Search NASA⌕ Search

SEARCH · Search NASA

Results for “IT Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 289 records · Page 16

SUNSet: The Software Understanding for National Security Dataset Repo

SAND2025-00511O SUNSet: The Software Understanding for National Security Dataset Repo serves as a repository for software understanding researchers to conduct systematic research in the field. It provides a platform for storing questions, answers, and scripts related to software programs, supporting research in software understanding. The repository is a nascent effort aimed at exploring the support needed by researchers and documenting how software understanding questions can be addressed using existing tools. The software consists of a simple database and front end interface for easy access and management of the stored information. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Amon, Tod [Sandia National Lab. (SNL-CA), Livermor↗

Securing Grid-interactive Efficient Buildings (GEB) through Cyber Defense and Resilient System (CYDRES)

The DOE CYDRES project is driven by the urgent need to address critical research gaps in the domain of cyber-physical security of smart buildings, including Grid-interactive Efficient Buildings (GEBs). CYDRES, a real-time advanced building resilient platform, aims to enhance the cyber-attack-immune capabilities of buildings through multi-layered prevention, detection, and adaptation mechanisms. CYDRES consists of five key modules: a multi-layer network analyzer, an Automatic Fault Detection, Diagnosis, and Prognosis (AFDDP) framework, an intelligent mode selector, a cyber-resilient control framework, and a situation awareness platform. The Network Analyzer employs a data-driven framework that includes a protocol state learning tool and a CRF (Conditional Random Field) command validator. In Hardware-In-the-Loop (HIL) testbeds, it achieved 100% detection accuracy with a false alarm rate of 3%, validating its efficacy in identifying selected cyber-attacks. The AFDDP framework leverages pattern matching, PCA (Principal Component Analysis)-based strategies, and a DBN (Dynamic Bayesian Network)-based fault diagnosis approach to pinpoint the causes of physical system abnormalities using Building Automation System (BAS) data. In HIL experiments, the AFDDP module attained a detection accuracy of over 95% with a false alarm rate below 7%. Additionally, the fault detector utilized machine learning (Random Forest) and deep learning (Multi-Layer Perceptron) methods with acoustic sensor data to achieve a 100% fault detection accuracy in Heating, Ventilation, and Air-Conditioning (HVAC) equipment. The Mode Selector offered real-time impact analysis, allowing immediate actions to protect BASs in the face of emerging threats. The cyber-resilient control framework included an adaptive Model Predictive Control (MPC) and a measurement compensator, reducing temperature violations by up to 94% and improving the total demand flexibility by up to 70% in HIL experiments. Such HIL experiments covered a cyber-attack case and a physical fault case, showcasing CYDRES’ efficiency in maintaining operational continuity during threats. The situation awareness platform in Grafana enhanced real-time threat detection and response visualization, augmenting the operational awareness for building operators. CYDRES demonstrated high technical effectiveness in various test scenarios, particularly in HIL environments. The project's phased development approach ensured efficient use of resources, highlighting its practical feasibility and readiness for commercialization. By enhancing the security and resilience of building operations, CYDRES represents a significant advance in mitigating risks associated with cyber-physical systems, thereby enhancing public confidence in the safety of modern building infrastructure. Future directions for the project include expanding testing protocols, refining AFDDP methodologies, exploring more comprehensive resilient control strategies, and testing in real commercial buildings.

42 ENGINEERING↗

Intelligent Partitioning based Fully Parallel AC Security-Constrained Optimal Power Flow

Today’s power grid is becoming more diverse and integrated with high-level distributed energy resources and smart control technologies that is creating a new set of grid management challenges in terms of large-scale, nonlinear, and non-convex problem modeling, complex and time-consuming computation, as well as difficult uncertainty handling. This project focused on solving a challenging multi-period security-constrained generation scheduling problem, which is of great importance for maximizing the social welfare of real-time dispatch, day-ahead market, as well as weekly planning of power systems. Our developed software explored parallel optimization algorithms for complex and realistic power system models, and develop fast, efficient, and robust grid optimization solutions on the high-performance computing platform that will enable increased grid economics, flexibility, resilience, as well as energy security in the United States.

24 POWER TRANSMISSION AND DISTRIBUTION↗

X-ray Security Imaging on Personal Dosimetry [Slides]

Federal regulations mandate that personal dosimetry devices — like optically stimulated luminescence (OSLs) — must be worn by all US Department of Energy (DOE) and associated radiation workers to track their occupational dose. Unfortunately, the inadvertent passage of OSLs through x-ray security scanners can compromise their validity. With the advent of high energy, advanced resolution security technology used in airports, this once insignificant issue now requires that Radiological Control (RadCon) be able to accurately discern non-occupational dose to effected OSLs. This presentation will discuss the principles, methods, and, rather surprising, models for establishing the corrective dose estimates at the Idaho National Laboratory (INL), and its implication across the DOE.

61 RADIATION PROTECTION AND DOSIMETRY↗

Physical & Cyber Security Modeling Interfacing Through Dante and ARCADE

Physical security is increasingly facing new threats from cyber attackers, for which there is little research in the way of characterizing this threat. This report discusses the efforts to combine cyber and physical security modeling tools to investigate this novel combinatorial threat space. To accomplish this, the Dante force-on-force modeling and simulation software and the Advanced Reactor Cyber Analysis and Development Environment (ARCADE) were integrated. Dante provides a 3D environment which models the physical world, while ARCADE provides the cyber and control systems world.

42 ENGINEERING↗

A Managed Tokens Service for Securely Keeping and Distributing Grid Tokens

Fermilab is transitioning authentication and authorization for grid operations to using bearer tokens based on the WLCG Common JWT (JSON Web Token) Profile. One of the functionalities that Fermilab experimenters rely on is the ability to automate batch job submission, which in turn depends on the ability to securely refresh and distribute the necessary credentials to experiment job submit points. Thus, with the transition to using tokens for grid operations, we needed to create a service that would obtain, refresh, and distribute tokens for experimenters’ use. This service would avoid the need for experimenters to be experts in obtaining their own tokens and would better protect the most sensitive long-lived credentials. Further, the service needed to be widely scalable, as we are currently keeping credentials active for approximately 15 experiments, each with 1-3 different credentials, and distributing those credentials to 2-20 submit points per experiment, with those numbers steadily increasing. To address these issues, we created and deployed a Managed Tokens service. The service is written in Go, taking advantage of that language’s native concurrency primitives to easily be able to scale operations as we onboard experiments. The service uses as its first credentials a set of kerberos keytabs, stored on the same secure machine that the Managed Tokens service runs on. These kerberos credentials allow the service to use htgettoken via condor_vault_storer to store vault tokens in the HTCondor credential managers (credds) that run on the batch system scheduler machines (HTCondor schedds); as well as downloading a local, shorter-lived copy of the vault token. The kerberos credentials are then also used to distribute copies of the locally-stored vault tokens to experiment submit points. When experimenters schedule jobs to be submitted, these distributed vault tokens are used to access a Hashicorp Vault instance (run separately from the Managed Tokens service), and previously-stored refresh tokens there are used to obtain the bearer token that is submitted with the job. We will discuss here the design of the Managed Tokens service, including elaborating on certain choices we made with regards to concurrent operations, configuration, monitoring, and deployment.

Bhat, Shreyas↗

Finding of adverse effect and proposed mitigation for the removal of three primary resources and twenty-four accessory resources within the mercury historic district, area 23, nevada national security site, nye county, nevada

The U.S. Department of Energy (DOE), National Nuclear Security Administration Nevada Field Office (NNSA/NFO) proposes the removal of three primary resources and 24 accessory resources in Mercury on the Nevada National Security Site (NNSS) in Nye County, Nevada. The majority of the resources are concrete pads that have previously been recorded as either primary resources or accessory resources thereof within the Mercury Historic District (MHD). They represent the former locations of environmental support program buildings including a greenhouse (MHD Resource C312), warehouses (Resource C293), offices (Resource C314), dormitories (Resource C298), and two of unknown purpose (Resource C292). The other resources include a buried storage tank and sidewalks.

54 ENVIRONMENTAL SCIENCES↗

Identification and evaluation for the mercury solar photovoltaic array and battery energy storage system, area 23, nevada national security site, nye county, nevada

The U.S. Department of Energy (DOE), in conjunction with the National Nuclear Security Administration Nevada Field Office (NNSA/NFO), proposes to construct a solar photovoltaic (PV) energy generation array and an associated Battery Energy Storage System (BESS) in the town of Mercury at the Nevada National Security Site (NNSS) in Nye County, Nevada. The purposes of the development of this facility are to support long-term efforts to modernize Mercury and to provide energy-resilient infrastructure and climate adaptation needs.

25 ENERGY STORAGE↗

A Real-Time Testbed for Smart Inverter Cyber Security Studies

Distributed energy resources (DER) have become a popular solution to modern-day issues surrounding the efficiency and reliability of power generation, as well as climate change concerns. Energy centers are shifting towards incorporating smart inverters with embedded functionalities such as high voltage ride through (HVRT), low voltage ride through (LVRT), active and reactive power compensation. However, the integration of smart inverters leave DER systems highly vulnerable to cybersecurity threats. The distributed network protocol 3 (DNP3) is a common method of communication between grid-tied hardware. Despite its popularity, the level of security leaves all hardware connected to the grid at risk of severe cyber-attacks. Thus, it is important to study any potential cybersecurity threats towards grid-tied smart inverters to mitigate cybersecurity vulnerabilities and refine existing cyber-security protections. This report describes the proposed testbed design to study cybersecurity threats to smart inverters. The testbed utilizes a real-time simulation case in RSCAD that includes a grid-tied wind turbine (WT) topology featuring two back-to-back two-level voltage source converters (BTB,2L-VSCs) and a permanent magnet synchronous machine (PMSM). The simulated case runs within the NovaCor real time digital simulator (RTDS). This report focuses on the design and implementation of a single module of the GTNETx2 card as a distributed network protocol and the configuration of an IEEE 1518 DNP database file that includes input and output variables mapped to different connection points in the grid that transmit and receive discrete, analog, and binary signals on command. This allows realistic emulation of the communication between the smart inverter and the grid for cybersecurity studies.

97 MATHEMATICS AND COMPUTING↗

Use of Radiofrequency Tamper Indicating Devices (RFTID) to Enhance Remotely Monitoring the Security of Advanced and Small Modular Reactors (A/SMRs)

A/SMRs will likely be deployed in remote locations that are difficult to access, thereby requiring limited on-site staff. • Vendors are considering remote monitoring as a solution to enhance nuclear security. RFTIDs are a candidate technology for maintaining nuclear security of A/SMRs but need to be evaluated for feasibility and implementation into the wider physical protection system.

O'Dowd, Kevin [Savannah River National Laboratory ↗

Shielding the Quantum Realm: Technical Considerations for Maintaining a Stable and Secure Radio Frequency Environment for Quantum Research

Advancements in quantum technology, which include quantum computing, quantum sensing, quantum communications, and associated research, continue to revolutionize various fields of study by solving challenging problems deemed too difficult or more efficient than those used for classical computers. However, as these systems become ever so complex, it is critical to secure their electromagnetic operational environments and the associated impact on quantum systems and infrastructure. The goal of this synopsis is to bring attention to the susceptibility of quantum technology facilities to potential issues related to the radio frequency (RF) environment within the broader electromagnetic context. A framework is proposed for identifying, mitigating, monitoring, and auditing these often complex operational environments. By establishing best practices in the consideration and evaluation of these criteria, one can enhance the operational integrity, resilience, and security of quantum technology systems and facilities, thereby supporting their continued development and application in research and industry.

42 ENGINEERING↗

Electric Grid Security (EGS) FY24 Annual Report

Sandia’s Electric Grid Security program advances a national vision of a secure, resilient, and affordable electric system for all users. Our achievements reflect a strategic approach combining technology development; modeling, simulation, and data analytics; and partnered demonstrations and outreach to further the adoption of advanced grid and storage technologies. Our FY24 efforts leverage the strengths of our partnerships—spanning Sandia’s core science and technology competencies as well as external technology leaders—to develop the solutions today which enable the grid of tomorrow. Key accomplishments in this report that support our strategy span our technical program areas and include: • The advancement of energy storage technologies, including creation of a national Long Duration Energy Storage Consortium; • Applications of artificial intelligence and machine learning to enhanced grid operations and planning; • Development of solid-state power conversion technologies and a new medium-voltage research lab; • New technologies to assess wildfire vulnerabilities and mitigate potential impacts; • Advanced applications of new cybersecurity technologies with industry partners; • Contributions to understanding the impacts of electromagnetic pulses and geomagnetic disturbances on grid components; and • Digital twin development for hybrid microgrids with multiple generators, storage, and loads.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Mitigation for the Demolition of Dormitory Buildings 12-32, 12-34, 12-35, and 12-37 in the Area 12 Camp Historic District, Nevada National Security Site, Nye County, Nevada

The purpose of this letter report is to document the mitigation of adverse effects of a proposed undertaking in compliance with the stipulations in the Programmatic Agreement DE-GM58-22NA25554 Among the U.S. Department of Energy and the Nevada State Historic Preservation Officer and the Advisory Council on Historic Preservation Concerning the Protection of Historic Properties on the Nevada National Security Site, Nye County, Nevada, hereafter referred to as the NNSS PA. The proposed undertaking would demolish Buildings 12-32 (State Historic Preservation Office [SHPO] Resource No. B18291), 12-34 (SHPO Resource No. B18292), 12-35 (SHPO Resource No. B18293), and 12-37 (SHPO Resource No. B18294) in the Area 12 Camp Historic District (SHPO Resource No. D372) on the Nevada National Security Site (NNSS). The Area 12 Camp Historic District has been determined eligible for listing in the National Register of Historic Places (NRHP) under Criteria A and C (Reed 2021; Reno et al. 2021).

54 ENVIRONMENTAL SCIENCES↗

Wind Supply Chain Security: Hardware Enumeration and Analysis

This project, undertaken by Idaho National Laboratory (INL) for the Department of Energy (DOE) Wind Energy Technologies Office (WETO), focused on the enumeration and analysis of six key devices important to wind technologies. The devices analyzed included Beckhoff Bus Terminal Controllers (BK1120 and BC9000), a Beckhoff Economy Built-in Panel PC (CP6231), an N-Tron Managed Industrial Ethernet Switch (711FX3), a Bachmann M1 Gateway, and a Bachmann Smart Power Plant Controller. Device selection was driven by availability and budget constraints, with several components sourced from existing wind farms and others procured through a co-agreement with another WETO-funded project. The project's primary objective was to create a hardware bill of materials (HBOM) for each device, identifying and documenting all components to assess potential security and supply chain risks. A detailed analysis revealed over 750 unique components across the six devices, with 80% successfully identified and accompanied by datasheets. Notably, Texas Instruments emerged as the leading supplier, providing over 16% of the components, followed by ON Semiconductor at 11.3%, Analog Devices at 5.3%, and Renesas Electronics Corp at 4.1%. Other notable vendors included Toshiba Corporation, iC-Haus Corporation, Atmel, Vishay, and STMicroelectronics. The enumeration process involved thorough documentation of each component, including its designation, quantity, identifiers, pin package, description, vendor, model, and country of origin. This process provided valuable insights into the complexity and diversity of the electronic systems within these wind devices. It also highlighted the distinct separation of components between vendors, suggesting a trend of vendor-specific component usage. Key findings from the project emphasized the importance of broadening the scope of vendor analysis in future research to gain a comprehensive understanding of component distribution and commonality. The identification of vendor-specific component usage patterns offers new avenues for research and underscores the significance of continued investigation in this field. Overall, this project provides critical insights into the component composition of wind devices, aiding in the development of improved supply chain management and component sourcing strategies. The results contribute valuable knowledge to the wind technology sector, laying the groundwork for enhanced security and resilience in wind energy systems.

17 - WIND ENERGY↗

Study of Applications of Radiological Data Fusion for Nuclear Security and Non-proliferation Applications

This report describes the radiological Scene Data Fusion (SDF) technology and the potential to apply the SDF technology to a variety of problems related to nuclear non-proliferation, radiological security, and other missions related to the national nuclear security agency and the US government, more broadly. The application space was conceived by both the authors of this report and the many scientists and stakeholders they interviewed. In order to successfully apply the SDF technology to the various applications, further research and development is often necessary and those R&D steps are also outlined herein.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Mitigation documentation for the removal of hazardous materials from the engine installation vehicle and manned control car area 25, Nevada national security site, NYE county, Nevada

The purpose of this letter report is to document the mitigation of adverse effects of a proposed undertaking that would remove hazardous materials from the Engine Installation Vehicle (EIV) in Area 25 of the Nevada National Security Site (NNNSS) in compliance with Section 106 of the National Historic Preservation Act (NHPA) and the terms of the 2024 Programmatic Agreement among the U.S. Department of Energy and the Nevada State Historic Preservation Officer and the Advisory Council on Historic Preservation Concerning the Protection of Historic Properties on the Nevada National Security Site, Nye County, Nevada, hereafter referred to as the NNSS PA. The EIV (State Historic Preservation Office [SHPO] Resource No. S3057) has been determined individually eligible for listing in the National Register of Historic Places (NRHP) under Criteria A and C and as a contributing element to the Nuclear Rocket Development Station (NRDS) Historic District, which is eligible for the NRHP under all four Significance Criteria (Reno et al. 2023; Reed 2024).

54 ENVIRONMENTAL SCIENCES↗

Nuclear Security Risks for HALEU Fuels

There is growing interest in high-assay low-enriched uranium (HALEU) for use in advanced nuclear reactors as a high-energy fuel source. The primary objectives of this report are to identify the security risks that directly result from HALEU and to identify the gaps and challenges it presents from a theft and sabotage perspective. This study focuses on HALEU security risks for the front end of the fuel cycle and includes a review of the supply chain, fuel fabrication, and transport for terrestrial reactors.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Secure State Estimation with Asynchronous Measurements for Coordinated Cyber Attack Detection in Active Distribution Systems

Coordinated cyber attacks tamper with measurement data to disrupt the situational awareness of active distribution systems. Various sensors report measurements asynchronously at different rates, which introduces challenges during state estimation. In addition, this forces cyber intruders to exert greater effort to compromise multiple communication channels and launch coordinated attacks. Therefore, multi-channel and asynchronous measurements could be harnessed to develop more secure cyber defense strategies. In this paper, a prediction-correction-based multi-rate observer is designed to exploit the value of asynchronous measurements for the detection of coordinated false data injection (FDI) attacks. First, a time-function-dependent prediction-correction strategy is proposed to adjust the sampling interval for each sensor’s measurement. Then, an observer is designed based on the trade-off between estimation error and the optimal period of the most recent sampling instant, with the convergence of estimation error with the maximum permitted sampling interval. Moreover, the conditions for exponential stability are developed using the Lyapunov–Krasovskii functional technique. Next, a coordinated FDI attack detection strategy is developed based on the dual nonlinear minimization problem. The proposed attack detection and secure state estimation strategies are tested on the IEEE 13-node system. Simulation results show that these schemes are effective in enhancing attack detection based on asynchronous measurements or compromised data.

asynchronous measurements↗