Search NASA⌕ Search

SEARCH · Search NASA

Results for “Critical Function Assurance”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

Cyber-Enabled Sabotage, Critical Function Assurance, and Cyber-Informed Engineering

Cyber-enabled Sabotage, Critical Function Assurance, and Cyber-Informed Engineering: This discussion will introduce the idea of cyber-enabled sabotage, and the role engineering plays in the cyber defense of critical functions with a focus on electric power systems. It will outline how and why engineering practice must be used to apply cybersecurity principles to establish safe and reliable operations even in the face of determined and skilled adversaries, and give an overview of INL’s Consequence-Driven Cyber-Informed Engineering methodology to apply these principles. There will be an opportunity for audience questions and answers at the end of the session.

42 ENGINEERING↗

Digital-Threat Bias and Psychological Distance: Barriers to Foundational Digital-Security Improvement

Modern life is held together by a web of digital dependencies that enable and provide delivery of critical services and functions—think the provision of utilities such as electricity and water, as well as our dependency on digital services for social and economic services (internet, communication, etc.). As this dependency grows, the complexity related to the delivery of these critical services increases as well. As complexity increases, the understanding of the risk and impact associated with potential disruption, degradation, or destruction—due to either malicious or non-malicious events of those digitally enabled functions—decreases. One potential explanation for the difficulty to 1) understand the risks faced and 2) address them appropriately and effectively is the abstractness and psychological distance assigned to “digital threat.” The complexity of these digitally enabled services creates a perceived complicatedness; as a result, digital threats are treated differently than similarly devasting (but more easily understood) kinetic or physical threats. How we categorize these threats also matters. Acts of cyber-enabled sabotage to critical infrastructure need to be defined as irregular warfare. By inadequately defining the threat, we compound the problem. Acknowledging this digital-threat bias is foundational to improving the ability to protect critical infrastructure. Using construal-level theory and psychological-distance concepts provides an intriguing starting point to address these issues, to reframe the challenges faced, and pursue more effective critical infrastructure security and defense policy.

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

Moving from Information Assurance to Functional Assurance with Engineered Controls

Cyber threats to operational technology demand more than traditional IT defenses—they require full-spectrum mission assurance. Cyber-Informed Engineering (CIE) is an approach that embeds engineered controls into system design to ensure critical functions remain safe and reliable, even under attack. Unlike conventional cybersecurity tools, engineered controls act directly on physical processes to prevent unacceptable outcomes such as equipment damage or mission failure. This session will outline the CIE framework and share examples of consequence-based design that deliver true resilience, not just fail-safe behaviors. Attendees will learn how to integrate these principles into the engineering lifecycle to support resilient-by-design architectures and inform emerging standards. This talk sets the stage for the panel discussion on advancing CIE across sectors as digital and physical systems converge.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Developing stable, simplified, functional consortia from Brachypodium rhizosphere for microbial application in sustainable agriculture

The rhizosphere microbiome plays a crucial role in supporting plant productivity and ecosystem functioning by regulating nutrient cycling, soil integrity, and carbon storage. However, deciphering the intricate interplay between microbial relationships within the rhizosphere is challenging due to the overwhelming taxonomic and functional diversity. Here we present our systematic design framework built on microbial colocalization and microbial interaction, toward successful assembly of multiple rhizosphere-derived Reduced Complexity Consortia (RCC). We enriched co-localized microbes from Brachypodium roots grown in field soil with carbon substrates mimicking Brachypodium root exudates, generating 768 enrichments. By transferring the enrichments every 3 or 7 days for 10 generations, we developed both fast and slow-growing reduced complexity microbial communities. Most carbon substrates led to highly stable RCC just after a few transfers. 16S rRNA gene amplicon analysis revealed distinct community compositions based on inoculum and carbon source, with complex carbon enriching slow growing yet functionally important soil taxa like Acidobacteria and Verrucomicrobia. Network analysis showed that microbial consortia, whether differentiated by growth rate (fast vs. slow) or by succession (across generations), had significantly different network centralities. Besides, the keystone taxa identified within these networks belong to genera with plant growth-promoting traits, underscoring their critical function in shaping rhizospheric microbiome networks. Furthermore, tested consortia demonstrated high stability and reproducibility, assuring successful revival from glycerol stocks for long-term viability and use. Our study represents a significant step toward developing a framework for assembling rhizosphere consortia based on microbial colocalization and interaction, with future implications for sustainable agriculture and environmental management.

59 BASIC BIOLOGICAL SCIENCES↗

Vulcan Test Platform: Demonstrating the Data Center as a Flexible Grid Asset

Explosive data center demand is outpacing grid infrastructure development. AI workloads and hyperscale cloud growth are creating unprecedented power requirements, while traditional grid expansion faces multi-year development timelines, regulatory hurdles, and decarbonization challenges. Sidewalk Infrastructure Partners recognized this impending crisis years ago and founded Verrus to develop an innovative solution: data centers that function as grid assets rather than passive loads. The Verrus approach integrates proprietary grid-aware controls with battery energy storage systems (BESS) in a medium-voltage architecture that delivers three critical capabilities: Fast-responding demand flexibility that can service requests from the utility within 10 seconds, Uninterrupted transition to islanded operation during grid disturbances, Continuous uptime assurance while maintaining all customer service level commitments Through Verrus' strategic partnership with the National Renewable Energy Laboratory (NREL), we validated these capabilities on Vulcan, a 70 MW utility-scale test platform powered by NREL's ARIES Virtual Emulation Environment. This deployment-ready technology has successfully demonstrated that Verrus data centers can deliver meaningful grid services while maintaining mission-critical reliability. This technical report outlines the design, methodology, and results of this emulated deployment, demonstrating that data centers can play a pivotal role in enhancing grid flexibility and reliability, without sacrificing service level guarantees.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Application of quantitative risk assessment to address stakeholder questions in geologic carbon storage

Ambitious international greenhouse gas emissions reduction targets demand a rapid transformation to a low-carbon economy. This transformation includes the accelerated adoption of carbon dioxide (CO2) capture and storage (CCS) technology. However, as with any large-scale engineering enterprise, the widespread commercial-scale deployment of geologic carbon storage (GCS) raises important questions about technology and cost-effectiveness, safety, environmental risk, and long-term liability. Effectively assessing and managing risks and liability associated with GCS projects is a key technical need throughout the project life cycle-from site selection and permitting to monitoring design, operational risk management, and post-operational site closure. This presentation highlights recent advancements in tools for quantitative risk assessment, being developed by the National Risk Assessment Partnership (NRAP). NRAP is a multi-year, multinational laboratory research collaboration sponsored by the U.S. Department of Energy's Office of Fossil Energy and Carbon Management. Our focus will be on these tools' applications in addressing critical stakeholder questions related to supporting permitting to ensure secure and environmentally protective storage; designing effective and efficient monitoring plans; evaluating the effectiveness of remedial actions and risk management alternatives; and informing liability assessment and investment decisions. This paper will detail the key functionality of NRAP’s Open-Source Integrated Assessment Model (NRAP-Open-IAM), a computational framework for assessing leakage risk and containment assurance. This model features streamlined workflows for calculating leakage risk profiles, delineating risk-based area of review, and assessing contingency plans and post-injection site care requirements. ORION is an open-source, observation-based ensemble forecasting toolkit to help operators assess the seismic hazard at a carbon storage site. The State of Stress Analysis Tool (SOSAT), designed to assess subsurface stress conditions and evaluate geomechanical risk resulting from CO2 injection in an area of interest will also be presented. We will also introduce a prototype model to evaluate storage project costs and liability associated with risk management. The Technoeconomic and Liability Evaluation for Storage (TALES) model uses results from forecasts of leakage and induced seismicity risk to estimate the lifecycle cost of managing risk. Finally, a preliminary example of how the NRAP Risk-based Adaptive Monitoring Plan (RAMP) tool can be used to design efficient and effective site monitoring plans and estimate the detectability of fluid leakage will be provided. The relevance of these tools for addressing key stakeholder questions amidst uncertainty will be emphasized.

decision support↗

Development of an Optical Library for Coevaporated CdSe x Te 1– x

The conversion efficiency of CdTe solar cells may be improved by bandgap engineering, i.e., changing the bandgap value through the addition of Se in the absorber. The Se alloying enables a short-circuit current density improvement, as it leads to a bandgap energy value decrease. Furthermore, it has been associated with increased minority carrier lifetimes, assuring high open-circuit voltage values. An Se gradient profile control can further optimize the solar cell performance. Thus, an optical model baseline of the CdSe x Te 1–x (CST) compound was developed. Spectroscopic ellipsometry measurements were conducted to accurately extract the optical constants of ten CST layers deposited through coevaporation with x varying from 0 to 1. Using the measured dielectric function spectra from the discrete CST layers with varying x, and considering the composition-induced shift in the critical point energies, an energy-shift model was employed to develop the accurate optical library for the CST compound for any x value to provide data for future modeling and optimization. Furthermore, the library accuracy was validated through optical simulations of the quantum efficiency of a graded CST solar cell using the finite-difference time-domain method by replicating the Se profile in the absorber layer measured through secondary ion mass spectrometry.

14 SOLAR ENERGY↗

The AMACStar ASIC for the HL-LHC ATLAS ITk Strip detector: design, verification, testing, and quality assurance

For the high-luminosity upgrade to the LHC (HL-LHC), the ATLAS detector at CERN requires an all-new inner detector, the Inner Tracker (ITk). The ITk Strip subdetector is made up of silicon modules, which include three types of radiation-hard ASICs. One of these is the Autonomous Monitor and Control (AMAC). The AMAC is manufactured by Global Foundries using 130 nm CMOS8RF DM technology and is approximately 3 by 5 mm in size. This ASIC autonomously monitors the temperatures, voltages, and currents in the module components while controlling critical values in order to prevent these quantities from reaching dangerous levels. The final design, AMACStar, was verified, tested, and ensured to perform all necessary functions. A quality control procedure using an in-house probe station set-up was developed in order to ensure that every individual chip on each wafer of AMACStars required by the ITk Strip project met performance requirements. The average per wafer yield of usable AMACStars is 92.33%, exceeding the design-specific 90% yield estimated for project costing. This estimate was based on actual yields for similar designs in this process.

Analogue electronic circuits↗

Challenges in Continuous In-Field Critical Current Testing of High-Temperature Superconducting Tapes: Thermal and Mechanical Perspectives

High-temperature superconductors (HTS) are essential for ultra-high-field applications requiring exceptional current-carrying capacity under extreme conditions. However, systematic characterization of critical current in long-length conductors remains challenging due to complex thermal, electromag netic, and mechanical interactions during continuous testing. This study reports the development of a continuous in-field magnetization testing system for position-dependent critical current measurement in HTS tapes at 20 K under 7.5 T fields applied normal to the tape plane, enabling identification of performance-limiting regions that could compromise magnet stability. Here, the system addresses two fundamental challenges inherent to cryogenic reel to-reel testing. First, thermal management requires continuous cooling of a moving conductor to 20 K, achieved through liquid nitrogen precooling combined with a 100 W@20 K Gifford McMahon cryocooler. Second, screening currents in high fields generate Lorentz forces that induce twisting, bowing, and potential delamination. To mitigate these risks, we propose mechanical reinforcement and active current density suppression strategies. Numerical simulations using the stream function formulation reveal four primary failure modes: frictional heating at guide interfaces, unstable equilibria causing deformation, transverse current-induced stresses at guide transitions, and unsupported forces in vertical spans. Our mitigation strategies include PTFE coated guides to minimize friction, spring-loaded stabilization mechanisms to maintain tape alignment, controlled pre-heating using the liquid nitrogen thermal jacket to suppress critical current at stress points, and optimized guide positioning to minimize force accumulation. The experimental system is nearing completion, with testing planned to commence within two months. Preliminary validation at 65 K under 0.5 T demonstrates strong correlation between simulation-predicted mechanical instabilities and observed critical current variations during conductor tran sitions through the measurement region. These findings establish a robust foundation for quality assurance protocols essential to next-generation superconducting magnet applications.

Chen, Siwei [Princeton Plasma Physics Laboratory (↗

IEEE PES GM Poster - Cyber-Informed Engineering Approach to Mitigating BESS Supply Chain Concerns

Battery energy storage systems (BESS) are increasingly important to meet the needs of grid resilience and reliability. BESS provide critical grid services, maintaining stability of the grid with increased variable conditions. However, there are significant geopolitical and security concerns regarding their operation in critical infrastructure, due to lack of a domestic supply chain and prevalence of foreign entity of concern (FEOC) components in BESS and associated inverter-based resources. The supply chain challenge is dually exacerbated by a lack of alternative suppliers who can meet the economic targets for energy delivery and a potentially adversarial supply chain. Solutions are needed to secure components, addressing mixed layers of risk and engineering controls. This paper presents a specific application of Cyber-Informed Engineering (CIE) principles for BESS and recommends an alternative strategy to blocking the supply chain, ensuring that grid modernization targets can be met despite lack of a validated or secure supply chain. This study focuses on the United State (U.S.) use case, but the process can be applied globally to address supply chain security challenges. CIE practices represent the next step in functional assurance and risk mitigation, ensuring optimal resource allocation and enhancing security measures to safeguard the future of energy in the U.S. and beyond.

25 - ENERGY STORAGE↗

Convergence in simulating global soil organic carbon by structurally different models after data assimilation

Abstract Current biogeochemical models produce carbon–climate feedback projections with large uncertainties, often attributed to their structural differences when simulating soil organic carbon (SOC) dynamics worldwide. However, choices of model parameter values that quantify the strength and represent properties of different soil carbon cycle processes could also contribute to model simulation uncertainties. Here, we demonstrate the critical role of using common observational data in reducing model uncertainty in estimates of global SOC storage. Two structurally different models featuring distinctive carbon pools, decomposition kinetics, and carbon transfer pathways simulate opposite global SOC distributions with their customary parameter values yet converge to similar results after being informed by the same global SOC database using a data assimilation approach. The converged spatial SOC simulations result from similar simulations in key model components such as carbon transfer efficiency, baseline decomposition rate, and environmental effects on carbon fluxes by these two models after data assimilation. Moreover, data assimilation results suggest equally effective simulations of SOC using models following either first‐order or Michaelis–Menten kinetics at the global scale. Nevertheless, a wider range of data with high‐quality control and assurance are needed to further constrain SOC dynamics simulations and reduce unconstrained parameters. New sets of data, such as microbial genomics‐function relationships, may also suggest novel structures to account for in future model development. Overall, our results highlight the importance of observational data in informing model development and constraining model predictions.

54 ENVIRONMENTAL SCIENCES↗

The Advanced Dimensional Depletion for Engineering of Reactors (ADDER) Software for Depletion and Fuel Management

The Advanced Dimensional Depletion for Engineering of Reactors (ADDER) software is being developed in the Research and Test Reactor (RTR) Program at Argonne National Laboratory to meet the reactor design and analysis needs of the Conversion Program. ADDER is a flexible tool that (1) provides a depletion capability through coupling external neutronics codes with a built-in CRAM solver or external depletion code and (2) provides a user-friendly interface to perform fuel management and criticality search operations. The ADDER software is a Python 3 application written using modern software development practices subject to a compliant implementation of NQA-1 and applicable Department of Energy software quality assurance standards. This report is the user guide for the software release referred to as ADDER v1.1.0. The motivation for a software to have flexible capabilities that ADDER possesses is the need to support a wide variety of geometries that are commonly required in analysis of research and test reactors. These reactors can have complex fuel, experiment, or control material shuffling patterns that persist over several years with many fuel management and partial refueling intervals. The scale of fuel management analysis can require tracking of an inventory that is multiple times the core loading. Many reactors, both power and non-power reactors of various types, will find the features of ADDER useful to facilitate key tasks that a fuel or core design engineer must perform with the convenience of concise input and validated functionality.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

The Advanced Dimensional Depletion for Engineering of Reactors (ADDER) Software for Depletion and Fuel Management

The Advanced Dimensional Depletion for Engineering of Reactors (ADDER) software is being developed in the Research and Test Reactor (RTR) Program at Argonne National Laboratory to meet the reactor design and analysis needs of the Conversion Program. ADDER is a flexible tool that (1) provides a depletion capability through coupling external neutronics codes with a built-in CRAM solver or external depletion code and (2) provides a user-friendly interface to perform fuel management and criticality search operations. The ADDER software is a Python 3 application written using modern software development practices subject to a compliant implementation of NQA-1 and applicable Department of Energy software quality assurance standards. This report is the user guide for the software release referred to as ADDER v1.1.0. The motivation for a software to have flexible capabilities that ADDER possesses is the need to support a wide variety of geometries that are commonly required in analysis of research and test reactors. These reactors can have complex fuel, experiment, or control material shuffling patterns that persist over several years with many fuel management and partial refueling intervals. The scale of fuel management analysis can require tracking of an inventory that is multiple times the core loading. Many reactors, both power and non-power reactors of various types, will find the features of ADDER useful to facilitate key tasks that a fuel or core design engineer must perform with the convenience of concise input and validated functionality.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Physicochemical and biological characterization of a bispecific antibody in a CrossMab/KIH format that targets EGFR and VEGF-A

Introduction Bispecific antibodies (BsAbs) are a class of antibody therapeutics engineered in various molecular formats to bind two distinct antigens and potentially mediate multiple biological effects. These molecular formats are tailored to mediate specific mechanisms of action and possess unique physicochemical and biological properties that are necessary to assure product quality. In ovarian cancer (OC), both EGFR- and VEGF-A-mediated signaling pathways are often upregulated and cooperate to promote tumor growth and angiogenesis. Thus, inhibiting of EGFR- and VEGF-A pathways with a BsAb may provide synergistic anti-tumor activity. Methods Using publicly available sequences and applying immunoglobulin domain crossover (CrossMab) and knobs-into-holes (KIH) technologies, we generated a BsAb to simultaneously bind EGFR and VEGF-A (designated as anti-EGFR/VEGF-A BsAb). This BsAb served as a model for physiochemical and biological characterization of quality attributes that would be critical for the BsAb’s mechanisms of action. Our goal was to gain fundamental insights into BsAbs designed to target a receptor with one arm and a soluble ligand with the other, to support bioassay development and inform quality control strategies. Results Our data demonstrated that the CrossMab/KIH platform successfully produced a correctly assembled BsAb during cell culture. Characterization confirmed that the anti-EGFR/VEGF-A BsAb bound both EGFR and VEGF-A with comparable activity and affinity to the respective parental monoclonal antibodies. Functionally, the BsAb disrupted both EGF/EGFR and VEGF-A/VEGFR2 signaling pathways in OC and human umbilical vein endothelial cell (HUVEC) models. Furthermore, the BsAb effectively blocked angiogenic signaling driven by VEGF-A secreted from OC cells in a paracrine manner. Discussion Based on the combinatorial mechanism of action and our characterization findings, we concluded that two or more bioassays may be needed to accurately assess the activity of both arms of this type of BsAb.

Immunology↗

Synthesis of Correct Digital Controller Models from Specifications by Model Transformation (21-0320)

The design of high consequence controllers (in weapons systems, autonomy, etc.) that do what they are supposed to do is a significant challenge. Testing simply does not come close to meeting the requirements for assurance. Today circuit designers at Sandia (and elsewhere) typically capture the core behavior of their components using state models in tools such as STATEFLOW. They then check that their models meet certain requirements (e.g. “The system bus must not deadlock” or “both traffic lights at an intersection must not be green at the same time”) using tools called model checkers. If the model checker returns “yes” then the property is guaranteed to be satisfied by the model. However, there are several drawbacks to this industry practice: (1) there is a lot of detail to get right, this is particularly challenging when there are multiple components requiring complex coordination (2) any errors returned by the model checker have to be traced back through the design and fixed, necessitating rework, (3) there are severe scalability problems with this approach, particularly when dealing with concurrency. All this places high demands on the designers who now face not only an accelerated schedule but also controllers of increasing complexity. This report describes a new and fundamentally different approach to the construction of safety-critical digital controllers. Instead of directly constructing a complete model and then trying to verify it, the designer can start with an initial abstract (think “sketch”) model plus the requirements, from which a correct concrete model is automatically synthesized. There is no need for post-hoc verification of required functional properties. Having tool to carry this out will significantly impact the nation’s ability to ensure the safety of high-consequence digital systems. The approach has been implemented in a prototype tool, along with a suite of examples, including ones that reflect actual problems faced by designers. Our approach operates on a variant of Statecharts developed at Sandia called Qspecs. Statecharts are a widely used formalism for developing concurrent reactive systems, supporting scalability through allowing state models containing composite states, which are the serial or parallel composition of substates which can themselves contain statecharts. Statecharts enable an incremental style of development, in which states are progressively refined to incorporate greater detail in an incremental model of software development. Our approach formulates a set of constraints from the structure of the models and the requirements and propagates these constraints to a fixpoint. The solution to the constraints is an inductive invariant along with guards on the transitions. We also show how our approach extends to implementation refinement, decomposition, composition, and elaboration. We currently handle safety requirements written in LTL (Linear Temporal Logic)

42 ENGINEERING↗