Search NASA⌕ Search

SEARCH · Search NASA

Results for “Critical Infrastructure”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

Smart Charge Management and Vehicle Grid Integration Deep Dive

The U.S. Department of Energy (DOE) Electric Vehicles at Scale Laboratory Consortium (EVs@Scale Lab Consortium) is accelerating research to support the establishment of a secure and scalable national network of charging infrastructure. Critical to this effort is an understanding of the potential grid impacts of EV charging and possible smart charge management (SCM) or vehicle-grid integration (VGI) capabilities that could mitigate these impacts. The EVs@Scale SCM/VGI Pillar is analyzing the impacts of EV charging and developing and demonstrating the capabilities of both SCM and VGI with many different vehicle use cases and grid scenarios. This deep dive discussion of the project encompasses the progress and future plans for the analysis components of the FUSE (Flexible charging to Unify the grid and transportation Sectors for Evs at scale) project.

ADVANCED PROPULSION SYSTEMS↗

Intern Poster: AIBOMs in Automated Defense: Capabilities & Challenges

AI is increasingly used in critical infrastructure, but it's often a “black box” that is difficult to understand. AIBOMs, or AI Bill of Materials, are one way to increase AI transparency and accountability. They can also be used in automated cyber defense. AIBOMs are a new concept with challenges to widespread adoption, but their potential in cybersecurity makes them a worthwhile investment.

99 GENERAL AND MISCELLANEOUS↗

Visualizing a Vulnerability: Its Connections to Hardware and Software

All Hazards Analysis (AHA) is a framework developed by Idaho National Laboratory that provides capabilities to collect, store, analyze, and visualize critical infrastructure information. A core function of AHA is its ability to simulate faults or outages in networks of infrastructure originating from a plethora of causes, ranging from natural disasters to cyberattacks. AHA utilizes Hardware and Software Bills of Material (HBOM and SBOM, respectively) along with Known Exploited Vulnerabilities (KEVs) to document the potential attack vectors for each piece of infrastructure. The objective of this contribution to AHA was to create a visualization tool that could capture the small details held in each individual artifact as well as preserve the large-scale connections that link them together to aid threat modeling.

58 GEOSCIENCES↗

On the Application of Cyber-Informed Engineering (CIE)

The 2023 National Cybersecurity Strategy has recommended a transition to secure-by-design methodologies in critical infrastructure. This paper presents the adoption of the National Cyber-Informed Engineering (CIE) Strategy as initiated by the U.S. DOE’s CESER office, advocating for the integration of cybersecurity at the earliest stages of system design. The strategy targets design engineers responsible for energy infrastructure to embed CIE principles within the engineering lifecycle, thus enhancing cyber resilience. This paper discusses the expansion of secure-by-design concepts to cyber-physical systems, moving beyond traditional IT security to include engineering considerations that can mitigate cyber risks through design choices. The paper introduces Digital Risk Management, balancing traditional cybersecurity with CIE to reduce both likelihood and impact of cyber threats. A set of CIE starter questions derived from 12 core principles is detailed, aiding engineers to consider cybersecurity in their designs and highlights the importance of CIE in anticipating and reducing the impacts of cyber attacks, suggesting that such integration is essential for national security and infrastructure resilience.

42 ENGINEERING↗

Electric Vehicle Supply Equipment Cybersecurity Through Emulation

As the grid evolves, it is paramount to understand the risks that cyberattacks pose before assets are deployed. Leveraging the ARIES Cyber Range, NREL has created a platform to conduct analysis of EV charging protocol cybersecurity to understand the risks and impacts that cyberattacks may pose to critical infrastructure.

bug bounty prize↗

An Old Guys Perspective of Cyber - Journey Through INL Cyber Research

An overview of the history of cybersecurity at INL and how it has evolved with today's Critical Infrastructure, including the advancement of Electric Vehicles (EVs) and the EV charging infrastructure. Recent and future research efforts are included to demonstrate the current state of the art and where this technology might progress. With maybe a little Fear, Uncertainty, and Doubt (FUD) mixed in...

99 GENERAL AND MISCELLANEOUS↗

SCA Tools - SCRM Value Add or Lossy Noise Machines

Software supply chain risk management (SCRM) depends upon accurate information regarding the software components that comprise any given software system. The collection of components included in a software package can be organized within a software bill of materials, or SBOM. SBOMs are ideally generated when the software components are put together, such as at compile time, but for many reasons that has not and is not always possible. For example, legacy or proprietary software packages often do not have SBOMs available to downstream consumers of that software. It’s not just end users that are affected, manufacturers themselves also must deal with this problem. To answer these questions, the market has seen the rise of several commercial software composition analysis (SCA) tools. These tools aim to peer into completed software systems, automatically identifying hidden software dependencies and looking up known vulnerabilities associated with those dependencies to enable end-users to enhance their cyber supply chain risk management processes. These tools are potentially a huge boon to end users of legacy and proprietary software – and a potential bane, depending on how accurate they are. This research asks that question – how accurate are currently available binary SCA tools – and provides answers to several other questions: What does it mean to be “accurate”? What limitations do the tools have in identifying common edge cases that take place in modern software development? Can they help you avoid a devastating supply chain attack, or is it all just noise? After researching SCA tools on the market, we identified three vendors that fit our use case and would provide analysis on compiled binaries. Using these tools, we submitted firmware for critical infrastructure devices for analysis and SBOM generation. The SBOM outputs were then cross referenced with SBOMs generated through manual analysis for comparison. In addition to the firmware samples, we also submitted edge case samples based off a popular open-source library that were specifically crafted to evaluate each tools’ ability to accurately identify components. These samples were customized to be consistent with modifications we have seen in modern software development as well as a couple that are representative of supply chain attacks.

97 MATHEMATICS AND COMPUTING↗

Lessons Learned for Responsible Use of Cloud in the Cirrus Project, Following the CrowdStrike Outage Event

A disruption in CrowdStrike’s Falcon cybersecurity platform on July 19th, 2024, caused worldwide chaos. This event highlights the imperative need for cloud security measures for networks that are critically reliant on cloud technology. This incident negatively impacted air travel, government networks, and critical infrastructure sectors such as hospitals and financial institutions. While no electric utilities had a physical impact, and few had an IT impact, there were issues created by loss of cloud services, and other interrelated industries. For utilities and energy distribution organizations, understanding and mitigating these risks is essential. The Cirrus tool offers a strategic solution engineered to weave cloud integration seamlessly into the fabric of operational management, thereby enhancing resilience and streamlining efficiency in the face of digital challenges.

25 ENERGY STORAGE↗

Pilot-Scale Validation of Distributed Optical Fiber Sensors for Underground Pipeline Monitoring

Distributed fiber optic sensing is a cutting-edge technology that has found extensive applications in the monitoring of Ensuring the safety, integrity, and operational efficiency of underground product pipelines is vital for maintaining the nation’s critical infrastructure. Monitoring parameters such as hoop strain, pressure, and acoustic vibrations is key to detecting potential leaks, intrusions, or structural issues. Distributed optical fiber sensor (DOFS) systems provide a compelling solution for continuous, real-time monitoring over long distances. This paper details the development and pilot-scale implementation of DOFS systems for underground pipeline monitoring, evolving from a proof-of-concept stage. Multiple custom-designed DOFS interrogator units—such as optical frequency-domain reflectometry (OFDR), Brillouin optical time-domain analysis (BOTDA), and multimodal interferometer-based fiber acoustic sensors—were employed to measure key parameters like hoop strain, pressure, and acoustic vibrations. The underground product pipeline's outer diameter is 30 inches, the wall thickness is 1.28 inches, and the 3-foot depth. The fiber deployment strategies, and sensing data acquisition methods for these systems are discussed. The results demonstrate the effectiveness of DOFS in detecting hoop strain, temperature changes, and acoustic vibrations, showcasing their potential for real-time monitoring and enhancing pipeline safety.

distributed fiber sensing↗

Field Programmable Gate Array Data Capture for Control Systems

Some Industrial Control Systems (ICS) networks are based on protocols such as Serial and Industrial Ethernet. These protocols currently have no existing cybersecurity monitoring tools, leaving a large gap in the cyber defense of critical infrastructure. In order to analyze such ICS traffic, it is first necessary to implement methods of capturing the ICS data. Whereas traditional methods of analyzing data would use microprocessors, the nature of high-speed analog data can be difficult to implement on such a versatile processor, as they are rather inefficient for doing a single task. Whereas Field Programmable Gate Arrays (FPGAs) provide an adequate tool in analyzing high speed data, as despite the lack of program versatility, Programmable Logic can implement a solution with minimal clock cycles, allowing time for each new packet of data to be captured before a new data sample is taken.

42 ENGINEERING↗

SECURED: Simulator-Enhanced Control and Understanding of Reactor systems for cyber-Event Defense

The study discusses a learning approach for analyzing cyber-events in reactor systems using integrated hardware and personal computer simulator models. Key points include the rise in cyber-attacks and their sophistication in industrial control systems (ICS), the necessity for awareness, understanding, resource allocation, and preparation to combat these threats, and the digital transformation of old and new nuclear plants, increasing their exposure to cyber threats. It highlights the cyber vulnerabilities of advanced reactor systems, which rely on digital instrumentation and control for operations and safety functions, making them susceptible to cyber-attacks. The approach involves demonstrating reactor system plant ICS cyber-attacks under various operational conditions utilizing tools like simulator models and hardware-based kits. A strategic solution approach tailored to critical infrastructure is emphasized, along with community engagement for public and government support, adopting effective learning approaches, and the preparation for anticipated future challenges. The presentation concludes with a call to action to address challenges, leverage opportunities, and advance through lesson learning in cybersecurity for nuclear energy systems.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

2024 Annual Report Laboratory Directed Research & Development

This is the FY-24 LDRD annual report. The 62 projects concluded in fiscal year 2024, highlighted in this report, represent a glimpse into the extraordinary breadth and depth of leading-edge science, technology, and engineering endeavors ongoing at INL. I invite you to explore this report thoroughly, discovering first-hand how INL's LDRD portfolio not only fosters innovation but also nurtures researcher talent, propelling us closer to realizing our vision of transforming the world's energy future and safeguarding our critical infrastructure.

99 - GENERAL AND MISCELLANEOUS↗

Benchmarking MCNP models to support gamma irradiation experiments

Seismic isolators and damping devices have been used for 30+ years to reduce seismic forces and deployed in 10,000+ structures, including bridges, buildings, and mission-critical infrastructure. Studies have shown that seismic isolation of nuclear power plants can reduce the seismic risk by several orders of magnitude and substantially reduce the overnight capital cost. Advanced reactor developers are considering seismic isolation as an integral design feature in their reactor design. It can either be deployed at the building level, isolating the entire reactor building, or at the component level, isolating individual pieces of safety-class equipment, such as a reactor vessel or a steam generator. For equipment isolation, located close to the reactor vessel, the seismic isolators and/or damping devices may be exposed to gamma and neutron radiation, with a possible effect on their mechanical properties which would affect the response of the isolated equipment under earthquake shaking. The Department of Energy, as part of its Nuclear Energy University Program (NEUP), in collaboration with the Idaho National Laboratory (INL), is funding a project at the University at Buffalo (UB) to investigate the effect of gamma radiation on the mechanical properties of various seismic protective devices. (When isolating equipment, the seismic protective devices will be located outside the reactor vessel where the neutron exposure will be insignificant.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

IEEE PES GM Poster - Cyber-Informed Engineering Approach to Mitigating BESS Supply Chain Concerns

Battery energy storage systems (BESS) are increasingly important to meet the needs of grid resilience and reliability. BESS provide critical grid services, maintaining stability of the grid with increased variable conditions. However, there are significant geopolitical and security concerns regarding their operation in critical infrastructure, due to lack of a domestic supply chain and prevalence of foreign entity of concern (FEOC) components in BESS and associated inverter-based resources. The supply chain challenge is dually exacerbated by a lack of alternative suppliers who can meet the economic targets for energy delivery and a potentially adversarial supply chain. Solutions are needed to secure components, addressing mixed layers of risk and engineering controls. This paper presents a specific application of Cyber-Informed Engineering (CIE) principles for BESS and recommends an alternative strategy to blocking the supply chain, ensuring that grid modernization targets can be met despite lack of a validated or secure supply chain. This study focuses on the United State (U.S.) use case, but the process can be applied globally to address supply chain security challenges. CIE practices represent the next step in functional assurance and risk mitigation, ensuring optimal resource allocation and enhancing security measures to safeguard the future of energy in the U.S. and beyond.

25 - ENERGY STORAGE↗

Encrypted Control Using Modified Learning With Errors-based Schemes

Cyber-physical systems (CPSs) require reliable, safe, and secure control of critical infrastructure, combining computational and networking capabilities, which heighten the risk of cyber attacks. These attacks can disrupt the physical process, causing unforeseen consequences. One solution is the use of fully homomorphic encryption (FHE) to protect the control loop, allowing for secure computations and communications without compromising signal and control system privacy. The challenge with FHE, however, is its requirement for inputs to be integers. This paper introduces a modified Learning With Errors (LWE) FHE approach that encodes control system dynamics and signals into integers. Our proposed scheme leverages a generalized LWE encoding function and modifies the Gentry-Sahai-Waters (GSW) gadget decomposition tool to encrypt the control system. Using the modified LWE scheme, we formalize a fully encrypted control system, supported by simulated results.

42 - ENGINEERING↗

Cyber-Informed Engineering Briefing for ABET

Cyber-Informed Engineering (CIE) is an emerging method to integrate cybersecurity considerations into the conception, design, development, and operation of any physical system, energy or otherwise, to mitigate or even eliminate avenues for cyber-enabled attacks.?CIE concepts use design decisions and engineering controls to prioritize defense against the worst possible consequences of cyberattacks facing critical infrastructure systems and asset owners. These slides offer a deep dive into Cyber-Informed Engineering for engineering educators.

42 - ENGINEERING↗

Intern Poster: STIG Shouldn't Drop ACID

STIG (Structured Threat Intelligence Graph) is an open-source graph database tool from INL. It’s used to create and process cyber intelligence graphs, which are shared in the cyber threat intelligence community and used to train INL machine learning products like @DisCo. For quality machine learning and critical infrastructure defense, STIG’s database must be ACID: Atomic, Consistent, Isolated, Durable. Various ACID tests were designed and applied to STIG to ensure its behavior follows these properties.

99 - GENERAL AND MISCELLANEOUS↗