Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “consequence-based targeting”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Consequence-driven cyber-informed engineering and related systems and methods

Embodiments of the disclosure relate to a computer-implemented consequence-driven cyber-informed engineering tool for performing and reporting consequence-based prioritization, system-of-systems breakdown, consequence-based targeting, and mitigations and protections. Embodiments of a CCE tool may perform one or more steps of defining a target industrial control system (ICS), wherein the target ICS includes operational goals, critical functions, and critical services; determining one or more scored high consequence events (HCE) associated with the defined target ICS; prioritizing the scored HCEs according to an HCE severity index; and updating a dashboard with one or more representations of the prioritized HCEs, wherein the updated dashboard is associated with the CCE tool and presented at a display.

Assante, Michael↗

The evolution of the Human Systems and Simulation Laboratory in nuclear power research

The events at Three Mile Island in the United States brought about fundamental changes in the ways that simulation would be used in nuclear operations. The need for research simulators was identified to scientifically study human-centered risk and make recommendations for process control system designs. This paper documents the human factors research conducted at the Human Systems and Simulation Laboratory (HSSL) since its inception in 2010 at Idaho National Laboratory. The facility’s primary purposes are to provide support to utilities for system upgrades and to validate modernized control room concepts. In the last decade, however, as nuclear industry needs have evolved, so too have the purposes of the HSSL. Thus, beyond control room modernization, human factors researchers have evaluated the security of nuclear infrastructure from cyber adversaries and evaluated human-in-the-loop simulations for joint operations with an integrated hydrogen generation plant. Lastly, our review presents research using human reliability analysis techniques with data collected from HSSL-based studies and concludes with potential future directions for the HSSL, including severe accident management and advanced control room technologies.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Survey of Cyber Risk Analysis Techniques for Use in the Nuclear Industry

Using traditional probabilistic risk analysis methods for severe accident safety risk management on non-digital systems, structures, and components at nuclear power plants is well-established. In contrast, cyber risk analysis of digital assets is still an immature field with unproven techniques due, in part, to the continuously changing threat environment and the challenge of digital assets failing in unexpected ways. As the nuclear fleet continues to adopt digital instrumentation and control systems, it is increasingly important to have effective and efficient cyber risk analysis techniques to support risk management decisions, such as risk elimination by system redesign or risk mitigation by implementation of prioritized security controls. To understand the state of the art in cyber risk analysis for future research, we surveyed 36 publications across ten application domains. We describe our survey methodology and rate each technique based upon scope, adoptability, and repeatability. In this work, we examine the unique constraints of the nuclear industry and outline the strengths and weaknesses of using the cyber risk analysis techniques in the industry, highlighting gaps with current techniques. We also discuss challenges and potential research directions for advancing the science for both existing and new advanced reactors.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

A Cyber-Resilience Risk Management Architecture for Distributed Wind

Distributed wind is an electric energy resource segment with strong potential to be deployed in many applications, but special consideration of resilience and cybersecurity is needed to address the unique conditions associated with distributed wind. Distributed wind is a strong candidate to help meet renewable energy and carbon-free energy goals. However, care must be taken as more systems are installed to ensure that the systems are reliable, resilient, and secure. The physical and communications requirements for distributed wind mean that there are unique cybersecurity considerations, but there is little to no existing guidance on best practices for cybersecurity risk management for distributed wind systems specifically. This research develops an architecture for the consideration of cyber risks associated with distributed wind systems. The architecture takes into account the configurations, challenges, and standards for distributed wind to create a risk-focused perspective that considers of threats, vulnerabilities, and consequences, with special emphasis on what sets distributed wind systems apart from other distributed energy resources (DER). We discuss common distributed wind architectures and how they are interconnected to larger power systems. Because cybersecurity cannot exist independently, the cyber-resilience architecture must consider the system holistically. Finally, we discuss the implementation of a risk assessment process that uses the cyber-resilience framework to address challenges specific to distributed wind.

17 WIND ENERGY↗

Trade-off Analysis of Operational Technologies to Advance Cyber Resilience through Automated and Autonomous Response to Threats

The advancement of cyber resilience requires a preliminary stage of characterizing the trade-off space of mitigation options and how these might affect the stability and determinism of an operational technology (OT). This first step will set the stage for the proper cyber-secure and cyber-resilient design and confirm the affects that can be considered and approved by the OT and the security groups. To provide a baseline for this discussion, this paper provides a consideration of the cyberphysical interactions, possible mitigation steps against certain attacks and their corresponding affects that lend to the security design planning and evaluation process. As an integral part of the proposed scheme this work introduces the concept of systemwide fuzzer, i.e., a tool that manipulates the system state in an effort to determine mitigation response sequences that minimize detriments and maximize benefit in accordance with specified operational requirements.

97 MATHEMATICS AND COMPUTING↗

Distributed Optimization in Distribution Systems: Use Cases, Limitations, and Research Needs

We report electric distribution grid operations typically rely on both centralized optimization and local non-optimal control techniques. As an alternative, distribution system operational practices can consider distributed optimization techniques that leverage communications among various neighboring agents to achieve optimal operation. With the rapidly increasing integration of distributed energy resources (DERs), distributed optimization algorithms are growing in importance due to their potential advantages in scalability, flexibility, privacy, and robustness relative to centralized optimization. Implementation of distributed optimization offers multiple challenges and also opportunities. This paper provides a comprehensive review of the recent advancements in distributed optimization for electric distribution systems and classifications using key attributes. Problem formulations and distributed optimization algorithms are provided for example use cases, including volt/var control, market clearing process, loss minimization, and conservation voltage reduction. Finally, this paper also presents future research needs for the applicability of distributed optimization algorithms in the distribution system.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber-Informed Engineering Case Study of an Integrated Hydrogen Generation Plant

Strategies for securing digital instrumentation and control (I&C) systems within the nuclear industry are provided by multiple standards and guidance documents. However, since selection and use of security controls outlined in these documents are frequently only considered during or after installation, there are often limitations on their use, such as technological constraints related to design or operation. Furthermore, alternative controls intended to provide the same or similar security countermeasure as the primary control may also be infeasible at these stages, leaving the I&C system vulnerable to cyber-attacks. The limitations associated with ‘bolting on’ security controls late in the systems engineering lifecycle can be reduced by integrating Cyber-Informed Engineering (CIE) into the process. This paper evaluates the use of CIE during the high-level design stage of a hydrogen generation project where heat and electricity are provided by a nuclear power plant. Applying CIE to this project highlighted potential cyber vulnerabilities of the initial design, leading to recommendations for process flow and I&C system design modifications to reduce, and at times eliminate, the risk from both deliberate and unintentional cyber incidents.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

A Functional All-Hazard Approach to Critical Infrastructure Dependency Analysis

The critical infrastructures protection landscape is a vast and varied pattern of independent, but interconnected infrastructure systems that are essential to the function of our modern society. The U.S. policy on critical infrastructure protection has been continually evolving since the “President’s Commission on Critical Infrastructure Protection” was published in 1997. In response to these policies, federal, state, and local governments, along with research institutions, have invested a substantial amount of time and effort into identifying and analyzing critical infrastructure, their functions, and dependencies/interdependencies to better understand their vulnerabilities. To date, the ability to assess vulnerabilities, resiliency, and priorities for protecting interdependent critical infrastructure systems from an all-hazards perspective remains a difficult problem. In this paper we introduce the All-Hazards Analysis (AHA) methodology, which provides an integrated functional basis across infrastructure systems, through the implementation of a common language and a scalable level of decomposition to effectively evaluate the resilience of interconnected infrastructure systems. AHA models infrastructure systems as directed multidimensional graphs, which enable the evaluation of cross-sector interdependencies prior to, during, and after disruptive events. Finally, and by design, AHA enables the cross linking of data taxonomies to enable more effective data sharing, such as the National Critical Functions (NCF) and Infrastructure Data Taxonomy (IDT).

02 PETROLEUM↗

The Energy Transition: Advanced Nuclear Needed but Address Climate Vulnerabilities Now

The term “Energy Transition” is an attempt to capture an elaborate set of activities related to the modernization and decarbonization of energy grids. Performed concurrently and often in an ad hoc manner across local, state, regional and national boundaries, it is bringing chaos to what should arguably be one of the most conservatively managed of all critical infrastructure sectors. What’s more, with climate change producing an increasing tempo of extreme events, confidence in the intended resilient and redundant structure of the electric grids is likely to ebb. Even without these climate induced stressors, the nation’s electric grid was built for an earlier century. In addition to a drive towards greater efficiency via digitization and a continuing price decline in distributed energy resources (DERs), one could argue that climate change concerns are the primary driver of the energy transition. Non-CO2 emitting generation sources like wind and solar have become an important part of the overall generation fleet, albeit ones that cannot be counted upon to provide dispatchable power. Current projections indicate deployment of even larger percentages of DERs in coming years. Until far better storage capabilities arrive, the variability of wind and solar, inconsistent performance of traditional thermal generation plants, and energy delivery failures associated with natural gas pipelines will reinforce mounting reliability concerns. This pertains to both electric transmission and distribution. The recent shuttering of nuclear power plants in Germany, Japan, the US and elsewhere are also putting more downward pressure on dispatchable generation. Russia’s attack on Ukraine has roiled energy markets worldwide and forced some countries to return to coal as a primary fuel. In view circumstances such as these, it is essential that significant changes be made to policies and planning criteria, and to the standards and code on which they are based. Given the accelerating pace of extreme weather events, this needs to occur as soon as possible.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Securing Distributed Energy Resource Integration

The penetration of distributed energy resources (DER) is growing at much higher rates than predicted 20 years ago. Far from being used only in residential settings, DER are now installed on distribution and transmission circuits. In this position, they do not have the same properties as traditional generators and are more flexible in many cases. The growing penetration and range of uses for DER motivate the need to reliably and safely integrate them into the grid. Operators must be able to rely on them not only for normal operation, but also during abnormal conditions like black starts or adverse cyber scenarios. To that end, we study the communications, device interfaces, and potential consequences of DER operation under abnormal and adversarial conditions. The weaknesses of communications networks are studied based on the industrial protocols used, and the benefits of security features are examined. The device interfaces are found to be vulnerable to attack based on the requirements in the IEEE-1547 standard for DER interconnection and interoperability, which is expected to be adopted in the next ten years. In addition to exploring the requirements of the standard, we show that these vulnerabilities and others do exist and can be used maliciously in a modern storage system DER. Consequences of these vulnerabilities range from exacerbated grid instability, to simultaneous loss of large portions of DER penetration, to physical damage to inverters or DER themselves and other sensitive equipment. We tie these outcomes to specific attacker actions in an effort to give operators a better threat intelligence view that allows them to prioritize mitigations. Finally, we discuss mitigations that could prevent many of the adversarial scenarios described. Some solutions can be added to existing infrastructure, while others may require longer term planning for grid modernization with consideration for security.

25 ENERGY STORAGE↗

Materials and Fuels Complex (FY2021-2025 Five-Year Mission Strategy)

The Idaho National Laboratory (INL), through its designated mission of advancing innovative nuclear energy solutions, is actively engaged in the research, development, demonstration and deployment of advanced nuclear technology, as well as in fostering private-public partnership for technology development. Key to the success of INL’s mission is the Materials and Fuels Complex (MFC), the only complex in the U.S. that hosts a world-class assemblage of facilities, capabilities and instruments for handling, testing, and characterizing radioactive materials. Driven by its mission/vision of “Engineering and Experiments that Drive the World’s Nuclear Energy Future,” MFC is at the center of INL’s – and indeed the Department of Energy’s – advanced nuclear technology development initiatives, providing essential capabilities such as engineering-scale high-assay low-enriched uranium (HALEU) fuel production, reactor demonstration facilities, post-irradiation examination, and transient irradiation testing. Furthermore, MFC provides an ideal environment for test beds that are utilized for research, development and demonstration (RD&D) activities on used fuel treatment, nuclear non-proliferation, forensics, and nuclear power sources used for space exploration missions conducted by the National Aeronautics and Space Administration (NASA).

99 GENERAL AND MISCELLANEOUS↗

Managing Cyber Supply Chain Risk for Renewable Energy Technologies

On July 1, 2021, the U.S. Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) hosted a virtual workshop facilitated by the National Renewable Energy Laboratory (NREL). Cybersecurity supply chain experts, researchers, and leaders in government and industry came together to share information on current and future challenges in securing emerging technologies and technical architecture. From a cybersecurity perspective, we need to move from a cybersecurity approach that focuses principally on legacy asset owners to one that incorporates more emphasis on end-point device manufacturers and third-party integrators. Cybersecurity for the global digital supply chain for manufacturers of consumer end-point devices—such as smart solar inverters and smart electric vehicle (EV) chargers—will be critical to the future cyber health of the grid.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

DOE Fffice of Nuclear Energy cybersecurity research, development and demonstration program plan

This document describes the Cybersecurity Research Development and Demonstration (RD&D) Program, established by the Department of Energy Office of Nuclear Energy (NE) to provide sciencebased methods and technologies necessary for cost-effective, cyber-secure digital instrumentation, control and communication in collaboration with nuclear energy stakeholders. It provides an overview of program goals, objectives, linkages to organizational strategies, management structure, and stakeholder and cross-program interfaces.

97 MATHEMATICS AND COMPUTING↗

Electrification FY2020 Annual Progress Report

The Electric Drive Technologies (EDT) program’s mission is to conduct early-stage research and development on transportation electrification technologies that accelerate the development of cost-effective and compact electric traction drive systems that meet or exceed performance and reliability requirements of internal combustion engine (ICE)-based vehicles, thereby enabling electrification across all light-duty vehicle types.

33 ADVANCED PROPULSION SYSTEMS↗

Cybersecurity Certification Recommendations for Interconnected Grid Edge Devices and Inverter Based Resources

Escalating deployment of PV and grid-edge devices on the distribution grid has increased the sustainability and efficiency of the electric grid. However, the increasing number of distributed energy resources (DERs) deployed creates a heightened cyber-physical interdependency on the distribution grid and thus creates more vectors for cyber-attacks to exploit through information and communication technology (ICT) systems and networks. For example, control signal packets can be modified, intercepted, or corrupted due to vulnerabilities in communication protocols used by microgrid controllers and grid edge devices for power control. Therefore, to mitigate and prevent cyber-attacks on grid edge devices and the inverter-based resources connected to the distribution grid, the U.S. Department of Solar Energy Technologies Office (SETO) awarded funding to the National Renewable Energy Laboratory and Sandia National Laboratory (SNL) to research, develop, and harmonize cybersecurity standards for Photovoltaic (PV) systems and for other kinds of DERs. To help develop a standard for DER cybersecurity, NREL established certification recommendations and test cases, in consensus with the solar industry and UL, for ensuring intrinsic design security for DERs. These recommendations were developed to bolster the cybersecure functionalities such as TLS, MAC, CRL, session resumption/renegotiation, and password, system, and service security management within the DER devices. The proposed test cases verify authentication, authorization, confidentiality, and data integrity for data and communications of DERs that use Transmission Control Protocol/Internet Protocol (TCP/IP). They were also developed to protect DER communications from eavesdropping, replay, man-in-the-middle, denial of service (DoS), spoofing through security certificates, least-privilege violation, and brute-force credentials. This report, which has been validated and reviewed by UL, expands upon those test cases to provide DER cybersecurity certification recommendations which increase DER resiliency and help to mitigate cyber-attacks. UL's collaboration with NREL and approval of this document will accelerate the adoption of a UL standard for DER cybersecurity.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Emerging Threats and Technology Investigation: Industrial Internet of Things - Risk and Mitigation for Nuclear Infrastructure

Industries supporting the global nuclear infrastructure striving for cost savings, expansions in efficiency, and convenience are likely to adopt components (e.g., hardware, software) that comprise the Internet of Things (IoT) and Industrial Internet of Things (IIoT). These devices offer potential improvements along with security challenges. Modern conveniences achieved through application of technology have propagated through society in the form of interconnected devices, from doorbells to microwave ovens, commonly referred to as IoT. IoT devices are often Internet-connected devices that are designed to send data back to a cloud-based server, where a smart phone application then presents device status and control options. Home-based IoT applications carry a different set of risks when compared to a business or security environment, where there is also a history of convenience and interconnection. Industrial settings have long relied on specifically designed Supervisory Control and Data Acquisition (SCADA) systems for process control where IIoT devices are intended to inform business decisions and augment traditional processes. A recent National Institute of Standards and Technology (NIST) report provides a distinction between process control and IIoT in that traditional process control is not replaced by IIoT, but rather IIoT devices are intended to enhance industrial processes through additional monitoring of various sensors and application of data analytics models using artificial intelligence (AI) and machine learning (ML) (Fagan, Marron, et al. 2021) (Ross, et al. 2021).

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Towards Software Bill of Materials in the Nuclear Industry

Large, modern industrial facilities often incorporate thousands of digital assets in their operational technology. Regulated facilities, such as nuclear power plants (NPPs), maintain robust cybersecurity and configuration management programs that often use bills of materials (BOMs) for these assets, including make, model, and version of hardware, firmware, and software. However, these BOMs typically capture only first- or second-tier information provided by the original equipment manufacturer (OEM). Unfortunately, as indicated by the increasing number and sophistication of software supply chain attacks, this level of detail is insufficient for identifying all the potential vulnerabilities and risks in software applications. Software BOMs (SBOMs) provide detailed enumeration of components and dependencies within the product or devices, including firmware. SBOMs can be combined with vulnerability data sources and vendor vulnerability attestations to improve vulnerability management and enable rapid identification of affected components when new software vulnerabilities are discovered. Ideally, SBOMs are created by the OEM prior to installation. However, since this practice is not yet commonplace and since NPPs are typically slow to adopt new technology, most NPPs do not incorporate SBOMs into their asset or configuration management programs. Fortunately, SBOMs can be generated by NPPs on existing digital assets to provide further insight into risk management decisions. This report provides an overview of the current SBOM ecosystem and recommends guidance on how to get started in a “crawl, walk, run” manner to develop and implement a sustainable SBOM program for digital assets in an NPP.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗