Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Integrating Cybersecurity”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 271 records · Page 15

Formally Verified ZTA Requirements for OT/ICS Environments with Isabelle/HOL: Preprint

The clean energy transformation led to the integration of distributed energy resources on a top of the grid, and so a substantial increase in the complexity of power grids infrastructure and the underlying operational technology environment. Operational technology environments are becoming a system of systems, integrating heterogeneous devices which are software/hardware intensive, have ever increasing demands to exploit advances in commodity of software/hardware infrastructures, and this for good reasons - improving energy systems requirements such as cybersecurity and resilience. In such a setting, system requirements at different levels mix, thus undesirable outcomes will surely happen. The use of formal methods will remove ambiguity, increase automation and provide high levels of assurance and reliability. In this paper, we contribute a methodology and a framework for the system level verification of zero trust architecture requirements in operational technology environments. We define a formal specification for the core functionalities of operational technology environments, the corresponding invariants, and security proofs. Of particular note is our modular approach for the formal verification of asynchronous interactions in operational technology environments. The formal specification and the proofs have been mechanized using the interactive theorem proving environment Isabelle/HOL.

formal methods↗

Advanced Transmission Technologies – GETs and HPCs Session 1: ATT Foundations and Dynamic Line Ratings (DLRs)

The INL TADA GETs Cohort Session 1, held on November 4, 2025, convened experts to address the integration of advanced transmission technologies, including Grid-Enhancing Technologies (GETs) and High Performance Conductors (HPCs), with a focus on digital assurance challenges. The session highlighted the growing importance of cybersecurity, supply chain transparency, reliability, and business risk management in deploying GETs, especially Dynamic Line Ratings (DLRs). Participants examined how expanded attack surfaces, limited vendor pools, and new regulatory requirements—such as FERC Orders 881, 2023, and 1920—are influencing utilities and technology providers. The workshop underscored the need for cyber-informed engineering, secure-by-design principles, and practical risk management strategies, while fostering collaboration and knowledge sharing among industry peers. Technical discussions covered the evolution from static to dynamic line ratings, complexities of cloud-based architectures, and NERC CIP compliance challenges. The session concluded with a collaborative risk exercise and a preview of future workshops on advanced power flow control and transmission topology optimization, reinforcing the cohort’s commitment to advancing digital assurance in the energy sector.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

A Survey on Cybersecurity Challenges, Detection, and Mitigation Techniques for the Smart Grid

The world is transitioning from the conventional grid to the smart grid at a rapid pace. Innovation always comes with some flaws; such is the case with a smart grid. One of the major challenges in the smart grid is to protect it from potential cyberattacks. There are millions of sensors continuously sending and receiving data packets over the network, so managing such a gigantic network is the biggest challenge. Any cyberattack can damage the key elements, confidentiality, integrity, and availability of the smart grid. The overall smart grid network is comprised of customers accessing the network, communication network of the smart devices and sensors, and the people managing the network (decision makers); all three of these levels are vulnerable to cyberattacks. In this survey, we explore various threats and vulnerabilities that can affect the key elements of cybersecurity in the smart grid network and then present the security measures to avert those threats and vulnerabilities at three different levels. In addition to that, we suggest techniques to minimize the chances of cyberattack at all three levels.

Tufail, Shahid↗

Charting the unknown: A dive into the world of standards mapping

When you hear standards mapping what do you think about? For the Secure Software Central (SSC) project this means comparing our process to the National Institute of Standards and Technology’s (NIST) security control catalog. So how is it done? The project completed this summer can be broken down into three simple phases. Phase one consists of mapping the SSC process to the NIST’s security control catalog. While phase two entails mapping mitigations from a threat profile to NIST. Lastly phase three requires the creation of a knowledge base allowing for the reuse of controls across numerous projects This project presented a few different challenges: locating the correct control within the NIST catalog while correctly matching the proposed mitigations from the SSC team, accurately leveling the mitigation to the security level of the system, creating a toolbox to showcase a dataset of mitigations and standards to be used in current and future projects. each challenge allowed for opportunities in growth and understanding of how security controls can map to a governing set of standards. These standards maps are a crucial element to support the insights provided by the SSC team and allow the client to have confidence in the work being completed. My internship has allowed me to set and achieve many goals such as coming to understand that the field of cybersecurity truly is the right place for me. I have also learned that it’s ok to be wrong if you learn something from it. For significant accomplishments I have helped integrate standards mapping into the fabric of SSC. The field experience that I have gained such as interacting with the SSC team along with other senior staff and building a good rapport are crucial skills to. This time at PNNL has been an irreplaceable experience.

42 ENGINEERING↗

Threat Hunt Guide for BESS Environments

The rapid digitalization of the electric grid - driven by the integration of inverter-based resources (IBRs), battery energy storage systems (BESS), and advanced grid control platforms - has significantly enhanced grid efficiency, visibility, and flexibility. However, this evolution also introduces new cybersecurity risks, particularly through supply chain dependencies and operational blind spots at the grid edge. To address these challenges, Idaho National Laboratory (INL), through the Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) Rapid Risk initiative, conducted a series of rapid risk assessment engagements with energy organizations across the United States. Drawing on lessons learned from these engagements, INL developed the following threat hunting guide for asset owners and operators (AOOs) to enhance their cybersecurity visibility within BESS and IBR systems. The guide demonstrates how to use passive network monitoring to baseline device behavior, detect adversarial activity, and investigate anomalies without disrupting operations. By implementing these practices, energy sector stakeholders can improve coordination between cybersecurity and operations teams and strengthen the resilience of distributed energy resources (DERs) within the modern power grid. Prior to implementing any network monitoring, packet capture, or threat hunting activity described in this guide, AOOs are strongly advised to review applicable governance frameworks, legal requirements, and organizational policies. This guide is intended for informational and educational purposes only. It does not replace compliance with any federal, state, or local cybersecurity mandates or industry standards. Implementation of described configurations, technologies, or analytic workflows is performed at the discretion and responsibility of the asset owner and operator.

25 - ENERGY STORAGE↗

Pillars of Innovation Across Southeast Idaho & the Interstate-15 Corridor

Since 1949, Idaho National Laboratory (INL) has been home to developing civilian and defense nuclear reactor technologies and managing spent nuclear fuel. Today, INL is the nation’s nuclear energy research laboratory, sustaining the safe and efficient operation of existing reactors, powering science in space, and breaking ground on the future fleet of advanced nuclear reactors. INL is only one of many rising technology resources in the region, however. Along the Interstate 15 (I-15) corridor, technology and cybersecurity industries and intellectual assets are rapidly expanding. Creating an innovation hub in this region would unite capabilities to solve current and future challenges in nuclear reactor sustainment and expanded deployment, integrated fuel cycle solutions, integrated energy systems, advanced materials and manufacturing for extreme environments, and secure and resilient cyber-physical systems.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Identification and Testing of Electric Vehicle Fast Charger Cybersecurity Mitigations

Fast-charging infrastructure for electric vehicles (EVs) is needed to enable and achieve the national goals of transitioning the vehicle fleet toward more electrification. Idaho National Laboratory, Oak Ridge National Laboratory, and the National Renewable Energy Laboratory (NREL) have jointly worked to identify, evaluate, and mitigate potential cyber-related consequences associated with fast charger systems. NREL contributed by considering cyberattack scenarios and consequences associated with integrating distributed energy resources (DERs) at fast-charging stations. The dynamic nature of fast-charger load profiles would encourage site operators to incorporate solar for energy cost reduction and energy storage for peak demand cost management at future charging facilities with multiple fast chargers at a site. These energy resources would be monitored and coordinated via a site energy management controller with data exchange between devices and local power metering infrastructure; thus, networking between devices and the design of the system becomes important in the overall cybersecurity posture. In addition, component vendors and system operators might have remote interfaces to any of these systems. It is therefore important to understand the breadth of the cyberattack surface and potential strategies to mitigate impacts. This project has focused on components and protocols expected to be found within a local charging site that includes multiple chargers and DER resources. Our methods and results are summarized in this final report.

42 ENGINEERING↗

Micro Baselines for Operational Technology Environments

Critical infrastructure stakeholders need to baseline their networks to understand expected communications. Top-down approaches to baselining rely on observables that are generally available but lack properties upon which traditional statistical tools depend. We propose to construct micro-baselines: signatures within operational networks based on observables associated with specific events. Such observables are informed by precursor analysis reports of historical cyber attacks on operational environments developed by Cybersecurity for Operational Technology Environments (CyOTE). Baseline measurements depend upon context beyond the cyber domain. An energy plant's baseline running in the summer may statistically differ from a similar facility in a colder region. Domain knowledge must be integrated to apply general micro-baselining algorithms to a facility-specific context. Therefore, we propose to explore the feasibility of transferring micro baselining algorithms across different facilities. Facilities that implement the same processes in different geographic locations will be compared relative to observable measurements used in micro-baselining for comparable events. One evaluation approach would condition or augment dynamic observables measured within a facility network testbed with additional observables derived from geographic context or infrastructure dependencies such as those provided by the All-Hazards Analysis tool.

97 MATHEMATICS AND COMPUTING↗

Advanced Grid Operational Technology Edge-Level Threat Detection

This report presents a deployable solution to improve the cybersecurity situational awareness of the legacy SCADA system infrastructure in power grids. The main goal of this project is to provide system owners and operators a highly trusted, intelligent alarm system and comprehensive situational awareness of ongoing or potential cybersecurity threats on the grid network. The key contributions of this project include: (1) the development of software, the Intrusion Detection Visualizer for the Operational Technology Network (IViz-OT), to visualize and locate intrusions on the grid network; (2) testing the signature-based Hybrid Intrusion Detection for Energy Systems (HIDES) for different types of intrusions; (3) the integration of HIDES and IViz-OT into the visualization dashboard; and (4) real-time testing using a hardware-in-the-loop test bed.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cognitive IoT and Edge Computing for Intrusion Detection with Federated TinyML

Internet of Things (IoT) and Edge Computing (EC) are rapidly becoming an integral part of the modern society. By 2030, there is estimated to be over 40 billion active and connected IoT devices [1]. This rapid progress also comes with a significant implication on cybersecurity. Back-end infrastructure and systems have a much broader attack than they did previously due to vulnerable IoT/EC devices being connected to wireless networks. This expanding attack surface is a growing concern because IoT/EC are increasingly being used in critical systems such as power grids, health care, and smart homes. To effectively address a problem of this scale, cognitive cyber methods—which can autonomously detect and react to cyber attacks as they develop—are needed. To address this, we bring Artificial Intelligence (AI) and Machine Learning (ML) to IoT/EC devices, using tinyML to monitor voluminous IoT data against cyber threats, and using Federated Learning (FL) to share local detection knowledge across the system while preserving privacy. We propose a novel three-layer architecture: (1) an IoT layer for tinyML-based inference, (2) an edge layer for ML model training, and (3) a cloud layer for FL operations. Using the publicly available 11-class N-BaIoT dataset [2], we demonstrate that this architecture mitigates resource constraints at the IoT layer while improving detection accuracy over standard two-layer designs. An outlier-resistant scaler, feature reduction, and quantization enable the tinyML model to maintain detection accuracy with a reduced model size. Additionally, federated learning that only utilizes the intersection (across heterogenous devices) of the reduced feature set achieves superior detection accuracy compared to locally trained models.

Li, Mingyan [ORNL] (ORCID:0009000569532640)↗

Cybersecurity Considerations and Research Pathways for Grid-Interactive Efficient Buildings

Federal facilities serve critical missions and functions that require safe, reliable, and efficient operations. Digitization of several facility operations has increased the cost-effectiveness of energy usage and optimization of energy system performance. As the building controls landscape shifts to become more connected and smarter, building operators now face unique opportunities and challenges to adopt smart enabled devices that can lower energy usage while also optimizing building system performance. The grid-interactive efficient buildings (GEB) initiative aims to make buildings cleaner and more flexible through these smart devices. Smart enabled devices allow greater connectivity and control through remote operations and provide crucial data for analytics and increased efficiency. GEBs enable demand flexibility that has the potential to reduce electrical costs and transform the grid edge where buildings connect to power grids. This operation of interconnected systems, if not designed with cybersecurity practices, causes security gaps and introduces potential attack paths by adversarial and non-adversarial entities leading to disruption of operations.

building controls↗

Science Uses Deployment Operations-Advanced Wireless: Exploring Open Radio Access Network Technologies for Energy Science

Open Radio Access Network is emerging as a solution to the increasing demand for more flexible, cost-effective, and advanced mobile network infrastructures. This evolution is driven by advancements in wireless technologies and the growing complexity of deploying and managing these networks. O-RAN represents a significant shift in wireless technology, building upon the 3rd Generation Partnership Project framework to foster openness, flexibility, and interoperability. By decoupling hardware and software components, Open Radio Access Network enables a multi-vendor ecosystem that encourages innovation and diverse solutions. Open Radio Access Network's potential extends beyond traditional wireless applications, with growing interest in its role in advancing energy systems, particularly in the context of smart grids, microgrids, and the integration of renewable energy sources. While the role of open-wireless technologies in driving energy transformation is increasingly recognized, further exploration is needed. Vendors and utilities are investigating how Open Radio Access Network technologies can optimize energy use cases and improve the performance of 5G and beyond applications. This report outlines efforts under the Science Uses Deployment Operations Advance Wireless project, a collaboration between the National Laboratory of the Rockies' Cybersecurity Research Center, Argonne National Laboratory, Lawrence Berkeley National Laboratory, and the Department of Energy's Energy Science Network research and operations staff. The focus of this project is on due diligence, through testing and evaluation, preparing for the deployment of advanced wireless infrastructure for scientific use cases, with an emphasis on Open Radio Access Network technology, its components, integrations, and its ability to support vertical stack application across the energy sector. Additionally, the report highlights the value cases for utilities, underscoring how adopting open wireless standards can accelerate the evolution of energy systems, foster innovation, and improve the integration of critical energy technologies.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Decarbonized Electric Grid: Defining, Measuring, and Integrating Decarbonization into Electricity Sector Policy and Planning

Traditionally, electric grid planning seeks to maintain safe, reliable, efficient, and affordable service for current and future customers. As policies, expectations of the energy system, and the threat landscape evolve, additional objectives for power system planners are emerging, including decarbonization, resilience, and equity. Renewable and clean energy goals, especially in the context of deep decarbonization strategies, are changing the mix of resources on the electric grid and prompting new considerations for grid architecture. The increased frequency and severity of extreme weather events over the last two decades, coupled with cybersecurity concerns, have elevated resilience as a key system need. More recently, there has been greater focus on equity and energy justice in grid planning to ensure that disadvantaged communities are not adversely affected by grid modernization and have equal access to its benefits. In response, new thinking around multi-objective decision planning is exploring improvements in grid planning processes to better integrate approaches to meet decarbonization, resilience, and equity objectives. To provide a foundation for this work, a series of white papers was produced to summarize these emerging objectives.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Resilient Electric Grid: Defining, Measuring, and Integrating Resilience into Electricity Sector Policy and Planning

Traditionally, electric grid planning seeks to maintain safe, reliable, efficient, and affordable service for current and future customers. As policies, expectations of the energy system, and the threat landscape evolve, additional objectives for power system planners are emerging, including decarbonization, resilience, and equity. Renewable and clean energy goals, especially in the context of deep decarbonization strategies, are changing the mix of resources on the electric grid and prompting new considerations for grid architecture. The increased frequency and severity of extreme weather events over the last two decades, coupled with cybersecurity concerns, have elevated resilience as a key system need. More recently, there has been greater focus on equity and energy justice in grid planning to ensure that disadvantaged communities are not adversely affected by grid modernization and have equal access to its benefits. In response, new thinking around multi-objective decision planning is exploring improvements in grid planning processes to better integrate approaches to meet decarbonization, resilience, and equity objectives. To provide a foundation for this work, a series of white papers was produced to summarize these emerging objectives.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Equitable Electric Grid: Defining, Measuring, and Integrating Equity into Electricity Sector Policy and Planning

Traditionally, electric grid planning seeks to maintain safe, reliable, efficient, and affordable service for current and future customers. As policies, expectations of the energy system, and the threat landscape evolve, additional objectives for power system planners are emerging, including decarbonization, resilience, and equity. Renewable and clean energy goals, especially in the context of deep decarbonization strategies, are changing the mix of resources on the electric grid and prompting new considerations for grid architecture. The increased frequency and severity of extreme weather events over the last two decades, coupled with cybersecurity concerns, have elevated resilience as a key system need. More recently, there has been greater focus on equity and energy justice in grid planning to ensure that disadvantaged communities are not adversely affected by grid modernization and have equal access to its benefits. In response, new thinking around multi-objective decision planning is exploring improvements in grid planning processes to better integrate approaches to meet decarbonization, resilience, and equity objectives. To provide a foundation for this work, a series of white papers was produced to summarize these emerging objectives.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Ambassador Project (Final Report)

SEL, in collaboration with its partners, performed research, development and demonstration of a trust, data, and resource management software layer enabling multiple software applications from different suppliers to operate in a Software Defined Infrastructure. The Energy sector has successfully deployed Software Defined Networking (SDN) technology and is rapidly scaling deployments. One major benefit of SDN is the abstracted centralized nature of the orchestration and management of the network. This architecture enables end users to deploy new technology and capabilities as quickly as they perform firmware upgrades to field devices. When an end user needs to roll trucks to install new equipment, they simply deploy new software to run on top of this SD-Infrastructure. This has attracted many software companies to develop value added features and introduce new capabilities, which is all good for the industry but has also introduced new challenges, including how to manage trust between these software applications, how to manage the data integrity and access, and how to manage access to the network resources each of these software applications are demanding. Completion of this project developed and demonstrated a safe and reliable resource scheduler and cybersecurity trust management communication platform allowing multiple software applications to operate in a SD-Infrastructure resulting in the commercialization of a software eco-system and architecture that maintains interoperability, cybersecurity, and reliability where the end user can safely scale out their software to leverage the powerful benefits of SDN.

97 MATHEMATICS AND COMPUTING↗

Advanced Research on Integrated Energy Systems (ARIES) Cyber Range Overview and Threat-to-Consequence Demonstration

This presentation was presented at the Aggregation and Grid Security Workshop - held on June 17-18, 2025, at NREL in Golden, Colorado. The goal of the two-day workshop was to address the critical cybersecurity challenges for the future electric grid. The threat-to-consequence demonstration showcases NREL's capability to model, simulate, test, and evaluate cyberattacks targeting energy systems that coincide with natural hazards, as well as the ramifications for the energy grid as a whole.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Blockchain Smart Contract Reference Framework and Program Logic Architecture for Transactive Energy Systems

This paper proposes a reference framework for a transactive energy market based on blockchain. The framework was designed based on the engineering requirements of a distribution-scale market; including participant needs, expected market transactions, and the cybersecurity constructs required to support a fair, secure and efficient market operation. It leverages the existing blockchain primitives to provide clear value propositions to the transactive market, including identity management (access control), data security (integrity), resiliency (decentralization, scalability and performance). The validity of the proposed framework is demonstrated using a real-time 5-min double-auction market. The results highlight its benefits while providing strong validation of applicability to blockchain within transactive energy systems.

Gourisetti, Sri Nikhil Gupta↗