Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Cybersecurity for Renewables”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Applying the Risk Management Framework: The Distributed Energy Resource Risk Manager

As part of a multiyear effort, the National Renewable Energy Laboratory (NREL) has dedicated resources to understand and identify cybersecurity weaknesses in distributed energy resources (DERs) by performing assessments. Due to a lack of standardization and rapidly increasing adoption of DERs, there is a critical need to address cybersecurity needs for DER systems in an interactive way. Furthermore, federal agencies, which are required to obtain an authority to operate, are challenged by the complexities of including their DERs. To help meet this need, in early 2020, NREL released the Distributed Energy Resources Cybersecurity Framework (DERCF) and accompanying Web application. This process is supported by the Risk Management Framework (RMF) developed by the National Institute of Standards and Technology. This project, referred to as the DERCF RMF application, expands on the existing DERCF work to include methods that support walking a user through the seven RMF steps. The tool will be available for download at no cost from [link ]. The purpose of this paper is to describe the steps the DERCF team at NREL took to understand Steps 1-5 of the RMF process. Additionally, this document will identify future work on the first five steps as well as a plan for Steps 6 and 7.

24 POWER TRANSMISSION AND DISTRIBUTION↗

The NREL Cyber Range

With the National Renewable Energy Laboratory's (NREL's) cyber range, researchers can replicate cybersecurity scenarios as they would occur on real, complex energy systems. With supercomputing and advanced emulation capabilities, the cyber range allows users to build digital twins of real systems and connect the emulated environment to actual physical devices throughout NREL's laboratories. The space offers unlimited potential to test the frontier of energy systems security.

cyber range↗

Cybersecurity Certification Recommendations for Interconnected Grid Edge Devices and Inverter Based Resources

Escalating deployment of PV and grid-edge devices on the distribution grid has increased the sustainability and efficiency of the electric grid. However, the increasing number of distributed energy resources (DERs) deployed creates a heightened cyber-physical interdependency on the distribution grid and thus creates more vectors for cyber-attacks to exploit through information and communication technology (ICT) systems and networks. For example, control signal packets can be modified, intercepted, or corrupted due to vulnerabilities in communication protocols used by microgrid controllers and grid edge devices for power control. Therefore, to mitigate and prevent cyber-attacks on grid edge devices and the inverter-based resources connected to the distribution grid, the U.S. Department of Solar Energy Technologies Office (SETO) awarded funding to the National Renewable Energy Laboratory and Sandia National Laboratory (SNL) to research, develop, and harmonize cybersecurity standards for Photovoltaic (PV) systems and for other kinds of DERs. To help develop a standard for DER cybersecurity, NREL established certification recommendations and test cases, in consensus with the solar industry and UL, for ensuring intrinsic design security for DERs. These recommendations were developed to bolster the cybersecure functionalities such as TLS, MAC, CRL, session resumption/renegotiation, and password, system, and service security management within the DER devices. The proposed test cases verify authentication, authorization, confidentiality, and data integrity for data and communications of DERs that use Transmission Control Protocol/Internet Protocol (TCP/IP). They were also developed to protect DER communications from eavesdropping, replay, man-in-the-middle, denial of service (DoS), spoofing through security certificates, least-privilege violation, and brute-force credentials. This report, which has been validated and reviewed by UL, expands upon those test cases to provide DER cybersecurity certification recommendations which increase DER resiliency and help to mitigate cyber-attacks. UL's collaboration with NREL and approval of this document will accelerate the adoption of a UL standard for DER cybersecurity.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Distribution Cybersecurity: Cybersecurity Considerations of Distributed Resources

This presentation is focused on cybersecurity of the distribution system. It will educate attendees about the evolving cybersecurity threats facing energy infrastructure through exploring relevant cybersecurity incidents. Additionally, Participants will gain an understanding of Distributed Energy Resources and their growing role in grid architecture. Finally, the session will examine critical standards and guidelines, including Cybersecurity Baselines for Electric Distribution Systems and the IEEE 1547.3 standard.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Multilevel Cybersecurity for Photovoltaic Systems

The motivation behind this project is to protect critical infrastructure in electric power generation pertaining to solar photovoltaic (PV) systems. This growing renewable energy resource is becoming a more vital part of the nation’s energy portfolio, particularly since it has achieved grid-parity to existing generation methods in terms of cost. It is thus vital that steps be taken to ensure the cybersecurity of these assets. The project goal was to devise a multilevel cybersecurity solution to address PV security gaps at the inverter and system levels, and field test the solution under the supervision and review of a US-based solar inverter manufacturer and PV installer/operator. A two-level cyberattack defense approach was formulated whereby the first level, the solar inverter level, hardens individual devices and achieves a deeply cyber-secure inverter. The inverter level security involves a multi-layer defense-in-depth approach for securing the inverter while also providing data for the system level algorithms. The second level, the system level, addresses intrusion detection and restoration involving an ensemble of inverters and relevant systems.

14 SOLAR ENERGY↗

A Cyber-Resilience Risk Management Architecture for Distributed Wind

Distributed wind is an electric energy resource segment with strong potential to be deployed in many applications, but special consideration of resilience and cybersecurity is needed to address the unique conditions associated with distributed wind. Distributed wind is a strong candidate to help meet renewable energy and carbon-free energy goals. However, care must be taken as more systems are installed to ensure that the systems are reliable, resilient, and secure. The physical and communications requirements for distributed wind mean that there are unique cybersecurity considerations, but there is little to no existing guidance on best practices for cybersecurity risk management for distributed wind systems specifically. This research develops an architecture for the consideration of cyber risks associated with distributed wind systems. The architecture takes into account the configurations, challenges, and standards for distributed wind to create a risk-focused perspective that considers of threats, vulnerabilities, and consequences, with special emphasis on what sets distributed wind systems apart from other distributed energy resources (DER). We discuss common distributed wind architectures and how they are interconnected to larger power systems. Because cybersecurity cannot exist independently, the cyber-resilience architecture must consider the system holistically. Finally, we discuss the implementation of a risk assessment process that uses the cyber-resilience framework to address challenges specific to distributed wind.

17 WIND ENERGY↗

Distributed Renewables Cyber Resilience

The following article is for Power Magazine, which has initial acceptance by the editor and focuses on presentation of a cybersecurity survey.

42 ENGINEERING↗

Evaluation of IEC 62443 Standard Gaps for Electric Grid Substation Model Use Case

This report presents an evaluation of the IEC 62443 standards in the context of electric grid substations, as part of a collaborative effort among Sandia National Laboratories (SNL), Idaho National Laboratory (INL), and the National Renewable Energy Laboratory (NREL). The primary objective is to assess the applicability of these standards to enhance cybersecurity measures for industrial automation and control systems (IACS) within the energy sector. The evaluation identifies strengths, such as the scalability of security levels and the structured lifecycle guidance provided by IEC 62443. However, it also highlights significant gaps, including limited integration of physical security, insufficient guidance for legacy systems, and challenges in addressing emerging threats like supply chain vulnerabilities. Recommendations for refining the standards are proposed, including the need for tailored guidance for securing legacy systems, integrating physical security with cybersecurity frameworks, and enhancing interoperability across multi-vendor environments. By addressing these gaps, the IEC 62443 standards can be strengthened to ensure comprehensive cybersecurity for electric grid substations, thereby supporting the resilience and reliability of critical energy infrastructure.

24 POWER TRANSMISSION AND DISTRIBUTION↗

FY25 Electric Grid Security Annual Report

Sandia’s Electric Grid Security program advances a national vision of energy dominance and accessibility, while applying our national security -emphasis on ensuring of a secure, resilient, and affordable electric system for all users. Our achievements reflect a strategic approach combining technology development; modeling, simulation, and data analytics; and partnered demonstrations and outreach to further the adoption of advanced grid and storage technologies. Our FY25 efforts leverage the strengths of our partnerships—spanning Sandia’s core science and technology competencies as well as external technology leaders—to develop the solutions today which enable the grid of tomorrow. Key accomplishments in this report that support our strategy span our technical program areas and include: • New open-source analytical tools for systems -level planning and optimization, including significant advances to the QuESt analytical environment; • Further advancement of artificial intelligence and machine learning to enhanced grid operations and planning as we rise to the challenge of new large loads; • Development of solid-state power conversion technologies and a new medium-voltage research lab; • New technologies to assess wildfire vulnerabilities and mitigate potential impacts; • Advanced applications of new cybersecurity technologies with industry partners; • Contributions to understanding the impacts of electromagnetic pulses and geomagnetic disturbances on grid components; and • Digital twin development for hybrid microgrids with multiple generators, storage, and loads. This report indicates key areas of research and engagement and summarizes the impact of Sandia’s contributions through notable accomplishments, journal publications, patents, and technical conferences and presentations. It is provided with the hope that readers discover ways we can further team to create our modern grid and apply the outcomes of our efforts. The bulk of work described herein is funded by several offices within the U.S. Department of Energy (USDOE), including the Office of Electricity (OE); Cybersecurity, Energy Security, and Emergency Response (CESER); former offices such as the Office of Energy Efficiency and Renewable Energy (EERE), the Grid Deployment Office (GDO), the Office of Clean Energy Demonstrations (OCED), and other key programs at USDOE. As we continue to state in these annual reports, the contributors to our successes are too numerous to name here, though our team wishes to express our deep gratitude to the numerous program and project sponsors at the US Department of Energy, who often function equally as technical collaborators; our many partners in industry, academia, utilities, and other national labs; and fellow researchers and business partners at Sandia whose leadership and creativity have enabled the accomplishments described herein.

24 POWER TRANSMISSION AND DISTRIBUTION↗

The Distributed Energy Resource Risk Manager

Organizations need a comprehensive approach to managing security and privacy risks, especially for energy resources that are becoming increasingly distributed. A tool by the National Renewable Energy Laboratory (NREL) makes it possible to manage these risks and maintain the highest standards of cybersecurity. To simplify risk management for facilities and distributed energy resources, NREL has created the Distributed Energy Resource Risk Manager, an automated, user-friendly tool that helps navigate and implement one of the most widely trusted frameworks for information security, the National Institute of Standards and Technology Risk Management Framework.

compliance↗

Reliability and Resiliency in South Asia's Power Sector - Pathways for Research, Modeling, and Implementation

Reliability and resilience are the core principles of power system planning and operations around the world. Power systems in South Asia are transforming with increasing penetration of clean energy generation resources, emerging technologies, increasing electricity demand and electrification. At the same time, these power systems are facing challenges posed by extreme weather events and climate change. All these factors would add furthermore importance to the reliability and resilience of future power systems in South Asia. This has motivated us to better understand the country specific challenges and chalk out the pathways for research, modelling and implementation in South Asia. Our research, experience in the region and feedback from key stakeholders indicate following as the key areas where more work is needed to improve reliability and resilience of power systems in the region: Renewable energy Data for power system studies, New Tools and Studies, Resilience Planning, Resource Adequacy, Advanced RE Forecasting, Cybersecurity, Load Forecasting, and Coordinated Planning and Operations.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Cybersecurity Considerations for Hydrogen Infrastructure in Airport Environments

This report explores key cybersecurity concerns and best practices within environments that serve as reference points for the development of hydrogen fueling infrastructure for aviation. This cybersecurity analysis leverages prior NREL studies: 1) hydrogen fueling station component validation to identify vulnerabilities and failure events documented in physical equipment, and 2) electric aircraft charging infrastructure analysis to explore primary cybersecurity vulnerabilities. It reviews the criticality of digitized technologies in sustaining hydrogen fuel production, storage, and fueling systems, noting cybersecurity concerns that are universal to power systems and industrial control systems in general. In considering cybersecurity vulnerabilities within a future landscape of hydrogen energy for aviation applications, a reference architecture was intended to reveal the points of connection between assets and the potential sensors that are vulnerable to manipulation in the event of compromised access or communication within a SCADA system. A generalized reference architecture can help stakeholders, engineers, or strategists understand connections, criticalities, and standard practices when it comes to designing and planning for new systems. There are several gaps to account for in assessing the future of hydrogen production, storage, and fueling for aviation. Engaging stakeholders, including aircraft manufacturers, electric utilities, site property owners, and local communities, will inform decision-making around site structure, operations, and resources for future hydrogen fueling infrastructure to understand operational needs and cybersecurity awareness. Cybersecurity mitigation strategy must consider physical attack vectors that emerge with the integration of hydrogen systems into existing airport security requirements. The cybersecurity risk assessment contained in this report is an entry point into potential future granular-level analyses to be conducted as part of hazard and risk assessments for safe aviation hydrogen infrastructure, determining how the scale of hydrogen fuel infrastructure for aviation impacts the volume of cyber attack vectors, and what, if any, are the vulnerabilities associated with different types of on-board hydrogen systems. In this nascent development phase, assessing how best to integrate cybersecurity practices into an evolving U.S. aviation landscape provides critical insights into building increased awareness and stakeholder engagement to support a cyber-resilient infrastructure.

08 HYDROGEN↗

Threats to DERs and Tools to Mitigate Them

As the pace of renewable energy development increases, so does the challenge and opportunity to develop innovative solutions to secure renewable technologies. Four national laboratories National Renewable Energy Laboratory, Sandia National Laboratories, Pacific Northwest National Laboratory, and Idaho National Laboratory are working together to increase cybersecurity maturity levels for solar stakeholders. INL will discuss a DER threat briefing and operator tools and training developed under the Securing Solar for the Grid (S2G) project.

14 SOLAR ENERGY↗

Master Services Agreement - Flexible Feeder/Distribution System Support: Cooperative Research and Development (Final Report)

PGE will engage NREL on a broad range of projects related to the integration of distributed energy resources (DERs) into the utility's operations. This portfolio of work could include projects focused on DER adoption models, advanced distribution management system (ADMS) and distributed energy management system (DERMS) design, DER dispatch strategy development, and DER valuation framework development. Additional topics could include long-term energy planning, renewable energy, energy efficiency and demand-side management. As well as technology evaluations and design guidance for building retrofits and new construction projects, energy and energy infrastructure planning, policies, and markets (and their analysis), energy storage, energy security and resilience (including energy system-related cybersecurity), transportation and mobility, technology integration analysis. Additionally, other assistance as requested by PGE consistent with NREL’s expertise.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Identification and Testing of Electric Vehicle Fast Charger Cybersecurity Mitigations

Fast-charging infrastructure for electric vehicles (EVs) is needed to enable and achieve the national goals of transitioning the vehicle fleet toward more electrification. Idaho National Laboratory, Oak Ridge National Laboratory, and the National Renewable Energy Laboratory (NREL) have jointly worked to identify, evaluate, and mitigate potential cyber-related consequences associated with fast charger systems. NREL contributed by considering cyberattack scenarios and consequences associated with integrating distributed energy resources (DERs) at fast-charging stations. The dynamic nature of fast-charger load profiles would encourage site operators to incorporate solar for energy cost reduction and energy storage for peak demand cost management at future charging facilities with multiple fast chargers at a site. These energy resources would be monitored and coordinated via a site energy management controller with data exchange between devices and local power metering infrastructure; thus, networking between devices and the design of the system becomes important in the overall cybersecurity posture. In addition, component vendors and system operators might have remote interfaces to any of these systems. It is therefore important to understand the breadth of the cyberattack surface and potential strategies to mitigate impacts. This project has focused on components and protocols expected to be found within a local charging site that includes multiple chargers and DER resources. Our methods and results are summarized in this final report.

42 ENGINEERING↗

Critical Energy Infrastructure Cybersecurity: Enhanced Cyber Resilience for Federal Energy Systems

This presentation is an overview of FEMP Resilient and Secure Infrastructure and Facilities. An educational and interactive workshop centered on resilient and secure federal infrastructure and facilities, with a focus on inverter-based resources at Federal sites, building automation systems, and Federal supply chains. This workshop will illustrate an all-hazards scenario and discuss how Federal agencies can be positioned to resist these real-world scenarios.

97 MATHEMATICS AND COMPUTING↗