Search NASASearch

SEARCH · Search NASA

Results for “software security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

Fermilab s Transition to Token Authentication

Fermilab is the first High Energy Physics institution to transition from X.509 user certificates to authentication tokens in production systems. All of the experiments that Fermilab hosts are now using JSON Web Token (JWT) access tokens in their grid jobs. Many software components have been either updated or created for this transition, and most of the software is available to others as open source. The tokens are defined using the WLCG Common JWT Profile. Token attributes for all the tokens are stored in the Fermilab FERRY system which generates the configuration for the CILogon token issuer. High security-value refresh tokens are stored in Hashicorp Vault configured by htvault-config, and JWT access tokens are requested by the htgettoken client through its integration with HTCondor. The Fermilab job submission system jobsub was redesigned to be a lightweight wrapper around HTCondor. For automated job submissions a managed tokens service was created to reduce duplication of effort and knowledge of how to securely keep tokens active. The existing Fermilab file transfer tool ifdh was updated to work seamlessly with tokens, as well as the Fermilab POMS (Production Operations Management System) which is used to manage automatic job submission and the RCDS (Rapid Code Distribution System) which is used to distribute analysis code via the CernVM FileSystem. The dCache storage system was reconfigured to accept tokens for authentication in place of X.509 proxy certificates. As some services and sites have not yet implemented token support, proxy certificates are still sent with jobs for backwards compatibility but some experiments are beginning to transition to stop using them. There have been some glitches and learning curve issues but in general the system has been performing well and is being improved as operational problems are addressed.

Dykstra, David

Fermilab's Transition to Token Authentication

Fermilab is the first High Energy Physics institution to transition from X.509 user certificates to authentication tokens in production systems. All the experiments that Fermilab hosts are now using JSON Web Token (JWT) access tokens in their grid jobs. Many software components have been either updated or created for this transition, and most of the software is available to others as open source. The tokens are defined using the WLCG Common JWT Profile. Token attributes for all the tokens are stored in the Fermilab FERRY system which generates the configuration for the CILogon token issuer. High security-value refresh tokens are stored in Hashicorp Vault configured by htvault-config, and JWT access tokens are requested by the htgettoken client through its integration with HTCondor. The Fermilab job submission system jobsub was redesigned to be a lightweight wrapper around HTCondor. The grid workload management system GlideinWMS which is also based on HTCondor was updated to use tokens for pilot job submission. For automated job submissions a managed tokens service was created to reduce duplication of effort and knowledge of how to securely keep tokens active. The existing Fermilab file transfer tool ifdh was updated to work seamlessly with tokens, as well as the Fermilab POMS (Production Operations Management System) which is used to manage automatic job submission and the RCDS (Rapid Code Distribution System) which is used to distribute analysis code via the CernVM FileSystem. The dCache storage system was reconfigured to accept tokens for authentication in place of X.509 proxy certificates. As some services and sites have not yet implemented token support, proxy certificates are still sent with jobs for backwards compatibility, but some experiments are beginning to transition to stop using them.

Dykstra, Dave [Fermilab] (ORCID:0000000326539015)

Real-Time Testbed for Smart Grid Recloser Controller

The growing need for a low voltage recloser has become apparent due to the rise in requirements for a smart grid. This includes more detailed management of power flow forward (towards load) and backward (towards generation), source synchronization in real time, more indepth fault responses, and the use of green energy. The SEL-651R-2 relay is a device that can manage these needs, especially in fault response and synchronization, and is commonly used in systems called microgrids. Microgrids are distribution level systems that are able to operate separated from the main grid, are typically installed much closer to the load(s), and are fed by distributed energy resources (DERs), such as wind, solar or diesel generators. The SEL-651R-2 is normally used in the field with presets operative settings, but the Western Michigan University (WMU) Center for Interdisciplinary Research on Secure, Efficient and Sustainable Energy Technology (WMU InterEnergy Center) wished to test this device in its range of capabilities for microgrid application. A Hardware-In-the-Loop (HIL) testbed was implemented and used through the Real Time Digital Simulator (RTDS) using the RSCAD software to test the SEL-651R-2's use cases and functions. The testbed includes a microgrid with interconnection to a larger main grid, and the relay is meant to control the recloser at the point of common coupling (PCC) between the main grid and microgrid. The testbed shows how basic protections, reclosing, and synchronization checks function when handling faults that affect both the microgrid and the main grid.

24 POWER TRANSMISSION AND DISTRIBUTION

Lignin molecular weights of Populus trichocarpa residues after CELF pretreatment

Here we present a dataset of molecular weights of lignin from a woody energy crop (Populus trichocarpa) residues after a series of co-solvent enhanced lignocellulosic fractionation (CELF) pretreatment. The natural poplar variant GW-9947 from the Center for Bioenergy Innovation (CBI) was used. The poplar was knife milled and passed through a 1 mm sieve and CELF pretreatment was performed in a Parr autoclave reactor with 7.5 wt % solids loading, 0.5 wt% H2SO4 as catalyst at 150°C with various time. Tetrahydrofuran was added in a 1:1 mass ratio with water as the pretreatment solvent. Lignin was isolated from the pretreated samples after ball-milling in a porcelain jar with ceramic balls via Retsch PM 200 at 580 rpm for 2.5 h followed by enzymatic hydrolysis in acetate buffer (pH 4.8, 50 °C) for 48 h. The solid residue was isolated by centrifugation and hydrolyzed again with freshly added buffer and enzymes for another 48 h. After filtration, the solid residue was extracted twice with 96% (v/v) 1,4-dioxane/water mixture at room temperature overnight. The extracts were combined, rotary evaporated, and freeze-dried to recover lignin. The lignin samples were then derivatized in an acetic anhydride/pyridine (1:1, v/v) mixture and stirred at room temperature for 24 h. Ethanol was added to the reaction mixture, left for 30 min and then removed with a rotary evaporator. The addition and removal of ethanol was repeated at least 3 times until all traces of acetic acid were removed. Acetylated lignin samples were then dissolved in tetrahydrofuran (THF) at a concentration of 1.0 mg/mL. The molecular weight of acetylated lignin was measured by a gel permeation chromatography (GPC) on a PSS-Polymer Standards Service (Warwick, RI, USA) GPC SECurity 1200 system featuring Agilent HPLC 1200 components equipped with four Waters Styragel columns (HR1, HR2, HR4 and HR6) and an UV detector (270 nm). Tetrahydrofuran was used as the mobile phase and flow rate was 0.3 mL/min. The Polymer Standards Service WinGPC Unity software (Build 6807) was used for data processing for all the samples. The data provides information about the effects of CELF pretreatment time at 150 ºC on lignin molecular weights.

09 BIOMASS FUELS

Multi-Agent Control Planes for Quantum Networks: A Scalable Architecture for Autonomous Quantum Internet Management

Quantum networks are expected to enable distributed quantum computing, secure communication, and global entanglement distribution. However, operating such networks presents significant challenges, including stochastic quantum processes, fragile entanglement resources, dynamic topology, and cross-layer control requirements. Current quantum network control architectures largely rely on centralized or hierarchical controllers inspired by classical software-defined networking (SDN). While effective for small testbeds, these approaches face scalability, latency, and reliability limitations as quantum networks grow. This paper proposes a multi-agent control plane architecture for quantum networks. In this design, intelligent software agents operate at quantum nodes, repeaters, and orchestration layers, collectively managing entanglement generation, routing, purification, and scheduling. The distributed intelligence of the agent system allows the network to adapt dynamically to quantum hardware variability and environmental noise. We argue that multi-agent systems provide significant advantages over centralized control approaches, including scalability, resilience, local autonomy, and real-time adaptation. The paper discusses architectural design principles, agent coordination mechanisms, and research challenges in deploying multi-agent control planes for the emerging quantum Internet.

Alnajjar, Anees [ORNL] (ORCID:0000000237101601)

ForceFinder

SAND2025-11750O ForceFinder extends the Structural Dynamics Python Libraries (SDynPy) with comprehensive tools for inverse source estimation (ISE) tasks via frequency response function (FRF) matrix inversion. The software is designed for transfer path analysis and multiple-input/multiple-output (MIMO) vibration control problems. It allows users to estimate sources through various algorithms, from the basic Moore-Penrose pseudo-inverse to statistical learning methods such as Tikhonov regularization via an L-curve and elastic net regularization via an information criterion. ForceFinder uses an object-oriented framework, where all components of the ISE problem—such as FRFs, responses, and transformations—are stored in a "SourcePathReceiver" object. This software can be applied to any noise and vibration problem. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Carter, Steven [Sandia National Lab. (SNL-CA), Liv

Wind Turbine Airfoil Design Tools

SAND2025-11738O Wind Turbine Airfoil Design Tools is a software tool that connects existing open-source airfoil analysis tools with optimization software to produce modern airfoil design for wind turbine applications. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Maniaci, David

PVCollada schema

SAND2025-11606O xml schema for PV uses Collada 1.4 schema to provide tag names and structures to allow PV software to exchange Collada files with PV-specific data. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Crosby, Sean

Automation Scripts for Feeder Analysis using CymPy

SAND2025-00330O Automation Scripts for Feeder Analysis using CymPy is a software tool that uses Python scripts to automate the analysis of power system feeders using CYME software. Utilities and researchers can use it to perform various types of analyses by leveraging the capabilities of CYME. The scripts use the CymPy library to interface with CYME and automate the analysis process. The software uses standard Python libraries along with the Eaton CymPy library. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525

Reno, Matthew

Comparison of Coupled and Uncoupled Modeling of Floating Wind Farms with Shared Anchors

As design options for floating wind farms continue to be explored, shared (or multiline) anchors that secure mooring lines from multiple turbines remain a promising technology that can potentially reduce the number of anchors and overall mooring costs. This study evaluates two methods for analyzing the loads on shared anchors: one in which floating offshore wind turbines are simulated individually (using the software OpenFAST), and one in which an entire floating wind farm is simulated collectively (using the software FAST.Farm). A three-line shared anchor is evaluated for multiple loading scenarios in deep water, using the International Energy Agency 15 MW turbine on the VolturnUS-S semisubmersible platform. While the two methods produce broadly comparable results, the coupled wave loading on platforms within the farm results in wave force cancellations and amplifications that decrease multiline force directional ranges and increase multiline force extreme values (up to 7%) and standard deviations (up to 11%) for wave-driven load cases. The inclusion of wakes in FAST.Farm also reduces the net load on the shared anchor due to the velocity deficit, leading to larger differences between OpenFAST and FAST.Farm (up to 3% difference in mean loads) for load cases with operational turbines.

17 WIND ENERGY

Lightfall v0.0.1

Lightfall is a desktop application for synchrotron beamline instrument control, data acquisition, and live analysis at the Advanced Light Source (ALS). Built on Python and Qt, it provides a native graphical interface for operating beamline hardware, configuring and executing experimental scans, and visualizing results in real time. Key features include direct integration with EPICS control systems, a built-in electronic logbook, remote beamline access over secure tunnels, and an interprocess communication (IPC) architecture that coordinates with external analysis applications via ZMQ and EPICS process variables. This IPC approach allows Lightfall to orchestrate specialized analysis tools—including GPU-accelerated streaming correlators—without embedding them, avoiding the dependency conflicts common in monolithic scientific software platforms. Compared to prior approaches such as Xi-CAM's plugin-based architecture, Lightfall's design cleanly separates instrument control from domain-specific analysis, enabling feedback-driven acquisition where live analysis results can adjust scan parameters during an experiment. Its native Qt interface provides responsive performance for real-time data visualization that web-based alternatives struggle to match. Lightfall is designed for use by beamline scientists and staff operating synchrotron instruments at national user facilities.

Pandolfi, Ronald [Lawrence Berkeley National Labor

Spiking Markov Reward Process v.0.1

SAND2024-11150O The Spiking Markov Reward Process software is a spiking neural network that streams binary arithmetic and computes the state value function of a Markov reward process. The software will be released to the SpiNNcloud group for development of neuromorphic acceleration. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Wang, Felix

Hydrogen Diffusion Through Stainless Steel

SAND2025-14430O Hydrogen Diffusion Through Stainless Steel is a tool that employs a finite difference method algorithm to solve Fick's law and other mass transport models pertinent to the diffusion of hydrogen through stainless steel. Additionally, the software uses particle swarm optimization to determine physical parameters based on experimental data. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Mason, Tyler [Sandia National Lab. (SNL-CA), Liver

EFBMC

SAND2026-23986O EFBMC performs elastic Bayesian model calibration by applying Bayesian statistics and functional analysis. The software provides Python, R, and MATLAB scripts that enable users to calibrate models. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Tucker, J. Derek [Sandia National Lab. (SNL-CA), L

Enterprise Artificial Intelligence Strategy for Los Alamos National Laboratory

In the 1984 martial arts drama film, The Karate Kid, a young Daniel LaRusso is unexpectedly placed in an adversarial environment unable to eYectively adapt to a series of new threats and limitations. Fortunately for the main character, once placed under the tutelage of a Mr. Miyagi, he finds resiliency not through the adoption of new tools, but a re-focused set of fundamentals. Much in the same way that Daniel learns waxing on and buYing oY car wax by hand has rewards for Karate, LANL is choosing the harder path of self-hosting Large Language Models (LLMs) for enterprise use instead of only relying on buying access to a hosted AI service like Azure’s OpenAI Application Programming Interface (API). We also are not willing to wait for software-as-a-service (SAAS) AI services to meet us where we need to be from a FedRAMP accreditation standpoint. Our operations regularly depend on access at CUI, UCNI, ITAR and other FIPS-199 moderate-impact data levels and hosting our own services gives us the right security and compliance posture to be useful across the broad range of our work at LANL. With the rise in threats to critical infrastructure, cloud service providers (CSPs), and supply chain attacks from both state and non-state actors, we are not placing the bet that SAAS hosted AI services will be available when we need them. Should a major event occur, we do not want our staY and operations left without a pathway for us to fix the problem and resume the use of AI tools.

42 ENGINEERING

EVs-at-RISC: A Secure and Resilient Interoperable SCM Control System Architecture for Electric Vehicle’s-at-Scale (Final Technical Report)

The EVs-at-RISC project was a five-year research, development, and demonstration initiative to create foundational tools for utility-scale fleet aggregation and Smart Charge Management (SCM) of Electric Vehicles (EV), Electric Vehicle Charging Infrastructure (EVCI), and related Distributed Energy Resources (DER). Rather than seeking to develop and demonstrate highly perfected SCM algorithms and control strategies, this project instead focused on creating foundational software solutions that enable unprecedented digital interoperability across the communications technologies and vendor platforms used to manage EV , EVCI, and DER, as well as existing energy management infrastructure operated by utilities, grid operators, and aggregators. This project then extends these novel interoperability capabilities to develop and deploy powerful middleware abstractions across grid edge networks and EVCI/DER fleet aggregations incorporating modern software tools and best practices, such as CI/CD, to bring the immense capabilities of infrastructure-as-code and policy-as-code to modern grid edge network environments. This addresses the foremost systemic issues preventing realization of any net operational benefits from scaled deployment of behind-the-meter EV, EVCI, and DER assets in electric power grids and markets today. The results of this approach and project unlock massive potential for new SCM capabilities to be easily prototyped, evaluated, and deployed at-scale within the existing grid edge network infrastructure and EVCI/DER technology ecosystem. The EVs-at-RISC project achieves this by extending Open Field Message Bus (OpenFMB), a conceptual model for digital interoperability and distributed intelligence in traditional front-of-meter utility SCADA networks, validating our hypothesis that OpenFMB could be similarly used to solve systemic digital interoperability issues in behind-the-meter environments and unlock real-world utility-scale SCM capabilities without requiring any new proprietary vendor solutions or significant infrastructure reconfiguration.

24 POWER TRANSMISSION AND DISTRIBUTION

Binder-benchmarking

SAND2025-07593O Binder-benchmarking evaluates the speed and memory impacts of C++, Python, and Matlab code binders. As a repository, it provides a way to locally run computation-based and memory-based benchmark suites on pybind11 and nanobind-based code in a Docker image. The software runs simple-speed and memory benchmarks on primitive navigation and integration exemplar algorithms. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Walker II, Michael [Sandia National Lab. (SNL-CA),