Search NASA⌕ Search

SEARCH · Search NASA

Results for “Functional Assurance”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Moving from Information Assurance to Functional Assurance with Engineered Controls

Cyber threats to operational technology demand more than traditional IT defenses—they require full-spectrum mission assurance. Cyber-Informed Engineering (CIE) is an approach that embeds engineered controls into system design to ensure critical functions remain safe and reliable, even under attack. Unlike conventional cybersecurity tools, engineered controls act directly on physical processes to prevent unacceptable outcomes such as equipment damage or mission failure. This session will outline the CIE framework and share examples of consequence-based design that deliver true resilience, not just fail-safe behaviors. Attendees will learn how to integrate these principles into the engineering lifecycle to support resilient-by-design architectures and inform emerging standards. This talk sets the stage for the panel discussion on advancing CIE across sectors as digital and physical systems converge.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

CRITICAL FUNCTION ASSURANCE: Understanding Critical Function and Critical Function Delivery is Foundational for Meaningful ICS Security Improvement and Policy Efforts

Modern life is enabled by a complex and interdependent web of critical functions, including energy, communications, transportation, food, and water. Automation has significantly reduced or replaced human interactions in the delivery of these functions, resulting in a web of goods and services that are made available 24/7 only through unique and intentional deployments of microprocessors, software, and firmware technologies. The prospect of cyber-enabled sabotage of these processes disrupts traditional risk determination models. Critical Function Assurance (CFA) is a foundational approach to identifying, prioritizing, and mitigating the risk that is inherent in the delivery of critical functions that depend on digital technology. It provides rapid focus to what matters most and illuminates elements and areas of risk that otherwise are often overlooked. This focus enables effective application of available security resources and optimizes security strategy and policy efforts. This paper introduces CFA to decision makers and risk executives (including CEOs, COOs, CFOs, and CISOs) whose organizations support and deliver the critical functions that underpin national defense, societal health and safety, and a vibrant economy.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Cyber-Enabled Sabotage, Critical Function Assurance, and Cyber-Informed Engineering

Cyber-enabled Sabotage, Critical Function Assurance, and Cyber-Informed Engineering: This discussion will introduce the idea of cyber-enabled sabotage, and the role engineering plays in the cyber defense of critical functions with a focus on electric power systems. It will outline how and why engineering practice must be used to apply cybersecurity principles to establish safe and reliable operations even in the face of determined and skilled adversaries, and give an overview of INL’s Consequence-Driven Cyber-Informed Engineering methodology to apply these principles. There will be an opportunity for audience questions and answers at the end of the session.

42 ENGINEERING↗

Application of Cyber-Informed Engineering for Protecting BESS

This white paper synthesizes an array of crucial grid services provided by BESS technology, assesses its architecture and communications, and presents a case study for analysis against the principles introduced by Cyber-Informed Engineering (CIE). Furthermore, in walking through the analysis, this paper presents a framework to evaluate risks and solutions when considering BESS components. Asset owners and buyers could perform this analysis to assess their BESS product implementations, alternative inverter-based resources (IBR), and energy management systems (EMS). Battery systems fulfill various roles contingent on the unique market demands and the specific challenges presented by regional grid infrastructures. These roles also vary due to the differing utility models for ownership and operation, which are adapted to meet regional and local capabilities and requirements. Concerns have been raised regarding the potential for adversaries to exploit knowledge of battery operational patterns to orchestrate decisive attacks. However, the security of operational data for these systems may not be the primary vulnerability, as much of this information is already well-understood within the community. Applying a modest degree of subject matter expertise can often yield valuable predictions regarding how a battery will respond under certain conditions, such as grid emergencies, high or low-temperature days, Public Safety Power Shutoff (PSPS) events, and outages. The operational characteristics of batteries are well-documented, and their capabilities, including the risks associated with misoperation and the resulting consequences, are published and understood within the industry. CIE practices represent the next step in gaining functional assurance and providing an acceptable level of risk, regardless of whether a battery vendor can support a trusted and validated supply chain. While this issue has exacerbated supply chain challenges, it is not an isolated condition. This foreign supply route is the primary source of BESS for the U.S. market. Significant efforts are underway through the Bipartisan Infrastructure Law (BIL) to change that. Still, strategic short-term operational mitigations are needed to ensure the security of our operational technology (OT) systems, which are enhanced by instilling trust and are separate from vendors implementing CIE principles.

25 ENERGY STORAGE↗

IEEE PES GM Poster - Cyber-Informed Engineering Approach to Mitigating BESS Supply Chain Concerns

Battery energy storage systems (BESS) are increasingly important to meet the needs of grid resilience and reliability. BESS provide critical grid services, maintaining stability of the grid with increased variable conditions. However, there are significant geopolitical and security concerns regarding their operation in critical infrastructure, due to lack of a domestic supply chain and prevalence of foreign entity of concern (FEOC) components in BESS and associated inverter-based resources. The supply chain challenge is dually exacerbated by a lack of alternative suppliers who can meet the economic targets for energy delivery and a potentially adversarial supply chain. Solutions are needed to secure components, addressing mixed layers of risk and engineering controls. This paper presents a specific application of Cyber-Informed Engineering (CIE) principles for BESS and recommends an alternative strategy to blocking the supply chain, ensuring that grid modernization targets can be met despite lack of a validated or secure supply chain. This study focuses on the United State (U.S.) use case, but the process can be applied globally to address supply chain security challenges. CIE practices represent the next step in functional assurance and risk mitigation, ensuring optimal resource allocation and enhancing security measures to safeguard the future of energy in the U.S. and beyond.

25 - ENERGY STORAGE↗

Function-based Taxonomy Implementation

Function-based taxonomies are relational mapping tools used to clearly illustrate how an organization delivers Critical Functions by using various people, processes, technologies, information, and infrastructure (PPTII). Critical Functions are the actions or activities that make up the organization’s primary purpose. Enabling Functions are the combination of PPTII used by the organization to deliver their Critical Functions. A function-based taxonomy provides a framework to categorize information and related artifacts that document an organization’s unique implementation of PPTII for Critical Function delivery. The ideal state of a function-based taxonomy is to organize the existing knowledge the organization already has throughout their numerous systems, policies, people, procedures, and configurations. A well-organized taxonomy helps organizations to effectively leverage their knowledge by clearly identifying dependencies and connections. This document is the result of combined engineering and analytical experience and describes a repeatable method for producing function-based taxonomies.

42 ENGINEERING↗

Digital-Threat Bias and Psychological Distance: Barriers to Foundational Digital-Security Improvement

Modern life is held together by a web of digital dependencies that enable and provide delivery of critical services and functions—think the provision of utilities such as electricity and water, as well as our dependency on digital services for social and economic services (internet, communication, etc.). As this dependency grows, the complexity related to the delivery of these critical services increases as well. As complexity increases, the understanding of the risk and impact associated with potential disruption, degradation, or destruction—due to either malicious or non-malicious events of those digitally enabled functions—decreases. One potential explanation for the difficulty to 1) understand the risks faced and 2) address them appropriately and effectively is the abstractness and psychological distance assigned to “digital threat.” The complexity of these digitally enabled services creates a perceived complicatedness; as a result, digital threats are treated differently than similarly devasting (but more easily understood) kinetic or physical threats. How we categorize these threats also matters. Acts of cyber-enabled sabotage to critical infrastructure need to be defined as irregular warfare. By inadequately defining the threat, we compound the problem. Acknowledging this digital-threat bias is foundational to improving the ability to protect critical infrastructure. Using construal-level theory and psychological-distance concepts provides an intriguing starting point to address these issues, to reframe the challenges faced, and pursue more effective critical infrastructure security and defense policy.

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

Shorter function summaries for finite state machine-based high consequence systems using logic synthesis and tautologies (Final Report LDRD 24-1302)

Computer programs are often viewed as collections of functions – each function has parameters (inputs) and computes a return value, and each has potential side effects that modify program state (outputs). In this research, a Sandia symbolic execution tool designed to support “human-in-the-loop” analysis was modified to automatically create “function summaries,” and a new tool, “diaboolical,” was created to support enhancing readability of the summary using a novel approach to bit-vector simplification that leverages logic synthesis and tautologies. For this effort, students at Auburn University created several finite state machines (FSMs) to serve as exemplars for high-consequence systems. Function summaries for each of the machines were obtained, and then portions of the summaries were simplified using both diaboolical and the simplification procedure of a popular SMT solver. A comparison of the results shows that diaboolical can often produce smaller function summaries, with expression length improvements over the unsimplified function summaries ranging from 0% to 90% for diaboolical and 0% to 65% for the SMT solver, though diaboolical had a significantly greater cost in time. Diaboolical was evaluated against a collection of “arbitrary” C-code as well as FSM exemplars, and for both datasets it achieved an approximately 10% improvement in expression length compared to simplifications that could be obtained using existing techniques. Function summaries can assist assurance efforts that evaluate existing systems and their executable code. A smaller function summary is likely easier for humans to understand and could thus increase the ability and efficacy of assurance practices centered around the analysis of executable artifacts.

97 MATHEMATICS AND COMPUTING↗

TRISO Fuel’s Safety Functions, Contributions to Reactor Safety, and Necessary Safety Limits

Safety functions are the actions, passive or active, that structures, systems, and components of nuclear facility that contribute to the safety of the workers, the public, or the environment. Well-defined safety functions are the foundation of a solid safety case for a reactor. For reactors that use TRISO-coated particles, the TRISO fuel plays an important part of the safety case because of its ability to contain radionuclides in the fuel itself. This ability enables the use of a functional containment strategy for the reactor where radionuclide retention is the primary safety function supported by the safety functions of controlling reactivity control and controlling heat rejection. This paper establishes at a deeper level the role that TRISO fuel plays in each of these safety functions and associated quality assurance and testing requirements for TRISO particle manufacturing to ensure these safety functions. Safety limits necessary to protect these safety functions include: operational limits, time at temperature limits, and fission gas release activity limits. In conclusion, this approach demonstrates the role that specific aspects of TRISO fuel play in protecting the safety of workers, the public, and the environment.

11 - NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

MARVEL 90% Final Design Report

This document provides documentation of the Microreactor Applications Research Validation and Evaluation Project’s (MARVEL) 90% Final Design, as required by U.S. Department of Energy (DOE) Standard-1189, “Integration of Safety into the Design Process." Per DOE-STD-1189-2016, the 90% Final Design documentation focuses on design completion, at a level capable of supporting procurement, construction, testing, and operation. At this phase, the design organization finalizes the hazards and accident analyses, Fire Hazard Analysis (FHA), security vulnerability assessments, and other supporting analyses for design completion. The objective of this report is to provide a high-level summary of the design thus far and provide references including, but not limited to, the following design deliverables: • Complete final drawings, specifications and commercial grade dedications that may be released for bid and/or construction. • Clearly defined testing plans for the safety and functionality of all subsystems. • Quality Assurance Program for Design, Testing and Procurement. • Software Quality Assurance Plan. • Code of Record (COR), applicable design requirements including codes and standards. • Final design that meets all the requirements stipulated in the COR. • Final design review, consisting of final validation of comment resolution from previous reviews, and a review of any additional developments since the last review. • Updated Safety Design Strategy. • Hazard Analysis. • Fire Hazard Analysis. • Accident analysis. • Security vulnerability assessment. • Current and detailed cost estimate. • Current construction schedule, and • Risk & Opportunities Assessment.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Design and Construction of the CMS Outer Tracker for the Phase-2 Upgrade

The High Luminosity LHC (HL-LHC) is expected to deliver an integrated luminosity of 3000-4000~fb$^{-1}$ after 10 years of operation with peak instantaneous luminosity reaching about 5-7.5$\times10^{34}$cm$^{-2}$s$^{-1}$. During Long Shutdown 3, several components of the CMS detector will undergo major changes, called Phase-2 upgrades, to be able to operate in the challenging environment of the HL-LHC. The current CMS tracker will be replaced. The Phase-2 Outer Tracker (OT) will have high radiation tolerance, higher granularity, and the capability to handle higher data rates. Moreover, the OT will provide tracking information to the Level-1 trigger, for the first time at hadron colliders, allowing trigger rates to be kept at a sustainable level without sacrificing physics potential. For this, the OT will be made of modules with two closely spaced silicon sensors read out by front-end ASICs, which can correlate hits in the two sensors creating short track segments (stubs), used for tracking in the L1 track finder. The modules come in two flavors: strip-strip (2S) and pixel-strip (PS), containing different sensor configurations and multiple ASICs. This contribution will present the design of the Phase-2 OT, the first results with pre-production devices, and the quality assurance procedures used to ensure the functionality of the modules: from fulfilling the precision specification of the module assembly procedure to ensuring the proper communication among the module's ASICs.

43 PARTICLE ACCELERATORS↗

SCALE depletion capabilities for molten salt reactors and other liquid-fueled systems

Nuclear reactor systems that use fuel dissolved in a liquid have the potential for enhanced safety characteristics, improved fuel-cycle outcomes, and more efficient isotope-production configurations. In these reactor systems, the fueled liquid may simultaneously undergo irradiation, physical and chemical removal processes, and fueling. The modeling and simulation of this transmutation and decay with material additions and removals is an ongoing research area. An accurate simulation tool is critical to the reactor and fuel-cycle design, reactor deployment, and source-term characterization for these advanced reactor systems. The work described herein involved implementing, testing, and applying the capability to perform reactor physics simulations within the Oak Ridge National Laboratory-developed SCALE suite for nuclear systems analyses and design, leveraging much of its pedigree in quality-assurance and reactor-analysis capabilities. The functionalities to simulate irradiation with material feeds and removals had been added in ORIGEN, and the TRITON reactor physics sequence was extended to calculate the total removed material and track external nonirradiated mixtures to estimate separate processing or waste streams. Results from these capabilities align with analytical expectations obtained from ORIGEN for simplified test cases and with expectations for a molten salt reactor application. This implementation, available with the SCALE 6.3 release, provides for a more efficient and accurate material accountability methodology, allowing for the characterization, design, and analysis of the complete isotopic material inventory of advanced liquid-fueled systems for a variety of applications.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Uncertainty quantification in machine learning for engineering design and health prognostics: A tutorial

On top of machine learning (ML) models, uncertainty quantification (UQ) functions as an essential layer of safety assurance that could lead to more principled decision making by enabling sound risk assessment and management. The safety and reliability improvement of ML models empowered by UQ has the potential to significantly facilitate the broad adoption of ML solutions in high-stakes decision settings, such as healthcare, manufacturing, and aviation, to name a few. In this tutorial, we aim to provide a holistic lens on emerging UQ methods for ML models with a particular focus on neural networks and the applications of these UQ methods in tackling engineering design as well as prognostics and health management problems. Towards this goal, we start with a comprehensive classification of uncertainty types, sources, and causes pertaining to UQ of ML models. Next, we provide a tutorial-style description of several state-of-the-art UQ methods: Gaussian process regression, Bayesian neural network, neural network ensemble, and deterministic UQ methods focusing on spectral-normalized neural Gaussian process. Established upon the mathematical formulations, we subsequently examine the soundness of these UQ methods quantitatively and qualitatively (by a toy regression example) to examine their strengths and shortcomings from different dimensions. Then, we review quantitative metrics commonly used to assess the quality of predictive uncertainty in classification and regression problems. Afterward, we discuss the increasingly important role of UQ of ML models in solving challenging problems in engineering design and health prognostics. In conclusion, two case studies with source codes available on GitHub are used to demonstrate these UQ methods and compare their performance in the life prediction of lithium-ion batteries at the early stage (case study 1) and the remaining useful life prediction of turbofan engines (case study 2).

97 MATHEMATICS AND COMPUTING↗

Design and construction of the CMS Outer Tracker for the Phase-2 Upgrade

he High Luminosity LHC (HL-LHC) is expected to deliver an integrated luminosity of $3000-4000$~fb$^{-1}$ after 10 years of operation with peak instantaneous luminosity reaching about $5-7.5\times10^{34}$cm$^{-2}$s$^{-1}$. During Long Shutdown 3, several components of the CMS detector will undergo major changes, called Phase-2 upgrade, to be able to operate in the challenging environment of the HL-LHC. The current CMS silicon strip tracker has to be replaced with a new detector. The Phase-2 Outer Tracker (OT) will have higher radiation tolerance, higher granularity, and the capability to handle higher data rates compared to the current system. Another key feature of the OT will be to provide tracking information to the Level-1 (L1) trigger, allowing trigger rates to be kept at a sustainable level without sacrificing physics potential. For this, the OT will be made out of modules with two closely spaced sensors read out by front-end ASICs, which can correlate hits in the two sensors creating short track segments called stubs. The stubs will be used for tracking in the L1 track finder. The modules come in two flavors: strip-strip (2S) and pixel-strip (PS), which contain different sensor configurations and multiple ASICs. In this contribution, the design of the CMS Phase-2 OT, the technological choices, and the quality assurance (QA) procedures used to ensure the functionality of the modules will be reported. The contribution will cover the first results with pre-production devices and the different aspects taken into account during the QA: from fulfilling the precision specification of the module assembly procedure to ensuring the proper communication between the different ASICs on the module. The module noise performance is also checked and the full module functionality is verified at different temperatures.

Zoi, Irene↗

Functional protein mining with conformal guarantees

Molecular structure prediction and homology detection offer promising paths to discovering protein function and evolutionary relationships. However, current approaches lack statistical reliability assurances, limiting their practical utility for selecting proteins for further experimental and in-silico characterization. To address this challenge, we introduce a statistically principled approach to protein search leveraging principles from conformal prediction, offering a framework that ensures statistical guarantees with user-specified risk and provides calibrated probabilities (rather than raw ML scores) for any protein search model. Our method (1) lets users select many biologically-relevant loss metrics (i.e. false discovery rate) and assigns reliable functional probabilities for annotating genes of unknown function; (2) achieves state-of-the-art performance in enzyme classification without training new models; and (3) robustly and rapidly pre-filters proteins for computationally intensive structural alignment algorithms. Our framework enhances the reliability of protein homology detection and enables the discovery of uncharacterized proteins with likely desirable functional properties.

59 BASIC BIOLOGICAL SCIENCES↗

Antiferroelectric Ceramics for Energy–Efficient Capacitors by Theory–Guided Discovery

Antiferroelectric ceramics, via the electric-field-induced antiferroelectric (AFE)–ferroelectric (FE) phase transitions, show great promise for high-energy-density capacitors. Yet, currently, only 70–80% energy release is found during a charge–discharge cycle. Here, for PbZrO 3 -based oxides, geometric nonlinear theory of martensitic phase transitions is applied (first used to guide supercompatible shape-memory alloys) to predict the reversibility of the AFE–FE transition by using density-functional theory to assess AFE/FE interfacial lattice-mismatch strain that assures ultralow electric hysteresis and extended fatigue lifetime. A good correlation of mismatch strain with electric hysteresis, hence, with energy efficiency of AFE capacitors is observed. Here, guided by theory, high-throughput material search is conducted and AFE compositions with a near-perfect charge–discharge energy efficiency (98.2%), i.e., near-zero hysteresis are discovered. And the fatigue life of the capacitor reaches 79.5 million charge–discharge cycles, a factor of 80 enhancement over AFE ceramics with large electric hysteresis.

36 MATERIALS SCIENCE↗

SAM: A Modern System Code for Advanced Non-LWR Safety Analysis

The System Analysis Module (SAM), developed at Argonne National Laboratory and by collaborators at other organizations, is for advanced non–light water reactor safety analysis. SAM aims to provide fast-running, modest-fidelity, whole-plant transient analysis capabilities that are essential for fast-turnaround design scoping and engineering analyses of advanced reactor concepts. To facilitate code development, SAM utilizes the MOOSE object-oriented application framework, its underlying finite element library, and linear and nonlinear solvers to leverage modern advanced software environments and numerical methods. SAM aims to solve tightly coupled physical phenomena, including fission reaction, heat transfer, fluid dynamics, and thermal-mechanical responses in advanced reactor structures, systems, and components with high accuracy and efficiency. Finally, this paper gives an overview of the SAM code development, including goals and functional requirements, physical models, current capabilities, verification and validation, software quality assurance, and examples of simulations for advanced nuclear reactor applications.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Bison Verification and Validation Activities for TRISO

Numerical modeling and simulation (M&S) tools play a key role in the research, development, and overall safety assessments of next-generation nuclear energy systems. One such tool, Bison, is a nuclear fuel performance code that is applicable to many fuel forms (e.g., light-water reactor fuel, oxide and metallic fuel for fast reactors, tri-structural isotropic (TRISO) fuel, and plate fuel), and it uses the finite element method to model the thermo- mechanical response of nuclear fuels. One fuel form widely utilized in Generation-IV high-temperature gas-cooled and fluoride- salt-cooled nuclear reactor concepts is TRISO fuel. Recently, Bison’s capabilities were significantly expanded to enable it to model the performance of TRISO particles and compacts. It is important that Bison’s computational results be reliable and predictive, since this code is used to inform high-consequence decisions. The various processes developed to address this issue generally entail two fundamental steps: verification and validation (V&V). Verification ensures that the code functions correctly and is reliable. Code/solution verification, code benchmark, and software quality assurance exercises are examples of verification activities. On the other hand, validation is the process of assessing a code’s capability to accurately model physical problems. Comparisons between code results and experiments quantify the validation level. Application of V&V procedures is crucial to the development of computational tools that are free of coding mistakes and can accurately represent reality. The current study presents an overview of Bison V&V activities relevant to the TRISO fuel concept, which include code/solution verification exercises, CRP-6 Benchmark—a Coordinated Research Program through the International Atomic Energy Agency (IAEA)—exercises, and validation exercises with the Advanced Gas Reactor (AGR)- 1/2/3/4 experiment series.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗