Engineering PapersSearch

SEARCH · Engineering Papers

Results for “identifying security consequences”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

A Framework for Building Security into the Design Process

This report presents guidance to support the implementation of security objectives during the design process for nuclear facilities using an organization’s quality management system. The guidance in this document is intended for design vendors and operators of nuclear power facilities. Additionally, this guidance document can be beneficial to regulatory bodies, industry partners, customers, and other stakeholders within the nuclear power market. This report aims to ensure security consequences are identified before designs are completed, which may lead to reduced costs and higher security effectiveness and efficiency.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS

A Framework for Building Security into the Design Process

This report presents guidance to support the implementation of security objectives during the design process for nuclear facilities using an organization’s quality management system. The guidance in this document is intended for design vendors and operators of nuclear power facilities. Additionally, this guidance document can be beneficial to regulatory bodies, industry partners, customers, and other stakeholders within the nuclear power market. This report aims to ensure security consequences are identified before designs are completed, which may lead to reduced costs and higher security effectiveness and efficiency.

22 GENERAL STUDIES OF NUCLEAR REACTORS

Data Centers and Digital Assurance Introduction to Supply Chain and Cybersecurity for Data Centers, Session 1

The first session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort Workshop, held on October 30, 2025, introduced foundational concepts of Digital Assurance in the context of data center and grid integration. Sponsored by the U.S. Department of Energy, the workshop brought together utilities, data center operators, developers, and vendors to address cybersecurity and supply chain vulnerabilities. The session emphasized the growing criticality of data centers within the electric grid and the need for secure, real-time, bidirectional communication. Participants explored the principles of Digital Assurance, including cybersecurity, cyber-informed engineering (CIE), and lifecycle security, and applied a threat-vulnerability-consequence framework to identify and mitigate risks at the data center–grid interface. Discussions covered a range of threats such as spoofed dispatch signals and insider threats, architectural vulnerabilities like SCADA interfaces and insecure protocols, and potential consequences including cascading grid failures. The session also raised strategic questions about business value, vendor assurance, and defining cyber boundaries and responsibilities. This foundational workshop set the stage for deeper technical analysis and the development of actionable frameworks in subsequent sessions. Session 1 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION

The Spaceport Command and Control System Security Assessor Project

This Summer, I worked as a National Aeronautics and Space Administration (NASA) Internships and Fellowships (NIF) intern under my mentor, Jill Giles within the Software Engineering Branch. Within this project, I worked alongside the Cyber Security branch to identify a list of Commercial Off the Shelf (COTS) software to analyze, research, and gain insight about potential vulnerabilities within the software that could become a threat of attack. After identifying the list of COTS software, my team and I used Microsoft Excel to create a worksheet to easily organize and design a questionnaire about the software. Security reports weregiven to us to identify the software used on the machines in the firing rooms. With these reports, we created a script that would populate the database with the software information to identify potential security weaknesses of COTS software.The goal of the project was to produce a final report, summarizing the most vulnerable launch control system servers and configurations and document vulnerabilities, residual risk, likelihood, and consequence. This project is important for the Cyber Security and Information Technology branches because it will identify security weaknesses and help to mitigate risk. From the Spaceport Command and Control System Security Assessor Project, I learned how to properly identify weaknesses and vulnerabilities within software and how to mitigate the risks within the software. This project also taught me how to create databases using scripts and input files.

Destani Satora Van Arsdalen

Simulation and Modeling Concepts for Secure Airspace Operations

With the expected advent of new entrants including Unmanned Aerial Systems, Commercial Launch Vehicles and Urban Air Mobility aircraft, the future United States National Airspace System will have to evolve to include their operations along with the current commercial, general aviation and military operations. The National Aeronautics and Space Administration and the Federal Aviation Administration are working together to provide a vision for aviation operations in the future—2045 and beyond. Their National Airspace System Horizons initiative seeks to provide stakeholders a list of operational scenarios and technologies, concepts and strategies needed for supporting that vision. They have identified cybersecurity as one of the seven strategic interest areas for realizing this vision. Consequently, NASA is studying cyber resiliency for secure airspace operations. This paper examines cyber security vulnerabilities of Urban Air Mobility operations. While there are many pathways to attack a cyber physical system such as Urban Air Mobility, their effect is expressed in modification or corruption of data/information used for controlling vehicles and making operational decisions. The paper describes cybersecurity technologies of Encryption, Blockchain, Virtual Information Fabric Infrastructure, Trusted Platform Module and Anomaly Detection for protecting the data, thus, improving the cyber resiliency of the current and future air traffic management system.

Cybersecurity

Simulation and Modeling Concepts for Secure Airspace Operations

This paper examines cyber security vulnerabilities of Urban Air Mobility operations. With the expected advent of new entrants including Unmanned Aerial Systems, Commercial Launch Vehicles and Urban Air Mobility aircraft, the future United States National Airspace System will have to evolve to include their operations along with the current commercial, general aviation and military operations. The National Aeronautics and Space Administration and the Federal Aviation Administration are working together to provide a vision for aviation operations in the future—2045 and beyond. Their National Airspace System Horizons initiative seeks to provide stakeholders a list of operational scenarios and technologies, concepts and strategies needed for supporting that vision. They have identified cybersecurity as one of the seven strategic interest areas for realizing this vision. Consequently, NASA is studying cyber resiliency for secure airspace operations. While there are many pathways to attack a cyber physical system such as Urban Air Mobility, their effect is expressed in modification or corruption of data/information used for controlling vehicles and making operational decisions. The paper describes cybersecurity technologies of Encryption, Blockchain, Virtual Information Fabric Infrastructure, Trusted Platform Module and Anomaly Detection for protecting the data, and the cyber resiliency of the current and future air traffic management system.

Urban Air Mobility

Simulation and Modeling Concepts for Secure Airspace Operations

This paper examines cyber security vulnerabilities of Urban Air Mobility operations. With the expected advent of new entrants including Unmanned Aerial Systems, Commercial Launch Vehicles and Urban Air Mobility aircraft, the future United States National Airspace System will have to evolve to include their operations along with the current commercial, general aviation and military operations. The National Aeronautics and Space Administration and the Federal Aviation Administration are working together to provide a vision for aviation operations in the future—2045 and beyond. Their National Airspace System Horizons initiative seeks to provide stakeholders a list of operational scenarios and technologies, concepts and strategies needed for supporting that vision. They have identified cybersecurity as one of the seven strategic interest areas for realizing this vision. Consequently, NASA is studying cyber resiliency for secure airspace operations. While there are many pathways to attack a cyber physical system such as Urban Air Mobility, their effect is expressed in modification or corruption of data/information used for controlling vehicles and making operational decisions. The paper describes cybersecurity technologies of Encryption, Blockchain, Virtual Information Fabric Infrastructure, Trusted Platform Module and Anomaly Detection for protecting the data, and the cyber resiliency of the current and future air traffic management system.

Urban Air Mobility

Climate Change, Nutrition and Food Security in Sub-Saharan Africa

Food security and nutrition in sub-Saharan Africa have long been affected by variations in the weather. Vulnerability to these hazards, along with economic shocks and an adverse political environment, is often uneven in a community. Some individuals and households are more susceptible to emergencies or crises than others, and thus determining who is most vulnerable are and how they are responding to a shock or crises is essential to understand the impact on food security. Daily, quantitative and global observations derived from satellite remote sensing instruments can contribute to understanding how food production has declined due to drought, flood or other weather-related hazard, but it can say nothing about the likelihood that the people living in that area are suffering food insecurity as a result. As Amartya Sen argued, a famine can occur even when there is an absolute surplus of food in a region. Thus organizations like the US Agency for International Development's Famine Early Warning Systems Network (FEWS NET) work to integrate biophysical and socio-economic indicators together with on-the ground assessments to estimate the food security consequences of a variety of events. Climate change is likely to restructure local, regional and global agricultural systems and commodity markets. Although remote sensing information has been used to identify seasonal production declines for the past two decades, new ways of using the data will need to be developed in order to understand, document and respond to the impact of climate change on food security as it is manifested in shorter term shocks. In this article, the contribution of remote sensing is explained, along with the other factors that affect food security

Brown, Molly E.

Explainable Machine Learning for Functional Data

Black-box machine learning models are recognized as useful tools for prediction applications, but the algorithmic complexity of some models causes interpretation challenges. Explainability methods have been proposed to provide insight into these models, but there is little research focused on supervised modeling with functional data inputs. We argue that, especially in applications of high consequence, it is important to explicitly model the functional dependence in a black-box analysis to not obscure or misrepresent patterns in explanations. As such, we propose the V ariable importance E xplainable E lastic S hape A nalysis (VEESA) pipeline for training supervised machine learning models with functional inputs. The pipeline is an analysis process that includes the data preprocessing, modeling, and post-hoc explanations. The preprocessing is done using elastic functional principal components analysis, which accounts for vertical and horizontal variability in functional data and, ultimately, allows for explanations in the original data space that identify the important functional variability without bias due to correlated variables. Here, we demonstrate the pipeline on two high-consequence applications: explosives classification for national security and inkjet printer identification in forensic science. The applications exhibit the VEESA pipeline’s ability to provide an understanding of the characteristics of the functional data useful for prediction. Code for implementing the pipeline is available in the veesa R package (and supplemental python code).

Elastic Shape Analysis

SURVEILLANCE DETECTION FOR TRANSPORTATION OPERATIONS PERSONNEL TO PREVENT HIJACKING, THEFT, SABOTAGE, AND MALICIOUS SECURITY EVENTS DURING TRANSPORTING NUCLEAR MATERIAL

The secure transportation of high-consequence materials, including nuclear and radiological assets, is a critical global priority in the face of escalating terrorism, security threats, and violent protests targeting these operations. Effective surveillance detection—the ability to identify, assess, and respond to potential threats across a continuum of scenarios—is paramount in addressing these challenges. This paper outlines a phased, multi-tiered training program designed to strengthen the surveillance detection capabilities of organizations responsible for nuclear material transport. The proposed training program adopts a progressive approach, gradually increasing in technical complexity to provide participants with comprehensive knowledge and tools for implementing robust security strategies. It targets a wide spectrum of stakeholders, including competent authorities, regulators, inspectors, shippers, carriers, law enforcement, and emergency response personnel, equipping them to plan, evaluate, and safeguard nuclear material transportation effectively. Each phase of the program emphasizes distinct elements of the surveillance detection continuum and transport security, focusing on critical topics such as threat identification, adversary task timelines, protective methodologies, and attack mitigation strategies. The training framework is anchored in technical exchanges and scenario-driven courses that reflect real-world complexities and challenges. By addressing the surveillance detection continuum comprehensively—from early threat assessment to active countermeasures—the program reinforces global efforts to secure nuclear assets. It aligns with international security objectives and fosters a strong security culture within participating organizations, ensuring personnel are prepared to counter potential threats and maintain the safe, secure movement of these materials. Ultimately, this initiative aims to enhance preparedness, security, and response capabilities, supporting the global mission to safeguard high-consequence materials against evolving threats.

Zineddin, Dr. Z. [ORNL] (ORCID:0009000848740725)

Engineering Trade-off Considerations Regarding Design-for-Security, Design-for-Verification, and Design-for-Test

The United States government has identified that application specific integrated circuit (ASIC) and field programmable gate array (FPGA) hardware are at risk from a variety of adversary attacks. This finding affects system security and trust. Consequently, processes are being developed for system mitigation and countermeasure application. The scope of this tutorial pertains to potential vulnerabilities and countermeasures within the ASIC/FPGA design cycle. The presentation demonstrates how design practices can affect the risk for the adversary to: change circuitry, steal intellectual property, and listen to data operations. An important portion of the design cycle is assuring the design is working as specified or as expected. This is accomplished by exhaustive testing of the target design. Alternatively, it has been shown that well established schemes for test coverage enhancement (design-for-verification (DFV) and design-for-test (DFT)) can create conduits for adversary accessibility. As a result, it is essential to perform a trade between robust test coverage versus reliable design implementation. The goal of this tutorial is to explain the evolution of design practices; review adversary accessibility points due to DFV and DFT circuitry insertion (back door circuitry); and to describe common engineering trade-off considerations for test versus adversary threats.

Design for reliability (DFR)

Autonomous Fueling System for Heavy-Duty Fuel Cell Electric Trucks

The motivation for this project stemmed from the challenges associated with rapidly refueling heavy-duty hydrogen fuel cell electric trucks (FCETs). Current manual refueling processes for fast refueling involve large, heavy equipment (e.g., hoses three times heavier than standard) and pose ergonomic risks and potential for equipment damage. The goal was to develop and test an autonomous fueling system to improve ergonomics, enhance safety, increase equipment durability through design improvements, and potentially speed up the fueling process. This project aimed to add to the understanding of autonomous systems in the context of heavy-duty hydrogen refueling, evaluating the technical effectiveness of potential concepts. A successfully developed system would benefit the public by facilitating the adoption of zero-emission heavy-duty transport, reducing reliance on manual labor for a physically demanding task, and potentially improving the safety and efficiency of hydrogen refueling infrastructure. The major accomplishment during the project's active period was the completion of the system-level architecture task. This involved establishing a detailed list of system requirements covering interfaces, environmental conditions, regulatory compliance, industry standards, safety, security, performance capabilities, and optional features. Five key use cases for the autonomous system were also identified. However, due to internal restructuring at Nikola, the necessary resources could not be allocated to continue the project. Consequently, Nikola opted to discontinue the project. The award was mutually terminated by Nikola and the DOE.

08 HYDROGEN

Responsible Artificial Intelligence for Insider Threat Mitigation

This report examines the application of artificial intelligence (AI) technologies for insider threat mitigation (ITM) programs in nuclear security facilities. Insider threat detection presents unique challenges due to the subtle and adaptive nature of these threats, the complex signatures involved, and the scarcity of available data for analysis. Traditional human-centered approaches, while essential, face limitations in processing large amounts of data continuously and detecting subtle patterns across multiple systems. AI technologies can potentially address these limitations by providing 24/7 monitoring capabilities, identifying complex patterns that might escape human observation, and offering consistent application of security criteria. However, the deployment of AI in nuclear security contexts introduces significant new risks, including workflow disruption, expanded attack surfaces, potential for misuse, and ethical concerns regarding privacy, fairness, transparency, safety, and security. The high-consequence nature of nuclear security decisions demands careful consideration of these risks and systematic approaches to their mitigation.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF

ARCADE Technical Pathway and Industry Impact

The Advanced Reactor Cyber Analysis and Development Environment (ARCADE) simplifies the evaluation and assessment of robustness factor and cyber resilience that support secure-by-design for advanced reactor nuclear power plants. In this manner, ARCADE supports risk-informed performance based (RIPB) evaluations of cybersecurity through its integration of plant physics with high-fidelity emulations of control systems. This cross domain approach enables comprehensive analysis of control system sensitivities, cyber-attack scenarios, and their consequences. ARCADE has been custom developed to meet the demands identified in Tier 1 of the Tiered Cyber Analysis (TCA) as outlined in NRC Draft Regulation Guide (RG) 5.96, which provides a RIPB cybersecurity approach for new reactors.

97 MATHEMATICS AND COMPUTING

Consequence and Resilience Modeling for Chemical Supply Chains

The U.S. chemical sector produces more than 70,000 chemicals that are essential material inputs to critical infrastructure systems, such as the energy, public health, and food and agriculture sectors. Disruptions to the chemical sector can potentially cascade to other dependent sectors, resulting in serious national consequences. To address this concern, the U.S. Department of Homeland Security (DHS) tasked Sandia National Laboratories to develop a predictive consequence modeling and simulation capability for global chemical supply chains. This paper describes that capability , which includes a dynamic supply chain simulation platform called N_ABLE(tm). The paper also presents results from a case study that simulates the consequences of a Gulf Coast hurricane on selected segments of the U.S. chemical sector. The case study identified consequences that include impacted chemical facilities, cascading impacts to other parts of the chemical sector. and estimates of the lengths of chemical shortages and recovery . Overall. these simulation results can DHS prepare for and respond to actual disruptions.

Stamber, Kevin L.

Data Centers and Digital Assurance Workshop 3 – Mitigations for Digital Assurance Risks

The third session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort, held on November 18, 2025, focused on developing mitigation strategies for digital assurance risks identified in previous workshops. Hosted by Idaho National Laboratory (INL) and ScottMadden, the session emphasized the application of Cyber-Informed Engineering (CIE) to data center infrastructure, particularly at the utility–data center interface. Participants revisited and ranked key digital assurance risks, including architecture and interface weaknesses, governance gaps, and AI-enabled threats. The workshop introduced the 12 principles of CIE, advocating for consequence-focused design, engineered controls, and secure information architecture to proactively reduce cyber-physical vulnerabilities. These principles were applied to critical data center systems such as power distribution, UPS, cooling, SCADA/BMS, and grid-forming batteries. The session also addressed governance challenges at the interconnection boundary, highlighting the need for clear roles in telemetry sharing, firmware management, and trip settings. Special attention was given to emerging risks from behind-the-meter (BTM) generation, including reverse-power flow and the integration of small modular reactors (SMRs), which shift data centers from large loads to complex generation nodes. Participants explored how interconnection agreements can serve as enforceable instruments for digital assurance, and reviewed gaps in current standards such as NERC CIP, IEC 62443, and IEEE 1547. The workshop concluded with pathways to standardization, including model agreement language, state-level programs, and expanded NERC guidance. INL also presented tools and frameworks for secure procurement and supplier risk management, reinforcing the need for integrated engineering and policy solutions to secure the evolving data center–grid ecosystem. Session 3 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION

Risk Assessment Overview

Risk assessment is used in many industries to identify and manage risks. Initially developed for use on aeronautical and nuclear systems, risk assessment has been applied to transportation, chemical, computer, financial, and security systems among others. It is used to gain an understanding of the weaknesses or vulnerabilities in a system so modification can be made to increase operability, efficiency, and safety and to reduce failure and down-time. Risk assessment results are primary inputs to risk-informed decision making; where risk information including uncertainty is used along with other pertinent information to assist management in the decision-making process. Therefore, to be useful, a risk assessment must be directed at specific objectives. As the world embraces the globalization of trade and manufacturing, understanding the associated risk become important to decision making. Applying risk assessment techniques to a global system of development, manufacturing, and transportation can provide insight into how the system can fail, the likelihood of system failure and the consequences of system failure. The risk assessment can identify those elements that contribute most to risk and identify measures to prevent and mitigate failures, disruptions, and damaging outcomes. In addition, risk associated with public and environment impact can be identified. The risk insights gained can be applied to making decisions concerning suitable development and manufacturing locations, supply chains, and transportation strategies. While risk assessment has been mostly applied to mechanical and electrical systems, the concepts and techniques can be applied across other systems and activities. This paper provides a basic overview of the development of a risk assessment.

Prassinos, Peter G.

Deliberate Satellite Fragmentations and their Effects on the Long-Term Space Environment

Since 1964 at least 56 spacecraft and two launch vehicle upper stages have been deliberately fragmented while in Earth orbit. Many of these events have had no long-lasting effects on the near-Earth space environment, but one represents the most devastating satellite breakup in history that will pose hazards to operational spacecraft in low Earth orbit for decades to come. International space debris mitigation guidelines now call for avoiding the creation of long-lived debris from intentional satellite fragmentations. This paper summarizes the reasons for and environmental consequences of deliberate satellite fragmentations. Contrary to popular belief, only one in five deliberate fragmentations have been related to the testing of anti-satellite weapon systems, for which only one such test has occurred during the past 25 years. Other reasons for deliberate satellite fragmentations range from engineering tests to protecting national security information. Whereas the majority of deliberate satellite fragmentations have occurred in low Earth orbits, some have involved spacecraft in highly elliptical orbits. The former Soviet Union and the current Russian Federation have been responsible for 90% of all identified deliberate on-orbit satellite fragmentations.

Johnson, N. L.