Engineering PapersSearch

SEARCH · Engineering Papers

Results for “hardware enumeration”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

Wind Supply Chain Security: Hardware Enumeration and Analysis

This project, undertaken by Idaho National Laboratory (INL) for the Department of Energy (DOE) Wind Energy Technologies Office (WETO), focused on the enumeration and analysis of six key devices important to wind technologies. The devices analyzed included Beckhoff Bus Terminal Controllers (BK1120 and BC9000), a Beckhoff Economy Built-in Panel PC (CP6231), an N-Tron Managed Industrial Ethernet Switch (711FX3), a Bachmann M1 Gateway, and a Bachmann Smart Power Plant Controller. Device selection was driven by availability and budget constraints, with several components sourced from existing wind farms and others procured through a co-agreement with another WETO-funded project. The project's primary objective was to create a hardware bill of materials (HBOM) for each device, identifying and documenting all components to assess potential security and supply chain risks. A detailed analysis revealed over 750 unique components across the six devices, with 80% successfully identified and accompanied by datasheets. Notably, Texas Instruments emerged as the leading supplier, providing over 16% of the components, followed by ON Semiconductor at 11.3%, Analog Devices at 5.3%, and Renesas Electronics Corp at 4.1%. Other notable vendors included Toshiba Corporation, iC-Haus Corporation, Atmel, Vishay, and STMicroelectronics. The enumeration process involved thorough documentation of each component, including its designation, quantity, identifiers, pin package, description, vendor, model, and country of origin. This process provided valuable insights into the complexity and diversity of the electronic systems within these wind devices. It also highlighted the distinct separation of components between vendors, suggesting a trend of vendor-specific component usage. Key findings from the project emphasized the importance of broadening the scope of vendor analysis in future research to gain a comprehensive understanding of component distribution and commonality. The identification of vendor-specific component usage patterns offers new avenues for research and underscores the significance of continued investigation in this field. Overall, this project provides critical insights into the component composition of wind devices, aiding in the development of improved supply chain management and component sourcing strategies. The results contribute valuable knowledge to the wind technology sector, laying the groundwork for enhanced security and resilience in wind energy systems.

17 - WIND ENERGY

Improving Cyber Situational Understanding

Effective cybersecurity operations require the ability to analyze large amounts of information to assess security risks and formulate defensive strategies against adversaries. This has become more complex in recent years as the sprawl and interconnectivity of devices grows through implementation of virtualization, cloud computing, and Internet of Things (IoT). The amount of data and analysis required for effective cybersecurity command and control decisions far exceeds humans’ capacity to perform manually. We characterize the analysis problem as cyber situational understanding. The research presented to improve cyber situational understanding focuses on vulnerability analysis and threat intelligence. Regarding vulnerabilities, entities must analyze and plan work for between thousands and tens of thousands of software vulnerabilities annually. Entities heavily use network firewalls to limit vulnerability exposure. As a result, some of these vulnerabilities permit exposure to adversarial exploitation, whereas others are inaccessible and therefore present negligible risk of exploitation. Distinguishing between high and low risk software vulnerabilities requires a deep understanding of the vulnerability, network firewall protection, and characteristics of the targeted device. This problem is solved by extracting network service features from vulnerability data features using both machine-learning and natural language processing. Then, the network firewall topology is parsed to determine which vulnerabilities are reachable by adversaries. Ultimately, a state-based safety analysis ascertains which vulnerabilities are unsafe. A related vulnerability analysis problem occurs in cybersecurity operations when associating an entity’s hardware and software assets to public vulnerability databases. Assets often reveal hardware and software through installation artifacts and network service identification, and entities store these artifacts in inventory databases. However, software and hardware vendors apply a standard Common Platform Enumeration (CPE) naming convention when publicly reporting vulnerabilities. Associating these two datasets often requires many hours to days of manual inspection. The proposed solution automates the mapping approach of human analysts using fuzzy matching techniques, natural language processing, and, ultimately, machine learning to present a small set of recommendations for mapping the two datasets. The result significantly reduces human analysis time and reduces the occurrence of false positives in vulnerability notifications. Finally, cyber threat intelligence (CTI) requires associating cyber observable artifacts, such as IP addresses, URIs, and file hashes, with cyber threat tactics, techniques, and procedures. Unfortunately, most CTI data is compartmentalized across multiple organizations and cannot be shared due to the legal and reputational risk with cyber threat being associated with the entity. The approach to solving this problem inovlves using a distributed ledger with anonymous token spending and authentication. This allows a consortium of semi-trusted entities to share the workload of curating CTI for a threat sharing community’s cooperative benefit.

Huff, Philip

Programmable Digital Devices used in Advanced Reactors

This paper introduces the concepts of common cause failure, diversity, and defense-in-depth used by the nuclear industry to analyze resilience in reactors. A survey of publicly traded and private companies building advanced reactors and their licensing status is presented. Safety and non-safety systems found in the NuScale Power design are summarized and the likely hardware and software categories used by those systems are enumerated. The importance of industry partners is highlighted. This paper also identifies an alternate path forward without industry partners to advance the knowledge needed to use artificial intelligence to analyze HBOMs and SBOMs to better understand reactor resiliency.

cybersecurity

Testbed Demonstration of a Microgrid Building Block Prototype

With the adoption of ambitious climate action goals, the penetration level of distributed energy resources (DERs) is rapidly increasing. Microgrids are an efficient way to integrate these DERs, facilitating their operation and control. Additionally, microgrids enhance the overall resilience of the distribution system by serving critical loads both within and outside their boundaries. However, the need for substantial customized engineering leads to a high cost of development, installation and maintenance of microgrids. To address this challenge, Microgrid Building Blocks (MBB) are proposed to reduce the deployment cost of microgrids through modular, standardized design and implementation. This work presents a testbed demonstrating the integrated power conversion, control, and communication functionalities of an MBB. The testbed is formed by a real-time electromagnetic transient (EMT) simulation combined with a hardware and software prototype of MBB. The use cases supported by the MBB testbed are enumerated. The islanded operation, voltage regulation, and optimal dispatch capabilities of an MBB-based microgrid controller are validated through a case study.

Somda, Baza [Virginia Tech]