Search NASA⌕ Search

SEARCH · Search NASA

Results for “internet protocol”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Improving transition to IPv6-only via RFC8925 and IPv4 DNS Interventions

Nine years have passed since the American Registry for Internet Numbers exhausted its allocation of Internet Protocol version 4 (IPv4) addresses, and four years have passed since the United States Government mandated federal agencies to complete the transition to Internet Protocol version 6 (IPv6). Despite the IPv4 address shortage and IPv6 mandate, Federally Funded Research and Development Centers (FFRDCs) are still struggling to sunset IPv4. As demonstrated on SC23’s SC23v6 wireless network, newer tooling such as RFC8925 allows clients to disable their IPv4 protocol stack while retaining legacy IP connectivity via the RFC6145 translation algorithm. However, SC23v6 wireless clients without RFC8925 support or a disabled IPv6 stack would continue to receive internet access via legacy IPv4. This paper introduces a method of using poisoned IPv4 Domain Name System (DNS) records to gracefully inform IPv4-only clients at SC24’s SC24v6 wireless network about their inability to use the current version of internet protocol, with a goal of minimal impact to RFC8925 and dual-stack clients. When implemented as designed, this method may improve supportability and user experience of IPv6-only deployments at FFRDCs.

Costello, Thomas M↗

IPv6 Tunneling and Translation Technologies Pilot

Based on the latest DOE (Department of Energy) milestones, Sandia needs to convert to IPv6 (Internet Protocol version 6)-only networks over the next 5 years. Our original IPv6 migration plan did not include migrating to IPv6-only networks at any point within the next 10 years, so it must necessarily change. To be successful in this endeavor, we need to evaluate technologies that will enable us to deploy IPv6-only networks early without creating system stability or security issues. We have set up a test environment using technology representative of our production network where we configured and evaluated industry standard translation technologies and techniques. Based on our results, bidirectional translation between IPv4 (Internet Protocol version 4) and IPv6 is achievable with our current equipment, but due to the complexity of the configuration, may not scale well to our production environment.

97 MATHEMATICS AND COMPUTING↗

Power and Communications Hardware-in-the-Loop CPS Architecture and Platform for DER Monitoring and Control Applications: Preprint

The rapid growth of distributed energy resources (DERs) has prompted increasing interest in the monitoring and control of DERs through hybrid smart grid communications. The deployment of communications and computation has transformed the traditional physical power grid into a smart cyber-physical system (CPS). To fully understand the interdependency between physical grid and cyber netowrks, this study designed a power and communications hardware-in-the-loop (PCommHIL) CPS architecture, which enables the flexible verification of DER monitoring and control with hybrid communications architectures and Internet protocols. Design, development and case study of a PCommHIL testbed for the DER coordination are discussed in detail, and the proposed platform integrates DER devices, Advanced Metering Infrastructures (AMIs), and a suite of hybrid communications networks for distribution automation applications. Case study on DER situational awareness and Volt-Var control validates the efficacy of this proposed PCommHIL platform with hybrid communications designs. Results show that the HAN communication technologies play a critical role in hybrid designs and it is the bottleneck for DER applications. High performance communication technologies are highly recommended to be applied in the HAN for enhanced monitoring and real-time control of DERs.

AMIs↗

Secure NTP Implementation for Power System Synchronization

Network Time Protocol (NTP), originally developed in the 1980s, remains one of the most widely adopted protocols for synchronizing clocks over Internet Protocol (IP)-based networks. It distributes time with millisecond-level accuracy across Ethernet-based systems and continues to be a standard in both enterprise and operational technology environments.

97 MATHEMATICS AND COMPUTING↗

OpenFacadeControl: enabling integration of automated facades with other building systems

Automated facades are, for the most part, still considered as separate from other building systems throughout the design, installation, commissioning, operation, and maintenance cycle. This takes place despite the fact that their energy and comfort performance are deeply interlinked with the operation of lighting and HVAC systems. Over the last two decades, research has shown that there are significant advantages from operating facades as an integrated system with the rest of the building. Nevertheless, significant barriers prevent this type of integration becoming more common. One of them is the lack of a platform that is inexpensive to implement and that easily allows the practical implementation of integrated control algorithms across fenestration and other building systems, using a variety of communications protocols. This is particularly challenging when automated facades are installed in existing buildings, where interaction with legacy building systems that were installed over the past lifetime of the building can require a high degree of interoperability. OpenFacadeControl (OFC) is an open-source controls framework aimed at unified control of facades and other building systems, including the sharing of third-party sensor information. Through leveraging the Volttron controls platform, it allows the integration of systems and sensors that are manufactured by different companies and that use different communications protocols into an ensemble that functions as a single system. OFC is designed to enable integrated control algorithms of varying degrees of complexity, ranging from simple, heuristic controls to more sophisticated approaches like model-predictive control. Use of a research version to test advanced lighting and shading strategies in a full-scale experimental testbed has demonstrated the ease of deploying advanced control solutions using OpenFacadeControl. This paper presents the structure of OpenFacadeControl and a demonstration case showing the use of OFC in laboratory tests of advanced lighting and fenestration controls that coordinated motorized shades communicating via the BACnet building communications standard and lights communicating via internet-protocol-based application programming interface (API), based on the readings of a shared light level sensor communicating via a different API.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Open-Source Framework for Data Storage and Visualization of Real-Time Experiments

Digital real time simulators (DRTS) are increasingly being used for the evaluation of power hardware and controller hardware in the laboratory prior to field deployment. Although DRTS are capable of simulating large models in real-time, it is challenging to visualize the results of large models without overdrawing or confounding the viewer. This paper provides an open-source framework for users to visualize their DRTS-based hardware-in-the-loop (HIL) experimental results in real-time. This proposed framework can be used by experimental test beds that can push data through an internet protocol based network. The proposed framework includes three main components. First, it includes the DRTS that generates and pushes the data to a relay. Second, it includes an application that serves multiple purposes, from data storage, testing, and translation of the data to a publisher/subscriber protocol. Finally, it includes libraries and applications that can be used to visualize the data by subscribing to the relay. This framework is available in open source, and it is tested using the HIL platform developed for testing advanced distribution management systems.

advanced distribution management systems↗

Artificial Diversity and Defense Security (ADDSec)

Artificial Diversity and Defense Security (ADDSec) machine learning algorithms are used to classify and cluster threats so that an appropriate response can be initiated as a mitigation strategy. The package includes an ensemble of machine learning algorithms such as Support Vector Machines, naïve bayes, logistic regression, and random forest that evolve with the data to recognize anomalous behavior at the host and network levels. Inputs into the machine learning algorithms include end host system calls, system utilization, packet captures, and syslog messages. The machine learning algorithms can be retrained based on user defined intervals or on the number of packets received. ADDSEC's threat responses include Internet Protocol (IP) Address randomization, application port number randomization, and application library randomization. The IP randomization implementation is built on top of a Software Defined Networking (SDN) framework. The SDN controller installs flows on each of the SDN switches with randomized source and destination IP addresses. The application port numbers are randomized using iptables. The application library randomization is created with a LLVM compiler. All randomization schemes are transparent to the endpoints on the network. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525. SAND2021-3379 O

Cox, RebeccaE.↗

Supporting Cyber Security of Power Distribution Systems by Detecting Differences Between Real-time Micro-Synchrophasor Measurements and Cyber-Reported SCADA (Final Report)

As modern power grids tend towards greater levels of automation and communication, the challenges of identifying and mitigating vulnerabilities to cyber-attacks are ones that are increasingly demanding attention. Today’s power system has evolved to form the foundational bedrock of modern society, and an attack on this infrastructure could prove disastrous. In this project we were tasked to investigate the use of distribution synchrophasors as an independent isolated sensor network with which we can corroborate, or flag potentially spoofed,Supervisory Control And Data Acquisition (SCADA) data. We adapted an approach to marry the underlying physical properties of power systems with the network communications used by power systems in order to offer insights unattainable by either data stream isolation. While the concept of intrusion detection systems (IDS) is well understood for monitoring network traffic and traditional IT computing systems, the approach discussed in this report is motivated by several key notions: first, current SCADA communications alone presents an incomplete view of the grid. Second, the power grid, and the equipment controlling it, is grounded by laws of physics. Given this, we leverage high-frequency physical grid measurements to understand the physical condition of the grid, and combine this with SCADA. While high-frequency physical grid measurements and SCADA communication over Internet Protocol (IP) networks are fundamentally disparate information sources, when collectively examined through appropriate lenses, they offer a much more nuanced depiction of the grid.

24 POWER TRANSMISSION AND DISTRIBUTION↗

TF9 Dataset Analysis

Incident Overview: In the time between November 2, 2019 and November 11, 2019, WheelByte was plagued by breaches in security. These insecurities led to breaches in customer data, company data, and even the death of an employee, Matthew Swift. They have launched an investigation into the company’s computer systems in hopes to find the root cause. We have been provided with the following artifacts from WheelByte: memory images, disk images, network packet captures, and emails. We have found multiple cyber-system attacks against WheelByte. Our investigation lasted from July 13th - August 3rd, 2023. WheelByte allowed us to look at any and every file, and there were no restrictions on what we could or could not use in our investigation. By the end of our investigation, we have been able to deduce who is behind the attack, what they have done, and why they did it. A company that is closely related to WheelByte is called Slyde. Slyde sells electric scooters and it is known that the Chief Executive Officer (CEO) of Slyde, Kimberly Holmes, sees WheelByte as a threat to business, as Wheelbyte sells electric skateboards. We have been able to deduce that Slyde is likely behind many of the malicious attacks. We have seen exfiltration addresses to Slyde domains, along with other Slyde information within their malware. We can see lots of traffic to and from Slyde Internet Protocol (IP) addresses. This may be an attempt to cripple WheelByte’s productivity to remove Slyde’s competitor from the market.

97 MATHEMATICS AND COMPUTING↗

Interface Specifications for RAdiation Portal Technology Enhancement & Replacement (RAPTER) Modules

Radiation Portal Monitors (RPMs) were deployed throughout the port and border infrastructure of the United States (U.S.) beginning in 2003 to monitor for the possible presence of uncontrolled radiological and nuclear materials. Since that time, the U.S. Government (USG) has learned much about the operational challenges faced in the field. Principal among the shortcomings has been the lack of flexibility afforded the USG when all Internet Protocol (IP) rights and interfaces of the system are owned by the Original Equipment Manufacturer (OEM).

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Grid Cyber-Security Strategy in an Attacker-Defender Model

The progression of cyber-attacks on the cyber-physical system is analyzed by the Probabilistic, Learning Attacker, and Dynamic Defender (PLADD) model. Although our research does apply to all cyber-physical systems, we focus on power grid infrastructure. The PLADD model evaluates the effectiveness of moving target defense (MTD) techniques. We consider the power grid attack scenarios in the AND configurations and OR configurations. In addition, we consider, for the first time ever, power grid attack scenarios involving both AND configurations and OR configurations simultaneously. Cyber-security managers can use the strategy introduced in this manuscript to optimize their defense strategies. Specifically, our research provides insight into when to reset access controls (such as passwords, internet protocol addresses, and session keys), to minimize the probability of a successful attack. Our mathematical proof for the OR configuration of multiple PLADD games shows that it is best if all access controls are reset simultaneously. For the AND configuration, our mathematical proof shows that it is best (in terms of minimizing the attacker's average probability of success) that the resets are equally spaced apart. We introduce a novel concept called hierarchical parallel PLADD system to cover additional attack scenarios that require combinations of AND and OR configurations.

97 MATHEMATICS AND COMPUTING↗

Self-Sustainable IoT-Based Remote Sensing Powered by Energy Harvesting Using Stacked Piezoelectric Transducer and Thermoelectric Generator

We propose a self-powered remote multi-sensing system for traffic sensing which is powered by the collective energy harvested from the mechanical vibration of the road caused by the passing vehicles and from the temperature gradient between the asphalt of the road and the soil underneath. A stacked piezoelectric transducer converts mechanical vibrations into electrical energy and a thermoelectric generator harvests the thermal energy from the thermal gradient. Electrical energy signals from the stacked piezoelectric transducer and the thermoelectric generators are converted into usable DC power to recharge the battery using AC-DC and DC-DC converters working simultaneously. The multi-sensing system comprises an embedded system with a microcontroller that acquires data from the sensors and sends the sensory data to an IoT transceiver which transmits the data as RF packets to an ethernet gateway. The gateway converts the RF packets into Internet Protocol (IP) packets and sends them to a remote server. Laboratory and road-testing results showed over 98% sensory data accuracy with the system functioning solely powered by the energy harvested from the alternative energy sources. The successful maximum transmission distance obtained between the IoT, and the gateway was approximately 1 mile, which is a considerable transmission distance achieved in an urban environment. Successful operation of the self-powered multi-sensing system under both laboratory and road conditions contributes considerably to the fields of energy harvesting and self-powered remote sensing systems. The energy flow chart and efficiency for the steps in the system were found to be mechanical power from vehicles to the energy harvester of 0.25%, stacked PZT transducer efficiency was found to be 37%, and for the TEGs the efficiency is 11%. AC-to-DC and DC-to-DC converters’ efficiencies were found to be 90% and 11%. The wireless communication RF transceiver efficiency was found to be 62.5%.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Module-OT: A Turnkey Solution for Securing Energy Systems

The Modular Security Apparatus for Managing Distributed Cryptography for Command-and-Control Messages on Operational Technology Networks (Module-OT) is a flexible and lightweight solution for grid-edge devices focusing on end-to-end security. It is a bump- in- the-wire solution acting as a secure conduit for data between devices or systems across a network. It improves the cybersecurity posture of DER systems by providing authentication, authorization, and data integrity to secure DER communications. Additionally, it performs key management, provides data security through whitelisting Internet Protocol addresses and ports, blocks unauthorized connections, controls user access, and allows serial or Ethernet connections for added flexibility. The core software is portable to various Linux-based operating systems and is developed to be customized by the developer and researcher communities. Module-OT has been validated in the lab, has been demonstrated at a 500-KW PV-plus-storage site, and has been proven ready to secure operational technology devices. Its core functionality meets current standards, including validation procedures of the NIST Cryptographic Algorithm Validation Program (CAVP) and the Federal Information Processing Standard (FIPS 140-2). Because of its capability to provide an accessible and affordable option for stepping up security across modern energy systems, Module-OT can serve as an effective technological option to standardize cybersecurity moving forward.

cryptography↗

System and method for provisioning protocol agnostic interface to internet of things application frameworks

The present invention provides a system and method for enabling a plurality of IoT applications running on a gateway to utilize a sub-set of underlying protocol services in a common way, where each application is agnostic of the specific implementation of each protocol service and has the flexibility to use any of the underlying protocols in the service set without impacting or restricting the application or any other applications that are sharing the protocol service set.

Krishna Dhulipala, Rama Vamshi↗

Enabling Interoperable SCADA Communications for PV Inverters through Embedded Controllers

The percentage integration of photovoltaic (PV) inverters in the field has increased significantly in the past 5 years. Regardless of the size of the PV plants and the inverters (residential vs. commercial), it is becoming crucial that these devices have the capability to communicate with peers (other smart devices) and with components that are at a hierarchy above the inverters (e.g., supervisory control and data acquisition (SCADA) systems, distributed controllers, and data managers). This project aims to develop a standard SCADA software code for inverters’ embedded controllers that will enable interoperability with other components in the system. To achieve this, the code will be developed using two different protocols: Distributed Network Protocol 3 and International Electrotechnical Commission 61850. The developed code is aimed to be deployed in simple embedded controllers. It will be tested in the National Renewable Energy Laboratory’s (NREL’s) Energy Systems Integration Facility. The tested code will then be made available through Triangle MicroWorks’s (TMW’s) software platform. The primary objectives of this project include training the NREL team with TMW’s embedded controller libraries, developing an interoperable communication code for embedded controllers, successfully testing and deploying the code, and demonstrating the newly developed code in a conference.

14 SOLAR ENERGY↗

Certified randomness using a trapped-ion quantum processor

Although quantum computers can perform a wide range of practically important tasks beyond the abilities of classical computers, realizing this potential remains a challenge. An example is to use an untrusted remote device to generate random bits that can be certified to contain a certain amount of entropy. Certified randomness has many applications but is impossible to achieve solely by classical computation. Here we demonstrate the generation of certifiably random bits using the 56-qubit Quantinuum H2-1 trapped-ion quantum computer accessed over the Internet. Our protocol leverages the classical hardness of recent random circuit sampling demonstrations: a client generates quantum ‘challenge’ circuits using a small randomness seed, sends them to an untrusted quantum server to execute and verifies the results of the server. We analyse the security of our protocol against a restricted class of realistic near-term adversaries. Using classical verification with measured combined sustained performance of 1.1 × 10 18 floating-point operations per second across multiple supercomputers, we certify 71,313 bits of entropy under this restricted adversary and additional assumptions. Our results demonstrate a step towards the practical applicability of present-day quantum computers.

computer science↗

Shape-shifting Elephants: Multi-modal Transport for Integrated Research Infrastructure

Data Acquisition (DAQ) workloads form an important class of scientific network traffic that by its nature (1) flows across different research infrastructure, including remote instruments and supercomputer clusters, (2) has ever-increasing throughput demands, and (3) has ever-increasing integration demands---for example, observations at one instrument could trigger a reconfiguration of another instrument. Today's DAQ transfers rely on UDP and (heavily tuned) TCP, but this is driven by convenience rather than suitability. The mismatch between Internet transport protocols and scientific workloads becomes more stark with the steady increase in link capacities, data generation, and integration across research infrastructure.This position paper argues the importance of developing specialized transport protocols for DAQ workloads. It proposes a new transport feature for this kind of elephant flow: multi-modality involves the network actively configuring the transport protocol to change how DAQ flows are processed across different underlying networks that connect scientific research infrastructure. Multi-modality is a layering violation that is proposed as a pragmatic technique for DAQ transport protocol design. It takes advantage of programmable network hardware that is increasingly being deployed in scientific research infrastructure. The paper presents an initial evaluation through a pilot study that includes a Tofino2 switch and Alveo FPGA cards, and using data from a particle detector.

97 MATHEMATICS AND COMPUTING↗