE Simulation Pipeline

IEC 61850 specifies the Generic Object Oriented Substation Event (GOOSE) protocol as one option for low latency communication of substation-related events. Due to its strict timing requirements, GOOSE lacks any form of encryption or authentication and has only minimal integrity guarantees. These absences render the protocol vulnerable to a variety of communication anomalies, including adversarial action. In particular, an adversary with access to the substation network can launch man in the middle (MITM) attacks. We propose Alerga, a set of tools to allow operators to mitigate some of the risks of the protocol while retaining its strengths. To that end, we have developed first a GOOSE simulation pipeline including data generation, anomaly detection, alert handling, causal reasoning and data visualization components. The simulator is designed to be modular, allowing operators to swap components to better fit their network capabilities. The volume of alert traffic on a substation network threatens operators with alert fatigue. In order to combat this, we secondly present a novel form of alert aggregation and processing, offering operators a condensed view of any threats to the system. Thirdly, to facilitate the handling of these threats, our causal reasoning system traces the alerts back to their most likely cause, generating an initial hypothesis for operators to investigate.

alert aggregation↗

Trust Model Utilization for Energy Grid Communication

The internet information that is used by the Energy Grid of Things requires both preventative security measures as well as surveillance measures. The preventative security measures include certificates, encryption, and all of the basic security protocols as defined by published standards. The surveillance measures include monitoring information flow activities and evaluating these messages for indications of potential security attacks. We describe in this paper the utilization of a Distributed Trust Model that was developed specifically for monitoring communication within an Energy Grid of Things. The goal for the Distributed Trust Models is to provide a level of aggregate trust that a Distributed Energy Resource Management System can meet its grid service obligations, as opposed to a detailed individual Distributed Energy Resources assessment.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Privacy-Preserving Average Consensus With Beaver Triple and Communication Obfuscation

A privacy-preserving average consensus algorithm is proposed that synergizes the Beaver triple in secret sharing theory and noise obfuscation. The algorithm safeguards the initial values of agents against passive adversaries in a multiagent system. It is proved that the proposed algorithm can concurrently ensure average consensus and privacy, while also reducing the online computation and communication overhead compared to encryption-based ones. In addition, it imposes a less stringent condition for privacy preservation compared to certain noise-obfuscation techniques.

Beaver triple↗

Information Leakage Analysis using a Co-design-Based Fault Injection Technique on a RISC-V Microprocessor

The RISC-V instruction set architecture open licensing policy has spawned a hive of development activity, making a range of implementations publicly available. The environments in which RISC-V operates have expanded correspondingly, driving the need for a generalized approach to evaluating the reliability of RISC-V implementations under adverse operating conditions or after normal wear-out periods. Fault injection (FI) refers to the process of changing the state of registers or wires, either permanently or momentarily, and then observing execution behavior. The analysis provides insight into the development of countermeasures that protect against the leakage or corruption of sensitive information which might occur because of unexpected execution behavior. In this paper, we develop a hardware-software co-design architecture that enables fast, configurable fault emulation and utilize it for information leakage and data corruption analysis. Modern System-on-chip FPGAs enable building an evaluation platform where control elements run on a processor(s) (PS) simultaneously with the target design running in the programmable logic (PL). Software components of the FI system introduce faults and report execution behavior. A pair of RISC-V FI-instrumented implementations are created and configured to execute the Advanced Encryption Standard and Twister algorithms. Key and plaintext information leakage and degraded pseudo-random sequences are both observed in the output for a subset of the emulated faults.

42 ENGINEERING↗

DISARM: Target Electronic Device Informed Mitigation of Software Runtime Side-Channel Vulnerabilities

Program runtime/timing attacks exploit variations in a program’s execution times to extract sensitive information from the program (e.g. encryption keys, sensitive variable data, intellectual property). State-of-the-art solutions to runtime side-channel attacks attempt to balance the execution time of the sensitive code for different control flow paths to eliminate the timing leakage. However, during the mitigation process, most techniques do not consider the underlying hardware/device on which the target program is supposed to run on. This can lead to over-fixing (unnecessary extra operations), under-fixing (not solving the imbalance properly), and even failures. Here, we propose DISARM, a joint hardware-software methodology (unlike any existing solution) for mitigating runtime side-channel vulnerabilities that utilizes timing values from real embedded devices to generate targeted software fixes. We implement DISARM to support C/C++/Java source codes and validate it across 22 standard benchmarks. DISARM outperforms state-of-the-art solutions such as PENDULUM and DifFuzzaR in terms of execution time overhead, code size overhead, and correctness on five different embedded/edge devices.

Timing/runtime side-channel↗

Module-OT: A Hardware Security Module for Operational Technology

Increased penetration levels of renewable energy and other types of distributed energy resources (DERs) on the modern electric grid-combined with technological advancements for electric system monitoring and control-introduce new cyberattack vectors and increase the cyberattack surface of energy systems. According to the IEEE Std. 1547-2018, DERs must use Modbus, Distributed Network Protocol 3 (DNP3), or Smart Energy Profile 2.0 (SEP2) as their communication protocol. Previous research identified several vulnerabilities and security breaches in each one of these communication protocols; despite this, existing standards for DERs do not recommend cybersecurity measures. In order to reduce vulnerabilities in power distribution systems, this paper presents a novel open-source hardware security module that improves both information and operational security to better protect data and communications on the distribution grid. The security hardware is called “module for operational technology,” or simply Module-OT, and it has been validated and tested in an emulated distribution system application. Module-OT is integrated within a communication system in the transport layer of the Open Systems Interconnection (OSI) model. It improves system security through encryption, authentication, authorization, certificate management, and user access control. The main advancement of Module-OT is the addition of hardware cryptographic acceleration that improves the overall communication performance in terms of end-to-end latency.

70 PLASMA PHYSICS AND FUSION TECHNOLOGY↗

A Privacy-Preserving Distributed Control of Optimal Power Flow

Here, we consider a distributed optimal power flow formulated as an optimization problem that maximizes a nondifferentiable concave function. Solving such a problem by the existing distributed algorithms can lead to data privacy issues because the solution information exchanged within the algorithms can be utilized by an adversary to infer the data. To preserve data privacy, in this paper we propose a differentially private projected subgradient (DP-PS) algorithm that includes a solution encryption step. We show that a sequence generated by DP-PS converges in expectation, in probability, and with probability 1. Moreover, we show that the rate of convergence in expectation is affected by a target privacy level of DP-PS chosen by the user. We conduct numerical experiments that demonstrate the convergence and data privacy preservation of DP-PS.

24 POWER TRANSMISSION AND DISTRIBUTION↗

VDiSC: An Open Source Framework for Distributed Smart City Vision and Biometric Surveillance Networks

Recent global growth in the interest of smart cities has led to trillions of dollars of investment toward research and development. These connected cities have the potential to create a symbiosis of technology and society and revolutionize the cost of living, safety, ecological sustainability, and quality of life of societies on a world-wide scale. Some key components of the smart city construct are connected smart grids, self-driving cars, federated learning systems, smart utilities, large-scale public transit, and proactive surveillance systems. While exciting in prospect, these technologies and their subsequent integration cannot be attempted without addressing the potential societal impacts of such a high degree of automation and data sharing. Additionally, the feasibility of coordinating so many disparate tasks will require a fast, extensible, unifying framework. To that end, we propose the Distributed Smart City framework for Vision, or VDiSC. VDiSC serves as a unified biometric API harness that allows for seamless evaluation, deployment, and simple pipeline creation for heterogeneous biometric software. VDiSC additionally provides a fully declarative capability for defining and coordinating custom machine learning and sensor pipelines, allowing the distribution of processes across otherwise incompatible hardware and networks. VDiSC ultimately provides a way to quickly configure, hot-swap, and expand large coordinated or federated systems online without interruptions for maintenance. Because much of the data collected in a smart city contains Personally Identifying Information (PII), VDiSC also provides built-in tools and layers to ensure secure and encrypted streaming, storage, and access of PII data across distributed systems.

Brogan, Joel↗

OmniFed: A Modular Framework for Configurable Federated Learning from Edge to HPC

Federated Learning (FL) is critical for edge and High Performance Computing (HPC) where data is not centralized and privacy is crucial. We present OmniFed, a modular framework designed around decoupling and clear separation of concerns for configuration, orchestration, communication, and training logic. Its architecture supports configuration-driven prototyping and code-level override-what-you-need customization. We also support different topologies, mixed communication protocols within a single deployment, and popular training algorithms. It also offers optional privacy mechanisms including Differential Privacy (DP), Homomorphic Encryption (HE), and Secure Aggregation (SA), as well as compression strategies. These capabilities are exposed through well-defined extension points, allowing users to customize topology and orchestration, learning logic, and privacy/compression plugins, all while preserving the integrity of the core system. We evaluate multiple models and algorithms to measure various performance metrics. By unifying topology configuration, mixed-protocol communication, and pluggable modules in one stack, OmniFed streamlines FL deployment across heterogeneous environments. Github repository is available at https://github.com/at-aaims/OmniFed.

Tyagi, Sahil [ORNL] (ORCID:0009000783144745)↗