Search NASA⌕ Search

SEARCH · Search NASA

Results for “trusted node”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

Extending quantum key distribution through proxy re-encryption

Modern quantum key distribution (QKD) network designs are based on sending photons from one node to another and require free-space or dedicated fiber optic cables between nodes. The purpose of this is to co-generate secret key material on both sides of the quantum channel. In addition to this quantum link, there are several insecure classical channels that allow QKD algorithms to exchange book-keeping information and send symmetrically encrypted data. The attenuation of photons transmitted through fiber becomes too high to practically generate key material over fiber at distances of more than 100 km. Free-space transmission through the atmosphere or the vacuum of space can reduce attenuation, but at the cost of system complexity and sensitivity to other impairments, such as weather. To extend the effective range of QKD networks, we present a method that combines QKD algorithms with post-quantum, homomorphic key-switching to allow multiple parties to effectively share secret key material over longer distances through semi-trusted relay nodes. We define how such a system should work for arbitrary network topologies and provide proofs that our scheme is both correct and secure. We assess the feasibility of this solution by building and evaluating two implementations based on lattice-based cryptography: learning with errors.

97 MATHEMATICS AND COMPUTING↗

Secure boot, trusted boot and remote attestation for ARM TrustZone-based IoT Nodes

With the extensive application of IoT techniques, IoT devices have become ubiquitous in daily lives. Meanwhile, attacks against IoT devices have emerged to compromise IoT devices by tampering with system pre-installed programs or injecting new malware. To mitigate these attacks, integrity enforcement of IoT systems has been proposed. The integrity of an IoT device system includes load-time integrity and runtime integrity. In this paper, we design an IoT system based on ARM TrustZone to enforce the system integrity. First, we establish the root of trust and propose a hybrid booting approach consisting of both secure boot and trusted boot to enforce the system load-time integrity. Second, we investigate a paging-based process integrity measurement method to measure the NW processes and conduct remote attestation based on the measurement results ensuring the NW runtime process integrity. We implement an IoT prototype system on a NXP i.MX6Q SABRE SD development board to assess its feasibility. Finally, real-world experiment results demonstrate that our prototype introduces negligible performance overhead to the original system.

97 MATHEMATICS AND COMPUTING↗

Distributed Detection of Malicious Attacks on Consensus Algorithms with Applications in Power Networks

Consensus-based distributed algorithms are well suited for coordination among agents in a cyber-physical system. These distributed schemes, however, suffer from their vulnerability to cyber attacks that are aimed at manipulating data and control ow. In this article, we present a novel distributed method for detecting the presence of such intrusions for a distributed multi-agent system following ratio consensus. We employ a Max-Min protocol to develop low cost, easy to implement detection strategies where each participating node detects the intrusion independently, eliminating the need for a trusted certifying agent in the network. The effectiveness of the detection method is demonstrated by numerical simulations on a 1000 node network to demonstrate the efficacy and simplicity of implementation.

27 ARPA - Advanced Research Projects Agency-Energy↗

Reproducibility of fixed-node diffusion Monte Carlo across diverse community codes: The case of water–methane dimer

Fixed-node diffusion quantum Monte Carlo (FN-DMC) is a widely trusted many-body method for solving the Schrödinger equation, known for its reliable predictions of material and molecular properties. Furthermore, its excellent scalability with system complexity and near-perfect utilization of computational power make FN-DMC ideally positioned to leverage new advances in computing to address increasingly complex scientific problems. Even though the method is widely used as a computational gold standard, reproducibility across the numerous FN-DMC code implementations has yet to be demonstrated. This difficulty stems from the diverse array of DMC algorithms and trial wave functions, compounded by the method’s inherent stochastic nature. Here, this study represents a community-wide effort to assess the reproducibility of the method, affirming that yes, FN-DMC is reproducible (when handled with care). Using the water–methane dimer as the canonical test case, we compare results from eleven different FN-DMC codes and show that the approximations to treat the non-locality of pseudopotentials are the primary source of the discrepancies between them. In particular, we demonstrate that, for the same choice of determinantal component in the trial wave function, reliable and reproducible predictions can be achieved by employing the T-move, the determinant locality approximation, or the determinant T-move schemes, while the older locality approximation leads to considerable variability in results. These findings demonstrate that, with appropriate choices of algorithmic details, fixed-node DMC is reproducible across diverse community codes—highlighting the maturity and robustness of the method as a tool for open and reliable computational science.

Della Pia, Flaviano [Univ. of Cambridge (United Ki↗

A Distributed Trust Model Simulator for Energy Grid of Things Distributed Energy Resource Management System

The evolution of networks into more distributed, self-reliant nodes has mitigated single-point failures that plagued traditional centralized networks. Applied to power grids, distributed systems can increase the integrity and availability of grid services while also offering a power management solution. However, while distributed networks provide scalability, security, and sustainability compared to centralized networks, their distributed nature makes them harder for anomaly detection and prevention. Incorporating a Distributed Trust Model (DTM) System into an Energy Grid of Things Distributed Energy Resource Management System (EGOT DERMS) allows grid participants to be characterized and their communication to be analyzed for possible attacks. A Trust Model simulator is needed to evaluate and improve the DTM System.Trustworthiness is calculated using a Trust Model. While many trust models exist, most only consider 2-3 matrices to evaluate trust. The TM proposed in this thesis uses a Metric Vector of Trust (MVoT) monitoring 17 parameters when assessing trust. Moreover, unlike standard trust models, the proposed trust model establishes a method to test the trust between various actors within the network and probe the trust model itself. Using a Trust Model Simulator, MVoT calaculations, initial values, and parameters are fine-tuned to achieve high-confidence message classifications and minimize false positives. The DTM System and Trust Mode Simulation Suite allow for distributed trust evaluation with a real-time classification of EGOT DERMS actors, providing additional security for distributed systems.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

pnnl/UUDEX

UUDEX describes a communications architecture and protocol suite that allows organizations to exchange data and information. It does this by defining relations between a set of client nodes that share data via a set of server nodes. The primary focus of UUDEX is to facilitate communications between control centers, operations centers, and other trusted organization.

Welsh, Jeff↗

Newton trust-region methods with primary variable switching for simulating high temperature multiphase porous media flow

Coupling multiphase flow with energy transport due to high temperature heat sources introduces significant new challenges since boiling and condensation processes can lead to dry-out conditions with subsequent re-wetting. The transition between two-phase and single-phase behavior can require changes to the primary dependent variables adding discontinuities as well as extending constitutive nonlinear relations to extreme physical conditions. Practical simulations of large-scale engineered domains lead to Jacobian systems with a very large number of unknowns that must be solved efficiently using iterative methods in parallel on high-performance computers. Performance assessment of potential nuclear repositories, carbon sequestration sites and geothermal reservoirs can require numerous Monte-Carlo simulations to explore uncertainty in material properties, boundary conditions, and failure scenarios. Due to the numerical challenges, standard NR iteration may not converge over the range of required simulations and require more sophisticated optimization method like trust-region. In this study, we use the open-source simulator PFLOTRAN for the important practical problem of the safety assessment of future nuclear waste repositories in the U.S. DOE geologic disposal safety assessment Framework. The simulator applies the PETSc parallel framework and a backward Euler, finite volume discretization. We demonstrate failure of the conventional NR method and the success of trust-region modifications to Newton’s method for a series of test problems of increasing complexity. Trust-region methods essentially modify the Newton step size and direction under some circumstances where the standard NR iteration can cause the solution to diverge or oscillate. Furthermore, we show how the Newton Trust-Region method can be adapted for Primary Variable Switching (PVS) when the multiphase state changes due to boiling or condensation. The simulations with high-temperature heat sources which led to extreme nonlinear processes with many state changes in the domain did not converge with NR, but they do complete successfully with the trust-region methods modified for PVS. This implementation effectively decreased weeks of simulation time needing manual adjustments to complete a simulation down to a day. Finally, we show the strong scalability of the methods on a single node and multiple nodes in an HPC cluster.

54 ENVIRONMENTAL SCIENCES↗

Emulation and Adversarial Analysis of EV Charging Networks

In the effort of decarbonization and evolution of the modern electrical grid, electric vehicles (EVs) play a key part to transform the grid. However, due to the rapid adoption of EVs and the demand of the charging infrastructure required to power said EVs, risk of a cyber-attack may impose serious consequences. There is a need to analyze and protect the charging ecosystem infrastructure from cyber threats before it reaches wide-scale deployment. In an effort to secure vehicle to grid (V2G) communications, standardization is necessary for continued reliable system operation. The protocol ISO 15118 outlines controls and practices that should be implemented for secure vehicle to grid (V2G) communications. The standard is gaining momentum for American markets as the demand for EV infrastructure grows. The adoption of ISO 15118 in American markets poses several challenges: the deployment of a public key infrastructure (PKI) as outlined within the standard, interoperability of charging different EVs with chargers from different manufactures using the PKI, and scaling the ecosystem to meet the demand while managing risks. This project was created to understand potential cyber and scaling challenges of PKI for EV infrastructure through utilizing a series of emulated components mapping to what exists in the EV ecosystem today, and the components of the PKI that are under development. The key nodes within the emulation that are under development are: electric vehicle (EV), electric vehicle supply equipment (EVSE), charge network operator (CNO), certificate authority (CA), and online certificate status protocol (OCSP) that must all interact using secure and trusted communications. With these emulated components and utilizing orchestration methods to rapidly deploy and scale the components, the ability to analyze risks of the ecosystem and address gaps before the PKI ecosystem is fully deployed to production should yield a more robust and mature production charging infrastructure. Our approach will use a modular architecture of virtual machines within an orchestration platform and will target scales of 100s, 1000s, and 10,000s of entities interacting. The core research questions trying to be answered with this scope of work are: what are the impacts of a rogue CA, what are the risks of certificate revocation list (CRL) management, what is the value of OCSP stapling, what components are vulnerable to DOS attacks, and what test effective payloads may impact the components.

charging ecosystem↗

Resilient information and inference networks under mixed-trust sensing

With ubiquitous digitization, sensing, and computational intelligence deployed in increasingly more and broader domains, including critical infrastructure, potentially misleading and destabilizing effects of multimodal anomalies and adversarial behavior are growing in importance. Here, we develop randomized and reinforcement learning-based strategies for strategically recruiting and utilizing deployed (and, thus, vulnerable and potentially faulty and/or compromised) nodes from information and inference networks, while defending against adversaries that attempt to misguide assessments of inferred variables. Recognizing that, besides communication and other costs, sampling from any observable node can either provide true data or dangerously expose our inference to misinformation (without being easily distinguishable what actually happens), the proposed strategies proceed by progressively recruiting nodes and cautiously scaling their information contribution based on assumed, or, in our reinforcement learning approach, intelligently weighed trustworthiness, with the learning approach also considering network-wide, threat-inclusive risk/value tradeoffs. While avoiding the hardware, communication, analytical and computational burden of explicit redundancy, the proposed defensive schemes enable on-the-fly assessments of underlying processes, and system-wide situational awareness with demonstrable resilience against adversarial activities.

97 - MATHEMATICS AND COMPUTING↗

Linear and Nonlinear Solvers for Simulating Multiphase Flow within Large-Scale Engineered Subsurface Systems

Simulation of multiphase flow in the subsurface is well-known to be computationally challenging. While there have been many studies that have explored approaches to overcoming these challenges, they often utilize relatively simple case studies. In this paper, we focus on the unique numerical challenges posed by modeling large-scale engineered subsurface systems, characterized by discrete features embedded in a heterogeneous natural subsurface setting. The man-made features such as shafts, tunnels, and barriers often cause multiple challenges in modeling the domain for multiphase porous media flow. This flow scenario can have a wide range of applications such as nuclear waste repositories, enhanced recovery of a petroleum reservoir, geothermal engineering, and carbon sequestration. An example of these severe numerical challenges is the case of performance assessment (PA) for Waste Isolation Pilot Plant (WIPP), the only operating deep geological repository in the US, which simulates extreme material properties of bedded salt rock formation and extreme contrast due to open excavation next to the formation. The models have extremes not only of permeability and porosity but also of the constitutive models needed for multiphase flow; additionally, they have process models like salt creep closure reducing porosity over time, fracturing in clay and anhydrite interbeds of the bedded salt, gas generation from the waste materials, and unintentional human borehole intrusions in some scenarios. Numerical simulations require the solution of coupled systems of nonlinear PDEs; in our work, we use the open-source simulator PFLOTRAN which is based on Finite Volume discretization. The solution of the nonlinear equations requires use of the Newton-Raphson iteration at each time step, which entails the solution of the linearized Jacobian system at each iteration. The effects of all the processes (i.e., large number of unknowns, highly nonlinear constitutive relations, large contrasts in material properties in short distances) lead to an ill-conditioned Jacobian matrix that severely challenges traditional linear solver, i.e., stabilized biconjugate gradient with block Jacobi incomplete LU preconditioner (BCGS-ILU) leading to non-convergence for traditional Newton-Raphson nonlinear solver causing unacceptably long computation time for each model. This paper presents linear solvers such as constrained pressure residual (CPR) two-stage preconditioner with alternate-block-factorization (ABF) and quasi- implicit pressure and explicit saturation (QIMPES) decouplers and flexible generalized residual solver (FGMRES). The new general-purpose nonlinear solver, Newton trust-region dogleg Cauchy (NTRDC), is also introduced to resolve extreme nonlinearities in the models. We demonstrate the effectiveness of each method relative to the default BCGS-Newton solver. The two best cases had nearly 50 times speed-up and achieved completion of a simulation in 14 hours that never completed due to non-convergence with the default solver. We also investigate the strong scalability of each method and discuss some of the deficiencies found for Block Jacobi preconditioner using parallel domain decomposition, and node packing effects of modern processor architecture.

Preconditioner, Nonlinear, Porous media, Multiphas↗

Blockchain-Enabled Secure Device-to-Device Communication in Software-Defined Networking

The Internet of Things (IoT) continues to increase the demand for seamless communication among IoT devices. The rapid growth of IoT devices has led to an exponential increase in device-to-device (D2D) communication within the Software-Defined Networking (SDN), though it enables a flexible archi-tecture for managing network resources. However, traditional security models face challenges (e.g., Security, privacy, and trust) in addressing the dynamic and decentralized nature of these communications. Despite of these challenges, this paper proposes a novel approach that leverages blockchain technology to enhance the security, privacy, and trustworthiness of D2D communication within an SDN environment. The proposed approach integrates blockchain nodes in sDN components to establish a decentralized ledger for transparent and verifiable records. Smart contracts enforce authentication rules to ensure that only authenticated devices can access the network and engage in transactions securely. It also automates the security policies to ensure temper resistance execution using the cryptographic mechanism for data integrity and authentic communication. The Implementation of the proposed algorithms validates the resilience of the proposed approach against cyberattacks. Overall, the proposed approach enables efficient and secure D2D communication for resilient SDN infrastructure in IoT ecosystems.

Das, Debashis↗

Zapiary: Creating Visibility in IOT Networks

Zigbee and Z-Wave are the main networking protocols used by low-power Internet of Things (IOT) devices. These protocols use low frequencies. Mesh architecture, and unique address formats that make them not compatible with traditional network traffic tools like IX-Discovery Tools. Zapiary is a software that takes CSV files with Zigbee and Z-Wave traffic and generates Structured Threat Information eXpression (STIX) JSON bundles illustrating the communication within IOT networks. The bundles can then be viewed within Structured Threat Intelligence Graph (STIG) or used with AI/ML models to provide deeper visibility into nodes that make up the network and the ability to trend the mesh network over time.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Novel Authentication Management for the Data Security of Smart Grid

Bidirectional wireless communication is employed in various smart grid components such as smart meters and control and monitoring applications where security is vital. The Trusted Third Party (TTP) and wireless connectivity between the smart meter and the third party in the key management-based encryption techniques for the smart grid are expected to be totally trustworthy and dependable. In a wired/wireless medium, however, a man-in-the-middle may seek to disrupt, monitor and manipulate the network, or simply execute a replay attack, revealing its vulnerability. Recognizing this, this study presents a novel authentication management (model) comprised of two layer security schema. The first layer implements an efficient novel encryption method for secure data exchange between meters and control center with the help of two partially trusted simple servers (constitutes the TTP). In this setting, one server handles the data encryption between the meter and control center/central database, and the other server administers the random sequence of data transmission. The second layer monitors and verifies exchanged data packets among smart meters. It detects abnormal packets from suspicious sources. To implement this node-to-node authentication, One class support vector machine algorithm is proposed which takes advantages of the location information as well as the data transmission history (node identification, packet size, and data transmission frequency). This schema secures data communication, and imposes a comprehensive privacy throughout the system without considerably extending the complexity of the conventional key management scheme.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Analysis of Neural Networks as Random Dynamical Systems

In this report we present our findings and outcomes of the NNRDS (analysis of Neural Networks as Random Dynamical Systems) project. The work is largely motivated by the analogy of a large class of neural networks (NNs) with a discretized ordinary differential equation (ODE) schemes. Namely, residual NNs, or ResNets, can be viewed as a discretization of neural ODEs (NODEs) where the NN depth plays the role of the time evolution. We employ several legacy tools from ODE theory, such as stiffness, nonlocality, autonomicity, to enable regularization of ResNets thus improving their generalization capabilities. Furthermore, armed with NN analysis tools borrowed from the ODE theory, we are able to efficiently augment NN predictions with uncertainty overcoming wellknown dimensionality challenges and adding a degree of trust towards NN predictions. Finally, we have developed a Python library QUiNN (Quantification of Uncertainties in Neural Networks) that incorporates improved-architecture ResNets, besides classical feed-forward NNs, and contains wrappers to PyTorch NN models enabling several major classes of uncertainty quantification methods for NNs. Besides synthetic problems, we demonstrate the methods on datasets from climate modeling and materials science.

97 MATHEMATICS AND COMPUTING↗

Oak Ridge National Laboratory Pilot Demonstration of an Attestation and Anomaly Detection Framework using Distributed Ledger Technology for Power Grid Infrastructure

This report summarizes the design and pilot demonstration of a framework called Grid Guard that was created to provide increased data and device trustworthiness to electric grid devices by leveraging distributed ledger technology (DLT), specifically blockchain. Grid Guard contains a combination of core cryptographic methods such as the secure hash algorithm (SHA), and asymmetric cryptography, private permissioned blockchain, baselining configuration data, consensus algorithm (Raft) and the Hyperledger Fabric (HLF) framework. The system implements a low energy, fast, and robust enhancement to system trustworthiness within and across electric grid systems such as substations, control centers and metering infrastructures. Blockchain is a distributed database structured that provides a practically unalterable (immutable) timeline of stored transactions. By relying on hashing and the Raft consensus algorithm, if an entity tries to illegitimately alter a record at one instance of the database the other ledger nodes are not altered. They work to cross-reference each other and easily locate any incorrectly added data and remove it. The bulk raw data is stored in an off-chain storage (outside of the blockchain ledger) and a hash of this baseline data is stored in the Blockchain ledger via hashing windows of time-series and configuration data, after aggregation and filtering. The bulk off-chain data repository is then considered to be trust-anchored using the hashes stored in the blockchain. To secure the electric grid testbed devices and data, device configuration baselines were compared to those baselines that had been previously stored in the ledger. Statistical baselines for device configurations, network communication patterns, and high-speed sensor data are calculated and then stored off-chain and hashes stored in the ledger. Measurements such as three-phase voltage and current, frequency, breaker status, protection scheme settings, network configuration settings (and other device configuration artifacts) and network traffic features (packet interarrival times) are compared every minute or other selected time windows. During phase 1 of the Grid Guard DLT project different DLT technologies were studies, and an assessment was performed on DLT technology vulnerabilities, uses, and key characteristics. DLT consensus protocols were studies (e.g., RAFT, named after Reliable, Replicated, Redundant, And Fault-Tolerant). Also, cryptography, public, private and permissioned or permissionless systems were assessed. Grid Guard implements a permissioned private DLT. Consensus algorithm selection and choice of DLT implementation depended heavily on the use-case. For this use-case, parameters were selected to measure performance and existing tools for assessment. Benchmarking was performed theoretically and practically. During phase 2 hashed transactions/blocks were inserted into the ledger every second. During phase 2 of the Grid Guard DLT project, a prototype framework was developed and demonstrated for attestation of critical substation devices and data using precision timing systems that use PTP and IRIG-B protocols) on a testbed of operational devices that emulated a distribution substation, control center, and power metering infrastructure using real Operational Technology (OT). The testbed includes OT devices such as protective relays, human machine interfaces (HMI), and power meters. To determine when to collect and compare system and network baselines, an initial examination of an anomaly detection capability to identify malicious manipulation of data streams was conducted. The resulting anomaly detection was demonstrated in a set of experiments and leveraged to trigger device artifact attestation checks. Attestation checks occur against device configuration baselines when compared with the immutable blockchain-stored baselines, which provided a cryptographically supported means by which to store baselines. The electrical substation-grid testbed was created to test the Grid Guard framework. The testbed emulates the operations of a portion of a power grid and SCADA systems as closely as possible. The testbed integrates real protocols, mainly IEC 61850 standard protocols, such as the Sampled Value (SV) and the GOOSE protocols. The testbed also supports DNP3 and other layer 2 and layer 3 protocols such as Telnet, SSH, SFTP/FTP and other proprietary protocols needed to connect to industrial control system equipment. The testbed emulates real power conditions using the OpalRT hardware-in-the-loop (HIL) device which can create fault situations that cannot be easily tested on real systems. The electrical substation-grid testbed was created using real measurement, communication, and protection devices that electrical utilities commonly use.

24 POWER TRANSMISSION AND DISTRIBUTION↗