Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Authentication”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 271 records · Page 15

TACPLUS-DO-AUTH

SF-23-084 This software provides enhanced authorization and access control support to be used in tandem with the open source Terminal Access Controller Access Control System (TACACS+) software tac_plus; providing Authentication, Authorization and Auditing (AAA) capabilities for networking devices.

WEST, GABRIALA↗

AQDrop Quantum Service (AQDrop) v1.0

AQDrop is a job management system designed to streamline access to the Advanced Quantum Testbed (AQT) at NERSC (National Energy Research Scientific Computing Center). It serves as a centralized middleware layer between researchers and quantum processing hardware. Key Features: AQDrop provides a FastAPI-based server backed by PostgreSQL for job submission, queue management, and role-based access control (members, operators, and administrators). Users submit Qiskit circuits via JSON payloads, which are queued, dispatched to the QPU through the Qubic API, and returned as measurement counts. A Python client library and web dashboard round out the interface options. Primary Use: Researchers submit quantum circuit jobs from a laptop or login node; an operator client executes those jobs on the AQT's physical QPU and returns results — all coordinated through the central API. Advantages: Compared to ad-hoc or direct hardware access, AQDrop adds structured queue management, auditable job-status tracking and OAuth2 authentication — reducing scheduling conflicts and unauthorized access. Its containerized deployment also improves reproducibility and scalability. Overall, AQDrop functions as a purpose-built quantum job broker tailored to NERSC's specific hardware and institutional access requirements.

Caplinger, Evan [Lawrence Berkeley National Labora↗

Different tertiary interactions create the same important 3D features in a distinct flavivirus xrRNA

During infection by a flavivirus (FV), cells accumulate noncoding subgenomic flavivirus RNAs (sfRNAs) that interfere with several antiviral pathways. These sfRNAs are formed by structured RNA elements in the 3' untranslated region (UTR) of the viral genomic RNA, which block the progression of host cell exoribonucleases that have targeted the viral RNA. Previous work on these exoribonuclease-resistant RNAs (xrRNAs) from mosquito-borne FVs revealed a specific three-dimensional fold with a unique topology in which a ring-like structure protectively encircles the 5' end of the xrRNA. Conserved nucleotides make specific tertiary interactions that support this fold. Examination of more divergent FVs reveals differences in their 3' UTR sequences, raising the question of whether they contain xrRNAs and if so, how they fold. To answer this, we demonstrated the presence of an authentic xrRNA in the 3' UTR of the Tamana bat virus (TABV) and solved its structure by X-ray crystallography. The structure reveals conserved features from previously characterized xrRNAs, but in the TABV version these features are created through a novel set of tertiary interactions not previously seen in xrRNAs. This includes two important A–C interactions, four distinct backbone kinks, several ordered Mg 2+ ions, and a C + –G–C base triple. The discovery that the same overall architecture can be achieved by very different sequences and interactions in distantly related flaviviruses provides insight into the diversity of this type of RNA and will inform searches for undiscovered xrRNAs in viruses and beyond.

59 BASIC BIOLOGICAL SCIENCES↗

Full scale structural, mechanical and dynamical properties of HIV-1 liposomes

Enveloped viruses are enclosed by a lipid membrane inside of which are all of the components necessary for the virus life cycle; viral proteins, the viral genome and metabolites. Viral envelopes are lipid bilayers that adopt morphologies ranging from spheres to tubes. The envelope is derived from the host cell during viral replication. Thus, the composition of the bilayer depends on the complex constitution of lipids from the host-cell’s organelle(s) where assembly and/or budding of the viral particle occurs. Here, molecular dynamics (MD) simulations of authentic, asymmetric HIV-1 liposomes are used to derive a unique level of resolution of its full-scale structure, mechanics and dynamics. Analysis of the structural properties reveal the distribution of thicknesses of the bilayers over the entire liposome as well as its global fluctuations. Moreover, full-scale mechanical analyses are employed to derive the global bending rigidity of HIV-1 liposomes. Finally, dynamical properties of the lipid molecules reveal important relationships between their 3D diffusion, the location of lipid-rafts and the asymmetrical composition of the envelope. Overall, our simulations reveal complex relationships between the rich lipid composition of the HIV-1 liposome and its structural, mechanical and dynamical properties with critical consequences to different stages of HIV-1’s life cycle.

59 BASIC BIOLOGICAL SCIENCES↗

Recombinant production of a functional SARS-CoV-2 spike receptor binding domain in the green algae Chlamydomonas reinhardtii

Recombinant production of viral proteins can be used to produce vaccine antigens or reagents to identify antibodies in patient serum. Minimally, these proteins must be correctly folded and have appropriate post-translation modifications. Here we report the production of the SARS-CoV-2 spike protein Receptor Binding Domain (RBD) in the green algae Chlamydomonas . RBD fused to a fluorescent reporter protein accumulates as an intact protein when targeted for ER-Golgi retention or secreted from the cell, while a chloroplast localized version is truncated. The ER-retained RBD fusion protein was able to bind the human ACE2 receptor, the host target of SARS-CoV-2, and was specifically out-competed by mammalian cell-produced recombinant RBD, suggesting that the algae produced proteins are sufficiently post-translationally modified to act as authentic SARS-CoV-2 antigens. Because algae can be grown at large scale very inexpensively, this recombinant protein may be a low cost alternative to other expression platforms.

59 BASIC BIOLOGICAL SCIENCES↗

Cyber–Physical System Security of Distribution Systems

The Information and Communications Technology (ICT) for control and monitoring of power systems is a layer on top of the physical power system infrastructure. The cyber system and physical power system components form a tightly coupled Cyber–Physical System (CPS). Sources of vulnerabilities arise from the computing and communication systems of the cyber–power grid. Cyber intrusions targeting the power grid are serious threats to the reliability of electricity supply that is critical to society and the economy. In a typical Information Technology environment, numerous attack scenarios have shown how unauthorized users can access and manipulate protected information from a network domain. The need for cyber security has led to industry standards that power grids must meet to ensure that the monitoring, operation, and control functions are not disrupted by cyber intrusions. Cyber security technologies such as encryption and authentication have been deployed on the CPS. Intrusion or anomaly detection and mitigation tools developed for power grids are emerging. Furthermore, this survey paper provides the basic concepts of cyber vulnerabilities of distribution systems and CPS security. The important ICT subjects for distribution systems covered in this paper include Supervisory Control And Data Acquisition, Distributed Energy Resources, including renewable energy and smart meters.

97 MATHEMATICS AND COMPUTING↗

Cybersecurity for Distance Relay Protection

This project is a DOE follow-up effort on the CREDC workshop held on September 13, 2018 in Cambridge, MA to discuss cybersecurity of distance relays, which considered the benefits, vulnerabilities and risk mitigations for the use of communication systems in power system protection. The objectives of this project are to define the taxonomy of relay protection and associated communications; define use cases describing approaches to reduce the cyber-attack surface on those protective relays; and evaluate the loss of operational functional capability from changes to communication coverage. Mitigating controls will also be evaluated to understand if there are other approaches to reduce attack surfaces while maintaining communications or partial communications. Distance relays are used to protect transmission lines of approximately 10 to 300 miles in length, by detecting short circuits (i.e., faults) on the lines and then tripping circuit breakers in the substation. Such protection systems are a subset of the power system and they incorporate sensing, logic and communication functions. Protection system exposure to cyberattack could be drastically limited by disconnecting relays from all vulnerable communication systems, but this may adversely impact overall power system performance in the absence of cyberattack. This project began with a use case analysis of protection systems with communications, as summarized in this report. It continued with modeling, testing and evaluation in a miniature power system (MPS), located in the Western Area Power Administration (WAPA) Electric Power Training Center (EPTC). The project also incorporated feedback from two industry meetings held in February and September 2019. The suggested next steps account for and complement the work already underway with DOE/CESER funding: 1. Study the performance of LCD and PC vs. PUTT, which is less reliant on communication system performance and GPS timing references. The PUTT scheme could prove to be more resilient to cyberattack or communications-related disruption. It could also be more tolerant of message re-routing with SDN/SDR communication systems. On the other hand, it will be more vulnerable to false tripping during dynamic events or to loss of the voltage signal. The optimum choice of scheme may depend on the specific power system and risk assessment. This study could provide a new template for evaluation based on business functions. 2. Research and develop new methods to detect and monitor distributed physical attacks, possibly using drones, video sensors, thermal sensors, machine learning and other advanced techniques. This will help mitigate the impact of cyberattack on the protection system, and will also help mitigate the impact of wild fires. 3. Implement a scalable PKI for use in electric utility protection systems. This will encourage widespread adoption of secure authentication methods that are already available, but not widely used at present. This will help secure engineering access to the relays. 4. Investigate the use of SDN in combination with SDR to achieve better cybersecurity and electromagnetic security of the network, incorporating path variability. This would help secure both engineering access and peer-to-peer GOOSE messaging. 5. Perform additional testing, with operator evaluation of “red button” scenarios, PUTT vs. LCD, relay mis-operations, and other cyberattacks in the EPTC. This is an important advantage of testing in the EPTC rather than by computer simulation or even hardware-in-the-loop simulation; the EPTC is already dedicated to managing the situational awareness, operator response times and other human impacts. One of the project objectives was to settle on a common nomenclature for this problem space. We have concluded that the OSI layer model, supplemented by ANSI device numbers and other IEEE standards, is already well-accepted by the industry. The IEEE PSRC knowledge base provides a great deal of public information

24 POWER TRANSMISSION AND DISTRIBUTION↗

Enterprise Credentialing Service Statement of Work (SOW)

The scope of this project includes providing professional services in support of the development and deployment of an Enterprise Credentialing Service for the Department of Energy (DOE) National Nuclear Security Administration (NNSA), which will be used for issuing and managing credentials used for authentication, digital signature, and encryption functions by users, applications, and devices in a closed computing environment. The Seller shall provide subject matter expertise for the design and deployment of the technologies and processes that comprise the Enterprise Credentialing Service, which will include a public key infrastructure (PKI) and a credential management system (CMS) that issues and manages PKI-based smartcard credentials. The Enterprise Credentialing Service will support approximately 17,000 users at 15 DOE NNSA sites and laboratories located across the continental United States.

97 MATHEMATICS AND COMPUTING↗

Warhead verification concepts and technologies [Slides]

Weapons verification concepts and technologies are discussed related to Arms Control instrumentation, which is a three-part problem: measurement; certification, and authentication.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

“Experimental investigation of the governing parameters of atmospheric ice nucleation using field-collected and laboratory generated aerosol particles and its application in cloud resolving models” (Final Report)

The objective of this research project is to improve our understanding of the role of aerosol particles acting as ice-nucleating particles (INPs) which in turn define the mixed-phase and cirrus cloud radiative properties and thus climate. The focus is placed on how the physicochemical particle population properties determine the particles’ ability to initiate ice nucleation. This research project combined micro-spectroscopic particle analysis, experimental ice nucleation studies, and model sensitivity studies to advance our predictive capability of the formation of mixed-phase and cirrus clouds. These project activities have led to new ice nucleation data from laboratory generated and ambient (authentic) aerosol particles furthering process-level understanding, insights in the role of organic aerosol in ice formation, and advancements in the interpretation and parameterization of ice nucleation.

54 ENVIRONMENTAL SCIENCES↗

Tribal Renewable Energy: Bishop Paiute Tribe Youth Solar Job Training Development (Final Report)

This Project provided workshops and hands on opportunities for young tribal adults to gain education,training,and employment in the solar industry; including 1 youth to meet the eligibility requirements for the NABCEP Solar Installer Exam. 10 tribal youth, ages 16-24, attended workshops focused on learning solar fundamentals and then applied those learned skills to hands on training, installing solar on 2 tribal homes. GRID provided certificates authenticating their volunteer hours and skills learned. This program of youth training really excited the tribal leadership as well as the tribal youth. This opportunity was in alignment with the tribe’s Strategic Energy Plan, and supported tribal self-sufficiency, a path to economic development and for the youth it also represented the environmental stewardship the tribe believes in.

14 SOLAR ENERGY↗

Investigating Secondary Aerosol Processes in the Amazon through Molecular-level Characterization of Semi-Volatile Organics

In areas where biogenic emissions are oxidized in the presence of anthropogenic pollutants, it has become increasingly apparent that secondary organic aerosol (SOA) formation from biogenic volatile organic compounds (BVOCs) is substantially enhanced. The Amazon forest is the dominant source of BVOCs globally, and the forest is rapidly being converted to urban and agricultural uses. We participated in a collaborative field study located in the Amazon region around Manaus, Brazil, in 2014 (Green Ocean Amazon; GoAmazon). This study was designed to comprehensively examine how BVOC emissions (specifically, the most highly emitted non-methane hydrocarbon, isoprene, and lesser studied sesquiterpenes) and their interaction with anthropogenic pollution (i.e., nitrogen oxides, sulfur dioxide, and black carbon) alter the atmosphere’s oxidative capacity, influence secondary aerosol formation, atmospheric composition and, ultimately, affect the earth’s radiation balance and climate. We provide the first hourly, in-situ measurement of 30 sesquiterpenes and 4 diterpenes, roughly estimating that sesquiterpene oxidation contributes to 10-14% of ozone reactive loss by terpenes and at least 0.4–5% (median 1 %) of total submicron OA mass. However, this is likely a low-end estimate, as evidence for additional unaccounted sesquiterpenes and their oxidation products clearly exists. We also provide new perspectives on sulfate, NO x , and particle acidity influencing isoprene-derived SOA, comparing the central Amazon environment with Southeastern U.S.A. summer, representing clean to polluted conditions, respectively. We find that summed concentrations of isoprene-derived SOA tracers correlated with particulate sulfate spanning three orders of magnitude, suggesting that 1 μg m -3 reduction in sulfate corresponds with at least ~0.5 μg m -3 reduction in isoprene-derived SOA. We also find that SOA mass derived from isoprene oxidation in the presence of NO x is primarily comprised of aerosol sulfate bound with isoprene oxidation products (i.e. organosulfates), ~97% in the Amazon and ~55% in the Southeastern U.S. We infer under natural conditions in high isoprene emission regions, preindustrial aerosol sulfate was almost exclusively isoprene-derived organosulfates, which are traditionally thought as representative of anthropogenic influence. We further report the first field observations showing that particle acidity impacts the distribution of isoprene oxidation tracers in the gas and particle phases, providing physicochemical insight into isoprene SOA formation chemistry. Coupled with other co-located measurements by the DOE Atmospheric Radiation Measurement (ARM) team and collaborating PIs at our measurement site (called T3), on the G1 aircraft, and at additional field sites (T0, T1, T2) this data set has been used to understand emission, oxidation, and particle formation pathways at the molecular level, to elucidate how these pathways change when influenced by anthropogenic sources, and to evaluate their importance for the atmospheric budget of aerosols and the earth’s radiation balance on regional scales. Recommendations: Further constraint of the role of sesquiterpenes on ozone (O 3 ) reactivity and SOA formation is limited by the availability of authentic standards and synthesized compounds of sesquiterpenes and their oxidation products. Future research efforts should focus on making such standards available via custom synthesis to allow for accurate quantification and focused oxidation experiments that will fully elucidate the chemistry of these compounds in the atmosphere. Further, reductions in aerosol sulfate (via SO 2 emissions control) continues to be one of the most effective methods to reduce SOA formation from isoprene, but the concerted role of ammonia (NH 3 ) gas emissions from (agricultural) industry and other sources requires more investigation to better understand the role of aerosol acidity in SOA formation and potential controls. As GoAmazon particles can be more acidic compared to areas with greater anthropogenic NH 3 emissions, this promotes relatively greater organosulfate (OS) formation from isoprene even in the presence of NO x . Because OS and inorganic sulfate differ in water uptake properties, this implies preindustrial aerosol sulfate (albeit less abundant) may have been less reflective than current earth system models assume. Further research should investigate the radiative impacts of organic vs inorganic sulfate in aerosols to improve model representation. Finally, future work (currently underway) should include constraint of the contributions of monoterpene (C 10 H 16 ) BVOCs and biomass burning VOCs as precursors to SOA formation in the region as well as their impacts on radiative forcing in the climate system.

54 ENVIRONMENTAL SCIENCES↗

Additively Manufactured Tamper Evident Container (TEC)

Researchers at Los Alamos National Laboratory have developed a tamper evident container (TEC) to secure a broad variety of items from adversarial disclosure and espionage accidents. The new technology uses additive-manufacturing (AM) techniques for the concurrent creation of a container and arbitrarily complex-shaped three-dimensional tamper-sensitive features within its walls that authenticate the package. Analog and encrypted digital boards safely stored inside the TEC permanently record the complete security history of the protected items. Los Alamos is seeking commercial partners interested in further development and engineering prototype work.

42 ENGINEERING↗

Recommendations for Distributed Energy Resource Access Control

Cybersecurity for internet - connected Distributed Energy Resources (DER) is essential for the safe and reliable operation of the US power system. Many facets of DER cybersecurity are currently being investigated within different standards development organizations, research communities, and industry committees to address this critical need. This report covers DER access control guidance compiled by the Access Controls Subgroup of the SunSpec/Sandia DER Cybersecurity Workgroup. The goal of the group was to create a consensus - based technical framework to minimize the risk of unauthorized access to DER systems. The subgroup set out to define a strict control environment where users are authorized to access DER monitoring and control features through three steps: (a) user is identified using a proof-of-identity, (b) the user is authenticated by a managed database, (c) and the user is authorized for a specific level of access. DER access control also provides accountability and nonrepudiation within the power system control environment that can be used for forensic analysis and attribution in the event of a cyber-attack. This paper covers foundational requirements for a DER access control environment as well as offering a collection of possible policy, model, and mechanism implementation approaches for IEEE 1547-mandated communication protocols.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Recommendations for Data-in-Transit Requirements for Securing DER Communications

With the adoption of Distributed Energy Resource (DER) interoperability standards, common communication protocols are now being deployed between power system operators and DER devices. In 2018, a revision to the US interconnection and interoperability standard, Institute of Electrical and Electronics Engineers (IEEE) Std. 1547, required DER equipment to have an IEEE 2030.5, IEEE 1815, or SunSpec Modbus communication exchange interface. This change supports the future transition to secure connection and exchange of information between the DER equipment and implementing parties, such as grid operators. Adoption of standardized communication protocols and associated information models is a critical step toward interoperability between power system operators and DER, such as photovoltaic (PV) and energy storage systems. However, security requirements for these standardized communication protocols are not comprehensive, resulting in non-standard and vendor-specific implementation that may leave DER equipment susceptible to cyberattacks. This paper examines the data-in-flight security requirements for standardized DER communication protocols, per IEEE 1547-2018 revision, as it relates to device authentication, key management, and encryption. The state of the art for these security features is also explored, addressing their impact on communication and performance of low-cost single board computers, which are typical of DER devices. In conclusion, a recommendation is provided to adopt a common set of communication requirements, which are intended to achieve interoperability and implement data security over DER network pathways, while ensuring reliable, secure, and real-time information delivery.

42 ENGINEERING↗

Verification of Data-Driven Models of Physical Phenomena using Interpretable Approximation

Machine-learned models, specifically neural networks, are increasingly used as “closures” or “constitutive models” in engineering simulators to represent fine-scale physical phenomena that are too computationally expensive to resolve explicitly. However, these neural net models of unresolved physical phenomena tend to fail unpredictably and are therefore not used in mission-critical simulations. In this report, we describe new methods to authenticate them, i.e., to determine the (physical) information content of their training datasets, qualify the scenarios where they may be used and to verify that the neural net, as trained, adhere to physics theory. We demonstrate these methods with neural net closure of turbulent phenomena used in Reynolds Averaged Navier-Stokes equations. We show the types of turbulent physics extant in our training datasets, and, using a test flow of an impinging jet, identify the exact locations where the neural network would be extrapolating i.e., where it would be used outside the feature-space where it was trained. Using Generalized Linear Mixed Models, we also generate explanations of the neural net (à la Local Interpretable Model agnostic Explanations) at prototypes placed in the training data and compare them with approximate analytical models from turbulence theory. Finally, we verify our findings by reproducing them using two different methods.

42 ENGINEERING↗

Evaluation of Data Catalog Software for Hanford Site Environmental Datasets

Environmental information and data underpin achievement of the U.S. Department of Energy (DOE) Office of Environmental Management (EM) mission at the Hanford Site. The Hanford Environmental Data Management (HEDM) Program is the DOE Richland Operations Office (RL) approach to develop and implement a formal program for managing environmental data and the associated records, materials, and systems at the Hanford Site. The current project, contract, organization, and contractor-specific efforts at managing environmental data sets are insufficient to provide orderly, long-term, site-wide access. A vital element to be created within the HEDM program plan is a catalog of data sources, called the Hanford Environmental Information and Data Index (HEIDI), that will enable long-term access and retrievability for the multiple independent sources of data that might otherwise be difficult to discover. This report compares leading open source and commercial data catalog platforms using criteria to assess the functionality needed to develop the HEIDI catalog of Hanford data sources that connects and exchanges data with established Hanford Local Area Network (HLAN) enterprise information technology systems. Proprietary platforms evaluated included ArcGIS Enterprise Sites, Junar, OpenDataSoft, and Socrata, and non-proprietary platforms included Energy Data eXchange (EDX), Comprehensive Knowledge Archive Network (CKAN), and DKAN (a Drupal-based open data portal based on CKAN). Capabilities supporting data discoverability, retrieval, and archival, as well as metadata standard requirements and integration into the HLAN were rated as either failing to meet requirements (F), meeting requirements (M), or exceeding requirements by delivering additional desired features (E). The lowest rating for any capability area was assigned as the overall rating for the platform. These findings enable DOE-RL and the contractors implementing the HEDM plan to focus on candidate tools likely to meet the requirements for implementing HEIDI. All of the platforms receiving an overall rating of ‘F’ were unable to be deployed on Hanford infrastructure or within dedicated cloud resources. A propriety software-as-a-service (SaaS) model of delivering a data catalog (e.g., found in software such as Junar and OpenDataSoft) favors consistency across customers at the expense of customization and configurable roles that are needed for Hanford work. Hosting data on a shared commercial platform places limits on dataset size (maximum of 240 Mb for OpenDataSoft), a significant limitation for HEIDI implementation. EDX, a government data catalog based on CKAN, received the ‘F’ rating due to an inability to incorporate authentication from HLAN into the system. Among platforms rated ‘M’ or ‘E’, only the Socrata platform had a SaaS delivery model. In contrast to other SaaS platforms, Socrata provided custom roles and gateways that allow local datasets to be incorporated into an online catalog. Socrata also complies with the Federal Risk and Authorization Management Program, a significant benefit for cloud-based management of Hanford data. The other platforms rated ‘M’ or ‘E’, ArcGIS Enterprise Sites, CKAN, and DKAN, provide fully self-hosted options, allowing for greater control and flexibility with the HEIDI catalog. These widely used tools have supportive communities of practice, extensive customization options, and demonstrated deployments that provide evidence that they can meet requirements, often deliver additional desired features, and work well with federal government systems. Completely customized alternatives built on a collection of applications were not evaluated because achieving similar performance to CKAN or DKAN requires substantial resources, especially in the absence of the active communities that have grown to support these tools. ArcGIS Enterprise Sites, Socrata, CKAN, and DKAN were evaluated as strong candidates for successful implementation with HEIDI.

54 ENVIRONMENTAL SCIENCES↗

Cybersecurity Certification Recommendations for Interconnected Grid Edge Devices and Inverter Based Resources

Escalating deployment of PV and grid-edge devices on the distribution grid has increased the sustainability and efficiency of the electric grid. However, the increasing number of distributed energy resources (DERs) deployed creates a heightened cyber-physical interdependency on the distribution grid and thus creates more vectors for cyber-attacks to exploit through information and communication technology (ICT) systems and networks. For example, control signal packets can be modified, intercepted, or corrupted due to vulnerabilities in communication protocols used by microgrid controllers and grid edge devices for power control. Therefore, to mitigate and prevent cyber-attacks on grid edge devices and the inverter-based resources connected to the distribution grid, the U.S. Department of Solar Energy Technologies Office (SETO) awarded funding to the National Renewable Energy Laboratory and Sandia National Laboratory (SNL) to research, develop, and harmonize cybersecurity standards for Photovoltaic (PV) systems and for other kinds of DERs. To help develop a standard for DER cybersecurity, NREL established certification recommendations and test cases, in consensus with the solar industry and UL, for ensuring intrinsic design security for DERs. These recommendations were developed to bolster the cybersecure functionalities such as TLS, MAC, CRL, session resumption/renegotiation, and password, system, and service security management within the DER devices. The proposed test cases verify authentication, authorization, confidentiality, and data integrity for data and communications of DERs that use Transmission Control Protocol/Internet Protocol (TCP/IP). They were also developed to protect DER communications from eavesdropping, replay, man-in-the-middle, denial of service (DoS), spoofing through security certificates, least-privilege violation, and brute-force credentials. This report, which has been validated and reviewed by UL, expands upon those test cases to provide DER cybersecurity certification recommendations which increase DER resiliency and help to mitigate cyber-attacks. UL's collaboration with NREL and approval of this document will accelerate the adoption of a UL standard for DER cybersecurity.

24 POWER TRANSMISSION AND DISTRIBUTION↗