Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Cybersecurity for Renewables”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Cybersecurity Assessment for a Behind-the-Meter Solar PV System: A Use Case for the DER-CF

The world's energy production is shifting toward lower-cost, cleaner, more efficient, and sustainable sources. The increasing numbers of distributed energy resources (DERs) are allowing for the rapid transformation of electric grids toward achieving the goal of energy decarbonization. Along with cleaner and more efficient energy, however, we must also aim for a secure energy future. Solar photovoltaic (PV) systems are an important part of this transition. This paper discusses a cybersecurity risk assessment for behind-the-meter DERs using a solar PV system as a use case of the Distributed Energy Resource Cybersecurity Framework (DER-CF) developed by the National Renewable Energy Laboratory. This poster presents a conference paper on the risk assessment processes and summarizes the DER-CF's use case recommendations to strengthen the cybersecurity posture of the electric grid.

cybersecurity↗

Cybersecurity for Clean Energy Resources [Slides]

This presentation provides motivation for research in clean energy cybersecurity and highlights INL projects and capabilities to address clean energy cybersecurity needs. The projects are broken down by device level, plant level, utility level, regulation level, and implementation. This introduction to INL capabilities creates opportunity for further conversations around how cohort members can improve their own organizational security postures.

14 SOLAR ENERGY↗

Achieving Cyber-Resilience for Power Systems using a Learning, Model-Assisted Blockchain Framework

The secure integration and management of distributed energy resources (DER) and power aggregators in the electric grid requires secure communications and a physics-aware Command and Control (C2) strategy. A Blockchain (BC)-based overlay network was developed to provide a security layer for the existing power grid network that mitigates risks in current and legacy network and C2 protocols. By integrating a Model-Assisted Machine Learning (MAML) framework with a Secure Blockchain Overlay Network (SBON) a defense-in-depth strategy was achieved. In our approach, the MAML framework leveraged a smart contract framework to gather network data and learn the dynamics of DER to develop detection strategies for attacks targeting sensors and actuators used by DER. The MAML framework learned dynamical systems models for individual DERs to detect sensor attacks. For DER we utilized a Digital Twin (DT) to accelerate the learning process for a model resistant to stealthy attacks. The project created DT for PV inverters and BESS. The DTs were coupled with a model-assisted, data-driven learning of DER behavior. Specifically, we evaluated architectures for model-based learning with model-free fine-tuning. Additionally, differential privacy techniques were used to obfuscate data, while still allowing the computation of attack detection results based on obfuscated data. The SBON developed leverages a private permissioned blockchain network orchestrated with the Hyperledger Fabric framework. To connect the cyber world, which orchestrates the blockchain fabric, and the physical world where the power network resides, we developed a system implementation to enable the secure interaction of the physical world and the abstracted blockchain.

97 MATHEMATICS AND COMPUTING↗

South Texas Industrial Assessment Center (Final Report)

The South Texas Industrial Assessment Center (ST-IAC) provides small to mid-size manufacturing companies and water treatment plants in the Rio Grande Valley of Texas, free energy assessments to help them reduce costs and stay competitive for sustainable development. The ST-IAC operates within the University of Texas Rio Grande Valley (UTRGV), and is the largest Hispanic-serving IAC in the U.S. Created in 2016, the ST-IAC, situated in the most economically disadvantaged region in the country, has been successful in training students and assessing local industries served by a predominantly Hispanic population. UTRGV, now the second largest Hispanic Serving Institution (HSI) of higher education in the U.S., has a student population of 32,000, of which 90% is Hispanic. While Covid-19 had a negative impact to our program during Budget Periods (BP) 4 and 5, the center still managed to provide opportunities for individuals, manufacturing and water industries in the local region. The program developed an energy engineering program in the region and further advanced national priorities. Those include resilience and sustainability of operations by implementing energy efficiency processes, renewable energy sources, decarbonization, battery storage, and cybersecurity in south Texas.

14 SOLAR ENERGY↗

Hydropower Cybersecurity Value-at-Risk Framework

Hydropower remains one of the strongest forms of renewable energy generation methods. It is crucial to address the increasing risks associated with the rapid digitization. The push towards decarbonization also factors in the need to ensure security and resilience for grid-connected renewable energy resources. This report summarizes the U.S. Department of Energy's Water Power Technologies Office's effort to develop a cybersecurity valuation methodology that assists hydropower stakeholders in assessing risks associated with plan operations and gathers valuation guidance through a web-based application. The Hydropower Cybersecurity Value-at-Risk Framework delivers a platform for industry members to perform self-assessments and make informed decisions on their cybersecurity investments.

13 HYDRO ENERGY↗

The Cybersecurity Value-at-Risk Framework

Hydropower remains one of the strongest forms of renewable energy generation methods. It is crucial to address the increasing risks associated with the rapid digitization. The push towards decarbonization also factors in the need to ensure security and resilience for grid-connected renewable energy resources. This report summarizes the U.S. Department of Energy's Water Power Technologies Office's effort to develop a cybersecurity valuation methodology that assists hydropower stakeholders in assessing risks associated with plan operations and gathers valuation guidance through a web-based applicaiton. The Hydropower Cybersecurity Value-at-Risk Framework delivers a platform for industry members to perform self assessments and make informed decisions on their cybersecurity investments.

CVF↗

Standardization and Recommendations for EVSE Cybersecurity Standards

Currently, there is an absence of cybersecurity certification programs specifically for EVSE. Many existing standards focus primarily on safety, such as battery safety, while others provide cybersecu rity guidelines for different types of equipment, which could be adapted for EVSE. Among these, ISA/IEC 62443 has been identified as highly aligned with EVSE security needs. This report is a follow on to the previous research published (“Assessment and Coordination of EVSE Cybersecurity Standards,”). This report aims to find appropriate strategies for closing the gaps found in the aforementioned report and continue to work towards a comprehensive cybersecurity certification program for EVSE. Future testing will leverage this standard to assess EVSE security gaps and strengths, providing valuable insights to support certification development and harmonization of cybersecurity standards.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Securing Solar for the Grid (S2G) (Final Project Report) [Slides]

This is the final technical report for the SETO-funded project Securing Solar for the Grid (S2G) from FY22-24. The project scope included development and dissemination of standards' requirements, best practices, equipment testing procedures, assessment tools, as well as education and training materials for cyber defense, posture and maturity tailored to solar technologies. The outcomes for this work include: co-led the development of cybersecurity certification standard (UL2941), co-led the development of cybersecurity guide (IEEE1547.3), development of recommendations for supply chain cybersecurity, and development of cybersecurity risk profiles and recommendations for DERMS.

14 SOLAR ENERGY↗

Caribbean Energy Sector Cybersecurity Forum: Modernizing and Securing the Grid

This presentation on Modernizing and Securing the Grid brought together regional and NREL cybersecurity expertise for USAID's Caribbean Energy Sector Cybersecurity Forum. The presentation's overall purpose was to provide a deep dive into the changes underway in the electric grid, including the greater integration of renewables and distributed energy resources. The presentation also reviewed best practices for building cybersecurity into modern energy systems, including in the areas of vendor assessment and supply chain cybersecurity.

Caribbean↗

Independent Review of the Proof-of-Concept Cyber100 Compass Cybersecurity Risk Tool

The U.S. Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER), and Office of Electricity (OE) commissioned the National Renewable Energy Laboratory (NREL) to develop a method and tool to enable electric utilities to understand and manage the risk of cybersecurity events that can lead to physical effects like blackouts. This tool, called Cyber100 Compass, uses cybersecurity data elicited from cybersecurity experts, then incorporates that data into a tool designed to be usable by cybersecurity non-experts who understand the system itself. The tool estimates dollar-valued risks for a current or postulated future electric power digital control configuration, in order to enable utility risk planners to prioritize among proposed cybersecurity risk mitigation options. With the development of the Cyber100 Compass tool for quantification of future cyber-physical security risks, NREL has taken an initial bold step in the direction of enabling and indeed encouraging electric utilities to address the potential for cybersecurity incidents to produce detrimental physical effects related to electric power delivery. As part of the Cyber100 Compass development process, DOE funded NREL to seek out an independent technical review of the risk methodology embodied in the tool. NREL requested this review from Sandia National Laboratories, and made available to Sandia a very late version of the project report, as well as NREL personnel to provide clarification and to respond to questions. This paper provides the result of the independent review activity.

97 MATHEMATICS AND COMPUTING↗

Envisioning the Future Renewable and Resilient Energy Grids—A Power Grid Revolution Enabled by Renewables, Energy Storage, and Energy Electronics

Today’s power grids are facing tremendous challenges because of the ever-increasing power demand, system complexity, infrastructure cost, knowledge base, and policy and regulatory issues to achieve supply–demand power balance and resiliency with respect to more frequent extreme weather events and cyberattacks. It is particularly challenging when the transition toward 100% intermittent renewable energy sources is considered. Many countries are calling for building up more transmission and distribution lines to increase power delivery capacities. This article is an attempt to answer two urgent questions: Is more transmission and distribution infrastructure really needed to meet the increasing power demand? What kind of future grid infrastructure should we envision and build? This article attempts to answer these questions and proposes the concept of community-centric asynchronous renewable and resilient energy grids. By clearly differentiating the concepts of grid resilience and reliability, the importance of building resilient power electronics’ devices and robust system-level control algorithms to achieve 100% renewable energy integrated resilient grids is presented. To identify the shortcomings and propose advancements, power electronics’ technologies are categorized using the proposed concepts of natural source frequencies (NSf), energy storage, direct energy conversion/control and fault protection (DeCaFp), and high-efficiency energy consumption and buffering (heECaB) technology. The ability of networked microgrids to greatly reduce power outages and power system restoration time is demonstrated by leveraging robust decentralized and centralized control algorithms, identified through a comprehensive literature review. Future research areas are proposed to further enhance grid stability, controllability, cybersecurity, and protection against faults in the presence of 100% renewable sources by leveraging the advanced capabilities of NSf, DeCaFp, and heECaB devices and system-level control algorithms.

14 SOLAR ENERGY↗

Bat Smart Curtailment: Efficacy and Operational Testing

Curtailment, or blanket curtailment, is a leading method to mitigate the impacts to bats from operating wind turbines. Although this strategy results in considerable decreases in bat fatalities, it also results in decreased energy production. In 2019, Natural Power was awarded funding by the Department of Energy to assess the readiness of the informed smart curtailment technology, EchoSense (formerly referred to as Detection and Active Response Curtailment, [DARC]). The research undertaken by this project expands the understanding of alternative methods, known as smart curtailment, to maintain a reduction in bat fatalities while simultaneously recovering lost energy associated with blanket curtailment. The overall project was composed of three major tasks; Task 1 was focused on cybersecurity compliance of the EchoSense system in accordance with the North American Electric Reliability Corporation Critical Infrastructure Protection (“NERC CIP”) standards, Task 2 assessed the mechanical loads exerted on turbines when operating under a smart curtailment regime, and Task 3 assessed the efficacy of the EchoSense system at an operational wind farm. Regarding Task 1, an external review by the National Renewable Energy Laboratory determined that the EchoSense system did not create any new cybersecurity weaknesses and was compliant with the NERC CIP standards. As a result of this process, Natural Power developed some best practices (10.1) for wind- wildlife technology developers. In conjunction with the National Renewable Energy Laboratory, the results (10.2) of the loads testing demonstrated that the periodic curtailment and release of turbines by the EchoSense system did not have any detrimental impact on the mechanical components of a wind turbine (Task 2). During the late summer to fall of 2020 and 2021, Natural Power demonstrated that the use of the EchoSense smart curtailment system resulted in no significant difference in bat fatalities compared to blanket curtailment with cut-in speeds at 6.9 m/s (2020) and 5.0 m/s (2021) while resulting in a significant difference in decreased lost energy (Task 3). This translates to an average of 41% (2020) and 56% (2021) reduction in per turbine energy loss compared to blanket curtailment. The reduction in energy loss that would have been achieved by EchoSense curtailment compared to blanket curtailment, if applied across all 69 turbines, is roughly equivalent to having an additional turbine on site. These results are notable for finding a balance between the environmental impact of wind energy and the economic feasibility in energy production associated with mitigating that impact. https://www.naturalpower.com/us/expertise/service/engineering-operations/echosense

17 WIND ENERGY↗

Attack Surface of Wind Energy Technologies in the United States

Low cost, reliable electrical energy production from wind relies upon automation and control systems, arguably more so than traditional thermal generation. These same systems, however, can serve as the target of adversaries’ cyber-attacks. Idaho National Laboratory (INL), at the request of the Department of Energy’s (DOE’s) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) and Energy Efficiency and Renewable Energy’s (EERE’s) Wind Energy Technologies Office (WETO), evaluated a generalized wind plant architecture to understand the classes of potential threat actors and the vectors that could enable a cyber-attack. This evaluation explores the attack surface of a representative wind plant, identifying potential methods and vectors that an adversary could leverage to conduct a cyber-attack. Included in this assessment are some recommended mitigations and approaches. Each recommendation requires a full security evaluation, cost/benefit analysis, and risk analysis by each owner and operator.

17 WIND ENERGY↗

Cybersecurity Risk Profiles for Distributed Energy Resource Management Systems

Managing the digitalization of increasingly diversity energy resources is a complex challenge for energy systems planners and managers. As the penetration of solar photovoltaics (PV) and other distributed renewable energy resources (DERs) expands, distributed energy resource management systems (DERMS) will play an increasingly important role in managing, monitoring, and controlling DERs as electric systems before more distributed, interconnected, and networked. However, the cybersecurity implications of DERMS deployments are not well understood today. A lack of understanding around the cybersecurity implications of DERMS deployments and variability in the security posture of DERMS vendors, owners, and operators could introduce new security risks to evolving electric power systems. This paper describes cybersecurity attack scenarios on DERMS, identifies related cybersecurity standards and guidelines, reviews the security features of state-of-the-art DERMS solutions, and offers cybersecurity guidance for DERMS vendors, owners, and operators to protect DERMS' unique capabilities. Standardizing cybersecurity requirements for DERMS could help improve the security of DERMS integrations and improve innovations that are more secure by design. The cybersecurity guidance found in this paper is intended to offer a unified approach and lay the foundation for future standardization of DERMS cybersecurity to reduce risk to the solar industry and other renewable energy stakeholders when integrating these technologies with electric power systems.

24 POWER TRANSMISSION AND DISTRIBUTION↗

The Distributed Energy Resource Cybersecurity Framework

For facilities with distributed energy resources (DERs), cybersecurity must be considered holistically, across system architectures and down to individual components. It's hard to know where to start. That's why the National Renewable Energy Laboratory (NREL) has developed an assessment tool for organizations with DERs to understand and improve their cybersecurity. With support from the U.S. Department of Energy's Federal Energy Management Program, the Distributed Energy Resource Cybersecurity Framework (DER-CF) provides a holistic evaluation of a facility's DER cybersecurity and makes customized recommendations that follow widely recognized best practices for cybersecurity. The DER-CF is available at no cost as an interactive web tool (dercf.nrel.gov).

cybersecurity↗

Applying the Risk Management Framework: The Distributed Energy Resource Risk Manager

As part of a multiyear effort, the National Renewable Energy Laboratory (NREL) has dedicated resources to understand and identify cybersecurity weaknesses in distributed energy resources (DERs) by performing assessments. Due to a lack of standardization and rapidly increasing adoption of DERs, there is a critical need to address cybersecurity needs for DER systems in an interactive way. Furthermore, federal agencies, which are required to obtain an authority to operate, are challenged by the complexities of including their DERs. To help meet this need, in early 2020, NREL released the Distributed Energy Resources Cybersecurity Framework (DERCF) and accompanying Web application. This process is supported by the Risk Management Framework (RMF) developed by the National Institute of Standards and Technology. This project, referred to as the DERCF RMF application, expands on the existing DERCF work to include methods that support walking a user through the seven RMF steps. The tool will be available for download at no cost from [link ]. The purpose of this paper is to describe the steps the DERCF team at NREL took to understand Steps 1-5 of the RMF process. Additionally, this document will identify future work on the first five steps as well as a plan for Steps 6 and 7.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Distribution Cybersecurity: Cybersecurity Considerations of Distributed Resources

This presentation is focused on cybersecurity of the distribution system. It will educate attendees about the evolving cybersecurity threats facing energy infrastructure through exploring relevant cybersecurity incidents. Additionally, Participants will gain an understanding of Distributed Energy Resources and their growing role in grid architecture. Finally, the session will examine critical standards and guidelines, including Cybersecurity Baselines for Electric Distribution Systems and the IEEE 1547.3 standard.

24 POWER TRANSMISSION AND DISTRIBUTION↗