Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Control Systems Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Network Security Challenges and Countermeasures for Software-Defined Smart Grids: A Survey

The rise of grid modernization has been prompted by the escalating demand for power, the deteriorating state of infrastructure, and the growing concern regarding the reliability of electric utilities. The smart grid encompasses recent advancements in electronics, technology, telecommunications, and computer capabilities. Smart grid telecommunication frameworks provide bidirectional communication to facilitate grid operations. Software-defined networking (SDN) is a proposed approach for monitoring and regulating telecommunication networks, which allows for enhanced visibility, control, and security in smart grid systems. Nevertheless, the integration of telecommunications infrastructure exposes smart grid networks to potential cyberattacks. Unauthorized individuals may exploit unauthorized access to intercept communications, introduce fabricated data into system measurements, overwhelm communication channels with false data packets, or attack centralized controllers to disable network control. An ongoing, thorough examination of cyber attacks and protection strategies for smart grid networks is essential due to the ever-changing nature of these threats. Previous surveys on smart grid security lack modern methodologies and, to the best of our knowledge, most, if not all, focus on only one sort of attack or protection. This survey examines the most recent security techniques, simultaneous multi-pronged cyber attacks, and defense utilities in order to address the challenges of future SDN smart grid research. The objective is to identify future research requirements, describe the existing security challenges, and highlight emerging threats and their potential impact on the deployment of software-defined smart grid (SD-SG).

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber–Physical System Security of Distribution Systems

The Information and Communications Technology (ICT) for control and monitoring of power systems is a layer on top of the physical power system infrastructure. The cyber system and physical power system components form a tightly coupled Cyber–Physical System (CPS). Sources of vulnerabilities arise from the computing and communication systems of the cyber–power grid. Cyber intrusions targeting the power grid are serious threats to the reliability of electricity supply that is critical to society and the economy. In a typical Information Technology environment, numerous attack scenarios have shown how unauthorized users can access and manipulate protected information from a network domain. The need for cyber security has led to industry standards that power grids must meet to ensure that the monitoring, operation, and control functions are not disrupted by cyber intrusions. Cyber security technologies such as encryption and authentication have been deployed on the CPS. Intrusion or anomaly detection and mitigation tools developed for power grids are emerging. Furthermore, this survey paper provides the basic concepts of cyber vulnerabilities of distribution systems and CPS security. The important ICT subjects for distribution systems covered in this paper include Supervisory Control And Data Acquisition, Distributed Energy Resources, including renewable energy and smart meters.

97 MATHEMATICS AND COMPUTING↗

Energy Management Information Systems Cybersecurity Best Practices

Energy management information systems (EMIS) are a broad and rapidly evolving family of tools that monitor, analyze, and control building energy use and system performance. Critical systems are often integrated with or operate on the same networks as EMIS scope systems, necessitating stable, continuous, and secure communication. When connecting EMIS to building automation and utility control systems, there are also many physical assets that could cause harm to the building and its occupants if a malicious act or human error were introduced. It is imperative to ensure all EMIS scope systems are connected securely to the EMIS and do not open vulnerable pathways to other facility networks and operations. The Federal Energy Management Program (FEMP) promotes best practices for impactful utilization of EMIS at federal facilities. This best practice document is part of a series of fact sheets created to help accelerate the market adoption and use of EMIS in the federal sector. It provides an overview of required EMIS cybersecurity standards for compliance and authority to operate along with additional recommendations.

cybersecurity↗

Energy Management Information Systems Cybersecurity Best Practices

Energy management information systems (EMIS) are a broad and rapidly evolving family of tools that monitor, analyze, and control building energy use and system performance. Critical systems are often integrated with or operate on the same networks as EMIS scope systems, necessitating stable, continuous, and secure communication. When connecting EMIS to building automation and utility control systems, there are also many physical assets that could cause harm to the building and its occupants if a malicious act or human error were introduced. It is imperative to ensure all EMIS scope systems are connected securely to the EMIS and do not open vulnerable pathways to other facility networks and operations. The Federal Energy Management Program (FEMP) promotes best practices for impactful utilization of EMIS at federal facilities. This best practice document is part of a series of fact sheets created to help accelerate the market adoption and use of EMIS in the federal sector. It provides an overview of required EMIS cybersecurity standards for compliance and authority to operate along with additional recommendations.

Cybersecurity↗

Deny-by-Default Network Port Security: SPaRC Technical Bulletin #002

Operational Technology (OT) networks [e.g., industrial control systems (ICS) and supervisory control and data acquisition (SCADA) systems] have unique cyber security challenges due to their decades long service life, high availability requirements, and limited visibility. OT networks often take credit for being “air gapped” (i.e. disconnected from the Internet) and all devices within the OT network can “talk” to each other—even if they should not. This SPaRC Technical Bulletin describes how the unique limitations of OT networks can become strengths when it comes to cybersecurity.

Cybersecurity↗

Designing Secure and Resilient Cyber-Physical Systems Using Formal Models

This work-in-progress paper proposes a design methodology that addresses the complexity and heterogeneity of cyber-physical systems (CPS) while simultaneously proving resilient control logic and security properties. The design methodology involves a formal methods-based approach by translating the complex control logic and security properties of a water flow CPS into timed automata. Timed automata are a formal model that describes system behaviors and properties using mathematics-based logic languages with precision. Due to the semantics that are used in developing the formal models, verification techniques, such as theorem proving and model checking, are used to mathematically prove the specifications and security properties of the CPS. This work-in-progress paper aims to highlight the need for formalizing plant models by creating a timed automata of the physical portions of the water flow CPS. Extending the time automata with control logic, network security, and privacy control processes is investigated. The final model will be formally verified to prove the design specifications of the water flow CPS to ensure efficacy and security.

42 ENGINEERING↗

Security Assessment of an LBP16-Protocol-Based Computer Numerical Control Machine

Subtractive manufacturing systems, specifically, computer numerical control machines, have revolutionized the manufacturing industry. Computer numerical control machining is the preferred method for producing finished parts due to its efficiency, speed and suitability for high-volume production. Securing computer numerical control machines is a priority. Compromises or disruptions of these machines can result in significant downtime, loss of productivity and financial loss. This study examines the vulnerabilities and risks associated with computer numerical control machines, in particular, systems utilizing the LBP16 protocol for controller-machine communications. The study reveals that an adversary can execute cyber-physical attacks such as sabotage and denial of service. The potential security threats emphasize the importance of implementing robust security measures to mitigate the cyber risks to computer numerical control machines.

Forihat, Yahya [Virginia Commonwealth University, ↗

Enhanced Control, Optimization, and Integration of Distributed Energy Applications (ECO-IDEA)

With support from the U.S. Department of Energy Solar Energy Technologies Office, the National Renewable Energy Laboratory (NREL) partnered with Xcel Energy, Schneider Electric, Varentec, and Electric Power Research Institute (EPRI) to meet the goals of the Enabling Extreme Real-Time Grid Integration of Solar Energy (ENERGISE) program. This project developed and validated an innovative data-enhanced hierarchical control architecture that enables the efficient, reliable, resilient, and secure operation of future distribution systems with a high penetration of distributed energy resources like solar energy. The architecture enables a hybrid control approach where a centralized control layer is complemented by distributed control algorithms for solar inverters and autonomous control of grid edge devices. It is fully interoperable and includes all the cybersecurity aspects necessary for reliable and secure system operation. The hybrid approach can seamlessly integrate multiple voltage-regulation technologies, both at central and grid-edge levels, which enables reliable and efficient system operation in the face of unpredictable conditions. The overarching goal of the Eco-Idea project is to develop, validate, and deploy a unique and innovative Data-Enhanced Hierarchical Control (DEHC) architecture that comprehensively addresses the formidable challenges associated with proliferation of high penetration of distributed PV such as reverse power flows, transients from variability of PV systems, feeder load balancing, and voltage stability. These issues are exposing the weaknesses of existing grid operations and controls - including, but not limited to, lack of grid situational awareness, heuristic and slow-acting control actions, latency of control for emergency situations, and points of failure in communications. The proposed architecture will comprehensively resolve the deficiencies of current operational settings - where monitoring and control solutions proposed across industry and academia may not be interoperable and may not coexist in the same system - and will enable an efficient, reliable, resilient, and secure operation of future distribution systems with penetration of solar energy well beyond current limits. The DEHC architecture was developed and validated rigorously through hardware-in-loop simulations in the laboratory environment and deployed on the field.

24 POWER TRANSMISSION AND DISTRIBUTION↗

ARCADE (Advanced Reactor Cyber Analysis and Development Environment)

SAND2025-11780O ARCADE (Advanced Reactor Cyber Analysis and Development Environment) software performs cybersecurity experiments on Defensive Cyber Security Architectures (DCSA) for Distributed Control Systems (DCSs). The application is integrated into a cohesive environment that performs cyber risk analyses and reduces costs. ARCADE can investigate the entire cyber-attack surface of a DCS from the physics of control, down to the firmware of individual components with automated efficiency. ARCADE has five major functional components: the Data Broker system, the virtualization environment, the cyber-attack simulator, the cyber-physical analysis system, and the physics simulator. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Valme, Romuald↗

Module-OT: A Turnkey Solution for Securing Energy Systems

The Modular Security Apparatus for Managing Distributed Cryptography for Command-and-Control Messages on Operational Technology Networks (Module-OT) is a flexible and lightweight solution for grid-edge devices focusing on end-to-end security. It is a bump- in- the-wire solution acting as a secure conduit for data between devices or systems across a network. It improves the cybersecurity posture of DER systems by providing authentication, authorization, and data integrity to secure DER communications. Additionally, it performs key management, provides data security through whitelisting Internet Protocol addresses and ports, blocks unauthorized connections, controls user access, and allows serial or Ethernet connections for added flexibility. The core software is portable to various Linux-based operating systems and is developed to be customized by the developer and researcher communities. Module-OT has been validated in the lab, has been demonstrated at a 500-KW PV-plus-storage site, and has been proven ready to secure operational technology devices. Its core functionality meets current standards, including validation procedures of the NIST Cryptographic Algorithm Validation Program (CAVP) and the Federal Information Processing Standard (FIPS 140-2). Because of its capability to provide an accessible and affordable option for stepping up security across modern energy systems, Module-OT can serve as an effective technological option to standardize cybersecurity moving forward.

cryptography↗

AOI-2, A Novel Access Control Blockchain Paradigm for Cybersecure Sensor Infrastructure in Fossil Power Generation Systems

Fossil power generation systems are increasingly vulnerable to attack from both cybercriminals as well as internal threats. These vulnerabilities demand that emerging technologies such as blockchains be utilized to secure the data involved in the information flows within the Supervisory Control and Data Acquisition (SCADA) systems of the fossil power generation plants. The publicly accessible blockchain protocols, although secure, are visible to everyone. Even private blockchains currently are unable to support different levels of access to different participants, which is a critical requirement for the existing SCADA systems running the power plants. In light of the above, novel blockchain protocols that are specifically adapted to fossil power generation environments need to be developed in order to achieve the goal of cybersecure sensor networks. In this work, we address this question by creating a novel blockchain technology, namely smart private ledger, for cybersecure communication within the fossil power generation systems. A lab-scale sensor network consisting of strain and temperature sensors is constructed to develop the ledger. The technology has hierarchical access control which is compatible with the existing SCADA systems in fossil power plants. The sensor data is used with cryptographic digital signatures and secret sharing protocols within the nodes of the blockchain technology. The research results will lead to cybersecurity for machine-to-machine interactions, infrastructure for secure data logging for sensors, decentralized data storage, and second-layer technologies for high volume machine-to-machine interactions in the power plants. The work aims to largely address the concerns for the security of distributed sensor networks in such systems that can be compromised by insider threats and by cybercriminals. The research has led to the training of the next generation of engineers and scientists in the important areas of sensor engineering and blockchain technology.

01 COAL, LIGNITE, AND PEAT↗

Impact of Blockchain Delay on Grid-Tied Solar Inverter Performance: Preprint

This paper investigates the impact of the delay resulting from a blockchain, a promising security measure, for a hierarchical control system of inverters connected to the grid. The blockchain communication network is designed at the secondary control layer for resilience against cyberattacks. To represent the latency in the communication channel, a model is developed based on the complexity of the blockchain framework. Taking this model into account, this work evaluates the plant’s performance subject to communication delays, introduced by the blockchain, among the hierarchical control agents. In addition, this article considers an optimal model-based control strategy that performs the system’s internal control loop. The work shows that the blockchain’s delay size influences the convergence of the power supplied by the inverter to the reference at the point of common coupling. In the results section, real-time simulations on OPAL-RT are performed to test the resilience of two parallel inverters with increasing blockchain complexity.

41 EE - Solar Energy Technologies Office (EE-4S)↗

Companion Assisted Software Based Remote Attestation in SCADA Networks

Critical infrastructure such as power generation and water distribution systems have become a priority target in cyber warfare because of their recent computerization and introduction to the internet. As a result, Supervisory Control and Data Acquisition (SCADA) system security has become a hot topic in academic and industrial research. Among these topics, Remote Attestation is a security method intended to detect the presence of fileless malware in remote devices as they continue to operate. This allows for the detection of malware in the absence of long-term storage artifacts before symptoms of compromise begin to appear. In general, a trusted device (the verifier) makes a request for evidence of innocence from the untrusted device (the prover). In software-based schemes, the verifier can then measure the delay between its request and the prover’s response. If this delay is greater than the known computational time of the evidence gathering algorithm performed by the prover, then evidence may have been forged. Multi-hop networks often introduce too much network jitter to allow accurate measurement of prover response time, which limits the effectiveness of software based Remote Attestation in a real-world setting. In this work, we introduce a companion device that the verifier can trust to perform a subset of attestation, thereby removing any network jitter. This device is a Field Programmable Gate Array (FPGA) that is physically connected to the prover. We provide a communication protocol between the verifier, prover, and companion. To evaluate our scheme, we simulate it in a common SCADA network environment under normal and heavy traffic loads. Our simulations are performed in the discrete event network simulator NS-3, and we perform statistical analysis over our results to show that our scheme allows for tight timing constraints to be placed on the prover such that the verifier can more easily determine the validity of the evidence that it receives.

Johnson, William A.↗

Network visualization, intrusion detection, and network healing

The present disclosure is related to a cyber-security system that includes a Supervisory Control and Data Acquisition (SCADA) network monitor configured to receive a data set from a power system network, an event manager, and a mitigation system, where the SCADA network monitor includes an anomaly detector.

Rivera, Joshua Eli↗

Deploying Software-Defined Networking in Operational Technology Environments

Software Defined Networking for Operational Technologies, referred to as OT-SDN, is a leading technology to secure critical infrastructure and command and control (C2) systems. As the name implies, OT-SDN networks are programmable, which allows system owners to utilize the characteristics of their physical process to inform the security of their network. There are best practices for deploying OT-SDN into an environment, whether it is all at once or over time (hybrid) that the network is converted to SDN technologies. Through the development of data mining tools and standardized process control, OT-SDN can be deployed reliably. These tools will minimize or eliminate any communication failures during the transition and provide the network owner with complete documentation of their environment. This documentation could enable or facilitate the network owner to pass any audits or policy checks (Authority to Operate) before being allowed to utilize the OT-SDN infrastructure.

Software Defined Networking, Operational Technolog↗

Cyber-Resilient Automatic Generation Control for Systems of AC Microgrids

In this paper we propose a co-design of the secondary frequency regulation in systems of AC microgrids and its cyber security solutions. We term the secondary frequency regulator a Micro-Automatic Generation Control (μ AGC) for highlighting its same functionality as the AGC in bulk power systems. We identify sensory challenges and cyber threats facing the μ AGC. To address the sensory challenges, we introduce a new microgrid model by exploiting the rank-one deficiency property of microgrid dynamics. This model is used to pose an optimal μ AGC control problem that is easily implemented, because it does not require fast frequency measurements. An end-to-end cyber security solution to the False Data Injection (FDI) attack detection and mitigation is developed for the proposed μ AGC. The front-end barrier of applying off-the-shelf algorithms for cyber attack detection is removed by introducing a data-driven modeling approach. Finally, we propose an observer-based corrective control for an islanded microgrid and a collaborative mitigation scheme in systems of AC microgrids. We demonstrate a collaborative role of systems of microgrids during cyber attacks. Furthermore, the performance of the proposed cyber-resilient μ AGC is tested in a system of two networked microgrids.

24 POWER TRANSMISSION AND DISTRIBUTION↗

INS–Support for Formal Cyber Security Education in Brazil–After Action Report

The adoption of digital technology into Instrumentation and Control (I&C) systems in nuclear facilities fundamentally changes the nature of these systems. Greater interconnectivity of reprogrammable, and functionally interdependent control systems has given rise to the need for computer security consideration in digital I&C Systems. The cyber security of I&C systems presents a growing risk to nuclear facilities and requires the development of educational and research tools to ensure the safety of these facilities. Currently there is a major gap in formal educational offerings on cyber security for these Operational Technology (OT) systems. To provide formal cyber security education resources, DOE’s office of International Nuclear Security (INS) partnered with the University of São Paulo (USP) to develop a training course on the cyber security of nuclear facility I&C systems using the hypothetical Nuclear Power Plant, Asherah.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Discovery of Signatures, Anomalies, and Precursors in Synchrophasor Data with Matrix Profile and Deep Recurrent Neural Networks (Final Project Report)

The widespread deployment of phasor measurement unit (PMU) across the U.S. together with the burgeoning machine learning technology made it possible to develop data-driven PMU data analytics to improve grid security and reliability in a more insightful and effective manner. Although PMU applications have been explored for over a decade, the representative PMU usage is limited to the bulk power system monitoring mainly due to the data integrity issues associated with PMUs (typically missing, fragmented, and wrongly amplified data). To forge a breakthrough on this stalemate and embrace PMUs for power system control and protection as well, we applied various advanced machine learning and big data analysis technology to the power system event detection and classification as the first step toward the power system control and protection pertaining to grid security enhancement.

24 POWER TRANSMISSION AND DISTRIBUTION↗