Search NASA⌕ Search

SEARCH · Search NASA

Results for “Public key cryptography”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

Inventory of Public Key Cryptography in US Electric Vehicle Charging

Electric vehicles (EVs) and charging infrastructure are networked systems, which employ high-level communications in support of charging and grid service decisions. Public key cryptography (PKC) underlies much of the security and privacy protections of the information exchange. We are entering a new epoch where quantum computing threats must be seriously considered. A sufficiently large quantum computer, so named Cryptographically Relevant Quantum Computer (QRQC), will be able to perform the mathematical operations to efficiently attack the underpinnings of traditional PKC, thus jeopardizing the digital foundations for trust, communications security, and data security. Estimates suggest a QRQC can break public key encryption and digital signatures in the manner of tens to hundreds of hours, compared to traditional computing that would demand more than 10 18 years in a brute force-style attack. A consensus belief of quantum theorists, quantum experimenters, and cryptographers suggest that the quantum threat will be likely realized in the next twenty years. To address the threat, post-quantum cryptography, which is cryptosystems that are designed to be secure against both traditional and quantum computing threats, must be adopted. Migration from traditional PKC to quantum-resilient cryptography is a global undertaking and likely represents the largest transition in computing history. The nascent state of EV public key infrastructure, combined with limited adoption of the vehicle secure charging features, presents an opportunity to establish a preference for quantum-resistant cryptography as a step on the migration path. Delays will stunt the efforts as rapidly accelerating EVs sales and huge infrastructure investments will create large growing bases of long-lived vehicles and infrastructure. Migration preparations can commence while NIST continues the process to standardize post-quantum cryptography (PQC), which are quantum-resilient algorithms designed to be secure against traditional and quantum computing threats. The first step in preparing EV charging is to identify the presence of traditional public key cryptography algorithms and applications. With this objective in mind, this report is intended to advise the vehicle manufacturers, charging station manufacturers, charging station operators, charge network providers and other EV charging stakeholders with information on traditional PKC application and the potential risks when PKC becomes insecure. This report, the first in a series of reports discussing the topics existing at the confluence of post-quantum cryptography adoption and EV charging, identifies traditional public key applications employed and identifies potential consequences of leaving EV charging infrastructure vulnerable to quantum computing. The focus remains squarely on the of EV charging and infrastructure with respect to PKC and is believed by the authors to complement the NIST SP 1800-38 Migration to Post-Quantum Cryptography. While the report is centered on infrastructure, there are implications to vehicles.

33 ADVANCED PROPULSION SYSTEMS↗

PUF-Based Two-Factor Authentication Protocol for Securing the Power Grid Against Insider Threat

Recent advances in smart grid technologies have enabled additional distributed control paradigms that allow more efficient and reliable operation. However, this creates new security concerns for the grid, such as attackers using spoofed grid control devices to generate false measurements. This paper introduces a two-factor authentication protocol leveraging standard public-key cryptography as one authentication factor and a hardware-based fingerprint, known as a Physical Unclonable Function, as a second authentication factor. This protocol incurs a small overhead and prevents cyber-attacks even when an adversary is able to compromise the cryptographic keys stored in the non-volatile memory of an intelligent control device.

42 ENGINEERING↗

Exploring the Adoption Challenges of Post-Quantum Cryptography in EV Charging Infrastructure

The rapid evolution of electric vehicle (EV) technology and the corresponding growth of the Electric Vehicle Charging Infrastructure (EVCI) brings to light significant cybersecurity concerns, notably in the context of emerging post-quantum computing capabilities. This report, prepared by Pacific Northwest National Laboratory (PNNL) under the U.S. Department of Energy contract, delves into the challenges associated with integrating Post-Quantum Cryptography (PQC) into EVCI to safeguard against potential quantum computing threats. Post-quantum computers will eventually be able to invalidate technologies secured through public key cryptography. As part of this effort, the primary gaps and challenges in the EVCI were investigated with a focus on comparing traditional algorithms against PQC algorithms. One of the notable findings was that the P-521 algorithm was frequently surpassed in performance by PQC algorithms. This document provides a thorough examination of the hurdles the industry can expect when transitioning to PQC within the EVCI, such as interoperability concerns, the computational and memory demands of PQC algorithms, and the organizational readiness for such a transition. It emphasizes the necessity of a forward-thinking approach to cybersecurity, advocating for early and strategic engagement among EVCI stakeholders to ensure a seamless and cost-effective migration to quantum-resistant cryptographic standards. Through this report, the authors aim to catalyze awareness and action among policymakers, industry leaders, and cybersecurity professionals towards fortifying the EVCI against emerging quantum threats, thereby securing the infrastructure essential for the future of electric mobility.

33 ADVANCED PROPULSION SYSTEMS↗

Entanglement-based quantum digital signatures over a deployed campus network

The quantum digital signature protocol offers a replacement for most aspects of public-key digital signatures ubiquitous in today’s digital world. A major advantage of a quantum-digital-signatures protocol is that it can have information-theoretic security, whereas public-key cryptography cannot. Here we demonstrate and characterize hardware to implement entanglement-based quantum digital signatures over our campus network. Over 25 hours, we collect measurements on our campus network, where we measure sufficiently low quantum bit error rates (<5% in most cases) which in principle enable quantum digital signatures at over 50 km as shown through rigorous simulation accompanied by a noise model developed specifically for our implementation. These results show quantum digital signatures can be successfully employed over deployed fiber. Moreover, our reported method provides great flexibility in the number of users, but with reduced entanglement rate per user. Finally, while the current implementation of our entanglement-based approach has a low signature rate, feasible upgrades would significantly increase the signature rate.

97 MATHEMATICS AND COMPUTING↗

Active High Assurance Authentication Protocol (AHAAP)

The AHAAP Maturation Project involves maturation and evaluation of a patented zero-trust tamper-resistant high-assurance session-less dynamic and active device authentication protocol that simultaneously authenticates identity and provides integrity verification in a single step, substantially reducing the risk of cyberattack, and eliminating the need for costly and complex conventional communication security systems requirements (i.e., cryptography, Public Key Infrastructure (PKI), and key management). These cybersecurity attributes of the technology must be preserved when applying the technology to different cybersecurity solutions, including Command & Control (C&C), Over-the-Air (OTA) update, Common Access Card (CAC), and distributed energy resource (DER) implementations, among others. The technology research objective is to test and verify that the cybersecurity attributes of the technology are not degraded in different cybersecurity applications. The primary technology development objective is to build minimum viable products to demonstrate the technology addresses today’s cybersecurity threats so that prospective investors, strategic partners, regulatory agencies, and commercial customers can interact with and assess the protection assured by the technology. The AHAAP Maturation Project goal is to develop, test, and validate one or more AHAAP implementations. The AHAAP Maturation Project tasks are: (i) engineer AHAAP implementation software, (ii) build a functional prototype that implements the AHAAP software for demonstration, testing, analysis, and evaluation purposes, and (iii) generate a report detailing the results of the AHAAP C&C software and hardware implementation. The final project deliverables are: (i) AHAAP software implementation and prototype, (ii) a report from Sandia National Laboratories detailing the results of the AHAAP implementations.

97 MATHEMATICS AND COMPUTING↗

Oak Ridge National Laboratory Pilot Demonstration of an Attestation and Anomaly Detection Framework using Distributed Ledger Technology for Power Grid Infrastructure

This report summarizes the design and pilot demonstration of a framework called Grid Guard that was created to provide increased data and device trustworthiness to electric grid devices by leveraging distributed ledger technology (DLT), specifically blockchain. Grid Guard contains a combination of core cryptographic methods such as the secure hash algorithm (SHA), and asymmetric cryptography, private permissioned blockchain, baselining configuration data, consensus algorithm (Raft) and the Hyperledger Fabric (HLF) framework. The system implements a low energy, fast, and robust enhancement to system trustworthiness within and across electric grid systems such as substations, control centers and metering infrastructures. Blockchain is a distributed database structured that provides a practically unalterable (immutable) timeline of stored transactions. By relying on hashing and the Raft consensus algorithm, if an entity tries to illegitimately alter a record at one instance of the database the other ledger nodes are not altered. They work to cross-reference each other and easily locate any incorrectly added data and remove it. The bulk raw data is stored in an off-chain storage (outside of the blockchain ledger) and a hash of this baseline data is stored in the Blockchain ledger via hashing windows of time-series and configuration data, after aggregation and filtering. The bulk off-chain data repository is then considered to be trust-anchored using the hashes stored in the blockchain. To secure the electric grid testbed devices and data, device configuration baselines were compared to those baselines that had been previously stored in the ledger. Statistical baselines for device configurations, network communication patterns, and high-speed sensor data are calculated and then stored off-chain and hashes stored in the ledger. Measurements such as three-phase voltage and current, frequency, breaker status, protection scheme settings, network configuration settings (and other device configuration artifacts) and network traffic features (packet interarrival times) are compared every minute or other selected time windows. During phase 1 of the Grid Guard DLT project different DLT technologies were studies, and an assessment was performed on DLT technology vulnerabilities, uses, and key characteristics. DLT consensus protocols were studies (e.g., RAFT, named after Reliable, Replicated, Redundant, And Fault-Tolerant). Also, cryptography, public, private and permissioned or permissionless systems were assessed. Grid Guard implements a permissioned private DLT. Consensus algorithm selection and choice of DLT implementation depended heavily on the use-case. For this use-case, parameters were selected to measure performance and existing tools for assessment. Benchmarking was performed theoretically and practically. During phase 2 hashed transactions/blocks were inserted into the ledger every second. During phase 2 of the Grid Guard DLT project, a prototype framework was developed and demonstrated for attestation of critical substation devices and data using precision timing systems that use PTP and IRIG-B protocols) on a testbed of operational devices that emulated a distribution substation, control center, and power metering infrastructure using real Operational Technology (OT). The testbed includes OT devices such as protective relays, human machine interfaces (HMI), and power meters. To determine when to collect and compare system and network baselines, an initial examination of an anomaly detection capability to identify malicious manipulation of data streams was conducted. The resulting anomaly detection was demonstrated in a set of experiments and leveraged to trigger device artifact attestation checks. Attestation checks occur against device configuration baselines when compared with the immutable blockchain-stored baselines, which provided a cryptographically supported means by which to store baselines. The electrical substation-grid testbed was created to test the Grid Guard framework. The testbed emulates the operations of a portion of a power grid and SCADA systems as closely as possible. The testbed integrates real protocols, mainly IEC 61850 standard protocols, such as the Sampled Value (SV) and the GOOSE protocols. The testbed also supports DNP3 and other layer 2 and layer 3 protocols such as Telnet, SSH, SFTP/FTP and other proprietary protocols needed to connect to industrial control system equipment. The testbed emulates real power conditions using the OpalRT hardware-in-the-loop (HIL) device which can create fault situations that cannot be easily tested on real systems. The electrical substation-grid testbed was created using real measurement, communication, and protection devices that electrical utilities commonly use.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Quantum Key Distribution for Critical Infrastructures: Towards Cyber-Physical Security for Hydropower and Dams

Hydropower facilities are often remotely monitored or controlled from a centralized remote control room. Additionally, major component manufacturers monitor the performance of installed components, increasingly via public communication infrastructures. While these communications enable efficiencies and increased reliability, they also expand the cyber-attack surface. Communications may use the internet to remote control a facility’s control systems, or it may involve sending control commands over a network from a control room to a machine. The content could be encrypted and decrypted using a public key to protect the communicated information. These cryptographic encoding and decoding schemes become vulnerable as more advances are made in computer technologies, such as quantum computing. In contrast, quantum key distribution (QKD) and other quantum cryptographic protocols are not based upon a computational problem, and offer an alternative to symmetric cryptography in some scenarios. Although the underlying mechanism of quantum cryptogrpahic protocols such as QKD ensure that any attempt by an adversary to observe the quantum part of the protocol will result in a detectable signature as an increased error rate, potentially even preventing key generation, it serves as a warning for further investigation. In QKD, when the error rate is low enough and enough photons have been detected, a shared private key can be generated known only to the sender and receiver. We describe how this novel technology and its several modalities could benefit the critical infrastructures of dams or hydropower facilities. The presented discussions may be viewed as a precursor to a quantum cybersecurity roadmap for the identification of relevant threats and mitigation.

97 MATHEMATICS AND COMPUTING↗

Exploring Applied Cryptosystems to Formally Verify Security in Cyber-Physical Systems

This project aims to evaluate RSA as a method for public-key encryption for cyber-physical systems (CPS). As technology advances, cyber attacks are increasing, and with them, the need for cybersecurity advances; the average cost for cybercrime in the world was estimated at $6 trillion in 2021. A public-key cryptosystem that has been around since 1977, RSA has recently garnered some critiques for its fragility, computational cost, and lazy implementation. In this project I will review the mathematical derivation of RSA, analyze the practical implications of such mathematical framework for the security of RSA, and propose a formal methods based approach to verify encryption schemes for CPS.

97 MATHEMATICS AND COMPUTING↗

Can you sign a quantum state?

Cryptography with quantum states exhibits a number of surprising and counterintuitive features. In a 2002 work, Barnum et al. argue that these features imply that digital signatures for quantum states are impossible (Barnum et al., FOCS 2002). In this work, we ask: can all forms of signing quantum data, even in a possibly weak sense, be completely ruled out? We give two results which shed significant light on this basic question. First, we prove an impossibility result for digital signatures for quantum data, which extends the result of Barnum et al. Specifically, we show that no nontrivial combination of correctness and security requirements can be fulfilled, beyond what is achievable simply by measuring the quantum message and then signing the outcome. In other words, only classical signature schemes exist. We then show a positive result: a quantum state can be signed with the same security guarantees as classically, provided that it is also encrypted with the public key of the intended recipient. Following classical nomenclature, we call this notion quantum signcryption. Classically, signcryption is only interesting if it provides superior performance to encrypt-then-sign. Quantumly, it is far more interesting: it is the only signing method available. We develop "as-strong-as-classical" security definitions for quantum signcryption and give secure constructions based on post-quantum public-key primitives. Along the way, we show that a natural hybrid method of combining classical and quantum schemes can be used to "upgrade" a secure classical scheme to the fully-quantum setting, in a wide range of cryptographic settings including signcryption, authenticated encryption, and CCA security.

71 CLASSICAL AND QUANTUM MECHANICS, GENERAL PHYSIC↗