Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Secure by Design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 145 records · Page 8

Trade-off Analysis of Operational Technologies to Advance Cyber Resilience through Automated and Autonomous Response to Threats

The advancement of cyber resilience requires a preliminary stage of characterizing the trade-off space of mitigation options and how these might affect the stability and determinism of an operational technology (OT). This first step will set the stage for the proper cyber-secure and cyber-resilient design and confirm the affects that can be considered and approved by the OT and the security groups. To provide a baseline for this discussion, this paper provides a consideration of the cyberphysical interactions, possible mitigation steps against certain attacks and their corresponding affects that lend to the security design planning and evaluation process. As an integral part of the proposed scheme this work introduces the concept of systemwide fuzzer, i.e., a tool that manipulates the system state in an effort to determine mitigation response sequences that minimize detriments and maximize benefit in accordance with specified operational requirements.

97 MATHEMATICS AND COMPUTING↗

Physical Security Model Development of an Electrochemical Facility

Nuclear facilities in the U.S. and around the world face increasing challenges in meeting evolving physical security requirements while keeping costs reasonable. The addition of security features after a facility has been designed and without attention to optimization (the approach of the past) can easily lead to cost overruns. Instead, security should be considered at the beginning of the design process in order to provide robust, yet efficient physical security designs. The purpose of this work is to demonstrate how modeling and simulation can be used to optimize the design of physical protection systems. A suite of tools, including Scribe3D and Blender, were used to model a generic electrochemical reprocessing facility. Physical protection elements such as sensors, portal monitors, barriers, and guard forces were added to the model based on best practices for physical security. Two theft scenarios (an outsider attack and insider diversion) as well as a sabotage scenario were examined in order to optimize the security design. Security metrics are presented. This work fits into a larger Virtual Facility Distributed Test Bed 2020 Milestone in the Material Protection, Accounting, and Control Technologies (MPACT) program through the Department of Energy (DOE). The purpose of the milestone is to demonstrate how a series of experimental and modeling capabilities across the DOE complex provide the capabilities to demonstrate complete Safeguards and Security by Design (SSBD) for nuclear facilities.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Decision Engines for Software Analysis Using Satisfiability Modulo Theories Solvers

The area of software analysis, testing and verification is now undergoing a revolution thanks to the use of automated and scalable support for logical methods. A well-recognized premise is that at the core of software analysis engines is invariably a component using logical formulas for describing states and transformations between system states. The process of using this information for discovering and checking program properties (including such important properties as safety and security) amounts to automatic theorem proving. In particular, theorem provers that directly support common software constructs offer a compelling basis. Such provers are commonly called satisfiability modulo theories (SMT) solvers. Z3 is a state-of-the-art SMT solver. It is developed at Microsoft Research. It can be used to check the satisfiability of logical formulas over one or more theories such as arithmetic, bit-vectors, lists, records and arrays. The talk describes some of the technology behind modern SMT solvers, including the solver Z3. Z3 is currently mainly targeted at solving problems that arise in software analysis and verification. It has been applied to various contexts, such as systems for dynamic symbolic simulation (Pex, SAGE, Vigilante), for program verification and extended static checking (Spec#/Boggie, VCC, HAVOC), for software model checking (Yogi, SLAM), model-based design (FORMULA), security protocol code (F7), program run-time analysis and invariant generation (VS3). We will describe how it integrates support for a variety of theories that arise naturally in the context of the applications. There are several new promising avenues and the talk will touch on some of these and the challenges related to SMT solvers. Proceedings

Bjorner, Nikolaj↗

AgMIP Training in Multiple Crop Models and Tools

The Agricultural Model Intercomparison and Improvement Project (AgMIP) has the goal of using multiple crop models to evaluate climate impacts on agricultural production and food security in developed and developing countries. There are several major limitations that must be overcome to achieve this goal, including the need to train AgMIP regional research team (RRT) crop modelers to use models other than the ones they are currently familiar with, plus the need to harmonize and interconvert the disparate input file formats used for the various models. Two activities were followed to address these shortcomings among AgMIP RRTs to enable them to use multiple models to evaluate climate impacts on crop production and food security. We designed and conducted courses in which participants trained on two different sets of crop models, with emphasis on the model of least experience. In a second activity, the AgMIP IT group created templates for inputting data on soils, management, weather, and crops into AgMIP harmonized databases, and developed translation tools for converting the harmonized data into files that are ready for multiple crop model simulations. The strategies for creating and conducting the multi-model course and developing entry and translation tools are reviewed in this chapter.

farm crops↗

Material Control & Accountancy for Molten Salt Reactors (FY2021 Report)

There is significant domestic and international interest, investment, and research and development momentum to pursue advanced nuclear reactor technologies. Molten salt reactor (MSR) concepts display the largest variability in fuel type and design features among the current advanced concepts. MSRs have been proposed with various core designs, sizes (power), and fuel cycles. Salt-fueled molten salt systems represent the only advanced reactor type with fuel that is not in a solid form during operation. These “liquid-fueled” MSRs are unique from perspectives of fuel fabrication, spent irradiated fuel and waste components, licensing, and material control and accountability (MC&A) including the potential of fissile material holdup. The liquid fuel salt is the defining distinction in comparison to other advanced reactors that propose TRI-structural ISOtropic particle fuel pebbles, various coolant options (e.g., molten salts or metals, high temperature gas), or small modular alternatives using solid fuel variants including both light water reactors and non-light water reactors. MSRs are appealing to the nuclear energy industry because of the diverse reactor characteristics they can support including various neutron energy spectra, fueling requirements, fuel cycles, and/or fuel utilization. However, because of the significant deviation and diversity of a salt-fueled system compared to traditional solid fuel light water-cooled reactors (LWRs), the history, regulatory licensing framework, modeling capabilities, and supporting engineering technology are either lacking or, in some cases, nonexistent. Therefore, the research community is actively supporting advanced MSR development on many of these fronts in particular to assist MSR vendors with licensing requirements. ORNL is leading the research and development of respective MC&A approaches for salt-fueled MSRs. This report summarizes the research performed at Oak Ridge National Laboratory (ORNL) under the US Department of Energy, Office of Nuclear Energy, Advanced Reactor Safeguards (ARS) program to investigate safeguards and security by design concepts, licensing and regulatory considerations, and dynamic system-level modeling to understand radioisotope concentrations for salt-fueled MSRs. The report builds upon the previous research and literature, identifies the MC&A challenges inherent to a salt-fueled MSR, reviews current regulatory frameworks for LWRs and their applicability towards salt-fueled MSRs, summarizes the status and progress of an MSR dynamic modeling tool, and discusses a prospective MC&A approach based on the Molten Salt Demonstration Reactor (MSDR) model.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Enabling Design Space Exploration for RISC-V Secure Compute Environments

Cycle-level architectural simulation of Trusted Execution Environments (TEEs) can enable extensive design space exploration of these secure architectures. Existing architectural simulators which support TEEs are either based on hardware-level implementations or abstract analytic models. In this paper, we describe the implementation of the gem5 models necessary to run and evaluate the RISC- V-based open source TEE, Keystone, and we discuss how this simulation environment opens new avenues for designing and studying these trusted environments. We show that the Keystone simulations on gem5 exhibit similar performance as the previous hardware evaluations of Keystone. We also describe three simple example use cases (understanding the reason of trusted execution slowdown, performance of memory encryption, and micro-architecture impact on trusted execution performance) to demonstrate how the ability to simulate TEEs can provide useful information about their behavior in the existing form and also with enhanced designs.

97 MATHEMATICS AND COMPUTING↗

Impact of cyberattacks on safety and stability of connected and automated vehicle platoons under lane changes

Connected and automated vehicles (CAVs) offer a huge potential to improve the operations and safety of transportation systems. However, the use of smart devices and communications in CAVs introduce new risks. CAVs would leverage vehicle to vehicle (V2V) and vehicle to infrastructure (V2I) communication, thus providing additional system access points compared to traditional systems. Automation makes these systems more vulnerable and increases the consequences of cyberattacks. This study utilizes an infrastructure-based communication platform consisting of cooperative adaptive cruise control and lane control advisories developed by the authors to perform cyber risk assessment of CAVs. The study emulates three types of cyberattacks (message falsification, dedicated denial of service, and spoofing attacks) in a representative traffic environment consisting of multiple CAV platoons and lane change events to analyze the safety and stability impacts of the cyberattacks. Simulation experiments using VISSIM reveals that traffic stream and CAV string is unstable under all three types of cyberattacks. The worst case is represented by the message falsification attack. Increases in volatility are observed over a no attack case, with variations increasing by an average of 43%–51% along with an increase of over 3000 crash conflicts. Similarly, lane change crash conflicts are observed to be more severe compared to rear end crash conflicts, showing a higher probability of severe injuries. Further, the case of slight cyberattack on a single CAV also creates significant disruption in the traffic stream. Analysis of variance (ANOVA) reveals the statistical significance of the results. Furthermore, these results pave the way for future design of secure systems from a monitoring perspective.

97 MATHEMATICS AND COMPUTING↗

A technique to make an enterprise network a Darknet on the Internet, while providing required services to authorized users

In a well-designed and secure enterprise network, the hosts inside the network are not directly accessible from the Internet. The enterprise firewall blocks direct access to hosts inside the enterprise network and also blocks any attempts to probe or discover information about those hosts from the Internet. However, access to the enterprise network from the Internet is a must in today’s day and age. Hence, specialized mechanisms to allow secure access are implemented.

97 MATHEMATICS AND COMPUTING↗

Advanced Radiation Panel design for applications in National Security and Food Safety

We describe a new concept for a basic radiation detection panel based on conventional scintillator technology and commercially available solid-state photo-detectors. The panels are simple in construction, robust, very efficient and cost-effective and are easily scalable in size, from tens of cm 2 to tens of m 2 . We describe two possible applications: flagging radioactive food coontamination and detection of illicit radio nucleides, such as those potentially used in a terrorist attack with a dirty bomb.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Cyber100 Compass User Guide

This document provides an overview of the Cyber100 Compass tool and serves as a guide to users interested in understanding the cybersecurity risks facing their clean energy transition. The National Renewable Energy Laboratory (NREL) developed the Cyber100 Compass tool for cyber risk assessment at the system-of-systems level for system planners trying to reach high levels of renewables. Two offices of the U.S. Department of Energy (DOE) - the Office of Electricity and the Office of Cybersecurity, Energy Security, and Emergency Response-funded NREL to develop this framework that will enable grid system planners to understand and mitigate cybersecurity risk for grids transitioning to high levels of renewable generation, including 100%. Cyber100 Compass can help systems planners apply the principle of security-by-design at scale. Investing in an upfront understanding of system-of-systems (where the constituent systems are operating entities of the different renewable resources) risks from high-renewable grids will result in a more resilient grid at a lower long-term cost.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Nuclear Material Control & Accounting for Pebble Bed Reactors (FY 2023 Summary Report)

This report discusses the work done under the US Department of Energy NE-5 Advanced Reactor Safeguards and Security Program during FY 2023. It provides a summary of material control and accounting (MC&A) for pebble bed reactors (PBRs) and addresses some of the main challenges with current PBR MC&A approaches that will inform safeguards and security by design efforts. The efforts to date have focused on tristructural isotropic (TRISO) pebble fuel material accounting and control including working with partners in industry, loss and production of nuclear material as part of reactor operations, burnup modeling and measurements, uncertainty quantifications for such modeling and measurements, statistical approaches needed, and measurement methods. The unique fuel management and utilization in a PBR, where the fuel in spherical form is introduced and circulates through the reactor, poses special challenges for MC&A. This contrasts with traditional water-cooled reactors in which the fuel is contained in large assemblies and can be easily identified and counted. Even online fueled reactors, such as the CANDU reactors (none of which operate in the United States), are significantly different because the fuel is still contained in relatively large assemblies, is uniquely identified, and the number of assemblies that pass through the core on an annual basis is much fewer than the hundreds of thousands that circulate in a PBR, none of which are uniquely identified. Additionally, the nature of the TRISO fuel results in very low heavy metal loading with each pebble containing less than 10 g of uranium and on the order of less than 1 g of fissile material. This low fuel density and the robustness of the TRISO particles are major features of the TRISO fuel from a safety basis as each TRISO particle and pebble acts as a containment for the nuclear material and fission products during normal and accident conditions. This also results in very low plutonium loading per pebble during normal operations, which is on the order of 0.1 g at full burnup. A major feature of PBRs is that they will allow for significantly higher burnup, on the order of 160 GWd/THM compared to the burnup of traditional LWRs, which is on the order of 45 GWd/THM. This is achieved by monitoring the pebbles as they circulate through the reactor and allowing them to be reintroduced into the core until the desired burnup is achieved and they are removed from the reactor and enter the spent fuel storage areas.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Advanced Reactor Safeguards and Security - Advanced Delay Technologies

As a new generation of reactors is developed, reducing the cost of physical security without impacting the required system effectiveness will help to make new reactors economical. This report discusses several access delay technologies available to help improve the overall effectiveness of the physical security system. These technologies include both passive and active delay elements, as well as guidance on best practices related to security by design principles.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Autonomous Inverter Controls for Resilient and Secure Grid Operation: Vector Control Design for Grid Forming

The project addresses both fundamental and practical challenges of GFM/GFL inverter control for the power grids with high inverter based resources (IBRs) penetration. A data- driven modeling technique is applied to accurately model dynamics of PWM inverters, including electromagnetic-transient (EMT). Systematic and integrative designs of grid- forming (GFM) and grid-following (GFL) primary controls are developed to guarantee system performance under either normal or abnormal operating conditions without violating constraints. This modeling and control framework provides black-start capability in case of an outage without relying on rotating generators, and its secondary control is also shown to enhance resilience against cyber-physical attacks.

14 SOLAR ENERGY↗

ARCADE Technical Pathway and Industry Impact

The Advanced Reactor Cyber Analysis and Development Environment (ARCADE) simplifies the evaluation and assessment of robustness factor and cyber resilience that support secure-by-design for advanced reactor nuclear power plants. In this manner, ARCADE supports risk-informed performance based (RIPB) evaluations of cybersecurity through its integration of plant physics with high-fidelity emulations of control systems. This cross domain approach enables comprehensive analysis of control system sensitivities, cyber-attack scenarios, and their consequences. ARCADE has been custom developed to meet the demands identified in Tier 1 of the Tiered Cyber Analysis (TCA) as outlined in NRC Draft Regulation Guide (RG) 5.96, which provides a RIPB cybersecurity approach for new reactors.

97 MATHEMATICS AND COMPUTING↗

Cyber-Physical Tabletop Exercise for Small Modular Reactor Facilities

U.S. nuclear power facilities face increasing challenges in meeting dynamic security requirements caused by evolving and expanding threats while keeping costs reasonable to make nuclear energy competitive. This evolving threat landscape includes adversaries having offensive cyber capabilities to attack information technology (IT) systems and operation technology (OT) systems. These adversaries may have the ability to attack the physical protection system (PPS) networks with potential consequential impacts that could degrade the effectiveness of the PPS. These cyber attacks may also be used to attack the safety and operational systems used to operate and ensure the safety of the reactor. Additionally, adversaries may gain access to unmanned aerial systems (UAS) that may be used to provide reconnaissance and surveillance of the facility, provide information to the adversaries, and be equipped with kinetic capabilities such as explosives or weapons that can be used to directly attack the facility. The Department of Energy’s Office of Nuclear Energy’s Advanced Reactor Safeguards and Security (ARSS) program funded Sandia National Laboratories (SNL) and Idaho National Laboratory (INL) to develop a cyber-physical tabletop exercise (TTX). This exercise was conducted on a hypothetical small modular reactor (SMR) facility, and only considered a potential adversary cyber attack on the PPS to a physical attack on the hypothetical facility to achieve a radiological release. This cyber-physical TTX is meant to provide lessons learned to integrate the cyber security system design and the physical protection system (PPS) design to decrease design, operation, and maintenance costs as well as increase effectiveness for defending against design basis threat attacks at the facility. This TTX will also provide a framework and method for SMR and microreactor vendors to conduct their own cyber-physical TTX and gain impactful insights to improving the cyber and physical protection system design for their SMR or microreactor facility design.

42 ENGINEERING↗

Cybersecurity Risk Profiles for Distributed Energy Resource Management Systems

Managing the digitalization of increasingly diversity energy resources is a complex challenge for energy systems planners and managers. As the penetration of solar photovoltaics (PV) and other distributed renewable energy resources (DERs) expands, distributed energy resource management systems (DERMS) will play an increasingly important role in managing, monitoring, and controlling DERs as electric systems before more distributed, interconnected, and networked. However, the cybersecurity implications of DERMS deployments are not well understood today. A lack of understanding around the cybersecurity implications of DERMS deployments and variability in the security posture of DERMS vendors, owners, and operators could introduce new security risks to evolving electric power systems. This paper describes cybersecurity attack scenarios on DERMS, identifies related cybersecurity standards and guidelines, reviews the security features of state-of-the-art DERMS solutions, and offers cybersecurity guidance for DERMS vendors, owners, and operators to protect DERMS' unique capabilities. Standardizing cybersecurity requirements for DERMS could help improve the security of DERMS integrations and improve innovations that are more secure by design. The cybersecurity guidance found in this paper is intended to offer a unified approach and lay the foundation for future standardization of DERMS cybersecurity to reduce risk to the solar industry and other renewable energy stakeholders when integrating these technologies with electric power systems.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Hand-Held Power Clamp

Tool furnishes large pushing or pulling forces. Device includes two clamping blocks, two clamping plates, and a motor-driven linear actuator with selflocking screw shaft. Power clamp exerts opening or closing force at push of switch. Tool approximately 1 m long. Originally designed to secure payload aboard Space Shuttle, operated with one hand to apply opening or closing force of up to 1,000 lb (4,400 N). Clamp has potential applications as end effector for industrial robots and in rescue work to push or pull wreckage with great force.

Clancy, J. P.↗