Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “consequence prioritization”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

CCE Phase 1: Consequence Prioritization

Idaho National Laboratory (INL) developed the Consequence-driven Cyber-informed Engineering (CCE) methodology to provide public and private organizations with steps to work collaboratively and establish a working relationship to protect critical infrastructure and other national assets. This process is a considerable undertaking, iterative in nature, and—as time and resources allow—should become a part of a company’s culture. By focusing on the impact of potentially negative Events, CCE provides a better understanding of how and why adversaries can affect critical functions and services using cyber-enabled sabotage. This document describes Phase 1 of the CCE process.

99 GENERAL AND MISCELLANEOUS↗

CCE Phase 2: System-of-System Analysis

During Phase 1, Consequence Prioritization, the CCE Team identified High Consequence Events (HCEs) that can be accomplished through cyber means to impact critical functions, services, and processes. During Phase 2, System-of-Systems Analysis (SoS Analysis), the CCE Team will conduct a systematic review and analysis of information related to the equipment, systems, processes, operations, maintenance, testing, and procurement practices based on the HCEs identified in Phase 1.

99 GENERAL AND MISCELLANEOUS↗

The Science of Scientific Software Development and Use

Increasingly powerful and affordable computing has revolutionized scientific and scholarly discovery across a broad range of fields. Computing relies on software, which has been rapidly growing in scope, diversity, and complexity. At the same time, the methods, processes, and tools used to produce and utilize this essential software are often ad hoc, and the study and improvement of them is often done without the benefit of direct funding or prioritization. Consequently, concerns are growing about the productivity of the developers and users of scientific software, its sustainability, and the trustworthiness of the results that it produces. The US Department of Energy Office of Science (DOE-SC) is at the forefront of modern software-enabled scientific discovery across numerous areas of computational, experimental, and observational science, including major investments in national user facilities that support these activities. In December 2021, the DOE-SC Office of Advanced Scientific Computing Research (ASCR) convened a workshop on basic research needs for the Science of Scientific Software Development and Use (SSSDU). Through keynote presentations, lightning talks, and breakout groups, participants discussed the current practice of software development, maintenance, evolution, and use, and considered how the scientific method could be used to examine these practices and develop more evidence-based approaches to enhance the impact of software and computing on all areas of science. Workshop participants identified three priority research directions (PRDs) and three important crosscutting themes that center on the following overarching insight: software has become an essential part of modern science that impacts new discovery, policy, and technological development. To have full confidence in science delivered via software, we must improve the processes and tools that help us create and use it, and this enhancement requires a deep understanding of the diverse array of teams and individuals doing the work. The full workshop report will be available at https://doi.org/10.2172/1846009.

97 MATHEMATICS AND COMPUTING↗

Basic Research Needs in The Science of Scientific Software Development and Use: Investment in Software is Investment in Science

Increasingly powerful and affordable computing has revolutionized scientific and scholarly discovery across a broad range of fields. Computing relies on software, which has been rapidly growing in scope, diversity, and complexity. At the same time, the methods, processes, and tools used to produce and utilize this essential software are often ad hoc, and the study and improvement of them are often done without the benefit of direct funding or prioritization. Consequently, concerns are growing about the productivity of the developers and users of scientific software, its sustainability, and the trustworthiness of the results that it produces. Increased investment, especially in the characterization and improvement of how scientific software is developed and used, is important for sustaining and improving the impact of software as the scope and complexity of scientific efforts expand. Without this investment, we face the risk of diminishing returns on our software investments because the demands for increased functionality, usability, reliability, and more will not be sufficiently met. The US Department of Energy Office of Science (DOE/SC) is at the forefront of modern software-enabled scientific discovery across numerous areas of computational, experimental, and observational science, including major investments in national user facilities that support these activities. For many years, DOE/SC software investments have provided tremendous value to the scientific community. We want to continue and further improve the value of DOE/SC software efforts by using a scientific approach to understanding and improving how scientific software is developed and used. In December 2021, the DOE/SC Office of Advanced Scientific Computing Research (ASCR) convened a workshop on basic research needs for the Science of Scientific-Software Development and Use (SSSDU). Through keynote presentations, lightning talks, and breakout groups, which built on insights from 124 pre-workshop position papers, participants discussed the current practice of software development, maintenance, evolution, and use, and considered how the scientific method could be used to examine these practices and develop more evidence-based approaches to enhance the impact of software and computing on all areas of science. Workshop participants identified three priority research directions (PRDs) and three important crosscutting themes that center on the following overarching insight: Software has become an essential part of modern science, impacting discoveries, policy, and technological development. To maintain and improve confidence in science delivered via software, we must improve the processes and tools that help us create and use software, and this enhancement requires a deep understanding of the diverse array of teams and individuals doing the work.

97 MATHEMATICS AND COMPUTING↗

Fossil Power Plant Cyber Security Life-Cycle Risk Reduction, A Practical Framework for Implementation

Market conditions are forcing fossil electricity generation facility owners and operators to implement advanced digital technologies. These technologies enable efficiencies, operational flexibility, operations and maintenance efficiencies, and adapting to a transitioning workforce. These digital technologies, however, can increase the cybersecurity attack surface. The purpose of this research was to develop a holistic cybersecurity risk reduction framework for fossil generation facilities. The framework begins with assessing how cyber risk changes across facility life cycles, including plant, system, vendor, and business life cycles. The next phase performs consequence analysis to prioritize high consequence events. Focusing on high consequence events allows owners to use a graded, risk-informed approach to prioritize cybersecurity efforts. The final phase identifies the digital asset attack surface in sensors and instrumentation and control equipment. After the vulnerabilities are identified, the owner selects mitigating cybersecurity control measures (or countermeasures) based on the risk analysis from the previous phases. This report describes the current industry cybersecurity best practices in fossil generation that are based on the first principles for cybersecurity engineering. The report is divided into five sections that describe the implementation of the risk reduction framework and present identified research, methodological, and technology gaps that were identified through this course of research and development.

01 COAL, LIGNITE, AND PEAT↗

Fossil Power Plant Cyber Security Life-Cycle Risk Reduction: A Practical Framework for Implementation

Market conditions are forcing fossil electricity generation facility owners and operators to implement advanced digital technologies. These technologies enable efficiencies, operational flexibility, operations and maintenance efficiencies, and adapting to a transitioning workforce. These digital technologies, however, can increase the cybersecurity attack surface. The purpose of this research was to develop a holistic cybersecurity risk reduction framework for fossil generation facilities. The framework begins with assessing how cyber risk changes across facility life cycles, including plant, system, vendor, and business life cycles. The next phase performs consequence analysis to prioritize high consequence events. Focusing on high consequence events allows owners to use a graded, risk-informed approach to prioritize cybersecurity efforts. The final phase identifies the digital asset attack surface in sensors and instrumentation and control equipment. After the vulnerabilities are identified, the owner selects mitigating cybersecurity control measures (or countermeasures) based on the risk analysis from the previous phases. This report describes the current industry cybersecurity best practices in fossil generation that are based on the first principles for cybersecurity engineering. The report is divided into five sections that describe the implementation of the risk reduction framework and present identified research, methodological, and technology gaps that were identified through this course of research and development.

20 FOSSIL-FUELED POWER PLANTS↗

Fossil Power Plant Cyber Security Life-Cycle Risk Reduction: A Practical Framework for Implementation

Market conditions are forcing fossil electricity generation facility owners and operators to implement advanced digital technologies. These technologies enable efficiencies, operational flexibility, operations and maintenance efficiencies, and adapting to a transitioning workforce. These digital technologies, however, can increase the cybersecurity attack surface. The purpose of this research was to develop a holistic cybersecurity risk reduction framework for fossil generation facilities. The framework begins with assessing how cyber risk changes across facility life cycles, including plant, system, vendor, and business life cycles. The next phase performs consequence analysis to prioritize high consequence events. Focusing on high consequence events allows owners to use a graded, risk-informed approach to prioritize cybersecurity efforts. The final phase identifies the digital asset attack surface in sensors and instrumentation and control equipment. After the vulnerabilities are identified, the owner selects mitigating cybersecurity control measures (or countermeasures) based on the risk analysis from the previous phases. This report describes the current industry cybersecurity best practices in fossil generation that are based on the first principles for cybersecurity engineering. The report is divided into five sections that describe the implementation of the risk reduction framework and present identified research, methodological, and technology gaps that were identified through this course of research and development.

20 FOSSIL-FUELED POWER PLANTS↗

Consequence-driven cyber-informed engineering and related systems and methods

Embodiments of the disclosure relate to a computer-implemented consequence-driven cyber-informed engineering tool for performing and reporting consequence-based prioritization, system-of-systems breakdown, consequence-based targeting, and mitigations and protections. Embodiments of a CCE tool may perform one or more steps of defining a target industrial control system (ICS), wherein the target ICS includes operational goals, critical functions, and critical services; determining one or more scored high consequence events (HCE) associated with the defined target ICS; prioritizing the scored HCEs according to an HCE severity index; and updating a dashboard with one or more representations of the prioritized HCEs, wherein the updated dashboard is associated with the CCE tool and presented at a display.

Assante, Michael↗

Consequence-Driven Cybersecurity for High-Power Electric Vehicle Charging Infrastructure

Cybersecurity of high-power charging infrastructure for electric vehicles (EVs) is critical to the safety, reliability, and consumer confidence in this publicly accessible technology. Cybersecurity vulnerabilities in high-power EV charging infrastructure may also present risks to broader transportation and energy-infrastructure systems. Here, this paper details a methodology used to analyze and prioritize high-consequence events that could result from cybersecurity sabotage to high-power charging infrastructure. The highest prioritized events are evaluated under laboratory conditions for the severity of impact and the complexity of cybersecurity manipulation. Mitigation solutions and strategies are presented to secure the vulnerabilities that potentially lead to high-consequence events. These mitigations can be immediately implemented by industry or executed during the design stage.

25 ENERGY STORAGE↗

Quantitative Risk Assessment for Fuel Cell Electric Bus Hydrogen Storage and Refueling Facility

It is necessary to understand the safety implications and risk mitigation options for fuel cell electric bus fleet deployment, especially for related facilities responsible for operations such as production, storage, compression, and dispensing of hydrogen for use by the buses. In this report, we present a quantitative risk assessment for a potential fuel cell electric bus fleet that was motivated by efforts to improve resilience at the Portland International Airport but can be applicable to a range of hydrogen case studies and use cases. We estimated risk for a facility that produces, stores, compresses, and dispenses hydrogen for the fleet of buses, with a focus on individual risk to people in terms of annual frequency of fatality. We considered the frequency of hydrogen leaks that could result in harmful physical outcomes like jet fires or explosions, and the consequences of those outcomes for people. We created customized fault trees to calculate the frequencies of different sizes of leaks and event sequence diagrams to calculate ignition probabilities for the various leak sizes. We also leveraged the HyRAM+ toolkit to use these inputs to calculate overall risk for the facility, which we separated into one section responsible for producing, storing, and compressing hydrogen, and one section responsible for dispensing the hydrogen to the buses. We found that the dispensing area seemed to have a higher risk than the production/storage/compression area of the facility, largely because of the inclusion of a component with a high leak frequency (the heat exchanger used to cool the hydrogen before entering the vehicle, to prevent overheating and expansion of hydrogen in the onboard tank). For the example production and refueling facility we evaluated and the data we used for the analysis, the leak frequency had a larger impact on the risk differences between the two sections on the facility, compared to the physical outcome consequence, which was slightly different due to the varying fuel conditions, but not substantially different. Actions can be taken to prevent these hazards (e.g., lowering leak frequencies in system components) or to mitigate the consequences if they do occur (e.g., installing barriers to protect people if ignition events occur). The choice of which actions to take depends not only on safety considerations but also on space, time, staffing, feasibility, and financial constraints. Therefore, the quantitative risk assessment approach can help understand relative risk contributions from different components, leak sizes, consequences, and human actions, to prioritize risk reduction strategies and balance these parameters. The outcomes of this report may be useful for a variety of stakeholders working in the hydrogen, transportation, vehicle, and aviation sector, including those responsible for aspects like facility design, operations, and regulations. There is not a single value of risk that determines whether a hypothetical system is “safe” or not. The insights about risk mitigations may be leveraged, and the quantitative risk assessment approach can be applied to other case studies to understand risk priorities and contributions specific to different FCEB and hydrogen facility uses.

08 HYDROGEN↗

Communications Reliability for Vehicle Grid Integration

Electric Vehicles (EVs) adoption rate has been steadily increasing in the US leading to a growing number of charging stations including faster DC (Direct Current) chargers and slower Level 1 and Level 2 AC (Alternating Current) chargers. This increase in demand for electricity is further exacerbated by recent developments in Artificial Intelligence (AI) technology, advanced manufacturing, and digitization. These factors will require electric utilities to upgrade their infrastructure to keep up with the increasing electrical demand (especially during peak hours). An easy way to counteract the need for these upgrades is to shift a major chunk of active charge sessions (durations where there is energy transfer from charger to EV's propulsion battery) to off-peak hours thereby flattening the load curve and making the infrastructure more resilient. This concept is known as Smart Charge Management (SCM). EV owners also benefit from SCM since it lowers their charging costs and consequently their transportation costs by prioritizing charging during off-peak hours. SCM takes advantage of EV's capability to act as a controllable load or DER (Distributed Energy Resource). This report summarizes the reliability analysis performed on the communication required for two of these SCM use-cases. This analysis only focuses on SCM strategies for unidirectional charging (energy transfer from EVSE to EV or V1G) and not bidirectional charging.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Human Factors Assessment and Redesign of the ISS Respiratory Support Pack (RSP) Cue Card

The Respiratory Support Pack (RSP) is a medical pack onboard the International Space Station (ISS) that contains much of the necessary equipment for providing aid to a conscious or unconscious crewmember in respiratory distress. Inside the RSP lid pocket is a 5.5 by 11 inch paper procedural cue card, which is used by a Crew Medical Officer (CMO) to set up the equipment and deliver oxygen to a crewmember. In training, crewmembers expressed concerns about the readability and usability of the cue card; consequently, updating the cue card was prioritized as an activity to be completed. The Usability Testing and Analysis Facility at the Johnson Space Center (JSC) evaluated the original layout of the cue card, and proposed several new cue card designs based on human factors principles. The approach taken for the assessment was an iterative process. First, in order to completely understand the issues with the RSP cue card, crewmember post training comments regarding the RSP cue card were taken into consideration. Over the course of the iterative process, the procedural information was reorganized into a linear flow after the removal of irrelevant (non-emergency) content. Pictures, color coding, and borders were added to highlight key components in the RSP to aid in quickly identifying those components. There were minimal changes to the actual text content. Three studies were conducted using non-medically trained JSC personnel (total of 34 participants). Non-medically trained personnel participated in order to approximate a scenario of limited CMO exposure to the RSP equipment and training (which can occur six months prior to the mission). In each study, participants were asked to perform two respiratory distress scenarios using one of the cue card designs to simulate resuscitation (using a mannequin along with the hardware). Procedure completion time, errors, and subjective ratings were recorded. The last iteration of the cue card featured a schematic of the RSP, colors, borders, and simplification of the flow of information. The time to complete the RSP procedure was reduced by approximately three minutes with the new design. In an emergency situation, three minutes significantly increases the probability of saving a life. In addition, participants showed the highest preference for this design. The results of the studies and the new design were presented to a focus group of astronauts, flight surgeons, medical trainers, and procedures personnel. The final cue card was presented to a medical control board and approved for flight. The revised RSP cue card is currently onboard ISS.

Byrne, Vicky↗

Human Factors Assessment of Respiratory Support Pack (RSP) Cue Card

The Respiratory Support Pack (RSP) is a medical pack onboard the International Space Station (ISS) that contains much of the necessary equipment for providing aid to a conscious or unconscious crewmember in respiratory distress. Inside the RSP lid pocket is a 5.5 by 11 inch paper cue card, which is used by a Crew Medical Officer as the procedure to set up the equipment and deliver oxygen to a crewmember. In training, crewmembers expressed concerns about the readability and usability of the cue card; consequently, updating the cue card was prioritized as an activity to be completed prior to Space Shuttle return-to-flight. The Usability Testing and Analysis Facility at the Johnson Space Center evaluated the current layout of the cue card, and proposed several new cue card designs based on human factors principals. A series of three studies were performed in order to experimentally compare performance with each of the cue card designs. Nonmedically trained personnel used either a redesigned RSP cue card, or the original card to simulate resuscitation (using a mannequin along with the hardware). Time to completion, errors and subjective ratings were recorded. The addition of pictures, colors, borders, and simplification of the flow of information (making minimal changes to the actual procedure content) elicited great benefits during testing. Time to complete RSP procedures was reduced by as much as three minutes with the final cue card design. Detailed results from these studies, as well as general guidelines for cue card design will be discussed.

Whitmore, Mihriban↗

Cyber-Informed Engineering Briefing for ABET

Cyber-Informed Engineering (CIE) is an emerging method to integrate cybersecurity considerations into the conception, design, development, and operation of any physical system, energy or otherwise, to mitigate or even eliminate avenues for cyber-enabled attacks.?CIE concepts use design decisions and engineering controls to prioritize defense against the worst possible consequences of cyberattacks facing critical infrastructure systems and asset owners. These slides offer a deep dive into Cyber-Informed Engineering for engineering educators.

42 - ENGINEERING↗

Addressing Human System Risks to Future Space Exploration

NASA is contemplating future human exploration missions to destinations beyond low Earth orbit, including the Moon, deep-space asteroids, and Mars. While we have learned much about protecting crew health and performance during orbital space flight over the past half-century, the challenges of these future missions far exceed those within our current experience base. To ensure success in these missions, we have developed a Human System Risk Board (HSRB) to identify, quantify, and develop mitigation plans for the extraordinary risks associated with each potential mission scenario. The HSRB comprises research, technology, and operations experts in medicine, physiology, psychology, human factors, radiation, toxicology, microbiology, pharmacology, and food sciences. Methods: Owing to the wide range of potential mission characteristics, we first identified the hazards to human health and performance common to all exploration missions: altered gravity, isolation/confinement, increased radiation, distance from Earth, and hostile/closed environment. Each hazard leads to a set of risks to crew health and/or performance. For example the radiation hazard leads to risks of acute radiation syndrome, central nervous system dysfunction, soft tissue degeneration, and carcinogenesis. Some of these risks (e.g., acute radiation syndrome) could affect crew health or performance during the mission, while others (e.g., carcinogenesis) would more likely affect the crewmember well after the mission ends. We next defined a set of design reference missions (DRM) that would span the range of exploration missions currently under consideration. In addition to standard (6-month) and long-duration (1-year) missions in low Earth orbit (LEO), these DRM include deep space sortie missions of 1 month duration, lunar orbital and landing missions of 1 year duration, deep space journey and asteroid landing missions of 1 year duration, and Mars orbital and landing missions of 3 years duration. We then assessed the likelihood and consequences of each risk against each DRM, using three levels of likelihood (Low: less than or equal to 0.1%; Medium: 0.1%–1.0%; High: greater than or equal to 1.0%) and four levels of consequence ranging from Very Low (temporary or insignificant) to High (death, loss of mission, or significant reduction to length or quality of life). Quantitative evidence from clinical, operational, and research sources were used whenever available. Qualitative evidence was used when quantitative evidence was unavailable. Expert opinion was used whenever insufficient evidence was available. Results: A set of 30 risks emerged that will require further mitigation efforts before being accepted by the Agency. The likelihood by consequence risk assessment process provided a means of prioritizing among the risks identified. For each of the high priority risks, a plan was developed to perform research, technology, or standards development thought necessary to provide suitable reduction of likelihood or consequence to allow agency acceptance. Conclusion: The HSRB process has successfully identified a complete set of risks to human space travelers on planned exploration missions based on the best evidence available today. Risk mitigation plans have been established for the highest priority risks. Each risk will be reassessed annually to track the progress of our risk mitigation efforts.

Paloski, W. H.↗

Consequence Based Framework for Deployment of Cloud Solutions in the Digital Energy Transition

This study proposes a framework for evaluating cloud computing deployment in the electric sector, focusing on the digital transition of energy systems. It assesses the implications of cloud technology adoption, particularly in terms of security, operational resilience, and efficiency. The paper introduces a method for consequence-driven risk analysis, enabling utilities to prioritize and mitigate potential threats effectively. It also discusses the shared responsibility model in cloud computing, highlighting the need for collaborative security efforts. The research aims to provide utilities with a strategic assessment tool for cloud adoption, emphasizing the importance of security culture in enhancing cloud computing's role in critical infrastructure.

99 GENERAL AND MISCELLANEOUS↗