Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Cybersecurity Resilience”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Advanced Transmission Technologies (ATTs) Supplier Cohort Workshops Cohort Summary [Slides]

This Summary slide deck summarizes the key outcomes of the Advanced Transmission Technologies (ATTs) supplier cohort, part of Idaho National Laboratory’s (INL) Technical Assistance for Digital Assurance (TADA) program. The program aimed to strengthen grid resilience through cybersecurity controls, supply-chain security, and Cyber-Informed Engineering (CIE) for advanced transmission technologies. The cohort brought together vendors representing the full range of Grid-Enhancing Technologies (GETs), including providers of Dynamic Line Ratings (DLR), Advanced Power Flow Control (APFC), Transmission Topology Optimization (TTO), and High-Performance Conductors (HPCs). Discussions focused on institutional, integration, and operational barriers limiting GET adoption; cybersecurity risks at EMS/SCADA, cloud, and network integration points; and supply-chain transparency issues such as semiconductor dependence and SBOM/HBOM expectations. Participants also addressed operator trust, human-in-the-loop requirements, and challenges with utility adoption, while exploring how CIE can support secure deployment of GETs. This deck represents a consolidated summary of challenges and risks identified by vendors, cross-cutting themes and technology-specific insights from three cohort workshops, and actionable mitigations to guide utilities, vendors, and the Department of Energy in advancing secure, trusted deployment of GETs.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Formally Verified ZTA Requirements for OT/ICS Environments with Isabelle/HOL: Preprint

The clean energy transformation led to the integration of distributed energy resources on a top of the grid, and so a substantial increase in the complexity of power grids infrastructure and the underlying operational technology environment. Operational technology environments are becoming a system of systems, integrating heterogeneous devices which are software/hardware intensive, have ever increasing demands to exploit advances in commodity of software/hardware infrastructures, and this for good reasons - improving energy systems requirements such as cybersecurity and resilience. In such a setting, system requirements at different levels mix, thus undesirable outcomes will surely happen. The use of formal methods will remove ambiguity, increase automation and provide high levels of assurance and reliability. In this paper, we contribute a methodology and a framework for the system level verification of zero trust architecture requirements in operational technology environments. We define a formal specification for the core functionalities of operational technology environments, the corresponding invariants, and security proofs. Of particular note is our modular approach for the formal verification of asynchronous interactions in operational technology environments. The formal specification and the proofs have been mechanized using the interactive theorem proving environment Isabelle/HOL.

formal methods↗

Cybersecurity Certification Recommendations for Interconnected Grid Edge Devices and Inverter Based Resources

Escalating deployment of PV and grid-edge devices on the distribution grid has increased the sustainability and efficiency of the electric grid. However, the increasing number of distributed energy resources (DERs) deployed creates a heightened cyber-physical interdependency on the distribution grid and thus creates more vectors for cyber-attacks to exploit through information and communication technology (ICT) systems and networks. For example, control signal packets can be modified, intercepted, or corrupted due to vulnerabilities in communication protocols used by microgrid controllers and grid edge devices for power control. Therefore, to mitigate and prevent cyber-attacks on grid edge devices and the inverter-based resources connected to the distribution grid, the U.S. Department of Solar Energy Technologies Office (SETO) awarded funding to the National Renewable Energy Laboratory and Sandia National Laboratory (SNL) to research, develop, and harmonize cybersecurity standards for Photovoltaic (PV) systems and for other kinds of DERs. To help develop a standard for DER cybersecurity, NREL established certification recommendations and test cases, in consensus with the solar industry and UL, for ensuring intrinsic design security for DERs. These recommendations were developed to bolster the cybersecure functionalities such as TLS, MAC, CRL, session resumption/renegotiation, and password, system, and service security management within the DER devices. The proposed test cases verify authentication, authorization, confidentiality, and data integrity for data and communications of DERs that use Transmission Control Protocol/Internet Protocol (TCP/IP). They were also developed to protect DER communications from eavesdropping, replay, man-in-the-middle, denial of service (DoS), spoofing through security certificates, least-privilege violation, and brute-force credentials. This report, which has been validated and reviewed by UL, expands upon those test cases to provide DER cybersecurity certification recommendations which increase DER resiliency and help to mitigate cyber-attacks. UL's collaboration with NREL and approval of this document will accelerate the adoption of a UL standard for DER cybersecurity.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cytrics Repository Of Analysis Tools And Engineering Resources

Cybersecurity Testing for Resilient Industrial Control Systems (CyTRICS) is a DOE-funded project that works with vendors to evaluate the cybersecurity of equipment used in US critical infrastructure. In the process of testing systems, CyTRICS researchers often develop custom tools. The tools in this repository were developed during multiple CyTRICS tests to assist with the testing process. They help solve problems encountered by CyTRICS researchers and address uncommon testing subjects for which limited tooling is available. They are useful to other researchers working on similar systems and architectures.

Laird, SutterE↗

Risks to the DOW Mission From Global Advanced Energy Adoption

Advanced energy technologies have the potential to enhance energy security and resilience; however, they can introduce new vulnerabilities even as they mitigate existing ones. This dichotomy highlights that both action and inaction carry strategic risks in a contested and logistically complex operating environment. Regardless of U.S. civilian or military adoption of such technologies, key allies and adversaries are on adoption paths that will impact the U.S. military at the tactical, operational, and strategic level. The global adoption of advanced energy technologies presents the potential for both positive and negative consequences for U.S. Department of Defense (DOD) missions in the next 10-20 years. Three categories of risk drivers are presented in this analysis: infrastructure-related, adoption-related, and response-related. Each risk type can generate consequences for DOD, including power disruptions, suboptimal DOD mission performance and operational effectiveness, higher costs and shortages for both legacy and advanced energy technologies, and loss of U.S. influence and strategic deterrent value. Specific impacts could include tactical impacts, operational impacts, and strategic impacts. Mitigation strategies could include energy resource and technology planning, cybersecurity, supply chain resilience, workforce development, exercises and simulations, investments in commercialized technology, operational testing and pilot programs, research into emerging technologies, partnerships and working groups, common standards, budget planning, and repurposing infrastructure.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Talk Title: AI & Cybersecurity in ASEAN's Digital Future Venue: CyberForum: ASEAN Cyber Resilience Conference Hosted by: Indonesia Cyber Security Forum (ICSF) in coordination with US State Department's mission to ASEAN in Indonesia

The talk covers: * Quick orientation around AI * Quick review of relevant domains of Cybersecurity * The promise of AI in cybersecurity – applications * Discussion of the state of technology today, referencing Gartner Hype Cycle diagram * The peril of AI for cybersecurity – threats and risks * A roadmap for where to go from here, emphasizing a trained workforce, referencing published (ISC)^2 survey results

Benz, Zachary O.↗

SolarSTARTS: Solar-Assisted State-Aware and ResilienT infrastructure System

This final technical report provides a description and results of the design, development, testing, and validation of the Automated Resilience Management System (ARMS) solution, which integrates different systems to collect, store and process relevant information from the power distribution system to automatically manage the operation of multiple energy assets to enhance the resilience of the power grid against high-impact physical incidents (e.g., hurricanes) and cyber threats. The developed solution comprises a suite of novel AI-based algorithms designed to first detect, locate, and classify anomalies by collecting and analyzing data from multiple monitoring and control devices

14 SOLAR ENERGY↗

Case Study: Applying the INL Resilience Framework to Iowa Lakes Electric Cooperative Distributed Wind Systems

Traditional metrics and evaluation methods for resiliency are not sufficient to evaluate the effect that distributed wind systems will have, particularly in light of the challenges described above. While the concept of resiliency is not new, its application to the electric grid is neither standardized nor well-defined, and there is little to no guidance on how to evaluate resilience specifically for distributed wind systems. To fill this gap, the Idaho National Laboratory (INL), as part of the multi-laboratory Microgrids, Infrastructure Resilience, and Advanced Controls Launchpad (MIRACL) project, has developed a resilience framework for electric energy delivery systems (EEDS). The framework provides detailed steps for evaluating resiliency in the planning, operational, and future stages, and encompasses five core functions of resilience. It allows users to evaluate the resilience of distributed wind, taking into consideration the resilience of the wind systems themselves, as well as the effect they have on the resiliency of any systems they are connected to. In this study, we evaluate the resilience of the distributed wind systems at Iowa Lakes Electric Cooperative to cybersecurity hazards. We show that the wind resource can benefit the overall system resilience during some hazards. We show that the practices in place make the wind subsystems resilient against some cybersecurity hazards but that there are still significant risks associated with other cybersecurity hazards

17 WIND ENERGY↗

RESCue Model (RESCue Experiment and Model) [SWR-24-84]

The Renewable Energy and Storage Cybersecurity Research (RESCue) project is a collaborative effort aimed at securing the rapidly growing deployment of transmission-connected hybrid renewable energy systems, consisting of a combination of wind, solar, and/or energy storage equipment, against escalating cyber threats. This project brings together major original equipment manufacturers (OEMs) of wind, solar, and energy storage, along with major asset owners and DOE National Laboratories, to collectively identify cyber threats, assess risks, and develop robust cybersecurity strategies and solutions. The development of hybrid reference architectures has provided comprehensive blueprints for the secure design and integration of hybrid renewable energy systems, accounting for their unique characteristics and interdependencies. Additionally, NREL has created a cyber-resilient design framework that integrates cybersecurity considerations from the start of the system lifecycle, ensuring security is "baked in" from the initial design phase. The research thrusts for the project included (i) development of hybrid reference architectures and (ii) a cyber-resilient design framework for hybrid energy systems. The reference architectures has provided comprehensive blueprints for the secure design and integration of hybrid renewable energy systems, accounting for their unique characteristics and interdependencies. Additionally, NREL has created a cyber-resilient design framework that integrates cybersecurity considerations from the start of the system lifecycle, ensuring security is "baked in" from the initial design phase. A demonstration experiment was developed for one of the architectures using NREL's Cyber Range resources. This experiment configuration, deployable using open-source tools, is provided here in this repository. Additional models were developed for the wind and solar architectures as well, however the configurations for only the Energy Storage scenario are provided here: https://www.nrel.gov/docs/fy24osti/89921.pdf

Hasandka, Adarsh↗

Cybersecurity Operational Research, Experimentation, Innovation, and Integration (COREII)

The Department of Energy’s Cybersecurity, Energy Security, and Emergency Response Office (CESER) has partnered with Idaho National Laboratory (INL) and energy companies to develop COREII. This research initiative aims to align with the national cybersecurity strategy, enhance the resilience of critical energy infrastructure, facilitate efforts to improve grid-enhancing technologies (GET) and major effects from other critical and emerging technologies, and to enable discovery of innovative solutions for emerging cybersecurity challenges

99 GENERAL AND MISCELLANEOUS↗

Decarbonized Electric Grid: Defining, Measuring, and Integrating Decarbonization into Electricity Sector Policy and Planning

Traditionally, electric grid planning seeks to maintain safe, reliable, efficient, and affordable service for current and future customers. As policies, expectations of the energy system, and the threat landscape evolve, additional objectives for power system planners are emerging, including decarbonization, resilience, and equity. Renewable and clean energy goals, especially in the context of deep decarbonization strategies, are changing the mix of resources on the electric grid and prompting new considerations for grid architecture. The increased frequency and severity of extreme weather events over the last two decades, coupled with cybersecurity concerns, have elevated resilience as a key system need. More recently, there has been greater focus on equity and energy justice in grid planning to ensure that disadvantaged communities are not adversely affected by grid modernization and have equal access to its benefits. In response, new thinking around multi-objective decision planning is exploring improvements in grid planning processes to better integrate approaches to meet decarbonization, resilience, and equity objectives. To provide a foundation for this work, a series of white papers was produced to summarize these emerging objectives.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Resilient Electric Grid: Defining, Measuring, and Integrating Resilience into Electricity Sector Policy and Planning

Traditionally, electric grid planning seeks to maintain safe, reliable, efficient, and affordable service for current and future customers. As policies, expectations of the energy system, and the threat landscape evolve, additional objectives for power system planners are emerging, including decarbonization, resilience, and equity. Renewable and clean energy goals, especially in the context of deep decarbonization strategies, are changing the mix of resources on the electric grid and prompting new considerations for grid architecture. The increased frequency and severity of extreme weather events over the last two decades, coupled with cybersecurity concerns, have elevated resilience as a key system need. More recently, there has been greater focus on equity and energy justice in grid planning to ensure that disadvantaged communities are not adversely affected by grid modernization and have equal access to its benefits. In response, new thinking around multi-objective decision planning is exploring improvements in grid planning processes to better integrate approaches to meet decarbonization, resilience, and equity objectives. To provide a foundation for this work, a series of white papers was produced to summarize these emerging objectives.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Equitable Electric Grid: Defining, Measuring, and Integrating Equity into Electricity Sector Policy and Planning

Traditionally, electric grid planning seeks to maintain safe, reliable, efficient, and affordable service for current and future customers. As policies, expectations of the energy system, and the threat landscape evolve, additional objectives for power system planners are emerging, including decarbonization, resilience, and equity. Renewable and clean energy goals, especially in the context of deep decarbonization strategies, are changing the mix of resources on the electric grid and prompting new considerations for grid architecture. The increased frequency and severity of extreme weather events over the last two decades, coupled with cybersecurity concerns, have elevated resilience as a key system need. More recently, there has been greater focus on equity and energy justice in grid planning to ensure that disadvantaged communities are not adversely affected by grid modernization and have equal access to its benefits. In response, new thinking around multi-objective decision planning is exploring improvements in grid planning processes to better integrate approaches to meet decarbonization, resilience, and equity objectives. To provide a foundation for this work, a series of white papers was produced to summarize these emerging objectives.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Distributed Renewables Cyber Resilience

The following article is for Power Magazine, which has initial acceptance by the editor and focuses on presentation of a cybersecurity survey.

42 ENGINEERING↗

Resilient Energy Delivery and Control Systems (REDCS) (Final Technical Report)

US critical infrastructure is increasingly the target of cyberattacks, where disturbances could cause considerable damage and disruption. To help provide a new layer of cyber-physical protection for one key energy delivery system, natural gas pipelines, GE Vernova Advanced Research along with partners Florida State University and Intel Corporation created an innovative technology called "Resilient Energy Delivery and Control Systems" (REDCS). This cybersecurity package helps detect anomalies caused by cyberattacks, isolate the subsystem being impacted by the attack, and provide functions that can allow for resiliency – giving better situational awareness to the operators and cybersecurity specialists or in the future perform closed loop control for continued operation while compromised.

03 NATURAL GAS↗

Disrupting EV Charging Sessions and Gaining Remote Code Execution with DoS, MITM, and Code Injection Exploits using OCPP 1.6

Open Charge Point Protocol (OCPP) 1.6 is widely used in the electric vehicle (EV) charging industry to communicate between Charging System Management Services (CSMSs) and Electric Vehicle Supply Equipment (EVSE). Unlike OCPP 2.0.1, OCPP 1.6 uses unencrypted websocket communications to exchange information between EVSE devices and an onpremise or cloud-based CSMS. In this work, we demonstrate two machine-in-the-middle (MITM) attacks on OCPP sessions to terminate charging sessions and gain root access to the EVSE equipment via remote code execution (RCE). Second, we demonstrate a malicious firmware update with a code injection payload to compromise an EVSE. Lastly, we demonstrate two methods to prevent availability of the EVSE or CSMS. One of these, originally reported by SaiFlow, prevents traffic to legitimate EVSE equipment using a DoS-like attack on CSMSs by repeatedly connecting and authenticating several CPs with the same identities as the legitimate CP. These vulnerabilities were demonstrated with proof-of-concept exploits in a virtualized Cyber Range at Wright State University and/or with a 350 kW Direct Current Fast Charger (DCFC) at Idaho National Laboratory. The team found that OCPP 1.6 could be protected from these attacks by adding secure shell (SSH) tunnels to the protocol, if upgrading to OCPP 2.0.1 was not an option. Index Terms—Electric vehicle charging, cybersecurity, OCPP, cyberattack, cyber-resilience. INSPEC Accession Number: 23981565

99 GENERAL AND MISCELLANEOUS↗

Hawaii Threat Brief

The Digital Energy Transformation is redefining how power systems operate, integrating physical infrastructure with digital technologies to enhance efficiency, visibility, and resilience. For islanded and digitally modernizing systems like Hawai‘i’s, this shift presents both new opportunities and evolving challenges in cybersecurity, supply chain assurance, and environmental resilience. This brief provides an overview of critical infrastructure dependencies and systemic risks associated with increasing digital integration. It summarizes recent energy-sector threat activity and case studies that illustrate adversary tactics and supply chain vulnerabilities, and identifies pathways to strengthen resilience.

25 - ENERGY STORAGE↗