Search NASASearch

SEARCH · Search NASA

Results for “hardware enumeration”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

Wind Supply Chain Security: Hardware Enumeration and Analysis

This project, undertaken by Idaho National Laboratory (INL) for the Department of Energy (DOE) Wind Energy Technologies Office (WETO), focused on the enumeration and analysis of six key devices important to wind technologies. The devices analyzed included Beckhoff Bus Terminal Controllers (BK1120 and BC9000), a Beckhoff Economy Built-in Panel PC (CP6231), an N-Tron Managed Industrial Ethernet Switch (711FX3), a Bachmann M1 Gateway, and a Bachmann Smart Power Plant Controller. Device selection was driven by availability and budget constraints, with several components sourced from existing wind farms and others procured through a co-agreement with another WETO-funded project. The project's primary objective was to create a hardware bill of materials (HBOM) for each device, identifying and documenting all components to assess potential security and supply chain risks. A detailed analysis revealed over 750 unique components across the six devices, with 80% successfully identified and accompanied by datasheets. Notably, Texas Instruments emerged as the leading supplier, providing over 16% of the components, followed by ON Semiconductor at 11.3%, Analog Devices at 5.3%, and Renesas Electronics Corp at 4.1%. Other notable vendors included Toshiba Corporation, iC-Haus Corporation, Atmel, Vishay, and STMicroelectronics. The enumeration process involved thorough documentation of each component, including its designation, quantity, identifiers, pin package, description, vendor, model, and country of origin. This process provided valuable insights into the complexity and diversity of the electronic systems within these wind devices. It also highlighted the distinct separation of components between vendors, suggesting a trend of vendor-specific component usage. Key findings from the project emphasized the importance of broadening the scope of vendor analysis in future research to gain a comprehensive understanding of component distribution and commonality. The identification of vendor-specific component usage patterns offers new avenues for research and underscores the significance of continued investigation in this field. Overall, this project provides critical insights into the component composition of wind devices, aiding in the development of improved supply chain management and component sourcing strategies. The results contribute valuable knowledge to the wind technology sector, laying the groundwork for enhanced security and resilience in wind energy systems.

17 - WIND ENERGY

Improving Cyber Situational Understanding

Effective cybersecurity operations require the ability to analyze large amounts of information to assess security risks and formulate defensive strategies against adversaries. This has become more complex in recent years as the sprawl and interconnectivity of devices grows through implementation of virtualization, cloud computing, and Internet of Things (IoT). The amount of data and analysis required for effective cybersecurity command and control decisions far exceeds humans’ capacity to perform manually. We characterize the analysis problem as cyber situational understanding. The research presented to improve cyber situational understanding focuses on vulnerability analysis and threat intelligence. Regarding vulnerabilities, entities must analyze and plan work for between thousands and tens of thousands of software vulnerabilities annually. Entities heavily use network firewalls to limit vulnerability exposure. As a result, some of these vulnerabilities permit exposure to adversarial exploitation, whereas others are inaccessible and therefore present negligible risk of exploitation. Distinguishing between high and low risk software vulnerabilities requires a deep understanding of the vulnerability, network firewall protection, and characteristics of the targeted device. This problem is solved by extracting network service features from vulnerability data features using both machine-learning and natural language processing. Then, the network firewall topology is parsed to determine which vulnerabilities are reachable by adversaries. Ultimately, a state-based safety analysis ascertains which vulnerabilities are unsafe. A related vulnerability analysis problem occurs in cybersecurity operations when associating an entity’s hardware and software assets to public vulnerability databases. Assets often reveal hardware and software through installation artifacts and network service identification, and entities store these artifacts in inventory databases. However, software and hardware vendors apply a standard Common Platform Enumeration (CPE) naming convention when publicly reporting vulnerabilities. Associating these two datasets often requires many hours to days of manual inspection. The proposed solution automates the mapping approach of human analysts using fuzzy matching techniques, natural language processing, and, ultimately, machine learning to present a small set of recommendations for mapping the two datasets. The result significantly reduces human analysis time and reduces the occurrence of false positives in vulnerability notifications. Finally, cyber threat intelligence (CTI) requires associating cyber observable artifacts, such as IP addresses, URIs, and file hashes, with cyber threat tactics, techniques, and procedures. Unfortunately, most CTI data is compartmentalized across multiple organizations and cannot be shared due to the legal and reputational risk with cyber threat being associated with the entity. The approach to solving this problem inovlves using a distributed ledger with anonymous token spending and authentication. This allows a consortium of semi-trusted entities to share the workload of curating CTI for a threat sharing community’s cooperative benefit.

Huff, Philip

Programmable Digital Devices used in Advanced Reactors

This paper introduces the concepts of common cause failure, diversity, and defense-in-depth used by the nuclear industry to analyze resilience in reactors. A survey of publicly traded and private companies building advanced reactors and their licensing status is presented. Safety and non-safety systems found in the NuScale Power design are summarized and the likely hardware and software categories used by those systems are enumerated. The importance of industry partners is highlighted. This paper also identifies an alternate path forward without industry partners to advance the knowledge needed to use artificial intelligence to analyze HBOMs and SBOMs to better understand reactor resiliency.

cybersecurity

Testbed Demonstration of a Microgrid Building Block Prototype

With the adoption of ambitious climate action goals, the penetration level of distributed energy resources (DERs) is rapidly increasing. Microgrids are an efficient way to integrate these DERs, facilitating their operation and control. Additionally, microgrids enhance the overall resilience of the distribution system by serving critical loads both within and outside their boundaries. However, the need for substantial customized engineering leads to a high cost of development, installation and maintenance of microgrids. To address this challenge, Microgrid Building Blocks (MBB) are proposed to reduce the deployment cost of microgrids through modular, standardized design and implementation. This work presents a testbed demonstrating the integrated power conversion, control, and communication functionalities of an MBB. The testbed is formed by a real-time electromagnetic transient (EMT) simulation combined with a hardware and software prototype of MBB. The use cases supported by the MBB testbed are enumerated. The islanded operation, voltage regulation, and optimal dispatch capabilities of an MBB-based microgrid controller are validated through a case study.

Somda, Baza [Virginia Tech]

Sampling Size Optimization for Bioburden Density Estimation in Planetary Protection

Planetary protection (PP) is a discipline that focuses on minimizing the biological contamination of spacecraft to ensure compliance with international policy. Precise estimation of bioburden - the total number of microbes in or on spacecraft hardware – and the bioburden density are of utmost importance for PP. Such estimation is the way concordance with requirements is demonstrated, and it is critical for quantifying the potential risk of inadvertently contaminating other planetary bodies. Although a suite of molecular techniques have been used to thoroughly characterize and profile the microbiome of various cleanroom environments and spacecraft, the gold standard remains the physical enumeration of microbes via culturing of samples directly taken from spacecraft and associated surfaces. However, due to technical, budgetary, and programmatic constraints, only a manageable portion (around 10%) of the entire spacecraft surface is directly sampled with cotton swabs or wipes. To generate the bioburden current best estimate (CBE) for components not directly verifiable, the accepted approach is to apply a NASA-defined bioburden estimate based on the components’ manufacturing or assembly environment. This approach utilizes a prespecified bioburden density estimation that applies a maximum value across the total surface area of the specified component. For hardware components that underwent similar assembly processes, an implied bioburden is adopted for all components, based on a direct verification of a representative component within the same lot. Once all components have a CBE, the bioburden estimates are generated. In previous publication [ 1], we have shown that statistical risks quantifying the accuracy of the estimates for sampled, prespecified, and implied components can be derived and ranked. For mean squared error (MSE) function, the risks are available analytically and hence a cost function can be obtained to optimize the risks with respect to the sampling area and sampling cost. Since the sampling area and sampling cost are two complimentary variables, their sum will have a well-defined minimum. This paper presents the multivariate optimization of the integrated risk of an empirical Bayes estimator to determine the optimal sampling schedule for a given number of components. It is assumed that given a number of components, N, the bioburden density for each component can either be sampled, implied, or prespecified. The multivariate optimization searches through different options to sample, imply or prespecify the bioburden density for a component, and account for the component’s surface area and cost of sampling. The idea of the optimization is based on the observation that the statistical risk of using an estimator is a monotonically decreasing function of the sampled area. The larger the sampled area, the lower the risk of using the estimator as the estimator becomes more and more accurate as the sampling area increases. On the other hand, the cost of sampling is monotonically increasing as the sampled surface grows. This makes the risk and total cost of sampling complimentary variables which can be counterbalanced to achieve an optimal overall value with respect to the sampled surface. In this paper, the integrated risk has been used to quantify the accuracy of the estimator. This risk has been selected because it depends on neither the true value of the parameter nor on the collected data. The cost of each sample was also available to obtain the total cost of sampling of N components. The paper will present the results based on computer-simulated data as well as the data collected during the InSight mission. The computer-simulated data have N components with randomly generated total areas and each component assigned to one of the three categories according to the method of estimating of bioburden density: sampled, implied, or prespecified. The cost of sampling is also available. The cost of sampling is estimated based on a cost model provided by the planetary protection group at JPL. For this paper, the overall cost was assumed to be a linear function of exposure. The optimization process finds the allocation of the components to the three categories that minimizes the tradeoff between integrated risk and total cost. For the InSight data, a set of components is selected representing all three categories, and optimization is performed to determine if the performed allocation was optimal or if a better allocation could have been obtained. To the best of our knowledge, this work is the first attempt not only perform an accurate estimation of bioburden density but also do it in an optimal way.

97 - MATHEMATICS AND COMPUTING