Search NASASearch

SEARCH · Search NASA

Results for “computer information security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Cyber-Informed Engineering (CIE) Integration into Model- Based Systems Engineering (MBSE)

Engineering design in the field of industrial engineering, such as designing automated factories or warehouses, is critical for the effective operation of facilities. Any design flaws introduced early can result in significant capital expenses to correct. However, early-stage engineering design is inherently complex. The systems are not yet built, requiring designers to integrate various aspects, including digital engineering and cybersecurity, to support virtual representations throughout the design process. In this study, we propose an approach to integrate Cyber-Informed Engineering (CIE) principles into model-based systems engineering (MBSE). This approach facilitates the development of a digital thread for engineering systems, ensuring secure digital artifacts in the design of industrial engineering systems.

42 - ENGINEERING

Cyber-Informed Engineering (CIE) Benefits Quantification: Recommendations for Consideration

Cyber-Informed Engineering (CIE) integrates engineering principles into the design, development, and operation of cyber-physical systems (CPS) to mitigate or eliminate the impact of cyber-enabled attacks. In July 2024, Idaho National Laboratory (INL) engaged MITRE researchers to investigate methods for systematically measuring the benefits of CIE implementation. This included evaluating the success and outcomes of CIE, identifying and quantifying the value of early adoption, and determining the business justification for its implementation, especially in existing infrastructure. MITRE reviewed existing methods in engineering and cybersecurity to understand how organizations prioritize security investments, considering their strengths, weaknesses, and relevance to CIE stakeholders. Based on this analysis, MITRE proposed potential approaches for quantifying CIE benefits and provided recommendations for INL's consideration.

42 ENGINEERING

ARPA-E Grid Optimization (GO) Competition Challenge 1

The ARPA-E Grid Optimization (GO) Competition Challenge 1, from 2018 to 2019, focused on the basic Security Constrained AC Optimal Power Flow problem (SCOPF) for a single time period. The Challenge utilized sets of unique datasets generated by the ARPA-E GRID DATA program. Each dataset consisted of a collection of power system network models of different sizes with associated operating scenarios (snapshots in time defining instantaneous power demand, renewable generation, generator and line availability, etc.). The datasets were of two types: Real-Time, which included starting-point information, and Online, which did not. Week-Ahead data is also provided for some cases but was not used in the Competition. Although most datasets were synthetic and generated by GRIDDATA, a few came from industry and were only used in the Final Event. All synthetic Input Data and Team Results for the GO Competition Challenge 1 for the Sandbox, Trial Events 1 to 3, and the Final Event along with problem, format, scoring and rules descriptions are available here. Data for industry scenarios will not be made public. Challenge 1, a minimization problem, required two computational steps. Solver 1 or Code 1 solved the base SCOPF problem under a strict wall clock time limit, as would be the case in industry, and reported the base case operating point as output, which was used to compute the Objective Function value that was used as the scenario score. The feasibility of the solution was provided by the Solver 2 or Code 2, which solves the power flow problem for all contingencies based on the results from Solver 1. This is not normally done in industry, so the time limits were relaxed. In fact, there were no time limits for Trial Event 1. This proved to be a mistake, with some codes running for more than 90 hours, and a time limit of 2 seconds per contingency was imposed for all other events. Entrants were free to use their own Solver 2 or use an open-source version provided by the Competition. Containers, such as Docker, were considered to improve the portability of codes, but none that could reliably support a multi-node parallel computing environment, e.g., MPI, could be found. For more information on the competition and challenge see the "GO Competition Challenge 1 Information" and "GO Competition Challenge 1 Additional Information" resources below.

ACOPF

Investigating Material Properties of Subsurface Rock Formations Modified by Engineering Mineral Precipitation (Final Scientific and Technical Report)

Montana State University’s (MSU) Energy Research Institute (ERI), in collaboration with the Center for Biofilm Engineering (CBE) and the Department of Civil Engineering (CE), has conducted a long‐term research program aimed at developing a novel cementing agent to address wellbore integrity and reduce the unwanted upward migration of fluids and greenhouse gases from the subsurface. The primary technology developed through this research program is known as ureolysis‐induced calcite precipitation (UICP), which harnesses bio‐chemical processes to precipitate calcium carbonate (CaCO 3 ). The same general process can also be called microbially-induced calcium carbonate precipitation (MICP) when microbes provide the process-catalyzing urease enzyme. Both terms are used in this report. Results have conclusively demonstrated that, if properly controlled, UICP can successfully seal fractures, high permeability zones, and compromised cement in the vicinity of wellbores and in nearby caprock. This technology has been successfully deployed to mitigate annular leakage in two test wells and over sixty commercial wells with a 100% success rate. This success in downhole deployment generates consideration of other subsurface applications where UICP could provide benefit to the energy sector, such as shale property modification for unconventional oil and gas recovery. The focus of this research project was to investigate fundamental material and mechanical properties of select shale cores and analyze how these properties change due to engineered mineral precipitation with the intent to control these properties to achieve a range of engineering objectives. Ultimately, the project aim was to identify valuable new areas where application of UICP might contribute to national energy security and environmental protection. The research workplan coupled UICP treatment of core samples, nuclear magnetic resonance (NMR) characterization, and mechanical strength testing at MSU with advanced X‐Ray micro-computed tomography (μCT) imaging and numerical modeling performed by collaborators at two national laboratories, the National Energy Technology Laboratory (NETL) and Lawrence Berkeley National Laboratory (LBNL). Experimental results are useful to inform geo-mechanical models which could be applied to predict mineralized rock formation behavior at field scale. Our findings suggest that NMR and μCT methods to detect and quantify biomineral formation in shale fractures are complementary and consistent with each other. Either could be used to estimate the volume of new mineral formed by UICP in shale fractures. The use of surfactants and guar gum to enhance biomineral precipitation in shale fractures merits further research. UICP can, under some conditions, increase the tensile strength of sealed shale fractures beyond that of the intact shale. These findings demonstrate that continued research in this area may be valuable to understanding and improving shale resource recovery techniques.

58 GEOSCIENCES

Enhancing Cloud Cybersecurity: Prescriptive Controls for Operational Technology

This whitepaper provides strategic insights and recommendations into security cloud-based solutions for electric utilities, encompassing operational technology (OT), virtual power plants (VPP), distributed energy resources (DERs), applications, networks, and data storage as they transition to and leverage cloud infrastructure through managed service providers (MSPs) and cloud service providers (CSPs). Principles derived from established frameworks serve as a foundation for best practices across cybersecurity projects and remove the constraints of settling on a single framework. For organizations that prefer not to integrate a specific framework altogether, elements of the proposed approach could be adopted or tailored to best fit defined requirements and expected functionalities. The Cirrus assessment, a utility cloud feasibility tool, and the roadmap it provides serve as a precursor to this paper, which seeks to be a valuable resource for defining next steps following cloud technology integration feasibility appraisal. With its comprehensive approach to adoption, the Cirrus framework offers strategic guidance on responsibly preparing for or deploying a utility cloud solution. The previously published whitepaper, “Use Case-Informed Framework for Utility Cloud Migration,” details the guiding strategy, research, and deployment of cloud solutions within electric and interconnected grid systems. Before implementing the controls suggested in this document, it is recommended that stakeholders complete Cirrus's cloud integration assessment and pair the results with their unique cybersecurity controls to form a comprehensive cloud-based utility cybersecurity plan. The Cirrus outcome will consider a series of future architectures for the grid before and after the energy transition and evaluate the arguments for and against cloud applications for each electric and interconnected grid layer. This document is a companion to the original whitepaper, "Use Case-Informed Framework for Utility Cloud Migration" to further identify and recommend security controls based on Cirrus’s cloud integration assessment output. The following whitepaper outlines the cybersecurity controls that secure cloud-service models pertinent to the electric sector using the predefined categories identify, protect, detect, and respond and recover. The objective is to outline prescriptive security controls based on the type of architecture and data stored in the cloud. The focus includes dissecting the shared responsibility model and elucidating what on-premises Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) entail. A pivotal consideration in this context is allocating responsibility for foundational cybersecurity aspects—having used Cirrus for the cloud integration assessment. The ensuing controls detailed herein also represent a checklist of controls necessary for a secure cloud transition, equipping utilities with the knowledge to navigate this digital transformation with confidence and strategic foresight in a safe and responsible manner.

42 ENGINEERING

Resonant metasurface‐enabled quantum light sources for single‐photon emission and entangled photon‐pair generation

Light encodes information in multiple degrees of freedom (e.g., frequency, amplitude, and phase), enabling high‐speed, high‐bandwidth communication through fiber optics. Unlike classical light, quantum light (single or entangled photons) can transmit quantum states over long distances without loss of coherence, thereby coherently interconnecting quantum nodes for distributed quantum entanglement. Quantum light sources are critical for developing scalable quantum networks aimed at distributed quantum computing, quantum teleportation, and secure quantum communications. However, existing quantum light sources suffer from limited integrability, insufficient spectral and spatial tunability, and inefficiencies in achieving mass‐produced, deterministic, on‐demand quantum light generation. These limitations significantly hinder progress toward direct, on‐chip integration with quantum processing units and detectors – an essential step toward scalable quantum networks. Resonant metasurfaces that leverage photonic modes – such as Mie resonances, guided‐mode resonances, or symmetry‐protected bound states in the continuum – offer strong spatial and temporal confinement of electromagnetic fields, characterized by high quality factors and small mode volumes. These metasurfaces greatly enhance linear and nonlinear light‐matter interactions, making them ideal for efficient on‐chip quantum light generation and manipulation. Here, we describe recent advances in nanoscale quantum light sources and quantum photonic state manipulation enabled by resonant metasurfaces. We also provide an outlook on next‐generation miniaturized quantum light sources achievable through materials innovations in quantum emitters, the co‐design of resonant metasurfaces, and ultimately, the heterogeneous integration of emerging layered van der Waals materials with resonant metasurfaces.

71 CLASSICAL AND QUANTUM MECHANICS, GENERAL PHYSIC

Pacific Northwest National Laboratory Annual Site Environmental Report for Calendar Year 2023

Pacific Northwest National Laboratory (PNNL), one of the U.S. Department of Energy (DOE) Office of Science’s 10 national laboratories, provides innovative science and technology development in the areas of energy and the environment, fundamental and computational science, and national security. There are three DOE offices within the Richland area. Two are responsible for the Hanford Site, whereas the Pacific Northwest Site Office oversees PNNL. PNNL prepares an Annual Site Environmental Report to meet the requirements of DOE Order 231.1B, Environment, Safety and Health Reporting, and DOE Order 458.1, Radiation Protection of the Public and the Environment, thus assuring that the public is informed of any PNNL-Richland campus or PNNL-Sequim campus event that could adversely affect the health and safety of the public, site staff, or the environment. The report provides a synopsis of ongoing environmental management performance and compliance activities for operations that occur at the PNNL-Richland campus in Richland, Washington, and at the PNNL-Sequim campus near Sequim, Washington. It describes the location of and background for each facility; addresses compliance with applicable DOE, federal, state, and local regulations, and site-specific permits; documents environmental monitoring efforts and their status; presents potential radiation doses to staff and the public in the surrounding areas; and describes DOE-required data quality assurance methods used for data verification. The ASER report describes Compliance with Federal, State, and Local Laws and Regulations in 2023, Environmental Sustainability, Environmental monitoring and dose assessment, Natural and Cultural Resource Management, and Quality Assurance activities that took place during Calendar Year 2023.

40 CFR 61 Subpart H

Cyber-Informed Engineering (CIE) – Engineered Controls Database and Use

Cyber-Informed Engineering (CIE) addresses the reality that cyber-attacks on engineered systems can have consequences far beyond data loss or disruption of digital networks. When control systems are compromised, safety, reliability, and performance of the physical process itself may be threatened. This database is meant to establish clear examples and guidance for defining and applying engineered controls in CIE. It explains what engineered controls are, how they differ from information security measures, and how they are integrated into system design. The goal is to ensure that resilience is engineered into systems from the outset. Unlike cybersecurity protections that defend the digital layer, engineered controls act directly at the physical and algorithmic levels to guarantee that unacceptable consequences are prevented or limited. CIE keeps the consequences of a cyber attack from impacting the safety, reliability, and performance of engineered systems.

42 - ENGINEERING

Radsource Mr: Mixed Reality Planning Tool For Radioactive Recovery

The RadSource MR system leverages Meta Quest 3's advanced mixed reality capabilities to create a comprehensive spatial planning platform for end-of-life sealed radioactive source recovery operations. The application utilizes the Quest 3's high-resolution passthrough cameras and spatial mapping algorithms to generate accurate 3D environmental models. Core technical components include: (1) Real-time spatial measurement algorithms calculating distances, angles, slopes, and surface areas with sub-centimeter accuracy; (2) Virtual object placement system allowing users to position digital representations of recovery equipment (trailers, containment vessels, protective barriers) within the real environment; (3) Voice recording and annotation system for hands-free documentation in protective equipment; (4) 3D mesh capture and storage capabilities for post-operation analysis and regulatory documentation. (5) Procedure documentation is available for viewing in Mixed Reality, providing an innovative and convenient way to access the information during pre-visit and inspection activities. (6) Support for screen capture for the view for real world and virtual objects together to use it later for planning. The system integrates computer vision techniques for environmental understanding, spatial mathematics for precise measurements, and human-computer interaction principles optimized for hazardous environment operations. Data persistence allows teams to save and share planning sessions across multiple stakeholders while maintaining operational security requirements.

Khadka, Rajiv [Idaho National Laboratory (INL), Id

Assessment and Coordination of EVSE Cybersecurity Standards

Cybersecurity certification programs for Electric Vehicle Supply Equipment (EVSE) are fragmented due to no single certification covering all aspects of the device and additionally the existence of multiple programs and under different levels of regulation. These devices are also confronted by the intricate assembly of product software, firmware, and hardware. Devices contain both logical and physical interfaces. These multifaceted devices have vulnerabilities at many levels and interconnect with other potentially vulnerable systems including the electric vehicle, the cloud where data and payment information are stored, and the electric grid and electric grid equipment including utilities. Of the EVSE certification programs that are found, none are directly for the cybersecurity of EVSE. Many standards are for safety, specifically battery safety, some are cybersecurity standards for other types of equipment and can be modeled for EVSE. In specific, ISA/IEC 62443 is found to be significantly in line with EVSE security needs and will be used in future testing to certify EVSE and help guide the project to demonstrate where gaps exist, where strengths lie in the standard and how this can be used to lead the certification efforts in harmonizing EVSE cybersecurity standards. In addition, there are multiple efforts that are currently seeking to build EVSE standards or revise existing standards to address gaps. This effort is seeking to establish a cybersecurity program for EVSE that will inform customers and help increase the level of security across products and state EVSE procurements to achieve consistency across different jurisdictions.

33 ADVANCED PROPULSION SYSTEMS

Tailoring Microbial Fitness Through Computational Steering and CRISPRi-Driven Robustness Regulation

The widespread application of genetically modified microorganisms (GMMs) across diverse sectors underscores the pressing need for robust strategies to mitigate the risks associated with their potential uncontrolled escape. This study merges computational modeling with CRISPR interference (CRISPRi) to refine GMM metabolic robustness. Utilizing ensemble modeling, we achieved high-throughput in silico screening for enzymatic targets susceptible to expression alterations. Translating these insights, we developed functional CRISPRi, boosting fitness control via multiplexed gene knockdown. Our method, enhanced by an insulator-improved gRNA structure and an off-switch circuit controlling a compact Cas12m, resulted in rationally engineered strains with escape frequencies below National Institutes of Health standards. The effectiveness of this approach was confirmed under various conditions, showcasing its ability for secure GMM management. This research underscores the resilience of microbial metabolism, strategically modifying key nodes to halt growth without provoking significant resistance, thereby enabling more reliable and precise GMM control. A record of this paper's transparent peer review process is included in the supplemental information.

59 BASIC BIOLOGICAL SCIENCES

Bayesian Attack Model (BAM) User Story

This document presents a user story for the Bayesian Attack Model (BAM) tool designed to aggregate and analyze cyber-attack observables for operational technology (OT) systems. BAM aims to empower cybersecurity analysts by providing a streamlined interface for collecting observable data from various sources, enabling real-time analysis of potential adversary activity. By enhancing the response capabilities of security teams, BAM facilitates risk-informed decision-making and improves organizational security posture. This user story outlines the key functionalities, user interactions, and requirements necessary to successfully integrate BAM with other security information and event management (SIEM) technology and cybersecurity operations centers (CSOCs).

97 MATHEMATICS AND COMPUTING

Transportation Secure Data Center: Frequently Asked Questions for Data Owners/Contributors

The Transportation Secure Data Center is a centralized repository for detailed transportation data from travel and transit surveys and studies conducted across the nation. It makes vital transportation data broadly available to users while preserving the privacy of survey participants. Hundreds of datasets from surveys and studies of household travel and transit passenger travel are archived in the TSDC, including surveys and studies conducted by state departments of transportation, metropolitan planning organizations, transit agencies, cities, and other public agencies. Detailed data from travel surveys and studies are extremely valuable for research purposes. However, the fine-grained information they contain could potentially be misused to identify individual travelers, so access to these data should only be granted with safeguards in place to protect participant privacy. The TSDC was created to address this challenge and to relieve public agencies from the burden of archiving their data and responding to data requests.

33 ADVANCED PROPULSION SYSTEMS

Defense Technical Assistance - Infographic 4/24/25

Defense Technical Assistance (TA) Infographic designed to inform potential pilot partnerships with military installation about the TA opportunities available. - Secure and reliable energy is crucial for the operational readiness and resilience of military installations. The Department of Energy’s Grid Deployment Office has funded a new initiative at Idaho National Laboratory to conduct technical, on-site assessments that aim to secure the power infrastructure of military bases reliant on civilian utilities for their operations, both CONUS and OCONUS. Including how the assessments work and INL capabilities, partnership model as well as outcomes.

21 - SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLAN

Characterizing climate pathways using feature importance on echo state networks

The 2022 National Defense Strategy of the United States listed climate change as a serious threat to national security. Climate intervention methods, such as stratospheric aerosol injection, have been proposed as mitigation strategies, but the downstream effects of such actions on a complex climate system are not well understood. The development of algorithmic techniques for quantifying relationships between source and impact variables related to a climate event (i.e., a climate pathway) would help inform policy decisions. Data-driven deep learning models have become powerful tools for modeling highly nonlinear relationships and may provide a route to characterize climate variable relationships. In this paper, we explore the use of an echo state network (ESN) for characterizing climate pathways. ESNs are a computationally efficient neural network variation designed for temporal data, and recent work proposes ESNs as a useful tool for forecasting spatiotemporal climate data. However, ESNs are noninterpretable black-box models along with other neural networks. The lack of model transparency poses a hurdle for understanding variable relationships. We address this issue by developing feature importance methods for ESNs in the context of spatiotemporal data to quantify variable relationships captured by the model. We conduct a simulation study to assess and compare the feature importance techniques, and we demonstrate the approach on reanalysis climate data. In the climate application, we consider a time period that includes the 1991 volcanic eruption of Mount Pinatubo. This event was a significant stratospheric aerosol injection, which acts as a proxy for an anthropogenic stratospheric aerosol injection. Furthermore, we are able to use the proposed approach to characterize relationships between pathway variables associated with this event that agree with relationships previously identified by climate scientists.

black-box models

Laboratory Directed Research and Development Program: FY 2024 Completed Projects Report

Oak Ridge National Laboratory (ORNL) is the US Department of Energy’s (DOE’s) largest multiprogram science, technology, and energy laboratory. It possesses distinctive capabilities in a variety of fields, such as neutron science, computing, advanced materials, and nuclear science and technology. Using these capabilities, ORNL conducts basic and applied research and development (R&D) to support DOE’s overarching mission “to ensure America’s security and prosperity by addressing its energy, environmental and nuclear challenges through transformative science and technology solutions.” As a national resource, ORNL also applies its capabilities and skills to the specific needs of other federal agencies and customers through the DOE Strategic Partnership Projects (SPP) Program. Information about the laboratory and its programs is available on the ORNL website. The Laboratory Directed Research and Development (LDRD) Program at ORNL operates under the authority of DOE Order 413.2C, Laboratory Directed Research and Development,3 which establishes DOE’s requirements for the program while providing the laboratory director broad flexibility for program implementation. The LDRD Program funds are obtained through a charge to all laboratory programs. Although it represents a relatively small portion of the overall research budget, the LDRD Program plays an essential role in maintaining the laboratory’s ability to respond to national needs. The program allows ORNL to improve its distinctive capabilities and to enhance its ability to conduct cutting-edge R&D. In accordance with the DOE order, R&D projects funded through the LDRD Program at ORNL support the goals of • maintaining the scientific and technical vitality of the laboratory; • enhancing the laboratory’s ability to address future DOE missions; • fostering creativity and stimulating exploration of forefront areas of science and technology; • serving as a proving ground for new concepts in R&D; and • supporting high-risk, potentially high-value R&D. This report provides an overview of the LDRD Program at ORNL in FY 2024 and contains summaries of all the LDRD research projects that concluded between October 1, 2023, and September 30, 2024.

99 GENERAL AND MISCELLANEOUS

Laboratory Directed Research and Development Program: FY 2025 Completed Projects

Oak Ridge National Laboratory (ORNL) is the US Department of Energy’s (DOE’s) largest multiprogram science, technology, and energy laboratory. It possesses distinctive capabilities in a variety of fields, such as neutron science, computing, advanced materials, and nuclear science and technology. Using these capabilities, ORNL conducts basic and applied research and development (R&D) to support DOE’s overarching mission “to ensure America’s security and prosperity by addressing its energy, environmental and nuclear challenges through transformative science and technology solutions.” As a national resource, ORNL also applies its capabilities and skills to the specific needs of other federal agencies and customers through the DOE Strategic Partnership Projects (SPP) Program. Information about the laboratory and its programs is available on the ORNL website. The Laboratory Directed Research and Development (LDRD) Program at ORNL operates under the authority of DOE Order 413.2C, Laboratory Directed Research and Development, which establishes DOE’s requirements for the program while providing the laboratory director broad flexibility for program implementation. The LDRD Program funds are obtained through a charge to all laboratory programs. Although it represents a relatively small portion of the overall research budget, the LDRD Program plays an essential role in maintaining the laboratory’s ability to respond to national needs. The program allows ORNL to improve its distinctive capabilities and enhance its ability to conduct cutting-edge R&D. In accordance with the DOE order, R&D projects funded through the LDRD Program at ORNL support the goals of • maintaining the scientific and technical vitality of the laboratory, • enhancing the laboratory’s ability to address future DOE missions, • fostering creativity and stimulating exploration of forefront areas of science and technology, • serving as a proving ground for new concepts in R&D, and • supporting high-risk, potentially high-value R&D. This report provides an overview of the LDRD Program at ORNL in FY 2025 and contains summaries of all the LDRD research projects that concluded between October 1, 2024, and September 30, 2025.

99 GENERAL AND MISCELLANEOUS