Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Cybersecurity Resilience”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

303 records · Page 17

Grid Energy Storage: Supply Chain Deep Dive Assessment

The report “America’s Strategy to Secure the Supply Chain for a Robust Clean Energy Transition” lays out the challenges and opportunities faced by the United States in the energy supply chain as well as the Federal Government plans to address these challenges and opportunities. It is accompanied by several issue-specific deep dive assessments, including this one, in response to Executive Order 14017 “America’s Supply Chains,” which directs the Secretary of Energy to submit a report on supply chains for the energy sector industrial base. The Executive Order is helping the Federal Government to build more secure and diverse U.S. supply chains, including energy supply chains. To combat the climate crisis and avoid the most severe impacts of climate change, the U.S. is committed to achieving a 50 to 52 percent reduction from 2005 levels in economy-wide net greenhouse gas pollution by 2030, creating a carbon pollution-free power sector by 2035, and achieving net zero emissions economy-wide by no later than 2050. The U.S. Department of Energy (DOE) recognizes that a secure, resilient supply chain will be critical in harnessing emissions outcomes and capturing the economic opportunity inherent in the energy sector transition. Potential vulnerabilities and risks to the energy sector industrial base must be addressed throughout every stage of this transition. The DOE energy supply chain strategy report summarizes the key elements of the energy supply chain as well as the strategies the U.S. Government is starting to employ to address them. Additionally, it describes recommendations for Congressional action. DOE has identified technologies and crosscutting topics for analysis in the one-year time frame set by the Executive Order. Along with the capstone policy report, DOE is releasing 11 deep dive assessment documents, including this one, covering the following technology sectors: carbon capture materials; electric grid including transformers and high voltage direct current (HVDC); energy storage; fuel cells and electrolyzers; hydropower including pumped storage hydropower (PSH); neodymium magnets; nuclear energy; platinum group metals and other catalysts; semiconductors; solar photovoltaics (PV); and wind. DOE is also releasing two deep dive assessments on the following crosscutting topics: Commercialization and competitiveness; and cybersecurity and digital components. More information can be found at www.energy.gov/policy/supplychains.

25 ENERGY STORAGE↗

Exponential Backoff and Its Security Implications for Safety-Critical OT Protocols over TCP/IP Networks

The convergence of Operational Technology (OT) and Information Technology (IT) networks has become increasingly prevalent with the growth of Industrial Internet of Things (IIoT) applications. This shift, while enabling enhanced automation, remote monitoring, and data sharing, also introduces new challenges related to communication latency and cybersecurity. Oftentimes, legacy OT protocols were adapted to the TCP/IP stack without an extensive review of the ramifications to their robustness, performance, or safety objectives. To further accommodate the IT/OT convergence, protocol gateways were introduced to facilitate the migration from serial protocols to TCP/IP protocol stacks within modern IT/OT infrastructure. However, they often introduce additional vulnerabilities by exposing traditionally isolated protocols to external threats. This study investigates the security and reliability implications of migrating serial protocols to TCP/IP stacks and the impact of protocol gateways, utilizing two widely used OT protocols: Modbus TCP and DNP3. Our protocol analysis finds a significant safety-critical vulnerability resulting from this migration, and our subsequent tests clearly demonstrate its presence and impact. A multi-tiered testbed, consisting of both physical and emulated components, is used to evaluate protocol performance and the effects of device-specific implementation flaws. Through this analysis of specifications and behaviors during communication interruptions, we identify critical differences in fault handling and the impact on time-sensitive data delivery. The findings highlight how reliance on lower-level IT protocols can undermine OT system resilience, and they inform the development of mitigation strategies to enhance the robustness of industrial communication networks.

DNP3↗

Developing Smart Building Technology Modules to Enhance Workforce Preparedness: A Case for AI-Driven Academic and Professional Education

Smart building technologies are resources that improve building energy efficiency and resilience, reduce carbon emissions, and provide load flexibility to the grid. However, in both academic curricula and building professionals’ continuing education, there is a lack of systematic instruction on methods to integrate multiple energy systems including distributed energy resources (DER), smart building technologies, AI (Artificial Intelligence) tools and key concepts, components, and controls, including “Internet of Things” (IoT) devices. In today’s dynamic workforce, this major gap in smart building technology education prevents stakeholders from being able to attract talent with an understanding and preparation to adopt smart building technologies in building design and operations. A federally funded project included a partnership between Slipstream and Texas A&M University (TAMU) to develop a semester-long smart building curriculum for engineering college students with the ability to adapt the contents for workforce development of professionals in building services. The final product consists of 16 training videos adapted for building professionals and the public. The educational content and training materials cover the benefits of building energy systems, the latest sensor technologies and IoT devices, all with a focus on smart building technologies. The key drivers are on topics related to smart building controls (i.e., energy management information systems), smart building control platforms, cybersecurity, grid-interactive-efficient buildings (GEBs), smart building control methods, and occupant-centric control. Although not explicitly included the technologies nod to the need for AI driven technologies to prepare engineers and industry professionals to be future ready. This paper describes the project approach, provides outlines of the training materials, and identifies lessons learned in creating the content for this course. The authors suggest ways to scale the instruction of smart building concepts to empower the workforce to accelerate the adoption of smart building technologies and AI-based teaching and learning in higher education and building sector.

99 GENERAL AND MISCELLANEOUS↗

The Design and Evaluation of Zero Trust Architecture for Electric Vehicle Charging Infrastructure: EVs @ Scale Series on EV Charging Station Cybersecurity

Implementing a zero trust architecture can significantly bolster the security of electric vehicle (EV) charging infrastructure. EV charging infrastructure includes numerous networked interfaces, each of which can present potential vulnerabilities. When these vulnerabilities are exploited, they can compromise the entire system, leading to severe operational and security risks. Zero trust is a security model that operates on the principle of "never trust, always verify," which helps manage the attack surface and limit the scope of any potential compromises. Fundamentally, this model ensures that no entity, whether inside or outside the network, is trusted by default. The design principles of zero trust include continuous verification, strict deny-by-default access controls, and micro-segmentation. Continuous verification ensures that every request is thoroughly checked, regardless of its origin. Strict access controls enforce the principle of least privilege, allowing users and devices only the minimum necessary access to perform their functions. Micro-segmentation involves dividing the network into smaller, isolated segments to prevent lateral movement in case of a breach. In the context of EV charging infrastructure, zero trust can be implemented through various strategies. For example, multi-factor authentication (MFA) can be required for engineers to access the management interfaces and control systems of charging stations. Real-time monitoring and analysis of network traffic can help detect and respond to anomalies. Systems that do not need to communicate with each other can be micro-segmented to enhance security. All communications should adhere to predefined policies to be permitted. Additionally, encrypting communications can protect sensitive information exchanged between chargers and management systems. This paper presents a zero trust architecture specifically designed for EV charging infrastructure. Implementing zero trust not only mitigates risks but also builds a resilient infrastructure capable of withstanding and quickly recovering from cyber threats. The architecture addresses six defined security objectives. A comprehensive test plan is developed to assess the architecture against these objectives, and the results of the evaluation are reported. This approach is essential for maintaining the reliability and integrity of EV charging services in an increasingly interconnected and vulnerable digital landscape. This is the first in a planned series of papers exploring the implementation of zero trust in EV charging infrastructure. Each paper will delve into different aspects and applications of zero trust, highlighting how various work processes and requirements can lead to distinct architectural designs. These architectures will be tailored to address specific security challenges and operational needs within the EV charging ecosystem, ensuring a robust and adaptable security framework.

33 ADVANCED PROPULSION SYSTEMS↗

Assessing Energy Infrastructure Devices for Vulnerabilities

Industrial control systems prove to be vital to the health and security of the nation in our critical infrastructure. Critical infrastructure includes the most foundational systems to support modern civilization which includes water and wastewater systems, communications, and the electricity we use to name a few sectors. However, these devices' overall composition remains largely unknown and are untested from a cyber security perspective. As part of the Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program, I analyzed one such energy infrastructure device to better understand how it functions, what hardware and software components are present within it, and assess it for security vulnerabilities. To achieve this, I reverse engineered binary files using Ghidra to understand system functionality and learned more about how to collaborate with other researchers on a shared Ghidra project. I learned more about how web sockets function and how to interact with them through Python to test if they are secure or not. This work led me to assess possible vulnerabilities in this device and provide a better understanding of its composition and function, which are essential to INL's mission of securing our nation's energy infrastructure.

99 - GENERAL AND MISCELLANEOUS↗

Cyber-Physical Resiliency for Wind Power Generation

During the next three years, wind power generation is expected to add more generation capacity to the national electrical grid than any other energy sector. With new wind turbine designs rated power over 10 MW and wind farms reaching over 1 GW capacities, the consequences of cyber-attacks on wind power generation are becoming increasingly more critical. Moreover, the known vulnerabilities of wind turbine control systems and the potential damaging effects of intrusions, motivate an urgent protection improvement for the wind power generation sector. This program has developed a variety of new adaptive defense technologies that enable wind power generation systems to survive sophisticated cyberattacks by enhancing the control systems capabilities of detection, localization, and accommodation. The introduction of these technologies in the on-shore and the emerging off-shore market will result in a significantly more reliable and secure wind power infrastructure.

17 WIND ENERGY↗

Battery Energy Storage Systems Report

Battery energy storage systems (BESS) are a critical component of grid reliability and resilience today, providing rapid response capabilities while enabling grid modernization and capacity expansion across the United States. As utilities, communities, and customers prepare to deploy significant BESS capacity over the next several years, the United States has an opportunity to build security into battery system design and deployments. This report provides a framework for assessing the current dominance of foreign-manufactured components in the supply chains for BESS, inverter-based resources, and transformers. It offers high-impact, actionable solutions to service partners, industry, and government to address supply chain risks for currently installed, in design, and future deployments.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

A Review of Visualization Methods for Cyber-Physical Security: Smart Grid Case Study

Cyber-Physical Systems (CPSs) are becoming increasingly complex and interconnected as they attempt to meet the demands of evolving society. As a result, monitoring and maintaining them becomes a more complex and demanding task for control system operators and cyber defenders. While the literature on visualization techniques in the context of cybersecurity is extensive, the same cannot be said for studies on visualization for the security of cyber-physical systems. This paper aims to fill that gap by: 1) defining the main features of a visualizations workflow for security visualizations in cyber-physical systems. The workflow includes the acquisition of cyber and physical data, processing of data, selection, and configuration of both visualization tools and end-user interactions. 2) Providing an overview of cyber-physical security visualization systems, with a focus on smart grids as a case study. Finally, we use the perspectives gained from this analysis to provide insights and directions for future research and design of cyber-physical visualization techniques.

24 POWER TRANSMISSION AND DISTRIBUTION↗

CyTRICS: Vulnerability Analysis Tailored for Critical Infrastructure

Society and modern life are dependent on critical infrastructure that is composed of expensive, special purpose devices that have long life cycles and may be in use for decades before being replaced. There are an abundance of organizations and individuals doing vulnerability analysis on a variety of systems, but what makes the Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program unique and valuable is its strategic focus on high-priority critical infrastructure, close partnership with vendors, and ability to leverage bills of materials (BOMs) to identify and relate vulnerabilities to affected systems. Creating a bill of materials is a formal way of understanding and documenting the components of a system, including everything from integrated circuits to operating systems to third-party libraries. This is beneficial for connecting known vulnerabilities to affected devices, since vulnerabilities in a specific component are often not mapped to all systems that use that vulnerable component. Additionally, CyTRICS finds novel vulnerabilities through its vulnerability testing process and works closely with vendor partners to provide vulnerability reports so that affected systems can be patched in a timely manner. This presentation will describe the interrelated technical processes CyTRICS uses to create bills of materials and conduct vulnerability analysis.

99 GENERAL AND MISCELLANEOUS↗

BESSIE: Battery & Energy Storage Supply Chain Analysis, Mitigation Deployment, and Tools

Battery energy storage systems (BESS) and their associated power electronic interfaces are key components to delivering clean and more resilient energy, providing much-needed fast-ramping, emergency discharge, generation, and operations support to the electric grid. These services have grown to be invaluable over the past ten years and will soon be an irreplaceable element of energy delivery. The Idaho National Laboratory (INL) strives to address these challenges through a strategic approach to supply chain risk assessment and mitigation for BESS and related digital energy equipment through the BESSIE project under the Center for Securing Digital Energy Technology. Recognizing that decreasing dependence on a foreign supply chain will take significant time and investment, BESSIE’s focus is strategically addressing battery supply chain risks by pairing short-term steps to operate securely through today’s risks with long-term steps to shape the supply chain over the coming years.

25 ENERGY STORAGE↗

Science Uses Deployment Operations-Advanced Wireless: Exploring Open Radio Access Network Technologies for Energy Science

Open Radio Access Network is emerging as a solution to the increasing demand for more flexible, cost-effective, and advanced mobile network infrastructures. This evolution is driven by advancements in wireless technologies and the growing complexity of deploying and managing these networks. O-RAN represents a significant shift in wireless technology, building upon the 3rd Generation Partnership Project framework to foster openness, flexibility, and interoperability. By decoupling hardware and software components, Open Radio Access Network enables a multi-vendor ecosystem that encourages innovation and diverse solutions. Open Radio Access Network's potential extends beyond traditional wireless applications, with growing interest in its role in advancing energy systems, particularly in the context of smart grids, microgrids, and the integration of renewable energy sources. While the role of open-wireless technologies in driving energy transformation is increasingly recognized, further exploration is needed. Vendors and utilities are investigating how Open Radio Access Network technologies can optimize energy use cases and improve the performance of 5G and beyond applications. This report outlines efforts under the Science Uses Deployment Operations Advance Wireless project, a collaboration between the National Laboratory of the Rockies' Cybersecurity Research Center, Argonne National Laboratory, Lawrence Berkeley National Laboratory, and the Department of Energy's Energy Science Network research and operations staff. The focus of this project is on due diligence, through testing and evaluation, preparing for the deployment of advanced wireless infrastructure for scientific use cases, with an emphasis on Open Radio Access Network technology, its components, integrations, and its ability to support vertical stack application across the energy sector. Additionally, the report highlights the value cases for utilities, underscoring how adopting open wireless standards can accelerate the evolution of energy systems, foster innovation, and improve the integration of critical energy technologies.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Optimized V1G and V2G Electric Vehicle Fleet Management and Grid Transaction at Marine Corps Air Station Miramar in San Diego, CA

The overall technical goal of the project was to demonstrate an all-electric bi-directional non-tactical fleet at Marine Corps Air Station (MCAS) Miramar that was integrated and controlled with other distributed energy resources (DERs) (i.e., PV, stationary battery, and building loads) to provide resilience to critical electric loads in the event of grid outages, to minimize charging costs, and to provide economic energy resources to electricity markets. In this project, the specific, technical objectives were: 1. Demonstrate that bi-directional electric vehicles can provide critical complementary services to fixed storage batteries in microgrid applications while performing function as non-tactical vehicles. 2. Demonstrate participation of bi-directional (V2G) and unidirectional (V1G) PEVs for demand management and minimization of charging costs. 3. Demonstrate integration of multiple DERs for grid service participation. US Marine Corps Air Station (MCAS) Miramar in San Diego was the site of this electric vehicle-to-microgrid-utility grid test and demonstration project. Existing microgrid assets in this study included (1) a public works building; (2) a 30-kW rooftop photovoltaic (PV) system and (3) a separate 250 kW carport PV system. In this project, six bi-directional V2G vans were located at the MCAS Miramar’s showcase building-scale microgrid to develop and test technical capabilities that V2G can provide in microgrid applications (e.g., cost reduction and resiliency). These resources provided aggregated demand management and simulated participation in current retail DR programs. The vehicles used in this demonstration were selected because they provided functionality that MCAS Miramar needed, 15 passenger transport and facilities work cargo carrying capacity, and bi-directional charging capability that the research project required. All vehicles in this study were manufactured and distributed by VIA Motors, Inc. There were six vehicles total and each was VIA’s VTRUX eREV V2G model, a modified General Motors Chevrolet 2500 2WD van. Three of the vans were configured as passenger vans and the other three were configured as cargo vans. Each van had an on-board bi-direcrtional inverter/charger, Bel Power Solutions model 350INVCHGT150-120-240-8G nominally rated at +/-15 kW. The VIA van’s charging connector follows the J1772 charging protocol. The bi-directional EVSEs demonstrated in this study were manufactured by Coritech, Inc. Each VGI-80-AC charging station enabled enhanced V2G charging capability to a Clipper Creek CS-100 charging module. The enhanced capabilities included ethernet communication following the SEP2.0 protocol with a distributed energy resource function set and an operator screen displaying real-time SOC, voltage, and current. The VGI-80-AC charging stations are classified as level 2 with a maximum current output of 80 A or effectively 19 kW. The VIA van’s onboard charger limited the charging and discharging power to 15 kW in each direction. A control computer was installed in the EWOC and connected to an existing monitor. The V2G control communication network was a completely stand-alone closed system that did not have any connection to any other networks on the base. A cybersecure remote communication connection was created with a cellular modem, firewall hardware, and a virtual private network configuration.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Achieving Cyber-Resilience for Power Systems using a Learning, Model-Assisted Blockchain Framework

The secure integration and management of distributed energy resources (DER) and power aggregators in the electric grid requires secure communications and a physics-aware Command and Control (C2) strategy. A Blockchain (BC)-based overlay network was developed to provide a security layer for the existing power grid network that mitigates risks in current and legacy network and C2 protocols. By integrating a Model-Assisted Machine Learning (MAML) framework with a Secure Blockchain Overlay Network (SBON) a defense-in-depth strategy was achieved. In our approach, the MAML framework leveraged a smart contract framework to gather network data and learn the dynamics of DER to develop detection strategies for attacks targeting sensors and actuators used by DER. The MAML framework learned dynamical systems models for individual DERs to detect sensor attacks. For DER we utilized a Digital Twin (DT) to accelerate the learning process for a model resistant to stealthy attacks. The project created DT for PV inverters and BESS. The DTs were coupled with a model-assisted, data-driven learning of DER behavior. Specifically, we evaluated architectures for model-based learning with model-free fine-tuning. Additionally, differential privacy techniques were used to obfuscate data, while still allowing the computation of attack detection results based on obfuscated data. The SBON developed leverages a private permissioned blockchain network orchestrated with the Hyperledger Fabric framework. To connect the cyber world, which orchestrates the blockchain fabric, and the physical world where the power network resides, we developed a system implementation to enable the secure interaction of the physical world and the abstracted blockchain.

97 MATHEMATICS AND COMPUTING↗

Deep Cyber-Physical Situational Awareness for Energy Systems: A Secure Foundation for Next-Generation Energy Management

This document provides the final report for the CYPRES project. The purpose is (1) to highlight and summarize its major accomplishments and (2) to provide guidance on how its outcomes have informed and can inform important additional research and technology transfer. The goal of CYPRES was the research, development, and demonstration of a security-oriented next generation cyber-physical EMS for electric power systems that detects malicious and abnormal events through the fusion of cyber and physical data. To achieve this, the CYPRES project team researched, developed, and built a prototype of the solution, referred to as the CYPRES EMS. The CYPRES EMS is a proof-of-concept cyber-physical platform that demonstrates the management of the energy system, communications, security, and cyber-physical grid modeling and analytics. As part of the capabilities of the CYPRES EMS, the team designed and developed a suite of power system applications for monitoring, risk analyses, detection, and control that are inherently cyberaware. At its core, the project aimed to research, develop, and demonstrate a security-oriented next-generation cyber-physical Energy Management System (EMS) capable of detecting malicious and abnormal events through the innovative fusion of cyber and physical data. This approach represents a fundamental shift from traditional EMS, reimagining how critical infrastructure can be protected through unified cyber-aware and physics-aware secure data flow pipelines. The project’s cornerstone deliverable, the CYPRES EMS, serves as a proof-of-concept cyber-physical platform that revolutionizes the management of energy systems, communications, security, and cyber-physical grid modeling and analytics. This prototype implements a comprehensive suite of power system applications for monitoring, risk analyses, detection, and control, all designed with inherent cyber awareness. The system’s architecture extends from end-devices in the field through to control center applications, establishing a secure and resilient control framework that addresses the challenges posed by diverse devices of unknown trustworthiness connecting to modern power systems. Through this innovative approach to deep cyber-physical situational awareness, the CYPRES project not only advances the state-of-the-art in energy infrastructure protection but also establishes a new paradigm for how EMS can be designed, deployed, and operated in an increasingly complex threat landscape. The findings and developments from this project provide crucial insights for stakeholders across the energy sector, offering a blueprint for enhancing the reliability and resilience of our nation’s critical energy infrastructure in the face of evolving cyber threats.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Enhancing the Survivability of Power Systems With Grid-Edge DERs Against DoS Attacks

Power system survivability, defined as the ability of a system to maintain steady-state functionality under varying operational conditions, reflects its resilience against disturbances. While existing research primarily focuses on physical-layer disturbances, the increasing prevalence of grid-edge DERs, which are primarily used for integrating renewable energy, has significantly expanded the cyber attack surface. As a result, operational disruptions caused by cyber threats are posing significant challenges to system survivability and cannot be overlooked. To fill this gap, we redefine system survivability to incorporate the cyber layer’s status and propose a Distributionally Robust Optimization (DRO) approach to enhance power system survivability against potential cyber-physical threats. In this paper, we first analyze the operational guidelines of systems with a high penetration of DERs under various cyber network conditions and redefine survivability in this context. Next, we focus on the most common cyber threat, Denial-of-Service (DoS) attacks, and develop a corresponding attack model. This model allows for the creation of a kernel-based ambiguity set that captures attack uncertainties using historical data. Finally, we transform the proposed DRO model as a tractable optimization problem, with its solution providing an optimal cyber redundancy plan to enhance system survivability in DoS attack scenarios. Simulation results on the IEEE 13-node and 123-node test feeders demonstrate the effectiveness of our proposed model in improving system survivability. This model can also be expanded to include other types of common attacks and serve as a comprehensive planning tool to improve overall cyber physical survival of the system.

cybersecurity↗