Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Secure by Design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 163 records · Page 9

Cybersecurity Risk Profiles for Distributed Energy Resource Management Systems

Managing the digitalization of increasingly diversity energy resources is a complex challenge for energy systems planners and managers. As the penetration of solar photovoltaics (PV) and other distributed renewable energy resources (DERs) expands, distributed energy resource management systems (DERMS) will play an increasingly important role in managing, monitoring, and controlling DERs as electric systems before more distributed, interconnected, and networked. However, the cybersecurity implications of DERMS deployments are not well understood today. A lack of understanding around the cybersecurity implications of DERMS deployments and variability in the security posture of DERMS vendors, owners, and operators could introduce new security risks to evolving electric power systems. This paper describes cybersecurity attack scenarios on DERMS, identifies related cybersecurity standards and guidelines, reviews the security features of state-of-the-art DERMS solutions, and offers cybersecurity guidance for DERMS vendors, owners, and operators to protect DERMS' unique capabilities. Standardizing cybersecurity requirements for DERMS could help improve the security of DERMS integrations and improve innovations that are more secure by design. The cybersecurity guidance found in this paper is intended to offer a unified approach and lay the foundation for future standardization of DERMS cybersecurity to reduce risk to the solar industry and other renewable energy stakeholders when integrating these technologies with electric power systems.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Hand-Held Power Clamp

Tool furnishes large pushing or pulling forces. Device includes two clamping blocks, two clamping plates, and a motor-driven linear actuator with selflocking screw shaft. Power clamp exerts opening or closing force at push of switch. Tool approximately 1 m long. Originally designed to secure payload aboard Space Shuttle, operated with one hand to apply opening or closing force of up to 1,000 lb (4,400 N). Clamp has potential applications as end effector for industrial robots and in rescue work to push or pull wreckage with great force.

Clancy, J. P.↗

Gripping System For Mechanical Testing Of Composites

Specimens held without slippage, even at high temperatures. Improved gripping system designed to securely hold ends of specimen of composite material during creep or tensile test. Each grip includes pair of wedges having sharply corrugated gripping surfaces. Wedges held between two plates containing cavities sloped to accommodate wedges. Two such grips (one for each end) holds specimen in furnace connected to tensile test machine for creep measurements.

Mackay, Rebecca A.↗

Navigation Ground Data System Engineering for the Cassini/Huygens Mission

The launch of the Cassini/Huygens mission on October 15, 1997, began a seven year journey across the solar system that culminated in the entry of the spacecraft into Saturnian orbit on June 30, 2004. Cassini/Huygens Spacecraft Navigation is the result of a complex interplay between several teams within the Cassini Project, performed on the Ground Data System. The work of Spacecraft Navigation involves rigorous requirements for accuracy and completeness carried out often under uncompromising critical time pressures. To support the Navigation function, a fault-tolerant, high-reliability/high-availability computational environment was necessary to support data processing. Configuration Management (CM) was integrated with fault tolerant design and security engineering, according to the cornerstone principles of Confidentiality, Integrity, and Availability. Integrated with this approach are security benchmarks and validation to meet strict confidence levels. In addition, similar approaches to CM were applied in consideration of the staffing and training of the system administration team supporting this effort. As a result, the current configuration of this computational environment incorporates a secure, modular system, that provides for almost no downtime during tour operations.

Beswick, R. M.↗

Evaluating software defined networking solutions to reduce the digital attack surface of nuclear security systems

Most nuclear security systems used today were not designed for today’s threat environment. Systems that were intended to be stand alone are now interconnected. Devices that have a single purpose are built on multi-purpose platforms and communication protocols that, while effective, have no ability to authenticate authorized versus unauthorized commands. These attributes provide an attacker significant ability to affect the system, pivot throughout the interconnected networks, and remain undetected if he/she is able to compromise a single node. Software defined networking (SDN) has been used for years by information technology (IT) cloud service providers to quickly provision or remove servers or other systems to meet changing demand. The same concept has recently been applied to operational technology (OT) systems to enable very fast failover on critical systems that have stringent and deterministic (<5ms) transmit/receive times. By carefully engineering the communication flows through a network using preplanned routes and specific pathways it is possible to achieve deterministic and extremely reliable message delivery even when components fail. This engineering approach to network design has added security benefits including securing the networking control plane, eliminating network scanning and mapping, inhibiting ARP spoofing and host masquerading, eliminating unauthorized network pivoting and enabling greater situational awareness on the network. SDN in OT environments is new but early testing in electrical power and other critical infrastructure has shown it to be a very powerful tool for building reliable networks and reducing the digital attack surface of the network. The authors tested a software defined network switch on a simple physical protection system with components commonly found in nuclear security systems and found improved mitigations to denial of service attacks, lateral movement and network reconnaissance. The paper details the tests and their results.

Cyber security, Nuclear security, software defined↗

Nontraditional Sensors for Aqueous Separation Research & Workforce Development

Idaho National Laboratory’s (INL) nuclear fuel cycle capabilities enable the deployment of technologies that sustain the current reactor fleet, support demonstration and deployment of new advanced reactors, and facilitate management and disposition of existing and future radiological waste materials. INL focuses on deploying nuclear energy systems with confidence by decreasing proliferation risk through research that demonstrates process transparency and supports safeguards and security by design. An example of these capabilities is the Beartooth test bed, set to begin operations toward the end of fiscal year 2026. Beartooth will include a cascade of centrifugal contactors, glove box lines, and solidification and dissolution equipment to aid in the progression of novel separation techniques and to provide hands-on experience to cultivate and maintain a robust workforce of experts. To support Beartooth’s enhanced instrumentation and monitoring equipment needs, several nontraditional sensors are being considered for future deployment. The non-traditional sensors include accelerometers, acoustic microphones, and infrared cameras. These nontraditional sensors have the potential to not only help monitor the process but also enhance nuclear safeguards.

98 - NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL↗

Digital Twins for Nuclear Power Plants and Facilities

The nuclear digital twin (DT) is the virtual representation of a nuclear energy system across its lifecycle. The nuclear DT uses real-time information and other data sources to improve the process of design, licensing, construction, security, O&M, decommissioning, and waste disposal. By leveraging the knowledge base and experience from the past 40 years of LWR operation, the nuclear DT is helping to accelerate the development and deployment of advanced nuclear technology in areas of passive safety, new fuel forms, instrumentation, and reactor control. For the currently operating nuclear fleet, DTs are reducing the operational risks, increasing plant availability, increasing energy capability, and reducing electricity production costs. For advanced fission and fusion reactors, DTs are being used to design for passive safety and built-in security-by-design. Rapidly deployable small modular reactor (SMR) and microreactor designs compatible with modular construction techniques and advanced manufacturing will be the new normal, reducing the need for large capital expenditures and compressing construction schedules. In addition, lower operational and maintenance costs will be realized by reducing the complexity of operations, staffing needs, and maintenance-related activities.

Kropaczek, Dave↗

Advanced Facility Design and AI/ML Enabled Safeguards to Establish Secure, Economical Recycling of Fast Reactor Fuels (Final Scientific/Technical Report)

The project, "Advanced Facility Design and AI/ML Enabled Safeguards to Establish Secure, Economical Recycling of Fast Reactor Fuels," represents a significant advancement in nuclear fuel recycling technology. It integrates cutting-edge multimodal sensor fusion, machine learning (ML), and digital twin (DT) technologies to address challenges in material safeguarding, process optimization, and regulatory compliance for pyroprocessing facilities. This research has significantly enhanced the understanding of pyrochemical fuel recycling processes by developing innovative tools and methodologies. The Multimodal Safeguards Monitoring Unit (MSMU) combines electroanalytical techniques, Raman spectroscopy, and differential thermal analysis (DTA) to enable high-fidelity, near-real-time material accountancy measurements. Machine learning techniques, such as Long Short-Term Memory (LSTM) autoencoders, are utilized to detect anomalies in material balances and sensor data, improving the reliability of safeguards monitoring. Additionally, digital twin technology has been established to provide real-time system-level monitoring and diagnostics, integrating physics-based models with sensor data to optimize process safety and efficiency.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Sandia Nuclear Cartridge Concept

Nuclear power offers the promise of long-term electrical power for remote areas. Recent advances in passive safety and long-life cores make a reactor that can be operated autonomously for 20 years or more a real possibility. This white paper discusses a reactor concept that offers the potential for further development, resulting in a permanently hermetically-sealed "nuclear cartridge." The term "nuclear cartridge" is meant to imply a nuclear energy source that can be inserted into a site and operated autonomously until its energy has been depleted, then withdrawn and replaced by another cartridge. The concept can be scaled for various sizes, ranging from about 1 megawatt-electric (MWe) to about 100 MWe. The paper also discusses the concept of Integrated Safety, Operations, Security, and Safeguards (ISOSS) by design as it applies to this reactor design. Finally, a discussion of smart grids and how they can benefit the transfer of power to the end user is included. The Nuclear Cartridge concept has been developed with the following characteristics in mind: highly reliable autonomous operation coupled with international monitoring, requiring minimal on-site operations personnel; walkaway passively safe design; cartridge replacement cycle on the order of 20 years; load following capability; physical security by design requiring minimal security personnel during operations; and proliferation resistance by design. As illustrated in figure 1, integrating the reactor with advanced power conversion, smart grids, and other sources of energy results in a resilient and sustainable energy source.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Privacy by Design in Distributed Edge Systems: Innovating Secure Workflows for Smart Cities

The proliferation of distributed edge systems, such as those in smart cities, healthcare, and industrial IoT, offers unprecedented opportunities for data processing closer to its source, thereby reducing latency and enhancing efficiency. However, these systems also present significant privacy challenges due to the handling of sensitive data from multiple sources. This article explores the critical need for designing privacy-preserving workflows in distributed edge systems to ensure data security while maximizing the potential of edge computing. By examining the challenges, technological advancements, and potential of privacy-by-design approaches, we highlight the importance of integrating advanced privacy-preserving techniques like federated learning, differential privacy, homomorphic encryption, secure multi-party computation, and zero-knowledge proofs. These innovations are crucial for enhancing data security, regulatory compliance, and public trust in smart city applications, ultimately leading to safer and more efficient urban environments.

Kotevska, Olivera↗

National-Tribal Critical Infrastructure Protection: Collaboration for Extraordinary National Security Benefit

This paper examines national and tribal collaborative opportunities to get ahead of the critical infrastructure insecurity problem. Recommendations are viewed through the lens of the Sandia Labs Tribal Cyber-Energy initiative and national security projects. Recommendations include 1) Collaboratively address national priority and shared challenges to gain faster and better solutions to national priority problems on a smaller yet comprehensive American Indian and Alaskan Native sovereign single-point of authority scale 2) Utilize newer standards-based technologies to provide scalable, capable, and manageable solutions for greatly expanded and connected national critical infrastructures 3) Employ Cyber-Physical-Resilient design preliminary analysis to define concept- to-disposition design requirements for preemptive critical infrastructure risk mitigation and baked-in security; 4) Develop data-centric protection to provide increased information asset protection as data shifts from data-owner operated on-premises infrastructure to virtual service provider data-steward owned and operated off-premises infrastructure; and 5) Balance shared solutions with the National Institute of Science and Technology (NIST) Cybersecurity and Risk Management frameworks, and the System Security Engineering Guidelines. As yet unallocated federal funding would support research, development, the timely application of National-Tribal critical infrastructure protection, and critical infrastructure Cyber disruption response and recovery with extraordinary mutual benefits for the foreseeable future. The Critical Infrastructure Insecurity Problem: Rapid modernization and expansive connectivity are due to advances in Information and Communications Technologies that have sweeping cyber impact across all critical infrastructure sectors. Supervisory Control and Data Acquisition and Industrial Control Systems are particularly impacted as systems long separated from the Internet are now being connected and computerized. Virtualization and mobility create a Data Everywhere-User Anywhere paradigm that has evaporated the enterprise network perimeter. There are multi-front technological challenges at play, where long depended on technologies simply don't scale to current needs resulting in a digital dichotomy of competing old and new standards. New standards-based technologies scale but are not as well-known or as widely deployed, which leaves decision makers, stakeholders, and the workforce in a quandary, caught mid-stream between the technological past and the virtual future. Rapid and expansive cyber threat accompanies disruptive change in connectivity and computational dependencies. A lack of action will exacerbate the problem if new technologies roll out without baked-in security design. The Risk: If National-Tribal CIP collaboration to design in security is not done, then an ongoing state of insufficient bolt-on security and elevated threat exposure will remain for years to come.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Computer Network Security- The Challenges of Securing a Computer Network

This article is intended to give the reader an overall perspective on what it takes to design, implement, enforce and secure a computer network in the federal and corporate world to insure the confidentiality, integrity and availability of information. While we will be giving you an overview of network design and security, this article will concentrate on the technology and human factors of securing a network and the challenges faced by those doing so. It will cover the large number of policies and the limits of technology and physical efforts to enforce such policies.

Scotti, Vincent, Jr.↗

Development of a Reference Design for a Cyber-Physical System

The purpose of this thesis is to develop a reference design to assist in the selection of security practices in power electronics design. A prototype will be developed from this reference design for evaluation. This evaluation will include a brief cost/benefit analysis to gauge the efficacy of implementing each layer of security throughout the power electronics design process. This thesis will also describe the obstacles and effectiveness of integrating a Trusted Platform Module (TPM) into a cyber-hardened grid-connected device. The TPM device is a secured crypto processor that assists in generating, storing, and restricting the use of cryptographic keys. The emphasis of this research is to establish integrity, authenticity, and confidentiality within a system by providing a baseline of security concerns for segments of the system. This research considers communication, control, and hardware level securities. The scope of this thesis will review the necessary security methods as well as consider the effects these methods have on the embedded system, to assess the desired security to responsiveness trade off. Applying this approach to a design process will alleviate various unknowns of appending security to a power electronics design. This thesis describes the specific vulnerabilities introduced within this grid-edge environment, and how the liabilities within the system can be mitigated. Initially, common security techniques will be considered to establish a guideline to benchmark performance and resource costs of the system. The foundation will be a non-hardened power electronic system platform with industry standard communication protocols. Several security techniques and attack vectors will then be evaluated to contribute to the base level platform. Other fail-safe features take place to gauge progress of the selected approach, non-inclusive to the TPM. Collectively, this investigation will determine a valid experiment by appraising and categorizing resource allocation, performance overhead, and monetary cost analysis results into a reference design. The prototype will then demonstrate methods to relieve common threats that are purposefully implemented into the design.

Blair, Nicholas Paul↗

Cyber-Informed Engineering Implementation Guide

This Implementation Guide describes the principles of Cyber-Informed Engineering (CIE) and outlines questions that engineering teams should consider during each phase of a system’s lifecycle to effectively employ these principles. It describes what it means to engineer systems in a cyber-informed way, rather than offering a comprehensive, step-by-step process or procedure for CIE implementation. This guide complements—but does not replace—the application of cybersecurity standards or practices currently in place within an organization. Engineers and technicians that design critical energy infrastructure installations can use this Implementation Guide to integrate the 12 principles of CIE into each phase of the engineering lifecycle, from concept to retirement. The guide is aimed at system or design engineers, rather than software engineers or operational cybersecurity practitioners. The engineers who design, build, operate, and maintain the physical infrastructure are best positioned to leverage a system’s engineering design to diminish the severity of cyber attacks or digital technology failures. CIE expands cybersecurity decisions into the engineering space, not by asking engineers to become cyber experts, but by calling on engineers to apply engineering tools and make engineering decisions that improve cybersecurity outcomes. CIE examines the engineering consequences that a sophisticated cyber attacker could achieve and drives engineering changes that may provide deterministic mitigations to limit or eliminate those consequences.

42 ENGINEERING↗

Gender Mainstreaming in Nuclear Security: Strategies for Incorporating Gender Equality by Design in the IAEA Milestones Approach

Gender mainstreaming has emerged as a critical mechanism towards achieving gender equality in the development and implementation of laws, policies, and programs, including those related to national security. Gender mainstreaming is generally defined as the process of assessing the implications for women and men of any planned action, including legislation, policies, and programs, in all areas and at all levels, with the ultimate goal to achieve gender equality. Gender mainstreaming, which in essence can be thought of as “gender equality by design,” is an important element for building a robust nuclear security infrastructure. To date, however, gender mainstreaming has not been fully operationalized in the nuclear sector. For instance, the IAEA Milestones Approach, which provides important guidance to states seeking to develop nuclear power programs, has not yet incorporated or addressed gender considerations in its various phases or nuclear infrastructure issues, including those related to nuclear security. Therefore, this paper will argue that specifically for nuclear newcomer states, gender mainstreaming could serve as a powerful tool to integrate gender considerations into the design of laws, policies, programs, and entities necessary to successfully implement a nuclear power program. The objective of this study is twofold: first, to explore the concept of gender mainstreaming and its relevance to nuclear security, and second, to identify how gender can be incorporated into the IAEA Milestones Approach. The paper will emphasize the importance of developing guidance for the IAEA and nuclear newcomer states on how gender considerations could be incorporated throughout the development of a nuclear security program.

Siserman-Gray, Ioana-Cristina↗

Inventory of Public Key Cryptography in US Electric Vehicle Charging

Electric vehicles (EVs) and charging infrastructure are networked systems, which employ high-level communications in support of charging and grid service decisions. Public key cryptography (PKC) underlies much of the security and privacy protections of the information exchange. We are entering a new epoch where quantum computing threats must be seriously considered. A sufficiently large quantum computer, so named Cryptographically Relevant Quantum Computer (QRQC), will be able to perform the mathematical operations to efficiently attack the underpinnings of traditional PKC, thus jeopardizing the digital foundations for trust, communications security, and data security. Estimates suggest a QRQC can break public key encryption and digital signatures in the manner of tens to hundreds of hours, compared to traditional computing that would demand more than 10 18 years in a brute force-style attack. A consensus belief of quantum theorists, quantum experimenters, and cryptographers suggest that the quantum threat will be likely realized in the next twenty years. To address the threat, post-quantum cryptography, which is cryptosystems that are designed to be secure against both traditional and quantum computing threats, must be adopted. Migration from traditional PKC to quantum-resilient cryptography is a global undertaking and likely represents the largest transition in computing history. The nascent state of EV public key infrastructure, combined with limited adoption of the vehicle secure charging features, presents an opportunity to establish a preference for quantum-resistant cryptography as a step on the migration path. Delays will stunt the efforts as rapidly accelerating EVs sales and huge infrastructure investments will create large growing bases of long-lived vehicles and infrastructure. Migration preparations can commence while NIST continues the process to standardize post-quantum cryptography (PQC), which are quantum-resilient algorithms designed to be secure against traditional and quantum computing threats. The first step in preparing EV charging is to identify the presence of traditional public key cryptography algorithms and applications. With this objective in mind, this report is intended to advise the vehicle manufacturers, charging station manufacturers, charging station operators, charge network providers and other EV charging stakeholders with information on traditional PKC application and the potential risks when PKC becomes insecure. This report, the first in a series of reports discussing the topics existing at the confluence of post-quantum cryptography adoption and EV charging, identifies traditional public key applications employed and identifies potential consequences of leaving EV charging infrastructure vulnerable to quantum computing. The focus remains squarely on the of EV charging and infrastructure with respect to PKC and is believed by the authors to complement the NIST SP 1800-38 Migration to Post-Quantum Cryptography. While the report is centered on infrastructure, there are implications to vehicles.

33 ADVANCED PROPULSION SYSTEMS↗

Towards 5G-Enabled Operational Technology for Process Monitoring and Network Slicing

Cyber-Physical Systems (CPS) are deployed to monitor physical processes in critical cyber-enabled services like power generation. However, CPS ecosystems are typically designed without robust security. While it is important to ensure optimal performance of the Operational Technology (OT) environments, security cannot be overlooked. To modernize traditional OT services, 5G technology is being integrated. 5G technology offers low latency and high availability, making it a suitable infrastructure for managing and monitoring physical processes. How-ever, integrating 5G mechanisms into large-scale OT networks introduces new implementation and performance challenges. Therefore, this paper presents a 5G-enabled CPS architecture (5G-CPS) that describes the necessary components, services, and communication protocols and conducts feasibility study to integrate 5G technology in industrial control system networks to understand the performance merits. The 5G-CPS architecture aims to minimize implementation and operational challenges associated with integrating 5G technology into constrained OT.

Aguayo, Jared M.↗

Fully Homomorphic Encryption

This code implements a Fully Homomorphic Encryption (FHE) system, enabling secure computation on encrypted data without requiring decryption. It supports encryption, decryption, and homomorphic operations like matrix multiplication and addition. This code is adaptable for integrating FHE into linear-time invariant (LTI) systems, including digital control and filtering. With proper configuration from subject matter expertise, encrypted system parameters and signals can be manipulated to perform tasks like state updates, output calculations, and convolution in the encrypted domain. By preserving the structure of LTI systems while ensuring privacy, the framework facilitates secure applications in areas such as autonomous systems, signal processing, and industrial automation. The code initializes the encryption system using parameters provided in the env dictionary. These parameters include the ciphertext modulus, key dimension, plaintext fixed-point scaling factor, and noise bound. During initialization, a secret key is generated, which is essential for encrypting and decrypting data securely. The modular design allows users to tailor these parameters to specific use cases or security requirements. The code implements multiple cryptographic schemes. The learning with errors (LWE) encryption method encodes cleartext message to their plaintext fixed-point representation then encrypted into ciphertext space with additive noise. This noise ensures the security of the scheme, relying on the computational hardness of the LWE problem. The code also includes the Gentry-Sahai-Waters (GSW) scheme based off the LWE problem. Homomorphic matrix multiplication is performed between the LWE and GSW to encrypted data. This is achieved using a decomposition function on the LWE ciphertext during the multiplication operation. For higher-dimensional data, the code includes a method to encrypt entire matrices (GSWMat) using GSW encryption. These encrypted matrices can then be used for homomorphic matrix multiplications (MatMult). The decryption function uses the secret key to recover the original plaintext, removing the added noise and scaling that was originally applied during encryption.

Lois, Roberts [Idaho National Laboratory (INL), Id↗