Engineering PapersSearch

SEARCH · Engineering Papers

Results for “Posture”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

DEVELOPMENT AND APPLICATION OF RISK ANALYSIS TOOLKIT FOR PLANT RESOURCE OPTIMIZATION

This paper presents the development of methods and tools that are being designed to optimize plant operations (e.g., maintenance/replacement schedules and optimal maintenance postures for plant components) in a manner that is more cost effective than current approaches and makes better use of available component health and cost data. These methods include both data- and model-based optimization methods. Model-based optimization methods directly include reliability and cost models to determine an optimal plant operational strategy. We consider gradient-based and evolutionary (based on genetic algorithms) optimization methods. The second class of methods target more specific use cases (e.g., project schedule optimization) and are not based on reliability models directly, but they require specific component reliability and cost data. This class of methods is based on variants of the knapsack problem with an aim to determine an optimal project schedule that maximizes the overall NPV. This paper also presents multi-objective methods designed to identify an optimal maintenance posture based on a Pareto frontier analysis. Rather than dictating the “right” tradeoff (i.e., identify the absolute best posture), we show how it is possible to perform a trade space exploration approach (i.e., identify value and costs of several postures and let the analysis account for desired value and cost metrics). This is performed by identifying maintenance postures that maximize value (e.g., system availability) and minimize operational costs, i.e., the Pareto frontier in a value-cost trade space. For all these methods we present detailed applicative examples that show their validity from a decision-making perspective.

97 - MATHEMATICS AND COMPUTING

Cyber Informed Engineering Cie Analysis Tool

Main Benefits: • Collaborate on assessment via the web and access and share assessments on your mobile device. • Helps you maximize your cybersecurity investment and resources • Saves you significant time and money by eliminating the requirement to research each government and industry standard in order to understand your cybersecurity posture • Contains easy to follow, step by step instructions to guide you through the process of identifying the cybersecurity posture of your organization • Provides a place to begin with cybersecurity improvement and a way to prioritize your tasks and budgets. • Covers all major cyber relevant topic areas for a comprehensive assessment of your organization’s cybersecurity posture. • Dives deep into the details of each topic area. • Contributes to the organization's risk management and decision-making process • Highlights vulnerabilities and gaps in your organization's IT and control systems. • Raises awareness and facilitates discussion on cybersecurity within your organization • Educates the controls system community on cyber security.

Hansen, Barry [Idaho National Laboratory (INL), Id

An Evaluation of The Dynamic Physical Security Risk Assessment Methodology for Fleet-Wide Applications

The requirements for U.S. nuclear power plants to maintain a large onsite physical security force contribute to their high operational costs. The cost of maintaining the current physical security posture is approximately 10% of the overall operation and maintenance budget for commercial nuclear power plants. The goal of the Light Water Reactor Sustainability (LWRS) program’s physical security pathway is to develop tools, methods, and technologies and provide the technical basis for an optimized physical security posture. The conservatisms built into current security postures may be analyzed and minimized to reduce security costs while still ensuring adequate security and operational safety. The research performed at Idaho National Laboratory within LWRS program’s physical security pathway has successfully developed a dynamic force-on-force modeling framework using various computer simulation tools and integrating them with the dynamic assessment Event Modeling Risk Assessment using Linked Diagrams (EMRALD) tool. This integrated process for physical security analysis is named Modeling and Analysis for Safety Security using Dynamic EMRALD Framework (MASS-DEF). This document provides an update on the progress in applying the MASS-DEF process to an operating commercial nuclear power plant as well as additional industry feedback regarding use of the tool for other physical security risk-informed topics. This report is only a summary of the progress and does not contain specific modeling results as those contain sensitive security information. Previous reports described how a user could integrate their plant-specific force-on-force models with the dynamic simulation tool EMRALD, model operator actions, and integrate with probabilistic risk assessment tools, such as CAFTA (Computer Aided Fault Tree Analysis System) or SAPHIRE (Systems Analysis Programs for Hands-on Integrated Reliability Evaluations), and with thermal-hydraulic tools, such as RELAP-5 or MAAP. Previous reports applied various combinations of available simulations codes with EMRALD using generic plant models to demonstrate how to perform the analysis. This report is an update the progress of applying the dynamic computational framework to an actual nuclear facility using their security scenarios and timelines. This report also provides an update to the procedural guidance for the MASS-DEF process and an overview of the generic models available for use by utilities. This report does not contain any plant’s sensitive information and/or safeguards information. This study’s purpose was to verify that the results achieved using generic models are similar to actual plant results and refine our guidance on the use of the framework. This assessment enables further analysis, such as what-if scenarios and staff-reduction evaluation, thereby optimizing physical security at plants.

22 GENERAL STUDIES OF NUCLEAR REACTORS

FEMP Cybersecurity Arsenal

The FEMP Cyber Security Arsenal is a family of cyber security tools for the federal facility owners and operators. Using these tools, facility owners can evaluate their overall cybersecurity posture. These tools are web-based front-end tools. The tools are meant to help federal owners and operators to evaluate their overall cybersecurity posture. These tools are developed based on the NIST Cybersecurity framework, risk management framework, and DOE C2M2 architectures. Version 3 provides significant updates and features in ten areas

Ashley, Travis [Pacific Northwest National Laborat

Land-Based Wind Reference Architecture

This report describes a summary and the final deliverables for the Wind Reference Architecture project funded by the Department of Energy's (DOE) Wind Energy Technology Office (WETO). The project objective was to further refine the reference architecture of the existing wind power plant reference architecture developed by Idaho National Laboratory (INL) and Sandia National Laboratories (SNL) by expanding the wind turbine generator (WTG) into a separate individual wind turbine reference architecture. Additional details regarding the wind turbine system and how it integrates with a wind power plant were researched and reflected in the reference architecture. This addition is important because it allows researchers to understand the components and devices in a wind turbine, how they function and how a wind turbine integrates into a wind power plant to be able to perform cybersecurity evaluations on the system. The communication and control systems were the focus while developing this reference architecture to understand the cybersecurity posture of a wind turbine and power plant. The information technology (IT) and operational technology (OT) systems perspective are integral in helping improve the cybersecurity posture by creating a starting point to study how wind energy can be safely designed and deployed in our power grid from an integrated systems standpoint. A holistic wind power plant and turbine reference architecture and simulation was developed and made open-sourced for further research efforts.

17 WIND ENERGY

Implementing an Objectives-Driven, Risk-Informed, and Case-Assured Approach to Safety and Mission Success at NASA

NASA is developing a “Standard for Assurance of Space Flight Safety and Mission Success” that implements an objectives-driven, risk-informed, and case-assured approach to safety and mission success (S&MS) for NASA space flight programs and projects. The standard aligns with the philosophy of risk leadership that has recently been established in NASA policy to assure acceptable levels of flight crew safety and mission success risk. It is consistent with existing NASA risk management requirements and is compatible with NASA program management and systems engineering requirements. The methodology described in the standard is presented in terms of an S&MS assurance framework that is designed to allow substantial flexibility in the specific means by which programs and projects achieve acceptable mission S&MS risk. Such flexibility is necessary to accommodate the increasingly broad range of acquisition strategies employed by NASA, including commercial transportation services, as well as to accommodate the increasingly rapid evolution of space flight-related technologies and practices. A key feature of the S&MS assurance framework is the specification of S&MS success criteria for each life-cycle review (LCR). The S&MS assurance case is structured around these criteria, the satisfaction of which indicates that the program/project is adhering to the S&MS risk posture. This enables the evolving S&MS assurance case to be used as a fundamental program/project submittal at each LCR, where its inherent structure of argument, supported by evidence, directly supports the evaluation of the program/project with respect to the S&MS success criteria, and by extension, the S&MS risk posture. As such, the S&MS assurance case is integral to program/project systems engineering, risk management, and S&MS oversight activities, and provides the principal basis for S&MS risk acceptance by the Decision Authority throughout the program/project life cycle.

42 ENGINEERING

Exploring the effectiveness of a back-supporting exosuit: Trunk muscle activity and user experience in controlled and real-world shoveling scenarios

Introduction: This study evaluates the effectiveness of a passive wearable exosuit (HeroWear Apex) in reducing lumbar muscle effort while shoveling. Method: Two experiments were conducted, involving: (1) moving calibrated sandbags at a predefined pace in a laboratory, and (2) moving loose dirt in an in-field setting. Studies were designed to emulate real-world shoveling conditions at Department of Energy - Environmental Management sites. Muscle activity of the lumbar and oblique muscles was analyzed, along with user perceptions. Due to the asymmetric nature of shoveling, analysis of muscle activity was split between the weighted and unweighted sides, with the weighted side being defined as the side of the body closest to the head of the shovel in a neutral posture. Results: While donning the device, both experiments showed a significant decrease in muscle activity for at least one lumbar muscle on the weighted side. Participants rated the device with a high usability score, and perceived exertion ratings were significantly lower while wearing the exosuit. While opinions varied regarding the device’s helpfulness, participants felt the device was comfortable and did not hinder motion during the task. Practical applications: The reduction in back muscle activity associated with wearing the exosuit has the potential to reduce muscle fatigue resulting from repetitive motions.

Exoskeleton

Designing resilient IoT and Edge Computing with federated tinyML

The rapid growth of the Internet of Things (IoT) and Edge Computing (EC) has brought significant conveniences to modern society but has also greatly expanded the cyber attack surfaces, particularly as these technologies are being increasingly integrated into critical systems such as power grids, healthcare, and smart homes. Here, to improve IoT/EC’s cybersecurity posture, we leveraged Artificial Intelligence (AI) and Machine Learning (ML) by employing tinyML to monitor voluminous IoT data for cyber threats while addressing devices’ resource constraints, and utilizing Federated Learning (FL) to share local detection knowledge across the system while preserving privacy. Building on our three-layer architecture combining tinyML and FL to enhance autonomous cyber attack detection, this paper demonstrated that the architecture improves detection accuracy, reduces resource consumption, and enables lightweight, secure IoT device monitoring. These results were validated using the public N-BaIoT dataset as well as real IoT network traffic data collected under multiple attack scenarios from our testbeds. Additionally, we introduced an enhanced FL methodology with a novel preprocessing stage, including federated feature selection and global preprocessor construction, to address IoT/EC data heterogeneity. We developed a physical IoT testbed for attack simulations and data collection, implemented a tinyML-powered detector for realistic model validation, and also built a virtual testbed for scalable evaluations of FL models across diverse network environments.

Cognitive cyber

Loading Capacity and Dilute Nitric Acid Rinse of Diglycolamide Resin for the Recovery of Transplutonium and Rare Earth Elements from Mark-18A Targets

N,N,N′,N′-tetraoctyldiglycolamide (TODGA) as a resin (“DGA resin”) produced by Eichrom Technologies will be used by Savannah River National Laboratory for the indiscriminate extraction of trivalent actinides and rare earth elements with the intent of recovering Cm and Am from dissolved irradiated 242 Pu Mark-18A targets in 7 to 9 M nitric acid. The extracted constituents will be recovered as an oxide by direct thermal decomposition of the loaded resin followed by calcination of the resultant residue. The characteristics of DGA resin with non-radiological feed simulant representative of the anticipated feed in the Mark-18A process, with Sm and Nd as surrogates for Cm and Am, respectively, including breakthrough point and saturation capacity were evaluated in this work. Additionally, this work examined the losses from the loaded resin by rinsing the resin bed with dilute acid to reduce the nitrate concentration in the resin bed prior to thermal decomposition operations to improve the safety posture of the process. A resin loading profile was developed, and the resin was determined to have a trivalent metal saturation capacity of 74 μmol/mL resin under the experimental conditions evaluated. Following a wash of the loaded resin bed with fresh 8 M HNO 3 , the trivalent metals retained was reduced to 68 μmol/mL resin, which represents the practical capacity of the resin for the Mark-18A process. Lighter lanthanides breakthrough the resin well before the saturation capacity is reached. Rinsing the saturated resin bed with 0.26 M HNO 3 was found to result in a rapid reduction in retention of rare earth elements by the resin. After 2.8 bed volumes of dilute acid rinse, the mean resin bed free acid concentration was reduced to 0.28 M and 3.1 bed volumes of dilute acid rinse resulted in a reduction of the cumulative rare earth element retention to 52 μmol/mL of resin.

Transplutonium separations

Designing a Comprehensive IDS Strategy for a Zero Trust Architecture Environment

Zero Trust Architecture or ZTA is a cybersecurity model for enterprises to structure their networked resources around to maintain total security externally and internally. In a Zero Trust environment, no part of the network is considered "trustworthy" and thus should be scrutinized and monitored extensively as is done in traditional "Trust But Verify" schemes at the network's perimeter. In this way, Zero Trust Architecture is a superior model for securing access to networked resources at the enterprise level. Fermilab, in pursuit of a better security posture, has decided to embrace this model of architecture for its network. Attaining this goal requires tremendous infrastructural, policy, and procedural adjustments that will affect all the lab's personnel and resources.

D'Antonio, Lucas

CARILEC Resilient Energy Community CoP for Cybersecurity Workshop Series: Cybersecurity Assessment Tools [Slides]

For the last several years and in collaboration with CARILEC, USAID and NREL have been working to support cyber resilience at power sector utilities in Latin America and the Caribbean. Direct technical assistance with regional utilities has been a key component of USAID-NREL Partnership activities, and technical assistance has typically included a foundational cybersecurity assessment using NREL's Distributed Energy Resource Cybersecurity Framework (DER-CF) tool. The DER-CF allows organizations to benchmark and evaluate their cybersecurity posture across the areas of Governance, Technical Management, and Physical Security. To complement the activities of the newly created CAREC IT/OT and Cybersecurity Team, this webinar on cybersecurity assessment tools includes an overview of the DER-CF tool and a discussion with regional stakeholders and NREL experts on the DER-CF assessment process and other resources for cybersecurity assessments.

24 POWER TRANSMISSION AND DISTRIBUTION

Cyber Informed Engineering (CIE) Principles Slide Presentation [Slides]

This document describes the concept and application of Cyber-Informed Engineering (CIE), a methodology that integrates cyber threat awareness into all stages of the systems engineering life cycle. It delineates how CIE enhances the security posture of critical infrastructure systems, which are increasingly targeted by sophisticated cyber threats. The exposition proceeds to methodically walk through the twelve foundational principles of CIE, each serving as a strategic guidepost for embedding cybersecurity into the fabric of system design, development, operation, and maintenance. The principles highlight the importance of proactive and comprehensive security measures that span from risk assessment to continuous improvement, ensuring that systems are not only designed with security in mind but are also resilient in the face of evolving cyber threats.

42 ENGINEERING

Design of Defensive Cybersecurity Architectures for High Temperature, Gas-Cooled Reactors

This report presents the design of defensive cybersecurity architectures (DCSAs) for High Temperature, Gas-Cooled Reactors (HTGRs). A DCSA is a cybersecurity design feature that places systems into security zones in a graded approach according to the importance of the functions performed by the systems. DCSA design efforts for advanced reactors may commence as early as the system-level design phase. This design approach is consistent with the draft regulatory guide for advanced reactor cybersecurity programs (DG-5075) and enables advanced reactor designers to consider the effects of security-by-design (SeBD) features on their DCSAs. Integration of DCSA design and other cybersecurity activities with the traditional design process as part of a SeBD framework may enable advanced reactor designers to improve the security posture of their plants while reducing implementation and operating costs. This report provides a DCSA template for an exemplar HTGR and describes a DCSA design process using event tree analysis so that the template may be optimized for a given HTGR design.

22 GENERAL STUDIES OF NUCLEAR REACTORS

Small Modular Reactor and Microreactor Security-by-Design Lessons Learned: Integrated PPS Designs

U.S. nuclear power facilities face increasing challenges in meeting dynamic security requirements caused by evolving and expanding threats while keeping costs reasonable to make nuclear energy competitive. The past approach has often included implementing security features after a facility has been designed and without attention to optimization, which can lead to cost overruns. Incorporating security into the design process can provide robust, cost-effective, and sufficient physical protection systems. The purpose of this report is to capture lessons learned by the Advanced Reactor Safeguards and Security (ARSS) program that may be beneficial for other advanced and small modular reactor (SMR) vendors to use when developing security systems and postures. This report will capture relevant information that can be used in the security-by-design (SeBD) process for SMR and microreactor vendors.

22 GENERAL STUDIES OF NUCLEAR REACTORS

DEReliction: A Cybersecurity Vulnerability Assessment Methodology for Distributed Energy Resources

With the increasing integration of Distributed Energy Resources (DER) into the electric grid, maintaining grid reliability and resilience requires that these devices remain secure. This paper discusses a cybersecurity vulnerability assessment methodology that incorporates best practices from Sandia National Laboratories, SANS Institute, OWASP Foundation, and other web and Internet of Things (IoT) penetration testing (“pen testing”) programs, courses, and frameworks for assessing the security posture of devices. The methodology involves five sequential steps: (1) Collect Public Information, (2) Extract Hardware Details, (3) Inventory Software Components, (4) Identify Vulnerabilities, and (5) Test Vulnerabilities. Each step uncovers potential weaknesses in both hardware and software components of DER devices, considering adversary tactics, techniques, and procedures (TTPs), and potential attack vectors along the way. The results from the execution of this method on multiple residential- and small commercial-scale photovoltaic (PV) inverters reveled hardware and software vulnerabilities, which highlight the benefit of taking a methodical approach to discover vulnerabilities. While the specific vulnerability details are not shared here, a generalized overview of findings underscore the importance of robust security assessments for DER devices. Adoption of an assessment framework of this kind will identify and mitigate cybersecurity threats and bolster the resilience of DER-integrated electric grids.

24 POWER TRANSMISSION AND DISTRIBUTION

Assessment of Physical Security Modeling and Simulation in the Vulnerability Assessment Process

This report provides a comprehensive assessment of physical security modeling and simulation tools available for use in the vulnerability assessment (VA) process for nuclear facilities. It outlines the historical evolution of VA methodologies, emphasizing the transition from traditional layer-based approaches to a more holistic framework that integrates detection probabilities directly into combat simulations. The document details the critical components of the VA process, including the characterization of targets, threats, and protective measures, as well as the development of adversary scenarios that reflect both insider and outsider threats. It highlights the importance of performance assurance programs, emphasizing the need for continuous evaluation and testing of security systems to ensure their effectiveness against evolving threats. Additionally, the report discusses the significance of utilizing accredited modeling and simulation tools in accredited areas to accurately represent adversary actions and the corresponding responses of protective forces. By establishing a systematic approach to VA, this document aims to enhance the overall security posture of nuclear facilities, ensuring compliance with regulatory standards while effectively mitigating risks associated with potential adversarial actions.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF

Enterprise Artificial Intelligence Strategy for Los Alamos National Laboratory

In the 1984 martial arts drama film, The Karate Kid, a young Daniel LaRusso is unexpectedly placed in an adversarial environment unable to eYectively adapt to a series of new threats and limitations. Fortunately for the main character, once placed under the tutelage of a Mr. Miyagi, he finds resiliency not through the adoption of new tools, but a re-focused set of fundamentals. Much in the same way that Daniel learns waxing on and buYing oY car wax by hand has rewards for Karate, LANL is choosing the harder path of self-hosting Large Language Models (LLMs) for enterprise use instead of only relying on buying access to a hosted AI service like Azure’s OpenAI Application Programming Interface (API). We also are not willing to wait for software-as-a-service (SAAS) AI services to meet us where we need to be from a FedRAMP accreditation standpoint. Our operations regularly depend on access at CUI, UCNI, ITAR and other FIPS-199 moderate-impact data levels and hosting our own services gives us the right security and compliance posture to be useful across the broad range of our work at LANL. With the rise in threats to critical infrastructure, cloud service providers (CSPs), and supply chain attacks from both state and non-state actors, we are not placing the bet that SAAS hosted AI services will be available when we need them. Should a major event occur, we do not want our staY and operations left without a pathway for us to fix the problem and resume the use of AI tools.

42 ENGINEERING

Zero Trust Strategies for Chemical, Biological, Radiological, and Nuclear Detection Systems: D.1 Cyber Scenarios

The evolving landscape of cybersecurity necessitates a paradigm shift to a Zero Trust (ZT) model, which assumes breaches and continuously verifies trust. This approach reshapes how trust boundaries are established, focusing on identities, devices, networks, applications, and data, rather than solely relying on perimeter defenses such as firewalls. Central to this transformation is the National Institute of Standards and Technology's (NIST) Special Publication 800-207, outlining the Zero Trust Architecture (ZTA), along with Executive Order 14028, which mandates federal agencies to adopt ZT principles. Complementary to these efforts, the Cybersecurity and Infrastructure Security Agency (CISA) developed the Zero Trust Maturity Model (ZTMM), providing a framework with five pillars and three cross-cutting capabilities to guide agencies toward enhanced cybersecurity maturity. In support of these initiatives, the DHS Countering Weapons of Mass Destruction Office (CWMD) is applying ZT principles to secure Chemical, Biological, Radiological, and Nuclear (CBRN) detection systems. Recognizing the diverse deployment models and network connectivity of these systems—from stationary, non-networked units to mobile, cloud-connected devices—the Pacific Northwest National Laboratory (PNNL) is developing cybersecurity scenarios specifically for CBRN environments. These scenarios examine various configurations and technological capabilities, offering insights into the application of ZTMM pillars in enhancing the security postures of CBRN devices. The cybersecurity scenarios presented by PNNL are hypothetical, crafted to explore theoretical situations and stimulate discussion on the potential use or compromise of CBRN detection systems in varied contexts. These narratives are illustrative and do not reference any real events or actual networks. Instead, they employ generalized reference models to highlight concepts and potential issues within CBRN security, focusing on how Zero Trust strategies can be adapted to address these challenges effectively.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF