Search NASA⌕ Search

SEARCH · Search NASA

Results for “security controls”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Engineering Against Digital Risk in CIP Applications: Cyber-Informed Engineering Use Cases

Cyber-Informed Engineering (CIE) addresses the reality that cyber attacks on engineered systems can have consequences far beyond data loss or disruption of digital networks. When control systems are compromised, safety, reliability, and performance of the physical process itself may be threatened. This presentation discusses engineered controls of 7 categories and the CIE database of controls that provides clear examples and guidance for defining and applying engineered controls in CIE. It explains what engineered controls are, how they differ from information security measures, and how they are integrated into system design.

99 - GENERAL AND MISCELLANEOUS↗

IEEE PES GM Poster - Cyber-Informed Engineering Approach to Mitigating BESS Supply Chain Concerns

Battery energy storage systems (BESS) are increasingly important to meet the needs of grid resilience and reliability. BESS provide critical grid services, maintaining stability of the grid with increased variable conditions. However, there are significant geopolitical and security concerns regarding their operation in critical infrastructure, due to lack of a domestic supply chain and prevalence of foreign entity of concern (FEOC) components in BESS and associated inverter-based resources. The supply chain challenge is dually exacerbated by a lack of alternative suppliers who can meet the economic targets for energy delivery and a potentially adversarial supply chain. Solutions are needed to secure components, addressing mixed layers of risk and engineering controls. This paper presents a specific application of Cyber-Informed Engineering (CIE) principles for BESS and recommends an alternative strategy to blocking the supply chain, ensuring that grid modernization targets can be met despite lack of a validated or secure supply chain. This study focuses on the United State (U.S.) use case, but the process can be applied globally to address supply chain security challenges. CIE practices represent the next step in functional assurance and risk mitigation, ensuring optimal resource allocation and enhancing security measures to safeguard the future of energy in the U.S. and beyond.

25 - ENERGY STORAGE↗

Securing Future Energy Supplies: From Renewables to Microreactors

This session will provide insight into how future energy deployments, critical to national-level programs focused on reducing carbon emissions, can be secured-by-design using lessons learned from current energy infrastructure. It will begin with an overview of current threats and risks associated with renewable energy assets and systems, primarily wind and solar, focusing on their control architecture and key system functions for both efficient and safe operations. This talk will then translate the key takeaways from current renewable infrastructure into applications for securing future energy systems, including microreactors and small modular reactors (SMRs), based on planned concepts of operations and control. Microreactors and SMRs are intended to be factory-assembled with commercially available components and deployed in more remote or distributed environments, necessitating centralized control centers, remote monitoring, and offsite maintenance and technical support. All of these factors lead these assets to a security posture and controls more similar to today's renewable energy assets than today's nuclear reactors, which represents a significant shift in mindset for the nuclear industry. This talk will provide justification for this shift as well as a path forward to motivate securing these groundbreaking technologies from the outset of their design and deployment.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Resilient State Recovery Using Prior Measurement Support Information

Resilient state recovery of cyber-physical systems has attracted much research attention due to the unique challenges posed by the tight coupling between communication, computation, and the underlying physics of such systems. By modeling attacks as additive adversary signals to a sparse subset of measurements, this resilient recovery problem can be formulated as an error correction problem. To achieve exact state recovery, most existing results require less than 50% of the measurement nodes to be compromised, which limits the resiliency of the estimators. In this paper, we show that observer resiliency can be further improved by incorporating data-driven prior information. Here, we provide an analytical bridge between the precision of prior information and the resiliency of the estimator. By quantifying the relationship between the estimation error of the weighted ℓ 1 observer and the precision of the support prior, this quantified relationship provides guidance for the estimator’s weight design to achieve optimal resiliency. Several numerical simulations and an application case study are presented to validate the theoretical claims.

24 POWER TRANSMISSION AND DISTRIBUTION↗

The Impact of Cultural Values and Organizational Processes on Nuclear Security Operations

Human performance is a pivotal factor in the design, testing, maintenance, and operation of security systems. The effectiveness of these systems relies not only on the capabilities, limitations, motives, and attitudes of the individuals involved, but also on the quality of training, instructional content, and evaluation methods provided. To uphold security standards, seamless integration between technologies and operators necessitates reliable human input. In security operations, human errors, often attributed to blame, sanctions, low motivation, individual accountability, or complacency, are primary causes of system failures. Complacency, characterized by a false sense of security, reflects a lack of awareness of potential threats and is a significant contributing factor to lapses in security. Security incidents arise from various factors, many extend beyond individual control, highlighting the need for a holistic approach to human performance that integrates organizational processes and team collaboration. Historically, errors have been attributed to individual moral or cognitive failures. However, insights from Operational Experiences (OEs) suggest that organizational processes weakness and deficiencies in nuclear cultural values contribute more significantly to security failures than individual mistakes. This paper consolidates lessons learned from diverse international nuclear security cultures and aims to highlight the importance of security culture in shaping global perspectives on nuclear security. It underscores the role of cultural values in shaping nuclear security practices and enhancing the resilience of security systems in the nuclear sector.

Zineddin, Dr. Z. [ORNL] (ORCID:0009000848740725)↗

Results of an In-Field Validation Exercise in Support of Wide-Area Environmental Sampling

The National Nuclear Security Administration’s (NNSA) Office of Nonproliferation and Arms Control (NA-24) is evaluating Wide-Area Environmental Sampling (WAES) as an additional safeguards verification tool for the International Atomic Energy Agency to detect undeclared nuclear activities. The NNSA is evaluating strategies for conducting a generic WAES campaign, the cost of a WAES campaign, and the effect of technological advancements that have occurred since the last major WAES review in 1999. Until now, the NNSA effort has focused on tabletop exercises (TTXs) in which high-performance computing allows for advanced modeling and simulation efforts to be applied to the WAES question. Although the modeling and simulations used in the TTXs are extremely valuable, field campaigns are still needed to validate the assumptions that underpin the models and the modeling process itself. During a 7 week period beginning in May 2023 and ending in June 2023, which included 4 weeks of active field collections, a multilaboratory team conducted its first in-field validation exercise. Prior to the in-field exercise, abbreviated TTXs were conducted to estimate the performance of all collection systems to be used during the field test. These TTXs guided the selection of materials to be released and the placement of the collection system. Based on these determinations, materials were procured to use in the field test, and an injection/release system was designed, built, and installed at the test facility. Background samples were collected during weeks one and four, and environmental collections against active releases were conducted during weeks two and three. The goals of this validation exercise included a demonstration of (1) the ability to provide controlled releases of particulates of surrogate materials, (2) the fielding and operation of collection systems (including deposition and active air collectors), and (3) the flexibility to revise equipment and campaign plans in the field. This paper presents the results and preliminary conclusions for this initial validation test. Based on these results, subsequent field campaigns are anticipated and will include the addition of other released materials.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

INS Nuclear Material Accounting and Control Instructional Video Materials- FY 25 Guides

This training video provides an essential guide to understanding and utilizing Tamper Indicating Devices (TIDs), with a specific focus on a common Mylar (Adhesive) variety during the application process. TIDs are a critical part of nuclear security, used to detect unauthorized access to sensitive materials or facilities. The Mylar (adhesive) TID employes a tamper-evident film integrated into the TID that visually indicates any tampering attempts. This video will explain how an example Mylar (adhesive) TID works, demonstrate proper installation techniques, and highlight how to interpret its indicators to ensure the security of nuclear materials.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

NCERC 2024 Highlights

The National Nuclear Security Administration (NNSA) is entrusted with ensuring the safety, security, and reliability of the nation’s nuclear weapons stockpile while advancing programs aimed at reducing global nuclear proliferation. These critical mission objectives are achieved through the expertise of a highly skilled team of professionals. The operations at the National Criticality Experiments Research Center (NCERC) play a vital role in developing and enhancing knowledge and expertise in advanced nuclear technologies. NCERC supports a wide range of mission areas, including nuclear criticality safety, nuclear emergency response, and nuclear nonproliferation, safeguards, and arms control. It also provides support to the Department of Homeland Security, advances stockpile stewardship science, and delivers scientific expertise to other government agencies, such as NASA and the Defense Threat Reduction Agency. NCERC conducts experiments utilizing diverse nuclear materials, from small neutron-emitting sources for testing radiation detection equipment to larger quantities of uranium and plutonium for criticality experiments. A cornerstone of NCERC's mission portfolio includes the operation of four critical mass assembly machines—Planet, Comet, Flattop, and Godiva-IV—which are instrumental in advancing nuclear science and ensuring the nation’s nuclear security objectives.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Asi Nuclear Energy Sensors Data Portal Chatbot And Data Structuring Tool

The Idaho National Laboratory (INL) is advancing the development of an AI-powered chatbot and data structuring tool specifically designed to accelerate data mining processes for sensor-related information and seamlessly integrate the results into the ASI Sensors Data Portal (https://nes.energy.gov/). By doing so, the software aims to enhance the accessibility, usability, and organization of sensor data for nuclear energy applications. The software initial phase focuses on retrieving comprehensive datasets, prioritizing the past five years of publicly available information from the Office of Scientific and Technical Information (OSTI). These datasets will be meticulously processed to ensure compatibility, employing cleaning and preprocessing steps to eliminate irrelevant, incomplete, or corrupted information, thus establishing a robust foundation for subsequent AI use. The data will serve as the backbone for training an AI model and chatbot, which will act as an interactive tool enabling users to ask complex, context-specific questions and receive accurate, validated answers derived from constrained literature. In parallel, the project incorporates a data structuring process supported by AI to organize sensor information from multiple sources into a standardized format. This structured data will include detailed sensor specifications, such as measurement range, applications, accuracy, and operating conditions, generated and documented with AI. These specifications will be systematically integrated into the sensor portal. To maintain the highest levels of accuracy and relevance, all AI-generated outputs will be reviewed and validated by subject matter experts (SMEs), with additional fields or parameters added as needed. Future stages of the project aim to expand the dataset beyond OSTI to include other sources and potentially incorporate unclassified controlled information (UCI) with restricted access protocols to address security and confidentiality requirements.

Mapes, NormanJ. [Idaho National Laboratory (INL), ↗

EV Charging Infrastructure Energization An Overview of Approaches for Simplifying and Accelerating Timelines to Processing EV Charging Load Service Requests

The United States has seen significant growth in electric vehicle (EV) adoption, leading to increased demand for EV charging infrastructure. Over the past decade, EV charging infrastructure site developers, site hosts, and electric distribution utilities have navigated the process to integrate chargers onto the electric grid. Site developers and site hosts have raised the alarm that the integration process for high-powered EV charging projects does not meet the needs of the EV market for timeliness or cost. High-powered charging stations typically require a load service request or an agreement with the local utility to connect to the grid. The process of energizing a new high-powered charging site can be complex and time-consuming, often taking up to 2 years. This timeline is the result of current utility energization processes having been designed for construction projects that take longer to build (i.e., buildings). The specific challenges stem from various factors, including compartmentalization in application processes, the integration of EV charging process approvals with other distributed energy resources (DERs), and the need to ensure grid reliability. The energization process needs to evolve to meet the growing demand for high-powered EV charging. This white paper compiles information gathered through various conversations with key stakeholders, including utilities, utility regulators, EV charging operators, site developers, and authorities having jurisdiction (AHJ) as well as through an extensive literature review. This document identifies the challenges and provides potential solutions to streamline the process of connecting EV charging infrastructure to the power grid in the United States, serving as a starting point for future conversations around these solutions. The solutions noted in this white paper require collaborative efforts among utilities, regulators, and EV charging infrastructure developers to streamline the grid connection process for EV charging infrastructure. They are broadly organized into four areas: 1. Increase data access and transparency: Develop automated load service request tools, integrate hosting capacity and load service request analyses, incorporate EV adoption forecasts, and provide transparency on the processing queue. 2. Improve energization processes and timing: Create fast-track options based on prescreening criteria, provide flexibility or phased approvals in the load service request/interconnection process, build internal knowledge within utilities about EV charging technologies, and provide standardized workforce training. 3. Promote economic efficiency: Right size distribution components to accurately reflect the load requirements of EV charging infrastructure, make proactive investments in grid infrastructure based on EV adoption forecasts and growth projections, and consider energy equity and environmental justice factors such as equitable access to EV charging when planning infrastructure. 4. Improve grid reliability and resilience: Use load management/power control systems (PCS) at EV charging stations, adopt and implement harmonized standards for communication protocols and information models between the EV charging and grid control infrastructure, and address cybersecurity considerations by implementing robust security measures and standards for EV charging infrastructure—with particular emphasis on clarifying the security requirements for the interface to the grid. The objective of the solutions proposed in this white paper is to accelerate the timeline and decrease costs associated with connecting EV charging infrastructure to the grid. Electric utilities, utility regulators, EV charging infrastructure developers, and site hosts will first need to understand which solutions are available in their service territory, and if warranted, which combination of solutions would support their specific needs. Through the successful implementations of solutions at scale detailed here, industry will demonstrate a new and innovative ecosystem where timely deployment and energization of EV charging infrastructure with greater grid resiliency and reliability is a reality.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Tracking and Positioning System for Floating Solar (CRADA Abstract)

The project goal is to develop a floating solar photovoltaics (FPV) tracking & position system that: (1) increases annual energy production of FPV projects by >10%, (2) lowers levelized cost of energy (LCOE) for FPV by >10%, and (3) leverages U.S. contract supply chain & manufacturing. The outcome of the project will be a certified tracking product that has undergone extensive field testing and is ready for commercial sales. The primary objectives for each budget period are: • BP1: Define product requirements, develop initial controls architecture and design other sub-components, complete small-scale pilot testing, install a larger-scale pilot, secure sites for commercial pilots, and develop the beta-version of a user portal. • BP2: complete control system and sub-component design, successful demonstration and testing at a commercial pilot, certification & bankability, finalize user portal, and complete various commercialization activities related to supply chain, customer acquisition, and sales. PNNL will provide support during both project phases for prototype development and testing of the controls architecture, software, and hardware components of the tracking and positioning system. PNNL will provide support during both project phases for prototype development and testing of the controls architecture, software, and hardware components of the tracking and positioning system. This effort represents PNNL’s first opportunity to support the floating solar photovoltaics (FPV) industry with capabilities, facilities, and personnel developed to contribute to the marine energy (e.g., wave and tidal energy) sector. This portfolio expansion leverages internal and DOE EERE investments and the growing visibility of PNNL-Sequim’s Marine and Coastal Research Laboratory (MCRL) and our marine research capabilities, in general. The development of effective and low-cost FPV platforms is a potential way to increase the nation’s set of tools for providing emission-free electricity without utilizing valuable terrestrial resources. Successful commercialization of such a project may lead to economic benefits through job creation, supply chain creation, and access to a cheaper source of electricity.

14 SOLAR ENERGY↗

Developing a Supply Chain Security Program

Amid growing concerns over foreign manufacturing for components and devices deployed in critical energy infrastructure, this research from the national labs will highlight best practices for developing and maintaining a supply chain security program. Tools for asset inventory, tips for developing and maintaining software- and hardware-bills-of-materials (SBOMs and HBOMs), recommended contractual language for vendor agreements, and identification of responsibilities will be shared. We discuss the one-time requirements to enable a successful supply chain security program and the best ways to operationalize this program for maximum impact, including development of robust practices for vulnerability tracking, patch management, and workarounds, with understanding of the reliability and uptime requirements for utilities. The recommendations shared are based on a cyber-informed engineering approach to identification of high-consequence impacts and the engineering controls related to supply chain management that can best mitigate these impacts. This approach allows for prioritization of resources. Additionally, we highlight relative up-front and ongoing costs associated with recommended controls. Viewers will leave with an understanding what a supply chain security program is, and what steps, prioritized for resource-constrained organizations, can build a robust program.

14 SOLAR ENERGY↗

INS Nuclear Material Accounting and Control Instructional Video Materials- FY 25 Full Scripts

Each section of the Adhesive TID Process Demonstration is broken down into subparts as referenced in the outline contained in the Contents section, these are referenced as Activity Sections. The structure of the Adhesive TID Process Demonstration items is, to the best of the writer’s ability, in the order of events that the NMAC mitigating techniques are performed.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Capabilities for Water Sector Infrastructure Resilience - Prioritizing RD&D in a Target Rich, Resource Poor Sector

WSTB & Water Sector Security Program Expansion Objective: Incubate and shepherd a public-private consortium of joint seal US government sponsors and industry stakeholders to build out industrial control system (ICS) and operational technology (OT) architecture of the Idaho National Laboratory (INL) Water Security Test Bed (WSTB) asset to enable research, testing, and cyber workforce training related to evolving cyber-physical and physical vulnerabilities and threats in the water sector.

99 - GENERAL AND MISCELLANEOUS↗

(U)Vendor Sanitization Requirements – SIEMENS Control

This document defines the software requirements for the sanitization of the IPC and or the controller. The system is intended to manage part programs and associated data (e.g. simulations, probing data) by capturing metadata, securely sanitizing files, logging operations, backing up data to a defined path, deploying a user defined program to a controller, and restoring part programs and associated data when required.

42 ENGINEERING↗

Multi-Agent Control Planes for Quantum Networks: A Scalable Architecture for Autonomous Quantum Internet Management

Quantum networks are expected to enable distributed quantum computing, secure communication, and global entanglement distribution. However, operating such networks presents significant challenges, including stochastic quantum processes, fragile entanglement resources, dynamic topology, and cross-layer control requirements. Current quantum network control architectures largely rely on centralized or hierarchical controllers inspired by classical software-defined networking (SDN). While effective for small testbeds, these approaches face scalability, latency, and reliability limitations as quantum networks grow. This paper proposes a multi-agent control plane architecture for quantum networks. In this design, intelligent software agents operate at quantum nodes, repeaters, and orchestration layers, collectively managing entanglement generation, routing, purification, and scheduling. The distributed intelligence of the agent system allows the network to adapt dynamically to quantum hardware variability and environmental noise. We argue that multi-agent systems provide significant advantages over centralized control approaches, including scalability, resilience, local autonomy, and real-time adaptation. The paper discusses architectural design principles, agent coordination mechanisms, and research challenges in deploying multi-agent control planes for the emerging quantum Internet.

Alnajjar, Anees [ORNL] (ORCID:0000000237101601)↗

Lightfall v0.0.1

Lightfall is a desktop application for synchrotron beamline instrument control, data acquisition, and live analysis at the Advanced Light Source (ALS). Built on Python and Qt, it provides a native graphical interface for operating beamline hardware, configuring and executing experimental scans, and visualizing results in real time. Key features include direct integration with EPICS control systems, a built-in electronic logbook, remote beamline access over secure tunnels, and an interprocess communication (IPC) architecture that coordinates with external analysis applications via ZMQ and EPICS process variables. This IPC approach allows Lightfall to orchestrate specialized analysis tools—including GPU-accelerated streaming correlators—without embedding them, avoiding the dependency conflicts common in monolithic scientific software platforms. Compared to prior approaches such as Xi-CAM's plugin-based architecture, Lightfall's design cleanly separates instrument control from domain-specific analysis, enabling feedback-driven acquisition where live analysis results can adjust scan parameters during an experiment. Its native Qt interface provides responsive performance for real-time data visualization that web-based alternatives struggle to match. Lightfall is designed for use by beamline scientists and staff operating synchrotron instruments at national user facilities.

Pandolfi, Ronald [Lawrence Berkeley National Labor↗

Innovating the next generation of commercial smart building software

Nearly 30% of commercial building energy use is wasted due to equipment faults and HVAC controls problems. The result is increased emissions, compromised comfort and productivity, and less reliable coordination of building power needs with a clean grid. The energy impact alone represents $17 billion in potential savings. Today’s smart building software provides a robust solution to address these operational deficiencies. Energy management and information systems (EMIS) are saving up to 9% on average, with two-year paybacks. They are being incorporated into energy management processes, commissioning services, and utility programs. As effective as they are, two barriers prevent even deeper benefits; limited personnel to fix problems once they are identified, and the expense and time to manually implement changes in control systems. In partnership with the research community, the EMIS industry is developing new capabilities to overcome these barriers. Moving beyond siloed products for either fault detection and diagnostics, or optimal control, these new capabilities empower users to not only automatically identify faults, but also to push corrective action, and control improvements to their buildings. In this paper, several areas for enhancements are documented: ‘one-time’ correction of faults such as setpoints, schedules, and economizer lockouts; short-term active testing for automated proportional integral derivative (PID) loop tuning and functional testing; and continuous supervisory control for demand flexibility and year-round efficiency. Results are presented from a pair of partner implementations out of a dozen providers integrating these enhancements into their products, including field tests from across the country, and insights into operator acceptance and integration into operations and maintenance practices.

Casillas, Armando↗