Search NASA⌕ Search

SEARCH · Search NASA

Results for “Security by Design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

ORNL Peer Review Summary and Recommendations for: Advanced Reactor Designs Security Analysis, Risk, and Recommendations: Risks, Consequences, and Possible Design Mitigation Approaches Associated with Select Advanced Reactors Study

The purpose of this document is to provide a summary of the peer review conducted for the "Advanced Reactor Designs Security Analysis, Risk, and Recommendations: Risks, Consequences, and Possible Design Mitigation Approaches Associated with Select Advanced Reactors" study prepared by researchers at Idaho National Laboratory (INL), Argonne National Laboratory (ANL), and Oak Ridge National Laboratory (ORNL). The National Nuclear Security Administration (NNSA) International Nuclear Security (INS) program team requested that ORNL perform a peer review of the study report prior to publication as a final peer check before distributing the report to a broader audience.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Advanced Reactor Designs Security Analysis, Risk, and Recommendations: Risks, Consequences, and Possible by-Design Mitigation Approaches Associated with Select Advanced Reactors

Next-generation advanced reactors (ARs) incorporate enhanced safety systems, have smaller source terms, and feature compact modular designs, which should lessen their collective risk profiles. However, to fully evaluate risk, security needs to be a part of the equation. Without taking security into consideration, safety systems and components in the new ARs may be vulnerable to sabotage. These base attributes, coupled with enhanced security features specific to AR design through sound engineering and security-by-design (SeBD), should provide developers and operators with lower inherent security risk profiles. Building security early into the AR design may remove or passively secure potential critical targets from an adversary’s reach , thereby increasing overall safety and security. An integrated approach and diverse design team that includes engineering, operations, and security experts are fundamental to building security into the design without sacrificing fundamental operational efficiencies and principles. The objective of this project was to evaluate the security and safety interfaces for five classes of reactors, identify potential security vulnerabilities of structures, systems, and components (SSC), and underscore the need to consider security alongside safety in the design o f these concepts. The five reactor classes evaluated in this project and presented in this report are molten-salt reactors (MSR), high temperature gas reactors (HTGR), sodium-fast reactors (SFR), advanced light-water reactors (ALWR), and microreactors. These designs were selected because they reflect the concepts that are closest to market deployment and have received significant resource investments from the public and private sector. This project assesses the inherent security risks posed by common classes of ARs, provides a methodology and framework to assess security along with safety, and offers an analysis of potential mitigation strategies that could be incorporated. For each AR technology, the SSCs that relate to radionuclide source safety functions are discussed to understand the SSC contribution to safety and relative importance in the protective strategy for the design. The assumptions that went into evaluating each reactor concept originated from generic publicly available nonproprietary information and should not directly be used to qualify an absolute risk profile nor to rank specific AR designs. Instead, the purpose of the analysis is to understand and compare the generic inherent security risks of different AR technologies.

98 - NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL↗

Model-based Hierarchical Reinforcement Learning for Improved Physical Security Design: A Prototype

Prior work in FY24 developed an adversarial AI agent aid in path analysis of physical protection systems. This agent, trained using a model-based reinforcement learning algorithm, was able to successfully learn the most vulnerable path in facilities. It was able to extend the current state of practice for physical protection design by exhibiting dynamic behavior based on current environmental conditions. Whereas PathTrace largely performs a static, graph-based analysis, the AI agent was able to make decisions based on relative position in the facility, current conditions (was the adversarial agnet discovered?), and proximity to secondary targets. The agent demonstrated some novel capabilities, but had limitations that need to be resolved before it can be used for production purposes. For example, the adversarial agent generalizes poorly and takes a relatively long time to train. Nonetheless, there is still considerable promise for developing the adversarial agent further in order to explore even richer, more dynamic behaviors (e.g., adversary motivations, environmental debris, and more). This work considers a complementary idea; development of a planning agent. The planning agent is envisioned as an auto-complete-like tool that can help accelerate security system design by human experts. The agent would respect existing barriers and sensors placed by a human expert while offering cost-effective suggestions (i.e., implicitly balancing effectiveness with cost) to improve the design. The goal is for this agent to be part of an expert’s toolbox, not to totally upend the current state-of-practice, or to displace human experts. The ultimate goal would be concurrent training of both the adversarial and planning agent together, to learn entirely through self-play. This would represent an entirely new way of performing system deign. We selected a hierarchical, model-based reinforcement learning algorithm to serve as the planning agent. This is an extension of concepts used in the prior FY24 adversarial agent work. There, we had a single agent acting an environment. Here, we have two different sub-agents (policies), working together, to form a complete agent. There is a manager policy, which can select abstract goals on slower time scales, and a worker, which performs primitive actions to reach goals selected by the manager. It is worth noting that this class of algorithm is challenging to work with. From our understanding, our work is one of the first successful uses of model-based reinforcement learning (MBRL) in nuclear energy1 , and likely the first hierarchical model-based reinforcement learning application in nuclear energy. Further, this work is one of the first known attempts to apply AI to perform a design tasks in nuclear energy. Consequently, there were significant implementation challenges and the bulk of the work was focused on successful implementation and algorithm design. The results presented here are very low technology readiness level as a consequence of the lack of related literature, but still represent a significant step forward in the pursuit of applied AI for design.

42 ENGINEERING↗

ARC-100 Reactor Security-by-Design Summary

This report applies the security-by-design methodology developed in a previous National Nuclear Security Administration–sponsored work to the Advanced Reactor Concepts 100 (ARC-100) sodium-cooled fast reactor (SFR) design. The report contains no proprietary information specific to the ARC 100 reactor. The insights developed in this report are high-level, and generally applicable to other sodium fast reactor designs. The information presented here is the result of a qualitative safety-based analysis and would not inform any potential adversary beyond what would be found in a docketed safety analysis report. The scope of this present report covers ARC-100’s reactor core, used fuel storage, and used fuel assembly wash station. These systems are also compared to a generic SFR design assumed in the previous study. The security assessment results show changes in structures, systems, and components (SSCs) safety importance relative to the generic SFR SSCs. However, the consequence assessment results are the similar to a previously assessed generic SFR. Several SSCs have higher importance rankings than others, and it is recommended that protection efforts are prioritized for these SSCs. This work will continue in the Fiscal Year 2025 for the remaining ARC-100 systems, including cesium trap, sodium cold trap, noble gas decay tanks (dewar bottles), and used fuel dry storage facility, to provide safety-and-security-by-design insights and recommendations on non-core systems. Results from this work will furnish a technical justification for the feasibility of these solutions for the ARC reactor's design and, where applicable, identify any regulatory benefits conferred by the proactive design aspect within a risk management framework. This initiative will contribute to a more secure design of the ARC reactor and support its licensing process.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

ARC-100 Reactor Security-by-Design Summary 2025

This report applies the security-by-design methodology developed in a previous National Nuclear Security Administration–sponsored work to the ARC-100, a sodium-cooled fast reactor (SFR) being developed by ARC Clean Technology, Inc (ARC). The report contains no proprietary information specific to the ARC 100 reactor. The insights developed in this report are high-level, and generally applicable to other sodium fast reactor designs. The information presented here is the result of a qualitative safety-based analysis and would not inform any potential adversary beyond what would be found in a docketed safety analysis report. The scope of this present report covers ARC-100’s reactor core, used fuel storage, used fuel assembly wash station, cesium trap, sodium cold trap, noble gas decay tanks, used fuel dry storage facility, damaged fuel storage facility, and radioactive waste building. These systems are also compared to a generic SFR design assumed in the previous study. The security assessment results show changes in structures, systems, and components (SSCs) safety importance relative to the generic SFR SSCs. Several SSCs have higher importance rankings than others, and it is recommended that protection efforts are prioritized for these SSCs. Results from this work will furnish a technical justification for the feasibility of these solutions for the ARC reactor's design and, where applicable, identify any regulatory benefits conferred by the proactive design aspect within a risk management framework. This initiative will contribute to a more secure design of the ARC reactor and support its licensing process.

21 - SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLAN↗

Oak Ridge National Laboratory Security by Design: A Plant Design and Component-Based Approach to Technical Solutions to Insider and Outsider Threat

Security costs for nuclear reactors have been shown to rise over the lifecycle of a nuclear facility as new threats, security weaknesses, and the generic threat profile of the plant location change over time. This paper conducts a review of the technological gaps that currently exist in Security by Design (SeBD) based on the literature available and attempts to close those gaps through proposing technological constructs and processes that can integrate safety and security in the design process of a plant, with a primary focus on SMR technology. Under the new modular and mass manufacturing regime, where plant designs attempt to reduce costs with potential economies of scale and modular construction, the current SeBD definitions focusing on state level regulators are not considered adequate since the licensing stage is often too late in the design process to integrate the true cost savings of SeBD. Thus, this paper attempts to remedy the current logic in order to allow for continuous implementation of security alongside the development of the safety concept for the plant. If adopted within the design process the establishment of this type of technology will allow for a technological ecosystem to evolve that will imbed security concepts into the physical design of the components of the plant.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

U.S. Domestic Molten Salt Reactor: Security-by-Design

U.S. nuclear power facilities face increasing challenges in meeting dynamic security requirements caused by evolving and expanding threats while keeping costs reasonable to make nuclear energy competitive. The past approach has often included implementing security features after a facility has been designed and without attention to optimization, which can lead to cost overruns. Incorporating security in the design process can provide robust, economical, and effective physical protection systems (PPS). The purpose of this work is both to develop a framework for the integration of security into the design phase of a molten salt reactor (MSR) and show how to effectively design a PPS with a reduced staffing headcount. Specifically, this work focuses on integrating PPS design features into a developed facility layout by making minor modifications to building structures. A suite of tools, including Scribe3D©, PathTrace©, and Blender©, were used to model a hypothetical, generic domestic MSR facility. Physical protection elements such as sensors, cameras, barriers, and responders were added into the model based on defending the hypothetical MSR facility against a hypothetical design basis threat (DBT). Multiple outsider sabotage scenarios were examined, with adversary team sizes ranging from 4–8 to determine security system effectiveness. The results of this work will influence PPS designs and facility designs for U.S. domestic MSRs. This work will also demonstrate how a series of experimental and modeling capabilities across the Department of Energy (DOE) complex can impact the design and completion of security-by-design (SeBD) for small modular reactors (SMRs). The conclusions and recommendations in this document may be applicable to all SMR designs.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Microreactor Security-by-Design Recommendations for Domestic and International Deployments

This report outlines methods vendors can use to incorporate security-by-design (SeBD) into their microreactor facility design to support and address security for both U.S. and international deployment. The team developed a hypothetical below-grade microreactor with a physical protection system (PPS) to protect the microreactor against acts of theft and sabotage and evaluated it against two adversary attack scenarios defined by a group of adversary subject matter experts (SMEs). The hypothetical microreactor facility consists of two distinct buildings. The first is the above-grade protected area (PA) entry control point (ECP) building, which houses security personnel responsible for conducting screenings and managing access to the PA. The second building is the reactor building, which features both an above-grade floor and a below-grade floor.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Small Modular Reactor and Microreactor Security-by-Design Lessons Learned: Integrated PPS Designs

U.S. nuclear power facilities face increasing challenges in meeting dynamic security requirements caused by evolving and expanding threats while keeping costs reasonable to make nuclear energy competitive. The past approach has often included implementing security features after a facility has been designed and without attention to optimization, which can lead to cost overruns. Incorporating security into the design process can provide robust, cost-effective, and sufficient physical protection systems. The purpose of this report is to capture lessons learned by the Advanced Reactor Safeguards and Security (ARSS) program that may be beneficial for other advanced and small modular reactor (SMR) vendors to use when developing security systems and postures. This report will capture relevant information that can be used in the security-by-design (SeBD) process for SMR and microreactor vendors.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Driving Economics and Reducing Risks: The Business Case for Security-by-Design in Nuclear Power

This report provides an analysis of the financial, operational, and strategic advantages of incorporating Security-by-Design (SeBD) early in the lifecycle of nuclear power plant projects. By framing security as a foundational design element rather than a late-stage add-on, owners, vendors, and operators can reduce budget overruns, strengthen regulatory compliance, and increase revenue opportunities. The report details key lifecycle phases, highlighting the strategic imperative for organizations (including project developers, investors, vendors, and regulators) to adopt SeBD. Drawing on industry estimates, real-world case studies, and comparative cost analyses, the findings underscore that even a modest upfront investment in SeBD can yield substantial long-term returns by preventing costly retrofit activities, minimizing regulatory delays, and positioning nuclear vendors for the ability to adapt in the evolving security market. By avoiding excessive retrofit expenses and positioning security as a built-in feature rather than an afterthought, nuclear projects can protect their financial performance, enhance public trust, and secure a competitive edge in an increasingly complex global energy market. The authors advocate for SeBD’s strategic implementation, supported by established quality management methodologies, thereby promoting continuous improvement and defect avoidance. Ultimately, early SeBD integration represents a strategic investment, yielding significant returns by preventing costly retrofits and positioning nuclear projects for enhanced competitiveness and public trust.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Internship Presentation: Integrating Safety and Cybersecurity: Security-by-Design with SOWT Analysis for Reactor Testing

This study covers leveraging reactor testing facilities that are primarily designed with a focus on safety to enhance cybersecurity testing. By incorporating reactor security-by-design with reactor safety-by-design principles and adopting defense-in-depth strategies that emphasize both safety and security, the research evaluates applicable cyber tools, models, and solutions. This includes simulating specific cyber-attack scenarios using reactor simulators and performing SWOT (Strengths, Weaknesses, Opportunities, Threats) analysis to improve the cybersecurity of reactor systems.

21 - SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLAN↗

U.S. Domestic Security-by-Design: On Site Response Force Strategies

U.S. nuclear power facilities face increasing challenges in meeting dynamic security requirements caused by evolving and expanding threats while keeping cost reasonable to make nuclear energy competitive. The past approach has often included implementing security features after a facility has been designed and without attention to optimization, which can lead to cost overruns. Incorporating security in the design process can provide robust, cost- effective, and sufficient physical protection systems. The purpose of this work is both to develop a framework for the integration of security into the design phase of High Temperature Gas Reactors (HTGRs) that utilize pebble-based fuels and microreactors. Specifically, this effort focuses on integrating security into the design phase of a model HTGR and microreactor that meets current Nuclear Regulatory Commission (NRC) physical protection requirements and providing advanced solutions to improve physical protection and decrease costs. A suite of tools, including SCRIBE3D©, PATHTRACE© and Blender© were used to model a hypothetical, generic domestic HTGR facility and microreactor facility. Physical protection elements such as sensors, cameras, barriers, and onsite response forces were added to the model based on best practices for physical protection systems. Multiple outsider sabotage scenarios were examined with four-to-eight adversaries to determine security metrics. The results of this work will influence physical protection system designs and facility designs for U.S. domestic HTGRs and microreactors. This work will also demonstrate how a series of experimental and modeling capabilities across the Department of Energy (DOE) Complex can lead to efficient security systems that utilize an onsite response force. The conclusions and recommendations in this document may be applicable to all SMR designs.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

A National Secure-by-Design Strategy

The US National Cybersecurity Strategy published March 2, 2023 uses plain language to communicate that the US is calling for a major change in how we prioritize the security of software systems used in critical infrastructure. It acknowledges that our current approach, which is essentially, “let the buyer beware,” leaves entities who are least able to assess or defend vulnerable software responsible for the impacts of designed-in weaknesses while the makers of the technology bear no liability. The strategy recommends a security-by-design approach, recommending that software vendors be held liable to uphold a “duty of care” to consumers and for systems to be designed to “fail safely and recover quickly” . For energy infrastructure, the strategy calls out the need to implement the National Cyber-Informed Engineering Strategy to achieve higher confidence security for energy infrastructures. The Idaho National Laboratory, a pioneer in cyber-informed engineering concepts, is at the forefront of organizations educating others in industry, academia, and government on how to apply these concepts to real-world challenges. In this brief, we'll outline some of the basic principles of security-by-design and offer examples of how, in a water sector context, they're being put into successful practice.

42 ENGINEERING↗

Secure biosystems design in Saccharomyces cerevisiae establishes effective biocontainment strategies and mechanisms of escape

The widespread application of recombinant DNA and synthetic biology approaches for microbial metabolic engineering pursuits has motivated the development of biocontainment strategies, targeting safe and secure deployment of genetically modified microorganisms (GMMs). However, the design rules and mechanistic drivers governing biocontainment efficacy, as well as impacts of biocontainment upon microbial fitness, remain to be comprehensively evaluated, hindering predictive design and application of these strategies. We have developed a platform for high-resolution analysis of a transactivated kill switch in laboratory and industrial strains of Saccharomyces cerevisiae to assess modes of biocontainment escape and establish design rules for development of kill switch systems in diverse microbes. A camphor-regulated, RelE toxin system was systematically deployed to assess the impacts of differential kill switch copy number and ploidy in laboratory vs industrial strains. CRISPR-mediated integration of the biocontainment system at various loci revealed rapid escape events driven, in part, by mutations to both the Cam-transactivator (cam-TA) and RelE toxin. Genetic engineering enabled recapitulation of escape phenotypes, confirming mechanisms of escape and establishing structure-function relationships in the cam-TA system. Interestingly, genomic resequencing of escape mutants also revealed a series of off-target mutations, implicating additional modes of kill switch escape. Multi-copy integration of the kill switch system mitigated these effects by orders of magnitude, without compromising the biosynthetic capacity of the microbes, but proved insufficient to establish sustained biocontainment. The resultant data define a series of key design rules for next-generation biocontainment strategies and add to a growing foundational knowledge base targeting establishment of secure biosystems designs.

59 BASIC BIOLOGICAL SCIENCES↗