Search NASA⌕ Search

SEARCH · Search NASA

Results for “security controls”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 145 records · Page 8

CIE Curriculum Guide (V.2.0)

The Cyber-Informed Engineering (CIE) Curriculum Guide offers a comprehensive framework, guidance, and resources for integrating CIE into university-level engineering programs and related educational activities. The primary goal is to help educators adopt CIE principles into their teaching to produce future engineers and technicians who understand digital risks in modern engineered systems, thereby addressing the nation’s infrastructure resilience needs. This guide outlines practical integration examples, links to resources to accelerate CIE adoption, and shares insights from partner academic institutions on various implementation strategies. CIE is a framework for embedding engineered controls that mitigate the impact of cyber-attacks in any cyber-physical system used in critical energy infrastructure and other sectors. Developed by the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER), the National Cyber-Informed Engineering Strategy emphasizes embedding CIE into formal education, training, and credentialing. This guide supports this strategic objective by providing examples of integrating CIE concepts into engineering curricula, from class activities to new courses and certificate programs. The importance of educating cyber-informed engineers is underscored by the evolving cybersecurity threats facing engineered systems. As industrial control systems (ICS) increasingly incorporate digital technologies, the responsibility for security extends to both cyber professionals and engineers. CIE addresses critical gaps in designing and protecting physical systems with digital components against cyber risks, ensuring engineers consider digital risk throughout the engineering design lifecycle. Currently, engineering education does not routinely include cyber-informed principles, highlighting a gap in addressing modern engineering system risks. This guide advocates for updating engineering curricula to include digital risk management as a fundamental element. By doing so, future engineers will be equipped to design resilient systems that mitigate digital risks from the outset. Through this guide, engineering faculty can integrate CIE into their curricula, bridging the gap between digital risk and engineering. This approach prepares a cyber-informed workforce capable of safeguarding the cyber-physical systems crucial to national security and public welfare. By embedding CIE into education and training, institutions can produce engineers and technicians who can effectively mitigate cyber impacts throughout the engineering design lifecycle, resulting in more secure critical infrastructures.

42 - ENGINEERING↗

Securing Smart Manufacturing: Detection of Cyber-Physical Attacks in CNC-Based Systems

As Industry 4.0 advances, the integration of computer numerical control (CNC) machines and advanced manufacturing technologies is transforming production into smart manufacturing systems that blend physical and digital processes as cyber-physical systems. However, this increased cyber-physical connectivity exposes manufacturing systems to cyber threats that can cause severe operational and financial disruptions. This paper presents a comparative study on cyber attacks and anomaly detection techniques in manufacturing, focusing on network traffic from CNC machines. The data extracted from network packets includes machine commands and control signals exchanged between the machine's interface and control system, crucial for maintaining operational integrity. We explore two types of cyber attacks, design modification and command injection, which pose substantial risks to CNC machine productivity and system integrity. Our investigation involves experiments on a real CNC system, highlighting the urgent need for effective detection mechanisms. To address these threats, we evaluate three anomaly detection methods: dynamic time warping (DTW), rolling average, and a deep learning, long short-term memory (LSTM) time-series-based autoencoder. Each is assessed for its effectiveness in identifying anomalous behaviors caused by the attacks. Our findings demonstrate the unique strengths and limitations of each detection technique, providing a deeper understanding of their applicability in realworld manufacturing environments. The comparative analysis indicates that while certain methods are highly effective against specific attack types, others offer broader applicability across different attacks. This study contributes to the accurate detection of anomalies in CNC machining processes, thereby enhancing the reliability and security of smart manufacturing systems against diverse cyber threats.

Williams, Bethanie [Tennessee Technological Univer↗

Cyber‐Resilient Distributed Energy Resource Control Algorithms for Smart Distribution Grids

ABSTRACT This paper focuses on the development of cyber‐resilient gradient‐based optimisation algorithms and theoretical proof for grid‐interactive distributed energy resource (DER) control to enable two grid services of virtual power plants (VPPs) dispatch and grid voltage regulation, considering the communication and security impacts. Firstly, the combined DER dispatch and voltage regulation as a real‐time gradient‐based optimisation problem is recapped. Thereafter, we consider a probabilistic traffic model to characterise packet delays and loss in a communication network, and study how the delays enter the process of information exchange among the grid measurement units, local DER controllers and the grid control centre that execute this control algorithm in a coordinated manner. Then, a strategy combining delay thresholds and message update rules is proposed to immunity the asynchrony resulting from the communications traffic and it avoids possible numerical instabilities and sensitivities of the power tracking and voltage regulation capabilities, resulting as cyber‐resilient DER control algorithms. Additionally, their convergence is theoretically proved. Effectiveness of proposed cyber‐resilient algorithms has been validated on the IEEE 37‐bus system in terms of convergence, VPP tracking and voltage regulation performance for smart distribution systems with high penetration of DERs.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Formal Methods for Provably Secure Software and Firmware

This project addresses a gap observed in verifying the programming in embedded devices used in international arms control: namely verifying that embedded programming in an arms control device does exactly what it is supposed to do, no more and no less, every time without fail, and without disclosing unauthorized information accidentally or intentionally. In critical military, aerospace, and industrial safety systems this problem is sometimes addressed using formal methods (FM). This multi-year project seeks to identify formal methods toolsets useable in arms control regimes, with emphasis on applicability, ease of use, long term availability, and support.

formal methods, Arms Control Verification↗

IMAGINE BioSecurity: Mesocosm-Based Methods to Evaluate Biocontainment Strategies and Impact of Industrial Microbes Upon Native Ecosystems

Project Goals: The Integrative Modeling and Genome-scale Engineering for Biosystems Security (IMAGINE BioSecurity) SFA project seeks to establish an understanding of the behavior of engineered microbes in controlled versus environmental conditions to predictively devise new strategies for responding to biological escape. To this end, the IMAGINE Team has established a plant-soil mesocosm platform to track and quantify the fate of industrial microbes in environmental systems and assess the efficacy of biocontainment constraints upon genetically engineered microbe escape frequency and the impact of industrial microbes upon native ecological microbiomes. Abstract Text: Genetically modified industrial production microbes and their associated bioproducts have emerged as an integral component of a sustainable bioeconomy. However, the rapid development of these innovative technologies raises biosecurity concerns, namely, the risk of environmental escape. Thus, the realization of a bioeconomy hinges not only on the development and deployment of microbial production hosts, but also on the development of secure biosystems and biocontainment designs. Current laboratory-based biocontainment testing systems do not accurately reflect complexities found in natural environments, necessitating an environmentally relevant analysis pipeline that allows for the detection of rare escapees, the effect of associated bio-products, and the impact on native ecologies. To this end, we have developed an approach that utilizes soil mesocosms and integrated systems analyses to evaluate the efficacy of novel biocontainment strategies and to assess the impact of production systems upon terrestrial microbiome dynamics. We demonstrate the utility of this approach by modeling a contamination with industrial microbial chasses versus their biocontained counterparts. Here we demonstrate the broad utility of this system by highlighting findings from both strains of Saccharomyces cerevisiae that are contained with an inducible toxin anti-toxin system, and stains of Escherichia coli that are contained via genomic recoding. The resultant data demonstrate that this system has broad utility across diverse microbial chassis and biocontainment strategies, enables us to track the fate of our contaminating microbe with high sensitivity in the soil, as well as monitor broader impacts of the perturbation on the underlying soil system. The findings presented here support the use of this mesocosm-based approach to assess the environmental impact of industrial microbes and to validate biocontainment strategies.

BASIC BIOLOGICAL SCIENCES,INORGANIC, ORGANIC, PHYS↗

Work With Us to Advance Cybersecurity for the Current and Future Grid

The energy sector is undergoing rapid change. Advanced technologies and controls, digitally connected devices, and a mix of generation sources offer increased energy reliability and security, reduced energy costs, and enhanced grid operations. But they can also carry physical and cybersecurity risks that are not yet fully understood. With deep expertise in advanced energy technologies, the National Laboratory of the Rockies is examining the cybersecurity implications of evolving systems and developing cutting-edge tools, novel approaches, and innovative research capabilities to address sector-wide challenges. Together with our partners, we are working to achieve a more secure, defensible, and reliable grid.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Tailoring Microbial Fitness Through Computational Steering and CRISPRi-Driven Robustness Regulation

The widespread application of genetically modified microorganisms (GMMs) across diverse sectors underscores the pressing need for robust strategies to mitigate the risks associated with their potential uncontrolled escape. This study merges computational modeling with CRISPR interference (CRISPRi) to refine GMM metabolic robustness. Utilizing ensemble modeling, we achieved high-throughput in silico screening for enzymatic targets susceptible to expression alterations. Translating these insights, we developed functional CRISPRi, boosting fitness control via multiplexed gene knockdown. Our method, enhanced by an insulator-improved gRNA structure and an off-switch circuit controlling a compact Cas12m, resulted in rationally engineered strains with escape frequencies below National Institutes of Health standards. The effectiveness of this approach was confirmed under various conditions, showcasing its ability for secure GMM management. This research underscores the resilience of microbial metabolism, strategically modifying key nodes to halt growth without provoking significant resistance, thereby enabling more reliable and precise GMM control. A record of this paper's transparent peer review process is included in the supplemental information.

59 BASIC BIOLOGICAL SCIENCES↗

5G Communications in Nuclear: Potential Use Cases and Security Considerations

As fifth-generation (5G) communications continues to revolutionize the future of wireless technology, there is growing demand to utilize its benefits for critical infrastructures such as nuclear power plants (NPPs). In regard to achieving full automation and control in the operation of existing and future nuclear reactors, the unique capabilities of 5G can bring several potential advantages over other wireless technologies. However, a deep investigation is needed for the availability and security of 5G communications under various NPP operational scenarios. This article examines how 5G security capabilities can be architecturally deployed in nuclear applications so as to replace existing communication infrastructures. We discuss the current use of all wireless technologies in NPPs with their key features. Consequently, we investigated several NPP use cases in which 5G offers potential advantages but entails specific security considerations. The present article covers the characteristics of 5G communications, general challenges to its application in nuclear, and the security gaps that need to be addressed. We also highlight certain 5G security-by-design features that can help addressing current stringent NPP requirements. In addition, we discuss some future research direction that can facilitate the implementation of 5G in a nuclear facility. The findings presented herein can help foster 5G deployment in NPPs, thus enabling secured data transmission, cost savings, and increased operational efficiency with enhanced reliability.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Electric Utility Communications Standards Landscape 2025 Edition

Historically, challenges to managing electric utility data exchange have been addressed through dedicated communication solutions, enabling the transmission of data with both speed and security. Protocols have been deployed in a relatively uniform fashion; for example, field communications for Supervisory Control and Data Acquisition (SCADA) are commonly implemented using IEEE 1815 (DNP3).

24 POWER TRANSMISSION AND DISTRIBUTION↗

Evaluation of IEC 62443 Standard Gaps for Electric Grid Substation Model Use Case

This report presents an evaluation of the IEC 62443 standards in the context of electric grid substations, as part of a collaborative effort among Sandia National Laboratories (SNL), Idaho National Laboratory (INL), and the National Renewable Energy Laboratory (NREL). The primary objective is to assess the applicability of these standards to enhance cybersecurity measures for industrial automation and control systems (IACS) within the energy sector. The evaluation identifies strengths, such as the scalability of security levels and the structured lifecycle guidance provided by IEC 62443. However, it also highlights significant gaps, including limited integration of physical security, insufficient guidance for legacy systems, and challenges in addressing emerging threats like supply chain vulnerabilities. Recommendations for refining the standards are proposed, including the need for tailored guidance for securing legacy systems, integrating physical security with cybersecurity frameworks, and enhancing interoperability across multi-vendor environments. By addressing these gaps, the IEC 62443 standards can be strengthened to ensure comprehensive cybersecurity for electric grid substations, thereby supporting the resilience and reliability of critical energy infrastructure.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Roadmap for Solar Photovoltaic (PV) Cybersecurity: A vision for improving cyber maturity of distributed and utility-scale solar energy installations

As the solar energy sector continues to expand, its integration into the broader energy infrastructure presents both unprecedented opportunities and new risks. The increasing reliance on digital technologies and interconnected systems in solar energy creates an expanded attack surface for motivated cyber adversaries. Cyberattacks have the potential to cause disruptions in energy production, damage to equipment, financial losses, and compromises in national security. Therefore, ensuring robust cybersecurity measures is paramount to protect the integrity, availability, confidentiality, and access control of solar energy systems. However, there are still key gaps and challenges to be addressed in industry and research, which stakeholders must race to address as they combat a growing number of real-world cyber incidents that affect solar energy systems and a growing number of vulnerabilities discovered and disclosed in key types of equipment. This roadmap explore the current state of solar PV cybersecurity and the gaps and challenges still to be addressed.

14 - SOLAR ENERGY↗

Opportunities, Challenges, and Research Needs for Remote Microreactor Operations

As the nuclear industry develops new advanced reactor technologies, many companies are embracing this advancement by pursuing the development of microreactors. The term microreactor generally refers to a nuclear reactor with an operating power of 20 MW(thermal) or less. The power range of microreactors makes them appealing for many use cases, such as powering remote communities, mining sites, and military bases. Most of the microreactor designs being pursued are expected to incorporate remote facility operations into the final product. However, no framework has yet been developed to determine what remote operations systems require for reliable, resilient, and secure operation of a microreactor. Here, this work identifies the research needs for challenges that are unique to remote operations and monitoring for microreactors, specifically regarding instrumentation and control, communication methods, regulatory requirements, and operational policies. The types of commands and sensor measurements that must be transmitted between the facilities, as well as methods for verifying the trustworthiness of these signals, are assessed. This work evaluates the security, reliability, and performance requirements that must be met when considering the selection of communication hardware and protocols for use in remote operations. Also, an assessment was performed to study how remote operations fit within current regulatory requirements and what may need to be updated in regulatory policy to allow for remote operation. Finally, the operational contingencies unique to remote operations that must be in place for responses to abnormal events are identified. This paper identifies the challenges and research opportunities within the areas of importance for the design of remote operation systems.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Advanced Reactor Safeguards & Security 2024 Program Roadmap

The Advanced Reactor Safeguards and Security (ARSS) program was established to provide research support addressing near term challenges that advanced nuclear reactor vendors face in meeting domestic Material Control and Accounting (MC&A), Physical Protection System (PPS), and Cybersecurity requirements for U.S. construction. The technical work in the program is meant to (1) support nuclear reactor vendors with advanced MC&A, PPS, and Cybersecurity designs for next generation reactors, (2) provide technical bases for the regulator, and (3) promote the integration of Safeguards and Security by Design early in the design process. Existing domestic regulations for safeguards and security, as outlined in the Code of Federal Regulations, were written for large light water reactors, and rule-making efforts are underway to develop regulations more suited to different reactor designs. The ARSS program seeks to remove roadblocks in the deployment of new and advanced reactors by solving regulatory challenges, reducing safeguards and security costs, and utilizing the latest technologies and approaches for robust plant monitoring and protection. This roadmap discusses the goals of the ARSS program, current research, and program plan for the next five years.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Enhancing Time Synchronization in Smart Grid With White Rabbit: Theory, Architecture, and Challenges

The smart grid aims to provide economically efficient and sustainable power to consumers with high quality and security. However, the increasing integration of distributed renewable energy sources presents challenges for smart grid protection and control systems. Here, to enhance smart grid operations, this article introduces White Rabbit (WR) as a more precise and accurate time synchronization technique. To explore White Rabbit’s potential applications in the smart grid, this study first explains existing time synchronization techniques and their limitations, followed by an analysis of the role and importance of time synchronization in smart grids. A comprehensive survey is then conducted, covering the theories, principles, implementations, performances, and existing application cases of White Rabbit. The findings suggest that White Rabbit is a promising technique for smart grid deployment. However, several challenges remain on the path to large-scale implementation. These challenges are analyzed in detail, highlighting key areas for future research.

Liu, Yu [University of Tennessee, Knoxville, TN (U↗

Cyber Labeling for Energy Industrial IoT

The U.S. Department of Energy’s (DOE) Office of Cybersecurity, Energy Security and Emergency Response (CESER), at the request of the Deputy National Security Advisor for Cyber and Emerging Technologies, Anne Neuberger, initiated research in 2023 to develop a cybersecurity labeling proof-of-concept for energy products to expand on the Federal Communications Commission’s (FCC) proposed U.S. Cyber Trust Mark program. DOE mobilized researchers from six National Laboratories to develop and gather feedback on a proof-of concept label for solar inverters and smart meters, which serve as representative products for market-facing energy sector Industrial Internet of Things (IIoT). This report details the research team’s process across two phases and the resulting findings, which include challenges facing cyber labeling programs and recommendations to implement an expanded IIoT cyber labeling program in the U.S.

32 - ENERGY CONSERVATION, CONSUMPTION, AND UTILIZA↗

Blockchain Research and Development Activities Sponsored by the U.S. Department of Energy and Utility Sector

This article provides an in-depth analysis of blockchain research in the energy sector, focusing on projects funded by the U.S. Department of Energy (DOE) and comparing them with industry-funded initiatives. A total of 110 funded activities within the U.S. power industry were successfully tracked and mapped into a newly developed categorization framework. This framework is designed to help research agencies to systematically understand their funded portfolio. Such characterization is expected to help them make effective investments, identify research gaps, measure impact, and advance technological progress to meet national goals. In line with this need, the proposed framework proposes a 2-D categorization matrix to systematically classify blockchain efforts within the energy sector.Under the proposed framework, the Energy System Domain serves as the primary classification dimension, categorizing use cases into 30 distinct applications. The second dimension, Blockchain Properties, captures the specific needs and functionalities provided by Blockchain technology. The aim was to capture blockchain’s applicability and functionality: where and why blockchain? Principles behind the selection of the viewpoint dimensions were carefully defined based on consensus obtained through the Blockchain for Optimized Security and Energy Management (BLOSEM) project. The mapped results show that activities within the Grid Automation, Coordination, and Control (31.8%), Marketplaces and Trading (25.5%), Foundational Blockchain Research (19.1%), and Supply Chain Management (17.3%) domains have been actively pursued to date. The three leading specific use case applications were identified as Transactive Energy Management for Marketplaces and Trading, Asset Management for Supply Chain Management, and Fundamental Blockchain for Foundational Blockchain Research. The Marketplaces and Trading and Retail Services Enablement domains stood out as being favored by industry by a factor greater than 2 (2.3 and 2.6, respectively), yet there seemed to be little to zero investment from DOE. Approximately 76% of the total projects prioritized Immutability, Identity Management, and Decentralization and/or Disintermediation compared to Asset Digitization and/or Tokenization, Automation, and Privacy and/or Anonymity. The greatest discrepancies between DOE and industry were in Asset Digitization and/or Tokenization and Automation. The industry efforts (36% in Asset Digitization/Tokenization and 22% in Automation) was 14 times and 2.4 times, respectively, more intensive than the DOE-sponsored efforts, indicating a significant discrepancy in industry versus government priorities. Overall, quantifying DOE-sponsored projects and industry activities through mapping provides clarity on portfolio investments and opportunities for future research.

24 POWER TRANSMISSION AND DISTRIBUTION↗

EV SALaD 2023 Demonstration: Best Practices and Mitigations for Protecting EVSE Infrastructure

The Electric Vehicle Secure Architecture Laboratory Demonstration (EV SALaD) program is a demonstration of cybersecurity best practices for high-power electric vehicle (EV) charging infrastructure led by Idaho National Laboratory (INL), in collaboration with other DOE National Laboratories participating in the EVs at Scale Consortium.a Sandia National Laboratories (SNL) and Pacific Northwest National Laboratory (PNNL) participated in the first 2-year (FY22-23) demonstration cycle for EV SALaD. This report documents the FY23 demonstration, the second in a series of demonstrations and collaborations in deploying and operating cybersecure EV charging infrastructure. It includes a summary of improvements from the FY22 demonstration, technical analysis of the FY23 demonstration, how the research demonstrates cyber-physical and cybersecurity best practices for high-power EV charging infrastructure, and related impacts to national and energy security. For EV SALaD, the FY22 demonstration focused on the detection, ranking, and prioritization of anomalous events for high-power EV charging. The FY23 demonstration additionally included the demonstration of cybersecurity best practices, which included protection and mitigation solutions to prevent, respond, and recover from anomalous events. During the demonstrations, the multi-lab EV SALaD team conducted a Test Effect Payload (TEP)b evaluation on extreme fast charger (XFC) hardware equipped with Cerberus, a detection and response solution, to demonstrate anomaly detection and mitigation cybersecurity best practices against cyber-enabled events.

33 ADVANCED PROPULSION SYSTEMS↗

Cybersecurity Considerations and Research Pathways for Grid-Interactive Efficient Buildings

Federal facilities serve critical missions and functions that require safe, reliable, and efficient operations. Digitization of several facility operations has increased the cost-effectiveness of energy usage and optimization of energy system performance. As the building controls landscape shifts to become more connected and smarter, building operators now face unique opportunities and challenges to adopt smart enabled devices that can lower energy usage while also optimizing building system performance. The grid-interactive efficient buildings (GEB) initiative aims to make buildings cleaner and more flexible through these smart devices. Smart enabled devices allow greater connectivity and control through remote operations and provide crucial data for analytics and increased efficiency. GEBs enable demand flexibility that has the potential to reduce electrical costs and transform the grid edge where buildings connect to power grids. This operation of interconnected systems, if not designed with cybersecurity practices, causes security gaps and introduces potential attack paths by adversarial and non-adversarial entities leading to disruption of operations.

building controls↗