Search NASA⌕ Search

SEARCH · Search NASA

Results for “secure remote access”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

DGaaS: GPU as a Service on Distributed Computing System

In the rapidly evolving landscape of scientific computing, Graphics Processing Units (GPUs) have become indispensable for their unparalleled ability to handle parallel tasks in complex calculations, simulations, and data analysis. Their utility is further magnified in machine learning and AI applications, where they significantly accelerate model training and predictive analytics. Within this context, the Triton Inference Server emerges as a pivotal open-source tool, specializing in AI inferencing and optimizing GPU utilization across various platforms and frameworks. This paper presents an in-depth study on distributed High Throughput Computing (HTC), specifically focusing on the HTCondor framework and its resource provisioning tools, GlideinWMS and HEPCloud. These systems enable large-scale scientific experiments like CMS and DUNE to efficiently access and utilize vast computational resources. The paper explores the core architectural components of GlideinWMS, including jobs, user pools, and worker nodes, and discusses their integration with GPUs and the Triton server. The primary aim of this research is to develop a solution that optimizes GPU utilization by leveraging Glideins and containers. This approach allows computational jobs, particularly those involving AI models, to use GPUs only when essential, thereby facilitating efficient sharing of limited GPU resources. To validate this architecture, the study conducted three key tests involving custom scripts, container-based servers, and Triton server deployments. However, the study faces challenges, notably in locating the Triton server and ensuring secure remote access. To address these issues, future work will focus on developing a proxy mechanism and enhancing security protocols. In conclusion, this study offers a comprehensive roadmap for effective and efficient GPU utilization in distributed High Throughput Computing. It aims to contribute significantly to the scientific community by solving pressing problems and implementing robust solutions in collaboration with the GlideinWMS and HEPCloud teams. The research sets the stage for a more efficient, scalable, and cost-effective paradigm in scientific computing.

97 MATHEMATICS AND COMPUTING↗

Advancing Conduction-Cooled 650 MHz SRF Technology for Industrial Accelerators at Fermilab's IARC

The National Nuclear Security Administration (NNSA) funds the Illinois Accelerator Research Center (IARC) at Fermilab in developing a high-power, conduction-cooled Superconducting Radio Frequency (SRF) accelerator tailored for industrial applications requiring robust and efficient operation. A 650 MHz, 1.6 MeV, 20 kW SRF accelerator is currently under development, employing a conduction cooling approach to simplify cryogenic requirements and enhance accessibility for industrial use. The accelerator’s control system is implemented on the Blinky Lite platform, selected for its open-source architecture, secure remote access capabilities, and operational flexibility—attributes advantageous for industrial deployment and sustained operation. A dedicated beamline is designed to measure essential beam parameters and test the integrated performance of the accelerator and control systems, thereby validating their operational readiness for intended applications

Ji, Y. [Fermilab] (ORCID:0000000233981752)↗

Advancing Conduction-Cooled 650 MHZ SRF Technology for Industrial Accelerators at Fermilab S IARC

The National Nuclear Security Administration (NNSA) funds the Illinois Accelerator Research Center (IARC) at Fermilab in developing a high-power, conduction-cooled Superconducting Radio Frequency (SRF) accelerator tailored for industrial applications requiring robust and efficient operation. A 650 MHz, 1.6 MeV, 20 kW SRF accelerator is currently under development, employing a conduction cooling approach to simplify cryogenic requirements and enhance accessibility for industrial use. The accelerator's control system is implemented on the Blinky Lite platform, selected for its open-source architecture, secure remote access capabilities, and operational flexibility attributes advantageous for industrial deployment and sustained operation. A dedicated beamline is designed to measure essential beam parameters and test the integrated performance of the accelerator and control systems, thereby validating their operational readiness for intended applications.

Ji, Yichen [Fermilab]↗

Project: Corbomite - Product: ConsoleWorks REACT

TDi Technologies presents ConsoleWorks REACT, an advanced platform designed to tackle the complexities of cyber and operational risk assessment. This comprehensive solution goes beyond asset-focused approaches by considering the impact of both assets and people have on the security and operation of critical infrastructure, specifically targeting preventing gird mis-operation by evaluating real-time human interaction or commands with critical assets. The hypothesis suggests that by integrating the assessment of user commands into the overall risk assessment process, organizations can make more informed decisions, prioritize resources effectively, and respond promptly to potential threats. This hypothesis forms the basis for the development of a proactive and holistic risk management approach that is more comprehensive and context aware than traditional models which only look at assets, patch levels, configuration and threat intel by collecting that information off the network vs directly from the asset, human, and human interaction all in real-time. ConsoleWorks' unique man-in-the-middle architecture is a key feature that sets it apart in the cybersecurity landscape. This architecture enables the real-time observation, enforcement, and commands or interaction risk transparency of user interaction with critical infrastructure to be risk mitigated and audited as they are aggregated with device and human risk factors for a more comprehensive risk threat score across a device or group of devices. This architecture allows ConsoleWorks to act as a secure intermediary between users and critical assets, monitoring all interactions and ensuring that only authorized commands are sent to the asset to be executed. This not only enhances security but also provides a comprehensive audit trail of all user activities, contributing to compliance efforts and facilitating incident investigation and risk management. By integrating this unique architecture with our comprehensive risk assessment methodology, ConsoleWorks REACT provides a powerful solution for managing cyber and operational risks, enabling organizations to maintain a robust security posture and effectively mitigate potential threats. To that end, the primary objective of this project was to research and develop a robust solution that enables the energy industry to mitigate the risks associated with human actions that can compromise the security or operations of assets critical to energy delivery, generation, transmission and operation. ConsoleWorks REACT plays a pivotal role in achieving this goal by leveraging its unique capabilities to monitor and track all user activity. Through its Zero Trust approach, which emphasizes continuous verification, the platform ensures secure access to assets and serves as the centralized human response and notification platform for addressing cyber and operational issues.

97 MATHEMATICS AND COMPUTING↗

Quantum Lock Technologies: Innovation Crossroads Final Report

At Quantum Lock Technologies, our mission is to use future-proof hardware and software to bridge the gap between physical access control and cyber security. Physical security includes access to doors, lockboxes/containers, and machinery/robots. Connecting physical access control to the cloud allows for remote detection, fast ledger updates, and mobile or remote access. However, this also opens physical security up to the world of cyber-attacks. At Quantum Lock, we use quantum random number generation to generate completely random and unpredictable digital keys to be used by connected equipment in a facility. This quantum technology is then paired with end-to-end encryption and a one-time-key communication protocol to ensure the highest level of security. Through the Innovation Crossroads program at Oak Ridge National Laboratory, we have developed benchtop prototypes of our technology, connected with utility boards as our first target customers, and prepared for our first pilot with customers (target end of summer 2022). Below is a photograph of myself at an energy substation where we plan to eventually apply our technology.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Lightfall v0.0.1

Lightfall is a desktop application for synchrotron beamline instrument control, data acquisition, and live analysis at the Advanced Light Source (ALS). Built on Python and Qt, it provides a native graphical interface for operating beamline hardware, configuring and executing experimental scans, and visualizing results in real time. Key features include direct integration with EPICS control systems, a built-in electronic logbook, remote beamline access over secure tunnels, and an interprocess communication (IPC) architecture that coordinates with external analysis applications via ZMQ and EPICS process variables. This IPC approach allows Lightfall to orchestrate specialized analysis tools—including GPU-accelerated streaming correlators—without embedding them, avoiding the dependency conflicts common in monolithic scientific software platforms. Compared to prior approaches such as Xi-CAM's plugin-based architecture, Lightfall's design cleanly separates instrument control from domain-specific analysis, enabling feedback-driven acquisition where live analysis results can adjust scan parameters during an experiment. Its native Qt interface provides responsive performance for real-time data visualization that web-based alternatives struggle to match. Lightfall is designed for use by beamline scientists and staff operating synchrotron instruments at national user facilities.

Pandolfi, Ronald [Lawrence Berkeley National Labor↗

CRADA Number NFE-20-08292 with Quantum Lock Technologies LLC (CRADA Final Report)

At Quantum Lock Technologies, our mission is to use future-proof hardware and software to bridge the gap between physical access control and cyber security. Physical security includes access to doors, lockboxes/containers, and machinery/robots. Connecting physical access control to the cloud allows for remote detection, fast ledger updates, and mobile or remote access. However, this also opens physical security up to the world of cyber-attacks. At Quantum Lock, we use quantum random number generation to generate completely random and unpredictable digital keys to be used by connected equipment in a facility. This quantum technology is then paired with end-to-end encryption and a one-time-key communication protocol to ensure the highest level of security. Through the Innovation Crossroads program at Oak Ridge National Laboratory, we have developed benchtop prototypes of our technology, connected with utility boards as our first target customers, and prepared for our first pilot with customers (target end of summer 2022).

97 MATHEMATICS AND COMPUTING↗

Quantum Lock Technologies: Innovation Crossroads Final CRADA Report

At Quantum Lock Technologies, our mission is to use future-proof hardware and software to bridge the gap between physical access control and cyber security. Physical security includes access to doors, lockboxes/containers, and machinery/robots. Connecting physical access control to the cloud allows for remote detection, fast ledger updates, and mobile or remote access. However, this also opens physical security up to the world of cyber-attacks. At Quantum Lock, we use quantum random number generation to generate completely random and unpredictable digital keys to be used by connected equipment in a facility. This quantum technology is then paired with end-to-end encryption and a one-time-key communication protocol to ensure the highest level of security. Through the Innovation Crossroads program at Oak Ridge National Laboratory, we have developed benchtop prototypes of our technology, connected with utility boards as our first target customers, and prepared for our first pilot with customers (target end of summer 2022). Below is a photograph of myself at an energy substation where we plan to eventually apply our technology.

42 ENGINEERING↗

Use of Radiofrequency Tamper Indicating Devices (RFTID) to Enhance Remotely Monitoring the Security of Advanced and Small Modular Reactors (A/SMRs)

A/SMRs will likely be deployed in remote locations that are difficult to access, thereby requiring limited on-site staff. • Vendors are considering remote monitoring as a solution to enhance nuclear security. RFTIDs are a candidate technology for maintaining nuclear security of A/SMRs but need to be evaluated for feasibility and implementation into the wider physical protection system.

O'Dowd, Kevin [Savannah River National Laboratory ↗

Development of A Hardware-In-the-Loop (HIL) Testbed for Cyber-Physical Security in Smart Buildings

As smart buildings move towards open communication technologies, providing access to the Building Automation System (BAS) through the building's intranet, or even remotely through the Internet, has become a common practice. However, BAS was historically developed as a closed environment and designed with limited cyber-security considerations. Thus, smart buildings are vulnerable to cyber-attacks with the increased accessibility. This study introduces the development and capability of a Hardware-in-the-Loop (HIT) testbed for testing and evaluating the cyber-physical security of typical BASs in smart buildings. The testbed consists of three subsystems: (1) a real-time HIL emulator simulating the behavior of a virtual building as well as the Heating, Ventilation, and Air Conditioning (HVAC) equipment via a dynamic simulation in Modelica; (2) a set of real HVAC controllers monitoring the virtual building operation and providing local control signals to control HVAC equipment in the HIL emulator; and (3) a BAS server along with a web-based service for users to fully access the schedule, setpoints, trends, alarms, and other control functions of the HVAC controllers remotely through the BACnet network. The server generates rule-based setpoints to local HVAC controllers. Based on these three subsystems, the HIL testbed supports attack/fault-free and attack/fault-injection experiments at various levels of the building system. The resulting test data can be used to inform the building community and support the cyber-physical security technology transfer to the building industry.

Li, Guowen↗

Implementation and Performance Evaluation of a Community-Scale Adobe Evaporative Cooling Chamber for Vegetable Preservation

The construction of evaporative coolers in remote areas can increase the longevity of vegetables, improving food security and the local economy of small farmers in remote, impoverished communities without access to electricity. This work presents a 1:1 scale prototype of an 8 m 3 (2.1 × 2.1 × 2.3 m) stabilized adobe evaporative cooler, with a design based on the appropriate technology framework, and it was built as a chamber using double adobe walls, filled with wet sand, to induce evaporative cooling. Furthermore, the paper presents the prototype’s performance evaluation. The tests were carried out in the dry and wet states, with different volumes of water. The results show good performance compared with other prototypes, although the optimum watering volume could not be determined because of the high climate variance (outside temperature and humidity) that prevented the repetition of the experiments in identical operating conditions. Stabilized adobe proved to be a good choice for use in the cooler, even when subject to moisture accumulation, indicating an estimated long lifetime for the cooler. The data obtained about the efficiency of evaporative cooling show that the cooler, as expected, has its best performance on the hottest and driest days, reducing the internal temperature (up to 13.24 °C) and managing to keep the internal humidity. The cost, efficiency, durability, and replicability make the proposed evaporative cooler a feasible solution for food preservation.

42 ENGINEERING↗

A critical review of cyber-physical security for building automation systems

Modern Building Automation Systems (BASs), as the brain that enable the smartness of a smart building, often require increased connectivity both among system components as well as with outside entities, such as the cloud, to enable low-cost remote management, optimized automation via outsourced cloud analytics, and increased building-grid integrations. As smart buildings move towards open communication technologies, providing access to BASs through the building's intranet, or even remotely through the Internet, has become a common practice. However, increased connectivity and accessibility come with increased cyber security threats. BASs were historically developed as closed environments with limited cyber-security considerations. As a result, BASs in many buildings are vulnerable to cyber-attacks that may cause adverse consequences, such as occupant discomfort, excessive energy usage, and unexpected equipment downtime. Therefore, there is a strong need to advance the state-of-the-art in cyber-physical security for BASs and provide practical solutions for attack mitigation in buildings. However, an inclusive and systematic review of BAS vulnerabilities, potential cyber-attacks with impact assessment, detection & defense approaches, and cyber resilient control strategies is currently lacking in the literature. This review paper fills the gap by providing a comprehensive up-to-date review of cyber-physical security for BASs at three levels in commercial buildings: management level, automation level, and field level. The general BASs vulnerabilities and protocol-specific vulnerabilities for the four dominant BAS protocols (i.e., BACnet, KNX, LonWorks, and Modbus) are reviewed, followed by a discussion on four attack targets and seven potential attack scenarios. Furthermore, the impact of cyber-attacks on BASs is summarized as signal corruption, signal delaying, and signal blocking. The typical cyber-attack detection and defense approaches are identified at the three levels. Cyber resilient control strategies for BASs under attack are categorized into passive and active resilient control schemes. Open challenges and future opportunities are finally discussed.

97 MATHEMATICS AND COMPUTING↗

Test and Evaluation of Radiofrequency Tamper Indicating Devices for Remote Monitoring of Advanced/Small Modular Reactors

Advanced and small modular reactors (A/SMRs), due to their versatile nature, are likely to be used in remote locations to provide electrical power or other services in regions that are difficult to access or have limited transportation infrastructure. This will result in limited on-site staff, therefore driving A/SMR vendors to consider remote monitoring as a solution to support nuclear security. Maintaining Continuity of Knowledge (CoK) of nuclear material quantities and locations is vital to nuclear security, and remote monitoring of active tamper indicating devices (TIDs) has been well established as a component of International Atomic Energy Agency (IAEA) Safeguards since the early 2000s. Active TIDs, such as radiofrequency TIDs (RFTIDs), immediately alarm upon unauthorized access attempts, promoting timely detection. In contrast, passive TIDs require a surveillance regime and offer delayed detection. Active TIDs deter insiders and enable prompt detection of malicious acts. They can be used on nuclear material containers and controlled entry points like vaults and toolboxes. Therefore, the implementation of RFTIDs into security programs bolsters overall nuclear material control, and provides a visible deterrent, with primary efficacy in mitigating the insider threat and potentially allowing for Security by Design considerations. They are a strong candidate technology for maintaining nuclear security of A/SMRs but need to be evaluated for feasibility and implementation into the wider physical protection system.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Technology Maturation of Wireless Harsh Environment Sensors For Improved Condition Based Monitoring Of Coal Fired Power Generation

The overall goal of this project was to demonstrate and develop the usage of high-temperature (HT) harsh-environment (HE) wireless surface acoustic wave resonator (SAWR) sensor technology to promote reliable maintenance through condition-based maintenance (CBM) for field applications in harsh service conditions associated with power plant environments. The project aimed to advance the HT HE wireless SAWR sensor technology from TRL 5 to TRL 7. In addition to HT HE wireless temperature sensing, efforts were dedicated during this project to investigate, develop and increase the TRL from 3 to 5 for the following technologies: (a) HT HE strain sensors to address additional CBM monitoring needs, such as boiler tube mechanical / thermal stresses, which can provide early indications for boiler tube cracking and failure; and (b) HT aluminum nitride (AlN) and scandium aluminum nitride (ScAlN) based piezoelectric thin film fabrication and implementation of SAW sensors, with the goal of releasing the need to use single crystal piezoelectric materials for SAWRs and thus broaden possible technology applications to non-planar and harder to modify surfaces. To achieve the goals mentioned above, UMaine and its partner, Environetix Technologies Corporation, established partnerships with the following power plants: Longview Power (Maidsville, WV), a coal-fired power plant; Penobscot Energy Recovery Corp (PERC, Orrington, ME), a waste-to-energy power plant; and the UMaine Steam Plant (Orono, ME), an oil / natural gas power plant. To realize wireless HT HE SAWR sensor systems in these harsh service conditions, the University of Maine research team worked with Environetix and these power plants to define, design, fabricate, test and validate a mature prototype wireless temperature SAWR sensor system for boiler tube applications within the HT HE of the reheater pass damper chamber to directly and wirelessly monitor the temperature at eighteen independent boiler tube locations. The system included three levels, or “tiers”, of wireless communication to enable remote monitoring: Tier 1, the wireless link in the reheater pass damper chamber directly accessing the sensors on the boilers; Tier 2, the wireless local area network link, transmitting processed sensor information within the power plant to the Tier 3, a commercial wireless signal carrier company for secure remote data monitoring outside of the power plant. Regarding the wireless sensor system installed at Longview Power, temperature information from the boilers was continuously transmitted from the Longview boilers at Maidsville, WV, to Environetix headquarters, Orono, ME, over a 34 month period, when the system was finally decommissioned. Strain sensors and piezoelectric ScAlN thin film sensors were successfully installed on the exhaust duct at the UMaine Steam Power plant. The advances in wireless strain sensors and thin film piezoelectric film fabrication and testing were performed mostly in UMaine laboratories and field tested at the UMaine Steam Plant, due to its close proximity to UMaine/Environetix, access to the plant facility, and due to difficulties in accessing the other power plants during the COVID shut-down period. The project accomplished the TRL level increase of the targeted CBM technologies through the successful fabrication, installation, test, and validation of dedicated and commercial wireless sensor systems, utilizing the three different power plants. The outcomes of this project, including the wireless sensor data capability, are expected to yield an advance for CBM in harsh power plant environments. The reduction of maintenance costs, improved safety during plant operation, and increased power plant efficiency will lead to increased revenues (i.e., fewer forced outages) due to better process monitoring enabled by the wireless HT HE SAWR temperature sensor technology.

20 FOSSIL-FUELED POWER PLANTS↗

Overview and Commentary on Applying the Coordinated Vulnerability Disclosure Process to Photovoltaic System Devices

The rapid expansion of photovoltaic (PV) systems, particularly inverters, has introduced new cybersecurity challenges that threaten both local operations as well as the broader electrical grid’s stability. PV inverters, integrated into critical energy infrastructure are potential targets for cyber attacks due to vulnerabilities in firmware, remote access systems, and communication protocols. The Coordinated Vulnerability Disclosure (CVD) process, as defined by the Cybersecurity and Infrastructure Security Agency (CISA), provides a framework for identifying, reporting, and addressing these vulnerabilities in a transparent and collaborative manner. This report outlines the CVD process as it applies to PV systems, detailing the roles of key stakeholders, such as manufacturers, grid operators, and security researchers. The report also highlights specific challenges in managing vulnerabilities for new and legacy PV systems, which includes those introduced by insecure communications and third-party supply chain components. By adhering to the CVD process, the PV industry can mitigate cybersecurity risks, ensure regulatory compliance, and maintain consumer trust, while safeguarding the operational resilience of the energy grid. Ultimately, the effective coordination of vulnerability management is crucial for securing the future of PV systems within the critical electric grid infrastructure landscape.

14 SOLAR ENERGY↗

Analyzing Insider Risk Threat to the Internet of Things (IoT)

Recent technological advancement has created a growing convergence of innovation. From machine learning to ubiquitous computing to wireless networks and automation, the world is seeing new technology increasingly capable of connecting with each other. Devices and systems use open communications networks to interact, process information, and react. This is called the Internet of Things (IoT) and is comprised of physical devices that exchange data over networks, creating revolutionary possibilities. The most common way most people interact with an IoT is through ‘smart home’ products like Amazon’s Alexa, which use microphones, speakers, and phones to control a variety of devices, from lights and thermostats, to cameras, to appliances and vacuum cleaners. But the open nature of IoT networks—necessary for their ability to communicate and operate—also introduces privacy and security concerns. At a personal level, this might mean a hack into a home to steal private information, but when applied in broader industries like healthcare, transportation, manufacturing, or the military, this vulnerability can have serious consequences. As IoT usage and interconnectivity increases, so too does the susceptibility to malicious actors. And the entire system is only as secure as its least secure member. This creates particular risk and vulnerability to radiological material industries, as a competent insider adversary could utilize the IoT to potentially steal or access classified or sensitive information about employees, sites, or systems; or simply sabotage security or maintenance from a more remote—and less secure—device. The IoT relies on a secure network across the entire system, especially in transport which may lack the security of more permanent locations; if one device fails, it can create a ripple effect and an insider threat may seek to exploit that connectivity. While IoT benefits drive increased innovation and usage, there are also vulnerabilities an insider threat could exploit; this risk of an IoT to radiological material must be addressed in any mitigation effort.

Kinney, Justin↗

Proposed Classifications of Remote Operations for Nuclear Reactors Based on Physical and Cybersecurity Considerations

The incorporation of remote operations into reactor operations is a topic of high interest among advanced and small modular reactor (A/SMR) vendors, with some considering it essential to the success of their business models. However, remote operations are a concept novel to the nuclear industry. While various technical aspects of remote operations have been explored, a significant gap remains in understanding the security implications of integrating remote operations into reactor designs, particularly concerning the security requirements for remote-operations facilities and infrastructure. This report aims to address this gap by first defining classes of remote operation based on the extent of remote access to reactor control systems and grounded in the existing regulatory framework with compatible terminology. Secondly, the report outlines the physical and cybersecurity requirements applicable to remote-operations facilities and infrastructure at each defined class. These requirements are based on existing licensing frameworks provided by 10 Code of Federal Regulations (CFR) Part 50 and 10 CFR Part 52, as well as the upcoming A/SMR licensing framework in the proposed Part 53. The assessment focuses specifically on security regulations, such as 10 CFR Part 73, which includes provisions for both cybersecurity (§ 73.54) and physical security (§ 73.55). This report proposes five classes of remote reactor operations. Class 1 involves remote monitoring only, with no control over reactor systems. Class 2 allows for the remote issuance of allowlisted commands to the reactor facility. Class 3 extends control to non-safety-significant, non-safety-related, or not important to safety systems and equipment. Class 4 permits remote control of safety-significant systems. Finally, Class 5 allows remote control of safety-related systems. It is important to note that these classes were defined purely with functionality in mind, without considering the practicality or feasibility of implementation for each class under current or upcoming regulatory guidance. The intention behind this approach is to enable an assessment of which security requirements apply to each class, allowing readers to evaluate the implementation possibilities for their specific use cases. Following the definition of remote-operation classes, the report assesses the specific physical and cybersecurity requirements applicable to the remote-operations facility and infrastructure within each defined class. This includes defining the types and locations of operators that are possible at each class of operation and, based on operator type and location, as well as functionality within each class, outlining the physical and cybersecurity requirements. By detailing the security requirements by class, the report provides readers with the information needed to determine the type of security program they may need to implement for their desired concept of operation. The next contribution of this report was to assess the practicality of implementing each proposed class of remote operations based upon the security requirement assessment. In short, three of the five proposed remote-operation classes were found to possibly have a practical path forward to implementation under the U.S. regulatory framework. Class 1 remote operations are currently in use in the U.S. while Class 2 and 3 remote operations may be logistically possible to implement under the U.S. regulatory framework. The final two Classes, 4 and 5, would likely be logistically difficult, if not infeasible to implement within the current U.S. physical- and cybersecurity regulatory framework. Given the results of the feasibility assessment, an example architecture is proposed for both Class 2, remote allowlisted commands, and Class 3, remote control of non-safety systems as well as security implication assessments of each architecture. These example implementations are not meant to be prescriptive in terms of how Class 2 or Class 3 remote operations should be deployed; instead, they are intended to be informative to stakeholders on how Class 2 or Class 3 could potentially be applied in order to inform their system design. An example architecture for Class 1 remote monitoring was not provided as Class 1 in already in use in U.S. nuclear operations. Example architectures for Class 4 and Class 5 were not provided due to their assessment of being likely infeasible to implement. The final contribution is an assessment of the physical- and cybersecurity implications of introducing autonomous operations into an A/SMR. What was found was that the security implications can be separated into two cases. Autonomous operations supported by SSCs located only at the reactor site, and autonomous operations supported by SSCs outside of the reactor site. For the first case, the introduction of autonomous systems will likely not change the facility’s requirement to comply with existing cyber and physical security regulation

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Cybersecurity Incident Response Guide for Wind

As wind energy systems become increasingly digitized and interconnected, they face a growing array of cyber threats that can disrupt operations, compromise safety, and trigger cascading impacts across the energy ecosystem. The Wind Incident Response Guide provides a structured, wind-specific framework for preparing for, detecting, responding to, and recovering from cyber incidents. Drawing on lessons from field demonstrations, cyber-physical testbeds, and stakeholder engagement across the wind sector, this guide integrates technical, operational, and regulatory considerations to support asset owners, operators, and responders. It outlines key roles and responsibilities, maps incident response phases to wind-specific scenarios, and highlights applicable laws, regulations, standards, and best practices. By tailoring general cybersecurity principles to the unique architectures and operational constraints of wind systems—including remote access, legacy components, and environmental interfaces—this guide aims to enhance resilience, reduce response time, and support coordinated action across public and private stakeholders. It is intended as a practical resource for utilities, developers, regulators, and emergency managers working to secure the future of wind energy.

17 - WIND ENERGY↗