Search NASA⌕ Search

SEARCH · Search NASA

Results for “firmware update”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

Secure LoRa Firmware Update with Adaptive Data Rate Techniques

Internet of Things (IoT) devices rely upon remote firmware updates to fix bugs, update embedded algorithms, and make security enhancements. Remote firmware updates are a significant burden to wireless IoT devices that operate using low-power wide-area network (LPWAN) technologies due to slow data rates. One LPWAN technology, Long Range (LoRa), has the ability to increase the data rate at the expense of range and noise immunity. The optimization of communications for maximum speed is known as adaptive data rate (ADR) techniques, which can be applied to accelerate the firmware update process for any LoRa-enabled IoT device. In this paper, we investigate ADR techniques in an application that provides remote monitoring of cattle using small, battery-powered devices that transmit data on cattle location and health using LoRa. In addition to issues related to firmware update speed, there are significant concerns regarding reliability and security when updating firmware on mobile, energy-constrained devices. A malicious actor could attempt to steal the firmware to gain access to embedded algorithms or enable faulty behavior by injecting their own code into the device. A firmware update could be subverted due to cattle moving out of the LPWAN range or the device battery not being sufficiently charged to complete the update process. To address these concerns, we propose a secure and reliable firmware update process using ADR techniques that is applicable to any mobile or energy-constrained LoRa device. The proposed system is simulated and then implemented to evaluate its performance and security properties.

97 MATHEMATICS AND COMPUTING↗

Secure Firmware Update and Device Authentication for Smart Inverters using Blockchain and Physically Uncloable Function (PUF)-Embedded Security Module

Cybersecurity of inverters has been significantly important as inverters become smarter in cyber-physical environments. However, firmware security of smart inverters against firmware attacks from various attack vectors has been less studied. Furthermore, this paper proposes a secure firmware update and device authentication method using a blockchain-based public key infrastructure (PKI) management system and a physically unclonable function (PUF)-embedded security module in a smart inverter. The proposed method is validated by experiments.

blockchain↗

Device-Centric Firmware Malware Detection for Smart Inverters using Deep Transfer Learning

Since future power grids are inverter-dominant grids and inverters are getting smarter by incorporating remote access and seamless firmware update, it is anticipated that malware attackers will directly target smart inverters. However, malware threats targeting smart inverters have been less studied yet. This paper explores potential malware attacks targeting smart inverters and proposes a deep transfer-learning (DTL)-based malware detection framework for smart inverters. The proposed DTL method can significantly reduce development time and efforts for an artificial intelligence-based malware detection algorithm while improving detection accuracy. The experimental result shows that the proposed method achieves 98% of firmware malware detection accuracy. Furthermore, this approach will be transformative to other smart grid devices enabling seamless firmware update.

artificial intelligence↗

Forensic Analysis of SOHO Router Binaries

Small Office/Home Office (SOHO) routers are used by millions of consumers across the United States, and are commensurately vulnerable. Forensic analysis of SOHO router firmware helps to understand and mitigate those vulnerabilities. This poster focused particularly on analysis of BusyBox executables, a software suite that provides several Unix utilities in a single file. Three main tools were used to analyze the binaries. BinWalk was used to extract the files, but also to build entropy graphs, extract Linux kernel images, and identify CPU architectures; WiiBin processed the binaries to find endianness, architecture, the percent compressed/encrypted, and compiler data; and @DisCo, a machine learning tool used to determine function similarity in disassembled binaries, analyzed similarities and determined versions of extracted BusyBox files from each router. These tools found that venders from all five routers utilized the same version of the BusyBox software across different firmware updates, demonstrating the importance of constant firmware scrutiny to protect against security vulnerabilities.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Gridtrust: Electricity Grid Root-of-Trust Decentralized Supply Chain Cyber-Security (Final Scientific/Technical Report)

GridTrust represents a departure from reliance on a single organization or a single person to multiple organizations and therefore multiple people across organizational structures. The motivating idea behind involving multiple organizations is the increase in security due to human factors. More specifically, the requirement that distinct people in different organizations sign off on a change or an update makes a cyberattack much less likely due to the inherent requirement that both organizations be penetrated and fooled. GridTrust focuses on the software update process as the primary exemplar for the research and development work. A novel hardware-based technology referred to as a Physical Unclonable Function (PUF) provides a microchip Root-of-Trust (RoT), i.e., a starting point for verifying that the hardware being communicated with is the hardware the control center believes the hardware to be. As a result, staff at power grid control centers can ensure the accurate and reliable identification of hardware devices from the outset. The GridTrust protocol introduces two key innovations, as detailed in this report. Firstly, the utilization of a PUF as a root-of-trust in the initial phase of a software or firmware update. Secondly, the application of multiple cryptographic signatures from two or more organizations to the update binary. These signatures are verified before implementing the update on a power grid device in the field. In terms of GridTrust hardware design, this report outlines two main components. The first is the GridTrust Native Device, integrating PUF technology intrinsically into the hardware device itself. The second is the GridTrust Interfacing Device, which incorporates PUF technology and multiple cryptographic signatures. These signatures are cross-checked within a separate hardware positioned between the power grid control center and the legacy power grid device, functioning as an intermediary. While the GridTrust Interfacing Device offers the advantage of being applicable to existing power grid equipment, it may have reduced security if the intermediary component is targeted. On the other hand, the GridTrust Native Device boasts increased security due to protocol integration within a unified form factor. The effectiveness of GridTrust technology has been extensively demonstrated, with multiple external red-team attackers unable to breach GridTrust's security measures. This was observed both in controlled laboratory settings during Phase 1 of the project and in real-world conditions within a City of Marietta substation during Phase 2 of the project.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Strengthening Cybersecurity for Industrial Control Systems: Innovations in Protecting PLC-Based Infrastructure

In this paper, we propose two new approaches aimed at enhancing the security of industrial control systems (ICS) that utilize programmable logic controllers (PLCs) for the control of critical processes. The first approach involves the addition of a unique digital watermark to the PWM control that adjusts the motor speed to control the critical process. This enables efficient detection and identification of any unauthorized modifications to the sensor signals responsible for controlling the plant. The second approach focuses on monitoring the input current (i.e power) drawn by the PLC during the execution of critical process control tasks. Malicious intrusions to change the PLC parameters and/or unauthorized firmware updates can be rapidly detected. Both approaches demonstrate a substantial improvement in the security of ICS, effectively safeguarding against potential cyber-attacks. Experimental results from a laboratory scale water tank level controlled via PLC showcases rapid intrusion detection capabilities.

Huang, Peng-Hao↗

Disrupting EV Charging Sessions and Gaining Remote Code Execution with DoS, MITM, and Code Injection Exploits using OCPP 1.6

Open Charge Point Protocol (OCPP) 1.6 is widely used in the electric vehicle (EV) charging industry to communicate between Charging System Management Services (CSMSs) and Electric Vehicle Supply Equipment (EVSE). Unlike OCPP 2.0.1, OCPP 1.6 uses unencrypted websocket communications to exchange information between EVSE devices and an onpremise or cloud-based CSMS. In this work, we demonstrate two machine-in-the-middle (MITM) attacks on OCPP sessions to terminate charging sessions and gain root access to the EVSE equipment via remote code execution (RCE). Second, we demonstrate a malicious firmware update with a code injection payload to compromise an EVSE. Lastly, we demonstrate two methods to prevent availability of the EVSE or CSMS. One of these, originally reported by SaiFlow, prevents traffic to legitimate EVSE equipment using a DoS-like attack on CSMSs by repeatedly connecting and authenticating several CPs with the same identities as the legitimate CP. These vulnerabilities were demonstrated with proof-of-concept exploits in a virtualized Cyber Range at Wright State University and/or with a 350 kW Direct Current Fast Charger (DCFC) at Idaho National Laboratory. The team found that OCPP 1.6 could be protected from these attacks by adding secure shell (SSH) tunnels to the protocol, if upgrading to OCPP 2.0.1 was not an option. Index Terms—Electric vehicle charging, cybersecurity, OCPP, cyberattack, cyber-resilience. INSPEC Accession Number: 23981565

99 GENERAL AND MISCELLANEOUS↗

Comparison of Response Times for the Thermo ASP-2S1/NRD and Ludlum 30-7B Neutron Instruments

Health Physics Services (HPS) received feedback from a customer service survey regarding the difference in response times between the Thermo ASP-2S1/NRD (Thermo) and Ludlum Model 30-7B (Ludlum). In response to the feedback, tests were performed in the field and duplicated in a laboratory to evaluate and compare each instrument’s response time to reach an applied exposure. The results of the tests showed that optimizing its screen refresh rate by updating the Ludlum’s firmware improves response time, making it more comparable to the Thermo.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Firmware Tampering Detection in Heavy-Duty Vehicles through J1939 CAN Analysis

Modern heavy-duty vehicles rely on complex networks of Electronic Control Units (ECUs) that communicate using the J1939 protocol. While this system makes it easier to update and configure vehicle components, it also opens the door to serious cybersecurity risks if not properly secured. This work investigates the potential for firmware tampering through the J1939 communication protocol, which enables ECU configuration and reprogramming over the Controller Area Network (CAN) bus. By monitoring CAN traffic during legitimate maintenance operations and reverse-engineering OEM diagnostic software, we identified common and proprietary J1939 message identifiers, authentication patterns, and vulnerabilities within Unified Diagnostic Services (UDS). These findings demonstrate that inadequate authentication mechanisms can allow malicious actors to alter ECU firmware or disable safety functions, posing severe operational and safety risks. Our analysis contributes to the development of vehicle intrusion detection systems capable of recognizing abnormal reprogramming activity and future firmware fingerprinting methods to verify software integrity across ECUs. This work highlights the importance of standardizing secure firmware authentication across manufacturers to strengthen cyber resilience in heavy-duty vehicle systems.

33 ADVANCED PROPULSION SYSTEMS↗

DIRECT RF SAMPLING BASED LLRF CONTROL SYSTEM FOR C-BAND LINEAR ACCELERATOR

Low Level RF (LLRF) control systems of linear accel- erators (LINACs) are typically implemented with hetero- dyne based architectures, which have complex analog RF mixers for up and down conversion. The Gen 3 Radio Fre- quency System-on-Chip (RFSoC) device from AMD Xilinx integrates data converters with maximum RF frequency of 6 GHz. This enables direct RF sampling of C-band LLRF signal typically operated at 5.712 GHz without any analogue mixers, which can significantly simplify the system architec- ture. The data converters sample RF signals in higher order Nyquist zones and then up or down convert digitally by the integrated data path in RFSoC. The closed-loop feedback control firmware implemented in FPGA integrated in RF- SoC can process the base-band signal from the ADC data path and calculate the updated phase and amplitude to be up- mixed by the DAC data path. We have developed a C-band LLRF control RFSoC platform with direct RF sampling, which targets Cool Copper Collider (𝐶3) and other C or S band LINAC research and development projects. In this paper, the architecture of the platform will be described. We have optimized the configuration of the data converter and characterized performance of them with RF pulses. The test results for some of the key performance parameters for the LLRF platform with our custom solid-state amplifier, such as phase and amplitude stability, will be discussed in this paper.

Liu, C↗

Digital Assurance Checklist for Homeowners and Installers

This document provides a comprehensive Digital Assurance Checklist for securing behind-the-meter energy assets, focusing on both installers and homeowners. As distributed energy resources (DERs) such as solar PV and battery storage become integral to residential energy systems, cybersecurity emerges as a critical component of reliability and safety. The guide outlines actionable steps for installers during pre-installation, commissioning, and post-installation phases, emphasizing practices like network segmentation, credential management, firmware validation, and homeowner education. For homeowners, the document introduces a tiered approach to cyber hygiene—from essential measures like strong Wi-Fi credentials and automatic updates to advanced strategies such as network segmentation, DNS filtering, and intrusion detection. By adopting these practices, stakeholders can mitigate cyber risks, safeguard energy infrastructure, and ensure resilient, secure operation of DER systems. Additional resources and references to industry standards are included to support implementation.

99 - GENERAL AND MISCELLANEOUS↗

Digital Assurance Checklist for Homeowners and Installers

This document provides a comprehensive Digital Assurance Checklist for securing behind-the-meter energy assets, focusing on both installers and homeowners. As distributed energy resources (DERs) such as solar PV and battery storage become integral to residential energy systems, cybersecurity emerges as a critical component of reliability and safety. The guide outlines actionable steps for installers during pre-installation, commissioning, and post-installation phases, emphasizing practices like network segmentation, credential management, firmware validation, and homeowner education. For homeowners, the document introduces a tiered approach to cyber hygiene—from essential measures like strong Wi-Fi credentials and automatic updates to advanced strategies such as network segmentation, DNS filtering, and intrusion detection. By adopting these practices, stakeholders can mitigate cyber risks, safeguard energy infrastructure, and ensure resilient, secure operation of DER systems. Additional resources and references to industry standards are included to support implementation.

99 - GENERAL AND MISCELLANEOUS↗

Recommendations for Distributed Energy Resource Patching

While computer systems, software applications, and operational technology (OT)/Industrial Control System (ICS) devices are regularly updated through automated and manual processes, there are several unique challenges associated with distributed energy resource (DER) patching. Millions of DER devices from dozens of vendors have been deployed in home, corporate, and utility network environments that may or may not be internet-connected. These devices make up a growing portion of the electric power critical infrastructure system and are expected to operate for decades. During that operational period, it is anticipated that critical and noncritical firmware patches will be regularly created to improve DER functional capabilities or repair security deficiencies in the equipment. The SunSpec/Sandia DER Cybersecurity Workgroup created a Patching Subgroup to investigate appropriate recommendations for the DER patching, holding fortnightly meetings for more than nine months. The group focused on DER equipment, but the observations and recommendations contained in this report also apply to DERMS tools and other OT equipment used in the end-to-end DER communication environment. The group found there were many standards and guides that discuss firmware lifecycles, patch and asset management, and code-signing implementations, but did not singularly cover the needs of the DER industry. This report collates best practices from these standards organizations and establishes a set of best practices that may be used as a basis for future national or international patching guides or standards.

97 MATHEMATICS AND COMPUTING↗

FY25 Mid-Year Report: FNCL Enhancements Implementation

During the first half of FY25 the FNCL team has made consistent progress toward the completion of our project goals. The FNCL prototype panel design has been successfully applied to a fully instrumented 3-panel system which is actively under construction. The FNCL Demonstrator System contains solid scintillators instrumented with SiPMs, which operate on an updated CAEN digitizer, requires no high-voltage, and has a smaller overall footprint. The onboard software will include the LLNL-developed GMM-PSD signal processing. Later this year the system will be experimentally tested alongside the baseline FNCL instrument at LLNLs ISSA facility. In addition to a full systems test, the performance of a DD generator for active interrogation measurements compared to the standard AmLi source will be established for both systems. The data collected at the ISSA facility will be used to experimentally validate the FNCL-Fast Isotopic Fuel Assay’s (FIFA) capability to measure U-235 loading and to predict gadolinium poison content with passive interrogation. The FNCL-FIFA modal was benchmarked with simulation-based data and a user-friendly GUI was added earlier this year. Three separate codes have been submitted to the LLNL ESW system for review prior to their transfers. These include the Predictive Modeling Response toolkit, GMM-PSD firmware beta version, and the FNCL-FIFA analysis package with GUI and user documentation.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗