Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Cybersecurity Resilience”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 253 records · Page 14

Pillars of Innovation Across Southeast Idaho & the Interstate-15 Corridor

Since 1949, Idaho National Laboratory (INL) has been home to developing civilian and defense nuclear reactor technologies and managing spent nuclear fuel. Today, INL is the nation’s nuclear energy research laboratory, sustaining the safe and efficient operation of existing reactors, powering science in space, and breaking ground on the future fleet of advanced nuclear reactors. INL is only one of many rising technology resources in the region, however. Along the Interstate 15 (I-15) corridor, technology and cybersecurity industries and intellectual assets are rapidly expanding. Creating an innovation hub in this region would unite capabilities to solve current and future challenges in nuclear reactor sustainment and expanded deployment, integrated fuel cycle solutions, integrated energy systems, advanced materials and manufacturing for extreme environments, and secure and resilient cyber-physical systems.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Countering Weapons of Mass Destruction (CWMD) Zero Trust Framework: CWMD Zero Trust Principles Model

The research focuses on the critical need for enhanced cybersecurity within the Countering Weapons of Mass Destruction (CWMD) Office, specifically targeting Chemical, Biological, Radiological, and Nuclear devices. Traditional perimeter-based security models are insufficient against modern cyber threats, prompting a shift toward Zero Trust principles (ZTP) that emphasize continuous verification and stringent security for all devices. Federal directives mandate the adoption of Zero Trust (ZT) across agencies, supported by guidelines from National Institute of Standards and Technology (NIST), U.S. Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA), U.S. Department of Defense (DoD) and National Security Agency (NSA). The research involved mapping ZT guidance from these agencies to develop tailored CWMD ZTP. The study identified gaps and areas for improvement, including clear transitional guidance from traditional to ZT architectures and the focus on explicit cross cutting capabilities. Design improvements are recommended to ensure increased comprehensive protection and resilience against sophisticated cyber threats for Chemical, Biological, Radiological, and Nuclear (CBRN) devices. Collaborative efforts among federal agencies are essential for the successful deployment of an optimized ZT guidance.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Envisioning the Future Renewable and Resilient Energy Grids—A Power Grid Revolution Enabled by Renewables, Energy Storage, and Energy Electronics

Today’s power grids are facing tremendous challenges because of the ever-increasing power demand, system complexity, infrastructure cost, knowledge base, and policy and regulatory issues to achieve supply–demand power balance and resiliency with respect to more frequent extreme weather events and cyberattacks. It is particularly challenging when the transition toward 100% intermittent renewable energy sources is considered. Many countries are calling for building up more transmission and distribution lines to increase power delivery capacities. This article is an attempt to answer two urgent questions: Is more transmission and distribution infrastructure really needed to meet the increasing power demand? What kind of future grid infrastructure should we envision and build? This article attempts to answer these questions and proposes the concept of community-centric asynchronous renewable and resilient energy grids. By clearly differentiating the concepts of grid resilience and reliability, the importance of building resilient power electronics’ devices and robust system-level control algorithms to achieve 100% renewable energy integrated resilient grids is presented. To identify the shortcomings and propose advancements, power electronics’ technologies are categorized using the proposed concepts of natural source frequencies (NSf), energy storage, direct energy conversion/control and fault protection (DeCaFp), and high-efficiency energy consumption and buffering (heECaB) technology. The ability of networked microgrids to greatly reduce power outages and power system restoration time is demonstrated by leveraging robust decentralized and centralized control algorithms, identified through a comprehensive literature review. Future research areas are proposed to further enhance grid stability, controllability, cybersecurity, and protection against faults in the presence of 100% renewable sources by leveraging the advanced capabilities of NSf, DeCaFp, and heECaB devices and system-level control algorithms.

14 SOLAR ENERGY↗

Digital Assurance Checklist for Homeowners and Installers

This document provides a comprehensive Digital Assurance Checklist for securing behind-the-meter energy assets, focusing on both installers and homeowners. As distributed energy resources (DERs) such as solar PV and battery storage become integral to residential energy systems, cybersecurity emerges as a critical component of reliability and safety. The guide outlines actionable steps for installers during pre-installation, commissioning, and post-installation phases, emphasizing practices like network segmentation, credential management, firmware validation, and homeowner education. For homeowners, the document introduces a tiered approach to cyber hygiene—from essential measures like strong Wi-Fi credentials and automatic updates to advanced strategies such as network segmentation, DNS filtering, and intrusion detection. By adopting these practices, stakeholders can mitigate cyber risks, safeguard energy infrastructure, and ensure resilient, secure operation of DER systems. Additional resources and references to industry standards are included to support implementation.

99 - GENERAL AND MISCELLANEOUS↗

Digital Assurance Checklist for Homeowners and Installers

This document provides a comprehensive Digital Assurance Checklist for securing behind-the-meter energy assets, focusing on both installers and homeowners. As distributed energy resources (DERs) such as solar PV and battery storage become integral to residential energy systems, cybersecurity emerges as a critical component of reliability and safety. The guide outlines actionable steps for installers during pre-installation, commissioning, and post-installation phases, emphasizing practices like network segmentation, credential management, firmware validation, and homeowner education. For homeowners, the document introduces a tiered approach to cyber hygiene—from essential measures like strong Wi-Fi credentials and automatic updates to advanced strategies such as network segmentation, DNS filtering, and intrusion detection. By adopting these practices, stakeholders can mitigate cyber risks, safeguard energy infrastructure, and ensure resilient, secure operation of DER systems. Additional resources and references to industry standards are included to support implementation.

99 - GENERAL AND MISCELLANEOUS↗

City Decision Analysis Resources and Tools

The City Decision Analysis at Any Scale Workshop was held February 17-18, 2021. This brochure was created to provide participants with a collection of tools and resources that support planning and implementation of clean energy goals for communities and businesses.

ACES↗

Smart Inverters, Dumb Risk: Taking Control of IBR Security in the Digital Age

This presentation addresses the security challenges posed by Inverter-Based Resources (IBRs) in the modern energy landscape. The presentation highlights the vulnerabilities and risks associated with IBRs, including the potential for cyber-attacks, the impact of insecure defaults, and the systemic risks posed by supply chain dependencies. Key topics covered include: 1) The increasing digital transformation in energy systems and the associated security risks. 2) Specific vulnerabilities in IBRs, including weak passwords, hardcoded credentials, and insecure web application interfaces. 3) The implications of persistent connectivity and the strategic risks posed by foreign-manufactured components. 4) The role of regulatory frameworks, such as NERC CIP, in addressing these challenges and the limitations of current oversight. 5) Practical solutions for mitigating risks, including secure design practices, vendor risk assessments, and the importance of strong passwords and role-based access control. The presentation underscores the necessity of a comprehensive, system-of-systems approach to securing IBRs, emphasizing the need for collaboration across various stakeholders, including operators, developers, and regulators, to ensure the resilience and security of the energy grid.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

New Jersey Transit Grid Distributed Generation Program. Cybersecurity Design Assurance Assessment

Superstorm Sandy caused a major disruption to passenger-rail and other commuter systems throughout New York and New Jersey. To address this issue, New Jersey Transit (NJT) established the NJ TRANSITGRID project, an effort designed to power bus, ferry, and limited passenger-rail service during natural or man-made disasters. Given the importance of these transportation systems, NJT partnered with Sandia National Laboratories (Sandia) to assess the cyber-resilience of the information systems that monitor and control the electrical systems within the microgrid. The Sandia “tabletop” assessment is based on the most recent 20% design packages. From this assessment, the Sandia team identified several security areas that were undefined or did not implement industry best practices. Finally, the Sandia team presented possible follow-on assessment activities and recommended investigating multiple hardening technologies. Addressing these findings and adding state-of-the-art detection and mitigation technologies will help ensure the NJ TRANSITGRID is built with more comprehensive cyber-resilience features.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Advanced Transmission Technologies – GETs and HPCs Session 1: ATT Foundations and Dynamic Line Ratings (DLRs)

The INL TADA GETs Cohort Session 1, held on November 4, 2025, convened experts to address the integration of advanced transmission technologies, including Grid-Enhancing Technologies (GETs) and High Performance Conductors (HPCs), with a focus on digital assurance challenges. The session highlighted the growing importance of cybersecurity, supply chain transparency, reliability, and business risk management in deploying GETs, especially Dynamic Line Ratings (DLRs). Participants examined how expanded attack surfaces, limited vendor pools, and new regulatory requirements—such as FERC Orders 881, 2023, and 1920—are influencing utilities and technology providers. The workshop underscored the need for cyber-informed engineering, secure-by-design principles, and practical risk management strategies, while fostering collaboration and knowledge sharing among industry peers. Technical discussions covered the evolution from static to dynamic line ratings, complexities of cloud-based architectures, and NERC CIP compliance challenges. The session concluded with a collaborative risk exercise and a preview of future workshops on advanced power flow control and transmission topology optimization, reinforcing the cohort’s commitment to advancing digital assurance in the energy sector.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

A Review of Technologies that can Provide a 'Root of Trust' for Operational Technologies

The supply chain attack pathway is being increasingly used by adversaries to bypass security controls and gain unauthorized access to sensitive networks and equipment (e.g., Critical Digital Assets). Cyber-attacks targeting supply chain generally aim to compromise the environments, products, or services of vendors and suppliers to inject, add, or substitute authentic software and hardware with malicious elements. These malicious elements are deemed to be authentic as they arise from the vendor or supplier (i.e., the supply chain). This research aims at providing a survey of technologies that have the potential to reduce exposure of sensitive networks and equipment to these attacks, thereby improving tamper resistance. The recent advances in the performance and capabilities of these technologies in recent years has increased their potential applications to reduce or mitigate exposure of the supply chain attack pathway. The focus being on providing an analysis of the benefits and disadvantages of smart cards, secure tokens, and elements to provide root of trust. This analysis provides evidence that these roots of trust can increase the technical capability of equipment and networks to authenticate changes to software and configuration thereby increasing resilience to some supply chain attacks, such as those related to logistics and ICT channels, but not development environment attacks.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Artificial Intelligence for Energy Systems Cybersecurity

Artificial intelligence and machine learning systems have the potential to influence the future design and implementation of cybersecurity systems for the power grid. These systems may enhance the overall operation of the power system by leveraging and making sense of massive amounts of data. However, we must also understand how AI/ML will need to be protected from cyber threat actors. We discuss the existing insights the NREL team has developed using AI/ML systems and then present resources including ESIF and the Cyber Energy Emulation Platform that can be used to generate training data and insights. We end by offering suggestions on priority research paths for AI in cybersecurity.

artificial intelligence↗

Development of Integrated Safety and Security Models for Comprehensive Reliability and Resiliency Evaluation

The security of the electric grid and supporting energy systems is crucial to national security. One of the complexities in analyzing the security of energy systems is the safety consequences that may result from accidents. For energy systems, the goal is to ensure that they operate as intended and that any consequences are mitigated or prevented. The integration of safety and security is paramount to protecting these systems from attacks and ensuring that large consequences are prevented. This report describes an integrated safety and security methodology to evaluate cybersecurity events that can lead to large consequences. This novel approach first describes how Systems-Theoretic Process Analysis (STPA) provides a digital causal analysis for Bayesian Networks (BNs). The use of STPA causal analysis provides a systematic approach to constructing BNs that adequately model cyber scenarios that result in consequences. When combined with the technical principles described in Risk-Informed Management of Enterprise Systems (RIMES), a comprehensive risk-informed cybersecurity analysis results that allows decision-makers to prioritize systems that most impact risk.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Poster: Responsible Adoption of Artificial Intelligence (AI) in Electric Grid Operations

The rapid integration of artificial intelligence (AI) in the utility transmission and distribution (T&D) sector is revolutionizing traditional grid management practices. As utilities encounter complexities from evolving consumer behaviors and energy integration, AI becomes a critical solution for enhancing grid monitoring, fault detection, and operational optimization. However, increased reliance on interconnected technologies introduces significant cybersecurity risks, regulatory compliance challenges, and human factors concerns. This study proposes a strategic, responsible and consequence-driven approach to AI implementation, examining the dual nature of AI adoption by highlighting its transformative benefits for utilities and associated risks. It provides utilities with a framework for evaluating AI integration, enabling them to navigate challenges and capitalize on opportunities to achieve greater reliability, efficiency, and resilience in an increasingly complex energy landscape.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Smart Building Technology Training Modules for Academic and Professional Education

Smart building technologies are a new suite of resources that improve building energy efficiency and resilience, reduce carbon emissions, and provide load flexibility to the grid. However, in both college curricula and building professionals’ continuing education, there is a lack of systematic instruction on smart building technologies–topics that include smart building concepts, key components, smart building controls, “Internet of Things” (IoT) devices, and how to integrate multiple energy systems including distributed energy resources (DER). This major gap in smart building education prevents stakeholders from understanding and adopting smart building technologies in building design and operations. Slipstream leads a DOE-funded project developing a semester-long smart building curriculum for college students and adapting the contents into 16 training videos for building professionals and the general public. The education and training cover the drivers and benefits of smart building technologies, key building energy systems, the latest sensor technologies and IoT devices, and focus on topics related to smart building controls (i.e., energy management information systems, smart building control platforms, cybersecurity, grid-interactive-efficient buildings (GEBs), smart building control methods, and occupant-centric control. This paper describes the project approach, provides outlines of the training materials, and identifies lessons learned in creating the content. We also suggest ways to scale the instruction of smart building concepts to empower the workforce to accelerate the adoption of smart building technologies in the real world.

99 GENERAL AND MISCELLANEOUS↗

Securing Grid Communications Infrastructure: Addressing Gaps Beyond NERC CIP Facility Perimeters

The North American electric grid relies on a complex communications infrastructure that extends beyond facility perimeters traditionally covered by NERC Critical Infrastructure Protection (CIP) standards. While CIP requirements have significantly strengthened cybersecurity within Electronic Security Perimeters, many operational communications—such as those between control centers, substations, and third-party networks—fall outside current regulatory scope. As grid modernization introduces new technologies and connectivity models, these external pathways present evolving security challenges. This brief explores the nature of these challenges, including emerging attack vectors and supply chain considerations, and highlights how ongoing grid transformation increases exposure to sophisticated threats. It outlines practical strategies and policy options to complement existing standards, such as expanding secure communications practices, enhancing supply chain transparency, and fostering collaboration among federal, state, and industry stakeholders. Near-term actions like encryption, authentication, and contractual safeguards can help reduce risk while longer-term frameworks are developed to ensure resilient and secure grid operations.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Situational Awareness of Grid Anomalies (SAGA) for Visual Analytics—Near-Real-Time Cyber-Physical Resiliency Through Machine Learning

The Situational Awareness of Grid Anomalies (SAGA) project built upon foundational power system tools developed at the National Renewable Energy Laboratory (NREL) integrated with an ever-increasing set of Gridmetrics data extracted from the cable television (CATV) broadband network infrastructure while assimilating other time-series geospatial data and information, such as weather and cyber-physical phenomena, to demonstrate a disruptive technology for power system data analytics relying on existing infrastructure. Three research thrusts supported (1) visual analytics, (2) cyber-physical power system simulation, and (3) anomaly detection. SAGA created technology that leverages, couples, and fortifies two vastly different realms - power and broadband - to increase the resiliency of the power grid in the face of increasing cyberattacks and operational challenges related to integrating DERs. The exploration of potential synergies of broadband-enabled grids resulted in identifying a mutually beneficial symbiosis that can increase the resiliency of both power and broadband services. Broadband networks perform better with reliable power and are good at providing real-time measurements that identify where the grid is under attack, is failing, or is weak. Likewise, sensor-starved distribution grids perform better and can be more reliable when their operation is buttressed with observations of broadband-detected anomalies. Future research can explore broadband's contribution to continuing to improve grid resiliency, reliability, and cost-effective operation.

24 POWER TRANSMISSION AND DISTRIBUTION↗

CIE Analysis Process for Engineered Systems

"CIE Analysis Process for Engineered Systems" outlines a comprehensive methodology for integrating Cyber-Informed Engineering (CIE) principles into both new and existing engineered systems. Sponsored by the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (DOE CESER), the process aims to achieve cyber-informed decisions by producing functional security requirements for new systems and retrofitting existing systems to mitigate digital risks. The document details a step-by-step approach, including mission and function definition, digital asset awareness, consequence analysis, and mitigation analysis. It emphasizes the importance of documenting mechanical, electrical, programmable, and network components to protect system functions and provides examples and considerations for each step. The ultimate goal is to ensure that engineered systems remain resilient against cyber threats, maintaining safety, performance, and reliability.

42 - ENGINEERING↗

Signal Decomposition for Intrusion Detection in Reliability Assessment in Cyber Resilience (Summary Report)

The complexity of assuring cyber resilience for physical process interactions in connected systems such as energy grids increases dramatically as the coupling between processes becomes more direct and responsive. An example of this growing complexity is provided by Integrated Energy Systems (IES), in which various processes such as nuclear heat generation and commodity production are being directly coupled for increased responsiveness to highly variable signals such as market pricing or electricity demand. As such, the potential attack surface of the coupled processes is larger than the two processes independently. Securing these complex systems requires two-fold monitoring: cybersecure monitoring for potential malicious incursion, and physics monitoring for system tampering. Physics monitoring includes analyzing the behavior of the signals within the system for anomalous behavior. This analysis has been shown to be insufficient if approached by only data-driven machine learning and artificial intelligence (MLAI) techniques or only low-level model comparison. Previous efforts at Purdue University suggested combining high-fidelity models with MLAI algorithms as a basis for a software tool for detecting anomalies in physical processes. This work built on that suggestion, developing an advanced library for signal decomposition and analysis using both MLAI and high-fidelity physics algorithms for greatly improved anomaly detection, especially false data injection. This software can be used as part of a secure imbedded intelligence (SEI) system designed under Consequence-driven Cyber-informed Engineering (CCE) for complex coupled systems. This library established a foundation for online and posteriori analysis of digital signals for the purpose of detecting potential malicious tampering in digital signals representing physical processes. Demonstrations carried out throughout the development highlight the effective use of characterization algorithms to detect signal perturbations, particularly triangle attack-style perturbations, in three wide-ranging applications: seismic monitoring, nuclear thermal hydraulics system simulation, and custom manufacturing.

97 MATHEMATICS AND COMPUTING↗