Search NASASearch

SEARCH · Search NASA

Results for “Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 145 records · Page 8

Quantifying Food Security and Mitigation Risks Consequential to Climate Change Impacts on Crop Yields

Climate change is expected to impact crop yields globally, with some regions benefiting from favorable conditions and CO2 fertilization, while others face adverse effects from altered precipitation and higher temperatures. Changes in crop yields can destabilize the global food system and pose challenges to food security. Moreover, crop production is crucial, as biofuels are becoming increasingly important contributors to climate change mitigation measures aimed at limiting global warming. This study uses the Integrated Model to Assess the Global Environment integrated assessment model framework to analyze different indicators related to food security and climate change mitigation under varying climate change impacts on crop yields. Twelve spatially explicit crop productivity projections were taken from the full archive of the Global Gridded Crop Model Intercomparison of 120 climate-crop model combinations, forced by CMIP6-based climate scenarios. The selection includes two average-performing climate-crop model combinations, two pessimistic combinations that perform one standard deviation below the mean, and two optimistic model combinations that perform one standard deviation above the mean. To single out the effect of climate change on productivity changes, we drew samples from two representative concentration pathways (RCP2.6 and RCP8.5). These productivity projections were applied within an otherwise uniform scenario (SSP2) and analyzed for their effect on total calorie demand, crop prices, and number of people at risk of undernourishment to quantify food security. Risks to climate change mitigation targets were explored by modeling the total bioenergy supply, emissions, and global mean temperature. The results revealed significant differences in the risk of food security and mitigation potential between different regions and climate change scenarios. Across scenarios, the crop area extent can vary up to 2 million km2 due to changing crop yields. The projected change in global hunger ranges from 60 to 160 million undernourished people, indicating uncertainty between climate and crop model combinations. Low-income regions are especially impacted because of their high sensitivity to changes in food prices. Global climate change mitigation ambitions can also deviate by the latter part of the 21st century, as changes in yields will impact biofuel production as well as agriculture, forestry and other land use emissions. The quantitative insights generated by this study highlight the need for global policy efforts to make the agricultural system more adaptive to climate change to handle potential negative impacts.

crop yields

Empowering Critical Infrastructure Communication with Secure 5G Private Networks

With the transformational New Radio- Unlicensed (NR-U), 5G network can be operated with unlicensed and shared spectrum. Private 5G networks without any licensed bands, which are both highly expensive and usually available to only large commercial wireless providers, can now be used for a whole range of new applications including smart factories, warehouses, connected cars and drones. 5G’s support of a) massive machine type communication (mMTC) for a large number of connected devices with b) ultra-reliable low latency communication (URLLC) capability when needed, and c) up to 20 times higher data rate with enhanced mobile broadband (eMBB) than previously available, enables new and powerful capabilities in a wireless network. While these capabilities are transformational, necessary security and reliability requirements have to be satisfied when used in critical infrastructure such as factories, power plants, water systems, ports, and other industrial facilities. 5G standards have introduced significant security improvement over 4G/LTE as well as mitigations for new attack surfaces created by changes in the 5G network. This talk will discuss these security improvements and whether they meet the security properties required for mission critical communication over wireless.

5G

Enabling Dynamic Probabilistic Risk Assessment of Physical Security Using EMRALD and MAAP (Presentation)

The optimization of physical security in nuclear power plants requires sophisticated methodologies that integrate operator actions and plant behavior through advanced simulation tools. Idaho National Laboratory has developed the Modeling and Analysis for Safety and Security using the Dynamic EMRALD Framework (MASS-DEF) methodology, an approach that integrates force-on-force simulations, dynamic probabilistic risk assessment, and thermal hydraulics modeling to enhance security planning while reducing costs. A reduced order model for thermal hydraulic simulations performed by the Modular Accident Analysis Program (MAAP) was developed to evaluate reactor core behavior during attack scenarios. MAAP simulations are computationally intensive and must be run in a secure environment, complicating analysis and validation. By pre-computed scenario outcomes for a small number of modified parameters, the reduced order model significantly decreases the computational cost and enables offsite review of the results.

22 - GENERAL STUDIES OF NUCLEAR REACTORS

Enabling Dynamic Probabilistic Risk Assessment of Physical Security Using EMRALD and MAAP

The optimization of physical security in nuclear power plants requires sophisticated methodologies that integrate operator actions and plant behavior through advanced simulation tools. To address this, Idaho National Laboratory [JL2.1]has developed the Modeling and Analysis for Safety and Security using the Dynamic EMRALD Framework (MASS-DEF) methodology, an approach that integrates force-on-force simulations, dynamic probabilistic risk assessment, and thermal-hydraulics modeling [JL3.1]to enhance security planning while reducing costs. We developed a tool that produces reduced order models using thermal hydraulic simulations from the Modular Accident Analysis Program (MAAP) [1]. These models can quickly evaluate reactor core behavior during attack simulations, and in so doing, address two barriers of traditional methods: (1) MAAP simulations are computationally intensive, and (2) attack scenarios must be run in a secure environment, which complicates analysis and validation. By precomputing scenario outcomes for a small number of modified parameters, the reduced order model significantly decreases the computational cost and enables offsite review of the results.

22 - GENERAL STUDIES OF NUCLEAR REACTORS

Managing information technology security risk

Information Technology (IT) Security Risk Management is a critical task for the organization to protect against the loss of confidentiality, integrity and availability of IT resources. As systems bgecome more complex and diverse and and attacks from intrusions and malicious content increase, it is becoming increasingly difficult to manage IT security risk. This paper describes a two-pronged approach in addressing IT security risk and risk management in the organization: 1) an institutional enterprise appraoch, and 2) a project life cycle approach.

security toolset

Integrating science for water security governance

Hydrological extremes are intensifying globally, increasing the complexity of decisions required to ensure water security. Advances in hydrological science, modeling, and data systems have expanded the technical frontier of water research, yet uptake of scientific insights in policy and management decisions remains limited. This persistent science–policy gap is not primarily a failure of knowledge generation or robustness, but an institutional challenge shaped by how scientific and governance systems are organized, coordinated, and connected to support the effective use of scientific knowledge. These challenges are particularly pronounced in multi-level and transboundary water governance, where decisions span jurisdictions and require coordination across institutional and political boundaries. We synthesize research at the science–policy interface and evidence from water security initiatives to show how institutional arrangements, scientific tool development, and research practices enable or constrain the sustained use of scientific knowledge in water-security governance processes. Building on these insights, we develop ‘shared decision infrastructure’ as a framing to describe how scientific knowledge is embedded within the institutional, relational, and procedural arrangements that connect science to decision-making processes over time. We translate this framing into a practical intervention roadmap centered on institutional design, tool translation, sustained co-production, and outcome-oriented evaluation to support the integration of science into ongoing governance processes. By positioning science as shared decision infrastructure, the roadmap clarifies how researchers can design scientific efforts that support more coordinated, accountable, and adaptive water security decisions amid deepening uncertainty.

M whitney, Kristen [NASA Goddard Space Flight Cent

Security constrained optimal power shutoff for wildfire risk mitigation

Abstract Electric grid faults are increasingly the source of ignition for major wildfires. To reduce the likelihood of such ignitions in high risk situations, utilities use preemptive de‐energization of power lines, commonly referred to as Public Safety Power Shutoffs (PSPS). Besides raising challenging trade‐offs between power outages and wildfire safety, PSPS removes redundancy from the network at a time when component faults are likely to happen. This may leave the network particularly vulnerable to unexpected line faults that may occur while the PSPS is in place. Previous works have not explicitly considered the impacts of these outages. To address this gap, the Security Constrained Optimal Power Shutoff problem is proposed which uses post‐contingency security constraints to model the impact of unexpected line faults when planning a PSPS. This model enables, for the first time, the exploration of a wide range of trade‐offs between both wildfire risk and pre‐ and post‐contingency load shedding when designing PSPS plans, providing useful insights for utilities and policy makers considering different approaches to PSPS. The efficacy of the model is demonstrated using the EPRI 39‐bus system as a case study. The results highlight the potential risks of not considering security constraints when planning PSPS and show that incorporating security constraints into the PSPS design process improves the resilience of current PSPS plans.

29 ENERGY PLANNING, POLICY, AND ECONOMY

Small-Scale Irrigation: Improving Food Security under Changing Climate and Water Resource Conditions in Ethiopia

We develop a new systems modeling tool that integrates knowledge from hydrology, agriculture, and economics to understand the effect of small-scale irrigation on food security and groundwater sustainability in Ethiopia. Irrigation is an effective tool to mitigate climate impacts and improve agricultural yields. Small-scale irrigation, such as decentralized groundwater irrigation, is well suited for developing countries where smallholder farming communities are widely dispersed and can only afford small infrastructure investment. We study the underlying interdependencies between food and water systems in Ethiopia, where small-holder agriculture is the foundation of the nation’s economy and climate variability has led to great challenges to its food security. Our coupled market and crop model with groundwater module captures the interdependencies of climate, water availability (including irrigation), crop yield, farmland allocation, crop production, transport and consumption based on a system approach across multiple spatial scales. We study the implication of small-scale irrigation to Ethiopia’s food security and water resource conditions as a “what-if” question by comparing an irrigation scenario to the calibrated baseline in 2015, a year of significant drought and crop failure over a large portion of Ethiopia. Our model offers fresh insights into geographic disparities in outcomes that are driven by baseline climate variability, soil fertility, and market conditions. In general, we find that small-scale irrigation can potentially improve food security through increases in food consumption, but it requires policy support to direct the increases of production to domestic consumption while maintaining a sustainable groundwater condition. By using Ethiopia as an example, we show the strength of our model to study how water infrastructure resources support critical functions and service in water and food systems.

Zhang, Ying

Towards Automatically Matching Security Advisories to CPEs: String Similarity-based Vendor Matching

When a vulnerability is reported by the National Vulnerability Database (NVD), affected products are listed in the structured Common Platform Enumeration (CPE) format. Unfortunately, if the vulnerability is in a software library (e.g., Log4j), it will not include CPEs for each product containing that library. In these cases, security operators need to manually read the vendor's or third-party security advisories to see if their product is affected. However, these advisories do not report affected products in a structured format, which prevents automated processing, This paper makes the first effort towards automatically constructing structured CPEs for the vulnerable products in a non-NVD security advisory from the unstructured data in the advisory. Since this is a very challenging problem, this paper specifically focuses on the initial but key step of matching the un-structured vendor names in security advisories to the structured vendor representations in the standard CPE format. We explore the feasibility of using string similarity to solve the problem. The basic idea is to compare a vendor name from the non-NVD advisory with each vendor in the official CPE dictionary. The CPE vendor with the highest similarity score to the advisory's vendor will be considered as the match. We first conduct an experimental, comparative study of multiple mainstream string similarity metrics for this matching problem. To improve the performance, we then design a new string similarity metric that is adapted from an existing metric by weighing different tokens in the advisory's vendor name differently.

McClanahan, Kylie

Secure and Privacy Aware Data Sharing Approach for Smart Electric Vehicles

The integration of smart electric vehicles (SEVs) into smart cities marks a significant step toward creating efficient, sustainable, and connected urban spaces. However, secure and private data sharing is a major challenge as SEVs connect with smart city systems. The interaction between SEVs and consumer electronic devices (CEDs) raises serious concerns about data security and privacy. Here, to address these challenges, this article presents how blockchain technology and federated learning (FL) can address these issues. The proposed approach provides a secure and privacy-aware framework for data exchange between SEVs and CEDs in smart cities. The experiment results demonstrate the effectiveness of the proposed framework for secure data sharing and maintaining system reliability in smart city environments. It also enables trust and promotes the widespread adoption of interconnected urban technologies.

Das, Debashis [Meharry Medical College, Nashville,

Advanced Reactor Safeguards & Security 2024 Program Roadmap

The Advanced Reactor Safeguards and Security (ARSS) program was established to provide research support addressing near term challenges that advanced nuclear reactor vendors face in meeting domestic Material Control and Accounting (MC&A), Physical Protection System (PPS), and Cybersecurity requirements for U.S. construction. The technical work in the program is meant to (1) support nuclear reactor vendors with advanced MC&A, PPS, and Cybersecurity designs for next generation reactors, (2) provide technical bases for the regulator, and (3) promote the integration of Safeguards and Security by Design early in the design process. Existing domestic regulations for safeguards and security, as outlined in the Code of Federal Regulations, were written for large light water reactors, and rule-making efforts are underway to develop regulations more suited to different reactor designs. The ARSS program seeks to remove roadblocks in the deployment of new and advanced reactors by solving regulatory challenges, reducing safeguards and security costs, and utilizing the latest technologies and approaches for robust plant monitoring and protection. This roadmap discusses the goals of the ARSS program, current research, and program plan for the next five years.

22 GENERAL STUDIES OF NUCLEAR REACTORS

Field Programmable Gate Array-Based Reactor Protection Systems and Potential for Inclusion of Secure Elements to Improve Cybersecurity

For acceptable implementations of technologies like wireless communications, remote monitoring, etc., strong mitigations must be developed and evaluated to ensure that new attack pathways do not increase risk for Advanced Reactors. Secure Elements can be adopted and adapted for this purpose based on tamper resistance and cryptographic abilities, but research must be done to properly integrate into critical components such as FPGA-based Important to Safety systems in conjunction with current and future regulations on cyber security features in Advanced Reactors. Typically, the integration of a Secure Element happens during the POST and UEFI boot of a computing platform, performed by the Operating System, which is not possible with FPGAs because they do not include these firmware components. Work must be done to identify a reliable and secure method for integration in FPGA-based systems which lack Operating Systems and therefore complex boot procedures, system calls, etc.

97 MATHEMATICS AND COMPUTING

Field Programmable Gate Array-Based Reactor Protection Systems and Potential for Inclusion of Secure Elements to Improve Cybersecurity

For acceptable implementations of technologies like wireless communications, remote monitoring, etc., strong mitigations must be developed and evaluated to ensure that new attack pathways do not increase risk for Advanced Reactors. Secure Elements can be adopted and adapted for this purpose based on tamper resistance and cryptographic abilities, but research must be done to properly integrate into critical components such as FPGA-based Important to Safety systems in conjunction with current and future regulations on cyber security features in Advanced Reactors. Typically, the integration of a Secure Element happens during the POST and UEFI boot of a computing platform, performed by the Operating System, which is not possible with FPGAs because they do not include these firmware components. Work must be done to identify a reliable and secure method for integration in FPGA-based systems which lack Operating Systems and therefore complex boot procedures, system calls, etc.

22 GENERAL STUDIES OF NUCLEAR REACTORS

Report series: finding of effect and mitigation documentation for the mercury solar photovoltaic array and battery energy storage system, area 23, nevada national security site, nye county, nevada

The U.S. Department of Energy (DOE), National Nuclear Security Administration Nevada Field Office (NNSA/NFO) proposes to install solar photovoltaic (PV) power generation arrays and an associated battery energy storage system (BESS) for the town of Mercury at the Nevada National Security Site (NNSS) in Nye County, Nevada (Figure 1). The purposes of the development of this facility are to support long-term efforts to modernize Mercury and to provide energy-resilient infrastructure and address climate adaptation needs. Because it is within the boundary of the Mercury Historic District (MHD), it is subject to the terms of the Programmatic Agreement Between the National Nuclear Security Administration Nevada Field Office and the Nevada State Historic Preservation Officer Regarding Modernization and Operational Maintenance of the Nevada National Security Site, at Mercury in Nye County, Nevada (hereafter referred to as the Mercury PA). An identification and evaluation report prepared for this undertaking determined that a contributing element to the MHD, the Mercury airstrip (26NY15777), is within the APE (Haynes 2024). The Mercury airstrip was developed following the closure of Camp Desert Rock in 1957 and used until late 1963 or 1964 when the Camp Desert Rock Airport was renovated, and the Mercury Bypass road constructed. The town of Mercury and the immediate surrounding area have been determined eligible for listing in the National Register of Historic Places (NRHP) as the MHD (SHPO Resource No. D230) under Criteria A and C for its importance in supporting nuclear testing and scientific research from 1951 through 1992 (Reed 2019). Originally recorded in 2016, 26NY15777 was determined individually not eligible for listing in the NRHP because it lacked sufficient integrity to convey its significance (Palmer 2016). It was subsequently determined in 2018 to be a contributing element of the MHD in an architectural survey of the district (Palmer 2018) and identified in Appendix C of the Mercury PA as a Category I contributing element. However, as per Stipulation IV.B.2, because the airstrip had already been formally evaluated and determined not to be individually eligible for the NRHP in consultation with the SHPO, this categorization was an error. NNSA/NFO reported this to the SHPO in Haynes 2024 and the SHPO concurred on June 11, 2024 (Reed). Accordingly, the airstrip is a Category II Property for the purposes of complying with the Mercury PA. The Mercury airstrip is a historic property for the purposes of compliance with Section 106 of the National Historic Preservation Act (NHPA) and subject to the stipulations of the Mercury PA.

25 ENERGY STORAGE

Security-by-Design: Light Water Small Modular Reactor

The growing demand for nuclear power is increasing pressure to find solutions to cost prohibitive requirements of both construction and security. Offsite response has been proposed as an option to reduce costs associated with training and maintaining an onsite response force. A previous report explored this option and revealed that security could be provided at the required level, but cost savings was not a result of this methodology. An offsite response strategy required costly active and passive delay barriers to provide sufficient time for responders to muster and deploy to a site in time to interrupt a determined and well-equipped adversary. Also, contrary to the hypothesis, the number of responders required for this strategy exceeded that needed for an onsite response force, as the adversaries could avail themselves of advantageous positions within the facility to repel arriving responders. This report builds upon the previous evaluation by using the same hypothetical light water small modular reactor (LWSMR) facility model, but this time an onsite response strategy was assessed. The goal of this analysis was to show that an onsite response strategy could be implemented effectively at a cost point that removes barriers within the industry at this critical time of growth and development. The assessment of the facility design and response strategy was completed through modeling using Scribe3D© and subsequent scenario analysis over the course of a two-day tabletop exercise. Subject matter experts in nuclear security, nuclear facility design, and response strategy and tactics contributed to the effort to ensure accurate representation of hypothetical scenarios. Several adaptations were made to the layout of the LWSMR based on lessons learned during the first day of scenario analysis. The subsequent design evaluated on the second day proved to provide a robust response posture against a large and well-trained adversary force. This report details the process of the analysis and compares the cost of the final facility design with that of the LWSMR model used for evaluation of offsite response. Ultimately, the results of this effort indicate that, when implemented correctly, an onsite response strategy is the best option from a security and cost perspective.

22 GENERAL STUDIES OF NUCLEAR REACTORS

Blueprint: Open Worldwide Application Security Project Top 10 Common Weakness Enumerations for Electric Vehicle Supply Equipment

This report categorizes the top 10 security weaknesses in electric vehicle supply equipment (EVSE) using a similar approach by the Open Worldwide Application Security Project (OWASP) Top 10, and it describes example exploitations, methods for prevention, and related common weakness enumerations (CWEs) for each category. The weaknesses listed in this report could lead to security issues or vulnerabilities in EVSE if they are exploited by an attacker to compromise the confidentiality, integrity, or availability of a system. This report also recommends EVSE industry best practices and remediations for the identified weaknesses to use as guidelines for their secure products and systems.

33 ADVANCED PROPULSION SYSTEMS

Securing Grid Communications Infrastructure: Addressing Gaps Beyond NERC CIP Facility Perimeters

The North American electric grid relies on a complex communications infrastructure that extends beyond facility perimeters traditionally covered by NERC Critical Infrastructure Protection (CIP) standards. While CIP requirements have significantly strengthened cybersecurity within Electronic Security Perimeters, many operational communications—such as those between control centers, substations, and third-party networks—fall outside current regulatory scope. As grid modernization introduces new technologies and connectivity models, these external pathways present evolving security challenges. This brief explores the nature of these challenges, including emerging attack vectors and supply chain considerations, and highlights how ongoing grid transformation increases exposure to sophisticated threats. It outlines practical strategies and policy options to complement existing standards, such as expanding secure communications practices, enhancing supply chain transparency, and fostering collaboration among federal, state, and industry stakeholders. Near-term actions like encryption, authentication, and contractual safeguards can help reduce risk while longer-term frameworks are developed to ensure resilient and secure grid operations.

24 - POWER TRANSMISSION AND DISTRIBUTION

FY25 Electric Grid Security Annual Report

Sandia’s Electric Grid Security program advances a national vision of energy dominance and accessibility, while applying our national security -emphasis on ensuring of a secure, resilient, and affordable electric system for all users. Our achievements reflect a strategic approach combining technology development; modeling, simulation, and data analytics; and partnered demonstrations and outreach to further the adoption of advanced grid and storage technologies. Our FY25 efforts leverage the strengths of our partnerships—spanning Sandia’s core science and technology competencies as well as external technology leaders—to develop the solutions today which enable the grid of tomorrow. Key accomplishments in this report that support our strategy span our technical program areas and include: • New open-source analytical tools for systems -level planning and optimization, including significant advances to the QuESt analytical environment; • Further advancement of artificial intelligence and machine learning to enhanced grid operations and planning as we rise to the challenge of new large loads; • Development of solid-state power conversion technologies and a new medium-voltage research lab; • New technologies to assess wildfire vulnerabilities and mitigate potential impacts; • Advanced applications of new cybersecurity technologies with industry partners; • Contributions to understanding the impacts of electromagnetic pulses and geomagnetic disturbances on grid components; and • Digital twin development for hybrid microgrids with multiple generators, storage, and loads. This report indicates key areas of research and engagement and summarizes the impact of Sandia’s contributions through notable accomplishments, journal publications, patents, and technical conferences and presentations. It is provided with the hope that readers discover ways we can further team to create our modern grid and apply the outcomes of our efforts. The bulk of work described herein is funded by several offices within the U.S. Department of Energy (USDOE), including the Office of Electricity (OE); Cybersecurity, Energy Security, and Emergency Response (CESER); former offices such as the Office of Energy Efficiency and Renewable Energy (EERE), the Grid Deployment Office (GDO), the Office of Clean Energy Demonstrations (OCED), and other key programs at USDOE. As we continue to state in these annual reports, the contributors to our successes are too numerous to name here, though our team wishes to express our deep gratitude to the numerous program and project sponsors at the US Department of Energy, who often function equally as technical collaborators; our many partners in industry, academia, utilities, and other national labs; and fellow researchers and business partners at Sandia whose leadership and creativity have enabled the accomplishments described herein.

24 POWER TRANSMISSION AND DISTRIBUTION