Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “bill of materials”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Evaluation of Hardware and Software Bill of Materials (HBOMs/SBOMs) Extraction Methods

Hardware and software bills of materials (HBOMs and SBOMs) provide important visibility into the components, dependencies, and supply chain relationships within programmable digital devices. This visibility is critical for advanced nuclear reactor applications, where use of common or shared hardware components, software libraries, suppliers, or manufacturing processes may create common cause failure (CCF) vulnerabilities despite apparent diversity. This paper evaluates current approaches for obtaining and analyzing HBOMs and SBOMs in support of CCF, diversity and defense-in-depth (D3) assessments, and begins to explore potential methods for artificial intelligence/machine learning-based analysis. The availability of BOM information from advanced reactor manufacturers and vendors, representative hardware and software categories found in advanced reactor systems continues to limit research [13]. This paper compares commonly used BOM formats, including CycloneDX, SPDX, and SWID. It also surveys publicly available tools for generating BOMs from source code, compiled binaries, and hardware-related information, noting limitations in language coverage, system age, and format interoperability. Finally, this paper evaluates methods for correlating BOM data with vulnerability and exploitability information, including VEX, CVE, and CWE resources. The findings indicate that publicly available nuclear-vendor BOMs are limited, making third-party extraction and research into novel analysis techniques necessary.

Cybersecurity↗

Software Bill of Materials (SBOM) Sharing Lifecycle Report

As Software Bill of Materials (SBOM) adoption efforts mature, SBOM sharing continues to occur, but no single solution or set of solutions have become ubiquitous. The purpose of this report is to enumerate and describe the different parties and phases of the SBOM sharing lifecycle and assist readers in choosing suitable SBOM sharing solutions based on the amount of time, resources, subject-matter expertise, effort, and access to tooling that is available to the reader to implement a phase of the SBOM sharing lifecycle. The SBOM sharing lifecycle consists of the Discovery, Access, and Transport of an SBOM and this report details these individual phases and how an SBOM goes from author to the consumer. This report also details how potential enrichment activities may be performed on an SBOM to create a new product before or after it has been shared. The concept of a sophistication classification for SBOM sharing solutions is concurrently introduced with a focus on the inclusion or lack of certain features and effort associated with their implementation. Examples of low, medium, and high-sophistication solutions are provided; however, these examples and associated categorizations should not be seen as a qualitative judgment meant to push the reader towards a particular adoption strategy since sharing solutions are chosen based on the unique needs of the user. This report does recommend the SBOM community consider how to make current and future sharing solutions interoperable with each other as well as more automated methods to facilitate sharing and broader SBOM adoption. This report also highlights an SBOM sharing survey results obtained from interviews with stakeholders to understand the current SBOM sharing landscape. The categorized results of the survey suggest that SBOMs are currently transported directly to the receiver through email or similar informal communication mechanisms or alternatively the SBOM resides on a repository available to consumers. In addition to these transport methods, this report captures industry efforts to create private sharing solutions and services that can store and transport enrichment data and may use higher sophistication features that are cloud-based or using distributed ledger technologies.

97 MATHEMATICS AND COMPUTING↗

HERO WEC - Bills of Materials: WEC, RO System, and Submersible Pump

This submission includes detailed Bills of Materials for the NREL-designed and -built Hydraulic and Electric Reverse Osmosis Wave Energy Converter (HERO WEC), as well as the reverse osmosis assembly and submersible pump that are used in the HERO WEC. The WEC file is specific to the components and sub-components that are included on the in-water buoy portion of the WEC. The RO file is specific to the components and sub-components that are included on the reverse osmosis module that is used for both the hydraulic and electric configuration. The submersible pumps file is specific to the components and sub-components that are included on the submersible pump module that is used feed the reverse osmosis module when the HERO WEC is in the electric configuration. In addition to this submission, an additional submission available for the WEC model itself, including the power electronics enclosure, and reverse osmosis assembly that is needed to supply water in the electric submission. A link is provided below. More details on this project including data, CAD drawings, etc. can be found in the HERO-WEC main page link below. This data set has been developed by the National Renewable Energy Laboratory, operated by Alliance for Sustainable Energy, LLC, for the U.S. Department of Energy (DOE) under Contract No. DE-AC36-08GO28308. Funding provided U.S. Department of Energy Office of Energy Efficiency and Renewable Energy Water Power Technologies Office.

16 TIDAL AND WAVE POWER↗

Software Bill of Materials in the Nuclear Industry

Nuclear power plants (NPP) have thousands of digital assets throughout their facility. Typically, NPPs have asset and configuration management programs that capture the make, model, and version of a component. This information, however, usually only includes first- or second-tier components and does not capture the complete enumeration of software components and their dependencies within operational technology (OT) equipment. As seen with recent cyberattacks, this level of detail is insufficient for identifying if and where an exploitable vulnerability exists within a facility. A software bill of materials (SBOM) provides this detailed enumeration. Further, integrating SBOMs with vulnerability data sources and vulnerability attestation reports can provide improved awareness leading to better cyber risk management and incident response. Preferably, SBOMs are provided by the supplier; however, when an NPP already owns a device, it is less likely they will have a supplier provided-SBOM. Fortunately, SBOMs can be generated on installed digital assets. This paper provides an introduction to the U.S. Department of Energy Office of Nuclear Energy paper titled “Towards Software Bill of Materials in the Nuclear Industry,” which describes the SBOM ecosystem and provides a suggested approach to methodically and seamlessly integrate an SBOM program in an NPP.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Correspondence: Bill of Materials Variation and Module Degradation in Utility-Scale PV Systems

We report photovoltaic (PV) modules of the same make and model are often assembled with different bills of materials (BOMs). In this correspondence, we revisit two case studies of utility-scale silicon PV systems in which these differing BOMs were associated with faster-than-expected degradation. In one of the sites, we found that different metallization paste had been used for grid lines in some cells leading to loss of contact to the cell and severe series resistance degradation. We provide details on the observation of this mechanism at two additional sites not described in the original article. In a second case study, we found that two different types of cell had been used, and that they could be distinguished by their back contact. Cells with uniform back contacts suffered from light and elevated temperature induced degradation (LeTID), while those with local back contacts did not. We also briefly describe BOM variations observed at other sites to illustrate the extent of the challenge. Our results from both sites underscore that variations in BOM, even among modules of the same make and model can lead to reliability challenges.

14 SOLAR ENERGY↗

Strengthening the Security of Operational Technology: Understanding Contemporary Bill of Materials

The evolution of cyber-physical infrastructure has made its security more challenging. The last few years have witnessed a convergence of hardware and software segments in various domains, including operational technology (OT) which is responsible for carrying out critical tasks such as monitoring and controlling power grids, nuclear plants, transportation, and emergency services. Both hardware and software encapsulate numerous open source and proprietary subcomponents, making it crucial for end-users to understand the composition of the products they are using. For example, wind turbines incorporate thousands of lines of code (software) used for the turbine's design, planning, operation, and analytics in addition to the numerous hardware subcomponents that construct it. Due to the highly complex nature of software and hardware, knowledge of the components and subcomponents is required to mitigate cyber vulnerabilities and defend against cyberattacks. There has also been a transformation from a traditional linear supply chain into a global, dynamic, diverse, and interconnected system. The digitization of the supply chain makes it easier to find and exploit vulnerabilities. Critical infrastructures (e.g., power grids, oil, natural gas, water, and wastewater) rely on OT to function, and if the OT is compromised, equipment damage and potential interruption of services could result. A significant security measure to protect OT systems from disruption is to develop a supply chain bill of materials (BoM) corresponding to the software and hardware used in OT, along with attestations amongst vendors and asset owners. A supply chain BoM is a proactive way to understand the inherent vulnerabilities in the system and mitigate them in advance of being exploited. BoMs bolster the trust placed in the digital infrastructure and enhance software supply chain security by sustaining the management of component obsolescence and compliance, along with the seclusion of unsafe segments of a specific product. Adopting BoM tools is becoming increasingly important across various government sectors, as evidenced by the recent U.S. executive order on cybersecurity (NIST 2021). This paper aims to classify BoMs based on structure, functionality, component type, and architecture. The work also discusses case studies to further highlight the benefits of BoMs. In addition, it identifies missing pieces in existing BoM implementations so that future research may identify bounds on where it could expect to make improvements and directly enable researchers to identify promising areas for exploration. Further, the authors provide valuable recommendations to tool developers, researchers, and standardizing organizations (policymakers), additionally benefitting critical infrastructure owners and government executives. This aids in paving a path for future work, thereby, providing suggestions to determine a tool for consumers that best suit their needs.

97 MATHEMATICS AND COMPUTING↗

Evaluating Methods of Software Bill of Materials Generation to Enhance Nuclear Power Plant Cybersecurity

Instrumentation and control (I&C) systems in nuclear power plants (NPPs) are potential targets of cyberattacks and can prove deleterious for the safety of the NPPs. A Software Bill of Materials (SBOM) provides a detailed list of the various components and their dependencies in software, which helps in vulnerability and risk assessment for cyber hygiene and situational awareness. For an NPP, the process of generating an accurate SBOM report can be complex due to the legacy systems and firmware binaries involved. While most current SBOM tools are focused more on modern internet technology software, this research provides insights and guidelines for an NPP to generate an accurate and efficient SBOM. Here, the paper proposes a new methodology to help NPPs categorize software and use appropriate tools to generate SBOMs for their digital I&C systems.

SBOM↗

Towards Software Bill of Materials in the Nuclear Industry

Large, modern industrial facilities often incorporate thousands of digital assets in their operational technology. Regulated facilities, such as nuclear power plants (NPPs), maintain robust cybersecurity and configuration management programs that often use bills of materials (BOMs) for these assets, including make, model, and version of hardware, firmware, and software. However, these BOMs typically capture only first- or second-tier information provided by the original equipment manufacturer (OEM). Unfortunately, as indicated by the increasing number and sophistication of software supply chain attacks, this level of detail is insufficient for identifying all the potential vulnerabilities and risks in software applications. Software BOMs (SBOMs) provide detailed enumeration of components and dependencies within the product or devices, including firmware. SBOMs can be combined with vulnerability data sources and vendor vulnerability attestations to improve vulnerability management and enable rapid identification of affected components when new software vulnerabilities are discovered. Ideally, SBOMs are created by the OEM prior to installation. However, since this practice is not yet commonplace and since NPPs are typically slow to adopt new technology, most NPPs do not incorporate SBOMs into their asset or configuration management programs. Fortunately, SBOMs can be generated by NPPs on existing digital assets to provide further insight into risk management decisions. This report provides an overview of the current SBOM ecosystem and recommends guidance on how to get started in a “crawl, walk, run” manner to develop and implement a sustainable SBOM program for digital assets in an NPP.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

The Benefits of a Software Bill of Materials Program at Nuclear Facilities

Software supply chain attacks are becoming increasingly more prevalent in both information communications technology and operational technology environments. Often, a supplier or other entity discloses vulnerability information about software components and subcomponents used in a digital asset, but an asset owner is unable to quickly ascertain if the vulnerable component is installed in their facility. The generation and use of a software bill of materials (SBOM) for installed digital assets can enable an asset owner to quickly identify if and where a component is used, allowing them to evaluate the risk and determine necessary risk treatments. The integration of an SBOM program into a nuclear facility not only improves vulnerability management and risk management processes, it also benefits asset and configuration management, cybersecurity, and supply chain programs. This paper reviews the U.S. Department of Energy Office of Nuclear Energy Cybersecurity Crosscutting Technology Development program’s work on integrating an SBOM program into a nuclear facility. It also provides a discussion on the benefits of such a program.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

SoK: A Framework for and Analysis of Software Bill of Materials Tools

Modern software development has gradually become more complex, leveraging available open-source software and third party components. This practice has raised questions about the provenance, licensing, versioning and compliance of reused code and its dependencies. Furthermore, it is par ticularly important to review such code fragments and third party components for known-vulnerabilities before they are included in a software product. A Software Bill of Materials (SBoM) is a mechanism to achieve such an analysis, provid ing transparency and visibility into a software product to both the software developer and its respective consumer. An SBoM lists information and details about all the elements constituting a piece of software and can, therefore, be used to evaluate associated security risk. While the concept of SBoMs is growing in popularity, it is still fairly new to many organizations, causing them to potentially struggle with pro ducing and processing SBoMs and limiting their widespread adoption. In this work, we delve into the area of SBoMs and present the state-of-the-art SBoM tools, creating a framework for analysis and categorizing them based on a diverse set of features and functionalities. We are the first to provide a detailed analysis of 83 open-source SBoM tools along with a perspective on how a potential SBoM user can select a tool based on their specific requirements. Our work aims to help promote understanding of this domain, thereby encouraging and furthering its overall adoption. We additionally seek to pave a path for future work in this area by providing recommendations to tool developers and users, researchers, and standardizing organizations.

99 GENERAL AND MISCELLANEOUS↗

Visualizing Comparisons of Bill of Materials

Protecting critical infrastructure from cyber attacks, natural disasters, and other disruptions is a priority of the U.S. Government. Critical infrastructure includes providing electricity to homes and businesses, supplying natural gas for heating, and producing renewable energy sources. A loss of these services, as seen in the Solarwinds supply chain attack in 2020 , Texas snowstorm of 2021, the Colonial Pipeline cyber incident of 2021, and the Washington power substation attacks in 2022 result in high costs to consumers, disruption of everyday life, and even death. To protect the infrastructure, we first have to know what equipment we are protecting. The complexity of distributed manufacturing and development coupled with the increasing prevalence of cyber and supply chain attacks necessitates a greater understanding of the hardware and software components that comprise equipment in critical infrastructure. When a vulnerability in a single software library can have disastrous consequences, it is vital to understand critical equipment and systems at a granular level. This need has led to increased energy around the development and incorporation of bill-of-materials (BOM) into existing asset management practices to aid in mitigating, and responding to future attacks \cite{noauthor_software_nodate}. While much of the current research is devoted to creating BOMs, it is equally important to develop methodologies for leveraging BOMs to answer questions, such as: How has my software changed? Are two pieces of equipment equivalent? Does this piece of equipment that just arrived match my historical information? In this work, we demonstrate how BOMs can be represented by graph structures. We then describe how these structures can be fed into a graph comparison algorithm to produce a novel interactive visualization that allows us to not only identify differences in BOMs, but show exactly where they are in the product.

Jones, Rebecca D.↗

Different Damp-Heat-Induced Series Resistance Degradation Behaviors in Fielded Crystalline Silicon Photovoltaic Modules Due to Difference in Bill of Materials

This case study investigates mono-crystalline silicon modules from underperforming portions of a utility-scale photovoltaic power plant. Field-collected I-V curves and electroluminescence imaging suggested that increased series resistance was a primary factor driving module degradation. Selected modules were removed from the field for further analysis, including incremental damp heat accelerated testing, which confirmed a progression in series resistance degradation. Two distinct cell degradation behaviors became apparent during the investigation. Cross-sectional scanning electron microscopy (with elemental analysis) and scanning spreading resistance microscopy identified key differences between the two degradation mechanisms, primarily grid finger width and contact resistance. Additionally, the study highlights the reliability implications of retest requirements in International Electrotechnical Commission 61215 for material changes and how they may have mitigated the degradation observed at this site.

14 SOLAR ENERGY↗

CyTRICS: Vulnerability Analysis Tailored for Critical Infrastructure

Society and modern life are dependent on critical infrastructure that is composed of expensive, special purpose devices that have long life cycles and may be in use for decades before being replaced. There are an abundance of organizations and individuals doing vulnerability analysis on a variety of systems, but what makes the Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program unique and valuable is its strategic focus on high-priority critical infrastructure, close partnership with vendors, and ability to leverage bills of materials (BOMs) to identify and relate vulnerabilities to affected systems. Creating a bill of materials is a formal way of understanding and documenting the components of a system, including everything from integrated circuits to operating systems to third-party libraries. This is beneficial for connecting known vulnerabilities to affected devices, since vulnerabilities in a specific component are often not mapped to all systems that use that vulnerable component. Additionally, CyTRICS finds novel vulnerabilities through its vulnerability testing process and works closely with vendor partners to provide vulnerability reports so that affected systems can be patched in a timely manner. This presentation will describe the interrelated technical processes CyTRICS uses to create bills of materials and conduct vulnerability analysis.

99 GENERAL AND MISCELLANEOUS↗

Trends in Field and Laboratory Performance of Photovoltaic Modules and Materials

This DuraMAT project intends to identify bill of materials (BOM) and/or process control measures for photovoltaic modules with representative failure modes as informed by accelerated and field tests to guide next steps in module and material design. We have begun work to identify correlation between module field performance and accelerated testing results by cross-comparing a module database of accelerated test results with a module database of fielded systems. We have identified fielded systems with degraded performance, and intend to compare this to the results observed in certification and qualification testing. We also intend to apply lessons and observations from accelerated tests to the field, where it may be possible to mitigate or avoid degradation in the field.

DuraMAT↗

Techno-Economic Wind Blade Manufacturing Model to Identify Opportunities for Cost Improvements Phase II IACMI Project 4.6/4.8

In IACMI Project 4.6 and IACMI Project 4.8, an Excel-based Techno-Economic Model (TEM) of the manufacturing process for composite wind turbine blades and a DELMIA Factory Flow Simulation of a generic wind blade manufacturing facility was developed. Together, these two tools provide a combined economic modeling capability that accounts for the material, labor, overhead and full-lifecycle operating costs associated with wind blade manufacturing as well as the impact of process flow and factory layout on overall manufacturing efficiency. The tools provide a novel means of detailed comparative analysis of the economic feasibility of proposed technologies and process changes for blade manufacturing. The modeling tools were developed with close support from members of industry and visits to multiple blade manufacturing facilities. With industry oversight, a detailed generalized manufacturing process plan and facility layout were developed with manufacturing parameters, material costs and economic factors based on historical data. Dassault Systèmes and the University of Texas at Dallas (UTD) contributed to the development of the Techno-Economic Model by providing macros to enable the generation of Bill of Material (BOM) data from a 3D blade design in either CATIA or NuMAD format, respectively. The TEM was built with the capability to directly import a Bill of Materials for economic analysis, and with the addition of the macros provided by Dassault and UTD, the TEM can directly import blade designs from both CATIA and NuMAD file formats. The modeling tools developed in Project 4.6 were used to investigate four wind blade manufacturing concepts in detail and select one to explore with laboratory-scale experimentation in Project 4.8. The four manufacturing concepts that were investigated were down-selected by the full project team from a larger list of concepts. The selections were made based on a number of criteria ranking viability and level of interest for each concept. The ‘One-Step Close’ manufacturing concept was ultimately selected for investigation in Project 4.8 and the demonstration was performed at the NREL CoMET facility. The TPI advanced manufacturing facility in Warren, RI contributed the production of several prototype components, the designs for which were developed by Janicki Industries. The demonstration project provided clear indication of the viability of the One-Step Close manufacturing concept for blade manufacturing and good validation of the Techno-Economic Model’s prediction of its economic impact.

17 WIND ENERGY↗

Development and Validation of Low-Cost, High-Reflectance Composite CSP Facets: SIPS Final Report

This work investigates the various challenges associated with developing heliostat structural composite facets using 1 mm glass mirrors. Such facets are desirable for Concentrating Solar Power because 1 mm glass mirrors provide an absolute increase in reflectivity of 2-3 % over the industry standard of 4 mm glass mirrors. Prototypes of paraboloid composite facets with 1 mm glass mirrors were constructed that have a root mean square slope error on the order of 2 mrad while achieving greater than 96% reflectivity. These facets were constructed using a low-quality aluminum mold and a bill of materials that show potential to achieve cost parity with existing 4 mm glass mirrors supported by structural steel. The facets produced were able to survive up to 50 mm hail ball impacts and were robust against accelerated environmental cycling designed to expose durability concerns. Further work is needed to develop a scalable and cost-effective manufacturing process with a similar bill of materials.

14 SOLAR ENERGY↗