Search NASA⌕ Search

SEARCH · Search NASA

Results for “information security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 145 records · Page 8

Cyber-Informed Engineering Adoption in University Engineering Programs: An Overview of CIE Integration Successes at Nine U.S. Educational Institutions

This report examines the adoption of Cyber-Informed Engineering (CIE) in university engineering programs, driven by the need to protect critical energy infrastructure from adversarial threats. CIE equips current and future engineers and technicians with the necessary mindset, skills, and competencies to enhance the resilience of engineered systems against cyber attacks. This report highlights nine academic partners who are incorporating CIE into their curricula through various approaches, including lectures, courses, and certificates.

42 ENGINEERING↗

A Computational Review of Privacy-Preserving Mechanisms for the Smart Grid

Smart grid technologies have rapidly become one of the largest and most comprehensive sources of data for the modern utility. For the most part, data streams are seen as an essential tool that enable utilities to carry their day-to-day business operations, but they also create the need for efficient and secure data management strategies. In the context of the smart grid, ensuring data privacy is becoming an increasing concern due to a combination of factors that range from shifts in operational paradigms and rapid technology evolution to changes in legislation. Furthermore, researchers have highlighted the risks associated with improperly protected energy records. For example, energy consumption data from homes could be used to infer the behaviors and habits of home occupants through activity recognition or user profiling (Fan, 2017), which may lead to unfair service pricing, targeted advertising, or other personal security violations. Similarly, Electric Vehicles’ (EVs) charging metadata could be used to reveal private information about the owner such as their payment methods, preferred charging stations, and other locational and timing information that could be used to reconstruct the vehicle owner’s behaviors. The privacy of user data, even when used for statistical analysis or machine learning training processes, also needs to be carefully considered, as an individual’s private traits may still be vulnerable if their inclusion/exclusion greatly impacts the result or could be linked to a public dataset through cross-reference. The breach of user privacy also has severe impacts for organizations that store, transmit, or work on the data in the form of diminishing the public’s trust in them while potentially incurring legal consequences (e.g., fines and suspensions under the European Union General Data Protection Regulation, Health Insurance Portability and Accountability Act, etc.). Because of these risks, several privacy-preserving mechanisms are available to help organizations comply with privacy legislations and prevent the unauthorized and malicious use of user data. In light of these concerns, this report focuses on performing a computational review of privacy-preserving mechanisms that have received a significant amount of interest in literature. It specifically focuses on 1) homomorphic encryption, 2) zero-knowledge proofs, 3) differential privacy, and 4) federated learning. It is worth noting that although many of the methods presented in this document rely on cryptographic primitives, their intent is not to provide perfect secrecy, but rather to enable users to maintain privacy, and thus they shall not be compared or equated to other constructs that are aimed to address cybersecurity constructs.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Harnessing large language models’ zero-shot and few-shot learning capabilities for regulatory research

Abstract Large language models (LLMs) are sophisticated AI-driven models trained on vast sources of natural language data. They are adept at generating responses that closely mimic human conversational patterns. One of the most notable examples is OpenAI's ChatGPT, which has been extensively used across diverse sectors. Despite their flexibility, a significant challenge arises as most users must transmit their data to the servers of companies operating these models. Utilizing ChatGPT or similar models online may inadvertently expose sensitive information to the risk of data breaches. Therefore, implementing LLMs that are open source and smaller in scale within a secure local network becomes a crucial step for organizations where ensuring data privacy and protection has the highest priority, such as regulatory agencies. As a feasibility evaluation, we implemented a series of open-source LLMs within a regulatory agency’s local network and assessed their performance on specific tasks involving extracting relevant clinical pharmacology information from regulatory drug labels. Our research shows that some models work well in the context of few- or zero-shot learning, achieving performance comparable, or even better than, neural network models that needed thousands of training samples. One of the models was selected to address a real-world issue of finding intrinsic factors that affect drugs' clinical exposure without any training or fine-tuning. In a dataset of over 700 000 sentences, the model showed a 78.5% accuracy rate. Our work pointed to the possibility of implementing open-source LLMs within a secure local network and using these models to perform various natural language processing tasks when large numbers of training examples are unavailable.

Biochemistry & Molecular Biology↗

Integration of the NCRC Database and Other INL Databases

The Nuclear Computational Resource Center provides a portal by which industry professionals, educational staff, students, national laboratory employees, and others may request access to certain engineering software tools. As the tools provided through the Nuclear Computational Resource Center portal are not open-source and freely available, a set of approvals are necessary before access is granted. All code recipients must be associated with an institution that has a license with Idaho National Laboratory for the code requested. Information about these licenses is controlled by Idaho National Laboratory’s Technology Deployment organization and housed in a Technology Deployment database. Those requesting code access who are not citizens of the United States must also have a security plan, mandated by Idaho National Laboratory policy. Security plans are managed by the International Access Program and are stored in an International Access Program database known as IFacts. Granting access to software thus depends on information stored in the Technology Deployment database and IFacts. In the past, no connection between the Nuclear Computational Resource Center portal and these databases existed, making checking the status of license agreements and security plans time consuming and error prone. This report demonstrates that the Nuclear Computational Resource Center portal now connects to both the Technology Deployment database and IFacts, greatly improving the ease of use of the Nuclear Computational Resource Center system for administrators, which leads to a better overall experience for those requesting code access.

99 GENERAL AND MISCELLANEOUS↗

The Meaning of Risk for Safety, Security, and Safeguards in the Design of Advanced Nuclear Reactors

What is the meaning of risk as it applies to the design of advanced reactors in the disciplines of safety, security, and safeguards? How can we find common terminology for the concept of risk and how can we find interfaces between these disciplines? These are important questions that should be explored in order that they may be applied in an integrated manner for the most effective and efficient design approaches. Eliminating or minimizing risks is a key design driver that motivates and informs the development of nuclear reactors. For safety, risk is well understood and applied in Probabilistic Risk Assessments. For security, the risk-based concepts of vulnerability assessments and vital areas are all considered in designing security systems. For safeguards, the concept of risk is not formally defined, as it relates to the design and operation of nuclear reactors. International nuclear safeguards seek to reduce the risk of proliferation in the nuclear fuel cycle and as such the concept of risk does exist. Therefore, the current understanding of the “3S’ approach, which seeks to find the interfaces and conflicts between safety, security, and safeguards requires a thorough understanding of the role that the reduction of risk plays in all three disciplines. The intersection of risk for safety and security is now being developed as there is a strong correlation between reactor design and operations and their vulnerability to sabotage. The intersection of risk for security and safeguards has to date chiefly been focused on the nuclear material control and accounting systems, which are relied on by both the operator (State) and the IAEA. This paper explores the concept of risk in each of the three disciplines, how they interact, potential conflicts and interfaces , how these might be addressed and leveraged, and a notional framework for how this could be achieved.

Kovacic, Donald N↗

Utilizing AI and Spatial Data to Identify & Rapidly Disseminate Energy Infrastructure Insights

GeoGov Summit Final Presentation entitled "Utilizing AI and Spatial Data to Identify & Rapidly Disseminate Energy Infrastructure Insights". Maintaining the integrity of energy infrastructure plays a critical role in ensuring energy security. Robust foundational AI models using data from federal, state, industry, and other sources can help address integrity risk management & mitigation issues as well as evaluate extended use strategies. Trusted foundational models can help with industry adoption and accelerate innovation by enhancing integrity predictions, reduce costs, and informing infrastructure build-out. Coordination, collaboration & data sharing to develop robust models to aid in: Optimizing operations; Minimizing costs; Ensuring energy security.

Advanced Infrastructure Integrity Model (AIIM)↗

A Quantum Leap for Dynamic Radiography

Dynamic radiography techniques have been instrumental in advancing the National Nuclear Security Administration's (NNSA) mission since WWII. This paper explores the transformative potential of quantum information science (QIS) to revolutionize dynamic radiography through enhanced image processing, tomographic reconstruction, statistics and uncertainty quantification (UQ), and artificial intelligence integration. By leveraging quantum algorithms to extract previously inaccessible information from existing datasets, this interdisciplinary approach promises unprecedented insights at the intersection of dynamic imaging, artificial intelligence, and quantum information technologies.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Closure Report for Corrective Action Unit 116: Area 25 Test Cell C Facility, Nevada National Security Site, Nevada with ROTC-1

CR loaded to this OSTI record. Just adding new file which includes CR plus new ROTC 1 and update the metadata to the following: This Closure Report (CR) presents information supporting closure of Corrective Action Unit (CAU) 116, Area 25 Test Cell C Facility. This CR complies with the requirements of the Federal Facility Agreement and Consent Order (FFACO) that was agreed to by the State of Nevada; the U.S. Department of Energy (DOE), Environmental Management; the U.S. Department of Defense; and DOE, Legacy Management (FFACO, 1996 [as amended March 2010]). CAU 116 consists of the following two Corrective Action Sites (CASs), located in Area 25 of the Nevada National Security Site: (1) CAS 25-23-20, Nuclear Furnace Piping and (2) CAS 25-41-05, Test Cell C Facility. CAS 25-41-05 consisted of Building 3210 and the attached concrete shield wall. CAS 25-23-20 consisted of the nuclear furnace piping and tanks. Closure activities began in January 2007 and were completed in August 2011. Activities were conducted according to Revision 1 of the Streamlined Approach for Environmental Restoration Plan for CAU 116 (U.S. Department of Energy, National Nuclear Security Administration Nevada Site Office [NNSA/NSO], 2008). This CR provides documentation supporting the completed corrective actions and provides data confirming that closure objectives for CAU 116 were met. Site characterization data and process knowledge indicated that surface areas were radiologically contaminated above release limits and that regulated and/or hazardous wastes were present in the facility. The Record of Technical Change 1 updated the use restriction information.

54 ENVIRONMENTAL SCIENCES↗

Grid Communications Supply Chain & Emerging Regulation Challenges Session 1

The TADA Grid Communications Workshops are designed to strengthen cybersecurity and digital assurance across the energy sector by focusing on secure deployment and management of grid communications technologies. These workshops bring together state energy offices, utilities, and technology suppliers to explore the intersection of communications infrastructure, supply chain risks, and emerging regulatory requirements. Participants will apply Cyber-Informed Engineering (CIE) principles to reduce risks in communications systems, engage with INL’s procurement guidance, and explore future tools. Through scenario-based exercises and peer exchange, attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their grid communications projects. The workshops also help participants navigate evolving regulatory frameworks such as FEOC rules in the OBBB, NERC CIP-013, and NDAA 2024, while identifying compliance gaps in mixed-technology environments. A key outcome is the formation of a practitioner network with ongoing access to INL expertise and resources, fostering long-term resilience in the digital energy ecosystem.

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

Grid Communications: Digital Assurance and Supply Chain Challenges and Emerging Regulation Session Two

The TADA Grid Communications Workshops are designed to strengthen cybersecurity and digital assurance across the energy sector by focusing on secure deployment and management of grid communications technologies. These workshops bring together state energy offices, utilities, and technology suppliers to explore the intersection of communications infrastructure, supply chain risks, and emerging regulatory requirements. Participants will apply Cyber-Informed Engineering (CIE) principles to reduce risks in communications systems, engage with INL’s procurement guidance, and explore future tools. Through scenario-based exercises and peer exchange, attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their grid communications projects. The workshops also help participants navigate evolving regulatory frameworks such as FEOC rules in the OBBB, NERC CIP-013, and NDAA 2024, while identifying compliance gaps in mixed-technology environments. A key outcome is the formation of a practitioner network with ongoing access to INL expertise and resources, fostering long-term resilience in the digital energy ecosystem. This is Session 2 of 3 (Full Version).

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

Grid Communications: Cybersecurity and Supply Chain Challenges and Emerging Regulation Session Three

The TADA Grid Communications Workshops are designed to strengthen cybersecurity and digital assurance across the energy sector by focusing on secure deployment and management of grid communications technologies. These workshops bring together state energy offices, utilities, and technology suppliers to explore the intersection of communications infrastructure, supply chain risks, and emerging regulatory requirements. Participants will apply Cyber-Informed Engineering (CIE) principles to reduce risks in communications systems, engage with INL’s procurement guidance, and explore future tools. Through scenario-based exercises and peer exchange, attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their grid communications projects. The workshops also help participants navigate evolving regulatory frameworks such as FEOC rules in the OBBB, NERC CIP-013, and NDAA 2024, while identifying compliance gaps in mixed-technology environments. A key outcome is the formation of a practitioner network with ongoing access to INL expertise and resources, fostering long-term resilience in the digital energy ecosystem. This is Session 3 of 3 (Full Version).

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

Renewable Energy and Storage Cybersecurity Research (RESCue) Pilot Final Report

The Renewable Energy and Storage Cybersecurity Research (RESCue) project is a collaborative effort aimed at securing the rapidly growing deployment of distributed energy resources (DERs) and transmission-connected hybrid renewable energy systems against escalating cyber threats. This project brings together major original equipment manufacturers (OEMs) of wind, solar, and energy storage, along with major asset owners and DOE National Laboratories, to collectively identify cyber threats, assess risks, and develop robust cybersecurity strategies and solutions. This publication the final report for the first year of the project.

24 POWER TRANSMISSION AND DISTRIBUTION↗

ARCADE Technical Pathway and Industry Impact

The Advanced Reactor Cyber Analysis and Development Environment (ARCADE) simplifies the evaluation and assessment of robustness factor and cyber resilience that support secure-by-design for advanced reactor nuclear power plants. In this manner, ARCADE supports risk-informed performance based (RIPB) evaluations of cybersecurity through its integration of plant physics with high-fidelity emulations of control systems. This cross domain approach enables comprehensive analysis of control system sensitivities, cyber-attack scenarios, and their consequences. ARCADE has been custom developed to meet the demands identified in Tier 1 of the Tiered Cyber Analysis (TCA) as outlined in NRC Draft Regulation Guide (RG) 5.96, which provides a RIPB cybersecurity approach for new reactors.

97 MATHEMATICS AND COMPUTING↗

Best Practices for Resilience Hub Development and Management

The Carbon League and its community partners in East St. Louis, Illinois, have identified five facilities to serve as resilience hubs. These hubs are intended to support the local community through a range of services and resources during blue-sky (everyday), gray-sky (pre-event), and black-sky (emergency) conditions. Transforming these facilities into fully functional resilience hubs requires a broad operational improvement and programmatic planning roadmap. This memo outlines best practices to guide the development of these resilience hubs in East St. Louis, including recommendations for infrastructure services; safety and physical protection; community services; operational protocols; and a phased implementation strategy aligned with realistic funding and capacity constraints. Infrastructure recommendations include strengthening electric power, communications, water, sanitation, and transportation/logistics capabilities, all of which are essential for hubs that may serve as cooling and warming centers, distribution points, and information hubs during emergencies. Safety recommendations focus on accessibility, emergency action planning, indoor air quality, and secure storage of critical equipment. A phased roadmap provides guidance from immediate, low-cost readiness actions to long-term optimization and community integration. Performance metrics and maintenance protocols ensure continuous improvement and operational readiness. This guidance draws on best practices that can be used to support the development of resilient, community-centered hubs capable of enhancing public safety, health, and well-being during everyday operations and emergencies alike.

99 GENERAL AND MISCELLANEOUS↗

Cyber Informed Engineering (CIE) Principles Slide Presentation [Slides]

This document describes the concept and application of Cyber-Informed Engineering (CIE), a methodology that integrates cyber threat awareness into all stages of the systems engineering life cycle. It delineates how CIE enhances the security posture of critical infrastructure systems, which are increasingly targeted by sophisticated cyber threats. The exposition proceeds to methodically walk through the twelve foundational principles of CIE, each serving as a strategic guidepost for embedding cybersecurity into the fabric of system design, development, operation, and maintenance. The principles highlight the importance of proactive and comprehensive security measures that span from risk assessment to continuous improvement, ensuring that systems are not only designed with security in mind but are also resilient in the face of evolving cyber threats.

42 ENGINEERING↗

ARC-100 Reactor Security-by-Design Summary

This report applies the security-by-design methodology developed in a previous National Nuclear Security Administration–sponsored work to the Advanced Reactor Concepts 100 (ARC-100) sodium-cooled fast reactor (SFR) design. The report contains no proprietary information specific to the ARC 100 reactor. The insights developed in this report are high-level, and generally applicable to other sodium fast reactor designs. The information presented here is the result of a qualitative safety-based analysis and would not inform any potential adversary beyond what would be found in a docketed safety analysis report. The scope of this present report covers ARC-100’s reactor core, used fuel storage, and used fuel assembly wash station. These systems are also compared to a generic SFR design assumed in the previous study. The security assessment results show changes in structures, systems, and components (SSCs) safety importance relative to the generic SFR SSCs. However, the consequence assessment results are the similar to a previously assessed generic SFR. Several SSCs have higher importance rankings than others, and it is recommended that protection efforts are prioritized for these SSCs. This work will continue in the Fiscal Year 2025 for the remaining ARC-100 systems, including cesium trap, sodium cold trap, noble gas decay tanks (dewar bottles), and used fuel dry storage facility, to provide safety-and-security-by-design insights and recommendations on non-core systems. Results from this work will furnish a technical justification for the feasibility of these solutions for the ARC reactor's design and, where applicable, identify any regulatory benefits conferred by the proactive design aspect within a risk management framework. This initiative will contribute to a more secure design of the ARC reactor and support its licensing process.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗