Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Secure by Design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 163 records · Page 9

Cyber Threat Assessment Methodology for Autonomous and Remote Operations for Advanced Reactors (Conference Presentation)

The next generation of Advanced Reactors include planned capabilities for both Autonomous (operating without human interaction for a set period-of-time) and Remote (operating with human interaction from a separate physical location) Operations. Existing Nuclear Reactor architectures include a set of safety and security constraints tightly coupled with personnel policies and procedures. As Advanced Reactors are fielded with these new Autonomous and Remote operational capabilities, the architectures and associated infrastructure services and components will perceivably expand the overall attack surface and risk calculations with regards to safe and secure operations. This paper is part of an FY21 work program focused on ensuring Advanced Reactor designs are informed with threat-based guidance on design and operation of Secure Architectures with a specific focus on the deployment of Autonomous Systems in support of Advanced Reactor Operations. The next phase of this research program is to complement produce a methodology for assessment of the cyber threat against these architectures as well as a catalogue of Use Cases to support the Advanced Reactor community in their implementation of Autonomous and Remote Operations.

97 MATHEMATICS AND COMPUTING↗

Reimagining Codesign for Advanced Scientific Computing: Report for the ASCR Workshop on Reimagining Codesign

In March 2021, the U.S. Department of Energy’s Advanced Scientific Computing Research program convened the Workshop on Reimagining Codesign. The workshop, also known as ReCoDe, was organized around discussions on eight topic areas: (1) codesign for traditional high-performance computing workloads; (2) codesign of memory/storage systems; (3) codesign of machine learning, neuromorphic, quantum, and other non-von Neumann accelerators; (4) codesign for edge computing and processing at experimental instruments; (5) codesign for security and privacy; (6) hardware design tools and open-source hardware for high-productivity codesign; (7) tools, software stack, and programming languages for high-productivity codesign; and (8) quantitative tools and data collection for modeling and simulation for codesign. The panels identified four Priority Research Directions from these deliberations: (1) breakthrough computing capabilities with targeted heterogeneity and rapid design; (2) software and applications that embrace radical architecture diversity; (3) engineered security and integrity, from transistors to applications; and (4) design with data-rich processes.

97 MATHEMATICS AND COMPUTING↗

The Impact of Cultural Values and Organizational Processes on Nuclear Security Operations

Human performance is a pivotal factor in the design, testing, maintenance, and operation of security systems. The effectiveness of these systems relies not only on the capabilities, limitations, motives, and attitudes of the individuals involved, but also on the quality of training, instructional content, and evaluation methods provided. To uphold security standards, seamless integration between technologies and operators necessitates reliable human input. In security operations, human errors, often attributed to blame, sanctions, low motivation, individual accountability, or complacency, are primary causes of system failures. Complacency, characterized by a false sense of security, reflects a lack of awareness of potential threats and is a significant contributing factor to lapses in security. Security incidents arise from various factors, many extend beyond individual control, highlighting the need for a holistic approach to human performance that integrates organizational processes and team collaboration. Historically, errors have been attributed to individual moral or cognitive failures. However, insights from Operational Experiences (OEs) suggest that organizational processes weakness and deficiencies in nuclear cultural values contribute more significantly to security failures than individual mistakes. This paper consolidates lessons learned from diverse international nuclear security cultures and aims to highlight the importance of security culture in shaping global perspectives on nuclear security. It underscores the role of cultural values in shaping nuclear security practices and enhancing the resilience of security systems in the nuclear sector.

Zineddin, Dr. Z. [ORNL] (ORCID:0009000848740725)↗

IRAD-MPE Radiological and Nuclear Security Threats (Day 1) [Slides]

This module is designed to enhance awareness regarding radiological and nuclear security threats and the types of radioactive materials that can be used for criminal purposes or terrorist acts. The goals are to: (1) Review the Threat Assessment Process for MPEs, (2) Recognize Potential Radiological and Nuclear Security Threats, (3) Understand the basics of Radiological Dispersal Devices (RDD) and Radiological Exposure Devices (RED), (4) Learn about Medical, Commercial, and Naturally Occurring Radioactive Materials (NORM) sources, and (5) Understand the term Material Out of Regulatory Control (MORC).

61 RADIATION PROTECTION AND DOSIMETRY↗

A Four-Layer Cyber-Physical Security Model for Electric Machine Drives Considering Control Information Flow

Despite the IEEE Power Electronics Society (PELS) establishing Technical Committee 10 on Design Methodologies with a focus on the cyber-physical security of power electronics systems, a holistic design methodology for addressing security vulnerabilities remains underdeveloped. This gap largely stems from the limited integration of computer science and power/control engineering studies in this interdisciplinary field. Addressing the inadequacy of unilateral cyber or control perspectives, this article presents a novel four-layer cyber-physical security model specifically designed for electric machine drives. Central to this model is the innovative control information flow (CIF) model, residing within the control layer, which serves as a pivotal link between the cyber layer's vulnerable resources and the physical layer's state-space models. By mapping vulnerable resources to control variable space and tracing attack propagation, the CIF model facilitates accurate impact predictions based on tainted control laws. The effectiveness and validity of this proposed model are demonstrated through hardware experiments involving two typical cyber-attack scenarios, underscoring its potential as a comprehensive framework for multidisciplinary security strategies.

97 MATHEMATICS AND COMPUTING↗

Cyber-Informed Engineering Adoption in University Engineering Programs: An Overview of CIE Integration Successes at Nine U.S. Educational Institutions

This report examines the adoption of Cyber-Informed Engineering (CIE) in university engineering programs, driven by the need to protect critical energy infrastructure from adversarial threats. CIE equips current and future engineers and technicians with the necessary mindset, skills, and competencies to enhance the resilience of engineered systems against cyber attacks. This report highlights nine academic partners who are incorporating CIE into their curricula through various approaches, including lectures, courses, and certificates.

42 ENGINEERING↗

Universal Utility Data Exchange (UUDEX) Functional Design Requirements - Rev 1

This document provides a set of high-level functional design requirements for Universal Utility Data Exchange (UUDEX). These requirements include a set of use cases, data exchanges supported by UUDEX, both for grid operations and for cyber security data, functional requirements for data exchange, data models used by UUDEX, data exchange architectures, and security considerations. These functional design requirements are intended to be used in more detailed design documents.

97 MATHEMATICS AND COMPUTING↗

Integrating Safety, Security, and Nuclear Operations for Advanced Reactors

The traditional separation between safety, security, and operations teams has created significant barriers to achieving optimal outcomes. When security considerations are introduced late in the design process, they often conflict with already-established architectural, operational, or engineering parameters. Retrofitting security measures can lead to increased costs, schedule delays, and compromises in security effectiveness. For instance, the need to retrofit physical barriers or surveillance systems often results in trade-offs that could have been avoided with earlier input from security professionals. Delayed integration can also affect regulatory processes and result in licensing delays. Security reviews conducted at later stages frequently identify gaps that necessitate significant redesign efforts, impacting not only scope, schedule, and budget, but also adding risk and lowering stakeholder confidence in the project. This paper aims to address these challenges by identifying practical opportunities for integrating security considerations seamlessly with design and operations teams throughout the entire lifecycle of nuclear facilities—from conceptual design to commissioning and beyond. The research emphasizes the value of early and continuous collaboration among stakeholders to ensure that security measures are robust, operationally effective, and cost-efficient. By examining case studies, analyzing past incidents, and leveraging best practices from other high-security industries, this study highlights actionable strategies for bridging the gap between safety, security, and operations teams.

Zineddin, Dr. Z. [ORNL] (ORCID:0009000848740725)↗

Integrating Cyber-Informed Engineering into Enterprise Risk Management

This document supports the application of Cyber-Informed Engineering (CIE) within the context of Enterprise Risk Management (ERM) to enhance cyber-resilience. It highlights that many critical infrastructure organizations use ERM to manage business risks and emphasizes the importance of evaluating critical systems and assets. The proposed approach can be adopted independently of formal ERM processes and offers a starting point for integrating CIE alongside existing or new ERM practices. Both CIE and ERM are iterative, and their alignment fosters continuous improvement and supports the engineering and operations cultures of an organization.

42 ENGINEERING↗

Our teams design high-resolution MeV x-ray radiography systems for National security missions [Poster]

The NNSS has been at the forefront of custom high-fidelity x-ray/gamma radiographic imaging solutions that serve our national security for over five decades. Our radiography team utilizes expertise in physics modeling and analysis, along with optical, mechanical, and electrical design, in close collaboration with our customers, to develop imaging methods and capabilities that go beyond their needs. Conceptual designs are developed through R&D efforts to provide solutions for the specific problem at hand. Field systems are designed and built in-house, then qualified utilizing a range of facilities across the National Security Enterprise. Radiographic imaging systems are deployed by our team in the most challenging environments. The NNSS has a strong math and programming team that provides novel on-site image analysis methods that extract crucial information from data returned in field tests.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Battery Energy Storage Systems Report

Battery energy storage systems (BESS) are a critical component of grid reliability and resilience today, providing rapid response capabilities while enabling grid modernization and capacity expansion across the United States. As utilities, communities, and customers prepare to deploy significant BESS capacity over the next several years, the United States has an opportunity to build security into battery system design and deployments. This report provides a framework for assessing the current dominance of foreign-manufactured components in the supply chains for BESS, inverter-based resources, and transformers. It offers high-impact, actionable solutions to service partners, industry, and government to address supply chain risks for currently installed, in design, and future deployments.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Protecting Websites from Cross-Site Scripting (XSS) Attacks: A Novel Configuration using Pulse Secure © Pulse Connect Secure © and Virtual Web Application Firewall (vWAF)

Cross-site scripting (XSS), one of the most prevalent forms of client-side attacks, is when bad actors attempt to access sensitive information from the backend web server and other systems on the backend network. Some XSS attacks attempt to access client-side sensitive information, such as cookies. Web application firewalls (WAFs) are a first line of defense where common Uniform Resource Locator (URL) patterns are analyzed to detect and block known attacks. This paper describes a novel configuration using the Pulse Secure © Pulse Connect Secure © (PCS © ) Secure Socket Layer Virtual Private Network software and Virtual Web Application Firewall (vWAF) that protects a website from XSS attacks. This paper also presents novel aspects of the configuration that control the redirection of traffic through the vWAF and provide fine-grained behavioral control at the application level while decoupling the PCS and vWAF configurations. The intended audience for this paper comprises system and site administrators who are familiar with standard web server environments. These configuration details might prove useful during the design of a more secure infrastructure.

97 MATHEMATICS AND COMPUTING↗

Engineering-In Cybersecurity

Cyber-Informed Engineering is a framework which allows engineers to build resiliency to the impacts of cyber attack into engineered systems starting in the early design phases. This article introduces the framework and provides a description of some of its principles and resources for learning more.

42 ENGINEERING↗

Proposed Subcritical Assembly for Nuclear Criticality Safety Training at the Oak Ridge National Laboratory

The design of a new subcritical assembly at Oak Ridge National Laboratory (ORNL) has been finalized. This design takes the feasibility study of the subcritical assembly performed in August 2020 to an implementable design. This subcritical assembly will support the Nuclear Criticality Safety Program (NCSP) training and education program. The addition of this subcritical assembly into the NCSP training and education will enhance the program by providing backup capacity for training if nuclear facility operations are disrupted at Sandia National Laboratories or the National Criticality Experiments Research Center; providing a new location that is more accessible to students in the Eastern portion of the United States; providing flexibility to support students from a diverse background (e.g., university students, foreign nationals). The proposed subcritical assembly uses legacy AGN-201M research reactor fuel plates that are available at the Y-12 National Security Complex. The final design of this subcritical assembly contains approximately 617 grams of 235 U as UO 2 powder distributed homogeneously in polyethylene. The fuel plates will have a graphite neutron reflector to obtain a core multiplication, M, from 10 to 20, corresponding to a $k_{eff}$ of 0.90 to 0.95, respectively. The subcritical assembly will be able to support at least four experiments for the training courses: (1) the addition of fissile material to the core (mass), (2) a core separation experiment (interaction), (3) the addition of moderators to the core (moderation), and (4) the addition of neutron absorbers to the core (poison/absorption). The subcritical assembly will be designed to be inherently safe—subcritical under all normal and abnormal conditions— and will provide the capability to conduct hands-on training to support NCSP and general nuclear criticality safety staff training and qualification goals.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

International Nuclear Security Nuclear Material Accounting and Control Instructions for Use and Supplementary Documentation

This document describes the use of exercise kits (called NMAC Kits) developed to support training and technical engagements sponsored by DOE/NNSA Office of Nuclear Security (INS) in the use of nuclear material accounting and control (NMAC) methodologies in support of nuclear security. INS has previously used other similar kits that were originally designed to support NMAC training for international safeguards purposes. These new kits are specifically designed to be used in nuclear security training and emphasis the role NMAC plays in nuclear security as well as security against the insider threat. Planning for the development of these kits is described in LA-UR-24-30063, FY24 NMAC Kits Upgrade and served as the initial framework for the development of the new NMAC Kit material in FY25.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Development of a Helical Closure for Radioactive Material Shipping Packages

The Savannah River National Laboratory (SRNL) Packaging Technology group proposed a closure design for the outer packaging of a prototype Type B shipping package being developed for the Department of Energy (DOE). The closure design provides an efficient means of securing the containment vessel (CV) within the radioactive material packaging. This design has a simplified operation, requires less components, and less maintenance when compared to current radioactive material package closure methods. This paper will review and discuss the materials, designs, processes, and testing activities that were considered and pursued in the development of the novel closure for the outer packaging of new radioactive material shipping packages.

Housley, William M. [Savannah River National Labor↗

CMIP6-based Multi-model Streamflow Projections over the Conterminous US, Version 1.1

This dataset presents an ensemble of streamflow projections covering the conterminous United States (CONUS), developed to support the SECURE Water Act Section 9505 Assessment for the US Department of Energy (DOE) Water Power Technologies Office (WPTO). Multiple Coupled Models Intercomparison Project phase 6 (CMIP6) Global Climate Models (GCMs) were downscaled using either statistical (DBCCA) or dynamical (RegCM) downscaling methods, based on two meteorological reference datasets (Daymet and Livneh). Subsequently, the downscaled precipitation, temperature, and wind speed data were used to drive two calibrated hydrologic models (VIC and PRMS), with total runoff routed through the Routing Application for Parallel computatIon of Discharge (RAPID) routing model, producing an ensemble of streamflow projections across 2.7 million NHDPlusV2 stream reaches across the CONUS. Each ensemble member covers the 1980-2019 baseline and 2020-2059 near-future periods under the high-end (SSP585) emission scenario. Additionally, using only DBCCA and Daymet, the projections extend to the 2060-2099 far-future period and encompass three additional emission scenarios (SSP370, SSP245, and SSP126). This dataset is designed to support the SECURE Water Act Section 9505 Assessment for the US Department of Energy (DOE) Water Power Technologies Office (WPTO). For further details, refer to Kao et al. (2022), Rastogi et al. (2022), and Ghimire et al. (2023).

13 HYDRO ENERGY↗

Advanced Reactor Safeguards Program Roadmap

The Advanced Reactor Safeguards (ARS) program was established in 2020 as part of appropriations for the Advanced Reactor Demonstration Program (ARDP) through the Office of Nuclear Energy in the Department of Energy. The goal of this program is to help address near term challenges that advanced nuclear reactor vendors face in meeting domestic Material Control and Accountancy (MC&A) and Physical Protection System (PPS) requirements for U.S. construction. Existing regulations for safeguards and security, as outlined in the Code of Federal Regulations, were written for large light water reactors, and some of the requirements are not suited to smaller, safer advanced reactor designs. The ARS program seeks to remove roadblocks in the deployment of new and advanced reactors by solving regulatory challenges, reducing safeguards and security costs, and utilizing the latest technologies and approaches for robust plant monitoring and protection. Safeguards and Security by Design (SSBD), or the consideration of safeguards and security requirements early in the design process, is an overarching principle that guides this program. This roadmap discusses the goals of the ARS program, current research, and program plan for the next five years.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗