Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “DER security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Hardware-in-the-loop Testing of Network Protectors for Low-Voltage Networks with Distributed Energy Resources

In this report, we developed and validated a network protector relay digital twin model and interfaced a commonly used network protector relay hardware with our real-time simulation system. Hardware-in-the-loop protection studies are performed to assess the impact of distributed energy resources (DER) and benchmark a rate-of-change-based mitigation strategy. Simulation results suggest that the network protector reverse trip and auto-reclose functions are negatively impacted by the high distributed energy resource penetration. To accommodate DER backfeed while remaining secure and reliable for faults on primary feeders, we recommend options for a rate-of-change-based blocking scheme and a protection setting change. Finally, future mitigation ideas and standard revisions are discussed.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Standards Library for Distributed Energy Resources

This presentation was presented at the Aggregation and Grid Security Workshop - held on June 17-18, 2025, at NREL in Golden, Colorado. The goal of the two-day workshop was to address the critical cybersecurity challenges for the future electric grid. This presentation overviews the evolution and need for harmonized distributed energy resource standards and a new distributed energy resource standards library.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Cyber‐Resilient Distributed Energy Resource Control Algorithms for Smart Distribution Grids

ABSTRACT This paper focuses on the development of cyber‐resilient gradient‐based optimisation algorithms and theoretical proof for grid‐interactive distributed energy resource (DER) control to enable two grid services of virtual power plants (VPPs) dispatch and grid voltage regulation, considering the communication and security impacts. Firstly, the combined DER dispatch and voltage regulation as a real‐time gradient‐based optimisation problem is recapped. Thereafter, we consider a probabilistic traffic model to characterise packet delays and loss in a communication network, and study how the delays enter the process of information exchange among the grid measurement units, local DER controllers and the grid control centre that execute this control algorithm in a coordinated manner. Then, a strategy combining delay thresholds and message update rules is proposed to immunity the asynchrony resulting from the communications traffic and it avoids possible numerical instabilities and sensitivities of the power tracking and voltage regulation capabilities, resulting as cyber‐resilient DER control algorithms. Additionally, their convergence is theoretically proved. Effectiveness of proposed cyber‐resilient algorithms has been validated on the IEEE 37‐bus system in terms of convergence, VPP tracking and voltage regulation performance for smart distribution systems with high penetration of DERs.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Achieving Cyber-Resilience for Power Systems using a Learning, Model-Assisted Blockchain Framework

The secure integration and management of distributed energy resources (DER) and power aggregators in the electric grid requires secure communications and a physics-aware Command and Control (C2) strategy. A Blockchain (BC)-based overlay network was developed to provide a security layer for the existing power grid network that mitigates risks in current and legacy network and C2 protocols. By integrating a Model-Assisted Machine Learning (MAML) framework with a Secure Blockchain Overlay Network (SBON) a defense-in-depth strategy was achieved. In our approach, the MAML framework leveraged a smart contract framework to gather network data and learn the dynamics of DER to develop detection strategies for attacks targeting sensors and actuators used by DER. The MAML framework learned dynamical systems models for individual DERs to detect sensor attacks. For DER we utilized a Digital Twin (DT) to accelerate the learning process for a model resistant to stealthy attacks. The project created DT for PV inverters and BESS. The DTs were coupled with a model-assisted, data-driven learning of DER behavior. Specifically, we evaluated architectures for model-based learning with model-free fine-tuning. Additionally, differential privacy techniques were used to obfuscate data, while still allowing the computation of attack detection results based on obfuscated data. The SBON developed leverages a private permissioned blockchain network orchestrated with the Hyperledger Fabric framework. To connect the cyber world, which orchestrates the blockchain fabric, and the physical world where the power network resides, we developed a system implementation to enable the secure interaction of the physical world and the abstracted blockchain.

97 MATHEMATICS AND COMPUTING↗

A Hybrid Data-Driven and Model-Based Anomaly Detection Scheme for DER Operation

This paper proposes a hybrid data and model-based anomaly detection scheme to secure the operation of distributed energy resources (DERs) in distribution grids. Data-driven autoencoders are set up at the edge device level and they use local DER operational data as inputs. The abnormal statuses are detected by analyzing reconstruction errors. In parallel, modelbased state estimation (SE) is set up at the central level and it uses system-wide models and measurements as data inputs. The anomalies are identified by analyzing measurement residuals. The hybrid scheme preserves the benefits of both data-driven and model-based analyses and thus improves the robustness and the accuracy of anomaly detection. Numerical tests based on the model of a real distribution feeder in Southern California highlight the proposed scheme's effectiveness and benefits.

anomaly detection↗

A Hybrid Data-Driven and Model-Based Anomaly Detection Scheme for DER Operation: Preprint

This paper proposes a hybrid data and model-based anomaly detection for securing the operation of distributed energy resources (DERs) in distribution grids. Data-driven autoencoders (AE) are set up at the edge level by taking local DER data and detect anomalous operations by leveraging the reconstruction ability. In parallel, model-based state estimation (SE) is running at the system level by taking system models and measurements, the anomalies are identified by analyzing the measurements residual. The hybrid scheme preserves the benefits of both data-driven and model-based analysis and thus improves the robustness and accuracy of anomaly detection. It can be established by getting full use of the existing infrastructures in distribution grids. Numerical tests on a realistic distribution feeder in Southern California highlight the effectiveness as well as benefits of the proposed scheme.

anomaly detection↗

Cyber Physical Grid-Interactive Distributed Energy Resources Control for VPP Dispatch and Regulation

This paper presents a cyber-physical algorithm for grid-interactive Distributed Energy Resource (DER) control to enable two features of Virtual Power Plants (VPPs) dispatch and grid voltage regulation, considering the communication and security impacts. We first formulate the DER dispatch problem as a real-time, iterative, and grid-interactive DER control problem. Thereafter, we consider a probabilistic traffic model to characterize packet delays and loss in a communication network, and study how the delays enter the process of information exchange among the grid measurement units, local DER controllers and the grid control center that coordinately execute this dispatch algorithm. Finally, a strategy combining delay threshold and modified message update rules is proposed to immune the asynchrony resulting from the communications network traffic and it avoids possible numerical instabilities and sensitivities of the tracking and regulation capabilities of this DER control algorithm. By implementing the proposed cyber-physical algorithm on the modified IEEE 37-node system, our preliminary results exhibit that the uncertainties of the underlying communications infrastructure must be considered for the VPP tracking and regulation capabilities of any DER in a generic Cyber-Physical System (CPS), because the delayed voltage measurements in the uplink/bi-link cases result in the off-track in VPP dispatch and jittery in voltage regulation.

cyber-physical algorithm↗

Cyber Physical Grid-Interactive Distributed Energy Resources Control for VPP Dispatch and Regulation: Preprint

This paper presents a cyber-physical algorithm for grid interactive DER control to enable two features of Virtual Power Plants (VPPs) dispatch and grid voltage regulation, considering the communication and security impacts. We first formulate the DER dispatch problem as a real-time, iterative, and grid-interactive DER control problem. Thereafter, we consider a probabilistic traffic model to characterize packet delays and loss in a communication network, and study how the delays enter the process of information exchange among the grid measurement units, local DER controllers and the grid control center that coordinately execute this dispatch algorithm. Finally, we propose a cyber-physical grid-interactive DER control algorithm using the previous message strategy. The tracking and regulation capabilities of this proposed algorithm can be made immune to the asynchrony resulting from the communications network traffic. We carry out simulations to show possible numerical instabilities and sensitivities of the tracking and regulation capabilities on the proposed strategy. Our results exhibit that the uncertainties of the underlying communications infrastructure must be considered in the control algorithm for the VPP tracking and regulation capabilities of any DER in a generic Cyber-Physical System (CPS).

co-simulation↗

Assessing DER Network Cybersecurity Defences in a Power-Communication Co-Simulation Environment

Increasing penetrations of interoperable distributed energy resources (DER) in the electric power system are expanding the power system attack surface. Maloperation or malicious control of DER equipment can now cause substantial disturbances to grid operations. Fortunately, many options exist to defend and limit adversary impact on these newly-created DER communication networks, which typically traverse the public internet. However, implementing these security features will increase communication latency, thereby adversely impacting real-time DER grid support service effectiveness. In this work, a collection of software tools called SCEPTRE were used to create a co-simulation environment where SunSpec-compliant PV inverters were deployed as virtual machines and interconnected to simulated communication network equipment. Network segmentation, encryption, and moving target defence security features were deployed on the control network to evaluate their influence on cybersecurity metrics and power system performance. The results indicated that adding these security features did not impact DER-based grid control systems but improved the cybersecurity posture of the network when implemented appropriately.

97 MATHEMATICS AND COMPUTING↗

Named Data Networking for DER Cybersecurity

We present our research findings on the novel NDN protocol. In this work, we defined key attack scenarios for possible exploitation and detail software security testing procedures to evaluate the security of the NDN software. This work was done in the context of distributed energy resources (DER). The software security testing included an execution of unit tests and static code analyses to better understand the software rigor and the security that has been implemented. The results from the penetration testing are presented. Recommendations are discussed to provide additional defense for secure end-to-end NDN communications.

97 MATHEMATICS AND COMPUTING↗

Cybersecurity Workforce Training for SMR Integration into Distribution Grids: A Competency Framework and Containerized Hands-On Lab for the SMR/DER/Microgrid Boundary

Small modular reactors (SMRs) and microreactors are entering the U.S. distribution grid as synchronous generation on feeders designed for loads and inverter-based distributed energy resources (DERs). No existing cybersecurity training program addresses this intersection of nuclear operations, DER management, and operational technology security. As subcontractor to Iowa State University on the CyDERMS Center, Argonne analyzed the relevant standards and training landscape, translated the resulting gaps into a twelve-objective competency framework across distribution-operator and graduate-analyst role tracks, and built a containerized training lab using a ∼400-bus composite grid model behind a realistically simulated Modbus TCP SCADA stack. The analysis isolates the balance-of-plant / energy-management-system (BOP/EMS) boundary as the critical jurisdictional seam where, as of March 2026, neither NRC nor NERC CIP cleanly claims cybersecurity responsibility for distribution-connected SMRs. The framework maps each objective across NIST CSF 2.0, ISA/IEC 62443, NIST NICE Task–Knowledge–Skill statements, and NRC RG 5.71 awareness-and-training controls. The training lab implements operator-recognition assessment scenarios spanning grid-side disturbances and telemetry-layer anomalies.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Digital Assurance Checklist for Homeowners and Installers

This document provides a comprehensive Digital Assurance Checklist for securing behind-the-meter energy assets, focusing on both installers and homeowners. As distributed energy resources (DERs) such as solar PV and battery storage become integral to residential energy systems, cybersecurity emerges as a critical component of reliability and safety. The guide outlines actionable steps for installers during pre-installation, commissioning, and post-installation phases, emphasizing practices like network segmentation, credential management, firmware validation, and homeowner education. For homeowners, the document introduces a tiered approach to cyber hygiene—from essential measures like strong Wi-Fi credentials and automatic updates to advanced strategies such as network segmentation, DNS filtering, and intrusion detection. By adopting these practices, stakeholders can mitigate cyber risks, safeguard energy infrastructure, and ensure resilient, secure operation of DER systems. Additional resources and references to industry standards are included to support implementation.

99 - GENERAL AND MISCELLANEOUS↗

Digital Assurance Checklist for Homeowners and Installers

This document provides a comprehensive Digital Assurance Checklist for securing behind-the-meter energy assets, focusing on both installers and homeowners. As distributed energy resources (DERs) such as solar PV and battery storage become integral to residential energy systems, cybersecurity emerges as a critical component of reliability and safety. The guide outlines actionable steps for installers during pre-installation, commissioning, and post-installation phases, emphasizing practices like network segmentation, credential management, firmware validation, and homeowner education. For homeowners, the document introduces a tiered approach to cyber hygiene—from essential measures like strong Wi-Fi credentials and automatic updates to advanced strategies such as network segmentation, DNS filtering, and intrusion detection. By adopting these practices, stakeholders can mitigate cyber risks, safeguard energy infrastructure, and ensure resilient, secure operation of DER systems. Additional resources and references to industry standards are included to support implementation.

99 - GENERAL AND MISCELLANEOUS↗

Securing Distributed Energy Resource Integration

The penetration of distributed energy resources (DER) is growing at much higher rates than predicted 20 years ago. Far from being used only in residential settings, DER are now installed on distribution and transmission circuits. In this position, they do not have the same properties as traditional generators and are more flexible in many cases. The growing penetration and range of uses for DER motivate the need to reliably and safely integrate them into the grid. Operators must be able to rely on them not only for normal operation, but also during abnormal conditions like black starts or adverse cyber scenarios. To that end, we study the communications, device interfaces, and potential consequences of DER operation under abnormal and adversarial conditions. The weaknesses of communications networks are studied based on the industrial protocols used, and the benefits of security features are examined. The device interfaces are found to be vulnerable to attack based on the requirements in the IEEE-1547 standard for DER interconnection and interoperability, which is expected to be adopted in the next ten years. In addition to exploring the requirements of the standard, we show that these vulnerabilities and others do exist and can be used maliciously in a modern storage system DER. Consequences of these vulnerabilities range from exacerbated grid instability, to simultaneous loss of large portions of DER penetration, to physical damage to inverters or DER themselves and other sensitive equipment. We tie these outcomes to specific attacker actions in an effort to give operators a better threat intelligence view that allows them to prioritize mitigations. Finally, we discuss mitigations that could prevent many of the adversarial scenarios described. Some solutions can be added to existing infrastructure, while others may require longer term planning for grid modernization with consideration for security.

25 ENERGY STORAGE↗

A Hybrid Optimization and Deep Learning Algorithm for Cyber-Resilient DER Control

With the proliferation of distributed energy resources (DERs) in the distribution grid, it is a challenge to effectively control a large number of DERs resilient to the communication and security disruptions, as well as to provide the online grid services, such as voltage regulation and virtual power plant (VPP) dispatch. To this end, a hybrid feedback-based optimization algorithm along with deep learning forecasting technique is proposed to specifically address the cyber-related issues. The online decentralized feedback-based DER optimization control requires timely, accurate voltage measurement from the grid. However, in practice such information may not be received by the control center or even be corrupted. Therefore, the long short-term memory (LSTM) deep learning algorithm is employed to forecast delayed/missed/attacked messages with high accuracy. The IEEE 37-node feeder with high penetration of PV systems is used to validate the efficiency of the proposed hybrid algorithm. The results show that 1) the LSTM-forecasted lost voltage can effectively improve the performance of the DER control algorithm in the practical cyber-physical architecture; and 2) the LSTM forecasting strategy outperforms other strategies of using previous message and skipping dual parameter update.

cyber-resilient algorithm↗

DEReliction: A Cybersecurity Vulnerability Assessment Methodology for Distributed Energy Resources

With the increasing integration of Distributed Energy Resources (DER) into the electric grid, maintaining grid reliability and resilience requires that these devices remain secure. This paper discusses a cybersecurity vulnerability assessment methodology that incorporates best practices from Sandia National Laboratories, SANS Institute, OWASP Foundation, and other web and Internet of Things (IoT) penetration testing (“pen testing”) programs, courses, and frameworks for assessing the security posture of devices. The methodology involves five sequential steps: (1) Collect Public Information, (2) Extract Hardware Details, (3) Inventory Software Components, (4) Identify Vulnerabilities, and (5) Test Vulnerabilities. Each step uncovers potential weaknesses in both hardware and software components of DER devices, considering adversary tactics, techniques, and procedures (TTPs), and potential attack vectors along the way. The results from the execution of this method on multiple residential- and small commercial-scale photovoltaic (PV) inverters reveled hardware and software vulnerabilities, which highlight the benefit of taking a methodical approach to discover vulnerabilities. While the specific vulnerability details are not shared here, a generalized overview of findings underscore the importance of robust security assessments for DER devices. Adoption of an assessment framework of this kind will identify and mitigate cybersecurity threats and bolster the resilience of DER-integrated electric grids.

24 POWER TRANSMISSION AND DISTRIBUTION↗

ModuleOT: A Hardware Security Module for Operational Technology: Preprint

With increasing penetration levels of distributed energy resources (DERs) on the distribution grid, as well as new technological advancements in the cyber space, new cyberattack vectors are being introduced, and the available attack surface is constantly increasing. Despite this increasing risk, the standard IEEE 1547-2018 does not yet recommend cybersecurity measures for DERs. To address this and to better protect data on the distribution grid - from the standpoints information security as well as operational security - ModuleOT has been developed. The module aims to significantly reduce cyberattack vectors by improving data privacy for user applications. This is accomplished by performing the core functions of encryption, authentication, authorization, certificate management, and user access control. The module integrates a custom security application with hardware cryptographic acceleration. The application secures all communications using Transmission Control Protocol over Internet Protocol (TCP/IP). These include the three most commonly used communications protocols for power systems information exchange: Modbus, Distributed Network Protocol 3 (DNP3), and Smart Energy Profile 2.0 (SEP2.0). These three protocols are also supported by IEEE 1547-2018 for all DER devices. This paper tests the data encryption/decryption feature on a physical networking test bed with emulated Modbus devices reporting grid data and presents the results.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Trust Model Measurements for the Energy Grid of Things

Information security is essential for the reliable operation of an Energy Grid of Things (EGoT). In addition to basic information security protocols as defined by published standards, there is a need for a monitoring function that measures the trustworthiness of the various actors participating in an EGoT. We describe in this paper the implementation and evaluation of a Distributed Trust Model that was developed specifically for monitoring communication within an EGoT. We then show how the model parameters are set using statistical measures for hypothesis testing.

Energy Grid of Things, EGoT, Smart Grid Security, ↗