Search NASASearch

SEARCH · Search NASA

Results for “software security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Braxton Marlatt Intern Poster

The Internet of Things (IoT) encompasses a vast network of interconnected devices embedded with software, sensors, and network connectivity, enabling data collection and exchange. While IoT technology revolutionizes various industries, it also introduces significant security challenges. This research focuses on enhancing IoT security through the implementation of Zero Trust Architecture concepts, specifically targeting the Network and Device pillars of the Cybersecurity and Infrastructure Security Agency’s Zero Trust Maturity Model. By generating Codified Attack Surfaces (CAS) using custom Structured Threat Information eXpression bundles, this project aims to provide enhanced visibility into network communications, detect vulnerabilities in device firmware, and improve the overall security posture for IoT devices and networks. The methodology involves defining custom STIX schema and objects, collecting data from intra-IoT traffic, external network traffic, and firmware analysis, and automating the conversion and correlation of this data into STIX bundles. The automated generation of attack surfaces offers comprehensive insights into activity, vulnerabilities, and anomalies within an IoT environment, enabling proactive threat identification and mitigation.

24 - POWER TRANSMISSION AND DISTRIBUTION

Inventory of Composable Elements (ICE) v6.0.0

The Inventory of Composable Elements (ICE) is an open source registry software platform for managing information about biological parts. It is capable of recording information about plasmids, microbial host strains and seeds, as well as DNA parts. Includes features such as DNA sequence visualization, editing and annotation, auto-aligning sequencing trace files against reference templates, SBOL XML/RDF support, and web-of-registries functionality. The web of registries functionality provides strong support for distributed interconnected use and enables sharing and transfer of biological parts across various independent ICE instances. ICE adopts modern software development principles, leveraging component-base frameworks, offering a REST API for convenient third-party integration and emphasizing scalability, security, and service integrations for dynamic content availability. The source code is hosted at https://github.com/JBEI/ice. A public instance is available at public-registry.jbei.org, where users can try out features, upload parts or simply use it for their projects.

Plahar, Hector

Autonomous Energy Systems: Building Reliable, Resilient, and Secure Electrified Communities

Technological changes across energy systems are forcing utilities and operators to reconsider their methods for managing power delivery, but few operators have adopted advanced controls and operational software. Their challenge is that every system has peculiar requirements, and the available solutions are relatively new, untested, and difficult to integrate into an operational environment. Through extensive collaboration with utilities and cooperatives, the National Renewable Energy Laboratory has realized the need for autonomous and optimized management of energy resources, leading to the development of Autonomous Energy Systems, a packaged set of controls that is ready to be integrated into existing control rooms.

automation

(U)Vendor Sanitization Requirements – SIEMENS Control

This document defines the software requirements for the sanitization of the IPC and or the controller. The system is intended to manage part programs and associated data (e.g. simulations, probing data) by capturing metadata, securely sanitizing files, logging operations, backing up data to a defined path, deploying a user defined program to a controller, and restoring part programs and associated data when required.

42 ENGINEERING

Scan2Sim: Software to Convert Network Scans to Emulations

Within operational technology (OT) systems design, the construction of testing environments for simulation is often a tedious, manual process that slows down safety and security evaluations. This document details the design and functionality of Scan2Sim, a program designed to construct high-fidelity topological schematics for OT systems without significant manual human input. Scan2Sim may take as input a detailed network scan of a system, and produces an instruction set to re-create the original scanned network within a virtualized simulation network. This construction is achieved via heuristic methods of machine template selection, which allows for a fast, performant approach to automated environment construction. The current tool is designed to produce topology schematics compatible with the Minimega, a tool designed by Sandia National Laboratories for repeatable experimentation management.

97 MATHEMATICS AND COMPUTING

Physical & Cyber Security Modeling Interfacing Through Dante and ARCADE

Physical security is increasingly facing new threats from cyber attackers, for which there is little research in the way of characterizing this threat. This report discusses the efforts to combine cyber and physical security modeling tools to investigate this novel combinatorial threat space. To accomplish this, the Dante force-on-force modeling and simulation software and the Advanced Reactor Cyber Analysis and Development Environment (ARCADE) were integrated. Dante provides a 3D environment which models the physical world, while ARCADE provides the cyber and control systems world.

42 ENGINEERING

LLGoMAX : Enhancing Industry-Standard Tools for AC Optimal Unit Commitment

In 2018, the Advanced Research Project Agency – Energy (ARPA-E) launched the Grid Optimization Competition (GOC) [1], a series of competitive challenges intended to accelerate innovation in decision support software used to schedule power grid operations, making them as efficient as possible, while respecting operational constraints of power equipment and operational security. This report covers the participation of the LLGoMAX team—a collaboration of the Lawrence Livermore National Laboratory (LLNL) and ECCO International, Inc.—in Challenge 3 of the competition.

97 MATHEMATICS AND COMPUTING

Human Supervision of Autonomous Vehicle Fleet Operations and Associated Passenger Communications: Preprint

Advances in automated vehicle (AV) technology and expanded operations are rapidly emerging with Automated Mobility District (AMD) deployments in global cities. NLR's AMD research addresses critical elements of human supervision of AV fleet operations and associated passenger communications for vehicles in which no driver or safety attendant is present. Although sufficiently advanced AVs no longer have direct oversight by a driver, fleet management remains staffed with operations personnel at the operations command and control (OCC) facility. This paper examines the functionality of the OCC, drawing comparisons of how automated train control and automated people mover OCCs operate. Within an AMD, the OCC manages various vehicle types, sizes, and operational modes, including on-demand and fixed route service, to facilitate a 'network of networks' for transport within a metropolitan area. The OCC serves as oversight for multiple AV fleets assisting AVs via remote operation of vehicles, communication, and dispatching personnel to resolve problems. The OCC also coordinates system operation, geographically staging vehicles, and managing weather, police, and emergency events. Informed by traffic management center (TMC) strategies using highly integrated software and communications, OCCs facilitate seamless information flows. OCC personnel remotely assist passengers and oversee multi-party operation to ensure safety and security. Although social norms mitigate large-capacity unattended vehicle operations, social interaction in multi-party automated small vehicles has little precedent. This poses a new frontier for society and requires research to effectively understand and manage. Future research will monitor OCC implementations, passenger interfaces, and deployment scaling of initial AMD systems.

33 ADVANCED PROPULSION SYSTEMS

Securing Digital Energy Infrastructure: Procurement, Contracting, and Supply Chain Risk Management Guidance

Recognizing the scale of this industry challenge, the United States (U.S.) Department of Energy (DOE) Grid Deployment Office (GDO) and Cybersecurity Energy Security & Emergency Response office have launched a multi-year BESS supply chain security initiative to identify consequence-driven approaches to addressing BESS supply chain security and provide resources to support prioritization of supply chain security efforts associated with the procurement of BESS equipment and services. This guide is one element of the supporting resources to be provided and sets forth a framework and guidance for procurement bidding, selection, risk analysis, and agreements stakeholders can implement to mitigate cybersecurity risks across the entirety of battery system component ecosystem, including the interconnected software and hardware required for control and monitoring BESSs.

25 ENERGY STORAGE

Advanced Measurements for Resilient Integration of Inverter-Based Resources: PROGRESS MATRIX Final Report

As nearly every aspect of the electric power grid undergoes rapid change, measurement technologies that support grid operation and planning must evolve as well. The rapid large-scale deployment of inverter-based resources (IBRs) vital to achieving the nation’s clean energy goals has in some cases led to negative impacts on the reliability and security of the bulk power system (BPS). Advanced power system measurements, including synchronized phasor and waveform measurements, are key to making IBR integration secure and reliable. To this end, the Department of Energy (DOE) initiated the PROGRESS MATRIX project to develop advanced measurement capabilities and analytics that will accelerate adoption of IBRs while improving the reliability and resilience of the BPS. This report discusses the outcomes of the project, which was a joint effort between the Pacific Northwest National Laboratory (PNNL), Oak Ridge National Laboratory (ORNL), the National Renewable Energy Laboratory (NREL), and Lawrence Berkeley National Laboratory (LBNL). In the project’s first year, PNNL, NREL, and ORNL partnered with the Bonneville Power Administration (BPA), the Western Area Power Administration (WAPA), and Kauai Island Utility Cooperative (KIUC) to understand their existing measurement capabilities and the gaps limiting deployment of IBR-focused measurement systems and analytics. The other primary activity in the first year was deployment of GridSweep instruments, which provide unprecedented precision in waveform measurement while probing distribution systems. The instruments were deployed at Dominion Energy and the University of California, Riverside. In the project’s second year, the input from partner utilities and collected measurements were used to advance measurement capabilities. Twelve analytical methods spanning disturbance analysis, power plant evaluation, feeder evaluation, and modeling were developed. Two software tools were developed, one to analyze GridSweep measurements and another to automatically evaluate the control performance of power plants connected to the BPS. Testbeds at ORNL and NREL were augmented to better enable studies of IBR integration. The project culminated in demonstrations of these analytical methods, software tools, and testbeds, both in the field and in the laboratory. This report discusses these various accomplishments and documents the significant progress in developing advanced measurement capabilities to support the secure, reliable, and accelerated adoption of IBRs in the BPS.

24 POWER TRANSMISSION AND DISTRIBUTION

Enhancing Security and Resiliency in Operational Technology Environments Through Network Slicing and Federated Learning

The growing convergence of Information Technology (IT) and Operational Technology (OT) within Industry 4.0 environments has introduced new demands on industrial network infrastructure. As cyber-physical systems become increasingly interconnected, ensuring the secure, timely, and efficient exchange of critical data is essential. This thesis explores how network slicing, a method of creating isolated virtual network segments, can be applied within OT environments to address challenges such as latency, security, and resource allocation. The first research question addressed in this thesis is: How can OT networks take advantage of NFV and SDN technology to become cyber resilient? This study examines the operational, security, and architectural implications of introducing network slicing into traditionally static OT infrastructures such as Industrial Control Systems (ICS) and SCADA. Through simulated deployments and case studies, the research demonstrates how slicing enables better isolation between critical and non-critical services, thereby improving response time, throughput, and security in sensitive environments. The second question considers: How to dynamically implement network slicing and take advantage of network resources towards integrating decentralized machine learning? In response, this thesis proposes a framework that combines Software-Defined Networking (SDN), Network Function Virtualization (NFV), and Federated Learning (FL) to enable real-time analytics while maintaining data locality. The proposed approach reduces the burden on centralized infrastructure and minimizes privacy risks by supporting on-site training of models across distributed OT nodes, coordinated through dynamically allocated network slices. The third focus explores: How slicing helps to increase the resiliency of OT networks through the orchestration of a dynamic DMZ? To answer this, the thesis presents a method for creating and managing Dynamic Demilitarized Zones (DMZs) using network slicing. This enables flexible and automated isolation of sensitive subsystems during threat scenarios or high-risk operations. Coupled with intelligent orchestration and containerized security services, the dynamic DMZ significantly enhances the system's ability to respond to cyber incidents without halting production. Ultimately, this thesis contributes a comprehensive architecture that blends network slicing with machine learning, secure segmentation, and automation, paving the way for resilient, adaptive, and intelligent OT environments. Performance evaluations across multiple scenarios show improvements in system reliability, threat response time, model accuracy, and resource utilization, providing a strong foundation for future industrial automation systems.

Rodiles Delgado, Brian G

National Energy Water Treatment & Speciation (NEWTS): A Water & Critical Mineral Database and Dashboard

The scarcity of water resources, the need for beneficial water reuse, and the challenges of wastewater treatment are becoming increasingly pressing in economic, social, and environmental domains. Addressing these concerns requires effective treatment strategies to manage wastewater streams and tackle environmental and economic issues. Furthermore, the recovery of critical minerals from the waste streams associated with energy production holds the promise of offsetting treatment costs and securing local sources of valuable minerals. However, relevant data on these waste streams are dispersed and challenging to locate. The process of ingesting such data into modeling software often involves multiple steps, requiring data restructuring to meet software-input requirements. The non-standardized reporting of water data makes data aggregation and reformatting a time-consuming process. Additionally, essential attributes necessary for modeling water treatment and mineral scale formation are frequently missing. Moreover, data gaps vary depending on the region of interest. Consequently, there is a pressing need for high-quality energy-water composition data that can be easily imported into water chemistry modeling software. To address this need, the National Energy Technology Laboratory has created the National Energy Water Treatment and Speciation (NEWTS) Database and Dashboard—a free online tool catering to community leaders and water researchers. NEWTS facilitates a comprehensive understanding of the composition of energy-related wastewater streams in the United States. The datasets provide detailed concentrations and speciation of major and minor aqueous compounds in energy-related wastewater streams, including power plant leachate, acid mine drainage, brackish water, and oil and gas produced water across the United States. Many of the aqueous species are critical minerals (Li, REEs) in high demand to modernize the world’s energy infrastructure. Many of the datasets also contain volumetric flow-rates needed to model the treatment and reuse scenarios in advanced aqueous chemistry software programs. The NEWTS Database and Dashboard offer public access to hitherto challenging-to-access datasets, presented in a standardized format that is tailored for easy input into aqueous chemistry modeling software. By performing the work needed to transform dispersed, disparate data sources into unified, model-ready datasets, NEWTS serves as an essential resource in advancing water treatment research and sustainable water resource management.

produced water management

Process Optimization and Modeling for Minerals Sustainability (PrOMMiS) v1.0.0

The U.S. Department of Energy's ("DOE") Process Optimization and Modeling for Minerals Sustainability project ("PrOMMiS Project") was initiated in 2023 to transform the national Critical Minerals and Rare Earth Elements (CM & REE) landscape, thereby supporting DOE's three enduring strategic objectives: security, economic competitiveness, and environmental responsibility. To address this initiative, the PrOMMiS Project will develop, demonstrate, and deploy an open-source, advanced system modeling, optimization, and analysis application ("PrOMMiS Software Application") that will support industry decision-makers by accelerating the scale-up of novel CM & REE technologies by de-risking the development and deployment of commercial scale processes and maximizing learning throughout the development cycle.

Beattie, KeithS [Lawrence Berkeley National Labora

Nuclear Computational Resource Center Progress and Status Report

The Nuclear Computational Resource Center (NCRC) at Idaho National Laboratory (INL), supported by the United States Department of Energy Office of Nuclear Energy (DOE-NE), provides access to supercomputer systems and protected software in support of nuclear energy research and development. The NCRC vision recognizes the central role modeling and simulation plays in nuclear energy innovation as well as ensuring the safe, secure, and efficient operations of existing nuclear energy systems. To accomplish this vision, the NCRC supports processes and systems which provide access to computational tools, supercomputing systems, and training in support of nuclear energy innovation.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS

Cognitive Grid Optimization

This project laid the foundation to include a security constrained economic dispatch (SCED) within one of the leading simulators which is used to train system operators who keep the lights on for over 150 million people in USA. The SCED is designed to handle very high penetrations of renewable generation as well as battery storage. As a follow on the this project, a Trusted Source Model of the North American Electric Interconnections will be built from public GIS data. The various North American Markets will be emulated. This Trusted Source Model will grow the software developers for the next generation of power applications that are needed to transition to all green generation while everything is electrified.

24 POWER TRANSMISSION AND DISTRIBUTION

Validating a Dynamic PWR Safety and Security Model?

Nuclear power plants (NPPs) are assessed for safety and security using separate models that cannot capture how an attacker's decisions and a plant's response unfold together in real time, leaving regulators and operators without a complete picture of true plant vulnerability. Traditional probabilistic risk assessment (PRA) methods treat adversarial events as fixed initiators with predetermined outcomes, and are structurally incapable of representing the time-dependent interplay between physical security events, safety system response, and operator mitigative actions. At Idaho National Laboratory (INL), I contributed to the development and validation of Modeling and Analysis for Safety and Security using the Dynamic EMRALD Framework (MASS-DEF). Where static PRA relies on event-tree logic that cannot evolve mid-scenario, MASS-DEF couples a time-dependent dynamic PRA tool EMRALD (Event Modeling Risk Assessment using Linked Diagrams) with attack simulation software, allowing attacker behavior, plant system states, and operator actions to interact across time. My work focused on validating a general Pressurized Water Reactor (PWR) model. I traced model logic against PWR plant to identified errors in logic and confirm accuracy. I then built and tested attack scenarios against a general PWR model to verify that the model produced expected outcomes across all logical pathways. I also contributed a section to a related technical paper applying the same EMRALD platform to radiation dose modeling. Results show that MASS-DEF can quantitatively demonstrate that many plants exceed their regulatory security thresholds. This demonstrated margin provides a technically defensible basis for reducing the number of guards without compromising regulatory compliance. Physical security costs represent roughly 10% of annual operating budgets, making such reductions directly meaningful to INL's mission of sustaining existing commercial NPPs. This internship strengthened my understanding of nuclear systems, probabilistic modeling, and technical writing, and has solidified my pursuit of a career at a national laboratory.

98 - NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL

Fast and robust strategies for large-scale mixed-integer SCOPF

This project develops scalable, computationally efficient algorithms to solve realistic large-scale power system optimization problems, including systems with more than 8,000 buses, as part of a larger series of competitions run by ARPA-E. These problems are critical because the secure and reliable operation of the power grid is becoming increasingly challenging, especially under conditions of increased uncertainty and variability. The economic feasibility of our methods is high, given that they are purely software-based solutions designed to operate power grids more efficiently. The technical effectiveness balances heuristics and approximations to provide a trade-off between speed and accuracy.

24 POWER TRANSMISSION AND DISTRIBUTION