Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Control Systems Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 145 records · Page 8

The NREL Sensor Laboratory Detection of Hydrogen Emissions

The development of a functional hydrogen detection system is a multifaceted process that integrates hardware, deployments strategies, and analytics which can be supported by the NREL Sensor Laboratory: 1. Support of the design, validation and optimization of sensing prototypes; 2. Guide optimized sensing element development, including control electronics; 3. Laboratory testing to validate/optimize metrological performance (measurement range, detection limit, etc.); 4. Provide test sites for field deployments representative of real-world scenarios with controlled hydrogen releases; 5. Develop sensor placement and operation guidance; 6. Provide guidance on electronics to accommodate facility integration; 7. Electrical safety designs to allow for operation within restricted zones; 8. Integration into facility monitoring and control systems; 9. Guide incorporation of cyber security elements to protect facilities from malicious attacks; 10. Modeling and application of advanced analytics to detect and quantify emissions; 11. Higher Order dispersion models to guide sensor placement for reliable detection; 12. Advanced analytics for improved metrological performances, and to inform inverse modeling; 13. Market support and commercialization (national and international markets); 14. Commercial deployments in H2@SCALE markets (e.g., HUBs and other large-scale hydrogen markets); and 15. Leverage off international collaborations/partnerships (e.g., NREL is on the advisory board for the European initiative "pre-Normative Research on Hydrogen Releases Assessment"-NHyRA).

08 HYDROGEN↗

NASA Unmanned Aircraft (UA) Control and Non-Payload Communication (CNPC) System Waveform Trade Studies

Unmanned Aircraft Systems (UAS) represent a new capability that will provide a variety of services in the government (public) and commercial (civil) aviation sectors. The growth of this potential industry has not yet been realized due to the lack of a common understanding of what is required to safely operate UAS in the National Airspace System (NAS). To address this deficiency, NASA has established a project called UAS Integration in the NAS (UAS in the NAS), under the Integrated Systems Research Program (ISRP) of the Aeronautics Research Mission Directorate (ARMD). This project provides an opportunity to transition concepts, technology, algorithms, and knowledge to the Federal Aviation Administration (FAA) and other stakeholders to help them define the requirements, regulations, and issues for routine UAS access to the NAS. The safe, routine, and efficient integration of UAS into the NAS requires new radio frequency (RF) spectrum allocations and a new data communications system which is both secure and scalable with increasing UAS traffic without adversely impacting the Air Traffic Control (ATC) communication system. These data communications, referred to as Control and Non-Payload Communications (CNPC), whose purpose is to exchange information between the unmanned aircraft and the ground control station to ensure safe, reliable, and effective unmanned aircraft flight operation. A Communications Subproject within the UAS in the NAS Project has been established to address issues related to CNPC development, certification and fielding. The focus of the Communications Subproject is on validating and allocating new RF spectrum and data link communications to enable civil UAS integration into the NAS. The goal is to validate secure, robust data links within the allocated frequency spectrum for UAS. A vision, architectural concepts, and seed requirements for the future commercial UAS CNPC system have been developed by RTCA Special Committee 203 (SC-203) in the process of determining formal recommendations to the FAA in its role provided for under the Federal Advisory Committee Act. NASA intends to conduct its research and development in keeping with this vision and associated architectural concepts. The prototype communication systems developed and tested by NASA will be used to validate and update the initial SC-203 requirements in order to provide a foundation for SC-203's Minimum Aviation System Performance Standards (MASPS).

Aircraft Communications↗

The hack attack - Increasing computer system awareness of vulnerability threats

The paper discusses the issue of electronic vulnerability of computer based systems supporting NASA Goddard Space Flight Center (GSFC) by unauthorized users. To test the security of the system and increase security awareness, NYMA, Inc. employed computer 'hackers' to attempt to infiltrate the system(s) under controlled conditions. Penetration procedures, methods, and descriptions are detailed in the paper. The procedure increased the security consciousness of GSFC management to the electronic vulnerability of the system(s).

Quann, John↗

Spacecraft automatic umbilical system

An umbilical system design is described that incorporates all the features specified for a power system to payload interconnect capability. A proof-of-concept prototype of the umbilical system was built to determine experimentally the suitability of the threading characteristics of the ram mechanism and to verify freedom from cross threading. It is concluded that Berthing systems that utilize remote manipulator systems (RMS) can be simplified by using RMS targets, closed circuit TV cameras, tie into the RMS control system, and grapple-fixture and end-effector-like capture and secure mechanisms. To effect a remotely controlled umbilical interconnect in proximity with a manned spacecraft and to provide for extravehicular activity backup and maintenance capabilities, 18 different mechanisms are found to be necessary. The weight impact of proving for maintenance capability in a large multiple connector umbilical system was found to be in the order of +60 percent.

Goldin, R. W.↗

Survey of Cybersecurity Governance, Threats, and Countermeasures for the Power Grid

The convergence of Information Technologies and Operational Technology systems in industrial networks presents many challenges related to availability, integrity, and confidentiality. In this paper, we evaluate the various cybersecurity risks in industrial control systems and how they may affect these areas of concern, with a particular focus on energy-sector Operational Technology systems. There are multiple threats and countermeasures that Operational Technology and Information Technology systems share. Since Information Technology cybersecurity is a relatively mature field, this paper emphasizes on threats with particular applicability to Operational Technology and their respective countermeasures. We identify regulations, standards, frameworks and typical system architectures associated with this domain. We review relevant challenges, threats, and countermeasures, as well as critical differences in priorities between Information and Operational Technology cybersecurity efforts and implications. These results are then examined against the recommended National Institute of Standards and Technology framework for gap analysis to provide a complete approach to energy sector cybersecurity. We provide analysis of countermeasure implementation to align with the continuous functions recommended for a sound cybersecurity framework.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Autonomous Energy Systems

Energy systems are increasingly complicated by the proliferation of clean energy technologies such as solar, wind, storage, electric vehicles, and building automations. Future energy systems will require secure, autonomous, and reliable communications, control, and interoperability among millions of distributed generation points and billions of buildings, vehicles, and more. To enable effective management of the anticipated growth of distributed devices and the deluge of data and extensive metering that will follow, the National Renewable Energy Laboratory (NREL) has developed the concept of autonomous energy systems (AES).

autonomous↗

Cyber Resilient Design and Controls for Energy Systems

As the grid of today is evolving into a highly distributed and autonomous cyber-physical system with higher penetration of Distributed Energy Resources (DERs) and autonomous controls that are dependent on the cyber infrastructure, there are novel and increasing challenges to cyber-resilient operation of the grid. While the traditional mechanisms take a "bolt on" approach to cybersecurity and resiliency, this talk presents two novel technologies developed at NREL that "bake in" security and resilience into the design and control of the grid. An Adaptive Resilience Metrics framework is a novel mechanism for system owners and operators to understand the impact of cyber and physical system design and topology on the resilient operation, while also helping determine optimal policies in response to adverse cyber events. Along with that a zero-knowledge proof-based technique helps incorporate security into the controls layer by focusing on computational integrity rather than data integrity. By leveraging design and control properties unique to Operational Technology systems these technologies will not only help enhance cyber-resilience for the grid of today, but a highly distributed and autonomous grid of tomorrow.

cyber resilience↗

Smart Inverters, Dumb Risk: Taking Control of IBR Security in the Digital Age

This presentation addresses the security challenges posed by Inverter-Based Resources (IBRs) in the modern energy landscape. The presentation highlights the vulnerabilities and risks associated with IBRs, including the potential for cyber-attacks, the impact of insecure defaults, and the systemic risks posed by supply chain dependencies. Key topics covered include: 1) The increasing digital transformation in energy systems and the associated security risks. 2) Specific vulnerabilities in IBRs, including weak passwords, hardcoded credentials, and insecure web application interfaces. 3) The implications of persistent connectivity and the strategic risks posed by foreign-manufactured components. 4) The role of regulatory frameworks, such as NERC CIP, in addressing these challenges and the limitations of current oversight. 5) Practical solutions for mitigating risks, including secure design practices, vendor risk assessments, and the importance of strong passwords and role-based access control. The presentation underscores the necessity of a comprehensive, system-of-systems approach to securing IBRs, emphasizing the need for collaboration across various stakeholders, including operators, developers, and regulators, to ensure the resilience and security of the energy grid.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

A Cybersecurity Threat Profile for a Connected Lighting System

In anticipation of improved energy performance and cost savings, cities and building owners are increasingly considering “smart lighting initiatives” that aim to convert their collection of simple luminaires (i.e., lighting fixtures) into an intelligent connected lighting system (CLS) capable of remotely monitoring energy consumption and fault conditions, and possibly implementing adaptive lighting schemes. The U.S. Department of Energy (DOE) has set an national goal of tripling the energy efficiency and demand flexibility of the buildings sector by 2030, relative to 2020 levels 1. It is forecast that connected lighting systems can contribute to that goal by delivering 125 TWh of annual energy savings by 2035 2, equivalent to the annual output of 50 typical (500 MW) power plants. However, these energy savings and the DOE goal are put at significant risk if connected technologies are not adopted due to real or perceived cybersecurity concerns. Connected IoT devices such as these have historically been rife with vulnerabilities which sometimes put security considerations secondary to functionality and operability. What are the cybersecurity threats that will impact these systems, as formerly banal luminaires transition into intelligent connected devices that collect information about themselves, their surrounding environment, and possibly us? In this paper we analyze a threat profile performed on a fault-detection use case for streetlights. A threat profile establishes security requirements, justifies security measures, yields actionable controls, and effectively communicates risk to stakeholders. This effort provides critical information for making threat-based decisions to increase security at a reasonable cost, and can effectively be used by development teams, software architects, and managers to make cybersecurity a part of their ongoing culture of awareness, training, and prevention. This leads to more secure systems and better-understood security. On-premise, cloud, and hybrid architectures with different authentication mechanisms were modeled and later categorized using the Microsoft STRIDE framework. An analysis of the recommended controls for each threat was performed to determine which controls could and should be put in place by manufacturers or third-party suppliers, and which controls need to be left up the end-user to implement. Fifty-seven threats were identified. Among our key findings: (1) 65% (37/57) of the threats did not involve the luminaires, but rather the other components needed to communicate with and manage them; (2) 63% (36/57) of the threats could have been mitigated through manufacturer-implemented defensive techniques or “controls”; and (3) 23% (13/57) of the threats were dependent on the network configuration. Recommendations based on the results of this work are made to key stakeholder groups. Notably, lighting technology developers are advised to address all threats that can be reasonably controlled with baked-in technology solutions (e.g., encryption or authentication controls), and employ some form of secure supply chain management and tracking where other parts (e.g., sensors, microprocessors) of a luminaire must also be built and manufactured with the proper security controls in place. Developers should also review threats involving assets not developed in-house to understand how connectivity with other devices will affect their product during system operation and determine if a compensating control for a defense-in-depth strategy will be needed. Finally, those interested in deploying CLS should compare the differences between cloud and on-premise models to determine which is more suitable for their needs and the abilities of their security team.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Command and Control of Utilities Systems

The utilities systems that encompass the Y-12 National Security Complex are an integral part of the entire campus, and are essential to maintaining critical mission focus for the site. Although the utilities systems each differ in function, the central production and distribution model creates a common thread on which each system is run. Several incidents in FY 2018 and FY 2019 documented a lack of overall systems control and highlighted the need to create a better command system that could maintain system availability and decrease possible impacts to the surrounding environment. An initial system was started in September of 2019 to better control mechanical utility distribution systems. The measurement of the system can be modeled against a standard command and control related incident. The corresponding work hours from a typical control-related incident were used as key component to this system model. System effectiveness is modeled against utility’s incidents that demonstrate a loss of command and control. The increased simulations of the model also document control can only be effectively contained within the stated time (3-5 years) by yielding more engineers to complete alignments, or drastically reducing the amount of time for alignments. The total control points of the model document a clear correlation between alignments, control points, and the amount of man-hours per incident. Current data shows that actual incident man-hours (1.88 manhours/ incident since initial system implementation) are near expected incident man-hours (1.81 manhours/ incident) with command and control for October 2021, which documents a 33.3% reduction in man-hours/incident since initial system implementation. A conclusion can be drawn that focus on increasing the amount of controlled points in the system can reduce incidents and the decrease the amount of non-value added work to employee’s day-to-day lives, while also achieving a culture that enhances and sustains utilities reliability.

99 GENERAL AND MISCELLANEOUS↗

Developing VSC-HVDC Oscillation Damping Control Constraints in Unit Commitment

High-voltage direct current (HVDC) systems within the existing power grids will play a pivotal role in enabling high share of renewable power integration and transportation electrification. There is a need for transmission planning models to accurately capture the impact of VSC-HVDC oscillation damping control on the system planning and model the constraints in the security constrained unit commitment (SCUC) problem. In this paper, the SCUC problem in a hybrid DC-AC grid considering damping on electromechanical inter-area oscillation is studied. An electromechanical oscillation-driven transmission capability constraints are derived from system swing equation and incorporated into the SCUC. Multiple system damping control scenarios are set based on the extracted plausible bounds of damping coefficient and inertia constant to linearize the nonlinear expressions. The SCUC problem with proposed constraints is tested on the IEEE 73-bus reliability test system (RTS) case via PLEXOS. The impact of the proposed constraints on regional generation, inertia, power flow, annual system cost, and renewable energy curtailment are fully assessed.

damping control↗

A review of underwater acoustic systems and methods for locating objects lost at sea

Information related to the location of objects lost at sea is presented. Acoustic devices attached to an object prior to being transported is recommended as a homing beacon. Minimum requirements and some environmental constraints are defined. Methods and procedures for search and recovery are also discussed. Both an interim system and a more advanced system are outlined. Controlled acoustic emission to enhance security is the theme followed.

Lovelady, R. W.↗

L-Band Digital Aeronautical Communications System Engineering - Initial Safety and Security Risk Assessment and Mitigation

This document is being provided as part of ITT's NASA Glenn Research Center Aerospace Communication Systems Technical Support (ACSTS) contract NNC05CA85C, Task 7: "New ATM Requirements--Future Communications, C-Band and L-Band Communications Standard Development." ITT has completed a safety hazard analysis providing a preliminary safety assessment for the proposed L-band (960 to 1164 MHz) terrestrial en route communications system. The assessment was performed following the guidelines outlined in the Federal Aviation Administration Safety Risk Management Guidance for System Acquisitions document. The safety analysis did not identify any hazards with an unacceptable risk, though a number of hazards with a medium risk were documented. This effort represents a preliminary safety hazard analysis and notes the triggers for risk reassessment. A detailed safety hazards analysis is recommended as a follow-on activity to assess particular components of the L-band communication system after the technology is chosen and system rollout timing is determined. The security risk analysis resulted in identifying main security threats to the proposed system as well as noting additional threats recommended for a future security analysis conducted at a later stage in the system development process. The document discusses various security controls, including those suggested in the COCR Version 2.0.

Zelkin, Natalie↗

Need for research and training reactors for advanced reactor designs

Full text of publication follows. Research and training reactors have served a valuable role in helping train workforce for currently operating fleet of light water reactors. These research and training reactors have been used in reactor laboratory classes to familiarize the students with such vital concepts as approach to criticality, reactor period, neutron moderation, reactivity, flux distribution and leakage, etc. As the industry moves toward advanced non-light-water reactor designs, it is critical that research and training reactors be developed and deployed at university campuses to help train the new generation of nuclear and non-nuclear engineers who are likely to design, build, and operate these advanced reactors. Among the designs currently being pursued for nuclear power generation include molten salt, sodium cooled, and gas cooled designs, with options for various fuel forms. Thus, industry and DOE in collaboration with academic institutions should devise plans on how to familiarize the next generation of nuclear workforce with hands-on experience necessary for such designs. These research and training reactors will play a vital role in familiarizing the future workforce with hands-on experience with concepts associated with fast spectrum reactors, gas cooled reactors, and other features not associated with light water reactors. In addition to classical nuclear engineering concepts, these advanced research and training reactors can also be used for hands-on training as well as for research on features being considered in the design of GEN-IV reactors: cyber security for digital control room operations, hybrid energy system, hydrogen generation, district heating, autonomous control... (author)

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Survey of Cyber Risk Analysis Techniques for Use in the Nuclear Industry

Using traditional probabilistic risk analysis methods for severe accident safety risk management on non-digital systems, structures, and components at nuclear power plants is well-established. In contrast, cyber risk analysis of digital assets is still an immature field with unproven techniques due, in part, to the continuously changing threat environment and the challenge of digital assets failing in unexpected ways. As the nuclear fleet continues to adopt digital instrumentation and control systems, it is increasingly important to have effective and efficient cyber risk analysis techniques to support risk management decisions, such as risk elimination by system redesign or risk mitigation by implementation of prioritized security controls. To understand the state of the art in cyber risk analysis for future research, we surveyed 36 publications across ten application domains. We describe our survey methodology and rate each technique based upon scope, adoptability, and repeatability. In this work, we examine the unique constraints of the nuclear industry and outline the strengths and weaknesses of using the cyber risk analysis techniques in the industry, highlighting gaps with current techniques. We also discuss challenges and potential research directions for advancing the science for both existing and new advanced reactors.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Developing VSC-HVDC Oscillation Damping Control Constraints in Unit Commitment

High-voltage direct current (HVDC) systems within the existing power grids will play a pivotal role in enabling high share of renewable power integration and transportation electrification. There is a need for transmission planning models to accurately capture the impact of VSC-HVDC oscillation damping control on the system planning and model the constraints in the security constrained unit commitment (SCUC) problem. In this paper, the SCUC problem in a hybrid DC-AC grid considering damping on electromechanical inter-area oscillation is studied. An electromechanical oscillation-driven transmission capability constraints are derived from system swing equation and incorporated into the SCUC. Multiple system damping control scenarios are set based on the extracted plausible bounds of damping coefficient and inertia constant to linearize the nonlinear expressions. The SCUC problem with proposed constraints is tested on the Reliability Test System Grid Modernization Lab Consortium (RTS-GMLC) via PLEXOS. The impact of the proposed constraints on regional generation, inertia, power flow, annual system cost, and renewable energy curtailment are fully assessed.

damping control↗

NASA Tech Briefs, March 2007

Topics include: Advanced Systems for Monitoring Underwater Sounds; Wireless Data-Acquisition System for Testing Rocket Engines; Processing Raw HST Data With Up-to-Date Calibration Data; Mobile Collection and Automated Interpretation of EEG Data; System for Secure Integration of Aviation Data; Servomotor and Controller Having Large Dynamic Range; Digital Multicasting of Multiple Audio Streams; Translator for Optimizing Fluid-Handling Components; AIRSAR Web-Based Data Processing; Pattern Matcher for Trees Constructed From Lists; Reducing a Knowledge-Base Search Space When Data Are Missing; Ground-Based Correction of Remote-Sensing Spectral Imagery; State-Chart Autocoder; Pointing History Engine for the Spitzer Space Telescope; Low-Friction, High-Stiffness Joint for Uniaxial Load Cell; Magnet-Based System for Docking of Miniature Spacecraft; Electromechanically Actuated Valve for Controlling Flow Rate; Plumbing Fixture for a Microfluidic Cartridge; Camera Mount for a Head-Up Display; Core-Cutoff Tool; Recirculation of Laser Power in an Atomic Fountain; Simplified Generation of High-Angular-Momentum Light Beams; Imaging Spectrometer on a Chip; Interferometric Quantum-Nondemolition Single-Photon Detectors; Ring-Down Spectroscopy for Characterizing a CW Raman Laser; Complex Type-II Interband Cascade MQW Photodetectors; Single-Point Access to Data Distributed on Many Processors; Estimating Dust and Water Ice Content of the Martian Atmosphere From THEMIS Data; Computing a Stability Spectrum by Use of the HHT; Theoretical Studies of Routes to Synthesis of Tetrahedral N4; Estimation Filter for Alignment of the Spitzer Space Telescope; Antenna for Measuring Electric Fields Within the Inner Heliosphere; Improved High-Voltage Gas Isolator for Ion Thruster; and Hybrid Mobile Communication Networks for Planetary Exploration.

Source record↗