Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “network security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 163 records · Page 9

Trust Model System for the Energy Grid of Things Network Communications

Network communication is crucial in the Energy Grid of Things (EGoT). Without a network connection, the energy grid becomes just a power grid where the energy resources are available to the customer uni-directionally. A mechanism to analyze and optimize the energy usage of the grid can only happen through a medium, a communications network, that enables information exchange between the grid participants and the service provider. Security implementers of EGoT network communication take extraordinary measures to ensure the safety of the energy grid, a critical infrastructure, as well as the safety and privacy of the grid participants. With the dynamic nature of network communication of the EGoT, the information provided by the customer or the service provider can be falsified by a malicious attacker. Therefore, a trust model is necessary to monitor any abnormal activities. This paper describes a distributed trust model system that meets the need of the EGoT. This paper describes methods for evaluating and improving the distributed trust model using standard hypothesis testing metrics such as true positive, false positive, true negative, false negative, equal error rate, and F1 score. Example calculations are shown based on generated sample data.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Achieving Cyber-Resilience for Power Systems using a Learning, Model-Assisted Blockchain Framework

The secure integration and management of distributed energy resources (DER) and power aggregators in the electric grid requires secure communications and a physics-aware Command and Control (C2) strategy. A Blockchain (BC)-based overlay network was developed to provide a security layer for the existing power grid network that mitigates risks in current and legacy network and C2 protocols. By integrating a Model-Assisted Machine Learning (MAML) framework with a Secure Blockchain Overlay Network (SBON) a defense-in-depth strategy was achieved. In our approach, the MAML framework leveraged a smart contract framework to gather network data and learn the dynamics of DER to develop detection strategies for attacks targeting sensors and actuators used by DER. The MAML framework learned dynamical systems models for individual DERs to detect sensor attacks. For DER we utilized a Digital Twin (DT) to accelerate the learning process for a model resistant to stealthy attacks. The project created DT for PV inverters and BESS. The DTs were coupled with a model-assisted, data-driven learning of DER behavior. Specifically, we evaluated architectures for model-based learning with model-free fine-tuning. Additionally, differential privacy techniques were used to obfuscate data, while still allowing the computation of attack detection results based on obfuscated data. The SBON developed leverages a private permissioned blockchain network orchestrated with the Hyperledger Fabric framework. To connect the cyber world, which orchestrates the blockchain fabric, and the physical world where the power network resides, we developed a system implementation to enable the secure interaction of the physical world and the abstracted blockchain.

97 MATHEMATICS AND COMPUTING↗

Cross-Layered Cyber-Physical Power System State Estimation towards a Secure Grid Operation

In the Smart Grid paradigm, this critical infrastructure operation is increasingly exposed to cyber-threats due to the increased dependency on communication networks. An adversary can launch an attack on a power grid operation through False Data Injection into system measurements and/or through attacks on the communication network, such as flooding the communication channels with unnecessary data or intercepting messages. A cross-layered strategy that combines power grid data, communication grid monitoring and Machine Learning based processing is a promising solution for detecting cyberthreats. In this paper, an implementation of an integrated solution of a cross-layer framework is presented. The advantage of such a framework is the augmentation of valuable data that enhances the detection of anomalies in the operation of power grid. IEEE 118-bus system is built in Simulink to provide a power grid testing environment and communication network data is emulated using SimComponents. The performance of the framework is investigated under various FDI and communication attacks.

cyber security, network security, cyber-physical s↗

Cybersecurity Platform and Certification Framework Development for Extreme Fast Charging (XFC)-Integrated Charging Ecosystem (Final Project Report)

This report summarizes a pioneering effort in Electric Vehicle charging infrastructure ecosystem cybersecurity requirements, assessment methodologies, functional verification, as well as embodiment of the key technologies in the form of hardware and software tools being made available to the public. EPRI led a team of experts, as well as a stakeholder coalition encompassing all key actors in the EV charging infrastructure ecosystem that includes eXtreme Fast Charging (XFC) equipment (defined as 200kW or above). EV charging infrastructure in the United States is a patchwork of networks that have continued to grow organically and have been designed to serve the charging needs of the EV owners, who are their customers. In doing so, each network provider, as well as their connected entities such as the cloud Electric Vehicle Service Providers or EVSPs, utility back office, utility AMI networks, payment networks, as well as Original Equipment Manufacturer (EV manufacturer) telematics networks, have designed systems that may work well individually, but no single entity is responsible for the entire ecosystem to be secure in terms of data exchange. Furthermore, there is no uniformity in how each actor has implemented the cybersecurity requirements since no system-wide cybersecurity requirements existed prior to this project. The final project report describes the technical approach guided by the EV charging infrastructure cybersecurity working group, convened specifically for this project. The technical approach included definition of requirements at the ecosystem level, treated as a ‘system of systems’, and then passed down to individual systems (EVSE, EV, cloud EVSP, utility, and the payment networks), followed by developing the cybersecurity risk and vulnerability assessment methods, that were later applied to real-world cyber-physical systems at EPRI, ANL, and NREL laboratories, to validate both the process and the results. Finally, in a spotlight over the most vulnerable equipment, which is the EV charge station (AC or DC), the team developed a multi-layer cybersecurity implementation in the embedded domain embodied by the open-source Secure Network Interface Card (SNIC) demonstrating the various ways in which the infrastructure can be secured protecting against the identified attack surfaces. Finally, the entire process of EV infrastructure cybersecurity assessment was encapsulated in the Electric Vehicle Charging Cybersecurity Management (EVC2M) online GUI-based tool, that is expected to be released to the public. The report presents the objectives, the technical approach, the key results, and recommendations for future work.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Adapting Secure MultiParty Computation to Support Machine Learning in Radio Frequency Sensor Networks

In this project we developed and validated algorithms for privacy-preserving linear regression using a new variant of Secure Multiparty Computation (MPC) we call "Hybrid MPC" (hMPC). Our variant is intended to support low-power, unreliable networks of sensors with low-communication, fault-tolerant algorithms. In hMPC we do not share training data, even via secret sharing. Thus, agents are responsible for protecting their own local data. Only the machine learning (ML) model is protected with information-theoretic security guarantees against honest-but-curious agents. There are three primary advantages to this approach: (1) after setup, hMPC supports a communication-efficient matrix multiplication primitive, (2) organizations prevented by policy or technology from sharing any of their data can participate as agents in hMPC, and (3) large numbers of low-power agents can participate in hMPC. We have also created an open-source software library named "Cicada" to support hMPC applications with fault-tolerance. The fault-tolerance is important in our applications because the agents are vulnerable to failure or capture. We have demonstrated this capability at Sandia's Autonomy New Mexico laboratory through a simple machine-learning exercise with Raspberry Pi devices capturing and classifying images while flying on four drones.

42 ENGINEERING↗

5G Zero Trust Architecture: A Testable and Phased Approach

With the emphasis being placed on Zero Trust Architecture in technology and by Executive Order (Executive Order on Improving the Nation’s Cybersecurity ), an investigation was performed as to the feasibility of implementing this approach into 5G. Reference documents include NIST Special Publication 800-207 and Department of Defense (DoD) Zero Trust Reference Architecture , and these provided guidance as to the overall approach. Progress is being made within 5G to address the lack of Zero Trust Architecture; a June 2021 DoD press release indicated that “The prototype 5G network is built on the next generation of Open Radio Network standards and designed to comply with DOD specifications for zero-trust architecture for native security and secure connectivity with other networks.”

5G↗

Evaluating Named Data Networking for Industrial Control System [Slides]

Current proposed work is: See if the inherent security that comes with Named Networking (NDN) can be applied to Industrial Control Systems; and, Every packet is required to be cryptographically signed which makes every single piece of data communicated in the system secure and authenticated.

42 ENGINEERING↗

Secure and Cost-Effective Micro Phasor Measurement Unit (PMU)-Like Metering for Behind-the-Meter (BTM) Solar Systems using Blockchain-Assisted Smart Inverters

Recently, there is increasing interest in using behind-the-meter (BTM) solar systems for grid services. However, providing visibility and operational situational awareness of BTM solar systems mainly operated by small-scale solar inverters is challenging due to the requirement of relatively expansive networked observation tools (e.g., micro phasor measurement units (µPMUs)) and consequent cybersecurity threats through networks. This paper presents a secure, cost-effective, µPMUs-like metering method using a blockchain-assisted smart (BAS) inverters for a BTM solar system. The proposed BAS inverter consisting of an internet of things device as a node of a local blockchain network enables the secure provision of inverter measurement data for grid services. The BAS inverter sends the encrypted local measurement data with a timestamp to a local blockchain miner. Once the blockchain miner generates a tamper-resistant metering ledger including the measurements, it is used to assess the situational awareness of the BTM solar system. The concept of the proposed metering using the BAS inverters is validated by experimental studies.

behind the meter↗

Serial communication tapping and transmission to routable networks

Apparatuses and methods for tapping serial communications and transforming the serial data into a format appropriate for routable networks are significant for purposes of security and troubleshooting, especially in critical infrastructure networks. Communication taps should be completely passive such that any failure would not interrupt the serial communications. Furthermore, automatic determination of unspecified serial protocol frames allow general implementation across various networks, or across devices within a single network, without the need to customize for each implementation.

Edgar, Thomas W.↗

Serial communication tapping and transmission to routable networks

Apparatuses and methods for tapping serial communications and transforming the serial data into a format appropriate for routable networks are significant for purposes of security and troubleshooting, especially in critical infrastructure networks. Communication taps should be completely passive such that any failure would not interrupt the serial communications. Furthermore, automatic determination of unspecified serial protocol frames allow general implementation across various networks, or across devices within a single network, without the need to customize for each implementation.

Edgar, Thomas W.↗

Dual-Phase Malicious User Detection Scheme for IM-OFDMA Systems Using IQ Imbalance

Physical-layer security techniques have contributed to the achievement of various security objectives in an efficient and lightweight manner. Thus, these techniques have been widely considered for limited-resource networks such as Internet of Things networks. Among the different security objectives, malicious user detection by exploiting physical-layer parameters has demonstrated efficient performance. In this work, malicious user detection in the recently proposed index modulation-based orthogonal frequency division multiple access (IM-OFDMA) is addressed. The proposed malicious user detection scheme exploits the hardware impairments, especially the in-phase and quadrature imbalance parameters, for both legitimate and malicious users to design a dual-phase efficient detection scheme. The proposed scheme accounts for the special characteristics of IM-OFDMA transmission that are different from other multiple-access techniques. The performance of the proposed scheme was evaluated considering detection probability and false alarm probability performance metrics. Moreover, closed-form expressions of these metrics were derived for both phases and were validated by Monte Carlo simulation results under different configurations of IM-OFDMA systems.

Alaca, Ozgur [ORNL] (ORCID:0000000153713758)↗

Toward Wireless Smart Grid Communications: An Evaluation of Protocol Latencies in an Open-Source 5G Testbed

Fifth-generation networks promise wide availability of wireless communication with inherent security features. The 5G standards also outline access for different applications requiring low latency, machine-to-machine communication, or mobile broadband. These networks can be advantageous to numerous applications that require widespread and diverse communications. One such application is found in smart grids. Smart grid networks, and Operational Technology (OT) networks in general, utilize a variety of communication protocols for low-latency control, data monitoring, and reporting at every level. Transitioning these network communications from wired Wide Area Networks (WANs) to wireless communication through 5G can provide additional benefits to their security and network configurability. However, introducing these wireless capabilities may also result in a degradation of network latency. In this paper, we propose utilizing 5G for smart grid communications, and we evaluate the latency impacts of encapsulating GOOSE, Modbus, and DNP3 for transmission over a 5G network. The OpenAirInterface open-source library is utilized to deploy an in-lab 5G Core Network and gNB for testing with off-the-shelf User Equipment (UE). This creates an effective 5G test platform for experimenting with different OT protocols such as GOOSE. The results are validated by measuring two different Intelligent Electronic Devices’ contact closure times for each network configuration. These tests are also conducted for varying packet sizes in order to isolate different sources of network latency. Our study outlines the latency impact of communication over 5G for time-critical and non-critical applications regarding their transition toward private 5G-based OT network implementations. The conducted experiments illustrate that in the case of GOOSE packets, simple encapsulation may exceed the protocol’s time-critical nature, and, therefore, additional measures must be taken to ensure a viable transition of GOOSE to 5G services. However, non-critical applications are shown to be viable for migration to 5G.

42 ENGINEERING↗

DATASET RELEASE AND QUALITY CONTROL REVIEW OF LIVERMORE NEVADA NETWORK (LNN) RECORDINGS OF A SUBSET OF NEVADA NUCLEAR SECURITY SITE NUCLEAR EXPLOSIONS FROM 1979 TO 1992.

Geophysical research on historical nuclear tests is an important aspect of future monitoring capabilities in seismic research. This research is challenging due to the limited number of digital seismic recordings during the peak of nuclear testing (1945-1992). These limited records are unique and non-reproducible data with potential high research impact. Releasing available nuclear explosion seismic records to the explosion monitoring community is thus of high value and is the motivation for this dataset release. The target of this effort was on compilation and quality control of regional seismic records of nuclear explosions recorded on Lawrence Livermore National Laboratory stations ELK, KNB, LAC, and MNV, known collectively as the Livermore National Network (LNN) (Figure 1). LNN was established in the early 1960s for the primary purpose of monitoring underground nuclear testing at the former Nevada Test Site (NTS), now known as the Nevada Nuclear Security Site (NNSS) following the signing of the Limited Test Ban Treaty (LTBT). LNN consisted initially of short-period vertical component Benioff’s recorded on film located at Mina, NV (MNV) and Kanab, Utah (KNB). LNN added two additional stations at Landers, CA (LAC) and Elko, NV (ELK) in 1967 and upgraded equipment to broadband seismometers recorded on frequency modulation (FM) tapes from 1967-1979, followed by digital recordings after 1979 (Jarpe, 1989). The digital recordings were on a variety of now obsolete media, including 9-track, Exabyte, and DAT tapes. Jarpe (1989) describes the seismic station instrumentation details over the period of deployment. LNN recorded valuable non-repeatable unique data of several hundreds of nuclear explosions at NNSS, as well as earthquakes and chemical and mining explosions (Walter, 2020). The details of these nuclear tests are provided in the Department of Energy Report NV-209 Rev 16 (DOE, 2015).

58 GEOSCIENCES↗

Advanced architectures for high-performance quantum networking

As practical quantum networks prepare to serve an ever-expanding number of nodes, there has grown a need for advanced auxiliary classical systems that support the quantum protocols and maintain compatibility with the existing fiber-optic infrastructure. We propose and demonstrate a quantum local area network design that addresses current deployment limitations in timing and security in a scalable fashion using commercial off-the-shelf components. First, we employ White Rabbit switches to synchronize three remote nodes with ultra-low timing jitter, significantly increasing the fidelities of the distributed entangled states over previous work with Global Positioning System clocks. Second, using a parallel quantum key distribution channel, we secure the classical communications needed for instrument control and data management. Therefore, the conventional network that manages our entanglement network is secured using keys generated via an underlying quantum key distribution layer, preserving the integrity of the supporting systems and the relevant data in a future-proof fashion.

97 MATHEMATICS AND COMPUTING↗

Topology-Dependent Performance of Free-Space Photonic Quantum Networks Under Noise

Photonic quantum communication enables secure and high-fidelity information transfer beyond classical limits, with direct relevance to emerging quantum networks operating in free-space environments. While physical-layer models of depolarizing noise, Gamma–Gamma turbulence statistics, entanglement swapping, and decoy-state QKD security bounds are individually well established, prior work typically treats these components in isolation or under fixed network assumptions. In this work, we develop a unified topology-aware analytical framework that simultaneously integrates free-space optical link budgets, turbulence-induced visibility degradation, depolarizing qubit noise, multi-hop entanglement cascade dynamics, teleportation fidelity thresholds, CHSH nonlocality certification, and asymptotic decoy-state secret key rate bounds across star, mesh, and ring graph structures. Rather than introducing new physical channel models, we demonstrate that identical physical links exhibit fundamentally different end-to-end performance once embedded within different network topologies. Mesh architectures minimize visibility cascade through hop-count reduction but incur quadratic hardware scaling. Star topologies minimize link count but concentrate noise and synchronization overhead at the hub. Ring configurations offer linear hardware scaling with multiplicative fidelity degradation. The results establish topology as a first-order design parameter in near-term free-space quantum networks operating without full quantum repeater infrastructures. While motivated by distributed multi-agent architectures, the framework applies broadly to terrestrial, airborne, and satellite-assisted photonic quantum communication systems.

QKD↗

Security Enhancements for Distributed Energy Resource Systems Interconnected with Distribution Networks: Final Technical Report

The revised IEEE 1547 Standard defines new complex communication-adjustable voltage and frequency regulation and ride-through characteristics, while maintaining the general antiislanding requirement for unintentional islanding situations. Unintentional islanding is prohibited while intentional islanding is specifically allowed, thus effectively enabling microgrid operation mode. Further, IEEE 1547-2018 Standard introduces new requirements in terms of interoperability so that the DER plant/circuit segments may be seamlessly integrated with the utility networks but at the same time become vulnerable to a cyber-attack. Traditional cybersecurity measures including encryption, authentication and role-based access control may not be fully implementable to all communication protocols specified in the IEEE 1547 Standard. Therefore, in this project we have identified, researched, implemented and tested several cyberphysical approaches that rely mostly on the behavior of the DER circuit and may help with validating the incoming command and control action potentially coming through an insecure communications channel. Additionally, we have built semantic models and communications profiles for DER facilities and have implemented lightweight IEC 61850 based publisher-subscriber GOOSE messaging mechanism, with security extensions in terms of authentication and encryption. The project proposed information models for integration into UCA OpenFMB 2.0 profiles focusing on grid code compliance.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Deploying Software-Defined Networking in Operational Technology Environments

Software Defined Networking for Operational Technologies, referred to as OT-SDN, is a leading technology to secure critical infrastructure and command and control (C2) systems. As the name implies, OT-SDN networks are programmable, which allows system owners to utilize the characteristics of their physical process to inform the security of their network. There are best practices for deploying OT-SDN into an environment, whether it is all at once or over time (hybrid) that the network is converted to SDN technologies. Through the development of data mining tools and standardized process control, OT-SDN can be deployed reliably. These tools will minimize or eliminate any communication failures during the transition and provide the network owner with complete documentation of their environment. This documentation could enable or facilitate the network owner to pass any audits or policy checks (Authority to Operate) before being allowed to utilize the OT-SDN infrastructure.

Software Defined Networking, Operational Technolog↗