Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Control Systems Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

Discovery of Signatures, Anomalies, and Precursors in Synchrophasor Data with Matrix Profile and Deep Recurrent Neural Networks (Final Project Report)

The widespread deployment of phasor measurement unit (PMU) across the U.S. together with the burgeoning machine learning technology made it possible to develop data-driven PMU data analytics to improve grid security and reliability in a more insightful and effective manner. Although PMU applications have been explored for over a decade, the representative PMU usage is limited to the bulk power system monitoring mainly due to the data integrity issues associated with PMUs (typically missing, fragmented, and wrongly amplified data). To forge a breakthrough on this stalemate and embrace PMUs for power system control and protection as well, we applied various advanced machine learning and big data analysis technology to the power system event detection and classification as the first step toward the power system control and protection pertaining to grid security enhancement.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Formal verification and validation of run-to-completion style state charts using Event-B

State chart notations with ‘run to completion’ semantics are popular with engineers for designing controllers that react to environment events with a sequence of state transitions but lack formal refinement and rigorous verification methods. State chart models are typically used to design complex control systems that respond to environmental triggers with a sequential process. The model is usually constructed at a concrete level and verified and validated using animation techniques relying on human judgement. Event-B, on the other hand, is based on refinement from an initial abstraction and is designed to make formal verification by automatic theorem provers feasible. Abstraction and formal verification provide greater assurance that critical (e.g. safety or security) properties are not violated by the control system. In this paper, we introduce a notion of refinement into a ‘run to completion’ state chart modelling notation and leverage Event-B’s tool support for theorem proving. We describe the difficulties in translating ‘run to completion’ semantics into Event-B refinements and suggest a solution. We illustrate our approach and show how models can be validated at different refinement levels using our scenario checker animation tools. We show how critical invariant properties can be verified by proof despite the reactive nature of the system and how behavioural aspects of the system can be verified by testing the expected reactions using a temporal logic, model checking approach. To verify liveness, we outline a proof that the run to completion is deadlock-free and converges to complete the run.

97 MATHEMATICS AND COMPUTING↗

A review of artificial intelligence applications in manufacturing operations

Abstract Artificial intelligence (AI) and machine learning (ML) can improve manufacturing efficiency, productivity, and sustainability. However, using AI in manufacturing also presents several challenges, including issues with data acquisition and management, human resources, infrastructure, as well as security risks, trust, and implementation challenges. For example, getting the data needed to train AI models can be difficult for rare events or costly for large datasets that need labeling. AI models can also pose security risks when integrated into industrial control systems. In addition, some industry players may be hesitant to use AI due to a lack of trust or understanding of how it works. Despite these challenges, AI has the potential to be extremely helpful in manufacturing, particularly in applications such as predictive maintenance, quality assurance, and process optimization. It is important to consider the specific needs and capabilities of each manufacturing scenario when deciding whether and how to use AI in manufacturing. This review identifies current developments, challenges, and future directions in AI/ML relevant to manufacturing, with the goal of improving understanding of AI/ML technologies available for solving manufacturing problems, providing decision‐support for prioritizing and selecting appropriate AI/ML technologies, and identifying areas where further research can yield transformational returns for the industry. Early experience suggests that AI/ML can have significant cost and efficiency benefits in manufacturing, especially when combined with the ability to capture enormous amounts of data from manufacturing systems.

Plathottam, Siby Jose↗

Resilient State Recovery Using Prior Measurement Support Information

Resilient state recovery of cyber-physical systems has attracted much research attention due to the unique challenges posed by the tight coupling between communication, computation, and the underlying physics of such systems. By modeling attacks as additive adversary signals to a sparse subset of measurements, this resilient recovery problem can be formulated as an error correction problem. To achieve exact state recovery, most existing results require less than 50% of the measurement nodes to be compromised, which limits the resiliency of the estimators. In this paper, we show that observer resiliency can be further improved by incorporating data-driven prior information. Here, we provide an analytical bridge between the precision of prior information and the resiliency of the estimator. By quantifying the relationship between the estimation error of the weighted ℓ 1 observer and the precision of the support prior, this quantified relationship provides guidance for the estimator’s weight design to achieve optimal resiliency. Several numerical simulations and an application case study are presented to validate the theoretical claims.

24 POWER TRANSMISSION AND DISTRIBUTION↗

The NREL Sensor Laboratory Detection of Hydrogen Emissions

The development of a functional hydrogen detection system is a multifaceted process that integrates hardware, deployments strategies, and analytics which can be supported by the NREL Sensor Laboratory: 1. Support of the design, validation and optimization of sensing prototypes; 2. Guide optimized sensing element development, including control electronics; 3. Laboratory testing to validate/optimize metrological performance (measurement range, detection limit, etc.); 4. Provide test sites for field deployments representative of real-world scenarios with controlled hydrogen releases; 5. Develop sensor placement and operation guidance; 6. Provide guidance on electronics to accommodate facility integration; 7. Electrical safety designs to allow for operation within restricted zones; 8. Integration into facility monitoring and control systems; 9. Guide incorporation of cyber security elements to protect facilities from malicious attacks; 10. Modeling and application of advanced analytics to detect and quantify emissions; 11. Higher Order dispersion models to guide sensor placement for reliable detection; 12. Advanced analytics for improved metrological performances, and to inform inverse modeling; 13. Market support and commercialization (national and international markets); 14. Commercial deployments in H2@SCALE markets (e.g., HUBs and other large-scale hydrogen markets); and 15. Leverage off international collaborations/partnerships (e.g., NREL is on the advisory board for the European initiative "pre-Normative Research on Hydrogen Releases Assessment"-NHyRA).

08 HYDROGEN↗

Survey of Cybersecurity Governance, Threats, and Countermeasures for the Power Grid

The convergence of Information Technologies and Operational Technology systems in industrial networks presents many challenges related to availability, integrity, and confidentiality. In this paper, we evaluate the various cybersecurity risks in industrial control systems and how they may affect these areas of concern, with a particular focus on energy-sector Operational Technology systems. There are multiple threats and countermeasures that Operational Technology and Information Technology systems share. Since Information Technology cybersecurity is a relatively mature field, this paper emphasizes on threats with particular applicability to Operational Technology and their respective countermeasures. We identify regulations, standards, frameworks and typical system architectures associated with this domain. We review relevant challenges, threats, and countermeasures, as well as critical differences in priorities between Information and Operational Technology cybersecurity efforts and implications. These results are then examined against the recommended National Institute of Standards and Technology framework for gap analysis to provide a complete approach to energy sector cybersecurity. We provide analysis of countermeasure implementation to align with the continuous functions recommended for a sound cybersecurity framework.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Autonomous Energy Systems

Energy systems are increasingly complicated by the proliferation of clean energy technologies such as solar, wind, storage, electric vehicles, and building automations. Future energy systems will require secure, autonomous, and reliable communications, control, and interoperability among millions of distributed generation points and billions of buildings, vehicles, and more. To enable effective management of the anticipated growth of distributed devices and the deluge of data and extensive metering that will follow, the National Renewable Energy Laboratory (NREL) has developed the concept of autonomous energy systems (AES).

autonomous↗

Cyber Resilient Design and Controls for Energy Systems

As the grid of today is evolving into a highly distributed and autonomous cyber-physical system with higher penetration of Distributed Energy Resources (DERs) and autonomous controls that are dependent on the cyber infrastructure, there are novel and increasing challenges to cyber-resilient operation of the grid. While the traditional mechanisms take a "bolt on" approach to cybersecurity and resiliency, this talk presents two novel technologies developed at NREL that "bake in" security and resilience into the design and control of the grid. An Adaptive Resilience Metrics framework is a novel mechanism for system owners and operators to understand the impact of cyber and physical system design and topology on the resilient operation, while also helping determine optimal policies in response to adverse cyber events. Along with that a zero-knowledge proof-based technique helps incorporate security into the controls layer by focusing on computational integrity rather than data integrity. By leveraging design and control properties unique to Operational Technology systems these technologies will not only help enhance cyber-resilience for the grid of today, but a highly distributed and autonomous grid of tomorrow.

cyber resilience↗

Smart Inverters, Dumb Risk: Taking Control of IBR Security in the Digital Age

This presentation addresses the security challenges posed by Inverter-Based Resources (IBRs) in the modern energy landscape. The presentation highlights the vulnerabilities and risks associated with IBRs, including the potential for cyber-attacks, the impact of insecure defaults, and the systemic risks posed by supply chain dependencies. Key topics covered include: 1) The increasing digital transformation in energy systems and the associated security risks. 2) Specific vulnerabilities in IBRs, including weak passwords, hardcoded credentials, and insecure web application interfaces. 3) The implications of persistent connectivity and the strategic risks posed by foreign-manufactured components. 4) The role of regulatory frameworks, such as NERC CIP, in addressing these challenges and the limitations of current oversight. 5) Practical solutions for mitigating risks, including secure design practices, vendor risk assessments, and the importance of strong passwords and role-based access control. The presentation underscores the necessity of a comprehensive, system-of-systems approach to securing IBRs, emphasizing the need for collaboration across various stakeholders, including operators, developers, and regulators, to ensure the resilience and security of the energy grid.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

A Cybersecurity Threat Profile for a Connected Lighting System

In anticipation of improved energy performance and cost savings, cities and building owners are increasingly considering “smart lighting initiatives” that aim to convert their collection of simple luminaires (i.e., lighting fixtures) into an intelligent connected lighting system (CLS) capable of remotely monitoring energy consumption and fault conditions, and possibly implementing adaptive lighting schemes. The U.S. Department of Energy (DOE) has set an national goal of tripling the energy efficiency and demand flexibility of the buildings sector by 2030, relative to 2020 levels 1. It is forecast that connected lighting systems can contribute to that goal by delivering 125 TWh of annual energy savings by 2035 2, equivalent to the annual output of 50 typical (500 MW) power plants. However, these energy savings and the DOE goal are put at significant risk if connected technologies are not adopted due to real or perceived cybersecurity concerns. Connected IoT devices such as these have historically been rife with vulnerabilities which sometimes put security considerations secondary to functionality and operability. What are the cybersecurity threats that will impact these systems, as formerly banal luminaires transition into intelligent connected devices that collect information about themselves, their surrounding environment, and possibly us? In this paper we analyze a threat profile performed on a fault-detection use case for streetlights. A threat profile establishes security requirements, justifies security measures, yields actionable controls, and effectively communicates risk to stakeholders. This effort provides critical information for making threat-based decisions to increase security at a reasonable cost, and can effectively be used by development teams, software architects, and managers to make cybersecurity a part of their ongoing culture of awareness, training, and prevention. This leads to more secure systems and better-understood security. On-premise, cloud, and hybrid architectures with different authentication mechanisms were modeled and later categorized using the Microsoft STRIDE framework. An analysis of the recommended controls for each threat was performed to determine which controls could and should be put in place by manufacturers or third-party suppliers, and which controls need to be left up the end-user to implement. Fifty-seven threats were identified. Among our key findings: (1) 65% (37/57) of the threats did not involve the luminaires, but rather the other components needed to communicate with and manage them; (2) 63% (36/57) of the threats could have been mitigated through manufacturer-implemented defensive techniques or “controls”; and (3) 23% (13/57) of the threats were dependent on the network configuration. Recommendations based on the results of this work are made to key stakeholder groups. Notably, lighting technology developers are advised to address all threats that can be reasonably controlled with baked-in technology solutions (e.g., encryption or authentication controls), and employ some form of secure supply chain management and tracking where other parts (e.g., sensors, microprocessors) of a luminaire must also be built and manufactured with the proper security controls in place. Developers should also review threats involving assets not developed in-house to understand how connectivity with other devices will affect their product during system operation and determine if a compensating control for a defense-in-depth strategy will be needed. Finally, those interested in deploying CLS should compare the differences between cloud and on-premise models to determine which is more suitable for their needs and the abilities of their security team.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Command and Control of Utilities Systems

The utilities systems that encompass the Y-12 National Security Complex are an integral part of the entire campus, and are essential to maintaining critical mission focus for the site. Although the utilities systems each differ in function, the central production and distribution model creates a common thread on which each system is run. Several incidents in FY 2018 and FY 2019 documented a lack of overall systems control and highlighted the need to create a better command system that could maintain system availability and decrease possible impacts to the surrounding environment. An initial system was started in September of 2019 to better control mechanical utility distribution systems. The measurement of the system can be modeled against a standard command and control related incident. The corresponding work hours from a typical control-related incident were used as key component to this system model. System effectiveness is modeled against utility’s incidents that demonstrate a loss of command and control. The increased simulations of the model also document control can only be effectively contained within the stated time (3-5 years) by yielding more engineers to complete alignments, or drastically reducing the amount of time for alignments. The total control points of the model document a clear correlation between alignments, control points, and the amount of man-hours per incident. Current data shows that actual incident man-hours (1.88 manhours/ incident since initial system implementation) are near expected incident man-hours (1.81 manhours/ incident) with command and control for October 2021, which documents a 33.3% reduction in man-hours/incident since initial system implementation. A conclusion can be drawn that focus on increasing the amount of controlled points in the system can reduce incidents and the decrease the amount of non-value added work to employee’s day-to-day lives, while also achieving a culture that enhances and sustains utilities reliability.

99 GENERAL AND MISCELLANEOUS↗

Developing VSC-HVDC Oscillation Damping Control Constraints in Unit Commitment

High-voltage direct current (HVDC) systems within the existing power grids will play a pivotal role in enabling high share of renewable power integration and transportation electrification. There is a need for transmission planning models to accurately capture the impact of VSC-HVDC oscillation damping control on the system planning and model the constraints in the security constrained unit commitment (SCUC) problem. In this paper, the SCUC problem in a hybrid DC-AC grid considering damping on electromechanical inter-area oscillation is studied. An electromechanical oscillation-driven transmission capability constraints are derived from system swing equation and incorporated into the SCUC. Multiple system damping control scenarios are set based on the extracted plausible bounds of damping coefficient and inertia constant to linearize the nonlinear expressions. The SCUC problem with proposed constraints is tested on the IEEE 73-bus reliability test system (RTS) case via PLEXOS. The impact of the proposed constraints on regional generation, inertia, power flow, annual system cost, and renewable energy curtailment are fully assessed.

damping control↗

Need for research and training reactors for advanced reactor designs

Full text of publication follows. Research and training reactors have served a valuable role in helping train workforce for currently operating fleet of light water reactors. These research and training reactors have been used in reactor laboratory classes to familiarize the students with such vital concepts as approach to criticality, reactor period, neutron moderation, reactivity, flux distribution and leakage, etc. As the industry moves toward advanced non-light-water reactor designs, it is critical that research and training reactors be developed and deployed at university campuses to help train the new generation of nuclear and non-nuclear engineers who are likely to design, build, and operate these advanced reactors. Among the designs currently being pursued for nuclear power generation include molten salt, sodium cooled, and gas cooled designs, with options for various fuel forms. Thus, industry and DOE in collaboration with academic institutions should devise plans on how to familiarize the next generation of nuclear workforce with hands-on experience necessary for such designs. These research and training reactors will play a vital role in familiarizing the future workforce with hands-on experience with concepts associated with fast spectrum reactors, gas cooled reactors, and other features not associated with light water reactors. In addition to classical nuclear engineering concepts, these advanced research and training reactors can also be used for hands-on training as well as for research on features being considered in the design of GEN-IV reactors: cyber security for digital control room operations, hybrid energy system, hydrogen generation, district heating, autonomous control... (author)

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Survey of Cyber Risk Analysis Techniques for Use in the Nuclear Industry

Using traditional probabilistic risk analysis methods for severe accident safety risk management on non-digital systems, structures, and components at nuclear power plants is well-established. In contrast, cyber risk analysis of digital assets is still an immature field with unproven techniques due, in part, to the continuously changing threat environment and the challenge of digital assets failing in unexpected ways. As the nuclear fleet continues to adopt digital instrumentation and control systems, it is increasingly important to have effective and efficient cyber risk analysis techniques to support risk management decisions, such as risk elimination by system redesign or risk mitigation by implementation of prioritized security controls. To understand the state of the art in cyber risk analysis for future research, we surveyed 36 publications across ten application domains. We describe our survey methodology and rate each technique based upon scope, adoptability, and repeatability. In this work, we examine the unique constraints of the nuclear industry and outline the strengths and weaknesses of using the cyber risk analysis techniques in the industry, highlighting gaps with current techniques. We also discuss challenges and potential research directions for advancing the science for both existing and new advanced reactors.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Developing VSC-HVDC Oscillation Damping Control Constraints in Unit Commitment

High-voltage direct current (HVDC) systems within the existing power grids will play a pivotal role in enabling high share of renewable power integration and transportation electrification. There is a need for transmission planning models to accurately capture the impact of VSC-HVDC oscillation damping control on the system planning and model the constraints in the security constrained unit commitment (SCUC) problem. In this paper, the SCUC problem in a hybrid DC-AC grid considering damping on electromechanical inter-area oscillation is studied. An electromechanical oscillation-driven transmission capability constraints are derived from system swing equation and incorporated into the SCUC. Multiple system damping control scenarios are set based on the extracted plausible bounds of damping coefficient and inertia constant to linearize the nonlinear expressions. The SCUC problem with proposed constraints is tested on the Reliability Test System Grid Modernization Lab Consortium (RTS-GMLC) via PLEXOS. The impact of the proposed constraints on regional generation, inertia, power flow, annual system cost, and renewable energy curtailment are fully assessed.

damping control↗

Cybersecurity Assessment in DER-rich Distribution Operations: Criticality Levels and Impact Analysis

The integration of distributed energy resources (DERs) in distribution networks has become a pivotal strategy for achieving decarbonization, enhancing grid resilience, and optimizing grid efficiency. Remote monitoring and control op- erations of such resources rely on a network of sensors and communication infrastructure, exposing the system to potential cyber threats. Therefore, as the deployment of DERs increases, ensuring secure monitoring and control becomes an imperative challenge. This paper utilizes real-time feeder models, which are instrumental in developing cybersecurity testbeds tailored for hardware-in-loop (HIL) systems. These models enable users to simulate cyber attacks in a real-world environment and analyze the power distribution operations during vulnerabilities. Furthermore, we discuss several practical sets of grid parameters to identify critical levels of DERs and evaluate various scenarios that simulate cyber threats on sensitive DERs. The modified IEEE 123-bus model is used as the test case for demonstrating the proposed scenarios. The findings from this study provide valuable insights into the vulnerabilities and potential consequences of cyber attacks on DERs, allowing for better mitigation strategies and improved cyber resilience in future distribution networks.

Maharjan, Manisha↗

CEEP (Cyber-Energy Emulation Platform) [SWR-20-102]

NREL's Cyber-Energy Emulation Platform (CEEP) provides the capability to realize cyber-energy security and resilience through automation and orchestration of virtualized systems and software defined networks for the electric grid. CEEP enables testing and validation of grid-security and -control methodologies as the grid evolves to include smart technologies/systems, such as virtualization and containerization of grid components, software defined networking, simulation and co-simulation frameworks, and hardware in the loop. CEEP is a modular system that can be distributed and deployed across different hardware infrastructure sizes and network architectures. For example, CEEP can visualize, emulate, and/or coordinate the Smart-Grid Network Visualization, Intrusion Detection, and Network Healing system. Using CEEP, intrusion-detection and network-self-healing solutions can be deployed at grid control centers, within secure private clouds, and in cyber-energy appliances.

Vaughan, Evan↗

Cyber Energy Emulation Platform (CEEP) [SWR-20-102]

NREL's Cyber-Energy Emulation Platform (CEEP) provides the capability to realize cyber-energy security and resilience through automation and orchestration of virtualized systems and software defined networks for the electric grid. CEEP enables testing and validation of grid-security and -control methodologies as the grid evolves to include smart technologies/systems, such as virtualization and containerization of grid components, software defined networking, simulation and co-simulation frameworks, and hardware in the loop. CEEP is a modular system that can be distributed and deployed across different hardware infrastructure sizes and network architectures. For example, CEEP can visualize, emulate, and/or coordinate the Smart-Grid Network Visualization, Intrusion Detection, and Network Healing system. Using CEEP, intrusion-detection and network-self-healing solutions can be deployed at grid control centers, within secure private clouds, and in cyber-energy appliances.

Rivera, Joshua↗