Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “network perimeter control”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

Sliding Mode Network Perimeter Control

Urban traffic congestion is a chronic problem faced by many cities in the US and worldwide. It results in inefficient infrastructure use as well as increased vehicle fuel consumption and emission levels. Congestion is intertwined with delay, as road users waste precious hours on the road, which in turn reduces productivity. Researchers have developed, and continue to design, tools and systems to alleviate this problem. Network perimeter control is one such tool that has been studied extensively. It attempts to control the flow of vehicles entering a protected area to ensure that the congested regime predetermined by the Network Fundamental Diagram (NFD) is not reached. In this paper, a method derived from sliding mode control theory is presented. Its main advantages over proportional-integral controllers include (1) minimal tuning, (2) no linearization of the governing equations, (3) no assumptions with regard to the shape of the NFD, and (4) ability to handle various demand profiles without the need to retune the controller. A sliding mode controller was implemented and tested on a congested grid network. The results show that the proposed controller produces network-wide delay savings and disperses congestion effectively.

42 ENGINEERING↗

On the evaluation and selection of network-level traffic control policies: Perimeter control, TUC, and their combination

Perimeter control (PC) of urban traffic networks can be effective in increasing network-wide efficiency. PC operates on the border of a protected region of a traffic network. Most studies thus far considered fixed-time plans for the inner part of these regions. A few studies have shown that combining PC with locally actuated or decentralized traffic control systems may have positive effects on traffic performance, including better-defined Network Macroscopic Fundamental Diagrams (NMFDs), increased network throughput, and reduced delays. The Traffic-responsive Urban Control (TUC) is a real-time network-wide traffic control system with particular design characteristics, such as the balancing of link's occupancies and an inherent gating feature. These characteristics suggest that TUC may enhance the traffic network performance when combined with PC whilst improving the resulting NMFDs and network throughput and delays. Here, in this work, we investigate the effect of feedback perimeter control (FPC), TUC, and their combination on the NMFD and on the traffic conditions of general traffic and public transport in the microsimulation of a realistic model of the Christchurch Central Business District in New Zealand. We perform a thorough investigation of practical aspects of both control strategies and their combination, including parameter tuning and infrastructure requirements, and how they may affect the control system choice. Results show higher throughput and less hysteresis on the NMFDs, particularly when TUC is involved. PC provides benefits concentrated in the protected region which can greatly benefit public transportation if there is an overlap with the transit network. The combination of TUC and FPC boosts network-wide throughput.

33 ADVANCED PROPULSION SYSTEMS↗

Vehicle Platooning: An Energy Consumption Perspective

Urban traffic congestion is a chronic problem faced by many cities in the US and worldwide. It results in inefficient infrastructure use as well as increased vehicle fuel consumption and emission levels. Excessive fuel consumptions add extra costs to commuters as well as transportation businesses. Consuming less fuel and thus reducing costs by a single percentage digit can have a significant impact on the balance sheet as well as the protection of the environment. Researchers have developed, and continue to develop, tools and systems to optimize the operations of fleets as well as engines in order to burn less fuel and therefore generate less CO2 emissions. Platooning is one such tool that attempts to maintain relatively small distances (i.e. pre-determined time gap) between consecutive vehicles. It has the potential to increase the capacity of the road as well as reduce the consumed fuel. In this paper, we use a fuel consumption model for internal combustion light-duty vehicles, electric vehicles, hybrid electric vehicles, buses and trucks in order to determine and quantify the effects of platooning on a fleet fuel consumption. The results suggest that a reduction of up to 3%, 3.5%, 4.5 %, 10%, and 15% in fuel consumption can be achieved for internal combustion engine vehicles, hybrid electric vehicles, electric vehicles, buses and trucks.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Securing Grid Communications Infrastructure: Addressing Gaps Beyond NERC CIP Facility Perimeters

The North American electric grid relies on a complex communications infrastructure that extends beyond facility perimeters traditionally covered by NERC Critical Infrastructure Protection (CIP) standards. While CIP requirements have significantly strengthened cybersecurity within Electronic Security Perimeters, many operational communications—such as those between control centers, substations, and third-party networks—fall outside current regulatory scope. As grid modernization introduces new technologies and connectivity models, these external pathways present evolving security challenges. This brief explores the nature of these challenges, including emerging attack vectors and supply chain considerations, and highlights how ongoing grid transformation increases exposure to sophisticated threats. It outlines practical strategies and policy options to complement existing standards, such as expanding secure communications practices, enhancing supply chain transparency, and fostering collaboration among federal, state, and industry stakeholders. Near-term actions like encryption, authentication, and contractual safeguards can help reduce risk while longer-term frameworks are developed to ensure resilient and secure grid operations.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Laboratory Validation of Integrated Lighting Systems Retrofit Performance and Energy Savings

Light-emitting diodes (LED) fixtures and lamps have emerged as leading technologies for general illumination and are a well-established energy efficiency retrofit measure in commercial buildings (from around 2% of installed fixtures and lamps in 2013 to 28% by 2020). Retrofit approaches that integrate elements, such as networked controls, daylight dimming, and advanced shade technologies lag in comparison. Integrated retrofits have been shown to increase savings over single end-use retrofits, but are perceived as higher complexity and risk. More validation of integrated lighting system performance is needed. This study presents results from laboratory testing of three packages combining fixtures, networked controls, task tuning, and daylight dimming, advanced shades, and lighting layout changes. We characterize performance in perimeter open-office zones, finding energy savings from 20% for daylight dimming and automated shades (no LED retrofit) to over 70% for LED retrofits with advanced controls and shades or lighting layout changes. We present some implementation details, including lessons learned from installation and commissioning in the laboratory setting. We also discuss cost-benefit analysis approaches for the types of packages presented, including the need to quantify and incorporate energy and non-energy benefits for advanced shades packages, which enhance occupant comfort but add significant cost.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Addressing the Tension Between Strong Perimeter Control an Usability

This paper describes a strong perimeter control system for a general purpose processing system, with the perimeter control system taking significant steps to address usability issues, thus mitigating the tension between strong perimeter protection and usability. A secure front end enforces two-factor authentication for all interactive access to an enclave that contains a large supercomputer and various associated systems, with each requiring their own authentication. Usability is addressed through a design in which the user has to perform two-factor authentication at the secure front end in order to gain access to the enclave, while an agent transparently performs public key authentication as needed to authenticate to specific systems within the enclave. The paper then describes a proxy system that allows users to transfer files into the enclave under script control, when the user is not present to perform two-factor authentication. This uses a pre-authorization approach based on public key technology, which is still strongly tied to both two-factor authentication and strict control over where files can be transferred on the target system. Finally the paper describes an approach to support network applications and systems such as grids or parallel file transfer protocols that require the use of many ports through the perimeter. The paper describes a least privilege approach that dynamically opens ports on a host-specific, if-authorized, as-needed, just-in-time basis.

Hinke, Thomas H.↗

National-Tribal Critical Infrastructure Protection: Collaboration for Extraordinary National Security Benefit

This paper examines national and tribal collaborative opportunities to get ahead of the critical infrastructure insecurity problem. Recommendations are viewed through the lens of the Sandia Labs Tribal Cyber-Energy initiative and national security projects. Recommendations include 1) Collaboratively address national priority and shared challenges to gain faster and better solutions to national priority problems on a smaller yet comprehensive American Indian and Alaskan Native sovereign single-point of authority scale 2) Utilize newer standards-based technologies to provide scalable, capable, and manageable solutions for greatly expanded and connected national critical infrastructures 3) Employ Cyber-Physical-Resilient design preliminary analysis to define concept- to-disposition design requirements for preemptive critical infrastructure risk mitigation and baked-in security; 4) Develop data-centric protection to provide increased information asset protection as data shifts from data-owner operated on-premises infrastructure to virtual service provider data-steward owned and operated off-premises infrastructure; and 5) Balance shared solutions with the National Institute of Science and Technology (NIST) Cybersecurity and Risk Management frameworks, and the System Security Engineering Guidelines. As yet unallocated federal funding would support research, development, the timely application of National-Tribal critical infrastructure protection, and critical infrastructure Cyber disruption response and recovery with extraordinary mutual benefits for the foreseeable future. The Critical Infrastructure Insecurity Problem: Rapid modernization and expansive connectivity are due to advances in Information and Communications Technologies that have sweeping cyber impact across all critical infrastructure sectors. Supervisory Control and Data Acquisition and Industrial Control Systems are particularly impacted as systems long separated from the Internet are now being connected and computerized. Virtualization and mobility create a Data Everywhere-User Anywhere paradigm that has evaporated the enterprise network perimeter. There are multi-front technological challenges at play, where long depended on technologies simply don't scale to current needs resulting in a digital dichotomy of competing old and new standards. New standards-based technologies scale but are not as well-known or as widely deployed, which leaves decision makers, stakeholders, and the workforce in a quandary, caught mid-stream between the technological past and the virtual future. Rapid and expansive cyber threat accompanies disruptive change in connectivity and computational dependencies. A lack of action will exacerbate the problem if new technologies roll out without baked-in security design. The Risk: If National-Tribal CIP collaboration to design in security is not done, then an ongoing state of insufficient bolt-on security and elevated threat exposure will remain for years to come.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Electrostatically figured membrane reflectors: An overview

A schematic diagram of the electrostatically figured membrane reflector (EFMR) is presented in Figure 1. Here, active reflector figure control is exercised via electrostatic stresses which operate between the reflector and a second surface called the -command surface. The command surface is located a short distance behind the reflector and is pulled firmly into an approximate paraboloid by a network of guy wires or comparable structure. This same surface supports insulated conducting segments which are individually addressable by dedicated control voltages. The control voltages are, in turn, collectively biased with respect to the reflector. The reflector, tensioned by a rigid rim at the perimeter, is distended toward the command surface by the bias. The resulting command surface potential distribution, and hence the electrostatic stress distribution acting on the reflector, is continuously and rapidly refined via the control voltages so as to produce and maintain a precise parabolic reflector figure. Optical reflector figure measurements provide the data necessary for computer-supervised figure control. Finally, in order to prevent command surface discharging by photons and charged particles, the command surface is completely enclosed by a conducting shroud of which the reflector serves as the front side. Guy wires to the back-side shroud can be used to figure the command surface. The complete shroud is not pictured in Figure 1.

J H Lang↗

Blockchain based Communication Architectures with Applications to Private Security Networks

Existing communication protocols in high consequence security networks are highly centralized. While this naively makes the controls easier to physically secure, external actors require fewer resources to disrupt the system because there are fewer points in the system can be destroyed or interrupted without the entire system failing. We present a solution to this problem using a proof-of-work-based blockchain implementation built on MultiChain. We construct a test-bed network containing two types of data input: visual imagers and microwave sensor information. These data types are ubiquitous in perimeter intrusion detection security systems and allow a realistic representation of a real-world network architecture. The cameras in this system use an object detection algorithm to nd important targets in the scene. The raw data from the camera and the outputs from the detection algorithm are then placed in a transaction on the distributed ledger. Similarly, microwave data is used to detect relevant events and are placed in a transaction. These transactions are then bundled into blocks and broadcast to the rest of the network using the Bitcoin-based MultiChain protocol. We develop five tests to examine the security metrics of our network. We performed the five security metric test using different sized networks from 7 to 39 nodes to determine how the metrics scale with respect to size. We nd that when compared to a centralized architecture our implementation provides a resiliency increase that is expected from a blockchain-based protocol without slowing the system so much that a human operator would notice. Furthermore, our approach is able to detect tampering in real time. Based on these results, we theorize that security networks in general could use a blockchain-based approach in a meaningful way.

97 MATHEMATICS AND COMPUTING↗

Analysis of Traffic Flow in Structured Urban Airspace Networks with MFD-based Feedback Control

This research delves into applying the Macroscopic Fundamental Diagram (MFD) concept to structured airspace networks for comprehensive aggregate modeling and introduces a feedback-based departure function aimed at optimizing traffic flow. Previous studies have rarely examined structured airspace networks featuring non-stationary vehicles through the MFD perspective. We devised a scenario grounded in practical applications, featuring a multi-lane network with explicit lane-changing behavior. The MFD effectively captured the open-loop response, displaying a low-scatter, unimodal curve on the flow versus occupancy plot. Drawing inspiration from the ground transportation ramp-metering strategies, a proportional-integral-based controller was developed. Extensive simulation outcomes suggest that feedback control, informed by MFD, holds significant potential for managing traffic flow in Urban Air Mobility (UAM) environments; a reduction of 80% in the peak number of vehicles in a holding pattern was observed for a slight reduction in throughput in this study.

MFD↗

Analysis of Traffic Flow in Structured Urban Airspace Networks with MFD-based Feedback Control

This research delves into applying the Macroscopic Fundamental Diagram (MFD) concept to structured airspace networks for comprehensive aggregate modeling and introduces a feedback-based departure function aimed at optimizing traffic flow. Previous studies have rarely examined structured airspace networks featuring non-stationary vehicles through the MFD perspective. We devised a scenario grounded in practical applications, featuring a multi-lane network with explicit lane-changing behavior. The MFD effectively captured the open-loop response, displaying a low-scatter, unimodal curve on the flow versus occupancy plot. Drawing inspiration from the ground transportation ramp-metering strategies, a proportional-integral-based controller was developed. Extensive simulation outcomes suggest that feedback control, informed by MFD, holds significant potential for managing traffic flow in Urban Air Mobility (UAM) environments; a reduction of 80% in the peak number of vehicles in a holding pattern was observed for a slight reduction in throughput in this study.

MFD↗

Zero-Trust Architecture for Autonomous Edge Computing

We are at the apex of an aviation revolution where autonomy will play a central role in enabling complex, multi-agent systems to communicate, interact, and collaborate on a myriad of applications spanning autonomous swarms to wild-fire management. Autonomy is not an absolute but rather a spectrum ranging from a system requiring significant human intervention to one requiring little to none [1]. For example, the extreme, in the case of an autonomous aircraft, is one that operates independently in the airspace interacting with all other elements (air traffic controllers, other pilots) as if it were a human pilot. Critical to this vision is an architecture that enables autonomous agents to interact with minimal latency. Edge computing is an emerging architecture where compute and storage is pushed to the ‘edge’ of the network in order to minimize the round-trip time from agent to resource thereby mitigating the latency associated with cloud-only based approaches. Additionally, services can generate massive amounts of data (e.g., video feeds), which may require analysis in near real-time. Moving this data to the cloud for further processing may not be feasible due to latency, bandwidth, and cost. Privacy, security, and reliability can also be improved by edge computing architectures. However, this geo-distributed and dynamic* architecture complicates the establishment of unambiguous network security boundaries and can lead to vulnerabilities including man in the middle attacks, replay attacks, physical security breaches of edge nodes, signal interception, etc. This motivates the need for zero-trust architectures [2–4] which de-emphasize the notion of static network perimeters and, as the name implies, do not instill any innate trust in any particular agent. It is required that all agents must be authorized and approved in every transaction. In this paper, we present a zero-trust architecture suitable for edge-computing applications that demand significant low-latency, security, privacy, and reliability.

zero trust↗