Engineering PapersSearch

Engineering topics

Sanghvi, Anuj

Publications and source records attributed to Sanghvi, Anuj.

Electric Vehicle Supply Equipment Security Solutions

The EVs@Scale cybersecurity pillar deep dive focuses on the three main tasks that NREL has in the consortium: (1) Analysis of EV charging mobile applications, (2) Cybersecurity risk assessments of EVSE through DER-CF, and (3) PKI for EVSE.

ADVANCED PROPULSION SYSTEMS,MATHEMATICS AND COMPUT

The Cybersecurity Value-at-Risk Framework: Informing Cybersecurity Decisions

The Cybersecurity Value-at-Risk Framework is a tool that can be used by hydropower plant manager to make more educated cybersecurity investments. Users can take a self guided assessment allowing the tools to generate risk, impact and cybersecurity scores and be given risk-based recommendations to enhance decision-making.

CVF

Cyber100 Compass [SWR 23-64]

Cyber100 Compass ("Compass") is a unique risk assessment framework that will enable grid system planners to understand and mitigate cybersecurity risk for grids transitioning to high levels of renewable generation, including 100%. The idea for Compass was developed by NREL based on past work on high-renewable grids and a series of discussions with DOE. Compass is part of Cyber100, a portfolio of proposed research activities that would greatly expand understanding of cybersecurity for high-renewable grids. Compass is a desktop application designed with a user-friendly interface. The tool gathers information from users, conducts probabilistic backend calculations, and outputs a series of visualizations to help users understand and analyze their cybersecurity risks based on the unique features of their future grid. Compass will take as inputs the values for different conditions and produce a risk score of the resulting grid. By trying different configurations, system planners can compare the resultant risks against their own risk tolerance and decide which system-of-system controls to implement as they transition toward a 100% renewable grid.

Martin, Maurice

Assessment and Coordination of EVSE Cybersecurity Standards

Cybersecurity certification programs for Electric Vehicle Supply Equipment (EVSE) are fragmented due to no single certification covering all aspects of the device and additionally the existence of multiple programs and under different levels of regulation. These devices are also confronted by the intricate assembly of product software, firmware, and hardware. Devices contain both logical and physical interfaces. These multifaceted devices have vulnerabilities at many levels and interconnect with other potentially vulnerable systems including the electric vehicle, the cloud where data and payment information are stored, and the electric grid and electric grid equipment including utilities. Of the EVSE certification programs that are found, none are directly for the cybersecurity of EVSE. Many standards are for safety, specifically battery safety, some are cybersecurity standards for other types of equipment and can be modeled for EVSE. In specific, ISA/IEC 62443 is found to be significantly in line with EVSE security needs and will be used in future testing to certify EVSE and help guide the project to demonstrate where gaps exist, where strengths lie in the standard and how this can be used to lead the certification efforts in harmonizing EVSE cybersecurity standards. In addition, there are multiple efforts that are currently seeking to build EVSE standards or revise existing standards to address gaps. This effort is seeking to establish a cybersecurity program for EVSE that will inform customers and help increase the level of security across products and state EVSE procurements to achieve consistency across different jurisdictions.

33 ADVANCED PROPULSION SYSTEMS