Engineering PapersSearch

SEARCH · Engineering Papers

Results for “electric grid security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Standards Library for Distributed Energy Resources

This presentation was presented at the Aggregation and Grid Security Workshop - held on June 17-18, 2025, at NREL in Golden, Colorado. The goal of the two-day workshop was to address the critical cybersecurity challenges for the future electric grid. This presentation overviews the evolution and need for harmonized distributed energy resource standards and a new distributed energy resource standards library.

29 ENERGY PLANNING, POLICY, AND ECONOMY

TrustDER: Trusted, Private and Scalable Coordination of Distributed Energy Resources

In this project, the Stanford and SLAC Teams have developed a Trusted, Private and Scalable platform for coordinating Coordination of Distributed Energy Resources (TrustDER). This is a layered system that ensures private, trusted and scalable coordination and monitoring of DERs. It accommodates a variety of resources, such as solar generation, gensets and loads, with a particular focus on battery systems-based resources, as they are a transformational technology experiencing fast growth in adoption by large critical facilities. The platform can be used as standalone or added to existing aggregation systems to enable trust, privacy and resilience. TrustDER consists of layers that address each of the shortcomings of the existing state of the art. Each layer in the platform can operate independently but provides information to the layers above it to enable a novel form of overall coordination architecture. The project consists of several tasks, with each task dedicated to the design of each layer. Task 2 Resource Virtualization defined a software abstraction layer for distributed energy resources (DERs). The goal of this abstraction was to simplify the implementation of algorithms utilizing cooperation of DERs resources in a variety of use cases. Task 3 is on Secure ID for Asset Authentication. Identity Management Systems (IDMS) are a foundational infrastructure for interactions between entities (organizations, users, devices, and services). Secure ID is blockchain-based a distributed identity management system allowing (1) identity provisioning, (2) authentication, (3) authorization, and (4) identity data sharing for IoT-enabled assets on the electricity grid. In this project, the SLAC team focused on designing and testing Keymaker, a protocol for authenticating device identity managed by Secure ID. Task 5 Private and Safe Integration is focused on the design and evaluation of a DER cooperation scheme which allows for the aggregation of DERs without impacting network reliability. The approach is designed based on realistic assumptions regarding data availability, communication infrastructure limitations, and privacy. Task 6 Scalable Distributed Privacy for Information explored how virtualized batteries could be managed privately. Specifically, it examined the case in which a principal provides a partitioned battery to multiple clients. Task 7 Use Cases was to ensure that this technology was applied in relevant situations and scenarios. Primarily, this means that virtualization needed to be employed in a manner that either improved flexibility, bolstered security or privacy, or decreased costs.

25 ENERGY STORAGE

Supporting ARPA-E Power Grid Optimization (Final Report)

Pacific Northwest National Laboratory (PNNL), Arizona State University (ASU), Georgia Institute of Technology (Georgia Tech), Los Alamos National Laboratory (LANL), National Renewable Energy Laboratory (NREL), Texas A&M University (TAMU), The University of Texas at Austin (UT), and the University of Wisconsin-Madison (UW-M) supported the ARPA-E Grid Optimization (GO) Competition by providing a common problem formulation, data format, datasets, evaluation mechanism, scoring, rules, and results that resulted in the awarding of $\$9.24$ million dollars to teams from academia, industry, and national labs for solving three sets of increasingly difficult non-linear, security- constrained AC Optimal Powerflow (AC-OPF) optimization problems in order to increase the efficiency of the US Electric Grid. It is estimated that a 1% increase in efficiency can save $\$1$ billion. Current industry practices typically use a linear DC model (DC-OPF) in order solve the OPF problem within the time constraints of the operation schedule. The GO Competition challenges the best power engineers, mathematicians, and computer scientists to make possible operational decisions based on accurate physical models. To accomplish this, the GO Competition created a series of Challenges and funded teams to produce the best solver. Challenge 1 was to solve the security constrained Alternating Current Optimal Power Flow (ACOPF) problem. Challenge 2 extended that to by adding adjustable transformer tap ratios, phase shifting transformers, switchable shunts, price-responsive demand, ramp rate constrained generators and loads, and fast-start unit commitment (UC). Furthermore, Challenge 2 was a maximization problem while Challenge 1 was a minimization problem. While Challenge 3 was being developed, the entrants were invited to find better solutions to the Challenge 2 synthetic datasets with no restrictions on time, hardware, or algorithms. The Challenge 2 solutions turned out to be very good. Challenge 3 expanded the Challenge 2 problem further by using multiperiod dynamic markets, including advisory models for extreme weather events, day-ahead markets, and the real-time markets with an extended look-ahead. These problems included active bid-in demand and topology optimization. Together the Challenges used nearly 30 million CPU hours. Since each team was working on the same problem, using the same data, and running on the same hardware, fair comparisons could be drawn as to the best solver. The datasets were varied enough, however, that the best solver for one dataset was not necessarily the best at another, so cumulative scores were used. The process was managed by the PNNL maintained website https://GOCompetition.energy.gov, where Entrants could find information about the problem, the data, the rules, submit their solver for evaluation, and see the scores of all the competing teams on a Leaderboard. Interest was world-wide but only American teams were eligible for prizes. The Competition has produced 34 journal articles 115 papers and been cited over 500 times in the literature, including 12 dissertations (4 from foreign countries; Columbia (2), Germany, and Italy) and 3 from the DOE ExaScale project. Software developed by Pearl Street Technologies for Challenges 1 and 2 is now deployed by Southwest Power Pool (SPP) and Midcontinent Independent Service Operator (MISO). Other teams have received inquiries from venture capitalists. Google DeepMind has thanked the Competition for making the datasets developed for the Competition public. They are using it to train machine learning models. The larger datasets have billions of unknowns to be solved for, but only a small percent matter in the final solution. Knowing what unknowns are important can dramatically speedup the solution.

24 POWER TRANSMISSION AND DISTRIBUTION

VPP Cybersecurity: Stakeholder Roles and Responsibilities

This presentation was presented at the Aggregation and Grid Security Workshop - held on June 17-18, 2025, at NREL in Golden, Colorado. The goal of the two-day workshop was to address the critical cybersecurity challenges for the future electric grid. This presentation outlines a framework for assessing the roles and responsibilities of virtual power plant stakeholders in mitigating cyber risk to virtual power plant projects and the overall power grid.

24 POWER TRANSMISSION AND DISTRIBUTION

Smart Charge Management and Vehicle Grid Integration Deep Dive

The U.S. Department of Energy (DOE) Electric Vehicles at Scale Laboratory Consortium (EVs@Scale Lab Consortium) is accelerating research to support the establishment of a secure and scalable national network of charging infrastructure. Critical to this effort is an understanding of the potential grid impacts of EV charging and possible smart charge management (SCM) or vehicle-grid integration (VGI) capabilities that could mitigate these impacts. The EVs@Scale SCM/VGI Pillar is analyzing the impacts of EV charging and developing and demonstrating the capabilities of both SCM and VGI with many different vehicle use cases and grid scenarios. This deep dive discussion of the project encompasses the progress and future plans for the analysis components of the FUSE (Flexible charging to Unify the grid and transportation Sectors for Evs at scale) project.

ADVANCED PROPULSION SYSTEMS

Advanced Research on Integrated Energy Systems (ARIES) Cyber Range Overview and Threat-to-Consequence Demonstration

This presentation was presented at the Aggregation and Grid Security Workshop - held on June 17-18, 2025, at NREL in Golden, Colorado. The goal of the two-day workshop was to address the critical cybersecurity challenges for the future electric grid. The threat-to-consequence demonstration showcases NREL's capability to model, simulate, test, and evaluate cyberattacks targeting energy systems that coincide with natural hazards, as well as the ramifications for the energy grid as a whole.

24 POWER TRANSMISSION AND DISTRIBUTION

Responsible Adoption of Artificial Intelligence (AI) in Electric Grid Operations

The future of the grid will be powered by AI—or undermined by it. Artificial intelligence is rapidly reshaping grid operations, improving fault detection, forecasting accuracy, and real-time optimization. As AI systems move closer to operational decision loops, however, they introduce new consequence pathways: expanded attack surfaces, model integrity risks, regulatory exposure, and human-automation challenges. This talk presents a consequence-driven framework for deploying AI responsibly in the electric grid. Attendees will gain practical strategies to strengthen resilience, boost reliability, and deploy AI securely — ensuring the grid of the future is not only smarter but safer.

25 - ENERGY STORAGE

Enhancing Cloud Cybersecurity: Prescriptive Controls for Operational Technology

This whitepaper provides strategic insights and recommendations into security cloud-based solutions for electric utilities, encompassing operational technology (OT), virtual power plants (VPP), distributed energy resources (DERs), applications, networks, and data storage as they transition to and leverage cloud infrastructure through managed service providers (MSPs) and cloud service providers (CSPs). Principles derived from established frameworks serve as a foundation for best practices across cybersecurity projects and remove the constraints of settling on a single framework. For organizations that prefer not to integrate a specific framework altogether, elements of the proposed approach could be adopted or tailored to best fit defined requirements and expected functionalities. The Cirrus assessment, a utility cloud feasibility tool, and the roadmap it provides serve as a precursor to this paper, which seeks to be a valuable resource for defining next steps following cloud technology integration feasibility appraisal. With its comprehensive approach to adoption, the Cirrus framework offers strategic guidance on responsibly preparing for or deploying a utility cloud solution. The previously published whitepaper, “Use Case-Informed Framework for Utility Cloud Migration,” details the guiding strategy, research, and deployment of cloud solutions within electric and interconnected grid systems. Before implementing the controls suggested in this document, it is recommended that stakeholders complete Cirrus's cloud integration assessment and pair the results with their unique cybersecurity controls to form a comprehensive cloud-based utility cybersecurity plan. The Cirrus outcome will consider a series of future architectures for the grid before and after the energy transition and evaluate the arguments for and against cloud applications for each electric and interconnected grid layer. This document is a companion to the original whitepaper, "Use Case-Informed Framework for Utility Cloud Migration" to further identify and recommend security controls based on Cirrus’s cloud integration assessment output. The following whitepaper outlines the cybersecurity controls that secure cloud-service models pertinent to the electric sector using the predefined categories identify, protect, detect, and respond and recover. The objective is to outline prescriptive security controls based on the type of architecture and data stored in the cloud. The focus includes dissecting the shared responsibility model and elucidating what on-premises Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) entail. A pivotal consideration in this context is allocating responsibility for foundational cybersecurity aspects—having used Cirrus for the cloud integration assessment. The ensuing controls detailed herein also represent a checklist of controls necessary for a secure cloud transition, equipping utilities with the knowledge to navigate this digital transformation with confidence and strategic foresight in a safe and responsible manner.

42 ENGINEERING

Network Security Challenges and Countermeasures for Software-Defined Smart Grids: A Survey

The rise of grid modernization has been prompted by the escalating demand for power, the deteriorating state of infrastructure, and the growing concern regarding the reliability of electric utilities. The smart grid encompasses recent advancements in electronics, technology, telecommunications, and computer capabilities. Smart grid telecommunication frameworks provide bidirectional communication to facilitate grid operations. Software-defined networking (SDN) is a proposed approach for monitoring and regulating telecommunication networks, which allows for enhanced visibility, control, and security in smart grid systems. Nevertheless, the integration of telecommunications infrastructure exposes smart grid networks to potential cyberattacks. Unauthorized individuals may exploit unauthorized access to intercept communications, introduce fabricated data into system measurements, overwhelm communication channels with false data packets, or attack centralized controllers to disable network control. An ongoing, thorough examination of cyber attacks and protection strategies for smart grid networks is essential due to the ever-changing nature of these threats. Previous surveys on smart grid security lack modern methodologies and, to the best of our knowledge, most, if not all, focus on only one sort of attack or protection. This survey examines the most recent security techniques, simultaneous multi-pronged cyber attacks, and defense utilities in order to address the challenges of future SDN smart grid research. The objective is to identify future research requirements, describe the existing security challenges, and highlight emerging threats and their potential impact on the deployment of software-defined smart grid (SD-SG).

24 POWER TRANSMISSION AND DISTRIBUTION

Efficient Reformulation and Optimization for SC-ACOPF with Line Switching

This project aims to develop efficient and robust computational methods for solving the security-constrained alternating current optimal power flow problem (SC-ACOPF). The SC-ACOPF problem is a central problem in operating the electric power grids in the United States. It determines the most economically efficient way to operate the generation and transmission system to meet daily electricity demand. The solution found by solving an SC-ACOPF problem must satisfy the physics of the alternating current (AC) power flows, various generator and network operational constraints, and must maintain secure operation under various contingency scenarios, where a generator, a transmission branch, or a transformer may unexpectedly trip offline.

97 MATHEMATICS AND COMPUTING

Cyber100 Compass: Quantification of Cybersecurity Risks for Systems Transitioning to High Levels of Renewables (Final Report)

The shift to high levels of renewable deployment will entail a significant re-engineering of the grid. As investors, utilities, customers, and others prepare for clean energy transitions, there is need to understand how restructuring the grid to accommodate renewables will change the attack surface of the grid and accompanying cyber risk. However, today the cyber-physical risks associated with electric grids incorporating high levels of renewable deployment remain largely unknown. The Cyber100 Compass proof-of-concept application attempts to quantify future cyber-physical security risks by combining risk data gathered from subject matter experts (SMEs) with input from system planners about conditions they expect to be true about their electric systems in the future. Users provide data about their organization’s tolerance for risk; the value they place on avoiding the consequences of different cyber events; and conditions that they expect to be true on their systems at some point in the future. The SMEs provide baseline probabilities for different cyber events; the probability that an event will be low-, moderate-, or high-impact; and the amount by which user-identified conditions on their systems will change the likelihood of the cyber events. The application takes both the user and SME input and performs a series of Monte Carlo simulations to arrive at a quantification of risk.

24 POWER TRANSMISSION AND DISTRIBUTION

Evaluation of IEC 62443 Standard Gaps for Electric Grid Substation Model Use Case

This report presents an evaluation of the IEC 62443 standards in the context of electric grid substations, as part of a collaborative effort among Sandia National Laboratories (SNL), Idaho National Laboratory (INL), and the National Renewable Energy Laboratory (NREL). The primary objective is to assess the applicability of these standards to enhance cybersecurity measures for industrial automation and control systems (IACS) within the energy sector. The evaluation identifies strengths, such as the scalability of security levels and the structured lifecycle guidance provided by IEC 62443. However, it also highlights significant gaps, including limited integration of physical security, insufficient guidance for legacy systems, and challenges in addressing emerging threats like supply chain vulnerabilities. Recommendations for refining the standards are proposed, including the need for tailored guidance for securing legacy systems, integrating physical security with cybersecurity frameworks, and enhancing interoperability across multi-vendor environments. By addressing these gaps, the IEC 62443 standards can be strengthened to ensure comprehensive cybersecurity for electric grid substations, thereby supporting the resilience and reliability of critical energy infrastructure.

24 POWER TRANSMISSION AND DISTRIBUTION

Securing the Modern Grid: Federal Investments, Digitization, and Supply Chain Strategy

Across the United States (U.S.) grid expansion and modernization is underway, paving the way for accelerated load growth and intelligent resource management. Digitization of the grid is supported by several state and federal programs, providing support for utilities installing advanced metering infrastructure (AMI), AI-powered analytics systems, battery energy storage systems (BESS), and distributed energy resource management systems (DERMS) to transform the grid from a one-way power delivery system into an intelligent, responsive network that will enable faster load growth and power expansion of data centers for advanced artificial intelligence (AI) applications. The digital transformation of America's grid presents opportunity for increased efficiency and resiliency but also introduces new digital risks that require careful management. Digital equipment often contains several vulnerabilities such as unencrypted communication protocols, and persistent remote access capabilities that could be exploited to manipulate device settings, coordinate service disruptions, or inject false data into grid operations. These digital risks become particularly important as the grid must rapidly scale to support AI-driven data centers, which the administration has identified as essential for maintaining U.S. technological leadership and economic competitiveness. These vulnerabilities are compounded by supply chain realities: Chinese manufacturers currently produce 70-90% of essential grid components including inverters, batteries, and control systems, with the U.S. lacking domestic manufacturing capacity for critical assets like extra-high voltage transformers. Recent federal legislation has established Foreign Entity of Concern (FEOC) restrictions to address these risks, requiring projects to achieve escalating thresholds of non-FEOC content to receive tax credits while utilities work to expand sourcing channels for their supply chains and strengthen security measures. These restrictions arrive precisely when utilities face unprecedented electricity demand growth driven by the rapid growth in data centers, creating a considerable challenge: rapidly expanding infrastructure while navigating complex compliance requirements while lacking viable alternatives for many critical components. Idaho National Laboratory (INL) and its partners have developed practical approaches to help utilities navigate these intersecting challenges as they leverage federal investment to strengthen and grow the grid. These solutions include Cyber-Informed Engineering (CIE) principles that build resilience directly into systems, the Cirrus tool for secure cloud migration, and enhanced procurement guidance that embeds security requirements throughout equipment lifecycles. Federal initiatives, such as the Technical Assistance for Digital Assurance (TADA) project, provide direct support to utilities implementing these approaches while facilitating knowledge sharing across the industry. While these tools and frameworks cannot eliminate all risks inherent in foreign supply chain dependencies, they offer pragmatic pathways for strengthening security posture without sacrificing the deployment momentum essential to meeting surging electricity demand. Ultimately, securing America's digital energy infrastructure demands dedicated coordination across multiple fronts: building domestic supply chains, implementing robust digital assurance practices, and maintaining the aggressive modernization timeline necessary for reliability, resilience, and energy independence.

24 POWER TRANSMISSION AND DISTRIBUTION

Cybersecurity Certification Requirements for Distributed Energy Resources: A Survey of SunSpec Alliance Standards

This survey paper explores the cybersecurity certification requirements defined by the SunSpec Alliance for Distributed Energy Resource (DER) devices, focusing on aspects such as software updates, device communications, authentication mechanisms, device security, logging, and test procedures. The SunSpec cybersecurity standards mandate support for remote and automated software updates, secure communication protocols, stringent authentication practices, and robust logging mechanisms to ensure operational integrity. Furthermore, the paper discusses the implementation of the SAE J3072 standard using the IEEE 2030.5 protocol, emphasizing the secure interactions between electric vehicle supply equipment (EVSE) and plug-in electric vehicles (PEVs) for functionalities like vehicle-to-grid (V2G) capabilities. This research also examines the SunSpec Modbus standard, which enhances the interoperability among DER system components, facilitating compliance with grid interconnection standards. This paper also analyzes the existing SunSpec Device Information Models, which standardize data exchange formats for DER systems across communication interfaces. Finally, this paper concludes with a detailed discussion of the energy storage cybersecurity specification and the blockchain cybersecurity requirements as proposed by SunSpec Alliance.

Tsikteris, Sean (ORCID:0009000524202250)

Virtual Power Plants: Pilots, Challenges, and Innovations Shaping Future Development

Virtual Power Plants (VPPs) aggregate distributed energy resources (DERs) to provide grid services traditionally delivered by centralized power plants. This article reviews the current state of VPP deployment, highlighting business models, compensation mechanisms, and global pilot projects. While VPPs offer benefits such as grid flexibility, resilience, and cost savings, challenges remain in communication infrastructure, regulatory frameworks, market access, and customer engagement. To address these, we propose a scalable, privacy-preserving hierarchical VPP architecture that coordinates with distribution utilities and preserves customer data. We also present the Integrated T&D Control Room of the Future as a key test bed for validating and accelerating VPP adoption. These innovations can help transition VPPs from pilot programs to integral components of a modern, reliable power grid.

24 POWER TRANSMISSION AND DISTRIBUTION

Correlation Between Weather Alerts and Grid Component Failures for Grid Alert

Weather events cause most grid failures. Often, we even get notifications on our phones to take cover or be prepared for an imminent event. If electric grid utilities had a similar warning that also included probable scenarios and the equipment involved, they could prepare and minimize the effects. Recent research at Idaho National Laboratory into electric grid risk analysis methods resulted in a tool that allows for the development of the most likely scenarios given failure probabilities of grid components. INL has a project with the U.S. Department of Energy’s Cybersecurity, Energy Security, and Emergency Response (CESER) program to develop a Grid Alert application that receives messages from the existing emergency alert system, filters and determines components possibly affected by the emergency event, calculates probable scenarios uses MASTERRI and then notifies the utility if there is significant risk. Historical failure data of elements that comprise the U.S. electric grid have been compiled by utilities and organizations such as the international regulatory body North American Electric Reliability Corporation (NERC). Nominal failure rates are obtained from this data. To make this tool possible, estimated failure rates are needed for different component types given the alert type, severity, and location. Historic weather-related grid element failures are correlated with historic weather events from Integrated Public Alert & Warning System (IPAWS). These correlated events and failures are used along with Bayesian updates from the historical norms to provide a modified failure rate for grid elements in the alert areas and calculate probable scenarios. This discusses the Grid Alert project plan but focuses on the data gathered and process used in determining failure rates for possible grid failure scenarios.

24 - POWER TRANSMISSION AND DISTRIBUTION

Natural Hazard Forecast Alert Grid Risk System

Weather events cause most power outages. Often, we even get notifications on our phones to take cover or be prepared for an imminent event. If electric grid utilities had a similar warning that also included probable scenarios and the equipment involved, they could prepare and minimize the effects. Idaho National Laboratory had a project with the U.S. Department of Energy’s Cybersecurity, Energy Security, and Emergency Response program to develop a grid alert application that receives messages from the existing emergency alert system, filters and determines components possibly affected by the emergency event, calculates probable scenarios using MASTERRI (Modeling And Simulation for Targeted Reliability and Resilience Improvement). For high-risk events, the application can then send alert links to subscribed electric distribution utility operations staff to allow them to see and evaluate the scenarios and the impact in a web based interactive map tool. This proof of concept application used data from utilities and organizations, such as the international regulatory body North American Electric Reliability Corporation, which have complied historical failure data of elements that comprise the U.S. electric grid. Nominal failure rates are obtained from this data. To make this tool possible, estimated failure rates were calculated for different component types given the alert type, severity, and location. Historic weather-related grid element failures were correlated with historic weather events from the Integrated Public Alert & Warning System. These correlated events and failures are used along with Bayesian updates from the historical norms to provide a modified failure rate for grid elements in the alert areas and calculate probable scenarios. Working with an industry collaborator, actual grid models and data were used for demonstration cases. This report outlines the work performed for this project.

24 - POWER TRANSMISSION AND DISTRIBUTION

Consequence Based Framework for Deployment of Cloud Solutions in the Digital Energy Transition

This study proposes a framework for evaluating cloud computing deployment in the electric sector, focusing on the digital transition of energy systems. It assesses the implications of cloud technology adoption, particularly in terms of security, operational resilience, and efficiency. The paper introduces a method for consequence-driven risk analysis, enabling utilities to prioritize and mitigate potential threats effectively. It also discusses the shared responsibility model in cloud computing, highlighting the need for collaborative security efforts. The research aims to provide utilities with a strategic assessment tool for cloud adoption, emphasizing the importance of security culture in enhancing cloud computing's role in critical infrastructure.

99 GENERAL AND MISCELLANEOUS