Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Authentication”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 163 records · Page 9

Nuclear Quadrupole Resonance for Substance Detection

This review paper provides a comprehensive overview of recent advances in nuclear quadrupole resonance (NQR) spectroscopy for substance detection, highlighting its principles, methodologies, and applications. The paper elucidates the fundamental physics underlying NQR spectroscopy, emphasizing the interaction between nuclear quadrupole moments and electric field gradients. It explores the various experimental techniques and instrumentation developments that have enabled the sensitive detection and precise characterization of substances containing quadrupolar nuclei. A significant portion of the survey is dedicated to discussing the diverse applications of NQR spectroscopy, including the detection of explosives, drug pharmaceuticals, and material authentication. Furthermore, the survey examines the challenges and limitations associated with NQR spectroscopy, including issues related to signal-to-noise ratio (SNR), temperature dependency, and substance restrictions. Strategies to overcome these challenges are discussed, offering insights into the future directions of NQR spectroscopy research that includes artificial intelligence (AI), internet of things (IoT) integration, incorporating a cloud database for NQR parameter storage, and multi-modal analysis.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Incremental Threshold Scheme Enabled IoT Group Key Management

Cyber landscape evolves rapidly. Internet of Things (IoT) and Edge Computing (EC) have rapidly become an integral part of the modern computing infrastructure. It is expected that there will be more than 50 billion active and connected IoT devices by 2025 [1]. Pervasive IoT/EC creates unprecedented opportunities bridging the gap between previously segregated cyber and physical spaces. However, this progress also brings along new security challenges. IoT devices typically have limited computation, communication, and storage resources. This leads to security architecture designs such as using symmetric keys for group communication. While secure and efficient in stable network settings, symmetric key solutions are ill-adapted for IoT's highly dynamic device mobility behavior and frequent group membership turnover. Whenever IoT members leave a group, the known symmetric keys cannot be made forgotten, posing a serious vulnerability. This leads to frequent re-groupings that require expensive re-authentication, key regeneration, and key redistribution in order to maintain IoT/EC security. We present a novel symmetric key management framework that integrate an Incremental Threshold Scheme (ITS) cryptographical function into communication protocol's key rotation mechanism to allow for secure and efficient symmetric key communication group member node revocation. This ITS-enabled key management framework alleviates the need of frequent and expensive re-grouping and re-keying needed by today's large and dynamic IoT/EC operations. We further applied this ITS-enabled key management framework to a distributed IoT/EC-integrated publish and subscribe framework for applicability validation.

Li, Mingyan↗

Cyber Protection of Grid-Connected Devices Through Embedded Online Security

Cybersecurity research regarding the electric power grid has primarily been focused on protecting the communication layer of grid-connected devices against cyber-attack threats. Although many developed methods have greatly reduced the effects of a cyber-attack on the vulnerabilities of grid-connected devices, discovering new vulnerabilities is inevitable and a constant threat. As a result, the overall reliability and security of network communications with regard to grid-connected devices is a concern. Here, this paper proposes a method that further secures a system by focusing on the control and hardware layer of grid-connected devices. The device’s controller firmware will be validated and authenticated using integrated device emulation resources prior to being activated to control the grid-connected device. This verification process is performed while the controller is online and actively controlling power flows related to the device. Therefore, an attack to the system through a malicious firmware patch would be detected by the online security and rejected while safely maintaining continuous and stable control of the device. This method integrates the concepts of firmware hot-patching, digital twins, and active monitoring into an overall cybersecurity protection system.

cybersecurity↗

Rapid Event Detection via Synchro-Waveform Based Temporal Attention Network in Distributed Grid

Compared with the information collected from phasor measurement units, synchro-waveforms contain high-fidelity disturbances of the grid, which can be a granular and authentic representation of measurements in the modern power system. However, the dynamic changing morphology makes it challenging to effectively capture various disturbance information from the synchro-waveforms. To tackle this issue, this paper proposes a Synchro-waveform based Temporal Attention (STA) network to achieve rapid event detection. First, a multi-scenario distributed model with renewable integration is established to generate synchro-waveforms under various uncertainties. Then, three typical temporal features are extracted directly from the synchro-waveform measurements. Additionally, the lightweight STA network is deployed to identify the most common event types in renewable energy systems via the self-attention based vision transformer module. The results from simulated experiments demonstrate that the proposed approach can achieve rapid and real-time detection within 0.81 ms and over 96.27 % accuracy.

Dong, Yuqing [University of Tennessee (UT)]↗

Disruption of Commercial Solar Inverter System by TLS Proxy Man-in-the-Middle Attack

Transport Layer Security (TLS) is a cryptographic protocol that encrypts communication data, providing end-to-end communication encryption and authentication. Currently, TLS is widely adopted for securing communication between servers and end devices, including solar inverter systems. Therefore, users/operators can securely access the solar inverters through a web user interface (WebUI) application programmable interface (API) on a PC or server over TLS-enabled Wi-Fi or Ethernet. However, the security of the TLS-based network becomes compromised if it is breached by a TLS proxy man-in-the-middle (MITM) exploit. This report explores potential vulnerabilities in a commercial solar inverter system that leverages a TLS proxy MITM and discusses the impacts through assume-breached penetration testing. Furthermore, the paper explores recommended mitigation methods against the TLS proxy MITM exploit in solar inverters.

97 MATHEMATICS AND COMPUTING↗

A Cryptographic Method for Defense Against MiTM Cyber Attack in the Electricity Grid Supply Chain

Critical infrastructures such as the electricity grid can be severely impacted by cyber-attacks on its supply chain. Hence, having a robust cybersecurity infrastructure and management system for the electricity grid is a high priority. This paper proposes a cyber-security protocol for defense against man-in-the-middle (MiTM) attacks to the supply chain, which uses encryption and cryptographic multi-party authentication. A cyber-physical simulator is utilized to simulate the power system, control system, and security layers. The correctness of the attack modeling and the cryptographic security protocol against this MiTM attack is demonstrated in four different attack scenarios.

Paul, Shuva↗

Integrating AEAD Ciphers into Software-Defined-Storage Systems

The use of software-defined storage (SDS) systems to store sensitive data is becoming increasingly prevalent. However, these systems primarily implement security measures to ensure the confidentiality and availability of stored data, with limited consideration for the protection of its integrity. This paper outlines why this is a harmful development, as well as how integrity-protecting measures can be included into SDS systems. To demonstrate the practical challenges and opportunities of such measures, we integrated "authenticated encryption with associated data" (AEAD) ciphers into the widely used SDS system Ceph, specifically, into its block storage interface, to secure the integrity of stored data and metadata. Ultimately, we identify the characteristics that an SDS system should possess to adopt our methodology.

Mohren, David [University of New Brunswick, Canada↗

An Extensible Software and Communication Platform for Distributed Energy Resource Management

This paper introduces a novel Distributed Extensible Grid Control (DEGC) software and communication platform to facilitate the control of distributed energy resources on electric grids. The DEGC software platform leverages state-of-the-art advances in secure, distributed communication and decentralized authorization and authentication. We discuss how these advances enable the kind of robust and secure communication required for a distributed grid control platform, and show how DEGC applies these technologies to the agile development and deployment of grid software through an extensible and flexible API. Here, we describe how DEGC can implement both Volt-VAR voltage magnitude control and Phasor-Based Control as sample applications and demonstrate the DEGC platform in hardware with the demanding Phasor-Based Control test case, and provide performance metrics.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Achieving Runtime State Verification Assurance in Critical Cyber-Physical Infrastructures

Industrial Cyber-Physical Systems (ICPS) are an essential backbone of national critical infrastructures. They help monitor and control crucial cyber-enabled services such as energy generation. Commonly ICPS monitors the physical process through Supervisory Control and Data Acquisition (SCADA) systems. The SCADA ecosystem takes critical real-time and future system operational decisions based on the runtime state behavior of field sensors. Traditional SCADA systems use legacy and insecure communication protocols such as the Modbus protocol that lack adequate security mechanisms to provide robust runtime state behavior assurance of constrained field sensors. Therefore, constrained field sensors are commonly vulnerable to standard semantic attacks that gradually change the behavior state of infected devices. This paper discusses process integrity assurance techniques necessary to enhance the security of behavior-based protocols such as the Modbus protocol. The Runtime State Verification (RSV) protocol proposed in this paper aims to address semantic attacks in the SCADA ecosystem by integrating behavior-based Mandatory Results Automata (MRA) and a Hyperledger Fabric (HLF) network. The RSV protocol provides high process integrity assurance through enhanced behavior-based MRA suitable for the constrained field devices. A proof of concept of the RSV protocol has been evaluated in an emulated water-tube boiler. Preliminary evaluations of the RSV protocol aimed to measure the efficiency of the proposed protocol by monitoring an Combustion Efficiency (CE) process necessary to preserve optimal combustion, thus minimizing costs and future maintenance of water-tube boilers. We analyze the overall network overhead and latency of the proposed RSV protocol by evaluating the HLF network performance and comparing the proposed RSV protocol with the state-ofart BloSPAI protocol. Through the preliminary evaluations of the proposed RSV protocol, this paper demonstrates that the proposed RSV protocol overcomes the shortcomings and network overhead of the BloSPAI protocol by integrating behavior-based authentication through novel MRAs and HLF networks.

Rivera, Abel Gomez↗

Alerga: Alert Aggregation and Reasoning in GOOSE Simulation Pipeline

IEC 61850 specifies the Generic Object Oriented Substation Event (GOOSE) protocol as one option for low latency communication of substation-related events. Due to its strict timing requirements, GOOSE lacks any form of encryption or authentication and has only minimal integrity guarantees. These absences render the protocol vulnerable to a variety of communication anomalies, including adversarial action. In particular, an adversary with access to the substation network can launch man in the middle (MITM) attacks. We propose Alerga, a set of tools to allow operators to mitigate some of the risks of the protocol while retaining its strengths. To that end, we have developed first a GOOSE simulation pipeline including data generation, anomaly detection, alert handling, causal reasoning and data visualization components. The simulator is designed to be modular, allowing operators to swap components to better fit their network capabilities. The volume of alert traffic on a substation network threatens operators with alert fatigue. In order to combat this, we secondly present a novel form of alert aggregation and processing, offering operators a condensed view of any threats to the system. Thirdly, to facilitate the handling of these threats, our causal reasoning system traces the alerts back to their most likely cause, generating an initial hypothesis for operators to investigate.

alert aggregation↗

Dynamic Role-Based Access Control Policy for Smart Grid Applications: An Offline Deep Reinforcement Learning Approach

Role-based access control (RBAC) is adopted in the information and communication technology domain for authentication purposes. However, due to a very large number of entities within organizational access control (AC) systems, static RBAC management can be inefficient, costly, and can lead to cybersecurity threats. In this paper, a novel hybrid RBAC model is proposed, based on the principles of offline deep reinforcement learning (RL) and Bayesian belief networks. The considered framework utilizes a fully offline RL agent, which models the behavioral history of users as a Bayesian belief-based trust indicator. Thus, the initial static RBAC policy is improved in a dynamic manner through off-policy learning while guaranteeing compliance of the internal users with the security rules of the system. By deploying our implementation within the smart grid domain and specifically within a Distributed Energy Resources (DER) ecosystem, we provide an end-to-end proof of concept of our model. Finally, detailed analysis and evaluation regarding the offline training phase of the RL agent are provided, while the online deployment of the hybrid RL-based RBAC model into the DER ecosystem highlights its key operation features and salient benefits over traditional RBAC models.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Fast Local Spatial Verification for Feature-Agnostic Large-Scale Image Retrieval

Images from social media can reflect diverse viewpoints, heated arguments, and expressions of creativity, adding new complexity to retrieval tasks. Researchers working on Content-Based Image Retrieval (CBIR) have traditionally tuned their algorithms to match filtered results with user search intent. However, we are now bombarded with composite images of unknown origin, authenticity, and even meaning. With such uncertainty, users may not have an initial idea of what the search query results should look like. For instance, hidden people, spliced objects, and subtly altered scenes can be difficult for a user to detect initially in a meme image, but may contribute significantly to its composition. It is pertinent to design systems that retrieve images with these nuanced relationships in addition to providing more traditional results, such as duplicates and near-duplicates — and to do so with enough efficiency at large scale. In this work, we propose a new approach for spatial verification that aims at modeling object-level regions using image keypoints retrieved from an image index, which is then used to accurately weight small contributing objects within the results, without the need for costly object detection steps. We call this method the Objects in Scene to Objects in Scene (OS2OS) score, and it is optimized for fast matrix operations, which can run quickly on either CPUs or GPUs. It performs comparably to state-of-the-art methods on classic CBIR problems (Oxford 5K, Paris 6K, and Google-Landmarks), and outperforms them in emerging retrieval tasks such as image composite matching in the NIST MFC2018 dataset and meme-style imagery from Reddit.

42 ENGINEERING↗

A Privacy-Preserving Cyber Threat Intelligence Sharing System

Cyber Threat Intelligence (CTI) is a key resource for developing defensive strategies against potential cyber adversaries. Entities typically access CTI through open-source platforms, national agencies, or specialized commercial services. However, the bi-directional exchange of CTI is hindered by organizational trust boundaries, which complicate the sharing processes between entities and CTI providers. Centralized CTI services benefit from receiving suspicious cyber observables such as IP addresses, domain names, and email addresses from various entities. The aggregation allows for the correlation of widespread adversarial activities to enhance the alert and response mechanisms across the network of involved parties. Despite these benefits, openly sharing such observables incurs potential legal, regulatory, and reputational risks for the disclosing entities.This paper introduces a system designed to facilitate the secure exchange of cyber observables across trust boundaries without compromising the anonymity of the sharing entities. Here, we propose an architecture that leverages common web protocols alongside zero-knowledge proofs to authenticate members while maintaining anonymity. Additionally, we outline a privacy model tailored for STIX (Structured Threat Information eXpression) cyber observables to minimize the risk of inadvertently disclosing private information. Through our threat models, we assess the privacy implications of our proposed system and demonstrate its potential to enhance collaborative cyber defense efforts without exposing entities to undue risk.

BBS+ Signatures↗

Synchronized Waveforms – A Frontier of Data-Based Power System and Apparatus Monitoring, Protection, and Control

Voltage and current waveforms contain the most authentic and granular information on the behaviors of power systems. In recent years, it has become possible to synchronize waveform data measured from different locations. Thus large-scale coordinated analyses of multiple waveforms over a wide area are within our reach. This development could unleash a set of new concepts, strategies, and tools for monitoring, protecting, and controlling power systems and apparatuses. This paper presents an in-depth review and analysis of the advancements in synchronized waveform data, including measurement devices, data characteristics, use cases, and comparisons with synchrophasor data. Based on the findings, five strategies are proposed to discover and develop synchronized waveform based applications over multiple application areas. The paper also presents three complementary measurement platforms and two data screening algorithms for application implementation. It further discusses committee activities and standard developments useful to explore the full potential of the data.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Perturbation-Based Diagnosis of False Data Injection Attack Using Distributed Energy Resources

Modern smart grid relies on various sensor measurements for its operational control. In a successful false data injection attack, the attacker manipulates the measurements from the grid sensors such that undetected errors are introduced into the estimates of the system parameters leading to catastrophic situations. This paper proposes a novel perturbation based false data injection attack detection mechanism that utilizes inverter based distributed energy resources (DERs) to create low magnitude perturbation signal in the distribution system voltage that is inconsequential to the normal grid operation. Two voltage sensitivity analysis based algorithms are designed to identify the optimal set of DERs that can create the voltage perturbation signal of desired magnitude. An analytical method of voltage sensitivity analysis is used to compute the magnitude of voltage perturbation signal at each node in a computationally efficient manner. Then, a detection mechanism is developed that checks for the presence of the perturbation sequence in each sensor measurement. A sensor measurement is deemed authentic if the voltage perturbation signal is present in the data. In case of sensor malfunction or cyber-attack, the perturbation signal will not be present in the measurement data. Performance of the proposed attack detection mechanism is validated via simulation of the IEEE 69 bus test system.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Multifractal Characterization of Distribution Synchrophasors for Cybersecurity Defense of Smart Grids

“Source ID Mix” spoofing emerged as a new type of cyber-attack on Distribution Synchrophasors (DS) where adversaries have the capability to swap the source information of DS without changing the measurement values. Accurate detection of such a highly-deceptive attack is a challenging task especially when the spoofing attack happens on short fragments of DS recorded within a relatively small geographical scale. Herein this letter proposes an effective approach to detect this cyber-attack by realizing the multifractal characteristics of DS measurements. First, the multifractal cross-correlation of DS measured at multiple intra-state locations is revealed. Then the derived correlation is integrated with weighted two-dimensional multifractal surface interpolation to reconstruct quasi high-resolution signals. Finally, informative location-specific signatures are extracted from the high-resolution DS and they are integrated with advanced machine learning techniques for source authentication. Experiments using the real-life DS are performed to verify the proposed method.

24 POWER TRANSMISSION AND DISTRIBUTION↗

The reactivity of experimentally reduced lunar regolith simulants: Health implications for future crewed missions to the lunar surface

Crewed missions to the Moon may resume as early as 2026 with NASA's Artemis III mission, and lunar dust exposure/inhalation is a potentially serious health hazard that requires detailed study. Current dust exposure limits are based on Apollo-era samples that spent decades in long-term storage on Earth; their diminished reactivity may lead to underestimation of potential harm that could be caused by lunar dust exposure. In particular, lunar dust contains nanophase metallic iron grains, produced by “space weathering”; the reactivity of this unique component of lunar dust is not well understood. Herein, we employ a chemical reduction technique that exposes lunar simulants to heat and hydrogen gas to produce metallic iron particles on grain surfaces. We assess the capacity of these reduced lunar simulants to generate hydroxyl radical (OH*) when immersed in deionized (DI) water, simulated lung fluid (SLF), and artificial lysosomal fluid (ALF). Lunar simulant reduction produces surface-adhered metallic iron “blebs” that resemble nanophase metallic iron particles found in lunar dust grains. Reduced samples generate ~5–100× greater concentrations of the oxidative OH* in DI water versus non-reduced simulants, which we attribute to metallic iron. SLF and ALF appear to reduce measured OH*. The increase in observed OH* generation for reduced simulants implies high oxidative damage upon exposure to lunar dust. Low levels of OH* measured in SLF and ALF imply potential damage to proteins or quenching of OH* generation, respectively. Reduction of lunar dust simulants provides a quick cost-effective approach to study dusty materials analogous to authentic lunar dust.

54 ENVIRONMENTAL SCIENCES↗

Information theory and machine learning illuminate large‐scale metabolomic responses of Brachypodium distachyon to environmental change

SUMMARY Plant responses to environmental change are mediated via changes in cellular metabolomes. However, <5% of signals obtained from liquid chromatography tandem mass spectrometry (LC‐MS/MS) can be identified, limiting our understanding of how metabolomes change under biotic/abiotic stress. To address this challenge, we performed untargeted LC‐MS/MS of leaves, roots, and other organs of Brachypodium distachyon (Poaceae) under 17 organ–condition combinations, including copper deficiency, heat stress, low phosphate, and arbuscular mycorrhizal symbiosis. We found that both leaf and root metabolomes were significantly affected by the growth medium. Leaf metabolomes were more diverse than root metabolomes, but the latter were more specialized and more responsive to environmental change. We found that 1 week of copper deficiency shielded the root, but not the leaf metabolome, from perturbation due to heat stress. Machine learning (ML)‐based analysis annotated approximately 81% of the fragmented peaks versus approximately 6% using spectral matches alone. We performed one of the most extensive validations of ML‐based peak annotations in plants using thousands of authentic standards, and analyzed approximately 37% of the annotated peaks based on these assessments. Analyzing responsiveness of each predicted metabolite class to environmental change revealed significant perturbations of glycerophospholipids, sphingolipids, and flavonoids. Co‐accumulation analysis further identified condition‐specific biomarkers. To make these results accessible, we developed a visualization platform on the Bio‐Analytic Resource for Plant Biology website ( https://bar.utoronto.ca/efp_brachypodium_metabolites/cgi‐bin/efpWeb.cgi ), where perturbed metabolite classes can be readily visualized. Overall, our study illustrates how emerging chemoinformatic methods can be applied to reveal novel insights into the dynamic plant metabolome and stress adaptation.

59 BASIC BIOLOGICAL SCIENCES↗