Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “High Consequence Event”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Fossil Power Plant Cyber Security Life-Cycle Risk Reduction, A Practical Framework for Implementation

Market conditions are forcing fossil electricity generation facility owners and operators to implement advanced digital technologies. These technologies enable efficiencies, operational flexibility, operations and maintenance efficiencies, and adapting to a transitioning workforce. These digital technologies, however, can increase the cybersecurity attack surface. The purpose of this research was to develop a holistic cybersecurity risk reduction framework for fossil generation facilities. The framework begins with assessing how cyber risk changes across facility life cycles, including plant, system, vendor, and business life cycles. The next phase performs consequence analysis to prioritize high consequence events. Focusing on high consequence events allows owners to use a graded, risk-informed approach to prioritize cybersecurity efforts. The final phase identifies the digital asset attack surface in sensors and instrumentation and control equipment. After the vulnerabilities are identified, the owner selects mitigating cybersecurity control measures (or countermeasures) based on the risk analysis from the previous phases. This report describes the current industry cybersecurity best practices in fossil generation that are based on the first principles for cybersecurity engineering. The report is divided into five sections that describe the implementation of the risk reduction framework and present identified research, methodological, and technology gaps that were identified through this course of research and development.

01 COAL, LIGNITE, AND PEAT↗

Fossil Power Plant Cyber Security Life-Cycle Risk Reduction: A Practical Framework for Implementation

Market conditions are forcing fossil electricity generation facility owners and operators to implement advanced digital technologies. These technologies enable efficiencies, operational flexibility, operations and maintenance efficiencies, and adapting to a transitioning workforce. These digital technologies, however, can increase the cybersecurity attack surface. The purpose of this research was to develop a holistic cybersecurity risk reduction framework for fossil generation facilities. The framework begins with assessing how cyber risk changes across facility life cycles, including plant, system, vendor, and business life cycles. The next phase performs consequence analysis to prioritize high consequence events. Focusing on high consequence events allows owners to use a graded, risk-informed approach to prioritize cybersecurity efforts. The final phase identifies the digital asset attack surface in sensors and instrumentation and control equipment. After the vulnerabilities are identified, the owner selects mitigating cybersecurity control measures (or countermeasures) based on the risk analysis from the previous phases. This report describes the current industry cybersecurity best practices in fossil generation that are based on the first principles for cybersecurity engineering. The report is divided into five sections that describe the implementation of the risk reduction framework and present identified research, methodological, and technology gaps that were identified through this course of research and development.

20 FOSSIL-FUELED POWER PLANTS↗

Fossil Power Plant Cyber Security Life-Cycle Risk Reduction: A Practical Framework for Implementation

Market conditions are forcing fossil electricity generation facility owners and operators to implement advanced digital technologies. These technologies enable efficiencies, operational flexibility, operations and maintenance efficiencies, and adapting to a transitioning workforce. These digital technologies, however, can increase the cybersecurity attack surface. The purpose of this research was to develop a holistic cybersecurity risk reduction framework for fossil generation facilities. The framework begins with assessing how cyber risk changes across facility life cycles, including plant, system, vendor, and business life cycles. The next phase performs consequence analysis to prioritize high consequence events. Focusing on high consequence events allows owners to use a graded, risk-informed approach to prioritize cybersecurity efforts. The final phase identifies the digital asset attack surface in sensors and instrumentation and control equipment. After the vulnerabilities are identified, the owner selects mitigating cybersecurity control measures (or countermeasures) based on the risk analysis from the previous phases. This report describes the current industry cybersecurity best practices in fossil generation that are based on the first principles for cybersecurity engineering. The report is divided into five sections that describe the implementation of the risk reduction framework and present identified research, methodological, and technology gaps that were identified through this course of research and development.

20 FOSSIL-FUELED POWER PLANTS↗

Consequence-Driven Cybersecurity for High-Power Electric Vehicle Charging Infrastructure

Cybersecurity of high-power charging infrastructure for electric vehicles (EVs) is critical to the safety, reliability, and consumer confidence in this publicly accessible technology. Cybersecurity vulnerabilities in high-power EV charging infrastructure may also present risks to broader transportation and energy-infrastructure systems. Here, this paper details a methodology used to analyze and prioritize high-consequence events that could result from cybersecurity sabotage to high-power charging infrastructure. The highest prioritized events are evaluated under laboratory conditions for the severity of impact and the complexity of cybersecurity manipulation. Mitigation solutions and strategies are presented to secure the vulnerabilities that potentially lead to high-consequence events. These mitigations can be immediately implemented by industry or executed during the design stage.

25 ENERGY STORAGE↗

Cyber-Informed Engineering: Standards Development Organization Quick Start Guide

Cyber-Informed Engineering (CIE) is an emerging methodology focused on identifying and reducing high-consequence events that may affect physical critical infrastructure systems as a result of their dependence on digital technology. CIE, developed by National Laboratories and promoted by the Department of Energy (DOE), incorporates consequence-focused planning into the design and engineering process from the earliest stages of a project. This guide provides a concise overview of CIE and offers practical insight into how Standards Development Organizations (SDOs) can interpret CIE principles and apply those concepts in updates to various standards. It is important to remember that CIE extends beyond a compliance checklist, emphasizing a broader, interpretive approach. Instead, it encourages an interpretive mindset - a "turning of 'what if' to 'even if'" approach that anticipates and engineers out high-consequence events. The authors encourage SDOs to establish and promote CIE principles as enhancements for more resilient-by-design outcomes across critical infrastructure energy sectors. The 12 core principles of CIE outline specific behaviors and actions that SDOs and engineers may adopt to enhance system resilience. This guide applies these principles in a manner intended to be relevant across various technologies and threat landscapes. We welcome institutions and vendors to identify new or different framework alignments and mappings as we collectively work towards a safer and more reliable digital landscape.

97 MATHEMATICS AND COMPUTING↗

Risks from Solar Particle Events for Long Duration Space Missions Outside Low Earth Orbit

The Integrated Medical Model (IMM) simulates the medical occurrences and mission outcomes for various mission profiles using probabilistic risk assessment techniques. As part of the work with the Integrated Medical Model (IMM), this project focuses on radiation risks from acute events during extended human missions outside low Earth orbit (LEO). Of primary importance in acute risk assessment are solar particle events (SPEs), which are low probability, high consequence events that could adversely affect mission outcomes through acute radiation damage to astronauts. SPEs can be further classified into coronal mass ejections (CMEs) and solar flares/impulsive events (Fig. 1). CMEs are an eruption of solar material and have shock enhancements that contribute to make these types of events higher in total fluence than impulsive events.

health↗

Consequence analyses of sabotage-induced radiological releases in high-temperature helium-cooled prismatic microreactors

Here, this study analyzes the radiological dose consequences of sabotage-induced accidents at three high-temperature helium-cooled prismatic microreactors (HTPMs) with thermal power ratings of 1, 10, and 50 MWt. Each HTPM employs uranium oxycarbide tristructural isotropic fuel enriched to 19.75 wt% high-assay low-enriched uranium. Simulations were conducted to estimate reactor core inventory at the point of fuel discharge––when the effective multiplication factor reduced to less than 1––representing peak radionuclide inventory. Postulated sabotage scenarios leading to reactor shutdown were analyzed at two intervals: immediately post-shutdown (0 h) and 3 days after shutdown using the SCALE code for radionuclide inventories and the RASCAL tool for dose consequences. Results show that although HTPMs benefit from inherent safety features and robust fuel design, radiological consequences scale with reactor power because of increased source term inventories. Smaller microreactors exhibited proportionally lower dose consequences. To support the economic and regulatory feasibility of microreactor deployment, this study emphasizes the value of a risk-informed, performance-based approach, as supported by regulations like 10 CFR Parts 100 and 53 in the United States. Microreactor developers should perform site-specific assessments of potential sabotage or low-probability, high-consequence events, especially when considering minimal on-site or full off-site emergency response.

Consequence↗

Cyber-Informed Engineering Validation Methods and Guidance

Validation is an important step in any systems engineering process to ensure the correct system was made to fulfill stakeholders’ needs, goals, and expectations. In the context of Cyber-Informed Engineering (CIE), validation ensures cyber impact is reduced through implemented design choices and CIE requirements. This document details a process in validating CIE-based design choices relative to their effectiveness at mitigating high consequence events. The document includes a case study to illustrate the CIE validation process. The case study explores the implementation of CIE validation within the engineering lifecycle of a chemical mixing plant.

42 ENGINEERING↗

Consequence-driven cyber-informed engineering and related systems and methods

Embodiments of the disclosure relate to a computer-implemented consequence-driven cyber-informed engineering tool for performing and reporting consequence-based prioritization, system-of-systems breakdown, consequence-based targeting, and mitigations and protections. Embodiments of a CCE tool may perform one or more steps of defining a target industrial control system (ICS), wherein the target ICS includes operational goals, critical functions, and critical services; determining one or more scored high consequence events (HCE) associated with the defined target ICS; prioritizing the scored HCEs according to an HCE severity index; and updating a dashboard with one or more representations of the prioritized HCEs, wherein the updated dashboard is associated with the CCE tool and presented at a display.

Assante, Michael↗

CCE Case Study: Stinky Cheese Company

This document explores how to apply Consequence-driven Cyber-informed Engineering (CCE) to identify and mitigate catastrophic effects resulting from cyber-enabled sabotage in a case study. For this case study, we will examine a fictional organization named the Stinky Cheese Company.

99 GENERAL AND MISCELLANEOUS↗

The flute instability as the trigger mechanism for disruption of cometary plasma tails

The sporadic disruption of the plasma tails of some comets has recently been explained to be caused by magnetic-field-line reconnection in the cometary ionospheres due to magnetic-sector-boundary traversals. An alternative model is proposed in which the tail disruption is the end result of compression of the cometary ionosphere by high-velocity solar-wind streams, triggering the flute instability in the marginally stable tangential-discontinuity surface which separates the cometary ionosphere from the solar-wind plasma. According to the proposed model, the tail-disruption events could occur at all heliographic latitudes, whereas the Niedner-Brandt (1978) model should predict that these events are restricted to low heliographic latitudes in view of the present understanding of the sector structure of the heliosphere. Consequently, the high-latitude disruption events observed seem to present a difficulty for the latter model.

Ip, W.-H.↗

A Review of Resilience and Long-Term Planning in Power and Water Systems in the United States

There is recognition among power and water utilities that the frequency and magnitude of high consequence and low probability events could increase as a result of climate change. The interconnected nature of energy-water systems raises the possibility of cascading failures, increasing complexity and risks. Resilience and long-term planning are important ways of weathering the effects of climate change. First, to understand more about resilience, we reviewed existing literature on resilience definitions, metrics, and modeling, focusing on integrated water-power systems. Second, to understand how resilience and planning are being applied in practice, we interviewed utilities and organized, curated, and synthesized the interview data to arrive at several key findings, which are presented here. We found that there is not a consistent definition for resilience, yet it is something that utilities regularly plan for, often with different names and varying methods/measures. However, there is a tangible shift in the industry towards defining and determining measurable resilience metrics. While the exact metrics are a work in progress, utilities are taking steps forward by (1) putting people and culture at the center of resilience, (2) recognizing their own interdependencies, and (3) pursuing better cross-sector collaboration.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Overland flow numerical model prediction, Lower Triangle Region in East River Watershed, Colorado, 3 days

This data package contains numerical simulation results of surface flow variables such as flow velocity and water depth in Lower Triangle Region in East River Watershed, Colorado. The surface flow is a consequence of a high intensity rainfall event with a total duration of 3 days, available at a resolution of 10 minutes. The results are computed on triangular multiresolution meshes with resolutions ranging from 10 meter to 80 meter. The data package also contains a simulation on a uniform triangular mesh with a resolution of 10 meter. The simulations consider surface flow only and neglect subsurface flow, infiltration, and evapotranspiration. The purpose of the data is to assess the quality of a mesh refinement strategy.

54 ENVIRONMENTAL SCIENCES↗

How Low Can You Go? Using Synthetic 3D Imagery to Drastically Reduce Real-World Training Data for Object Detection

Deep convolutional neural networks (DCNNs) currently provide state-of-the-art performance on image classification and object detection tasks, and there are many global security mission areas where such models could be extremely useful. Crucially, the success of these models is driven in large part by the widespread availability of high-quality open source data sets such as Image Net, Common Objects in Context (COCO), and KITTI, which contain millions of images with thousands of unique labels. However, global security relevant objects-of-interest can be difficult to obtain: relevant events are low frequency and high consequence; the content of relevant images is sensitive; and adversaries and proliferators seek to obscure their activities. For these cases where exemplar data is hard to come-by, even fine-tuning an existing model with available data can be effectively impossible. Recent work demonstrated that models can be trained using a combination of real-world and synthetic images generated from 3D representations; that such models can exceed the performance of models trained using real-world data alone; and that the generated images need not be perfectly realistic (Tremblay, et al., 2018). However, this approach still required hundreds to thousands of real-world images for training and fine tuning, which for sparse, global security-relevant datasets can be an unrealistic hurdle. In this research, we validate the performance and behavior of DCNN models as we drive the number of real-world images used for training object detection tasks down to a minimal set. We perform multiple experiments to identify the best approach to train DCNNs from an extremely small set of real-world images. In doing so, we: Develop state-of-the-art, parameterized 3D models based on real-world images and sample from their parameters to increase the variance in synthetic image training data; Use machine learning explainability techniques to highlight and correct through targeted training the biases that result from training using completely synthetic images; and Validate our results by comparing the performance of the models trained on synthetic data to one another, and to a control model created by fine-tuning an existing ImageNet-trained model with a limited number (hundreds) of real-world images.

97 MATHEMATICS AND COMPUTING↗

Adaptation of G-TAG Software for Validating Touch-and-Go Comet Surface Sampling Design Methodology

The G-TAG software tool was developed under the R&TD on Integrated Autonomous Guidance, Navigation, and Control for Comet Sample Return, and represents a novel, multi-body dynamics simulation software tool for studying TAG sampling. The G-TAG multi-body simulation tool provides a simulation environment in which a Touch-and-Go (TAG) sampling event can be extensively tested. TAG sampling requires the spacecraft to descend to the surface, contact the surface with a sampling collection device, and then to ascend to a safe altitude. The TAG event lasts only a few seconds but is mission-critical with potentially high risk. Consequently, there is a need for the TAG event to be well characterized and studied by simulation and analysis in order for the proposal teams to converge on a reliable spacecraft design. This adaptation of the G-TAG tool was developed to support the Comet Odyssey proposal effort, and is specifically focused to address comet sample return missions. In this application, the spacecraft descends to and samples from the surface of a comet. Performance of the spacecraft during TAG is assessed based on survivability and sample collection performance. For the adaptation of the G-TAG simulation tool to comet scenarios, models are developed that accurately describe the properties of the spacecraft, approach trajectories, and descent velocities, as well as the models of the external forces and torques acting on the spacecraft. The adapted models of the spacecraft, descent profiles, and external sampling forces/torques were more sophisticated and customized for comets than those available in the basic G-TAG simulation tool. Scenarios implemented include the study of variations in requirements, spacecraft design (size, locations, etc. of the spacecraft components), and the environment (surface properties, slope, disturbances, etc.). The simulations, along with their visual representations using G-View, contributed to the Comet Odyssey New Frontiers proposal effort by indicating problems and/or benefits of different approaches and designs.

Mandic, Milan↗

Risk Management and Risk Aversion, from Benefit to Impediment

Risk management is a critical tool for improving the probability of project success by identifying, assessing, prioritizing, and attempting to control threats to project realization. For industries that require high operational reliability due to the potential consequences of off-normal events, such as the nuclear, aerospace, and chemical sectors, a major focus of risk management is the preservation of process safety. Due to the nature of the processes or systems under consideration, the associated process safety analyses (such as risk and safety assessments) and safety features can require significant resources. These costs are typically tolerated either due to the need to satisfy regulatory requirements or based on the assumption that they generally decrease the occurrence of unwanted events and therefore improve the probability of project success. However, as the level of acceptable or tolerable risk from unwanted events decreases, the required resources necessary for ensuring and demonstrating satisfaction of these criteria can grow and in turn can become one of the dominant impediments to project success. This paper outlines a high-level theoretical framework for the consideration of dominant project risks, which includes potential project failure from both the occurrence of high consequence off-normal events and the inability to achieve project completion due to the resource needs and innovation losses associated with extreme risk aversion. Utilizing such an integrated approach permits an attempt to optimize the probability of successful project realization while also providing valuable insight into the proper level of acceptable risk. The work is presented as a first step, in hopes of spurring additional discussion and analysis regarding appropriate levels of risk tolerance and the balance of project benefits.

Grabaskas, David↗

River Geomorphology Affects Biogeochemical Responses to Hydrologic Events in a Large River Ecosystem

Shifts in the frequency and intensity of high discharge events due to climate change may have important consequences for the hydrology and biogeochemistry of rivers. However, our understanding of event-scale biogeochemical dynamics in large rivers lags that of small streams. To fill this gap, we used high-frequency sensor data collected during four consecutive summers from a main channel and backwater site of the Upper Mississippi River. We identified high discharge events and calculated event concentration-discharge responses for both physical-chemical (nitrate, turbidity, and fluorescent dissolved organic matter) and biological (chlorophyll-a and cyanobacteria) constituents using metrics of hysteresis and slope. We found a range of responses across events, particularly for nitrate. Although fluorescent dissolved organic matter (FDOM) and turbidity exhibited more consistent responses across events, contrasting hysteresis metrics indicated that FDOM was flushed to the river from more distant sources than turbidity. Biological responses (chlorophyll a and cyanobacteria) differed more between sites than physical and chemical constituents. Lastly, we found that the event characteristics best explaining concentration responses differed between sites, with event magnitude more frequently related to responses in the main channel, and antecedent wetness conditions associated with response variation in the backwater. Furthermore, our results indicate that event responses in large rivers are distinct across the diverse habitats and biogeochemical components of a large floodplain river, which has implications for local and downstream ecosystems as the climate shifts.

54 ENVIRONMENTAL SCIENCES↗

Regulatory Considerations Regarding Potential High Temperature Fluid Releases in Advanced Reactor Designs

The current effort is supported by the U.S. Department of Energy (DOE), Advanced Reactor Demonstration Program (ARDP) Regulatory Development, Regulatory Framework Modernization area, which seeks to address potential regulatory challenges for advanced reactor vendors that are currently or will soon be initiating the licensing process. In pursuit of this goal, this effort seeks to aid the advanced reactor industry and regulatory bodies in understanding and addressing the potential occurrence of high-temperature fluid releases in advanced reactor designs as part of licensing and regulatory oversight of operation. Improving the awareness and understanding of the behavior and potential consequences associated with high-temperature fluid release events can ensure that they are appropriately considered and addressed.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗