Search NASASearch

SEARCH · Search NASA

Results for “security verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Impact of light output on the timing resolution of organic glass scintillator bars in a dual-ended readout configuration

The effectiveness of detector system modeling and validation depends on the quality of characterization performed on the system. For nuclear nonproliferation applications, which require detectors to address complex and variable field conditions, access to accurate system models is essential. This study presents the timing characterization of organic glass scintillator bars used in an imaging system developed at the University of Michigan. 137 Cs and 60 Co gamma-ray sources were used to determine the coincidence time resolution as a function of measured light output for two Compton scatter events between two organic glass scintillator bars. Timing resolution for two events, each with light output ranging from 100 to 1100 keVee were characterized. The resulting data were fit to a parametric function that was validated to agree with experimental results within ±25 ps. Simulations were performed to establish appropriate calibration points for each organic scintillator, thereby ensuring accurate calibration of light output values during analysis. This work successfully characterized the light output dependence of the coincidence timing resolution of a pair of organic glass detectors for use in an imaging system. Depending on the amount of scintillation light output from the events, the full width at half maximum of the measured coincidence time resolution ranged from 653.2 ± 16.1 ps for low light yields, 100 keVee, to 121.0 ± 8.4 ps for higher yields at 1100 keVee. The insights obtained from the timing resolution behavior will allow for accurate simulation capabilities in future security and verification efforts using scatter-based imaging systems.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND

Storage Field Development Plan: One Earth Energy

This Storage Field Development plan presents the Storage Complex characterization results, construction, monitoring, and operational plans, and costs associated with the proposed One Earth Sequestration Carbon Capture and Storage (OES-CCS) site in McLean County, Illinois, near Gibson City. The proposed storage complex, known as the Mt. Simon Storage Complex, comprises the Cambrian Mt. Simon Sandstone reservoir and the primary seal, the Cambrian Eau Claire Formation. The lowermost Underground Source of Drinking Water (USDW) identified for the site is the Ordovician St. Peter Sandstone. Geologic characterization of the Mt. Simon Storage Complex at the OES-CCS site was performed by the Illinois Storage Corridor CarbonSAFE Phase III project, which also prepared and submitted three UIC Class VI applications to construct three injection wells; the permit applications were submitted and are in the federal EPA review process. A characterization well, OEE #1, was drilled to collect site-specific data. These data were analyzed and used to develop the UIC Class VI applications. The OEE #1 well will be converted to an in-zone monitoring (IZM) well for the injection phase. The proposed buildout for the OES-CCS site includes (1) three injection wells (OES #1, OES #2, and OES #3), (2) two IZM wells, (3) two above confining zone (ACZ) monitoring wells, one of which will be used to monitor the lowermost USDW, (4) capture and compression facilities, and (5) transportation facilities, i.e., pipelines. A pre-operational testing program was proposed in the Class VI permit application and will be employed at the site pending approval. Additional pre-injection (baseline), syn-injection, and post-injection monitoring and site care procedures will be followed by OES to ensure that injection activities are protective of human health and the environment. Injection is scheduled to begin in 2025, distributed across the three injection wells in accordance with the permit operating conditions. One Earth Sequestration intends to inject up to 90 million tonnes of CO 2 over a period of approximately 20 years. Injection will begin at approximately 0.5 million tonnes of CO 2 annually and ramp up to a maximum of 4.5 million tonnes annually. Daily injection rates are expected to range from 1,400 to 1,500 tonnes per day initially and reach a maximum of approximately 4,225 tonnes per day, depending on site geology and injectivity at each injection well location, and CO 2 availability. The costs associated with the OES-CCS project include pre-operational costs (e. g. additional seismic data acquisition and well drilling), capture and transportation facility and equipment costs, predicted field operating expenditures (OpEx), and decommissioning and post-injection site care (PISC) costs. The risks associated with project activities, such as site construction, injection operations, and verification of secure storage were evaluated, and mitigation strategies proposed to alleviate those risks.

09 BIOMASS FUELS

Countering Weapons of Mass Destruction (CWMD) Zero Trust Framework: CWMD Zero Trust Principles Model

The research focuses on the critical need for enhanced cybersecurity within the Countering Weapons of Mass Destruction (CWMD) Office, specifically targeting Chemical, Biological, Radiological, and Nuclear devices. Traditional perimeter-based security models are insufficient against modern cyber threats, prompting a shift toward Zero Trust principles (ZTP) that emphasize continuous verification and stringent security for all devices. Federal directives mandate the adoption of Zero Trust (ZT) across agencies, supported by guidelines from National Institute of Standards and Technology (NIST), U.S. Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA), U.S. Department of Defense (DoD) and National Security Agency (NSA). The research involved mapping ZT guidance from these agencies to develop tailored CWMD ZTP. The study identified gaps and areas for improvement, including clear transitional guidance from traditional to ZT architectures and the focus on explicit cross cutting capabilities. Design improvements are recommended to ensure increased comprehensive protection and resilience against sophisticated cyber threats for Chemical, Biological, Radiological, and Nuclear (CBRN) devices. Collaborative efforts among federal agencies are essential for the successful deployment of an optimized ZT guidance.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF

Toward Trustworthy Autonomous Science: A Two-Year Community Roadmap

One year ago, the AISLE roadmap argued that autonomous laboratories operated as isolated islands and proposed a grassroots network organized around five critical dimensions. The field has since moved faster than that roadmap anticipated: multi-agent systems have produced experimentally validated hypotheses, self-driving laboratories have grown more interoperable and orchestrated, reasoning-trained and domain foundation models have raised the capability ceiling, and the Genesis Mission has placed autonomous experimentation at the center of U.S. federal science strategy, with industry emerging as a primary actor. Progress has met a sobering counter-current, including a corrected flagship discovery result, benchmarks showing that agents which rival experts on closed-ended questions still complete only a fraction of open-ended research, and fabricated citations surfacing at leading venues. We read this as the defining tension of the field: producing a candidate discovery is no longer the hard part, but verifying it is, and this asymmetry now limits autonomous science more than raw model capability. Accordingly, we update the roadmap around seven dimensions, revisiting the original five and elevating two former cross-cutting concerns, trust, verification, and reproducibility, and safety, security, and governance, to first-class status. We assess the original milestones (M1 through M14) as achieved, partially achieved, reframed, or open, add four new milestones (M15 through M18) for the elevated dimensions, and scope the path forward to a two-year horizon, with the first year concentrating on interfaces, protocol adoption, and the scaffolding of verification, and the second targeting federation, zero-trust coordination, and governance. Throughout, we position the grassroots network as the interoperability fabric that lets national programs, international initiatives, and commercial platforms connect rather than re-silo.

99 GENERAL AND MISCELLANEOUS

Orthogonality broadcasting and quantum position verification

The no-cloning theorem leads to information-theoretic security in various quantum cryptographic protocols. However, this security typically derives from a possibly weaker property that classical information encoded in certain quantum states cannot be broadcast. To formally capture this property, we introduce the study of ‘orthogonality broadcasting.’ When attempting to broadcast the orthogonality of two different qubit bases, we establish that the power of classical and quantum communication is equivalent. However, quantum communication is shown to be strictly more powerful for broadcasting orthogonality in higher dimensions. We then relate orthogonality broadcasting to quantum position verification and provide a new method for establishing error bounds in the no pre-shared entanglement model that can address protocols previous methods could not. Our key technical contribution is an uncertainty relation that uses the geometric relation of the states that undergo broadcasting rather than the non-commutative aspect of the final measurements.

quantum cryptography

Quantifying Operational Drivers of Multimodal Biometric Verification in Aerial Surveillance

Multimodal biometric verification is increasingly applied across operational contexts ranging from close-range security cameras and building-mounted surveillance to long-range ground sensors and unmanned aerial system (UAS) imagery. Variations in acquisition conditions—such as image resolution, viewing geometry, and motion artifacts—pose significant challenges for cross-domain algorithmic generalization. This study evaluates two independent multimodal biometric verification systems developed under the Intelligence Advanced Research Projects Activity (IARPA) Biometric Recognition and Identification at Altitude and Range (BRIAR) program, comparing performance on close-range and aerial datasets. Close-range video served as a baseline to quantify the decline in verification performance on aerial footage. The dataset included six UAS platforms, spanning small quadcopters at 10m altitude to medium-sized fixed-wing aircraft at 360m. Mixed-effects logistic regression identified image resolution (head and body pixel counts), head height, sensor characteristics, and algorithm selection as primary determinants of verification success, whereas demographic attributes and mission gait were not significant predictors. Activity type and collection site influenced performance in close-range data but had negligible impact on UAS imagery. These results clarify modality-specific strengths and limitations and highlight opportunities to enhance cross-domain biometric verification.

Peluso, Alina [ORNL] (ORCID:0000000328950406)

Roxana Paramo Ramirez: MSIIP 2025-2026 Internship [Poster]

At Sandia National Laboratories, there is a high level of importance placed on identifying and developing solutions to the nation’s current and future security problems. One of these problem would be hardware electronics validation and verification.

42 ENGINEERING

PROACTIVE Focus Area 4: Structured Decision Metrics Analysis (Final Report)

A structured decision metrics analysis was developed as one of the tasks under PROACTIVE’s Focus Area 4 (FA4) and used structured decision metrics for processes, items, and facilities (PIF) to determine the efficacy of an M&V system in meeting treaty goals and technical objectives. The method starts with the functional decomposition of a “treaty” with the M&V system overlaid on it. A Functional Decomposition Rubric (FDR) for each PIF is used to determine a score ranging from 0 (weak) to 4 (strong) for assurance, security, and burden. The individual scores are combined to provide an overall Verification System Score (VSS) which assesses the overall verification system’s suitability given goals; scores for each step of the process are also given. The outcome of the evaluation is to identify needs or modifications to the enterprise model, verification system, or proposed testbed capabilities. VeriScore was used to evaluate FA4’s Spiral 0 exercise; those results are included in this report. The VeriScore and FDR framework can also be used in a non-treaty environment, as any goal/objective/method structure will work, thus expanding its applicability beyond traditional arms control structures.

99 GENERAL AND MISCELLANEOUS

Navigating United States Standards and Regulation for Digital Energy Systems

This report provides an analysis of the U.S. standards and regulatory landscape for digital energy systems, focusing on cybersecurity, safety, and reliability requirements. It examines the interplay between federal mandates, state regulations, voluntary industry standards, and utility-specific policies, highlighting critical gaps between compliance and real-world risk mitigation. While NERC CIP standards enforce cybersecurity for Bulk Electric System assets, distribution-level infrastructure and emerging technologies often fall outside mandatory oversight, creating vulnerabilities. The report identifies systemic challenges such as reliance on self-attestation, uneven state adoption of safety codes, and lagging standards for advanced technologies like battery energy storage and inverter-based resources. Through a detailed gap analysis, it underscores the urgency of proactive risk-based approaches, independent verification, and strategic engagement with state and federal entities. Recommendations include adopting tiered security frameworks, strengthening procurement practices, and addressing emerging technology risks to ensure resilient and secure digital energy infrastructure. This guidance is intended for utilities, regulators, and stakeholders navigating compliance obligations and seeking to enhance cybersecurity and safety beyond minimum standards.

24 - POWER TRANSMISSION AND DISTRIBUTION

Evaluation of Real-Time Mitigation Techniques forCyber Security in IEC 61850 / IEC 62351Substations

This paper presents the design logic and implementation aspects of three potential real-time mitigation techniques capable of countering GOOSE-based attacks: (i) IEC 62351-compliant message authentication code (MAC) scheme, (ii) a semantics-enforced rule- based intrusion detection system (IDS), and (iii) a hybrid approach integrating both MAC verification and Intrusion Detection System (IDS). A comparative evaluation of these real-time mitigation approaches is conducted using a cyber-physical system(CPS) security testbed. The results show that the hybrid integration significantly enhances mitigation capability. Furthermore, the processing delays of all three methods remain within the strict delivery requirements of GOOSE communication. The study also identifies limitations that none of the techniques can fully address, highlighting areas for future work.

Liu, Chen-Ching [Virginia Polytechnic Inst. and St

Certified randomness using a trapped-ion quantum processor

Although quantum computers can perform a wide range of practically important tasks beyond the abilities of classical computers, realizing this potential remains a challenge. An example is to use an untrusted remote device to generate random bits that can be certified to contain a certain amount of entropy. Certified randomness has many applications but is impossible to achieve solely by classical computation. Here we demonstrate the generation of certifiably random bits using the 56-qubit Quantinuum H2-1 trapped-ion quantum computer accessed over the Internet. Our protocol leverages the classical hardness of recent random circuit sampling demonstrations: a client generates quantum ‘challenge’ circuits using a small randomness seed, sends them to an untrusted quantum server to execute and verifies the results of the server. We analyse the security of our protocol against a restricted class of realistic near-term adversaries. Using classical verification with measured combined sustained performance of 1.1 × 10 18 floating-point operations per second across multiple supercomputers, we certify 71,313 bits of entropy under this restricted adversary and additional assumptions. Our results demonstrate a step towards the practical applicability of present-day quantum computers.

computer science

Hardware Fuzzing with An Emulator

Bugs in digital logic have led to some significant security vulnerabilities. Hardware bugs are particularly troublesome since they cannot be easily patched. Additionally, if the bug is in the root of trust, all trust built upon it can be vulnerable. Traditional testing either require a deep knowledge of the system, creative attack vectors and lots of human interaction. This is not scalable as there are very few engineers that can wear the hat of a designer, a verification engineer, and a cybersecurity expert. Hardware fuzzing is a relatively new research area in dynamic hardware testing. It has proven to be an effective method for discovering bugs, unexpected behaviors, and security vulnerabilities in software. While hardware fuzzing is new to the hardware domain, it has a strong track record in software testing. Fuzzing is a testing technique that randomly mutates the input data to uncover bugs or vulnerabilities in the design. It is especially good at finding corner cases that test engineers can not envision. Another advantage over other dynamic testing techniques is that, if done well, deep knowledge of the design is not required. Additionally, fuzzing scales well. If the system is set up correctly, it can run unsupervised for weeks if necessary. In this work, we propose using hardware fuzzing to improve the input vector generation for an information flow tracking tool. To get reasonable throughput of test vectors, an emulator is targeted as the execution platform. Efficient emulator execution has some specific requirements.

42 ENGINEERING

Measuring very low radiation doses in PTFE for nuclear forensic enrichment reconstruction

Every country that has made nuclear weapons has used uranium enrichment to do so. Despite the centrality of this technology to international security, there is still no reliable physical marker of past enrichment in the open literature that can be used to perform forensic verification of historically produced weapons on gas centrifuges. We show that the extremely low radioactivity from uranium alpha emissions during enrichment leaves detectable and irreversible calorimetric signatures in the common enrichment gasket material PTFE, allowing for historical reconstruction of past enrichment activities at a sensitivity better than one weapon’s quantity of highly enriched uranium. Fast scanning calorimetry also enables the measurement of recrystallization enthalpies of sequentially microtomed slices, confirming the magnitude and the type of radiation exposure while also providing detection of tampering and a method for analyzing field samples useful for treaty verification. Furthermore, this work opens the door for common items to be turned into precise dosimeters to detect the past presence of radioactivity, nuclear materials, and related activities with high confidence.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P

Results of an In-Field Validation Exercise in Support of Wide-Area Environmental Sampling

The National Nuclear Security Administration’s (NNSA) Office of Nonproliferation and Arms Control (NA-24) is evaluating Wide-Area Environmental Sampling (WAES) as an additional safeguards verification tool for the International Atomic Energy Agency to detect undeclared nuclear activities. The NNSA is evaluating strategies for conducting a generic WAES campaign, the cost of a WAES campaign, and the effect of technological advancements that have occurred since the last major WAES review in 1999. Until now, the NNSA effort has focused on tabletop exercises (TTXs) in which high-performance computing allows for advanced modeling and simulation efforts to be applied to the WAES question. Although the modeling and simulations used in the TTXs are extremely valuable, field campaigns are still needed to validate the assumptions that underpin the models and the modeling process itself. During a 7 week period beginning in May 2023 and ending in June 2023, which included 4 weeks of active field collections, a multilaboratory team conducted its first in-field validation exercise. Prior to the in-field exercise, abbreviated TTXs were conducted to estimate the performance of all collection systems to be used during the field test. These TTXs guided the selection of materials to be released and the placement of the collection system. Based on these determinations, materials were procured to use in the field test, and an injection/release system was designed, built, and installed at the test facility. Background samples were collected during weeks one and four, and environmental collections against active releases were conducted during weeks two and three. The goals of this validation exercise included a demonstration of (1) the ability to provide controlled releases of particulates of surrogate materials, (2) the fielding and operation of collection systems (including deposition and active air collectors), and (3) the flexibility to revise equipment and campaign plans in the field. This paper presents the results and preliminary conclusions for this initial validation test. Based on these results, subsequent field campaigns are anticipated and will include the addition of other released materials.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS

Foreign Entity of Concern Requirements in the One Big Beautiful Bill Act

The One Big Beautiful Bill Act (OBBB), enacted July 4, 2025, makes billions of dollars in federal energy tax credits conditional on supply chain independence from China and other foreign entities of concern. The OBBB simultaneously creates powerful economic incentives to reshore energy supply chains to the United States and allied nations. Through such incentives, the OBBB elevates digital assurance and supply chain verification from voluntary best practices into critical capabilities for demonstrating tax credit eligibility. The OBBB uses tax credit eligibility requirements to simultaneously address national security concerns regarding foreign supply chain dependencies and incentivize domestic energy manufacturing. This brief details how organizations should operationalize these requirements through baseline compliance audits, interim documentation systems, supply chain diversification strategies, and long-term institutional integration of digital assurance capabilities that turn compliance burdens into competitive advantages

29 - ENERGY PLANNING, POLICY AND ECONOMY

Non-nuclear Component Signatures for Warhead Dismantlement Confirmation

The verification of warhead dismantlement is expected to be an important component in future arms reduction treaties. Historic approaches developed with future arms control treaty verification in mind often involve intrusive measurements, process monitoring, and/or inspector presence to provide confidence that an authentic warhead has been dismantled. This work explores the possibility of reducing the negative impacts of these invasive approaches while also delivering a method that is more likely to provide non-sensitive data that can be shared with not only other nuclear weapons states but also non-nuclear weapons states partners. This work explores a novel approach for verifying dispositioned non-nuclear weapon components, providing confidence post-dismantlement that a treaty accountable item that was dismantled was in fact a treaty-relevant nuclear weapon system as declared. This method provides an alternative to intrusive inspection processes in nuclear weapons production environments, which would require significant changes to the host’s operational behaviors. It achieves this by identifying intrinsic neutron-induced signatures of non-nuclear components to determine their authenticity and estimate the duration they were exposed within a nuclear weapons system using technologies that are already in use for other national security applications. Intrinsic radiation effects studies are already a part of the stockpile aging and surveillance evaluations. However, none of these technologies and approaches have been previously considered for verification applications of non-nuclear component disposition. In this report, we introduce modeling studies that have been used to identify the most promising candidate parts and materials with signatures that are measurable and actionable. These models have been validated with laboratory measurements of signatures induced by the exposure of candidate materials to neutrons over a range of times. Predictive modeling then demonstrates the methodology for estimating exposure times and/or limits. Laboratory measurements of authentic non-nuclear parts from a dismantled warhead demonstrate the feasibility of employing these signature measurements. And finally, a concept of operations (CONOPS) for the potential use of this methodology is presented.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P

Artificial Intelligence in Nuclear Safeguards; Evaluating Safeguards and Security Risks and Benefits for Advanced and Small Modular Reactor Deployments

Rapidly growing interest in advanced and small modular reactor (A/SMR) technologies presents challenges as well as opportunities for implementing international safeguards and security. A/SMR deployments are expected to be more numerous, more geographically dispersed, and more varied in their designs, placing new demands on the data systems and analytical tools used to support oversight (Alberti et al., 2023; Canadian Nuclear Safety Commission et al., 2024). Because of this variability, the importance and reliance on data systems for A/SMR deployments is expected to be higher than for previous reactor generations. Artificial Intelligence and Machine Learning (AI/ML) offer potential capabilities to address the high variability inherent in A/SMR technology. The beneficiaries of AI-assisted tools include facility operators, government regulators, IAEA inspectors, and A/SMR vendors. This report analyzes how AI/ML-assisted technologies can strengthen the implementation of IAEA safeguards and security measures. It also identifies AI-assisted tools to strengthen operator, facility, and regulator knowledge management practices and examines the potential risks AI/ML-based tools may introduce to IAEA safeguards and security efforts. It concludes with a set of hypothetical, standards-style requirements for AI/ML systems used in safeguards contexts, grounded in an inspector-centric view of system verification. Despite the potential benefits of AI/ML systems, understanding potential intentional and unintentional failure modes is critical for ensuring adequate protection of nuclear materials and facilities. Unique features of A/SMRs including sealed cores, remote and novel paradigms of operation, off-site reactor fabrication, novel fuel forms, and varied refueling requirements, introduce challenges for traditional safeguards technological approaches (Pensado et al., 2024; Federation of American Scientists, 2025). AI/ML systems deployed to address these challenges may introduce new risks requiring systematic evaluation rooted in both AI-specific risk frameworks, such as the NIST AI Risk Management Framework (NIST AI RMF), and established cyber risk management standards such as NIST SP 800-30 (National Institute of Standards and Technology [NIST], 2023; NIST, 2012).

97 MATHEMATICS AND COMPUTING

The Design and Evaluation of Zero Trust Architecture for Electric Vehicle Charging Infrastructure: EVs @ Scale Series on EV Charging Station Cybersecurity

Implementing a zero trust architecture can significantly bolster the security of electric vehicle (EV) charging infrastructure. EV charging infrastructure includes numerous networked interfaces, each of which can present potential vulnerabilities. When these vulnerabilities are exploited, they can compromise the entire system, leading to severe operational and security risks. Zero trust is a security model that operates on the principle of "never trust, always verify," which helps manage the attack surface and limit the scope of any potential compromises. Fundamentally, this model ensures that no entity, whether inside or outside the network, is trusted by default. The design principles of zero trust include continuous verification, strict deny-by-default access controls, and micro-segmentation. Continuous verification ensures that every request is thoroughly checked, regardless of its origin. Strict access controls enforce the principle of least privilege, allowing users and devices only the minimum necessary access to perform their functions. Micro-segmentation involves dividing the network into smaller, isolated segments to prevent lateral movement in case of a breach. In the context of EV charging infrastructure, zero trust can be implemented through various strategies. For example, multi-factor authentication (MFA) can be required for engineers to access the management interfaces and control systems of charging stations. Real-time monitoring and analysis of network traffic can help detect and respond to anomalies. Systems that do not need to communicate with each other can be micro-segmented to enhance security. All communications should adhere to predefined policies to be permitted. Additionally, encrypting communications can protect sensitive information exchanged between chargers and management systems. This paper presents a zero trust architecture specifically designed for EV charging infrastructure. Implementing zero trust not only mitigates risks but also builds a resilient infrastructure capable of withstanding and quickly recovering from cyber threats. The architecture addresses six defined security objectives. A comprehensive test plan is developed to assess the architecture against these objectives, and the results of the evaluation are reported. This approach is essential for maintaining the reliability and integrity of EV charging services in an increasingly interconnected and vulnerable digital landscape. This is the first in a planned series of papers exploring the implementation of zero trust in EV charging infrastructure. Each paper will delve into different aspects and applications of zero trust, highlighting how various work processes and requirements can lead to distinct architectural designs. These architectures will be tailored to address specific security challenges and operational needs within the EV charging ecosystem, ensuring a robust and adaptable security framework.

33 ADVANCED PROPULSION SYSTEMS