Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “source authentication”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Source Authentication of Distribution Synchrophasors for Cybersecurity of Microgrids

This letter proposes a hybrid approach combining Self-Adaptive Mathematical Morphology (SAMM) and Time-Frequency (TF) techniques to authenticate the source information of Distribution Synchrophasors (DS) within near-range locations. The SAMM can adaptively regulate the synchrophasors variations which are representatives of local environmental characteristics. Subsequently, TF mapping is employed to extract informative signatures from the regulated synchrophasors variation. Finally, Random Forest Classification (RFC) is used to correlate the extracted signatures with the source information based on the derived TF mapping. Experiment results using DS collected at multiple small geographical scales validated the proposed methodology.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Data source authentication of synchrophasor measurement devices based on 1D-CNN and GRU

Synchrophasor measurement devices (SMDs) have been widely deployed to support real-time monitoring and control of power systems. In the meantime, data spoofing has emerged in recent years. Therefore, it is of great importance to study data authentication algorithms for detecting and defending the data spoofing effectively. Here, a one-dimensional convolutional neural network (1D-CNN) is utilized to extract temporal signatures hidden in frequency, voltage angle and amplitude data; then the gated recurrent unit (GRU) employs these temporal signatures for data source authentication. In case studies, the performances of different algorithms are tested in large-scale power systems with numerous SMDs for the first time, and comparisons among different algorithms show that the proposed algorithm can achieve a higher accuracy of data source authentication with a shorter time window.

47 OTHER INSTRUMENTATION↗

Method and system for source authentication in group communications

A method and system for authentication is provided. A central node for issuing certificates to a plurality of nodes associated with the central node in a network is also provided. The central node receives a first key from at least one node from among the plurality of nodes and generates a second key based on the received first key and generates a certificate for the at least one node. The generated certificate is transmitted to the at least one node.

Roy-Chowdhury, Ayan↗

Multi-View Convolutional Neural Network for Data Spoofing Cyber-Attack Detection in Distribution Synchrophasors

Security of Distribution Synchrophasors Data (DSD) is of paramount importance as the data is used for critical smart grid applications including situational awareness, advanced protection, and dynamic control. Unfortunately, the DSD are attractive targets for malicious attackers aiming to damage grid. Data spoofing is a new class of deceiving attack, where the DSD of one Phasor Measurement Units (PMUs) is tampered by other PMUs thereby spoiling measurement based applications. In order to address this issue, a source authentication based data spoofing attack detection method is proposed using Multi-view Convolutional Neural Network (MCNN). First, common components embedded in raw frequency measurements from DSD are removed by Savitzky-Golay (SG) filter. Second, fast S transform (FST) is utilized to extract representative spatial fingerprints via time frequency analysis. Third, the spatial fingerprint is fed to MCNN, which combines dilated and standard convolutions for automatic feather extraction and source identification. Finally, according to the output of MCNN, spoofing attack detection is performed via threshold criterion. Extensive experiments with actual DSD from multiple locations in FNET/Grideye are conducted to verify the effectiveness of the proposed method.

97 MATHEMATICS AND COMPUTING↗

First Experiences Using XACML for Access Control in Distributed Systems

Authorization systems today are increasingly complex. They span domains of administration, rely on many different authentication sources, and manage permissions that can be as complex as the system itself. Worse still, while there are many standards that define authentication mechanisms, the standards that address authorization are less well defined and tend to work only within homogeneous systems. This paper presents XACML, a standard access control language, as one component of a distributed and inter-operable authorization framework. Several emerging systems which incorporate XACML are discussed. These discussions illustrate how authorization can be deployed in distributed, decentralized systems. Finally, some new and future topics are presented to show where this work is heading and how it will help connect the general components of an authorization system.

Lorch, Marcus↗

Model-Free Data Authentication for Cyber Security in Power Systems

With the development and wide deployment of measurement equipment, data can be automatically measured and visualized for situation awareness in power systems. However, the cyber security of power systems is also threated by data spoofing attacks. This letter proposed a measurement data source authentication (MDSA) algorithm based on feature extraction techniques including ensemble empirical mode decomposition (EEMD) and fast Fourier transform (FFT), and machine learning for real-time measurement data classification. Compared with previous work, the proposed algorithm can achieve higher accuracy of MDSA using a shorter window of data from closely located synchrophasor measurement sensors.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cardea: Providing Support for Dynamic Resource Access in a Distributed Computing Environment

The environment framing the modem authorization process span domains of administration, relies on many different authentication sources, and manages complex attributes as part of the authorization process. Cardea facilitates dynamic access control within this environment as a central function of an inter-operable authorization framework. The system departs from the traditional authorization model by separating the authentication and authorization processes, distributing the responsibility for authorization data and allowing collaborating domains to retain control over their implementation mechanisms. Critical features of the system architecture and its handling of the authorization process differentiate the system from existing authorization components by addressing common needs not adequately addressed by existing systems. Continuing system research seeks to enhance the implementation of the current authorization model employed in Cardea, increase the robustness of current features, further the framework for establishing trust and promote interoperability with existing security mechanisms.

Lepro, Rebekah↗

Multifractal Characterization of Distribution Synchrophasors for Cybersecurity Defense of Smart Grids

“Source ID Mix” spoofing emerged as a new type of cyber-attack on Distribution Synchrophasors (DS) where adversaries have the capability to swap the source information of DS without changing the measurement values. Accurate detection of such a highly-deceptive attack is a challenging task especially when the spoofing attack happens on short fragments of DS recorded within a relatively small geographical scale. Herein this letter proposes an effective approach to detect this cyber-attack by realizing the multifractal characteristics of DS measurements. First, the multifractal cross-correlation of DS measured at multiple intra-state locations is revealed. Then the derived correlation is integrated with weighted two-dimensional multifractal surface interpolation to reconstruct quasi high-resolution signals. Finally, informative location-specific signatures are extracted from the high-resolution DS and they are integrated with advanced machine learning techniques for source authentication. Experiments using the real-life DS are performed to verify the proposed method.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cardea: Dynamic Access Control in Distributed Systems

Modern authorization systems span domains of administration, rely on many different authentication sources, and manage complex attributes as part of the authorization process. This . paper presents Cardea, a distributed system that facilitates dynamic access control, as a valuable piece of an inter-operable authorization framework. First, the authorization model employed in Cardea and its functionality goals are examined. Next, critical features of the system architecture and its handling of the authorization process are then examined. Then the S A M L and XACML standards, as incorporated into the system, are analyzed. Finally, the future directions of this project are outlined and connection points with general components of an authorization system are highlighted.

Lepro, Rebekah↗

Synthesis of hydroxycinnamoyl shikimates and their role in monolignol biosynthesis

Hydroxycinnamoyl shikimates were reported in 2005 to be intermediates in monolignol biosynthesis. 3-Hydroxylation of p-coumarate, originally thought to occur via coumarate 3-hydroxylase (C 3 H) from p-coumaric acid or its CoA thioester, was revealed to be via the action of coumaroyl shikimate 3'-hydroxylase (C 3 'H) utilizing p-coumaroyl shikimate as the substrate, itself derived from p-coumaroyl-CoA via hydroxycinnamoyl-CoA: shikimate hydroxycinnamoyltransferase (HCT). The same HCT was conjectured to convert the product, caffeoyl shikimate, to caffeoyl-CoA to continue on the pathway starting with its 3-O-methylation. At least in some plants, however, a more recently discovered caffeoyl shikimate esterase (CSE) enzyme hydrolyzes caffeoyl shikimate to caffeic acid from which it must again produce its CoA thioester to continue on the monolignol biosynthetic pathway. HCT and CSE are therefore monolignol biosynthetic pathway enzymes that have provided new opportunities to misregulate lignification. To facilitate studies into the action and substrate specificity of C 3 H/C 3 'H, HCT, and CSE enzymes, as well as for metabolite authentication and for enzyme characterization, including kinetics, a source of authentic substrates and products was required. A synthetic scheme starting from commercially available shikimic acid and the four key hydroxycinnamic acids (p-coumaric, caffeic, ferulic, and sinapic acid) has been developed to provide this set of hydroxycinnamoyl shikimates for researchers.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

Shape Optimization of Header Pipes in Power Plants for Enhanced Efficiency and Environmental Sustainability

In a power plant, the header pipe plays a pivotal role in optimizing the performance of diverse systems by serving as a central conduit for the collection and distribution of steam within the plant. This paper investigates the significance of header pipes within power plant setups, highlighting their critical influence on reliability, efficiency, and the performance of the power plant as a whole. The concept of shape optimization emerges as a crucial factor in power plant design and operation, with the potential to maximize performance while minimizing the use of materials. Shape optimization not only enhances efficiency but also contributes to reducing the environmental footprint of power plant installations. In this paper, we initially developed a methodology designed for optimizing header shapes with the primary goal of reducing the usage of costly new alloy materials and lowering the overall maintenance operation expenses. Secondly, we conducted a case study based on an authentic header sourced from an operational power plant.

20 FOSSIL-FUELED POWER PLANTS↗

Extracting Critical Metals from Authentic Bauxite Residue

Securing domestic sources of critical minerals (CM) is paramount to ensuring a robust and self-sustaining technology infrastructure. Utilizing untapped non-conventional sources, like acid mine drainage, coal ash, bauxite residue/red mud, and more is an emerging approach that addresses this national concern while identifying new value-added pathways originating from waste streams. Red mud is a byproduct of the Bayer process that produces alumina and contains a wealth of CM – 50 µg/g Ga, 2.9 mg/g total rare earth elements plus yttrium, 12 mg/g Mn, 58 mg/g Al, and others. About 170 MM tonnes of red mud are co-produced annually alongside the 142 MM tonnes of alumina generated, highlighting the abundancy of this feedstock. In this work, different strategies were explored for extracting CM from authentic bauxite residue that involve thermal heating, microwave heating, and sonication all with different acids and buffers. CM recovery was then explored one step further by testing the adsorption of the extracted metals onto NETL’s Multi-functional Sorbent Technology (MUST). Microwave treatment of red mud proved the most effective CM extraction, whereas sonication was less desirable due to scale-up concerns. Successful recovery of CM from this leachate with MUST supports further studies toward optimizing the overall process.

bauxite residue↗

Assessment of the Electrical Substation-Grid Testbed with Inside/Outside Devices and Distributed Ledger Technology

The electrical substation-grid testbed was created to integrate the GOOSE and/or DNP (Distributed Network Protocol) messages with time synchronized sources and Distributed Ledger Technology (DLT). The objective was to study the impact of faults and cyber-events at an electrical substation with inside (protective relays) and outside (power meters) substation devices. The electrical substation-grid testbed was based on the design of a 34.5/ 12.47 kV electrical substation (sectionalized bus configuration) with two power transformers, connected to radial power lines and load feeders. The electrical substation-grid testbed was installed at 252 lab space (Advanced Power System Protection), Grid Research Integration and Deployment Center (GRID-C), Oak Ridge National Laboratory. This testbed was created for Task 5, DarkNet project. The electrical substation-grid testbed was created to simulate fault and/or cyber events that could potentially result in damage to the electrical infrastructure. In addition, tests were run that are usually not allowed to be performed in an operational electrical power grid, because these test scenarios could trip breakers and/or generate fault situations that could potentially damage equipment. The number of tests performed in the electrical substation-grid testbed were executed in a better way than in a real electrical substation and/or power grid, because multiple tests could be run in a short period of time, and complex permits, and safety/ schedule restrictions like in a real electrical substation environment were not needed. The electrical substation-grid testbed was created using real measurement, communication, and protection devices that are used by electrical utilities, to have same conditions that we could observe in a real power grid or electrical substation. The electrical substation-grid testbed was based on using a real time simulator and expansion box with amplifiers that were wired to electrical substation-grid devices. This hardware-in-the-loop (HIL) was provided by protective relays, power meters, ethernet switches, remote terminal units, synchronized timing network clock, DLT devices, workstations, and servers. This report includes the design, installation, and assessment of the electrical substation-grid testbed that was similar to an operational electrical substation, integrating the power system protection, communication, and control systems. The results for the electrical substation-grid testbed were based on:• verifying the analog signals for protective relays and power meters, • observing the synchronized time source frame at devices, • authenticating the GOOSE (IEC 61850) and DNP messages from power meters and protective relays, and • verifying the trip conditions of protective relays at fault tests with the power system fault event detection, using DLT devices. For future work, the electrical substation-grid testbed with protective relays and power meters, using DLT and synchronized time source from DarkNet, will be used to study the impact of cyber-events at inside and outside substation devices. Advanced algorithms for detecting cyber-events produced by non-desired protective relay settings will be studied, to improve the detection and reliability of protection, control, and communication systems at power grids.

24 POWER TRANSMISSION AND DISTRIBUTION↗

VISTA

SAND2025-14753O VISTA Image Management is a tool that serves as a thin wrapper around S3 storage, enabling teams to create projects, upload images, and add labels to data. It uses standard open-source libraries, employs conventional authentication and authorization methods, and is expected to run behind a reverse proxy that handles authentication. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Garland, Anthony [Sandia National Lab. (SNL-CA), L↗

Modular Security Apparatus for Managing Distributed Cryptography for Command-and-Control Messages on Operational Technology Networks (Module-OT)

Module-OT is a bump- in- the- wire solution acting as a secure conduit for data between devices or systems across a network. Using the latest in open-source cryptographic libraries, all defined communications undergo authentication, authorization, and encryption. The core system can be easily installed through industry standard processes, and the use of popular open-source packages allows for it to be customizable customized by the developer community or deployed in unique embedded environments.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Heterogeneity Determination and Purification of Commercial Hen Egg-White Lysozyme

Hen egg-white lysozyme (HEWL) is widely used as a model protein, although its purity has not been adequately characterized by modern biochemical techniques. We have identified and quantified the protein heterogeneities in three commercial HEWL preparations by sodium dodecyl sulfate polyacrylamide gel electrophoresis with enhanced silver staining, reversed-phase fast protein liquid chromatography (FPLC) and immunoblotting with comparison to authentic protein standards. Depending on the source, the contaminating proteins totalled 1-6%(w/w) and consisted of ovotransferrin, ovalbumin, HEWL dimers, and polypeptides with approximate M(sub r) of 39 and 18 kDa. Furthermore, we have obtained gram quantities of electrophoretically homogeneous [> 99.9%(w/w)] HEWL by single-step semi-preparative scale cation-exchange FPLC with a yield of about 50%. Parallel studies of crystal growth kinetics, salt repartitioning and crystal perfection with this highly purified material showed fourfold increases in the growth-step velocities and significant enhancement in the structural homogeneity of HEWL crystals.

Thomas, B. R.↗