Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “data authentication”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Non-intrusive data authentication systems and methods

Systems and methods are disclosed that create a separate digital and cryptographically secure signal “branch” to a secondary observer from a primary signal path of an information system. The information system may be a measurement system. The secure signal branch is creating without interfering with the primary signal path. In such a manner, the secondary observer may authenticate reported data while not interfering with the signal of the information system.

97 MATHEMATICS AND COMPUTING↗

Model-Free Data Authentication for Cyber Security in Power Systems

With the development and wide deployment of measurement equipment, data can be automatically measured and visualized for situation awareness in power systems. However, the cyber security of power systems is also threated by data spoofing attacks. This letter proposed a measurement data source authentication (MDSA) algorithm based on feature extraction techniques including ensemble empirical mode decomposition (EEMD) and fast Fourier transform (FFT), and machine learning for real-time measurement data classification. Compared with previous work, the proposed algorithm can achieve higher accuracy of MDSA using a shorter window of data from closely located synchrophasor measurement sensors.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Communication systems and methods for authenticating data packets within network flow

A communication system includes a first quantum key distribution device and an intermediary device. The first quantum key distribution device is configured to be coupled to a second quantum key distribution device over a quantum channel and to generate a shared key with the second quantum key distribution device based on a quantum state transmitted along the quantum channel. The intermediary device is disposed along a communication pathway within a network between a sender device and a receiver device. The intermediary device is communicatively connected to the first quantum key distribution device and configured to utilize the shared key to authenticate one or more data packets communicated from the sender device along the communication pathway by examining the one or more data packets for a presence of an information pattern that is associated with the shared key.

Bush, Stephen Francis↗

Data source authentication of synchrophasor measurement devices based on 1D-CNN and GRU

Synchrophasor measurement devices (SMDs) have been widely deployed to support real-time monitoring and control of power systems. In the meantime, data spoofing has emerged in recent years. Therefore, it is of great importance to study data authentication algorithms for detecting and defending the data spoofing effectively. Here, a one-dimensional convolutional neural network (1D-CNN) is utilized to extract temporal signatures hidden in frequency, voltage angle and amplitude data; then the gated recurrent unit (GRU) employs these temporal signatures for data source authentication. In case studies, the performances of different algorithms are tested in large-scale power systems with numerous SMDs for the first time, and comparisons among different algorithms show that the proposed algorithm can achieve a higher accuracy of data source authentication with a shorter time window.

47 OTHER INSTRUMENTATION↗

System for authenticating an additively manufactured object

A method for authenticating an additively manufactured (AM) object is disclosed herein. A computing device obtains a measurement that is indicative of a stochastic distribution of dopant incorporated into the AM object. The computing device generates authentication data for the AM object based upon the measurement, and authenticates the AM object based upon the authentication data.

36 MATERIALS SCIENCE↗

Model Residuals as Shields: A Two-Level Formulation to Defend Smart Grids From Poisoning Attacks

The advancement of smart grids presents both vast opportunities and heightened cybersecurity risks. Data-driven defense mechanisms, though designed as a shield against these threats, can fall prey to poisoning attacks. We delve into regression settings, underscoring the imperative to fortify defenses against a spectrum of poison ratios, notably those above 0.5—an issue scarcely addressed in prior studies. Recognizing the susceptibilities of smart grids and their manipulable sensors, we exploit the very intent of poisoning attacks, compromising model accuracy, as our defense mechanism. Our proposed two-level optimization framework discerns between poisoned and authentic data based on model residuals, outperforming or matching existing methods in 72% to 77% of precision and 75% to 80% of recalls across various poisoning attacks, poison ratios, and datasets. Once the authentic data are identified, the trained model is adaptable for a variety of applications. Comprehensive evaluations on different smart grid datasets, pitted against myriad poisoning schemes, validate our methodology’s edge over existing methods. Here, we also shed light on the implications of model misspecification originating from temporal auto-correlation, a common feature in Internet of Things and smart grid data.

Adversarial machine learning (ML)↗

Encryption of Signal Pulses to Replace Tamper-indicating Conduit

In order to verify signal integrity and point of origin for TTL pulse data used in IAEA systems, and to avoid the need for expensive tamper-indicating conduit or electronic techniques, we propose the development of a signal pulse signing and encryption in-line device. In measurement applications in which the data acquisition electronics is separate from the enclosed, sealed detector, tamper-indicating techniques are required to protect raw TTL pulse streams between the detector and the data acquisition module, i.e UMSR. The goal of this proposed project is to design a rad-tolerant transmitter that would mount inside the sealed detector system and a receiver in the sealed electronics cabinet with the data acquisition instrument. This transmitter/receiver pair would digitally sign and encrypt the pulse stream data at the detector then transmit the data to the sealed cabinet where the receiver would decrypt the data and reproduce the original pulse stream. Existing tamper indicating techniques, such as LiveWire’s spread spectrum time domain reflectometry rely on detecting physical changes to the wiring system and can be blind to fast coupling of micro-second wide pulses. Digital signing and encryption techniques such as the Sandia Laboratories Enhanced Data Authentication System (EDAS) are capable of encrypting communications data, i.e. RS-232, but are not capable reproducing a critical time correlated data streams. Recent NA-241 Safeguards Technology supported developments have reduced the need for special conduit to transmit data via Ethernet by incorporating the IAEA RAINSTORM data encryption and authentication protocol, a tamper indicator is still required to protect raw pulse data from detectors to the acquisition electronics. Encrypting pulse data is especially complicated for radiation detection instruments due to the time correlation data analysis that is performed on this data stream. Any corruption in the timing information will produce errors in measurement values.

97 MATHEMATICS AND COMPUTING↗

Adding power of artificial intelligence to situational awareness of large interconnections dominated by inverter‐based resources

Abstract Large‐scale power systems exhibit more complex dynamics due to the increasing integration of inverter‐based resources (IBRs). Therefore, there is an urgent need to enhance the situational awareness capability for better monitoring and control of power grids dominated by IBRs. As a pioneering Wide‐Area Measurement System, FNET/GridEye has developed and implemented various advanced applications based on the collected synchrophasor measurements to enhance the situational awareness capability of large‐scale power grids. This study provides an overview of the latest progress of FNET/GridEye. The sensors, communication, and data servers are upgraded to handle ultra‐high density synchrophasor and point‐on‐wave data to monitor system dynamics with more details. More importantly, several artificial intelligence (AI)‐based advanced applications are introduced, including AI‐based inertia estimation, AI‐based disturbance size and location estimation, AI‐based system stability assessment, and AI‐based data authentication.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Securing Environmental IoT Data Using Masked Authentication Messaging Protocol in a DAG-Based Blockchain: IOTA Tangle

The demand for the digital monitoring of environmental ecosystems is high and growing rapidly as a means of protecting the public and managing the environment. However, before data, algorithms, and models can be mobilized at scale, there are considerable concerns associated with privacy and security that can negatively affect the adoption of technology within this domain. In this paper, we propose the advancement of electronic environmental monitoring through the capability provided by the blockchain. The blockchain’s use of a distributed ledger as its underlying infrastructure is an attractive approach to counter these privacy and security issues, although its performance and ability to manage sensor data must be assessed. We focus on a new distributed ledger technology for the IoT, called IOTA, that is based on a directed acyclic graph. IOTA overcomes the current limitations of the blockchain and offers a data communication protocol called masked authenticated messaging for secure data sharing among Internet of Things (IoT) devices. We show how the application layer employing the data communication protocol, MAM, can support the secure transmission, storage, and retrieval of encrypted environmental sensor data by using an immutable distributed ledger such as that shown in IOTA. Finally, we evaluate, compare, and analyze the performance of the MAM protocol against a non-protocol approach.

Gangwani, Pranav (ORCID:0000000159226002)↗

A Novel Authentication Management for the Data Security of Smart Grid

Bidirectional wireless communication is employed in various smart grid components such as smart meters and control and monitoring applications where security is vital. The Trusted Third Party (TTP) and wireless connectivity between the smart meter and the third party in the key management-based encryption techniques for the smart grid are expected to be totally trustworthy and dependable. In a wired/wireless medium, however, a man-in-the-middle may seek to disrupt, monitor and manipulate the network, or simply execute a replay attack, revealing its vulnerability. Recognizing this, this study presents a novel authentication management (model) comprised of two layer security schema. The first layer implements an efficient novel encryption method for secure data exchange between meters and control center with the help of two partially trusted simple servers (constitutes the TTP). In this setting, one server handles the data encryption between the meter and control center/central database, and the other server administers the random sequence of data transmission. The second layer monitors and verifies exchanged data packets among smart meters. It detects abnormal packets from suspicious sources. To implement this node-to-node authentication, One class support vector machine algorithm is proposed which takes advantages of the location information as well as the data transmission history (node identification, packet size, and data transmission frequency). This schema secures data communication, and imposes a comprehensive privacy throughout the system without considerably extending the complexity of the conventional key management scheme.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Attack on Grid Event Cause Analysis: An Adversarial Machine Learning Approach

With the ever-increasing reliance on data for data-driven applications in power grids, such as event cause analysis, the authenticity of data streams has become crucially important. The data can be prone to adversarial stealthy attacks aiming to manipulate the data such that residual-based bad data detectors cannot detect them, and the perception of system operators or event classifiers changes about the actual event. This paper investigates the impact of adversarial attacks on convolutional neural network-based event cause analysis frameworks. We have successfully verified the ability of adversaries to maliciously misclassify events through stealthy data manipulations. The vulnerability assessment is studied with respect to the number of compromised measurements. Furthermore, a defense mechanism to robustify the performance of the event cause analysis is proposed. The effectiveness of adversarial attacks on changing the output of the framework is studied using the data generated by real-time digital simulator (RTDS) under different scenarios such as type of attacks and level of access to data.

Niazazari, Iman↗

The Essence of Cryptol: A Denotational Cryptol Interpreter in Coq for Foundational Assurances for Quantum Resistant Cryptosystems

Systems of the utmost consequence need a means to establish authenticity of software and data. Cryptosystems implement authentication, but can be vulnerable to cryptographic and implementation attacks. With the threat of quantum cryptographic attacks, “post-quantum” cryptosystems (PQCs) must be henceforth used in these systems. However, the new cryptography needs new ways to, rigorously and machine-checkably, prove systems free of vulnerabilities. We propose a retargetable capability to rapidly instantiate proven correct postquantum cryptosystems through novel proof-carrying synthesis and proof-automation technique, extending those proven successful on existing systems. This capability is crucial to meeting the cryptographic requirements for future high-consequence systems. Since specifications for high consequence cryptography are presently captured in a domain specific language known as Cryptol. While this can enable convenient fully automated reasoning about Cryptol specificaitons and implementations via the Software Analysis Workbench (SAW), Cryptol has expressivity gaps, so that cryptosystems with probabilistic programming features like Falcon cannot be fully expressed in the language. Moreover, SAW’s automation fails for programs and specificaitons with inductive and recursive structure, as in the Sphincs+ PQC. Finally, Cryptol and SAW together represent some 200,000 lines of unverified Haskell, so that the any guarantees about high consequence cryptography are presently contingent on a large, unverified, yet trusted computing base. The first step of the larger project of agile, assured crpytography is therefore to provide a formal, mechanized semantics for Cryptol, so that the specifications expressed by cryptographers in Cryptol can be reasoned about and compiled into performant implementations with a foundational, machine checkable certificate of correctness. This report describes our work on this first step, culminating in the design of a certified denotational interpreter, in Coq, for core Cryptol.

97 MATHEMATICS AND COMPUTING↗

Multi-View Convolutional Neural Network for Data Spoofing Cyber-Attack Detection in Distribution Synchrophasors

Security of Distribution Synchrophasors Data (DSD) is of paramount importance as the data is used for critical smart grid applications including situational awareness, advanced protection, and dynamic control. Unfortunately, the DSD are attractive targets for malicious attackers aiming to damage grid. Data spoofing is a new class of deceiving attack, where the DSD of one Phasor Measurement Units (PMUs) is tampered by other PMUs thereby spoiling measurement based applications. In order to address this issue, a source authentication based data spoofing attack detection method is proposed using Multi-view Convolutional Neural Network (MCNN). First, common components embedded in raw frequency measurements from DSD are removed by Savitzky-Golay (SG) filter. Second, fast S transform (FST) is utilized to extract representative spatial fingerprints via time frequency analysis. Third, the spatial fingerprint is fed to MCNN, which combines dilated and standard convolutions for automatic feather extraction and source identification. Finally, according to the output of MCNN, spoofing attack detection is performed via threshold criterion. Extensive experiments with actual DSD from multiple locations in FNET/Grideye are conducted to verify the effectiveness of the proposed method.

97 MATHEMATICS AND COMPUTING↗

Challenges in the Use of AI-Driven Non-Destructive Spectroscopic Tools for Rapid Food Analysis

Routine, remote, and process analysis for foodstuffs is gaining attention and can provide more confidence for the food supply chain. A new generation of rapid methods is emerging both in the literature and in industry based on spectroscopy coupled with AI-driven modelling methods. Current published studies using these advanced methods are plagued by weaknesses, including sample size, abuse of advanced modelling techniques, and the process of validation for both the acquisition method and modelling. This paper aims to give a comprehensive overview of the analytical challenges faced in research and industrial settings where screening analysis is performed while providing practical solutions in the form of guidelines for a range of scenarios. After extended literature analysis, we conclude that there is no easy way to enhance the accuracy of the methods by using state-of-the-art modelling methods and the key remains that capturing good quality raw data from authentic samples in sufficient volume is very important along with robust validation. A comprehensive methodology involving suitable analytical techniques and interpretive modelling methods needs to be considered under a tailored experimental design whenever conducting rapid food analysis.

59 BASIC BIOLOGICAL SCIENCES↗

Deployable sensor system using mesh networking and satellite communication

A sensor system may be configured for continuous operation in a low resource environment and/or in extreme environmental conditions. The sensor system may have sufficient processing capabilities to provide scientific computing for pre-processing, quality control, statistical analysis, event classification, data compression and corrections (e.g., spikes in the data), autonomous decisions and actions, triggering other nodes, and information assurance functions that provide data confidentiality, data integrity, authentication, and non-repudiation. The hardware may have both mesh networking and satellite and cellular communication capability, and may be available for relatively low cost. Such a network provides the flexibility to have potentially any number of nodes be completely independent from one another. Thus, the network may scale across a diverse terrain.

Frigo, Janette↗

Methods for communicating data utilizing sessionless dynamic encryption

The present disclosure is directed to methods that provide a secure communication protocol by utilizing one step process of authenticating and encrypting data without having to exchange symmetric keys or needing to renew or re-issue digital identities fundamental to asymmetric encryption methodology.

Choi, Sung Nam↗