Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “DER security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Trust Model Measurements for the Energy Grid of Things

Information security is essential for the reliable operation of an Energy Grid of Things (EGoT). In addition to basic information security protocols as defined by published standards, there is a need for a monitoring function that measures the trustworthiness of the various actors participating in an EGoT. We describe in this paper the implementation and evaluation of a Distributed Trust Model that was developed specifically for monitoring communication within an EGoT. We then show how the model parameters are set using statistical measures for hypothesis testing.

Energy Grid of Things, EGoT, Smart Grid Security, ↗

Cybersecurity Standards for Distributed Energy Resources: Gaps and Harmonization Strategy

This report examines cybersecurity standards for Distributed Energy Resources (DERs) in light of their rapid growth and increasing integration into energy systems. It identifies critical gaps in existing frameworks, including inadequate coverage of DER-specific challenges, complexities in implementing comprehensive standards, integration issues with legacy systems, adoption hurdles for newer standards, and a lack of harmonization across regulatory landscapes. The analysis highlights vulnerabilities such as data integrity risks, unauthorized device control, and denial-of-service attacks across various DER technologies like solar PV, wind turbines, energy storage systems, and hydrogen fuel cells. The report proposes a harmonization strategy to address these deficiencies by developing unified cybersecurity requirements, certification programs, and training resources while fostering collaboration among stakeholders such as government agencies, industry groups, DER operators, manufacturers, and research institutions. A phased roadmap is outlined to refine and implement these measures through pilot testing and widespread adoption. Ultimately, the report underscores the urgent need for coordinated efforts to enhance DER cybersecurity and ensure the reliable operation of future energy systems.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Security Enhancement of Network Constraint Grid-Edge Energy Management System

Network constrained grid edge energy management system (EMS) provides economic solution for active and reactive power dispatch of distributed energy resources (DERs) at the grid edge level. Grid edge EMS ensures secure interconnection of a circuit segment to the distribution system by maintaining grid code requirements (e.g. IEEE 1547–2018). Grid edge EMS is dependent on communication to receive load measurement, which brings a risk of unobservable false data injection attacks (FDIAs). To mitigate the risk, this paper proposes a framework to enhance resilient operation of grid edge EMS by detecting the unobservable FDIAs on loads and replacing them with forecasted values. In this work, a two-step detection algorithm is proposed. In first step, conventional residual based algorithm is deployed. Autoencoder (AE) based data driven mechanism is included in second step to detect the presence of unobservable FDIAs. After ensuring the presence of FDIA, its specific location is detected by checking the maximum residue values till the predefined threshold value is reached. Detected false data injected loads are then replaced with forecasted load values following long-short term memory (LSTM) based forecast to ensure resilient performance of grid edge EMS in the presence of attacks. This proposed security enhancement framework for grid edge EMS is evaluated in IEEE 13 bus system with three integrated DERs. Numerical simulation shows the validation of the proposed framework by reducing voltage violation in real operation of grid edge EMS.

cyber attack detection↗

Cybersecurity for Distributed Energy Resources: All Hazards Approach for Grid Modernization

Distributed energy resources (DER) sit at the intersection of IoT and critical infrastructure. As we work towards clean energy and decarbonization targets, high rates of growth of DER are expected, making them an important component of generation and grid services. They have been a part of the explosion of internet connected devices developed to solve real-world problems and make life easier by providing clean, local energy and enable the smart management of grid services. However, the quick-to-market, low-cost drivers for DER, combined with a historically relative low-impact has meant that cybersecurity has not been a top priority. So as DER penetration increases, will DER be a part of the growing challenge of securing the grid, or part of the solution for necessary grid modernization? In this talk, we will discuss the factors that have led to our current position and what makes cybersecurity for DER unique. A wide range of research is conducted at national labs, in partnership with industry and academia, to inform everything from standards and regulation, to the development of cyber-physical anomaly detection through use of digital twins, and even advanced threat analytics to SBOM and HBOM tracking. Even with this multi-faceted approach to the challenges, the question remains: is this too little too late or are we doing enough to secure the grid for the next 30 years?

14 SOLAR ENERGY↗

Cyber–physical vulnerability and resiliency analysis for DER integration: A review, challenges and research needs

High penetration of renewable and sustainable Distributed Energy Resources (DER) into the traditional distribution system requires a well-coordinated control strategy for the improvement of system-wide reliability and resiliency. Implementation of such a holistic control architecture requires a flexible, near real-time, and bi-directional communication framework for facilitating the participation of various agents in a multi-vendor heterogeneous smart grid. While the sustainability of energy generation is ensured, this exposes the smart grid to extrinsic cyber threats, and appropriate defense mechanism(s) must be deployed to guarantee continued reliability and resiliency of the power grid. Further, the comprehensive literature review presented in this paper discusses the latest trends in the DER control schemes with fast communication requirements and their accompanying cyber–physical vulnerabilities. These control schemes are compared and contrasted for various traits. A three-level DER system architecture has been depicted, facilitating the deployment of these control schemes. The current developments of standard communication protocols, key security mechanisms, and best practices along major standards and guidelines are explored. The impacts of different attack types with miscellaneous DER functions based on various control schemes and associated mitigation solutions are also provided. Finally, challenges and future research directions for limiting cyber-power susceptibility to enhance resiliency are summarized. The work presented here will help us enabling a cyber-resilient and sustainable smart electric grid.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cybersecurity Assessment Tools for Distributed Energy Resources

This growing number of smart devices that support DERs can increase the number of access points outside a utility’s administrative domain, which can increase the potential for cyberattack. With the integration of DERs at federal sites, the cybersecurity vulnerabilities of DER systems must be understood and addressed. This presentation covers two NREL tools available. The Distributed Energy Resource Cybersecurity Framework (DER-CF) is a web-based holistic tool for evaluating cybersecurity posture including governance, physical security and technical management. The Distributed Energy Resource Risk Manager (DER-RM) extends the DER-CF by applying it to the NIST risk management framework process. It will be downloadable application that runs locally and documents all the major requirements for achieving Authority to Operate the DER.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

Real-time Implementation of Grid Code Compliant Grid Edge Energy Management System

Integrated distributed energy resources (DER) in a distribution system need to follow grid codes to avoid violations that result in DER/circuit segment disconnection. To comply with grid code requirements at the grid edge level, network constrained grid edge energy management system (EMS) can be deployed. The objective of grid edge EMS is to provide economic solution for active and reactive power DER setpoints at each dispatch interval and ensure voltage regulation to support secure interconnection of the grid edge segment to the distribution system with multiple inverter based DER units. In this work, real-time simulation of grid code compliant grid edge EMS is deployed in a realistic feeder circuit segment. For real-time simulation, communication between the grid edge EMS and DERs is done exploiting IEC 61850-7-420. It enables interoperability among different DERs and grid edge EMS. No prior art has deployed IEC 61850-7-420 GOOSE communication protocol for grid edge EMS. Conversion of IEC 61850 GOOSE messages to Modbus communication protocol is also performed to communicate with grid edge EMS in commodity-off the shelf embedded boards in this work. The real-time simulation in OPAL-RT real-time digital simulator shows the out-performance of grid edge EMS by reducing the voltage violation in the distribution circuit.

Energy management system↗

Secure Communications Concept and API Concept for Integrating XENDEE Positronix with TESLA PowerPack System at Site 300 (Final Deliverable)

The CleanStart DERMS project focuses on the management of Distributed Energy Resources (DER) for enhanced distribution grid resilience. The demonstration site has changed from Riverside Public Utility to the LLNS Site 300 DERS demonstration site. This project has so far focused only on device level controllers and local area controllers. These controllers potentially lack the ability to perform supervisory control and grid interactive control functions, essential for grid-level optimal DER management. This project seeks to close that gap in development of secure communication concept and appropriate Application Programming Interfaces (API) to enable integration with DERs, device level and local area controllers, such as Distributed Energy Resources Management System (DERMS).

24 POWER TRANSMISSION AND DISTRIBUTION↗

Impact of High Penetration Distributed Energy Resources on the Bulk Electric System

The growth of distributed energy resources (DERs), mostly generation using intermittent renewable energy sources, along with the retirement of central generation (mostly conventional power plants using fossil-fuel-based resources) has implications for the steady-state and dynamic performance of the bulk electric system (BES). Among the DERs connected to the distribution system, photovoltaic (PV) systems are the most prevalent and have been installed at an increasing rate. Until recently, the penetration levels of DERs have not been high enough to create significant impacts on the reliability and security of power system operation. However, in recent years, the penetration levels of DERs have risen to a level that their impacts on the bulk electric system should be considered in a detailed fashion in planning and operations.

24 POWER TRANSMISSION AND DISTRIBUTION↗

EVs-at-RISC: A Secure and Resilient Interoperable SCM Control System Architecture for Electric Vehicle’s-at-Scale (Final Technical Report)

The EVs-at-RISC project was a five-year research, development, and demonstration initiative to create foundational tools for utility-scale fleet aggregation and Smart Charge Management (SCM) of Electric Vehicles (EV), Electric Vehicle Charging Infrastructure (EVCI), and related Distributed Energy Resources (DER). Rather than seeking to develop and demonstrate highly perfected SCM algorithms and control strategies, this project instead focused on creating foundational software solutions that enable unprecedented digital interoperability across the communications technologies and vendor platforms used to manage EV , EVCI, and DER, as well as existing energy management infrastructure operated by utilities, grid operators, and aggregators. This project then extends these novel interoperability capabilities to develop and deploy powerful middleware abstractions across grid edge networks and EVCI/DER fleet aggregations incorporating modern software tools and best practices, such as CI/CD, to bring the immense capabilities of infrastructure-as-code and policy-as-code to modern grid edge network environments. This addresses the foremost systemic issues preventing realization of any net operational benefits from scaled deployment of behind-the-meter EV, EVCI, and DER assets in electric power grids and markets today. The results of this approach and project unlock massive potential for new SCM capabilities to be easily prototyped, evaluated, and deployed at-scale within the existing grid edge network infrastructure and EVCI/DER technology ecosystem. The EVs-at-RISC project achieves this by extending Open Field Message Bus (OpenFMB), a conceptual model for digital interoperability and distributed intelligence in traditional front-of-meter utility SCADA networks, validating our hypothesis that OpenFMB could be similarly used to solve systemic digital interoperability issues in behind-the-meter environments and unlock real-world utility-scale SCM capabilities without requiring any new proprietary vendor solutions or significant infrastructure reconfiguration.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Module-OT: A Hardware Security Module for Operational Technology

Increased penetration levels of renewable energy and other types of distributed energy resources (DERs) on the modern electric grid-combined with technological advancements for electric system monitoring and control-introduce new cyberattack vectors and increase the cyberattack surface of energy systems. According to the IEEE Std. 1547-2018, DERs must use Modbus, Distributed Network Protocol 3 (DNP3), or Smart Energy Profile 2.0 (SEP2) as their communication protocol. Previous research identified several vulnerabilities and security breaches in each one of these communication protocols; despite this, existing standards for DERs do not recommend cybersecurity measures. In order to reduce vulnerabilities in power distribution systems, this paper presents a novel open-source hardware security module that improves both information and operational security to better protect data and communications on the distribution grid. The security hardware is called “module for operational technology,” or simply Module-OT, and it has been validated and tested in an emulated distribution system application. Module-OT is integrated within a communication system in the transport layer of the Open Systems Interconnection (OSI) model. It improves system security through encryption, authentication, authorization, certificate management, and user access control. The main advancement of Module-OT is the addition of hardware cryptographic acceleration that improves the overall communication performance in terms of end-to-end latency.

70 PLASMA PHYSICS AND FUSION TECHNOLOGY↗

Sensing Electrical Networks Securely & Economically (SENSE)

The growing adoption of distributed energy resources (DERs) like battery energy storage systems and roof top solar/PV and the rapid penetration of electric vehicles (EVs), the electric grid is undergoing a major transformation with elevated stress on legacy grid assets. Despite a lot of expenditure to address these challenges, both in dollars and manpower, utilities have not been able to receive the value that was promised. The gains have been most visible at the transmission and substation level, especially where the main objective was improving operational and economic efficiency for the utility. Improving visibility and control at a few select points enhances the existing and established paradigm of centralized command and control. With changing load patterns, load types and the overall transition to an “active grid”, the centralized control and coordination paradigm gets challenged. To address the challenges, a new architecture and mechanism is needed, one that supports decentralized control and decision making, extracting value streams at the grid edge, particularly as the changes are fueled by transitions occurring in the distribution system. To address this, a communications and data processing platform, “GAMMA” was developed and demonstrated through the project. At the heart of the platform, are distributed, intelligent edge nodes with sensing and compute capabilities, that can record and analyze information locally. They are embedded in sensors and actuators specific to different distribution system applications. Phase 1 of the project focused on developing novel sensor technology that can be used for monitoring utility pole top distribution transformers. The sensors were designed with the objective of being low-cost, communicating with the GAMMA cloud using novel “delay-tolerant” networking using Bluetooth and a secure mobile application. They were non-intrusive in nature so that they can be installed quickly in the field, resulting in overall low cost of deployment and operations. Following the successful completion of Phase 1, the team manufactured 100 units for a field demonstration in Phase 2. The field demonstration was carried out on two real feeder systems with the local utility partner. In total, 100 sensors were installed and operated over a period of 6 months in the state of Georgia. The platform is operational end to end, with the cloud infrastructure deployed on a distributed, serverless environment that can serve multiple data streams, an analytics engine and a portal to securely view the data from multiple assets. The data collected through the GAMMA Mobile Phone app showcased the viability of the novel delay tolerant networking architecture, and the data processing algorithms developed through the course of the project, were successful in extracting important information about the overall network, improving the utility’s visibility and situational awareness in the distribution feeder.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Faster-than-real-time Simulation with Demonstration for Resilient DER Integration

The US electric grid is facing operational, stability, and security challenges. Transmission system operators need some measure of visibility into distribution system renewable generation. Distribution system generation needs to support transmission system voltage. The grid is experiencing an expansion in measurement systems. How to take full advantage of this expansion and defend against attacks, both cyber and physical, poses additional challenges. The Faster-than-real-time Simulation with demonstration for Resilient DER Integration project set out to do the following: a. Flatten the voltage profile through the feeders and system for cost saving and voltage stabilization needs. b. Increase the amount of intermittent distributed energy resources (IDERs) that could be deployed on a utility feeder and provide 100% or more energy needed for the demands on that feeder, and c. based on an accurate model (Digital Twin) of the utilities system, be able to detect any abnormalities on the utilities distribution system. To manage the voltage and increase IDER penetration (a,b), Graph Trace Analysis is employed in a time-series, optimal power flow to coordinate the time-varying feedback control setpoints of a distribution feeder’s utility control devices. Under the coordinated control are a Load Tap Changing Transformer, a voltage regulator, and five switched capacitor banks. The feeder serves over 2000 customers, the feeder secondaries are modeled, and the feeder has 2.3 MW of PV generation, corresponding to a 17.4% penetration of PV generation. The feeder model has over 12,000 components, where every customer load bus and PV generator are modeled. The accuracy of the power flow solution is compared against historical meter voltage measurements, the improvement in conservation voltage reduction energy savings as a function of the coordinated control desired voltage profile is investigated, and the increase in PV penetration of the coordinated control over the existing control is presented. To achieve improved control performance while observing system operation constraints, bellwether Advanced Metering Infrastructure (AMI) voltage measurements are used to adjust the desired voltage profile used by the optimal power flow analysis. To detect and alleviate or negate attacks or failures on the distribution and transmission utility grids (c) the grid needs to be resilient and self-healing. In this project software was designed to do just that. At the center of the software is an Integrated System Model (ISM) that spans from transmission to secondary distribution. The ISM is employed in real-time abnormality detection, voltage stability forecasting, and multi-mode control. Testing results are presented for: 1—attacks on utility infrastructure; 2—energy savings from optimal control; 3—distribution system control response during a low voltage transmission system event; 4—cyber-attacks on PV inverters, where physical inverters are used in hard-ware-in-the-simulation-loop studies. Contributions of this work include real-time analysis that spans from three-phase transmission through secondary distribution; an approach for detecting abnormalities that employs measurements from three independent measurement systems; and a multi-mode distribution system control that responds to cyber-attacks, physical attacks, equipment failures, and transmission system needs.

Integrated System Model, Graph Trace Analysis, Adv↗

Incentivizing Distributed Energy Resource Participation in Grid Services

The bulk power system is experiencing a dramatic shift as renewable generation growth continues to accelerate. Large-scale renewables adoption will help societies transition to a low-carbon, low-cost, and environmentally friendly electrical power system. However, the transition from a paradigm of generation following load to one where load follows generation will require large-scale interconnection and coordinated operation of Distributed Energy Resources (DERs), supported by open communication protocols. In this future grid scenario, DER aggregations will provide critical grid services that enable high penetration levels of renewable generation. This position paper presents an Energy Service Interface (ESI) that defines scope for ensuring secure, trustworthy information exchange between grid service providers and DERs. The goal of the ESI is to encourage large-scale participation of DERs in order to provide grid services through dispatch of DER aggregations. This position paper also presents an open smart energy communications protocol that allows DERs to advertise their characteristics and participate in grid services, within constraints established by the ESI. The paper presents several monetization incentives that grid service providers could use to encourage large-scale DER participation.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

TrustDER: Trusted, Private and Scalable Coordination of Distributed Energy Resources

In this project, the Stanford and SLAC Teams have developed a Trusted, Private and Scalable platform for coordinating Coordination of Distributed Energy Resources (TrustDER). This is a layered system that ensures private, trusted and scalable coordination and monitoring of DERs. It accommodates a variety of resources, such as solar generation, gensets and loads, with a particular focus on battery systems-based resources, as they are a transformational technology experiencing fast growth in adoption by large critical facilities. The platform can be used as standalone or added to existing aggregation systems to enable trust, privacy and resilience. TrustDER consists of layers that address each of the shortcomings of the existing state of the art. Each layer in the platform can operate independently but provides information to the layers above it to enable a novel form of overall coordination architecture. The project consists of several tasks, with each task dedicated to the design of each layer. Task 2 Resource Virtualization defined a software abstraction layer for distributed energy resources (DERs). The goal of this abstraction was to simplify the implementation of algorithms utilizing cooperation of DERs resources in a variety of use cases. Task 3 is on Secure ID for Asset Authentication. Identity Management Systems (IDMS) are a foundational infrastructure for interactions between entities (organizations, users, devices, and services). Secure ID is blockchain-based a distributed identity management system allowing (1) identity provisioning, (2) authentication, (3) authorization, and (4) identity data sharing for IoT-enabled assets on the electricity grid. In this project, the SLAC team focused on designing and testing Keymaker, a protocol for authenticating device identity managed by Secure ID. Task 5 Private and Safe Integration is focused on the design and evaluation of a DER cooperation scheme which allows for the aggregation of DERs without impacting network reliability. The approach is designed based on realistic assumptions regarding data availability, communication infrastructure limitations, and privacy. Task 6 Scalable Distributed Privacy for Information explored how virtualized batteries could be managed privately. Specifically, it examined the case in which a principal provides a partitioned battery to multiple clients. Task 7 Use Cases was to ensure that this technology was applied in relevant situations and scenarios. Primarily, this means that virtualization needed to be employed in a manner that either improved flexibility, bolstered security or privacy, or decreased costs.

25 ENERGY STORAGE↗

Electrical substation grid testbed for DLT applications of electrical fault detection, power quality monitoring, DERs use cases and cyber-events

Electrical utilities continue to deploy more intelligent electronic devices (IEDs) inside and outside electrical substation, and are associated with customer-owned distributed energy resources (DERs). The integrity and confidentiality of data from these IEDs, like power meters and protective relays, is crucial. Blockchain technology could improve the resilience of microgrids by improving the security of data sharing. The penetration of customer-owned DERs (renewable energy sources) and the increasing deployment of IEDs can lead to integrate power system applications with Distributed Ledger Technology (DLT). In this study, we implemented the electrical faulted phase detection and power quality monitoring algorithms with a Cyber Grid Guard (CGG) system using DLT. In addition, the DERs (wind turbine farms) use case and protective relay cyber-event tests were assessed, by using the CGG system with DLT. In the experimental model, the testbed was created by using a real-time simulator and CGG system with power meters/ protective relays in-the-loop. The data collected from the CGG system and IEDs were compared with the same time stamp source. These results had shown the successful assessment of protection, control and monitoring applications using a CGG system with DLT. In the future, the ESGT with DERs and the CGG system will be used in other power system applications, based on implementing smart contracts between electrical utilities with customer-owned DERs.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Security Constrained Economic Optimization of Photovoltaic and Other Distributed Assets

The rapid growth of distributed energy resources (DERs), especially photovoltaic (PV) systems, has introduced new complexities in maintaining grid reliability, stability, and cost-effective operation. This project addresses these challenges by developing and demonstrating a scalable GridOS Distributed Energy Resource Management System (DERMS) that enables secure, real-time optimization and control of DERs at the distribution feeder level.

14 SOLAR ENERGY↗

DER as a service-ecoLong and VOLTTRON (Abstract)

The project goal is to commercialize the VOLTTRON-hosted “DER as a Service” (DaaS) application and make it an “out-of-the-box” solution for ecoLong to use as a secure residential energy management system that allows 1.) distributed energy resources (DERs) to participate in wholesale markets and provide services to the grid and 2.) intelligently control the energy in the residential buildings to the desired level while maintaining occupancy comfort. The product will be field deployed onto multiple Solar Liberty sites in New York state to demonstrate wide-scale participation of DERs in wholesale markets to provide services to the grid and validate the effectiveness of the solution. The integrated management of DERs and buildings increases the penetration of solar resources by managing its variability, providing grid services, and solving the evening ramping challenges. Ultimately, the DaaS platform will make buildings and DERs smarter by unlocking grid-interactive efficient buildings.

24 POWER TRANSMISSION AND DISTRIBUTION↗