Search NASASearch

SEARCH · Search NASA

Results for “Critical Infrastructure Protection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Cybersecurity Operational Research, Experimentation, Innovation, and Integration (COREII)

The Department of Energy’s Cybersecurity, Energy Security, and Emergency Response Office (CESER) has partnered with Idaho National Laboratory (INL) and energy companies to develop COREII. This research initiative aims to align with the national cybersecurity strategy, enhance the resilience of critical energy infrastructure, facilitate efforts to improve grid-enhancing technologies (GET) and major effects from other critical and emerging technologies, and to enable discovery of innovative solutions for emerging cybersecurity challenges

99 GENERAL AND MISCELLANEOUS

Engineering Against Digital Risk in CIP Applications: Cyber-Informed Engineering Use Cases

Cyber-Informed Engineering (CIE) addresses the reality that cyber attacks on engineered systems can have consequences far beyond data loss or disruption of digital networks. When control systems are compromised, safety, reliability, and performance of the physical process itself may be threatened. This presentation discusses engineered controls of 7 categories and the CIE database of controls that provides clear examples and guidance for defining and applying engineered controls in CIE. It explains what engineered controls are, how they differ from information security measures, and how they are integrated into system design.

99 - GENERAL AND MISCELLANEOUS

Deep Cyber-Physical Situational Awareness for Energy Systems: A Secure Foundation for Next-Generation Energy Management

This document provides the final report for the CYPRES project. The purpose is (1) to highlight and summarize its major accomplishments and (2) to provide guidance on how its outcomes have informed and can inform important additional research and technology transfer. The goal of CYPRES was the research, development, and demonstration of a security-oriented next generation cyber-physical EMS for electric power systems that detects malicious and abnormal events through the fusion of cyber and physical data. To achieve this, the CYPRES project team researched, developed, and built a prototype of the solution, referred to as the CYPRES EMS. The CYPRES EMS is a proof-of-concept cyber-physical platform that demonstrates the management of the energy system, communications, security, and cyber-physical grid modeling and analytics. As part of the capabilities of the CYPRES EMS, the team designed and developed a suite of power system applications for monitoring, risk analyses, detection, and control that are inherently cyberaware. At its core, the project aimed to research, develop, and demonstrate a security-oriented next-generation cyber-physical Energy Management System (EMS) capable of detecting malicious and abnormal events through the innovative fusion of cyber and physical data. This approach represents a fundamental shift from traditional EMS, reimagining how critical infrastructure can be protected through unified cyber-aware and physics-aware secure data flow pipelines. The project’s cornerstone deliverable, the CYPRES EMS, serves as a proof-of-concept cyber-physical platform that revolutionizes the management of energy systems, communications, security, and cyber-physical grid modeling and analytics. This prototype implements a comprehensive suite of power system applications for monitoring, risk analyses, detection, and control, all designed with inherent cyber awareness. The system’s architecture extends from end-devices in the field through to control center applications, establishing a secure and resilient control framework that addresses the challenges posed by diverse devices of unknown trustworthiness connecting to modern power systems. Through this innovative approach to deep cyber-physical situational awareness, the CYPRES project not only advances the state-of-the-art in energy infrastructure protection but also establishes a new paradigm for how EMS can be designed, deployed, and operated in an increasingly complex threat landscape. The findings and developments from this project provide crucial insights for stakeholders across the energy sector, offering a blueprint for enhancing the reliability and resilience of our nation’s critical energy infrastructure in the face of evolving cyber threats.

24 POWER TRANSMISSION AND DISTRIBUTION

Developing a Robust, Interoperable GNSS Space Service Volume (SSV) for the Global Space User Community

For over two decades, researchers, space users, Global Navigation Satellite System (GNSS) service providers, and international policy makers have been working diligently to expand the space-borne use of the Global Positioning System (GPS) and, most recently, to employ the full complement of GNSS constellations to increase spacecraft navigation performance. Space-borne Positioning, Navigation, and Timing (PNT) applications employing GNSS are now ubiquitous in Low Earth Orbit (LEO). GNSS use in space is quickly expanding into the Space Service Volume (SSV), the signal environment in the volume surrounding the Earth that enables real-time PNT measurements from GNSS systems at altitudes of 3000 km and above. To support the current missions and planned future missions within the SSV, initiatives are being conducted in the United States and internationally to ensure that GNSS signals are available, robust, and yield precise navigation performance. These initiatives include the Interagency Forum for Operational Requirements (IFOR) effort in the United States, to support GPS SSV signal robustness through future design changes, and the United Nations-sponsored International Committee on GNSS (ICG), to coordinate SSV development across all international GNSS constellations and regional augmentations. The results of these efforts have already proven fruitful, enabling new missions through radically improved navigation and timing performance, ensuring quick recovery from trajectory maneuvers, improving space vehicle autonomy and making GNSS signals more resilient from potential disruptions. Missions in the SSV are operational now and have demonstrated outstanding PNT performance characteristics; much better than what was envisioned less than a decade ago. The recent launch of the first in a series of US weather satellites will employ the use of GNSS in the SSV to substantially improve weather prediction and public-safety situational awareness of fast moving events, including hurricanes, flash floods, severe storms, tornados and wildfires. Thus, the benefits of the GNSS expansion and use into the SSV are tremendous, resulting in orders of magnitude return in investment to national governments and extraordinary societal benefits, including lives saved and critical infrastructure and property protected. However, this outstanding success is tempered by dual challenges: that for GPS, the current SSV specifications do not adequately protect SSV future use; and that for GNSS, the capabilities that are currently available are not protected in the future by specifications.

Bauer, Frank H.

Developing a Robust, Interoperable GNSS Space Service Volume (SSV) for the Global Space User Community

For over two decades, researchers, space users, Global Navigation Satellite System (GNSS) service providers, and international policy makers have been working diligently to expand the space-borne use of the Global Positioning System (GPS) and, most recently, to employ the full complement of GNSS constellations to increase spacecraft navigation performance. Space-borne Positioning, Navigation, and Timing (PNT) applications employing GNSS are now ubiquitous in Low Earth Orbit (LEO). GNSS use in space is quickly expanding into the Space Service Volume (SSV), the signal environment in the volume surrounding the Earth that enables real-time PNT measurements from GNSS systems at altitudes of 3000 km and above. To support the current missions and planned future missions within the SSV, initiatives are being conducted in the United States and internationally to ensure that GNSS signals are available, robust, and yield precise navigation performance. These initiatives include the Interagency Forum for Operational Requirements (IFOR) effort in the United States, to support GPS SSV signal robustness through future design changes, and the United Nations-sponsored International Committee on GNSS (ICG), to coordinate SSV development across all international GNSS constellations and regional augmentations. The results of these efforts have already proven fruitful, enabling new missions through radically improved navigation and timing performance, ensuring quick recovery from trajectory maneuvers, improving space vehicle autonomy and making GNSS signals more resilient from potential disruptions. Missions in the SSV are operational now and have demonstrated outstanding PNT performance characteristics; much better than what was envisioned less than a decade ago. The recent launch of the first in a series of US weather satellites will employ the use of GNSS in the SSV to substantially improve weather prediction and public-safety situational awareness of fast moving events, including hurricanes, flash floods, severe storms, tornados and wildfires. Thus, the benefits of the GNSS expansion and use into the SSV are tremendous, resulting in orders of magnitude return in investment to national governments and extraordinary societal benefits, including lives saved and critical infrastructure and property protected. However, this outstanding success is tempered by dual challenges: that for GPS, the current SSV specifications do not adequately protect SSV future use; and that for GNSS, the capabilities that are currently available are not protected in the future by specifications.

Bauer, Frank H.

Comparison of Daily, Monthly (Lunar), Yearly, Decadal, Quarter-Century, Half-Century, and Centurial Shoreline Change Rates at the Kennedy Space Center, Cape Canaveral, Florida, USA

The Kennedy Space Center (KSC) is North America’s premier spaceport and provides crucial access to space for both government and private entities. The National Aeronautics and Space Administration (NASA) facilities are clustered along a 12 km active shoreline at Cape Canaveral, Florida, USA, with the entire NASA and US Space Force station (SF) shoreline stretching over 32 km (Figure 1). Several Launch Complexes (LC’s) including the modern heavy lift facilities are only a few tens of meters from the active shoreline and are imminently threatened by continued sea level rise and ongoing coastal erosion. The space center was built on the northern part of Cape Canaveral. Images collected in 1943 show that Apollo Heavy Lift Launch Complexes were built in swales on ground that was at or below sea level with Launch Complex 39B constructed on a paleo inlet (Figures 2 and 3). Today the Heavy Lift Launch Complexes are ~220 meters from the shoreline with the area between the complexes retreating at the highest rates along the cape (Figure 4). To better understand the intersection of environmental concerns, limited budgets for shoreline protection, and sheltering critical infrastructure; NASA, The University of Florida, United States Geological Survey (USGS), National Park Service (NPS) and contractors have and continue to conduct numerous studies to characterize and understand the shoreline evolution and rates of change at KSC. This project aims to better understand and visualize the temporal and spatial variability of change along the NASA shoreline beyond a simple point to point solution.

Richard MacKenzie III

Handling Emergency Management in [an] Object Oriented Modeling Environment

It has been understood that protection of a nation from extreme disasters is a challenging task. Impacts of extreme disasters on a nation's critical infrastructures, economy and society could be devastating. A protection plan itself would not be sufficient when a disaster strikes. Hence, there is a need for a holistic approach to establish more resilient infrastructures to withstand extreme disasters. A resilient infrastructure can be defined as a system or facility that is able to withstand damage, but if affected, can be readily and cost-effectively restored. The key issue to establish resilient infrastructures is to incorporate existing protection plans with comprehensive preparedness actions to respond, recover and restore as quickly as possible, and to minimize extreme disaster impacts. Although national organizations will respond to a disaster, extreme disasters need to be handled mostly by local emergency management departments. Since emergency management departments have to deal with complex systems, they have to have a manageable plan and efficient organizational structures to coordinate all these systems. A strong organizational structure is the key in responding fast before and during disasters, and recovering quickly after disasters. In this study, the entire emergency management is viewed as an enterprise and modelled through enterprise management approach. Managing an enterprise or a large complex system is a very challenging task. It is critical for an enterprise to respond to challenges in a timely manner with quick decision making. This study addresses the problem of handling emergency management at regional level in an object oriented modelling environment developed by use of TopEase software. Emergency Operation Plan of the City of Hampton, Virginia, has been incorporated into TopEase for analysis. The methodology used in this study has been supported by a case study on critical infrastructure resiliency in Hampton Roads.

Tokgoz, Berna Eren

ARC-SAFE: Accelerated Response semiconducting Contactors and Surge Attenuation For DC Electrical systems (Final Scientific/Technical Report)

The landscape of power transmission and distribution is quickly evolving as more power conversion is done through power electronics and transmitted or distributed at medium voltage direct current (MVDC). As power electronics tend to store less energy and be less resilient to faults than conventional power transformers, a reliable and fast protection against faults is critical to protect power electronics (PE) based infrastructure, especially for medium- and high-voltage applications. This motivates the development of PE based protection circuits to replace slower contemporary electromechanical breakers. In this project a novel PE based MVDC circuit breaker is developed; the new design is comprised of 1) a normally-on leg made of commercially-available, cascaded SiC junction field effect transistors (JFETs) with a passive balancing network, and 2) a normally-off leg based on an optically-triggered gallium nitride (GaN) photoconductive semiconductor switch (PCSS). The normally-off leg was designed to be quickly turned on, to divert current to an auxiliary dissipative circuit, as the normally-on leg is turned off. This approach, using solid-state devices, was selected for a high-performance, fast-switching operation for the DC circuit breaker as compared to approaches that use slower mechanical switches. To be practical, the circuit breaker must have low conduction loss (low Ron) in the normally-on leg and fast coordinated triggering of the normally-off leg to avoid damage from inductive flyback, which could be considerable for long lengths of cable.

24 POWER TRANSMISSION AND DISTRIBUTION

Applying a Space-Based Security Recovery Scheme for Critical Homeland Security Cyberinfrastructure Utilizing the NASA Tracking and Data Relay (TDRS) Based Space Network

Protection of the national infrastructure is a high priority for cybersecurity of the homeland. Critical infrastructure such as the national power grid, commercial financial networks, and communications networks have been successfully invaded and re-invaded from foreign and domestic attackers. The ability to re-establish authentication and confidentiality of the network participants via secure channels that have not been compromised would be an important countermeasure to compromise of our critical network infrastructure. This paper describes a concept of operations by which the NASA Tracking and Data Relay (TDRS) constellation of spacecraft in conjunction with the White Sands Complex (WSC) Ground Station host a security recovery system for re-establishing secure network communications in the event of a national or regional cyberattack. Users would perform security and network restoral functions via a Broadcast Satellite Service (BSS) from the TDRS constellation. The BSS enrollment only requires that each network location have a receive antenna and satellite receiver. This would be no more complex than setting up a DIRECTTV-like receiver at each network location with separate network connectivity. A GEO BSS would allow a mass re-enrollment of network nodes (up to nationwide) simultaneously depending upon downlink characteristics. This paper details the spectrum requirements, link budget, notional assets and communications requirements for the scheme. It describes the architecture of such a system and the manner in which it leverages off of the existing secure infrastructure which is already in place and managed by the NASAGSFC Space Network Project.

Cybersecurity

Performance Analysis and Simulaion of the Hydraulic Scram System in TREAT Reactor

The Transient Reactor Test Facility (TREAT) at Idaho National Laboratory (INL) serves a vital role in nuclear fuel safety research, enabling transient experiments that simulate reactivity excursions and accident scenarios. Central to these operations is the transient control rod drive system (TCRDS), which drives rapid motion of the transient control rods such that TREAT can simulate rapid power changes typical of reactor accidents. The reliability and performance of this system are critical for protecting both fuel specimens and reactor infrastructure. This study presents the initial phase of a two-year investigation into the dynamics and reliability of the TREAT hydraulic TCRDS. Conducted in collaboration with INL, the research employs a combined computational and experimental approach to analyze the system's response time, pressure transients, and potential failure modes. Emphasis is placed on understanding how fluid characteristics influence the TCRDS’s ability to achieve both rapid power changes and mechanical stability. The TRDS and the skid that powers it will be analyzed throughout this investigation. Computational modeling using computational fluid dynamics (CFD) will simulate the hydraulic response under varying conditions. In parallel, experimental testing planned at INL will validate these models and capture key performance metrics. This paper outlines the system design, analytical framework, and modeling strategies that form the foundation for later testing. Ultimately, this work aims to support improvements to the TCRDS’s design and reliability, contributing to the broader goal of enhancing nuclear fuel safety and sustaining TREAT’s mission as a premier nuclear fuel test facility.

21 - SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLAN

Relevant Environment Additive Construction Technology (REACT)

Project Overview This project is focused on developing technologies that enable construction of a Lunar Safe Haven type structure on the moon. A full scale architectural and structural design will be completed based on lunar conditions and Artemis mission needs. A scaled structure will be 3D printed in simulated lunar environments. Technical Approach Polymer bound regolith composite materials will be developed and characterized for lunar additive construction applications. A full scale architectural and structural design will be completed based on the latest scientific data on lunar environments including radiation, meteoroids, thermal conditions, reduced gravity, and moonquakes. The project will culminate with a demonstration of additive construction in simulated lunar vacuum, thermal, regolith, and UV conditions. Results/Summary Preliminary material specifications have been developed and an initial batch has been produced. A first iteration of the architectural and structural designs have been completed. Hardware for 3D printing in simulated lunar conditions is under development. Contributing Partners AI Space Factory – Winner of the NASA 3D Printed Habitat Centennial Challenge Infusion and Transition Plan On-surface construction of infrastructure is a critical capability of the sustainable phase of the Artemis Program and eventual sustainable human presence on Mars. It provides the ability to create protective shelters on-demand using local resources. The 3D-printing technology will achieve TRL 6 in 1g/vacuum tests with thermal/UV exposure in this project. CLPS missions will be pursued for infusion to demonstrate vertical construction with lunar regolith and conditions. Modeling and simulation will be used to define the pilot-scale shelter construction mission for long-term exposure on the lunar surface to validate the system for Artemis operational deployment.

Lunar Construction

Layered virus protection for the operations and administrative messaging system

NASA's Deep Space Network (DSN) is critical in supporting the wide variety of operating and plannedunmanned flight projects. For day-to-day operations it relies on email communication between the three Deep Space Communication Complexes (Canberra, Goldstone, Madrid) and NASA's Jet Propulsion Laboratory. The Operations & Administrative Messaging system, based on the Microsoft Windows NTand Exchange platform, provides the infrastructure that is required for reliable, mission-critical messaging. The reliability of this system, however, is threatened by the proliferation of email viruses that continue to spread at alarming rates. A layered approach to email security has been implemented across the DSN to protect against this threat.

IT security antivirus

Resilient Energy Delivery and Control Systems (REDCS) (Final Technical Report)

US critical infrastructure is increasingly the target of cyberattacks, where disturbances could cause considerable damage and disruption. To help provide a new layer of cyber-physical protection for one key energy delivery system, natural gas pipelines, GE Vernova Advanced Research along with partners Florida State University and Intel Corporation created an innovative technology called "Resilient Energy Delivery and Control Systems" (REDCS). This cybersecurity package helps detect anomalies caused by cyberattacks, isolate the subsystem being impacted by the attack, and provide functions that can allow for resiliency – giving better situational awareness to the operators and cybersecurity specialists or in the future perform closed loop control for continued operation while compromised.

03 NATURAL GAS

FiberFlex: Real-time FPGA-based Intelligent and Distributed Fiber Sensor System for Pedestrian Recognition

In recent years, security monitoring of public places and critical infrastructure has heavily relied on the widespread use of cameras, raising concerns about personal privacy violations. To balance the need for effective security monitoring with the protection of personal privacy, we explore the potential of optical fiber sensors for this application. This article proposes FiberFlex, an intelligent and distributed fiber sensor system. Ultizing Field Programmable Gate Arrays (FPGA) high-level synthesis (HLS) acceleration, FiberFlex offers real-time pedestrian detection by co-designing the entire pipeline of optical signal acquisition, processing, and recognition networks based on the principles of optical fiber sensing. As a promising alternative to traditional camera-based monitoring systems, FiberFlex achieves pedestrian detection by analyzing the vibration patterns caused by pedestrian footsteps, enabling security monitoring while preserving individual privacy. FiberFlex comprises three modules: First , fiber-optic sensing system: A fiber-optic distributed acoustic sensing (DAS) system is built and used to measure the ground vibration waves generated by people walking. Second , algorithms: We first collect the training data by measuring the ground vibration waves, label the data, and use the data to train the neural network models to perform pedestrian recognition. Third , hardware accelerators: We use HLS tools to design hardware modules on FPGA for data collection and pre-processing and integrate them with the downstream neural network accelerators to perform in-line real-time pedestrian detection. The final detection results are sent back from FPGA to the host CPU. We implement our system FiberFlex with the in-house built DAS system and AMD/Xilinx Kintex7 FPGA KC705 board and verify the whole system using the real-world collected data. We conduct recognition tests on five test subjects of varying ages, heights, and weights in a fixed sensing area. Each subject experienced 20 real-time recognition tests using their daily walking habits, and the subjects were given adequate rest between tests. After 100 tests on five test subjects, the overall real-time recognition accuracy exceeded \(88.0\%\) . The whole system uses 55 W of power, 33 W in the optical DAS system and 22 W in the FPGA. Relying on its end-to-end interdisciplinary design, FiberFlex seamlessly combines fiber-optic sensors with FPGA accelerators to enable low-power real-time security monitoring without compromising privacy, making it a valuable addition to the existing security monitoring network. According to FiberFlex, more valuable research can be conducted in the future, such as fall monitoring for the elderly, migration of identification networks between different application scenarios, and improvement of anti-interference performance in more complex environments. In future perception networks, where the “eyes” are not feasible, let’s use fiber optic touch instead.

Distributed

GridSTIX

SF-25-112 Grid-STIX is a comprehensive extension of the STIX (Structured Threat Information Expression) 2.1 ontology specifically designed for electrical grid cybersecurity applications. This ontology provides a standardized, machine-readable framework for modeling grid assets, operational technology devices, threats, vulnerabilities, supply chain risks, and security relationships in electrical power systems. ## Key Features - **Comprehensive Grid Coverage**: Physical assets, OT devices, grid components, sensors, and energy storage systems - **Zero Trust Architecture**: Policy decision points, enforcement points, trust brokers, and continuous monitoring - **AMI Infrastructure**: Advanced metering networks, head-end systems, mesh gateways, and MDM systems - **Advanced Security Modeling**: Attack patterns, vulnerabilities, mitigations, and supply chain risks - **Critical Grid Relationships**: Power flow, protection, control, and synchronization relationships - **Supply Chain Security**: Supplier modeling, country of origin tracking, and risk assessment - **Protocol Support**: DNP3, Modbus, IEC 61850, IEC 60870-5-104, OPC-UA, and IEEE standards - **Python Code Generation**: Automated STIX-compliant Python class generation from ontologies - **Interactive Visualization**: Enhanced HTML network graphs with grid-specific categorization - **STIX 2.1 Compliance**: Full compatibility with STIX threat intelligence ecosystem

Blakely, Benjamin [Argonne National Laboratory (AN

SDN-Based Dynamic Cybersecurity Framework of IEC-61850 Communications in Smart Grid

In recent years, critical infrastructure and power grids have experienced a series of cyber-attacks, leading to temporary, widespread blackouts of considerable magnitude. Since most substations are unmanned and have limited physical security protection, cyber breaches into power grid substations present a risk. Nowadays, the susceptibility of SDN architecture to cyber-attacks has exhibited a notable increase in recent years, as indicated by research findings. This suggests a growing concern regarding the potential for cybersecurity breaches within the SDN framework. In this paper, we propose a hybrid intrusion detection system (IDS)-integrated SDN architecture for detecting and preventing the injection of malicious IEC 61850-based generic object-oriented system event (GOOSE) messages in a digital substation. Additionally, this program locates the fault’s location and, as a form of mitigation, disables a certain port. Furthermore, implementation examples are demonstrated and verified using a hardware-in-the-loop (HIL) testbed that mimics the functioning of a digital substation.

Liu, Chen-Ching [Virginia Tech] (ORCID:00000002894

Data Management for Digital Twin Implementation: Enhancing Existing SCADA Architecture for INL's CITRC Test Distribution System

The United States power grid will continue to experience stress from aging infrastructure, extreme weather, and increasing loads. In order to strengthen resiliency, researchers need to run tests and simulations that model real-life infrastructure. Idaho National Laboratory (INL) is creating a digital twin of its Critical Infrastructure Test Range Complex (CITRC). CITRC is an at-scale grid testbed which can be configured in utility-realistic distribution scenarios for a variety of tests, such as advanced grid protection and control. A digital twin of this infrastructure would support in-depth tests/simulations without risking physical consequences, before trialing devices under test at-scale. This project focuses on the data acquisition part of constructing a digital twin. It investigates the Supervisory Data Acquisition and Control (SCADA) system of CITRC and explores ways to utilize this system for the twin. Future “ideal” at-scale implementations such as upgraded equipment, modern communication protocols, and automation applications are also explored.

24 - POWER TRANSMISSION AND DISTRIBUTION