Search NASA⌕ Search

SEARCH · Search NASA

Results for “Firmware”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

OPET Firmware (Open PV Electrical Tool Firmware) [SWR-25-43]

The main application of OPET is long term performance measurements of PV devices in field or under controlled environmental conditions. This repository contains everything relating to the firmware of the OPET device including source code. If you are looking for the hardware or control software repositories, links are below: https://github.com/NREL/opet-hardware https://github.com/NREL/opet-control

McDanold, Byron [National Renewable Energy Laborat↗

IoT Firmware Emulation and Its Security Application in Fuzzing: A Critical Revisit

As IoT devices with microcontroller (MCU)-based firmware become more common in our lives, memory corruption vulnerabilities in their firmware are increasingly targeted by adversaries. Fuzzing is a powerful method for detecting these vulnerabilities, but it poses unique challenges when applied to IoT devices. Direct fuzzing on these devices is inefficient, and recent efforts have shifted towards creating emulation environments for dynamic firmware testing. However, unlike traditional software, firmware interactions with peripherals that are significantly more diverse presents new challenges for achieving scalable full-system emulation and effective fuzzing. This paper reviews 27 state-of-the-art works in MCU-based firmware emulation and its applications in fuzzing. Instead of classifying existing techniques based on their capabilities and features, we first identify the fundamental challenges faced by firmware emulation and fuzzing. We then revisit recent studies, organizing them according to the specific challenges they address, and discussing how each specific challenge is addressed. We compare the emulation fidelity and bug detection capabilities of various techniques to clearly demonstrate their strengths and weaknesses, aiding users in selecting or combining tools to meet their needs. Finally, we highlight the remaining technical gaps and point out important future research directions in firmware emulation and fuzzing.

Zhou, Wei (ORCID:0000000178340839)↗

Firmware Tampering Detection in Heavy-Duty Vehicles through J1939 CAN Analysis

Modern heavy-duty vehicles rely on complex networks of Electronic Control Units (ECUs) that communicate using the J1939 protocol. While this system makes it easier to update and configure vehicle components, it also opens the door to serious cybersecurity risks if not properly secured. This work investigates the potential for firmware tampering through the J1939 communication protocol, which enables ECU configuration and reprogramming over the Controller Area Network (CAN) bus. By monitoring CAN traffic during legitimate maintenance operations and reverse-engineering OEM diagnostic software, we identified common and proprietary J1939 message identifiers, authentication patterns, and vulnerabilities within Unified Diagnostic Services (UDS). These findings demonstrate that inadequate authentication mechanisms can allow malicious actors to alter ECU firmware or disable safety functions, posing severe operational and safety risks. Our analysis contributes to the development of vehicle intrusion detection systems capable of recognizing abnormal reprogramming activity and future firmware fingerprinting methods to verify software integrity across ECUs. This work highlights the importance of standardizing secure firmware authentication across manufacturers to strengthen cyber resilience in heavy-duty vehicle systems.

33 ADVANCED PROPULSION SYSTEMS↗

Software and Firmware-logic Design for the PIP-II Machine Protection System Mode and Configuration Control at Fermilab

The PIP-II Machine Protection System (MPS) requires a dedicated set of tools for configuration control and management of the machine modes and beam modes of the accelerator. The protection system reacts to signals from various elements of the machine according to rules established in a setup database in the form of a Look-Up-Table filtered by the program Mode Controller. This is achieved in accordance with commands from the operator and governed by the firmware logic of the MPS. This paper describes the architecture, firmware logic, and implementation of the program mode controller.

43 PARTICLE ACCELERATORS↗

USPAS Digital Low-Level RF firmware and software suite (uspas_llrf) v1.0

The USPAS Digital Low-Level RF firmware and software suite was originally developed for the USPAS 2023 LLRF course, for demonstrating the close loop RF control on the BerkeleyLab Marble FPGA carrier and Zest digitizer platform in controlling the RF field for various accelerators. The suite features Register-transfer level (RTL) designs for the board-support layer, digital signal processing and verification test benches, system-on-chip architecture, and Experimental Physics and Industrial Control System (EPICS) support, utilizing a open-source tool chain.

Du, Qiang↗

RFSoC based digital low level RF control firmware and software suite (mimo_llrf) v1.0

It features a framework of a firmware and software architecture in support of building a digital low-level RF control system for accelerators, where precised digital RF generation and measurement are needed across many RF channels. It primarily supports the Xilinx RFSoC chips (xczu48dr, xczu47dr, xczu29dr) and their evaluation boards (zcu208, zcu216), for a highly integrated solution enabling the need for synchronous low-level RF systems, including: multi-tile synchronization, external reference for sampling clocks, deterministic delay, aligned NCO phase for digital mixers, and built-in EPICS IOC.

Du, Qiang [Lawrence Berkeley National Laboratory (↗

Formal Methods for Provably Secure Software and Firmware

This project addresses a gap observed in verifying the programming in embedded devices used in international arms control: namely verifying that embedded programming in an arms control device does exactly what it is supposed to do, no more and no less, every time without fail, and without disclosing unauthorized information accidentally or intentionally. In critical military, aerospace, and industrial safety systems this problem is sometimes addressed using formal methods (FM). This multi-year project seeks to identify formal methods toolsets useable in arms control regimes, with emphasis on applicability, ease of use, long term availability, and support.

formal methods, Arms Control Verification↗

Forensic Analysis of SOHO Router Binaries

Small Office/Home Office (SOHO) routers are used by millions of consumers across the United States, and are commensurately vulnerable. Forensic analysis of SOHO router firmware helps to understand and mitigate those vulnerabilities. This poster focused particularly on analysis of BusyBox executables, a software suite that provides several Unix utilities in a single file. Three main tools were used to analyze the binaries. BinWalk was used to extract the files, but also to build entropy graphs, extract Linux kernel images, and identify CPU architectures; WiiBin processed the binaries to find endianness, architecture, the percent compressed/encrypted, and compiler data; and @DisCo, a machine learning tool used to determine function similarity in disassembled binaries, analyzed similarities and determined versions of extracted BusyBox files from each router. These tools found that venders from all five routers utilized the same version of the BusyBox software across different firmware updates, demonstrating the importance of constant firmware scrutiny to protect against security vulnerabilities.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A prototype scintillator real‐time beam monitor for ultra‐high dose rate radiotherapy

Background: FLASH Radiotherapy (RT) is an emergent cancer RT modality where an entire therapeutic dose is delivered at more than 1000 times higher dose rate than conventional RT. For clinical trials to be conducted safely, a precise and fast beam monitor that can generate out-of-tolerance beam interrupts is required. This paper describes the overall concept and provides results from a prototype ultra-fast, scintillator-based beam monitor for both proton and electron beam FLASH applications. Purpose: A FLASH Beam Scintillator Monitor (FBSM) is being developed that employs a novel proprietary scintillator material. The FBSM has capabilities that conventional RT detector technologies are unable to simultaneously provide: (1) large area coverage; (2) a low mass profile; (3) a linear response over a broad dynamic range; (4) radiation hardness; (5) real-time analysis to provide an IEC-compliant fast beam-interrupt signal based on true two-dimensional beam imaging, radiation dosimetry and excellent spatial resolution. Methods: The FBSM uses a proprietary low mass, less than 0.5 mm water equivalent, non-hygroscopic, radiation tolerant scintillator material (designated HM: hybrid material) that is viewed by high frame rate CMOS cameras. Folded optics using mirrors enable a thin monitor profile of ∼10 cm. A field programmable gate array (FPGA) data acquisition system generates real-time analysis on a time scale appropriate to the FLASH RT beam modality: 100–1000 Hz for pulsed electrons and 10–20 kHz for quasi-continuous scanning proton pencil beams. An ion beam monitor served as the initial development platform for this work and was tested in low energy heavy-ion beams ( 86 Kr +26 and protons). A prototype FBSM was fabricated and then tested in various radiation beams that included FLASH level dose per pulse electron beams, and a hospital RT clinic with electron beams. Results: Results presented in this report include image quality, response linearity, radiation hardness, spatial resolution, and real-time data processing. Furthermore, the HM scintillator was found to be highly radiation damage resistant. It exhibited a small 0.025%/kGy signal decrease from a 216 kGy cumulative dose resulting from continuous exposure for 15 min at a FLASH compatible dose rate of 237 Gy/s. Measurements of the signal amplitude versus beam fluence demonstrate linear response of the FBSM at FLASH compatible dose rates of >40 Gy/s. Comparison with commercial Gafchromic film indicates that the FBSM produces a high resolution 2D beam image and can reproduce a nearly identical beam profile, including primary beam tails. The spatial resolution was measured at 35–40 µm. Tests of the firmware beta version show successful operation at 20 000 Hz frame rate or 50 µs/frame, where the real-time analysis of the beam parameters is achieved in less than 1 µs. Conclusions: The FBSM is designed to provide real-time beam profile monitoring over a large active area without significantly degrading the beam quality. A prototype device has been staged in particle beams at currents of single particles up to FLASH level dose rates, using both continuous ion beams and pulsed electron beams. Using a novel scintillator, beam profiling has been demonstrated for currents extending from single particles to 10 nA currents. Radiation damage is minimal and even under FLASH conditions would require ≥50 kGy of accumulated exposure in a single spot to result in a 1% decrease in signal output. Beam imaging is comparable to radiochromic films, and provides immediate images without hours of processing. Real-time data processing, taking less than 50 µs (combined data transfer and analysis times), has been implemented in firmware for 20 kHz frame rates for continuous proton beams.

2D beam imaging↗

Time-tagging data acquisition system for testing superconducting electronics based on an RFSoC and custom analog frontend

Novel electronic devices can often be operated in a plethoraof ways, which makes testing circuits comprised of them difficult.Often, no single tool can simultaneously analyze the operatingmargins, maximum speed, and failure modes of a circuit, particularlywhen the intended behavior of subcomponents of the circuit is notstandardized. This work demonstrates a cost-effective time-domaindata acquisition system for electronic circuits that enables moreintricate verification techniques than are practical withconventional experimental setups. We use high-speeddigital-to-analog converters and real-timemulti-gigasample-per-second waveform processing to push experimentalcircuits beyond their maximum operating speed. Our customtime-tagging data capture firmware reduces memory requirements andcan be used to determine when errors occur. The firmware iscombined with a thermal-noise-limited analog frontend with50 dB of dynamic range. Compared to currentlyavailable commercial test equipment that is seven times moreexpensive, this data acquisition system was able to operate asuperconducting shift register at a nearly three-times-higher clockfrequency (200 MHz vs. 80 MHz).

Foster, Reed A. [MIT] (ORCID:0000000231002127)↗

otsdaq

otsdaq is a Ready-to-Use data-acquisition (DAQ) solution aimed at scaling down to test-beam, detector development, and other rapid-deployment scenarios; and scaling up through the development cycle to fullscale production and operation. otsdaq uses the artdaq DAQ framework under-the-hood, providing flexibility and scalability to meet evolving DAQ needs. otsdaq provides a library of supported front-end boards and firmware modules which implement a custom UDP protocol. Additionally, an integrated Run Control GUI and readout software are provided, preconfigured to communicate with otsdaq firmware.

Rivera, Ryan [Fermi National Accelerator Laborator↗

An Open-Source Framework for Rapid Validation of Scientific ASICs

Spacely is an open-source framework for the post-silicon validation of analog, digital, and mixed-signal ASICs (Application-Specific Integrated Circuits) which maximizes the reuse of hardware and software, reducing the time taken to achieve meaningful test results. Spacely specifically addresses the needs of small, flexible ASIC design teams commonly found in academia or research institutions which benefit most from sharing the overhead of test stand creation between many unique ASIC designs. Spacely is a set of software, firmware, and design practices. It targets two primary hardware platforms (NI-PXI and Caribou) as well as offering extensible support for bench instruments. Spacely provides a high-level Python interface to all test hardware for accessibility, while also giving more sophisticated teams the opportunity to integrate custom test firmware. The design principles of Spacely are presented in brief. Current documentation is available at https://github.com/SpacelyProject/spacely-docs.

Quinn, Adam [Fermilab]↗

Physical Testing of The PSEC5 ASIC

The PSEC5 ASIC is a high-speed waveform sampling chip designed for ultra-fast timing detectors, offering up to 40 GSPS sampling with 10-bit resolution. This makes it well-suited for applications requiring fine time resolution, such as MCPs and LGADs. This work focuses on the physical testing and validation of the chip s internal clocking and SPI-controlled registers. Testing began with inspection of schematics and the prototype to identify and resolve design issues. Then, custom firmware was developed for an Arduino controller to interface with the chip via SPI, enabling read and write access to key control registers. Results confirm that the VCO operates between ~3.2 4.0 GHz and remains stable under non-VCOVDD fluctuations. The Division Ratio register enables frequency division by known factors (256, 128, 64, etc.), indicating a pre-division frequency of 3.2 GHz when the digital band is unmodified. While most registers responded correctly, some issues were observed, including unexpected current draw and unstable discriminator behavior. Overall, the chip shows promising functionality, but further work is needed to understand the state of the read only registers and address the existing issues. Continued testing and firmware development will be critical to ensuring reliable integration into detector systems.

Fahey, Alexander [Unlisted, US]↗

Apex Study: Compensating Transient Beam Loading in the RHIC 28 MHZ

With the EIC on the way, it is important that developments and strategies are in place to deal with the very high beam currents that the machine will feature. Specifically, the EIC will collide beams of up to 2.5 A, three times the beam current in RHIC. This higher beam current will cause significant voltage transients in the cavity fields which can lead to longitudinal instabilities and beam loss. In anticipation of these negative effects, studies were carried out on the RHIC 28 MHz cavities using newly developed firmware and software to diagnose and combat beam loading. Diagnostic tools such as the bunch-by-bunch (BbyB) ADC firmware and digital network analyzer (DNA) were used to characterize the closed loop system and transient on the cavity voltage magnitude and phase. Then, a one-turn delay feedback (OTFB) and adaptive feed-forward (aFFWD) were used to minimize the transient beam loading. The studies were carried out with beam during 2 accelerator physics experiements (APEXs) using one of the 28 MHz accelerating cavities here at RHIC.

43 PARTICLE ACCELERATORS↗

Intelligent Experiments Through Real-time AI: Fast Data Processing and Autonomous Detector Control for sPHENIX and Future EIC Detectors (Final Report)

The overall vision of this project was to integrate real-time artificial intelligence (AI) directly into the data acquisition and detector-control systems of nuclear physics experiments, including both fast online event selection and an autonomous detector-control feedback loop. The work carried out under the award focused on the fast online event-selection half of that vision: the efficient recording of low-momentum heavy-flavor (HF) hadron decays in proton-proton collisions at the sPHENIX experiment at the Relativistic Heavy Ion Collider (RHIC)—an observable that requires fast tracking and topological trigger selection not previously demonstrated at RHIC, and that is essential for QCD studies at future facilities such as the Electron-Ion Collider (EIC). The autonomous detector-control (GPU-based feedback) component named in the project title remained a design concept and was not implemented under this award. The Massachusetts Institute of Technology (MIT) group led the offline simulation and data processing needed to train the machine-learning (ML) models, the translation of trained models to Field-Programmable Gate Array (FPGA) firmware using the hls4ml framework, and the physics validation of heavy-flavor reconstruction. Over the award period, the team developed and hardware-tested the principal components of an AI-based heavy-flavor trigger on simulated and recorded sPHENIX tracker data: a software Bipartite Graph Attention Network (BiGAT) trigger model reaching > 95% signal efficiency at 99% background rejection; an FPGA-native hit clusterizer matching the offline clustering; smaller networks synthesized to FPGA within the required sub-10 µs latency; and an assembled decoder–clusterizer–inference firmware chain exercised on the FELIX readout board. A complete, fully integrated hardware demonstrator was not finished within the award period. This report documents the project goals, the MIT group’s contributions, the technical accomplishments, and the outlook toward applications at the future EIC ePIC detector.

73 NUCLEAR PHYSICS AND RADIATION PHYSICS↗