Search NASA⌕ Search

SEARCH · Search NASA

Results for “security and privacy”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Security and Privacy Issues in New 5G and 6G Capabilities

Slides for opening INL hosted panel on Security and Privacy Issues in New 5G and 6G Capabilities in the Security and Privacy of Next-Generation Networks (FutureG) Workshop co-located with NDSS Symposium 2025, San Diego, CA.

5G Security↗

Secure and Privacy Aware Data Sharing Approach for Smart Electric Vehicles

The integration of smart electric vehicles (SEVs) into smart cities marks a significant step toward creating efficient, sustainable, and connected urban spaces. However, secure and private data sharing is a major challenge as SEVs connect with smart city systems. The interaction between SEVs and consumer electronic devices (CEDs) raises serious concerns about data security and privacy. Here, to address these challenges, this article presents how blockchain technology and federated learning (FL) can address these issues. The proposed approach provides a secure and privacy-aware framework for data exchange between SEVs and CEDs in smart cities. The experiment results demonstrate the effectiveness of the proposed framework for secure data sharing and maintaining system reliability in smart city environments. It also enables trust and promotes the widespread adoption of interconnected urban technologies.

Das, Debashis [Meharry Medical College, Nashville,↗

Privacy-preserving Information Security for the Energy Grid of Things

Smart grid infrastructure relies on information exchange between multiple actors in order to ensure system reliability. These actors include but are not limited to smart loads, grid control, and energy management technologies. Further, as information exchange between these actors is susceptible to cyber-attacks, security and privacy issues are indispensable to ensure a reliable and stable grid. This position paper proposes a privacy-preserving, trust-augmented secure scheme for a smart grid implementation.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Blockchain-Enabled Secure Device-to-Device Communication in Software-Defined Networking

The Internet of Things (IoT) continues to increase the demand for seamless communication among IoT devices. The rapid growth of IoT devices has led to an exponential increase in device-to-device (D2D) communication within the Software-Defined Networking (SDN), though it enables a flexible archi-tecture for managing network resources. However, traditional security models face challenges (e.g., Security, privacy, and trust) in addressing the dynamic and decentralized nature of these communications. Despite of these challenges, this paper proposes a novel approach that leverages blockchain technology to enhance the security, privacy, and trustworthiness of D2D communication within an SDN environment. The proposed approach integrates blockchain nodes in sDN components to establish a decentralized ledger for transparent and verifiable records. Smart contracts enforce authentication rules to ensure that only authenticated devices can access the network and engage in transactions securely. It also automates the security policies to ensure temper resistance execution using the cryptographic mechanism for data integrity and authentic communication. The Implementation of the proposed algorithms validates the resilience of the proposed approach against cyberattacks. Overall, the proposed approach enables efficient and secure D2D communication for resilient SDN infrastructure in IoT ecosystems.

Das, Debashis↗

Isolating Insecurely: A Call to Arms for the Security and Privacy Community During the Time of COVID-19

The privacy question is one that has only begun to be addressed. While on one hand, many of the staunchest privacy advocates have argued for relaxation of privacy controls in order to develop better tests, “back to work” protocols, and vaccines and other treatments, the same advocates point out that any loss of privacy for the public good should be temporary, transparent, necessary, proportionate, and follow a due process. What should solutions look like for data gathering, sharing, use, and disposal; or for protocols requiring strong individual identity verification and validation?

99 GENERAL AND MISCELLANEOUS↗

Federated Learning and Differential Privacy: What might AI-Enhanced co-design of microelectronics learn?

Data is a valuable commodity, and it is often dispersed over multiple entities. Sharing data or models created from the data is not simple due to concerns regarding security, privacy, ownership, and model inversion. This limitation in sharing can hinder model training and development. Federated learning can enable data or model sharing across multiple entities that control local data without having to share or exchange the data themselves. Differential privacy is a conceptual framework that brings strong mathematical guarantee for privacy protection and helps provide a quantifiable privacy guarantee to any data or models shared. The concepts of federated learning and differential privacy are introduced along with possible connections. Lastly, some open discussion topics on how federated learning and differential privacy can tied to AI-Enhanced co-design of microelectronics are highlighted.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Development of an Energy Services Interface for the EGoT

The Energy Services Interface (ESI) is a set of rules that ensure private, secure, and trustworthy information exchange between Grid Service Providers (GSPs) and utility customers. Large-scale adoption of Distributed Energy Resources (DERs) will be necessary for GSPs to dispatch effective grid services, and to stimulate technological innovations in DER and DERMS (DER Management Systems) technologies, as well as novel grid service programs. The ESI promotes these objectives by advancing a set of rules and interoperability requirements that define bi-directional, service-oriented, logical interfaces between GSPs and customers’ DERs, with expectations for privacy, security, and trust. The ESI rules and interoperability requirements establish boundaries between customers and GSPs that delineate the functions and responsibilities that must be implemented by the developers of Energy Grid of Things (EGoT) ecosystem products. These rules impose constraints on the implementation of a DERMS. The ESI interoperability requirements are based on the Interoperability Maturity Model (IMM), developed by the Grid Modernization Laboratory Consortium. By emphasizing private, secure, and trustworthy information exchange, and by mandating a service-oriented and interoperable architecture, the ESI promotes the development of an EGoT ecosystem that motivates customer participation and technological innovation. Interoperability will encourage innovation by reducing barriers to entry and increasing confidence of stakeholders. Customers will be willing to participate in DER service programs that establish trust and emphasize customer choice. Large-scale customer participation ensures GSPs have ample DER resources to provide grid services that have significant impact on grid reliability and reduce electricity cost for consumers. This in turn signals economic opportunities that encourage innovation, resulting in the development of a robust EGoT ecosystem.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Development of an end state vision to implement digital monitoring in nuclear plants

Transitioning from an onsite Maintenance & Diagnostics Center to cloud-based services offers many new opportunities with computing power and storage, but also new challenges in terms of networking and security. This report will cover everything required for that transition including data processing and uploading to cloud services, feature selection, model creation, and result visualization for decision making. Although there are several other cloud-based services (e.g. Amazon Web Services and Google Cloud), this report explores Microsoft Azure to simplify nomenclature and maintain a consistent focus. Many of the services offered by Microsoft Azure are also available in the other cloud-based services, and their differences have been recorded in other literature. The Azure services most important to a nuclear power plant including networking & security, storage & databases, and Artificial Intelligence (AI) are reviewed here. Networking covers all aspects related to communication to Azure resources including security, privacy, and redundancy. Storage & databases includes data storage, upgrading, patching, backups, and monitoring. The AI services allows the user access to the machine learning (ML) techniques developed with Azure including automated ML, anomaly detection, computer vision, and natural language processing. This report summaries the features, capabilities, and challenges when using cloud-based services in a user-friendly manner.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Transactive Energy System Deployment Over Insecure Communication Links

Here, in this paper, the privacy and security issues associated with the transactive energy system (TES) deployment over insecure communication links are addressed. In particular, it is ensured that 1) individual agents’ bidding information is kept private throughout hierarchical market-based interactions; and 2) any extraneous data injection attack can be quickly and easily detected. An implementation framework is proposed to enable the cryptography-based enhancement of privacy and security for the deployment of any general hierarchical systems including TESs. Under the proposed framework, a unified cryptography-based approach is developed to achieve both privacy and security simultaneously. Specifically, privacy preservation is realized by an enhanced Paillier encryption scheme, where a block design is proposed to significantly improve computational efficiency. Attack detection is further achieved by an enhanced Paillier digital signature scheme, where a stamp-concatenation mechanism is proposed to enable detection of data replace and reorder attacks. Simulation results verify the effectiveness of the proposed cyber-resilient design for transactive energy systems. Note to Practitioners—This paper is motivated by addressing the issues of cyber resiliency for practically deploying transactive energy system (TES) but it is also applicable to the problem of enhancing the privacy and security for any general hierarchical control systems. TES is an emerging control approach that engages energy suppliers and customers through market operations and uses the price to optimally allocate energy resources. While it has been shown to be promising for power system applications, the underlying market-based interactions raise significant concerns of privacy (data leakage) and security (data tampering). However, existing TES works only focus on the coordination mechanism instead of privacy and security issues. This paper proposes a new cryptography-based TES design for practical deployment. Specifically, to protect privacy, individual supply and demand amounts to be exchanged are all encrypted in a particular way such that the original amounts cannot be inferred from the encrypted amounts, while the desired computation for setting the market clearing price can be carried out over the encrypted amounts, thus generating an encrypted result which, when decrypted, matches that of the same computation over the original amounts. To achieve security, for each exchanged data, its sender generates a particular digital signature which is exchanged together with the data. This enables the receiver to automatically detect the integrity by checking whether a mathematical relationship holds for the pair of data and signature. In our future research, we will investigate more challenging scenarios where some suppliers and customers themselves could be corrupted and purposely submit distorted amounts.

97 MATHEMATICS AND COMPUTING↗

Investigating Users’ Privacy Concerns of Internet of Things (IoT) Smart Devices

Although the number of smart Internet of Things (IoT) devices has grown in recent years, the public's perception of how effectively these devices secure IoT data has been questioned. Many IoT users do not have a good level of confidence in the security or privacy procedures implemented within IoT smart devices for protecting personal IoT data. Moreover, determining the level of confidence end users have in their smart devices is becoming a major challenge. In this paper, we present a study that focuses on identifying privacy concerns IoT end users have when using IoT smart devices. We investigated multiple smart devices and conducted a survey to identify users’ privacy concerns. Furthermore, we identify five IoT privacy-preserving (IoTPP) control policies that we define and employ in comparing the privacy measures implemented by various popular smart devices. Results from our study show that the over 86% of participants are very or extremely concerned about the security and privacy of their personal data when using smart IoT devices such as Google Nest Hub or Amazon Alexa. In addition, our study shows that a significant number of IoT users may not be aware that their personal data is collected, stored or shared by IoT devices.

Joy, Daniel↗

K-anonymity applied to the energy grid of things distributed energy resource management system

Smart grid infrastructure relies on information exchange between multiple actors in order to ensure system reliability. These actors include but are not limited to smart loads, grid control, and energy management technologies. As information exchange between these actors is susceptible to cyber-attacks, security and privacy issues are indispensable to ensure a reliable and stable grid. This position paper proposes a privacypreserving, trust-augmented secure scheme for a smart grid implementation.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Are System Baselines within OT Environments Feasible?

Critical infrastructure stakeholders need to baseline their systems to understand expected protocol communications.Baseline behaviors may vary based on operational context.Expected operations during a maintenance window, for example, may be different from normal operations.Furthermore, constructing system baselines for Industrial Control Systems (ICS) is difficult and time-consuming.ICS processes generate artifacts expressed across heterogeneous data sources such as network and device logs. There needs to be a corpus of data in order to develop and compare methods that evaluate the feasibility, performance, and generality of approaches to construct baselines for ICS events. Standalone repositories of network packet captures are insufficient to develop methods to classify or recognize operational events expressed across multiple data sources. Moreover, static data corpora do not enable researchers to compare the impact of changing the underlying system for which a baseline is being constructed and this limits the ability to evaluate the performance of system baselines given system changes (e.g. patches, configuration, maintenance events). In order to address these limitations within the community, this talk intends to promote discussion about the state of the practice of constructing baselines. In this manner, we can continue to understand requirements within industry that are not being met by current approaches to baseline construction. This talk builds on two previous talks on the topic of system baselines for OT environments. First, Weaver co-presented at the RSA Conference ICS Sandbox with Dan Gunter. The talk confirmed the need within industry to construct baselines across multiple types of data sources relative to the semantics of specific business processes. Second, Weaver presented at IEEE Security and Privacy Workshop on Language-Theoretic Security.

02 PETROLEUM↗

Securing Environmental IoT Data Using Masked Authentication Messaging Protocol in a DAG-Based Blockchain: IOTA Tangle

The demand for the digital monitoring of environmental ecosystems is high and growing rapidly as a means of protecting the public and managing the environment. However, before data, algorithms, and models can be mobilized at scale, there are considerable concerns associated with privacy and security that can negatively affect the adoption of technology within this domain. In this paper, we propose the advancement of electronic environmental monitoring through the capability provided by the blockchain. The blockchain’s use of a distributed ledger as its underlying infrastructure is an attractive approach to counter these privacy and security issues, although its performance and ability to manage sensor data must be assessed. We focus on a new distributed ledger technology for the IoT, called IOTA, that is based on a directed acyclic graph. IOTA overcomes the current limitations of the blockchain and offers a data communication protocol called masked authenticated messaging for secure data sharing among Internet of Things (IoT) devices. We show how the application layer employing the data communication protocol, MAM, can support the secure transmission, storage, and retrieval of encrypted environmental sensor data by using an immutable distributed ledger such as that shown in IOTA. Finally, we evaluate, compare, and analyze the performance of the MAM protocol against a non-protocol approach.

Gangwani, Pranav (ORCID:0000000159226002)↗

An Ethics-Based Review of Generative Artificial Intelligence: Assuring Responsible Use (Version 1.0)

The rapid expansion of generative artificial intelligence (GenAI) has generated excitement regarding its potential benefits and concern over its ethical implications. Governments, corporations, and standards organizations have described ethical principles to direct GenAI's development and use; however, practical guidance for implementing these principles is limited. Addressing this gap is critical, especially considering the array of risks associated with GenAI, such as legal liabilities, privacy concerns, security threats, and potential misuse. Robust policies and procedures are critical to support responsible deployment of GenAI. This report examines Pacific Northwest National Laboratory (PNNL)’s approach to promoting responsible GenAI use. Proposed initiatives include developing policies based on ethical principles, creating a governance process to review projects relative to those principles, and implementing onboarding processes for training staff. The governance framework described in this report adapts the structure and principles of Institutional Review Boards (IRBs), traditionally used in human subjects research, for GenAI ethical review, providing oversight. Ethical principles guiding responsible GenAI usage include transparency and accountability, privacy, fairness, safety, security, and validity and reliability. To operationalize these principles, we propose forming a GenAI Assurance Council (GAC) that mirrors the IRB's structure. The GAC will evaluate GenAI projects across privacy, accountability, transparency, safety, security, fairness, and validity dimensions. Complementing policy and governance is AI literacy training to support staff understanding of GenAI's ethical implications. An initial training effort for AI Incubator Chat—a GenAI tool deployed at PNNL—showed promising results, underscoring the importance of clear guidelines and user accountability. Collaborative efforts and the dissemination of best practices are also discussed. The proposed GAC model and AI literacy training provide a blueprint for establishing ethical GenAI use and governance, offering practical tools to bridge the gap between ethical principles and real-world applications. The responsible integration of GenAI at PNNL entails a multifaceted approach involving policy development, ethical governance, and AI literacy training. The positive initial feedback and collaborative opportunities position PNNL to lead by example in GenAI's responsible use, reflecting a proactive stance in addressing the ethical, legal, and societal challenges associated with this emerging technology. PNNL's systematic and ethical approach to GenAI offers a model for other institutions to emulate, promoting safe and responsible technological advancements in the AI domain.

97 MATHEMATICS AND COMPUTING↗

Optimal vocabulary selection approaches for privacy-preserving deep NLP model training for information extraction and cancer epidemiology

With the use of artificial intelligence and machine learning techniques for biomedical informatics, security and privacy concerns over the data and subject identities have also become an important issue and essential research topic. Without intentional safeguards, machine learning models may find patterns and features to improve task performance that are associated with private personal information. The privacy vulnerability of deep learning models for information extraction from medical textural contents needs to be quantified since the models are exposed to private health information and personally identifiable information. The objective of the study is to quantify the privacy vulnerability of the deep learning models for natural language processing and explore a proper way of securing patients’ information to mitigate confidentiality breaches. The target model is the multitask convolutional neural network for information extraction from cancer pathology reports, where the data for training the model are from multiple state population-based cancer registries. This study proposes the following schemes to collect vocabularies from the cancer pathology reports; (a) words appearing in multiple registries, and (b) words that have higher mutual information. We performed membership inference attacks on the models in high-performance computing environments. The comparison outcomes suggest that the proposed vocabulary selection methods resulted in lower privacy vulnerability while maintaining the same level of clinical task performance.

59 BASIC BIOLOGICAL SCIENCES↗

Tikiri—Towards a lightweight blockchain for IoT

Internet of Things (IoT) platforms have been deployed in several domains to enhance efficiency of business process and improve productivity. Most IoT platforms comprise of heterogeneous software and hardware components which can potentially introduce security and privacy challenges. Blockchain technology has been proposed as one of the solutions to realize IoT security by leveraging the (a) Immutable ledger, (b) Decentralized architecture and (c) Strong cryptography primitives. However, integrating blockchain platforms with IoT based applications presents several challenges due to lack of (a) acceptable performance on resource-constrained devices, (b) high transaction throughput, (c) keyword-based search and retrieve, (d) transaction back pressure operations, and (e) real-time response. In this paper, we propose a lightweight blockchain platform, “Tikiri”, for resource-constrained IoT devices. Tikiri uses Apache Kafka for the consensus and proposes new blockchain architecture to handle real-time transaction execution on the blockchain. Tikiri is characterized by functional programming and actor-based smart contract platform that realizes concurrent execution of transactions in the blockchain. Tikiri realizes a lightweight and scalable blockchain that can provides performance on the resource-constrained IoT devices.

97 MATHEMATICS AND COMPUTING↗

Emerging Technologies for Privacy Preservation in Energy Systems

This study explores the intersection of digitalization and privacy within the energy sector, focusing on the emerging challenges and opportunities presented by integrating Distributed Energy Resources (DERs) and advanced metering infrastructure. The need for robust digital privacy measures has become crucial as the energy industry evolves towards a more decentralized, digitalized, and decarbonized future. This study delves into four cutting-edge privacy-preserving technologies—Homomorphic Encryption (HE), Secure Multiparty Computation (SMPC), Differential Privacy (DP), and Federated Learning (FL)—each offering unique solutions to safeguard consumer data by increasing digital connectivity and data exchange. Through a detailed examination of these methods, the study explains how each technology operates, its applications within the energy sector, and the specific privacy challenges it addresses. Homomorphic Encryption allows for secure computations on encrypted data, enabling data analysis without compromising privacy. Secure Multiparty Computation enables collaborative data analysis across different entities while protecting the confidentiality of the inputs. Differential Privacy introduces randomness into the assembled data set, preventing the identification of individual records in statistical databases. Lastly, Federated Learning offers a paradigm shift in data analysis, where machine learning models are trained at the edge, minimizing the centralization of sensitive data. The research underscores the significance of implementing these privacy-enhancing technologies to comply with strict data protection regulations, foster consumer trust, and enhance the security of the energy infrastructure. By providing a comprehensive overview of these methodologies and their practical implications for the energy sector, this study aims to contribute to the ongoing discourse on digital privacy, offering insights into how the energy industry can navigate the complexities of data privacy in the digital age.

Cali, Umit↗