Search NASA⌕ Search

Engineering topics

Johnson, Jay

Publications and source records attributed to Johnson, Jay.

Data for "Propagation of EMIC Waves from Shabansky Orbits in the Dayside Magnetosphere"

Full-wave simulations of electromagnetic ion cyclotron waves in a non-dipole compressed magnetic field have been conducted using the Petra-M simulation code. The manuscript investigates the effect of misalignment of the Faraday screen and electron density in the scrape-off layer on the excitation and propagation of fast helicon and slow mode waves.

Magnetosphere: outer↗

DEReliction: A Cybersecurity Vulnerability Assessment Methodology for Distributed Energy Resources

With the increasing integration of Distributed Energy Resources (DER) into the electric grid, maintaining grid reliability and resilience requires that these devices remain secure. This paper discusses a cybersecurity vulnerability assessment methodology that incorporates best practices from Sandia National Laboratories, SANS Institute, OWASP Foundation, and other web and Internet of Things (IoT) penetration testing (“pen testing”) programs, courses, and frameworks for assessing the security posture of devices. The methodology involves five sequential steps: (1) Collect Public Information, (2) Extract Hardware Details, (3) Inventory Software Components, (4) Identify Vulnerabilities, and (5) Test Vulnerabilities. Each step uncovers potential weaknesses in both hardware and software components of DER devices, considering adversary tactics, techniques, and procedures (TTPs), and potential attack vectors along the way. The results from the execution of this method on multiple residential- and small commercial-scale photovoltaic (PV) inverters reveled hardware and software vulnerabilities, which highlight the benefit of taking a methodical approach to discover vulnerabilities. While the specific vulnerability details are not shared here, a generalized overview of findings underscore the importance of robust security assessments for DER devices. Adoption of an assessment framework of this kind will identify and mitigate cybersecurity threats and bolster the resilience of DER-integrated electric grids.

24 POWER TRANSMISSION AND DISTRIBUTION↗

EV SALaD 2023 Demonstration: Best Practices and Mitigations for Protecting EVSE Infrastructure

The Electric Vehicle Secure Architecture Laboratory Demonstration (EV SALaD) program is a demonstration of cybersecurity best practices for high-power electric vehicle (EV) charging infrastructure led by Idaho National Laboratory (INL), in collaboration with other DOE National Laboratories participating in the EVs at Scale Consortium.a Sandia National Laboratories (SNL) and Pacific Northwest National Laboratory (PNNL) participated in the first 2-year (FY22-23) demonstration cycle for EV SALaD. This report documents the FY23 demonstration, the second in a series of demonstrations and collaborations in deploying and operating cybersecure EV charging infrastructure. It includes a summary of improvements from the FY22 demonstration, technical analysis of the FY23 demonstration, how the research demonstrates cyber-physical and cybersecurity best practices for high-power EV charging infrastructure, and related impacts to national and energy security. For EV SALaD, the FY22 demonstration focused on the detection, ranking, and prioritization of anomalous events for high-power EV charging. The FY23 demonstration additionally included the demonstration of cybersecurity best practices, which included protection and mitigation solutions to prevent, respond, and recover from anomalous events. During the demonstrations, the multi-lab EV SALaD team conducted a Test Effect Payload (TEP)b evaluation on extreme fast charger (XFC) hardware equipped with Cerberus, a detection and response solution, to demonstrate anomaly detection and mitigation cybersecurity best practices against cyber-enabled events.

33 ADVANCED PROPULSION SYSTEMS↗

Disrupting EV Charging Sessions and Gaining Remote Code Execution with DoS, MITM, and Code Injection Exploits using OCPP 1.6

Open Charge Point Protocol (OCPP) 1.6 is widely used in the electric vehicle (EV) charging industry to communicate between Charging System Management Services (CSMSs) and Electric Vehicle Supply Equipment (EVSE). Unlike OCPP 2.0.1, OCPP 1.6 uses unencrypted websocket communications to exchange information between EVSE devices and an onpremise or cloud-based CSMS. In this work, we demonstrate two machine-in-the-middle (MITM) attacks on OCPP sessions to terminate charging sessions and gain root access to the EVSE equipment via remote code execution (RCE). Second, we demonstrate a malicious firmware update with a code injection payload to compromise an EVSE. Lastly, we demonstrate two methods to prevent availability of the EVSE or CSMS. One of these, originally reported by SaiFlow, prevents traffic to legitimate EVSE equipment using a DoS-like attack on CSMSs by repeatedly connecting and authenticating several CPs with the same identities as the legitimate CP. These vulnerabilities were demonstrated with proof-of-concept exploits in a virtualized Cyber Range at Wright State University and/or with a 350 kW Direct Current Fast Charger (DCFC) at Idaho National Laboratory. The team found that OCPP 1.6 could be protected from these attacks by adding secure shell (SSH) tunnels to the protocol, if upgrading to OCPP 2.0.1 was not an option. Index Terms—Electric vehicle charging, cybersecurity, OCPP, cyberattack, cyber-resilience. INSPEC Accession Number: 23981565

99 GENERAL AND MISCELLANEOUS↗

Chapter 32 - Power Grid Resilience

The new energy paradigm is altering the current power grid trend from synchronous generator reliant system toward power-electronics-based distributed energy resources (DERs). The resilient operation of modern power grid is highly dependent upon cyber and physical reliable operation of DERs. Power grid resilience broadly refers to the ability of the grid to be robust to eventualities and singularities that may disrupt the continuity of reliable power flow. This could involve resilience related to the physical system but more recently, the focus on cyber resilience has been evolving rapidly especially given the burgeoning growth of distributed generation and power-electronics-based DERs under smart grid and given that such threats to reliable operation do not have to evolve localized to where the physical asset is. Commonly, in power grids dominated by DERS, control and energy management are structured at a multitime scale multilayer fashion: (i) primary control layer at microseconds time scale, (ii) secondary control layer at millisecond time scale, and (iii) tertiary control layer at seconds to minutes time scale. The cyber-related issues that may affect the power grid resilience can be introduced in through primary, secondary, and tertiary control layers. The failure of each of these control layers may impact the reliable and resilient operation of the overall network and cause widespread failures which leads to unintended blackouts. As such, this chapter focuses on cyber-related resilience issues in primary control layer, secondary control layer, tertiary control layer, wide area/utility control, and anomaly detection and resilient communication.

anomaly detection↗

Institute for Advanced Education in Geospatial Sciences Educating the Next Generation of Scientists

The project, as stated earlier is sponsored by NASA and is located at the University of Mississippi in Oxford, MS. It has two principal investigators with one of them, Pam Lawhead, serving as the Director of the Institute. The goal of the project is to create fifty online courses in Remote Sensing over the five year life of the project. Each year ten courses are put out for bid and the best ten submissions are accepted. This request for proposals insures that the course creators are content experts. Equivalence of product drives the online hosting of the courses. That is, we want the online presentation and delivery of each course to be as multi-media intensive as is effective. The goal is not to replace existing courses but, to provide courses created by content experts to as many colleges and universities as possible. This effort to create and host online courses has as its final goal the creation of a very large college educated workforce prepared to use the vast stores of information gathers by NASA and other remote sensing industries to enhance life on this planet.

Lawhead, Pamela↗

An intelligent planning and scheduling system for the HST servicing missions

A new, intelligent planning and scheduling system has been delivered to NASA-Goddard Space Flight Center (GSFC) to provide support for the up-coming Hubble Space Telescope (HST) Servicing Missions. This new system is the Servicing Mission Planning and Replanning Tool (SM/PART). SM/PART is written in C and runs on a UNlX-based workstation (IBM RS/6000) under Motif. SM/PART effectively automates the complex task of building or rebuilding integrated timelines and command plans which are required by HST Servicing Mission personnel at their consoles during the missions. SM/PART is able to quickly build or rebuild timelines based on information stored in a Knowledge Base (KB) by using an Artificial Intelligence (AI) tool called the Planning And Resource Reasoning (PARR) shell. After a timeline has been built in the batch mode, it can be displayed and edited in an interactive mode with help from the PARR shell. Finally a detailed command plan is generated. The capability to quickly build or rebuild timelines and command plans provides an additional safety factor for the HST, Shuttle and Crew.

Johnson, Jay↗

Software reuse in spacecraft planning and scheduling systems

The use of a software toolkit and development methodology that supports software reuse is described. The toolkit includes source-code-level library modules and stand-alone tools which support such tasks as data reformatting and report generation, simple relational database applications, user interfaces, tactical planning, strategic planning and documentation. The current toolkit is written in C and supports applications that run on IBM-PC's under DOS and UNlX-based workstations under OpenLook and Motif. The toolkit is fully integrated for building scheduling systems that reuse AI knowledge base technology. A typical scheduling scenario and three examples of applications that utilize the reuse toolkit will be briefly described. In addition to the tools themselves, a description of the software evolution and reuse methodology that was used is presented.

Mclean, David↗