Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Hardware Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 163 records · Page 9

Chapter Nine - Automated Optimal Control in Energy Systems: The Reinforcement Learning Approach

With the development of smart grid technologies an increasing number of new devices and participants have joined modern energy systems and are inevitably making them more complicated and interdependent than ever. Optimally controlling such a complex energy system and maintaining its operation in a high-efficient, secure, and resilient manner are challenging tasks to the system operators. Fortunately, the revolution in deep learning and artificial intelligence (AI), both from hardware and algorithms perspectives, has provided new ideas and solutions to many previously intractable problems. As a result, this advance in computer science also sparked great research interests in utilizing AI in solving engineering problems related to the modern energy systems. Among many AI techniques, deep reinforcement learning (DRL) has demonstrated great potential for solving sequential optimization problems, which are very common in the engineering domains. Its ability to handle nonlinearity and stochasticity in controlled systems has out-competed many traditional optimal control algorithms. Therefore in this chapter, we focus on the state-of-the-art of DRL concepts and related algorithms, compare their pros and cons with traditional optimal control approaches and discuss the typical workflow for leveraging RL in solving complex problems in modern energy systems.

artificial intelligence↗

Switched Band-Pass Filters for Adaptive Transceivers

Switched band-pass filters are key components of proposed adaptive, software- defined radio transceivers that would be parts of envisioned digital-data-communication networks that would enable real-time acquisition and monitoring of data from geographically distributed sensors. Examples of sensors to be connected to such networks include security cameras, radio-frequency identification units, and geolocation units based on the Global Positioning System. Through suitable software configuration and without changing hardware, these transceivers could be made to operate according to any of a number of complex wireless-communication standards that could be characterized by diverse modulation schemes, bandwidths, and data-handling protocols. The adaptive transceivers would include field-programmable gate arrays (FPGAs) and digital signal-processing hardware. In the receiving path of a transceiver, the incoming signal would be amplified by a low-noise amplifier (LNA). The output spectrum of the LNA would be processed by a band-pass filter operating in the frequency range between 900 MHz and 2.4 GHz. Then a down-converter would translate the signal to a lower frequency range to facilitate analog-to-digital conversion, which would be followed by baseband processing by one or more FPGAs. In the transmitting path, a digital stream would first be converted to an analog signal, which would then be up-converted to a selected frequency band before being applied to a transmitting power amplifier. The aforementioned band-pass filter in the receiving path would be a combination of resonant inductor-and-capacitor filters and switched band-pass filters. The overall combination would implement a switch function designed mathematically to exhibit desired frequency responses and to switch the signal in each frequency band to an analog-to-digital converter appropriate for that band to produce a digital intermediate-frequency signal for digital signal processing.

Wang, Ray↗

NASA Tech Briefs, June 2012

Topics covered include: iGlobe Interactive Visualization and Analysis of Spatial Data; Broad-Bandwidth FPGA-Based Digital Polyphase Spectrometer; Small Aircraft Data Distribution System; Earth Science Datacasting v2.0; Algorithm for Compressing Time-Series Data; Onboard Science and Applications Algorithm for Hyperspectral Data Reduction; Sampling Technique for Robust Odorant Detection Based on MIT RealNose Data; Security Data Warehouse Application; Integrated Laser Characterization, Data Acquisition, and Command and Control Test System; Radiation-Hard SpaceWire/Gigabit Ethernet-Compatible Transponder; Hardware Implementation of Lossless Adaptive Compression of Data From a Hyperspectral Imager; High-Voltage, Low-Power BNC Feedthrough Terminator; SpaceCube Mini; Dichroic Filter for Separating W-Band and Ka-Band; Active Mirror Predictive and Requirement Verification Software (AMP-ReVS); Navigation/Prop Software Suite; Personal Computer Transport Analysis Program; Pressure Ratio to Thermal Environments; Probabilistic Fatigue Damage Program (FATIG); ASCENT Program; JPL Genesis and Rapid Intensification Processes (GRIP) Portal; Data::Downloader; Fault Tolerance Middleware for a Multi-Core System; DspaceOgreTerrain 3D Terrain Visualization Tool; Trick Simulation Environment 07; Geometric Reasoning for Automated Planning; Water Detection Based on Color Variation; Single-Layer, All-Metal Patch Antenna Element with Wide Bandwidth; Scanning Laser Infrared Molecular Spectrometer (SLIMS); Next-Generation Microshutter Arrays for Large-Format Imaging and Spectroscopy; Detection of Carbon Monoxide Using Polymer-Composite Films with a Porphyrin-Functionalized Polypyrrole; Enhanced-Adhesion Multiwalled Carbon Nanotubes on Titanium Substrates for Stray Light Control; Three-Dimensional Porous Particles Composed of Curved, Two-Dimensional, Nano-Sized Layers for Li-Ion Batteries 23 Ultra-Lightweight; and Ultra-Lightweight Nanocomposite Foams and Sandwich Structures for Space Structure Applications.

Source record↗

Gridtrust: Electricity Grid Root-of-Trust Decentralized Supply Chain Cyber-Security (Final Scientific/Technical Report)

GridTrust represents a departure from reliance on a single organization or a single person to multiple organizations and therefore multiple people across organizational structures. The motivating idea behind involving multiple organizations is the increase in security due to human factors. More specifically, the requirement that distinct people in different organizations sign off on a change or an update makes a cyberattack much less likely due to the inherent requirement that both organizations be penetrated and fooled. GridTrust focuses on the software update process as the primary exemplar for the research and development work. A novel hardware-based technology referred to as a Physical Unclonable Function (PUF) provides a microchip Root-of-Trust (RoT), i.e., a starting point for verifying that the hardware being communicated with is the hardware the control center believes the hardware to be. As a result, staff at power grid control centers can ensure the accurate and reliable identification of hardware devices from the outset. The GridTrust protocol introduces two key innovations, as detailed in this report. Firstly, the utilization of a PUF as a root-of-trust in the initial phase of a software or firmware update. Secondly, the application of multiple cryptographic signatures from two or more organizations to the update binary. These signatures are verified before implementing the update on a power grid device in the field. In terms of GridTrust hardware design, this report outlines two main components. The first is the GridTrust Native Device, integrating PUF technology intrinsically into the hardware device itself. The second is the GridTrust Interfacing Device, which incorporates PUF technology and multiple cryptographic signatures. These signatures are cross-checked within a separate hardware positioned between the power grid control center and the legacy power grid device, functioning as an intermediary. While the GridTrust Interfacing Device offers the advantage of being applicable to existing power grid equipment, it may have reduced security if the intermediary component is targeted. On the other hand, the GridTrust Native Device boasts increased security due to protocol integration within a unified form factor. The effectiveness of GridTrust technology has been extensively demonstrated, with multiple external red-team attackers unable to breach GridTrust's security measures. This was observed both in controlled laboratory settings during Phase 1 of the project and in real-world conditions within a City of Marietta substation during Phase 2 of the project.

24 POWER TRANSMISSION AND DISTRIBUTION↗

CROWBAR: Natively Fuzzing Trusted Applications Using ARM CoreSight

Abstract Trusted execution environments (TEE) are deployed on many platforms to provide both confidentiality and integrity, and their extensive use offers a secure environment for privacy-sensitive operations. Despite TEE prevalence in the smartphone and tablet market, vulnerability research into TEE security is relatively rare. This is, in part, due to the strong isolation guarantees provided by its implementation. In this paper, we propose a hardware assisted fuzzing framework, CROWBAR, that bypasses TEE isolation to natively evaluate trusted applications (TAs) on mobile devices by leveraging ARM CoreSight components. CROWBAR performs feedback-driven fuzzing on commercial, closed source TAs while running in a TEE protected environment. We implement CROWBAR on 2 prototype commercial-off-the-shelf (COTS) smartphones and one development board, finding 3 unique crashes in 5 closed source TAs that are previously unreported in the TrustZone fuzzing literature.

Shan, Haoqi↗

Tunable stochastic memristors for energy-efficient encryption and computing

Information security and computing, two critical technological challenges for post-digital computation, pose opposing requirements – security (encryption) requires a source of unpredictability, while computing generally requires predictability. Each of these contrasting requirements presently necessitates distinct conventional Si-based hardware units with power-hungry overheads. This work demonstrates Cu 0.3 Te 0.7 /HfO 2 (‘CuTeHO’) ion-migration-driven memristors that satisfy the contrasting requirements. Under specific operating biases, CuTeHO memristors generate truly random and physically unclonable functions, while under other biases, they perform universal Boolean logic. Using these computing primitives, this work experimentally demonstrates a single system that performs cryptographic key generation, universal Boolean logic operations, and encryption/decryption. Circuit-based calculations reveal the energy and latency advantages of the CuTeHO memristors in these operations. This work illustrates the functional flexibility of memristors in implementing operations with varying component-level requirements.

97 MATHEMATICS AND COMPUTING↗

Real-Time Testbed for Smart Grid Recloser Controller

The growing need for a low voltage recloser has become apparent due to the rise in requirements for a smart grid. This includes more detailed management of power flow forward (towards load) and backward (towards generation), source synchronization in real time, more indepth fault responses, and the use of green energy. The SEL-651R-2 relay is a device that can manage these needs, especially in fault response and synchronization, and is commonly used in systems called microgrids. Microgrids are distribution level systems that are able to operate separated from the main grid, are typically installed much closer to the load(s), and are fed by distributed energy resources (DERs), such as wind, solar or diesel generators. The SEL-651R-2 is normally used in the field with presets operative settings, but the Western Michigan University (WMU) Center for Interdisciplinary Research on Secure, Efficient and Sustainable Energy Technology (WMU InterEnergy Center) wished to test this device in its range of capabilities for microgrid application. A Hardware-In-the-Loop (HIL) testbed was implemented and used through the Real Time Digital Simulator (RTDS) using the RSCAD software to test the SEL-651R-2's use cases and functions. The testbed includes a microgrid with interconnection to a larger main grid, and the relay is meant to control the recloser at the point of common coupling (PCC) between the main grid and microgrid. The testbed shows how basic protections, reclosing, and synchronization checks function when handling faults that affect both the microgrid and the main grid.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Modernization of B-2 Data, Video, and Control Systems Infrastructure

The National Aeronautics and Space Administration (NASA) Glenn Research Center (GRC) Plum Brook Station (PBS) Spacecraft Propulsion Research Facility, commonly referred to as B-2, is NASA s third largest thermal-vacuum facility with propellant systems capability. B-2 has completed a modernization effort of its facility legacy data, video and control systems infrastructure to accommodate modern integrated testing and Information Technology (IT) Security requirements. Integrated systems tests have been conducted to demonstrate the new data, video and control systems functionality and capability. Discrete analog signal conditioners have been replaced by new programmable, signal processing hardware that is integrated with the data system. This integration supports automated calibration and verification of the analog subsystem. Modern measurement systems analysis (MSA) tools are being developed to help verify system health and measurement integrity. Legacy hard wired digital data systems have been replaced by distributed Fibre Channel (FC) network connected digitizers where high speed sampling rates have increased to 256,000 samples per second. Several analog video cameras have been replaced by digital image and storage systems. Hard-wired analog control systems have been replaced by Programmable Logic Controllers (PLC), fiber optic networks (FON) infrastructure and human machine interface (HMI) operator screens. New modern IT Security procedures and schemes have been employed to control data access and process control flows. Due to the nature of testing possible at B-2, flexibility and configurability of systems has been central to the architecture during modernization.

Cmar, Mark D.↗

Modernization of B-2 Data, Video, and Control Systems Infrastructure

The National Aeronautics and Space Administration (NASA) Glenn Research Center (GRC) Plum Brook Station (PBS) Spacecraft Propulsion Research Facility, commonly referred to as B-2, is NASA's third largest thermal-vacuum facility with propellant systems capability. B-2 has completed a modernization effort of its facility legacy data, video and control systems infrastructure to accommodate modern integrated testing and Information Technology (IT) Security requirements. Integrated systems tests have been conducted to demonstrate the new data, video and control systems functionality and capability. Discrete analog signal conditioners have been replaced by new programmable, signal processing hardware that is integrated with the data system. This integration supports automated calibration and verification of the analog subsystem. Modern measurement systems analysis (MSA) tools are being developed to help verify system health and measurement integrity. Legacy hard wired digital data systems have been replaced by distributed Fibre Channel (FC) network connected digitizers where high speed sampling rates have increased to 256,000 samples per second. Several analog video cameras have been replaced by digital image and storage systems. Hard-wired analog control systems have been replaced by Programmable Logic Controllers (PLC), fiber optic networks (FON) infrastructure and human machine interface (HMI) operator screens. New modern IT Security procedures and schemes have been employed to control data access and process control flows. Due to the nature of testing possible at B-2, flexibility and configurability of systems has been central to the architecture during modernization.

Cmar, Mark D.↗

Decomposition Algorithms for Solving NP-hard Problems on a Quantum Annealer

NP-hard problems such as the maximum clique or minimum vertex cover problems, two of Karp’s 21 NP-hard problems, have several applications in computational chemistry, biochemistry and computer network security. Adiabatic quantum annealers can search for the optimum value of such NP-hard optimization problems, given the problem can be embedded on their hardware. However, this is often not possible due to certain limitations of the hardware connectivity structure of the annealer. This paper studies a general framework for a decomposition algorithm for NP-hard graph problems aiming to identify an optimal set of vertices. Our generic algorithm allows us to recursively divide an instance until the generated subproblems can be embedded on the quantum annealer hardware and subsequently solved. Furthermore, the framework is applied to the maximum clique and minimum vertex cover problems, and we propose several pruning and reduction techniques to speed up the recursive decomposition. The performance of both algorithms is assessed in a detailed simulation study.

97 MATHEMATICS AND COMPUTING↗

Open-Source Architecture for Multi-Party Update Verification for Data Acquisition Devices

Power grids are integral parts of modern daily life and are increasingly under cyberattack. Common software update processes for grid control devices rely on only one organization to provide verification. This paper roposes a multi-signature software update process to help better secure data acquisition devices from malicious actions by using standard cryptosystems such as TLS. A prototype system build on Linux and off-the-shelf hardware has shown successful update and attack prevention with our customized multi-party update software.

Newberg, Benjamin↗

Enhanced Control, Optimization, and Integration of Distributed Energy Applications (ECO-IDEA)

With support from the U.S. Department of Energy Solar Energy Technologies Office, the National Renewable Energy Laboratory (NREL) partnered with Xcel Energy, Schneider Electric, Varentec, and Electric Power Research Institute (EPRI) to meet the goals of the Enabling Extreme Real-Time Grid Integration of Solar Energy (ENERGISE) program. This project developed and validated an innovative data-enhanced hierarchical control architecture that enables the efficient, reliable, resilient, and secure operation of future distribution systems with a high penetration of distributed energy resources like solar energy. The architecture enables a hybrid control approach where a centralized control layer is complemented by distributed control algorithms for solar inverters and autonomous control of grid edge devices. It is fully interoperable and includes all the cybersecurity aspects necessary for reliable and secure system operation. The hybrid approach can seamlessly integrate multiple voltage-regulation technologies, both at central and grid-edge levels, which enables reliable and efficient system operation in the face of unpredictable conditions. The overarching goal of the Eco-Idea project is to develop, validate, and deploy a unique and innovative Data-Enhanced Hierarchical Control (DEHC) architecture that comprehensively addresses the formidable challenges associated with proliferation of high penetration of distributed PV such as reverse power flows, transients from variability of PV systems, feeder load balancing, and voltage stability. These issues are exposing the weaknesses of existing grid operations and controls - including, but not limited to, lack of grid situational awareness, heuristic and slow-acting control actions, latency of control for emergency situations, and points of failure in communications. The proposed architecture will comprehensively resolve the deficiencies of current operational settings - where monitoring and control solutions proposed across industry and academia may not be interoperable and may not coexist in the same system - and will enable an efficient, reliable, resilient, and secure operation of future distribution systems with penetration of solar energy well beyond current limits. The DEHC architecture was developed and validated rigorously through hardware-in-loop simulations in the laboratory environment and deployed on the field.

24 POWER TRANSMISSION AND DISTRIBUTION↗

TRIM: AI Guided Random Number Generation for Resource-Constrained IoT Systems

Random numbers often serve as the backbone for many security solutions in diverse domains such as cryptography, side channel leakage prevention, and moving target defense. However, generating true random numbers requires a physical source of entropy (e.g. hardware, quantum, environmental phenomenon) making it difficult to realize at a large scale and at a low cost. On the flip side, pseudorandom number generators (easy to implement) following a specific distribution (e.g. Gaussian) can be easily compromised given a sufficient amount of traces. In this work, we have developed a machine learning-guided generative approach that can be used to create portable, resource-efficient, and cost-effective random number generators with high throughput and true randomness characteristics. We implement the proposed approach as a highly parameterized framework and perform extensive evaluation for different settings. The framework was able to learn from true random sources such as irrational numbers and environmental audio noise and imitate those sources towards generating new good quality random numbers on demand. We have generated more than 1 billion bits and observed robust performance in terms of true randomness metrics obtained from NIST SP 800-22 and FIPS 140-1 randomness test suites achieving a throughput of up to 142.85 Mbps. Compared to the state-of-the-art (SOTA) technique, the iso-cost setup of our framework can achieve more than 500 Mbps in a distributed setting. We have evaluated the efficacy of running the true randomness imitation AI models on target edge devices such as Raspberry Pi 4 (Model B), Nvidia Jetson Nano, Nvidia Jetson Orin Nano and Nvidia Jetson Xavier. We have also looked at the security of the TRIM framework itself against different adversarial threat models.

Cybersecurity↗

Cyber-Attack Detection for Photovoltaic Farms Based on Power-Electronics-Enabled Harmonic State Space Modeling

Here in this paper, a physics-data-based detection method is proposed to detect a variety of cyber-attacks in Photovoltaic (PV) farms using the power electronics-enabled harmonic state space (HSS) models, which, to our knowledge, is original. At the device level, HSS-based detection is developed to monitor harmonic vectors of individual PV converter with minimum sensor measurements, thus improving accuracy and robustness compared to Kalman Filter-based detection. At the system level that involves multiple PV converters, a clustering approach is developed to investigate attack propagation and accurately locate attack sources within a PV farm. The proposed approach is one of the first attempts to address PV security through interaction between the device and system, maximizing the accuracy and robustness at different levels. To verify the feasibility, a comprehensive attacks model is built, including single attack, coordinated attacks, and replay attacks. Besides, the impacts of irradiance changes are taken into consideration in the test scenarios. With the real-time data acquisition and hardware-in-the-loop testbed, comprehensive test results are provided to verify the feasibility of the proposed detection methodology.

42 ENGINEERING↗

Blockchain-Based Smart Contracts Use for Photovoltaic Energy Trade Transactions

In recent decades, interest in renewable energy via solar energy has increased, especially in California and Nevada. In a region that can produce enough solar power for self-use, prosumers must use or sell surplus energy. Solar energy self-consumption is essential in modern energy transactions in the grid. This paper proposes an approach towards grid services that includes photovoltaic hardware to store the excess energy in battery storage. Such energy can then be sold to power companies while the transaction is handled using blockchain. Software, security architecture and data flow requirements based on the Ethereum Blockchain are included. Furthermore, this solution protects the private information of seller and buyer and secures transactions.

14 SOLAR ENERGY↗

Cybersecurity Assessment in DER-rich Distribution Operations: Criticality Levels and Impact Analysis

The integration of distributed energy resources (DERs) in distribution networks has become a pivotal strategy for achieving decarbonization, enhancing grid resilience, and optimizing grid efficiency. Remote monitoring and control op- erations of such resources rely on a network of sensors and communication infrastructure, exposing the system to potential cyber threats. Therefore, as the deployment of DERs increases, ensuring secure monitoring and control becomes an imperative challenge. This paper utilizes real-time feeder models, which are instrumental in developing cybersecurity testbeds tailored for hardware-in-loop (HIL) systems. These models enable users to simulate cyber attacks in a real-world environment and analyze the power distribution operations during vulnerabilities. Furthermore, we discuss several practical sets of grid parameters to identify critical levels of DERs and evaluate various scenarios that simulate cyber threats on sensitive DERs. The modified IEEE 123-bus model is used as the test case for demonstrating the proposed scenarios. The findings from this study provide valuable insights into the vulnerabilities and potential consequences of cyber attacks on DERs, allowing for better mitigation strategies and improved cyber resilience in future distribution networks.

Maharjan, Manisha↗

Systems integration for the Kennedy Space Center (KSC) Robotics Applications Development Laboratory (RADL)

A laboratory for developing robotics technology for hazardous and repetitive Shuttle and payload processing activities is discussed. An overview of the computer hardware and software responsible for integrating the laboratory systems is given. The center's anthropomorphic robot is placed on a track allowing it to be moved to different stations. Various aspects of the laboratory equipment are described, including industrial robot arm control, smart systems integration, the supervisory computer, programmable process controller, real-time tracking controller, image processing hardware, and control display graphics. Topics of research include: automated loading and unloading of hypergolics for space vehicles and payloads; the use of mobile robotics for security, fire fighting, and hazardous spill operations; nondestructive testing for SRB joint and seal verification; Shuttle Orbiter radiator damage inspection; and Orbiter contour measurements. The possibility of expanding the laboratory in the future is examined.

Davis, V. Leon↗

Securing Digital Energy Infrastructure: Procurement, Contracting, and Supply Chain Risk Management Guidance

Recognizing the scale of this industry challenge, the United States (U.S.) Department of Energy (DOE) Grid Deployment Office (GDO) and Cybersecurity Energy Security & Emergency Response office have launched a multi-year BESS supply chain security initiative to identify consequence-driven approaches to addressing BESS supply chain security and provide resources to support prioritization of supply chain security efforts associated with the procurement of BESS equipment and services. This guide is one element of the supporting resources to be provided and sets forth a framework and guidance for procurement bidding, selection, risk analysis, and agreements stakeholders can implement to mitigate cybersecurity risks across the entirety of battery system component ecosystem, including the interconnected software and hardware required for control and monitoring BESSs.

25 ENERGY STORAGE↗