Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “cybersecurity risk”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 361 records · Page 20

ARIES Annual Report FY25

Advanced Research on Integrated Energy Systems (ARIES) at the National Laboratory of the Rockies (NLR) is the U.S. Department of Energy's (DOE's) test bed for energy system demonstration and de-risking. ARIES comprises the largest collection of physical and digital assets in the DOE laboratory complex, supporting flexible configuration across a broad range of energy scenarios. In Fiscal Year 2025, ARIES provided a platform for system-level research to anticipate and address future energy needs in energy security, system reliability, and technology deployment.

24 POWER TRANSMISSION AND DISTRIBUTION↗

CPES-QSM: A Quantitative Method Towards the Secure Operation of Cyber-Physical Energy Systems

Power systems are evolving into cyber-physical energy systems (CPES) mainly due to the integration of modern communication and Internet-of-Things (IoT) devices. CPES security evaluation is challenging since the physical and cyber layers are often not considered holistically. Existing literature focuses on only optimizing the operation of either the physical or cyber layer while ignoring the interactions between them. This paper proposes a metric, the Cyber-Physical Energy System Quantitative Security Metric (CPES-QSM), that quantifies the interaction between the cyber and physical layers across three domains: electrical, cyber-risk, and network topology. A method for incorporating the proposed cyber-metric into operational decisions is also proposed by formulating a cyber-constrained AC optimal power flow (C-ACOPF) that considers the status of all the CPES layers. The C-ACOPF considers the vulnerabilities of physical and cyber networks by incorporating factors such as voltage stability, contingencies, graph-theory, and IoT cyber risks, while using a multi-criteria decision-making technique. We note that simulation studies are conducted using standard IEEE test systems to evaluate the effectiveness of the proposed metric and the C-ACOPF formulation.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Security Evaluation of Smart Cards and Secure Tokens: Benefits and Drawbacks for Reducing Supply Chain Risks of Nuclear Power Plants

The supply chain attack pathway is being increasingly used by adversaries to bypass security controls and gain unauthorized access to sensitive networks and equipment (e.g., Critical Digital Assets). Cyber-attacks targeting supply chain generally aim to compromise the environments, products, or services of vendors and suppliers to inject, add, or substitute authentic software and hardware with malicious elements. These malicious elements are deemed to be authentic as they arise from the vendor or supplier (i.e., the supply chain). This research aims to leverage findings and assumptions made from the previous report to determine the security benefits and drawbacks of a smart card- based hardware root of trust. Smart cards can provide devices inside Nuclear Power Plants (NPP) with a secure environment to store keys in and perform sensitive operations such as digital signature generation. These abilities can be leveraged to increase supply chain cybersecurity by autonomously providing NPP Licensees with reports on device integrity, authenticity and measurements of executable and non-executable data.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Addressing Rising Energy Demand Through Innovation

The U.S. is facing a significant increase in energy demand, driven by AI advancements, the rapid expansion of data centers, manufacturing and industrial growth, and the electrification of transportation and buildings. Buildings alone account for approximately 75% of U.S. electricity consumption and 40% of total energy use. To address these challenges, NLR leverages its state-of-the-art research facilities, advanced energy modeling, hardware-in-the-loop emulation, and real-world demonstrations to provide data-driven insights that de-risk emerging energy solutions, increase efficiency and demand flexibility, optimize grid controls, and identify vulnerabilities to enhance energy security. This presentation will highlight our research ecosystem and its role in supporting a more reliable, affordable, and adaptive energy infrastructure in the face of accelerating demand.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

CyOTE ASSET OWNER ENGAGEMENT – SIDE CHANNEL POWER ANALYSIS PROTOTYPE

The U.S. Department of Energy’s (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER), through the Cybersecurity for the Operational Technology Environment (CyOTE) Program, worked with energy sector asset owners and operators (AOOs), partners, and Idaho National Laboratory (INL) to develop capabilities for AOOs to independently identify adversarial tactics, techniques, and procedures (TTPs) within their operational technology (OT) environments. The CyOTE methodology seeks to identify adversarial techniques within an AOO OT environment that could result in physical disruptions to energy flow or damage to equipment. CyOTE provides a general roadmap for AOOs, starting from a triggering event, or the point in time and space they perceive an anomalous event or condition meriting investigation, and culminating when the AOO has sufficient confidence to make a business risk decision on the appropriate resolution. This paper outlines the results of one such engagement with the New York Power Authority (NYPA), where the CyOTE program partnered with an AOO to develop a design specification for a power side channel detector to identify anomalous changes to device load. It describes the goal of developing this capability, the development process, the challenges the technical teams faced and the future steps an AOO will need to take to install and use this detector in its OT environment.

99 GENERAL AND MISCELLANEOUS↗

Advanced Reactor Control Systems Authentication Methods and Recommendations

In the dynamic landscape of Operational Technology (OT), and specifically the emerging landscape for Advanced Reactors, the establishment of trust between digital assets emerges as a challenge for cybersecurity modernization. This report reviews existing approaches to authentication in Enterprise environments, and proposed methods for authentication in OT, and analyzes each for its applicability to future Advanced Reactor digital networks. Principles of authentication ranging from underlying cryptographic mechanisms to trust authorities are evaluated through the lens of OT. These facets emphasize the importance of mutual authentication in real-time environments, enabling a paradigm shift from the current approach of strong boundaries to a more malleable network that allows for flexible operation. This work finds that there is a need for evaluation and decision making by industry stakeholders, but current technologies and approaches can be adapted to fit needs and risk tolerances.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Operation and Maintenance of PV Systems: Data Science, Analysis, and Standards

This effort improves the effectiveness and reduce uncertainty in O&M cost through four primary objectives/tasks: 1) institutionalize standards for reliability and availability reporting for large PV power plants; 2) bridge systemic O&M knowledge gaps around important topics affecting O&M; 3) characterize systemic failure modes and patterns and accelerate O&M experiential learning cycles using field data; and 4) establish a baseline understanding of UPVS O&M cost drivers. Key results of this effort include publication of IEC standards, published topical papers on O&M topics, training, and characterize field data for climate- and service-related patterns (additional details below). Integrating these results serves to reduce performance risk and facilitate improvement in the way solar projects are operated and maintained. Results are well received and two publications are among the most successful SETO publications at NREL ("Model of Operation and Maintenance Costs for Photovoltaic Systems with over 40,000 downloads and "Best Practices in Operation and Maintenance of PV Systems, 3rd Ed." with over 90,000 downloads).

14 SOLAR ENERGY↗

Smart Inverters, Dumb Risk: Taking Control of IBR Security in the Digital Age

This presentation addresses the security challenges posed by Inverter-Based Resources (IBRs) in the modern energy landscape. The presentation highlights the vulnerabilities and risks associated with IBRs, including the potential for cyber-attacks, the impact of insecure defaults, and the systemic risks posed by supply chain dependencies. Key topics covered include: 1) The increasing digital transformation in energy systems and the associated security risks. 2) Specific vulnerabilities in IBRs, including weak passwords, hardcoded credentials, and insecure web application interfaces. 3) The implications of persistent connectivity and the strategic risks posed by foreign-manufactured components. 4) The role of regulatory frameworks, such as NERC CIP, in addressing these challenges and the limitations of current oversight. 5) Practical solutions for mitigating risks, including secure design practices, vendor risk assessments, and the importance of strong passwords and role-based access control. The presentation underscores the necessity of a comprehensive, system-of-systems approach to securing IBRs, emphasizing the need for collaboration across various stakeholders, including operators, developers, and regulators, to ensure the resilience and security of the energy grid.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

A Computational Review of Privacy-Preserving Mechanisms for the Smart Grid

Smart grid technologies have rapidly become one of the largest and most comprehensive sources of data for the modern utility. For the most part, data streams are seen as an essential tool that enable utilities to carry their day-to-day business operations, but they also create the need for efficient and secure data management strategies. In the context of the smart grid, ensuring data privacy is becoming an increasing concern due to a combination of factors that range from shifts in operational paradigms and rapid technology evolution to changes in legislation. Furthermore, researchers have highlighted the risks associated with improperly protected energy records. For example, energy consumption data from homes could be used to infer the behaviors and habits of home occupants through activity recognition or user profiling (Fan, 2017), which may lead to unfair service pricing, targeted advertising, or other personal security violations. Similarly, Electric Vehicles’ (EVs) charging metadata could be used to reveal private information about the owner such as their payment methods, preferred charging stations, and other locational and timing information that could be used to reconstruct the vehicle owner’s behaviors. The privacy of user data, even when used for statistical analysis or machine learning training processes, also needs to be carefully considered, as an individual’s private traits may still be vulnerable if their inclusion/exclusion greatly impacts the result or could be linked to a public dataset through cross-reference. The breach of user privacy also has severe impacts for organizations that store, transmit, or work on the data in the form of diminishing the public’s trust in them while potentially incurring legal consequences (e.g., fines and suspensions under the European Union General Data Protection Regulation, Health Insurance Portability and Accountability Act, etc.). Because of these risks, several privacy-preserving mechanisms are available to help organizations comply with privacy legislations and prevent the unauthorized and malicious use of user data. In light of these concerns, this report focuses on performing a computational review of privacy-preserving mechanisms that have received a significant amount of interest in literature. It specifically focuses on 1) homomorphic encryption, 2) zero-knowledge proofs, 3) differential privacy, and 4) federated learning. It is worth noting that although many of the methods presented in this document rely on cryptographic primitives, their intent is not to provide perfect secrecy, but rather to enable users to maintain privacy, and thus they shall not be compared or equated to other constructs that are aimed to address cybersecurity constructs.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Enhancing Cloud Cybersecurity: Prescriptive Controls for Operational Technology

This whitepaper provides strategic insights and recommendations into security cloud-based solutions for electric utilities, encompassing operational technology (OT), virtual power plants (VPP), distributed energy resources (DERs), applications, networks, and data storage as they transition to and leverage cloud infrastructure through managed service providers (MSPs) and cloud service providers (CSPs). Principles derived from established frameworks serve as a foundation for best practices across cybersecurity projects and remove the constraints of settling on a single framework. For organizations that prefer not to integrate a specific framework altogether, elements of the proposed approach could be adopted or tailored to best fit defined requirements and expected functionalities. The Cirrus assessment, a utility cloud feasibility tool, and the roadmap it provides serve as a precursor to this paper, which seeks to be a valuable resource for defining next steps following cloud technology integration feasibility appraisal. With its comprehensive approach to adoption, the Cirrus framework offers strategic guidance on responsibly preparing for or deploying a utility cloud solution. The previously published whitepaper, “Use Case-Informed Framework for Utility Cloud Migration,” details the guiding strategy, research, and deployment of cloud solutions within electric and interconnected grid systems. Before implementing the controls suggested in this document, it is recommended that stakeholders complete Cirrus's cloud integration assessment and pair the results with their unique cybersecurity controls to form a comprehensive cloud-based utility cybersecurity plan. The Cirrus outcome will consider a series of future architectures for the grid before and after the energy transition and evaluate the arguments for and against cloud applications for each electric and interconnected grid layer. This document is a companion to the original whitepaper, "Use Case-Informed Framework for Utility Cloud Migration" to further identify and recommend security controls based on Cirrus’s cloud integration assessment output. The following whitepaper outlines the cybersecurity controls that secure cloud-service models pertinent to the electric sector using the predefined categories identify, protect, detect, and respond and recover. The objective is to outline prescriptive security controls based on the type of architecture and data stored in the cloud. The focus includes dissecting the shared responsibility model and elucidating what on-premises Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) entail. A pivotal consideration in this context is allocating responsibility for foundational cybersecurity aspects—having used Cirrus for the cloud integration assessment. The ensuing controls detailed herein also represent a checklist of controls necessary for a secure cloud transition, equipping utilities with the knowledge to navigate this digital transformation with confidence and strategic foresight in a safe and responsible manner.

42 ENGINEERING↗

Cyber-Informed Engineering Briefing for ABET

Cyber-Informed Engineering (CIE) is an emerging method to integrate cybersecurity considerations into the conception, design, development, and operation of any physical system, energy or otherwise, to mitigate or even eliminate avenues for cyber-enabled attacks.?CIE concepts use design decisions and engineering controls to prioritize defense against the worst possible consequences of cyberattacks facing critical infrastructure systems and asset owners. These slides offer a deep dive into Cyber-Informed Engineering for engineering educators.

42 - ENGINEERING↗

ARCADE Analysis Methods & Validation Pathway

The Advanced Reactor Cyber Analysis and Development Environment (ARCADE) provides an automated analysis system which supports risk-informed performance based (RIPB) evaluations of nuclear control systems. Every possible cyber threat which could lead to consequence is identified by simulating the unsafe control action sequences which transform digital harm into physical harm. Eliminating the simulation of complex digital cyber attack chains cuts out unnecessary computational overhead and focuses directly on the physics of cyber-physical attacks. This focus enables designers to make informed decisions which can entirely eliminate categories of cyber threats against advanced reactors through the physical nature of the plant design. This narrowing of cyber threat against nuclear power plants through the physics of the system is intended to make any remaining threat management and cost efficient. This is the goal of the Tiered Cyber Analysis (TCA) outlined in NRC Draft Regulation Guide (RG) 5.96, which provides a RIPB cybersecurity approach for new reactors. ARCADE has been custom developed to meet the demands of the rigorous analysis required in Tier 1 of the TCA, which forms the foundation of the TCA process. Currently, ARCADE is still under development, but has made significant leaps in capability. A pilot analysis on the opensource Asherah simulator was performed which demonstrated key functionality goals. The next stage of ARCADE development involves improvements to the applications which support the analysis system, and enabling the analysis system to utilize the full suite of unsafe control action simulations. Since the analysis method’s core functions are complete, validation of the analysis method will be started concurrent to the next development stages. The automated analysis ARCADE will provide can radically change the cybersecurity design process for advanced reactors, reducing the cost of security implementation while enhancing cyber resilience. The pathway for ARCADE’s development to this goal has become much clearer. The majority of technical hurdles have been cleared, and the remaining development needs have been solidified. ARCADE is now capable of assisting the advanced reactor design process and directly support advanced reactor industry RIPB practices.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Security Architecture for Microgrid Integration

The purpose of this document is to present cyber security risk considerations and mitigations for community microgrids. The mitigations discussed herein specifically focus on cyber security technical requirements for the De-centralized Autonomous Community Controller (DAC) as part of the SECURE project’s technology development effort. These requirements also consider the associated security implementation challenges involved with the decentralized characteristics of microgrids where upstream communications to utility security management functions are lost. These security recommendations and technical requirements may be used by microgrid implementers and technology vendors to specify the security design of the microgrid systems and their components.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Assessment of Cloud-Based Applications Enabling a Scalable Risk-Informed Predictive Maintenance Strategy Across the Nuclear Fleet

The current light water reactor fleet uses time-based or failure-based maintenance strategies to achieve high-capacity factors. But to make nuclear more competitive in the energy market, these reactors could utilize emerging technologies in terms of artificial intelligence (AI) and cloud computing to enable a cost-effective, predictive maintenance strategy. This report examines the feasibility of cloud computing for the nuclear industry’s needs in terms of the cloud’s computing capabilities, feasibility, and regulatory concerns. The technical viability of cloud computing was analyzed using one year worth of data from a boiling water reactor’s safety relief valve. Models were hosted on a local desktop, Idaho National Laboratory’s high-performance computer, and Microsoft Azure. Data was loaded, processed, and two types of models were trained in an A/B fashion. Based on the speed at which these actions were completed, it was used to determined that cloud computing has adequate computing resources. Additionally, the computing power can scale with the demanded load. To enable cloud computing in the existing fleet, additional sensors, networks, and other requirements must be implemented to ensure a smooth transition from current maintenance strategies. However, there is a benefit as the plant no longer needs manage their own servers, software, cybersecurity, and IT support staff. Many of these features can be offloaded on to the cloud provider. A comprehensive analysis was completed that showed the current annual cost of operating is more expensive than using cloud computing resources. Lastly, the regulatory framework does not explicitly address AI or autonomous control. Currently, the NRC and other regulatory bodies are evaluating providing guidance to address gaps rather than new regulations to address the use of AI and ML. But since many of the AI applications are focused on non-safety related applications, such as balance-of-plant components, they will likely have little or no regulatory restrictions or necessary approvals. Demonstrating how AI can improve maintenance and operation of these non-safety related systems seems like the likely path forward for implementing AI and cloud computing resources inside nuclear power plants (NPPs).

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Grid Energy Storage: Supply Chain Deep Dive Assessment

The report “America’s Strategy to Secure the Supply Chain for a Robust Clean Energy Transition” lays out the challenges and opportunities faced by the United States in the energy supply chain as well as the Federal Government plans to address these challenges and opportunities. It is accompanied by several issue-specific deep dive assessments, including this one, in response to Executive Order 14017 “America’s Supply Chains,” which directs the Secretary of Energy to submit a report on supply chains for the energy sector industrial base. The Executive Order is helping the Federal Government to build more secure and diverse U.S. supply chains, including energy supply chains. To combat the climate crisis and avoid the most severe impacts of climate change, the U.S. is committed to achieving a 50 to 52 percent reduction from 2005 levels in economy-wide net greenhouse gas pollution by 2030, creating a carbon pollution-free power sector by 2035, and achieving net zero emissions economy-wide by no later than 2050. The U.S. Department of Energy (DOE) recognizes that a secure, resilient supply chain will be critical in harnessing emissions outcomes and capturing the economic opportunity inherent in the energy sector transition. Potential vulnerabilities and risks to the energy sector industrial base must be addressed throughout every stage of this transition. The DOE energy supply chain strategy report summarizes the key elements of the energy supply chain as well as the strategies the U.S. Government is starting to employ to address them. Additionally, it describes recommendations for Congressional action. DOE has identified technologies and crosscutting topics for analysis in the one-year time frame set by the Executive Order. Along with the capstone policy report, DOE is releasing 11 deep dive assessment documents, including this one, covering the following technology sectors: carbon capture materials; electric grid including transformers and high voltage direct current (HVDC); energy storage; fuel cells and electrolyzers; hydropower including pumped storage hydropower (PSH); neodymium magnets; nuclear energy; platinum group metals and other catalysts; semiconductors; solar photovoltaics (PV); and wind. DOE is also releasing two deep dive assessments on the following crosscutting topics: Commercialization and competitiveness; and cybersecurity and digital components. More information can be found at www.energy.gov/policy/supplychains.

25 ENERGY STORAGE↗

Cyberattack Scenarios for the Rancor Microworld Simulator

The digitization of new generation nuclear power plants increases the risk of cyber-physical attacks. Hence, the collection of data from operators that respond to realistic cyberattacks can provide a paramount insight on the correlation of cyber evidence and physical alerts. The simplicity and configurability of the Rancor Microworld Simulator, enables the training of non-expert operators in a PWR environment, and the extensive and tailored collection of data. Therefore, we develop the necessary tools and infrastructure in Rancor that allow such attacks to take place. Additionally, we perform these attacks to examine the attention and situation awareness of operators during malicious infiltrations.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

DSS Security Assessment

The Discovery and Synchronization service (DSS) has implemented some reasonable technical controls that help improve security and there are very few technical findings. The use of Docker and Kubernetes helps simplify the deployment process, and the DSS uses mutual TLS (mTLS) to connect. Much of the security risk across the DSS is a factor of its nature, a distributed environment that relies on all members to secure their parts correctly. As such, the DSS team should attempt to emphasize security controls that reduce complexity for securing entities’ Cockroach DB (CRDB) instances properly and improve coordination among DSS members for things like security patching, incident response, detecting, and removing bad actors. The DSS team must recognize that operating a DSS instance securely will require a combination of technical and procedural controls. Each DSS entity must configure their instance properly and follow standard operating procedures to ensure that the DSS service is secure.

threat modeling↗

Automation for Distributed Energy Resources Risk Manager Using OSCAL

The risk management framework (RMF) provides a well-organized and thorough approach to diagnose information technology (IT) system threats, to gather required materials to comply with industry standards, and to document a plan for achieving authority to operate (ATO). ATO is given by the operating authority with the awareness of vulnerabilities that arise when operating the IT system. The primary goal of the National Renewable Energy Laboratory’s (NREL’s) distributed energy resource (DER) RM application is to provide a user-friendly interface and in-depth guidance for generating the authorization package for the authorizing official to review. In other words, the application satisfies steps 1 through 7 of the RMF process with a focus on DERs.

cybersecurity↗