Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “zero knowledge”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Demonstration and Concept of Operations for a Zero-Knowledge Protocol Passive Imaging Measurement for Arms Control

Here, we present an imaging system that employs zero-knowledge protocols to protect sensitive geometrical information, along with procedures to increase confidence in the result. The goal of this work is to enable the inclusion of warhead confirmation measurements in future arms control treaties. We present a demonstration of both true positive and true negative measurements that validate models and establish authenticating procedures toward meeting acceptance requirements for use in nuclear facilities. We use a two-dimensional time-encoded fast neutron imaging system with an anti-symmetric mask pattern; the fast neutron count values exceeding minimum or maximum thresholds indicate that two measured items are not identical. Laboratory measurements over twenty trials show that alarm rates for negative confirmation measurements are within uncertainties of model predictions. Positive confirmation measurements indicate that alarm rates are large enough to encourage treaty compliance.

Sweany, Melinda Dominique [Sandia National Laborat↗

Verifying the Computational Integrity of Power Grid Controls with Zero-Knowledge Proof

The control of future power grids is migrating from a centralized to a distributed/decentralized scheme to enable a massive penetration of distributed energy resources with rising dependence on communication infrastructure. A common assumption made for most existing distributed/decentralized controllers is that local controllers would faithfully follow the designated controller dynamics based on the data received from communication channels. However, with increased probability of cyberattacks on Operational Technology infrastructure, such an assumption could be risky because proper execution of the controller dynamics is then built on trust in secure communication and computation. In this work, we leverage a cryptography technology known as zero-knowledge scalable transparent arguments of knowledge (zk-STARK) to verify the computational integrity of power grid control algorithms, with projected linear dynamics-based control schemes as the initial proof-of-concept test case. The method presented here converts the cybersecurity challenge of data integrity for grid control into a subset of computational integrity.

computational integrity↗

COnfirmation using Gamma-ray Non-Imaging Zero-knowledge ANti-mask Time-encoding (COGNIZANT) Final Summary Report

In potential future arms reduction treaties in which the numbers of nuclear warheads may approach small numbers, using delivery systems as a proxy for the warheads themselves may be insufficient. Therefore, a technical means of verifying the presence of a nuclear warhead may become necessary. Verifying that a declared item actually is a warhead is technically challenging within a verification regime: providing assurance to the monitoring party that a presented item is a warhead while protecting sensitive information about that warhead may be required. It is generally believed that strong assurance will require the confirmation of key attributes that may reveal closely-guarded critical design information. This provides high confidence to the monitoring party, but presents a risk of information loss to the host. A verification system must overcome this hurdle. Over the last several decades, systems have been developed that balance host and monitoring partner needs by using sensitive information to confirm treaty accountable items (TAI) as warheads while sequestering that information behind an information barrier (1). These are designed to meet the needs of the host but places the onus on the monitor to authenticate the hardware, firmware, and software. Authentication requires that the monitor confirm that all components of the system have not been modified and work as intended. In 2014, Glaser et al. proposed applying the concept of “zero knowledge protocols” (ZKP) from the field of cryptography to the problem of warhead verification (2). In mathematical cryptography, ZKP is accomplished by challenging one party to solve a problem that is only possible if that party possesses the information being authenticated. After repeated challenges, the party provides confidence that it possesses this information without revealing any details about the information itself. Systems have been in development based on this idea at both Princeton and MIT (2) (3) (4). The final measurement results produced by these systems can be viewed by both the host and the monitoring party without the worry of revealing sensitive information. However, in both of these physical implementations, there remains an information barrier within the system. The need for a digital information barrier to protect a measurement result is eliminated, but it has been replaced with the need to sequester physical components of the system, potentially obfuscating the measurement process itself. Both implementations physically insert information into the system that requires protection to prevent undesired disclosure of sensitive information: in the Princeton method, one must physically load the complement of the expected image of a true warhead into the system, and in the MIT technique, one loads a collection of spectator foils whose thicknesses physically encrypt a measured spectrum. This complicates authentication of the hardware and measurement process. The CONFIDANTE/COGNIZANT concept developed in this project do not load sensitive information into the system at any time, and could therefore open the possibility of allowing the inspector to not only view the final data but also the measurement as it is being performed and all associated equipment.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Cyber Resilient Design and Controls for Energy Systems

As the grid of today is evolving into a highly distributed and autonomous cyber-physical system with higher penetration of Distributed Energy Resources (DERs) and autonomous controls that are dependent on the cyber infrastructure, there are novel and increasing challenges to cyber-resilient operation of the grid. While the traditional mechanisms take a "bolt on" approach to cybersecurity and resiliency, this talk presents two novel technologies developed at NREL that "bake in" security and resilience into the design and control of the grid. An Adaptive Resilience Metrics framework is a novel mechanism for system owners and operators to understand the impact of cyber and physical system design and topology on the resilient operation, while also helping determine optimal policies in response to adverse cyber events. Along with that a zero-knowledge proof-based technique helps incorporate security into the controls layer by focusing on computational integrity rather than data integrity. By leveraging design and control properties unique to Operational Technology systems these technologies will not only help enhance cyber-resilience for the grid of today, but a highly distributed and autonomous grid of tomorrow.

cyber resilience↗

A Privacy-Preserving Cyber Threat Intelligence Sharing System

Cyber Threat Intelligence (CTI) is a key resource for developing defensive strategies against potential cyber adversaries. Entities typically access CTI through open-source platforms, national agencies, or specialized commercial services. However, the bi-directional exchange of CTI is hindered by organizational trust boundaries, which complicate the sharing processes between entities and CTI providers. Centralized CTI services benefit from receiving suspicious cyber observables such as IP addresses, domain names, and email addresses from various entities. The aggregation allows for the correlation of widespread adversarial activities to enhance the alert and response mechanisms across the network of involved parties. Despite these benefits, openly sharing such observables incurs potential legal, regulatory, and reputational risks for the disclosing entities.This paper introduces a system designed to facilitate the secure exchange of cyber observables across trust boundaries without compromising the anonymity of the sharing entities. Here, we propose an architecture that leverages common web protocols alongside zero-knowledge proofs to authenticate members while maintaining anonymity. Additionally, we outline a privacy model tailored for STIX (Structured Threat Information eXpression) cyber observables to minimize the risk of inadvertently disclosing private information. Through our threat models, we assess the privacy implications of our proposed system and demonstrate its potential to enhance collaborative cyber defense efforts without exposing entities to undue risk.

BBS+ Signatures↗

Secure System Composition and Type Checking using Cryptographic Proofs [Slides]

By using zkSNARKs to prove that values have specific dependent types, it is possible to provably assure compatibility and correctness without revealing sensitive information and extend our trusted computing base well beyond our own system. The approach we developed expands the scope of what non-interactive zero-knowledge proofs can capture to include properties about both the execution and correctness of programs.

97 MATHEMATICS AND COMPUTING↗

A Computational Review of Privacy-Preserving Mechanisms for the Smart Grid

Smart grid technologies have rapidly become one of the largest and most comprehensive sources of data for the modern utility. For the most part, data streams are seen as an essential tool that enable utilities to carry their day-to-day business operations, but they also create the need for efficient and secure data management strategies. In the context of the smart grid, ensuring data privacy is becoming an increasing concern due to a combination of factors that range from shifts in operational paradigms and rapid technology evolution to changes in legislation. Furthermore, researchers have highlighted the risks associated with improperly protected energy records. For example, energy consumption data from homes could be used to infer the behaviors and habits of home occupants through activity recognition or user profiling (Fan, 2017), which may lead to unfair service pricing, targeted advertising, or other personal security violations. Similarly, Electric Vehicles’ (EVs) charging metadata could be used to reveal private information about the owner such as their payment methods, preferred charging stations, and other locational and timing information that could be used to reconstruct the vehicle owner’s behaviors. The privacy of user data, even when used for statistical analysis or machine learning training processes, also needs to be carefully considered, as an individual’s private traits may still be vulnerable if their inclusion/exclusion greatly impacts the result or could be linked to a public dataset through cross-reference. The breach of user privacy also has severe impacts for organizations that store, transmit, or work on the data in the form of diminishing the public’s trust in them while potentially incurring legal consequences (e.g., fines and suspensions under the European Union General Data Protection Regulation, Health Insurance Portability and Accountability Act, etc.). Because of these risks, several privacy-preserving mechanisms are available to help organizations comply with privacy legislations and prevent the unauthorized and malicious use of user data. In light of these concerns, this report focuses on performing a computational review of privacy-preserving mechanisms that have received a significant amount of interest in literature. It specifically focuses on 1) homomorphic encryption, 2) zero-knowledge proofs, 3) differential privacy, and 4) federated learning. It is worth noting that although many of the methods presented in this document rely on cryptographic primitives, their intent is not to provide perfect secrecy, but rather to enable users to maintain privacy, and thus they shall not be compared or equated to other constructs that are aimed to address cybersecurity constructs.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Enabling Computation on Sensitive Data in International Safeguards with Privacy-Preserving Encryption Techniques

Privacy-preserving machine learning is a field of study that explores how to protect and preserve the privacy of sensitive data while allowing the data to be used by machine learning algorithms. This field has had substantial industry investment due to heightened concerns about privacy in the technology industry, with a focus in two broad application areas: financial services and healthcare. Numerous privacy-preserving methods have also been proposed for international safeguards, but they have been difficult to enact because the data they require is con- sidered sensitive or proprietary by the nuclear facility operator. This work examines how current privacy-preserving approaches might be used to enable the International Atomic Energy Agency (IAEA) to use that data to contribute to a safeguards conclusion about a state while giving nuclear operators confidence that their sensitive data is adequately protected. This paper begins by exploring several broad categories of privacy-preserving techniques including homomorphic encryption, secure multiparty computation, secure enclaves, and zero-knowledge proofs. Then we discuss some of the security considerations related to using these methods, potential use cases, and a conceptual system design for applying privacy-preserving methods in international safeguards.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Privacy by Design in Distributed Edge Systems: Innovating Secure Workflows for Smart Cities

The proliferation of distributed edge systems, such as those in smart cities, healthcare, and industrial IoT, offers unprecedented opportunities for data processing closer to its source, thereby reducing latency and enhancing efficiency. However, these systems also present significant privacy challenges due to the handling of sensitive data from multiple sources. This article explores the critical need for designing privacy-preserving workflows in distributed edge systems to ensure data security while maximizing the potential of edge computing. By examining the challenges, technological advancements, and potential of privacy-by-design approaches, we highlight the importance of integrating advanced privacy-preserving techniques like federated learning, differential privacy, homomorphic encryption, secure multi-party computation, and zero-knowledge proofs. These innovations are crucial for enhancing data security, regulatory compliance, and public trust in smart city applications, ultimately leading to safer and more efficient urban environments.

Kotevska, Olivera↗

Structured Prompt Interrogation and Recursive Extraction of Semantics (SPIRES): a method for populating knowledge bases using zero-shot learning

Abstract Motivation Creating knowledge bases and ontologies is a time consuming task that relies on manual curation. AI/NLP approaches can assist expert curators in populating these knowledge bases, but current approaches rely on extensive training data, and are not able to populate arbitrarily complex nested knowledge schemas. Results Here we present Structured Prompt Interrogation and Recursive Extraction of Semantics (SPIRES), a Knowledge Extraction approach that relies on the ability of Large Language Models (LLMs) to perform zero-shot learning and general-purpose query answering from flexible prompts and return information conforming to a specified schema. Given a detailed, user-defined knowledge schema and an input text, SPIRES recursively performs prompt interrogation against an LLM to obtain a set of responses matching the provided schema. SPIRES uses existing ontologies and vocabularies to provide identifiers for matched elements. We present examples of applying SPIRES in different domains, including extraction of food recipes, multi-species cellular signaling pathways, disease treatments, multi-step drug mechanisms, and chemical to disease relationships. Current SPIRES accuracy is comparable to the mid-range of existing Relation Extraction methods, but greatly surpasses an LLM’s native capability of grounding entities with unique identifiers. SPIRES has the advantage of easy customization, flexibility, and, crucially, the ability to perform new tasks in the absence of any new training data. This method supports a general strategy of leveraging the language interpreting capabilities of LLMs to assemble knowledge bases, assisting manual knowledge curation and acquisition while supporting validation with publicly-available databases and ontologies external to the LLM. Availability and implementation SPIRES is available as part of the open source OntoGPT package: https://github.com/monarch-initiative/ontogpt.

59 BASIC BIOLOGICAL SCIENCES↗

Cyber-Resilient Distributed Autonomous Energy Grid

The aim of Cyber-Resilient Distributed Autonomous Grid research initiative is to advance fundamental science and engineering approaches for cyber-resilient design, control, and operation of a distributed, highly interconnected, and autonomous energy grid of the future. From increasing penetration of DERs, smart homes and building with highly controllable loads at the distribution layer, to the interconnection of bulk renewables at the transmission layer the fundamental nature of the energy grid is changing, and these changes are enabled by rapid increase in dependence on the communication infrastructure and independent third parties for control and operation of the grid. NREL's Integrated Energy Pathways critical objective correctly identifies that there are fundamental cyber-resilience challenges inherent in the grid's evolution, and this effort is establishing strong and novel integrated cyber-resilience framework and approaches to address these new and fundamental challenges.

controls↗

Three Approaches for Complete Measurement of the Transverse Beam Optics Along the Fermilab Muon Campus Extraction Line

Traditionally, the process of measuring the optical parameters of a beamline has employed the use of one of two standard methods, namely the three-screen method or a quadrupole magnet scan. Both require either an area of zero dispersion to perform the measurements or knowledge of the dispersion function and momentum spread beforehand in order to provide accurate results. There is however a third method that can be used to measure the standard optical parameters, the beam parameters, the dispersion function, and the momentum spread simultaneously. This method, aptly named the six-screen method, is an extension of the more standard three-screen method. Utilizing the simulation environment of G4beamline, we simulated the 8 GeV proton beam in the M4 beamline and measured the optical and beam parameters using the two standard approaches. Those results were then used as a reference to check the viability of employing the less standard six-screen method in the M4 line. If shown to be a viable option, the six-screen method could be used to retrieve the dispersion function and momentum spread of the beam without needing to change the energy of the beam.

43 PARTICLE ACCELERATORS↗

The Global Climate Action Partnership

The Global Climate Action Partnership (GCAP; formerly the Low Emission Development Strategies Global Partnership) is a worldwide network that accelerates ambitious climate goals and advances implementation in Africa, Asia, and Latin America and the Caribbean (LAC). Our strategic approach emphasizes country-driven implementation actions to achieve resilient, just, and inclusive low-emission and net-zero economies. As an incubator for scalable knowledge and solutions, GCAP is leading the way to equitable, climate-resilient, low-emission development.

African Climate Action Partnership↗

Sustainable Port Operations: Powered by NREL

Seaports are vital economic hubs that allow the United States to compete on a global scale. But the heavy vehicles and cargo equipment that enable their operations also emit harmful air pollutants and greenhouse gas emissions. For nearly two decades, National Renewable Energy Laboratory (NREL) researchers have worked toward comprehensive seaport decarbonization. They fuse world-class analysis with deep vehicle and transportation systems knowledge to guide strategic deployment of low- and zero-emissions vehicles, charging and refueling infrastructure, and grid improvements. Together, these capabilities can enable sustainable port operations. This fact sheet outlines major seaport and airport decarbonization capabilities across the laboratory, including: fleet research, energy data, and insights for decarbonization; comprehensive hydrogen infrastructure deployment; optimized charging through grid integration; strategic blueprinting for clean, optimized technology deployment; and integrating diversity, equity, inclusion, and accessibility considerations into decarbonization efforts.

ADVANCED PROPULSION SYSTEMS,ENERGY CONSERVATION, C↗