Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “energy efficient cybersecurity”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Field Insights: Strengthening Digital Assurance Through On-Site Network Monitoring

The accelerating deployment of digital energy infrastructure, ranging from inverter-based resources (IBRs), battery energy storage systems (BESS), to advanced grid control platforms, has brought unprecedented visibility, flexibility, and efficiency to the electric grid. However, this digital transformation also introduces new cybersecurity challenges, particularly in the form of supply chain risks and operational blind spots at the grid edge. Over the past year, the Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER), through its Rapid Risk Assessment initiative, along with the Grid Deployment Office (GDO), through its Technical Assistance for Digital Assurance (TADA) initiative, have supported a series of on-site network engagements led by Idaho National Laboratory (INL). These engagements, conducted in partnership with asset owners across the country, have focused on identifying real-world vulnerabilities and misconfigurations in operational environments, many of which are not detectable through remote assessments or traditional compliance audits. The goal of this report is to distill key findings and lessons learned during network hunt engagements from INL’s fiscal year (FY) 2024 - 2025. It is intended to help asset owners—regardless of their participation in the program—better understand the evolving threat landscape and adopt practical measures to secure their digital energy infrastructure.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Cybersecurity Considerations and Research Pathways for Grid-Interactive Efficient Buildings

Federal facilities serve critical missions and functions that require safe, reliable, and efficient operations. Digitization of several facility operations has increased the cost-effectiveness of energy usage and optimization of energy system performance. As the building controls landscape shifts to become more connected and smarter, building operators now face unique opportunities and challenges to adopt smart enabled devices that can lower energy usage while also optimizing building system performance. The grid-interactive efficient buildings (GEB) initiative aims to make buildings cleaner and more flexible through these smart devices. Smart enabled devices allow greater connectivity and control through remote operations and provide crucial data for analytics and increased efficiency. GEBs enable demand flexibility that has the potential to reduce electrical costs and transform the grid edge where buildings connect to power grids. This operation of interconnected systems, if not designed with cybersecurity practices, causes security gaps and introduces potential attack paths by adversarial and non-adversarial entities leading to disruption of operations.

building controls↗

Pathways to commercial building plug and process load efficiency and control

Abstract To accomplish net-zero carbon emissions in the built environment by 2050, we must equitably decarbonize commercial buildings, including reducing plug and process loads (PPLs). PPLs are plug-in or hardwired electric and gas loads that are not associated with major building end uses like lighting and HVAC. Research shows PPL energy reduction strategies and control technologies have the potential to save energy. But even when implemented, these savings have rarely been achieved and there has not been widespread uptake in U.S. commercial buildings. We investigate why these technologies and strategies have not seen widespread adoption and identify behavior and technology pathways to increase PPL reduction in U.S. commercial buildings. We examined behaviors of commercial building stakeholders through 44 interviews and cross-referenced qualitative analysis findings with in-depth technical knowledge of existing PPL control technologies and reduction strategies. PPL control implementation must be paired with management strategies, such as occupant engagement and training, to achieve optimal savings, and best practices should be disseminated across the industry. We found that increasing access to cost and energy savings data will promote uptake of PPL control technologies and allow designers to better incorporate PPLs into building design. Improving access to funding for PPL energy efficiency projects and addressing the split-incentive problem will increase adoption of PPL efficiency and control. Code bodies should continue to include PPL monitoring and reduction measures in energy codes. Key building stakeholders, including cybersecurity and information technology teams, should be involved in PPL monitoring and reduction strategy processes for successful implementation.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Digital Twin + AI: Control Room of the Future

A digital twin enhances power grid control room operations by providing real-time monitoring, predictive insights, simulation capabilities, remote control, training opportunities, data integration, and decision support. This technology empowers control room operators to effectively manage the grid, optimize performance, and ensure reliable and efficient energy distribution.

control room of the future↗

Decarbonization Considerations: Grid-Interactive Efficient Buildings [Slides]

The Federal Energy Management Program (FEMP) is helping federal agencies understand how to meet decarbonization goals with grid interactive efficient buildings (GEB). This training will provide attendees with an introduction to GEB, how to work with utilities, and opportunities for federal sites.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Cybersecurity Assessment in DER-rich Distribution Operations: Criticality Levels and Impact Analysis

The integration of distributed energy resources (DERs) in distribution networks has become a pivotal strategy for achieving decarbonization, enhancing grid resilience, and optimizing grid efficiency. Remote monitoring and control op- erations of such resources rely on a network of sensors and communication infrastructure, exposing the system to potential cyber threats. Therefore, as the deployment of DERs increases, ensuring secure monitoring and control becomes an imperative challenge. This paper utilizes real-time feeder models, which are instrumental in developing cybersecurity testbeds tailored for hardware-in-loop (HIL) systems. These models enable users to simulate cyber attacks in a real-world environment and analyze the power distribution operations during vulnerabilities. Furthermore, we discuss several practical sets of grid parameters to identify critical levels of DERs and evaluate various scenarios that simulate cyber threats on sensitive DERs. The modified IEEE 123-bus model is used as the test case for demonstrating the proposed scenarios. The findings from this study provide valuable insights into the vulnerabilities and potential consequences of cyber attacks on DERs, allowing for better mitigation strategies and improved cyber resilience in future distribution networks.

Maharjan, Manisha↗

Hawaii Threat Brief

The Digital Energy Transformation is redefining how power systems operate, integrating physical infrastructure with digital technologies to enhance efficiency, visibility, and resilience. For islanded and digitally modernizing systems like Hawai‘i’s, this shift presents both new opportunities and evolving challenges in cybersecurity, supply chain assurance, and environmental resilience. This brief provides an overview of critical infrastructure dependencies and systemic risks associated with increasing digital integration. It summarizes recent energy-sector threat activity and case studies that illustrate adversary tactics and supply chain vulnerabilities, and identifies pathways to strengthen resilience.

25 - ENERGY STORAGE↗

Blockchain Smart Contract Reference Framework and Program Logic Architecture for Transactive Energy Systems

This paper proposes a reference framework for a transactive energy market based on blockchain. The framework was designed based on the engineering requirements of a distribution-scale market; including participant needs, expected market transactions, and the cybersecurity constructs required to support a fair, secure and efficient market operation. It leverages the existing blockchain primitives to provide clear value propositions to the transactive market, including identity management (access control), data security (integrity), resiliency (decentralization, scalability and performance). The validity of the proposed framework is demonstrated using a real-time 5-min double-auction market. The results highlight its benefits while providing strong validation of applicability to blockchain within transactive energy systems.

Gourisetti, Sri Nikhil Gupta↗

Cybersecurity Certification Recommendations for Interconnected Grid Edge Devices and Inverter Based Resources

Escalating deployment of PV and grid-edge devices on the distribution grid has increased the sustainability and efficiency of the electric grid. However, the increasing number of distributed energy resources (DERs) deployed creates a heightened cyber-physical interdependency on the distribution grid and thus creates more vectors for cyber-attacks to exploit through information and communication technology (ICT) systems and networks. For example, control signal packets can be modified, intercepted, or corrupted due to vulnerabilities in communication protocols used by microgrid controllers and grid edge devices for power control. Therefore, to mitigate and prevent cyber-attacks on grid edge devices and the inverter-based resources connected to the distribution grid, the U.S. Department of Solar Energy Technologies Office (SETO) awarded funding to the National Renewable Energy Laboratory and Sandia National Laboratory (SNL) to research, develop, and harmonize cybersecurity standards for Photovoltaic (PV) systems and for other kinds of DERs. To help develop a standard for DER cybersecurity, NREL established certification recommendations and test cases, in consensus with the solar industry and UL, for ensuring intrinsic design security for DERs. These recommendations were developed to bolster the cybersecure functionalities such as TLS, MAC, CRL, session resumption/renegotiation, and password, system, and service security management within the DER devices. The proposed test cases verify authentication, authorization, confidentiality, and data integrity for data and communications of DERs that use Transmission Control Protocol/Internet Protocol (TCP/IP). They were also developed to protect DER communications from eavesdropping, replay, man-in-the-middle, denial of service (DoS), spoofing through security certificates, least-privilege violation, and brute-force credentials. This report, which has been validated and reviewed by UL, expands upon those test cases to provide DER cybersecurity certification recommendations which increase DER resiliency and help to mitigate cyber-attacks. UL's collaboration with NREL and approval of this document will accelerate the adoption of a UL standard for DER cybersecurity.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Enhanced Control, Optimization, and Integration of Distributed Energy Applications (ECO-IDEA)

With support from the U.S. Department of Energy Solar Energy Technologies Office, the National Renewable Energy Laboratory (NREL) partnered with Xcel Energy, Schneider Electric, Varentec, and Electric Power Research Institute (EPRI) to meet the goals of the Enabling Extreme Real-Time Grid Integration of Solar Energy (ENERGISE) program. This project developed and validated an innovative data-enhanced hierarchical control architecture that enables the efficient, reliable, resilient, and secure operation of future distribution systems with a high penetration of distributed energy resources like solar energy. The architecture enables a hybrid control approach where a centralized control layer is complemented by distributed control algorithms for solar inverters and autonomous control of grid edge devices. It is fully interoperable and includes all the cybersecurity aspects necessary for reliable and secure system operation. The hybrid approach can seamlessly integrate multiple voltage-regulation technologies, both at central and grid-edge levels, which enables reliable and efficient system operation in the face of unpredictable conditions. The overarching goal of the Eco-Idea project is to develop, validate, and deploy a unique and innovative Data-Enhanced Hierarchical Control (DEHC) architecture that comprehensively addresses the formidable challenges associated with proliferation of high penetration of distributed PV such as reverse power flows, transients from variability of PV systems, feeder load balancing, and voltage stability. These issues are exposing the weaknesses of existing grid operations and controls - including, but not limited to, lack of grid situational awareness, heuristic and slow-acting control actions, latency of control for emergency situations, and points of failure in communications. The proposed architecture will comprehensively resolve the deficiencies of current operational settings - where monitoring and control solutions proposed across industry and academia may not be interoperable and may not coexist in the same system - and will enable an efficient, reliable, resilient, and secure operation of future distribution systems with penetration of solar energy well beyond current limits. The DEHC architecture was developed and validated rigorously through hardware-in-loop simulations in the laboratory environment and deployed on the field.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Complete Evaluation on Advanced Reactor Machine Learning Subversion Attacks (Final)

Navigating through the world of Artificial Intelligence (AI) in nuclear reactors and their Instrumentation and Control (I&C) systems demands a careful, deliberate journey. AI’s capability to manage massive datasets and streamline control systems has indeed carved out a significant role in various sectors, including nuclear energy. However, while AI, and particularly Large Language Models (LLMs), bring a lot to the table in terms of operational efficiency and anomaly detection, they also expose the sector to a new breed of cybersecurity threats, like Inference Attacks, Adversarial Attacks, and Trojan Attacks. This guide is designed to be a straightforward manual, diving deep into the intertwining worlds of AI and cybersecurity within nuclear reactors, and tailoring insights for three crucial audiences: I&C Vendors/Developers, Nuclear Regulators, and Nuclear Reactor Operators and Cyber Defense Teams. (1) Section 2, directed at I&C Vendors/Developers, will provide a clear and focused look at several cybersecurity attacks, offering practical recommendations and detailed scenarios related to AI cybersecurity. This section isn’t just about identifying problems but also about giving solid, usable solutions. (2) Section 3, meant for Nuclear Regulators, gets straight to the point about regulations, policy suggestions, and guidelines that are needed to lay down a robust, secure, and ethical foundation for the application of AI in nuclear operations. The focus is on making sure that everything adheres to international standards and laws while being practicable and clear-cut. (3) Section 4, aimed at Nuclear Reactor Operators and Cyber Defense Teams, offers an exhaustive exploration and technical reports, with clear recommendations and scenario analyses vital to protect operational environments and guarantee the secure application of AI in nuclear reactor operations. The goal is simple: as we step into an era where AI becomes a fundamental element of our technological and energy infrastructures, this guide is here to act as a clear, direct handbook, ensuring that AI is implemented within the nuclear sector in a manner that is secure, responsible, and practical. It’s about striking a balance – optimizing the undeniable benefits offered by AI while securing and shielding against potential cyber threats as we move through this new and complex landscape.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Pillars of Innovation Across Southeast Idaho & the Interstate-15 Corridor

Since 1949, Idaho National Laboratory (INL) has been home to developing civilian and defense nuclear reactor technologies and managing spent nuclear fuel. Today, INL is the nation’s nuclear energy research laboratory, sustaining the safe and efficient operation of existing reactors, powering science in space, and breaking ground on the future fleet of advanced nuclear reactors. INL is only one of many rising technology resources in the region, however. Along the Interstate 15 (I-15) corridor, technology and cybersecurity industries and intellectual assets are rapidly expanding. Creating an innovation hub in this region would unite capabilities to solve current and future challenges in nuclear reactor sustainment and expanded deployment, integrated fuel cycle solutions, integrated energy systems, advanced materials and manufacturing for extreme environments, and secure and resilient cyber-physical systems.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Energy Systems Integration Facility Stewardship Summary: Fiscal Year 2022

A summary of NREL's good stewardship of the nationally unique Energy Systems Integration Facility (ESIF) highlighting performance metrics, infrastructure and capability upgrades, and examples of R&D impact. In fiscal year 2022, ESIF researchers made breakthroughs in everything from long-duration energy storage and cybersecurity visualizations to a world record in heavy-duty hydrogen vehicle fueling, and built out research assets to advance microgrid operation and controls, renewable hydrogen production, electric vehicles, energy-efficient buildings, and more.

ADVANCED PROPULSION SYSTEMS,ENERGY CONSERVATION, C↗

A Photovoltaic MPPT Charge Controller Real-Time Testbed for Cybersecurity Applications

The increasing deployment of distributed energy resources (DER) over the last decade is a great ally to combat climate change and strengthen the grid during increasingly common extreme weather events. However, DER systems, combined with the ongoing transition to a digital power grid, also pose substantial cybersecurity threats. One of the most common communication protocols used in DER integration is the Distributed Network Protocol 3 (DNP3), which is known to have many security vulnerabilities. Thus, it is essential to investigate cyberattack behaviors and mitigation on power systems using DNP3. In this paper, we designed and implemented a cybersecurity testbed for a simulated photovoltaic (PV) maximum power point tracking (MPPT) charge controller. Our testbed uses an MPPT charge controller simulated on a Typhoon HIL602+ real-time simulator with a real DNP3 communication connection over TCP/IP, allowing for safe and efficient monitoring and manipulation of data traffic between the simulated hardware and supervisory control and data acquisition (SCADA) systems.

14 SOLAR ENERGY↗

Industrial Assessment Center – integration of education and practice. Final progress report

The goal of the DOE’s Industrial Assessment Center (IAC) program is twofold: first, to help US manufacturing competitiveness by providing assessments and recommendations for small and medium-sized enterprises (SMEs) on energy efficiency, productivity, sustainability and competitiveness – including measuring the impacts of these recommendations on reducing greenhouse gas emissions; and second, to address a growing shortage of engineering professionals with applied energy and manufacturing-related skills by training a diverse cross-section of engineering students through hands-on involvement in these assessments. IUPUI has an IAC, which was established in 2011, in the Department of Mechanical and Energy Engineering, Purdue School of Engineering and Technology, IUPUI. The IAC has won the awards twice. We have built the center that has the expertise and infrastructure for quality energy assessments to manufactures and commercial building owners and aligned our current research and teaching activities to the DOE’ training mission with programs to train the next generation of industrial energy efficiency experts, with theory and hands-on experience in conducting energy assessment for small and median manufacturing enterprises. We have made recommendations that have the potential to save about $20M annually. We also initiated research projects to meet DOE priorities, specifically in the areas of smart manufacturing and cybersecurity. On the energy assessment side, the Center has provided energy assessments to 144 qualified companies, primarily located in Indiana. On the training side, the center has trained students in various programs, such as the department’s Bachelor of Science (BS) programs in Mechanical Engineering (ME) and BS in Energy Engineering (EEN), both are ABET accredited engineering programs, as well as a graduate level Energy Management and Assessment certificate program. At the present, the center has trained 95 students, 43 or them received the DOE issued certificates. Research projects were developed within the center to advance energy efficiency related technologies, which provided excellent opportunities for our trainees. The center has also been building a professional network with utilities, Manufacturing Extension Partnership (MEP), government agencies, and manufacturing companies, to increase our client base and promote collaborations. The center received the 2019 Center of Excellence of the Year Award and three students received the “Outstanding Achievement in Energy Engineering by an IAC Student” awards in the past five years.

42 ENGINEERING↗

TRANSSFORM Workshop Empowering the US manufacturing industry proceedings report

The U.S. Department of Energy (DOE), Office of Energy Efficiency and Renewable Energy, and Advanced Manufacturing Office (AMO) hosted the TRANSSFORM (Transformative, Resilient, Adaptive, Nimble, Sustainable, Smart, Flexible, Optimal, Robust, and Model-based1 – A Bold Vision for the Future of U.S. Manufacturing) Workshop on September 8–10, 2021. The objective of the workshop was to hear from stakeholders about how manufacturing digitalization can improve manufacturing competitiveness and reduce energy consumption and emissions production from U.S. manufacturing, and what research, development, and demonstrations are needed to have the desired impact.

manufacturing digitalization, decarbonization, IoT↗

A Cybersecurity Threat Profile for a Connected Lighting System

In anticipation of improved energy performance and cost savings, cities and building owners are increasingly considering “smart lighting initiatives” that aim to convert their collection of simple luminaires (i.e., lighting fixtures) into an intelligent connected lighting system (CLS) capable of remotely monitoring energy consumption and fault conditions, and possibly implementing adaptive lighting schemes. The U.S. Department of Energy (DOE) has set an national goal of tripling the energy efficiency and demand flexibility of the buildings sector by 2030, relative to 2020 levels 1. It is forecast that connected lighting systems can contribute to that goal by delivering 125 TWh of annual energy savings by 2035 2, equivalent to the annual output of 50 typical (500 MW) power plants. However, these energy savings and the DOE goal are put at significant risk if connected technologies are not adopted due to real or perceived cybersecurity concerns. Connected IoT devices such as these have historically been rife with vulnerabilities which sometimes put security considerations secondary to functionality and operability. What are the cybersecurity threats that will impact these systems, as formerly banal luminaires transition into intelligent connected devices that collect information about themselves, their surrounding environment, and possibly us? In this paper we analyze a threat profile performed on a fault-detection use case for streetlights. A threat profile establishes security requirements, justifies security measures, yields actionable controls, and effectively communicates risk to stakeholders. This effort provides critical information for making threat-based decisions to increase security at a reasonable cost, and can effectively be used by development teams, software architects, and managers to make cybersecurity a part of their ongoing culture of awareness, training, and prevention. This leads to more secure systems and better-understood security. On-premise, cloud, and hybrid architectures with different authentication mechanisms were modeled and later categorized using the Microsoft STRIDE framework. An analysis of the recommended controls for each threat was performed to determine which controls could and should be put in place by manufacturers or third-party suppliers, and which controls need to be left up the end-user to implement. Fifty-seven threats were identified. Among our key findings: (1) 65% (37/57) of the threats did not involve the luminaires, but rather the other components needed to communicate with and manage them; (2) 63% (36/57) of the threats could have been mitigated through manufacturer-implemented defensive techniques or “controls”; and (3) 23% (13/57) of the threats were dependent on the network configuration. Recommendations based on the results of this work are made to key stakeholder groups. Notably, lighting technology developers are advised to address all threats that can be reasonably controlled with baked-in technology solutions (e.g., encryption or authentication controls), and employ some form of secure supply chain management and tracking where other parts (e.g., sensors, microprocessors) of a luminaire must also be built and manufactured with the proper security controls in place. Developers should also review threats involving assets not developed in-house to understand how connectivity with other devices will affect their product during system operation and determine if a compensating control for a defense-in-depth strategy will be needed. Finally, those interested in deploying CLS should compare the differences between cloud and on-premise models to determine which is more suitable for their needs and the abilities of their security team.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Public – Private Partnership to Promote Efficient Manufacturing and Workforce Development (IAC Final Technical Report)

Through delivering ninety (90) energy assessments to small- and medium-sized manufacturing facilities in and around Tennessee, significant understandings were gained through providing detailed energy assessment reports to manufacturers and training seventy-seven (77) engineering students in which thirty-five (35) certified IAC students were recognized by DOE. The robust involvement of Tennessee Valley Authority (TVA), local utility and Tennessee Tech’s Cybersecurity Education, Research, and Outreach Center (CEROC) in majority of assessments made the technical operation very effective where leaded to 40.5% implementation rate of energy recommendations. Other benefits of the award to the public are a dynamic modeling tool capable of analyzing existing cooling towers for energy use optimization was developed and presented to DOE IAC, providing technical assistance to non-participating manufacturers in the form of workshop and training, publishing fifteen (15) peer-reviewed conference and journal papers as well as a book chapter in the area of industrial energy efficiency field, assisting the TVA Magnolia Combined Cycle Power Plant to become the First 50001 Ready Certified Power Plant in the U.S. through briefing them on ISO 50001 and 50001 Ready as well as providing an energy assessment to the plant, assisted the new IAC center at Clemson University with on-site and remote support, and provided assessment and training in unique areas of water, waste water, cyber security and smart manufacturing to our clients, students and community.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗