Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “DER security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

A Blockchain Based Co-Simulation Framework for Integrating DERs to Wholesale Electricity Markets: Preprint

As the number of distributed energy resources (DERs) continue to increase across energy-delivery systems, there remains a need for integrating their capabilities into traditional grid operations. In this paper, a blockchain-based solution is proposed to facilitate FERC's Order No. 2222 implementations. The presented use-case enables small-scale DERs to participate in wholesale market operations through DER aggregators, while also enabling local distribution system operators to enforce distribution system constraints in a secure and traceable manner. The presented use case is built around the Unified Testing Platform (UTP) being developed as a part of the Blockchain for Optimized Security and Energy Management (BLOSEM) project. This is a multi-lab effort intended to simplify the deployment of blockchain-powered grid solutions by enabling the integration of simulation tools, and blockchain technologies through the use of system-agnostic interfaces that provide a modular, interoperable, and reusable connectivity layer.

blockchain testing↗

Icypaw

The Intermode Communication Protocol Wrapper, or Icypaw, structures and facilitates communication between endpoints in a network. It is used to connect various independent software and hardware components into one loosely organized system controllable from one or more locations. The code uses the MQTT protocol to communicate and enhances it with a useful framework. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525. SAND2021-8293 O

Van Der Wall, JayW.↗

EMS and DMS Integration of the Coordinative Real-time Sub-Transmission Volt-Var Control Tool under High DER Penetration

This paper proposes an applicable approach to deploy the Coordinative Real-time Sub-Transmission Volt-Var Control Tool (CReST-VCT), and a holistic system integration framework considering both the energy management system (EMS) and distribution system management system (DMS). This provides an architectural basis and can serve as the implementation guideline of CReST-VCT and other advanced grid support tools, to co-optimize the operation benefits of DERs and assets in both transmission and distribution networks. Potential communication protocols for different physical domains of a real application is included. Performance and security issues are also discussed, along with specific considerations for field deployment. Finally, the paper presents a viable pathway for CReST-VCT and other advanced grid support tools, which could be integrated in an open-source standardized-based platform that supports distribution utilities.

Nguyen, Quan H.↗

Creating the Distributed Energy Resources Education Center (DEREC)

The built environment in the United States consumes 40% of the energy generated and emits roughly the same percentage of total carbon footprint. Distributed energy resources (DER), small or modular energy generation and storage technologies, present the nation with an opportunity to substantially improve those metrics while securing the nation’s energy independence. As opportunities increase for implementing such technologies, they also continue to evolve and often outpace the nation’s traditional building practices. In an effort to effectively and proactively incorporate distributed energy resources into the nation’s energy supply, Southface Energy Institute convened with national and regional partners to create the Distributed Energy Resources Education Center (DEREC). Using national model codes and their regionally amended versions as a collective starting point, the DEREC team collaborated with industry experts and identified impediments to effective implementation of DERs, developing discipline-specific curriculum to eliminate those impediments. The center, developed in collaboration with Interstate Renewable Energy Committee (IREC) and National Buildings Institute (NBI), leverages existing DER education content as well as new and dynamic training materials and online courses that collectively engage the many roles necessary for DER implementations, including designers, code officials, builders and skilled trades, and building owners who specify, inspect, build, operate, and maintain buildings with DERs.

14 SOLAR ENERGY↗

Federated Architecture for Secure and Transactive Distributed Energy Resource Management Solutions

There are fewer conventional, dispatchable generation resources and more variable renewable energy (VRE) and distributed energy resources (DERs). There is more uncertainty from bulk-level VRE and net demand from distribution systems with high DER levels. FAST-DERMS aims to develop and demonstrate a scalable solution for managing uncertainties in supply and demand at the grid edge. We propose that distribution system operators (DSOs) provide firm net load forecasts to the bulk system operator's energy management system (EMS).

distributed energy resources↗

Enhancing Cloud Cybersecurity: Prescriptive Controls for Operational Technology

This whitepaper provides strategic insights and recommendations into security cloud-based solutions for electric utilities, encompassing operational technology (OT), virtual power plants (VPP), distributed energy resources (DERs), applications, networks, and data storage as they transition to and leverage cloud infrastructure through managed service providers (MSPs) and cloud service providers (CSPs). Principles derived from established frameworks serve as a foundation for best practices across cybersecurity projects and remove the constraints of settling on a single framework. For organizations that prefer not to integrate a specific framework altogether, elements of the proposed approach could be adopted or tailored to best fit defined requirements and expected functionalities. The Cirrus assessment, a utility cloud feasibility tool, and the roadmap it provides serve as a precursor to this paper, which seeks to be a valuable resource for defining next steps following cloud technology integration feasibility appraisal. With its comprehensive approach to adoption, the Cirrus framework offers strategic guidance on responsibly preparing for or deploying a utility cloud solution. The previously published whitepaper, “Use Case-Informed Framework for Utility Cloud Migration,” details the guiding strategy, research, and deployment of cloud solutions within electric and interconnected grid systems. Before implementing the controls suggested in this document, it is recommended that stakeholders complete Cirrus's cloud integration assessment and pair the results with their unique cybersecurity controls to form a comprehensive cloud-based utility cybersecurity plan. The Cirrus outcome will consider a series of future architectures for the grid before and after the energy transition and evaluate the arguments for and against cloud applications for each electric and interconnected grid layer. This document is a companion to the original whitepaper, "Use Case-Informed Framework for Utility Cloud Migration" to further identify and recommend security controls based on Cirrus’s cloud integration assessment output. The following whitepaper outlines the cybersecurity controls that secure cloud-service models pertinent to the electric sector using the predefined categories identify, protect, detect, and respond and recover. The objective is to outline prescriptive security controls based on the type of architecture and data stored in the cloud. The focus includes dissecting the shared responsibility model and elucidating what on-premises Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) entail. A pivotal consideration in this context is allocating responsibility for foundational cybersecurity aspects—having used Cirrus for the cloud integration assessment. The ensuing controls detailed herein also represent a checklist of controls necessary for a secure cloud transition, equipping utilities with the knowledge to navigate this digital transformation with confidence and strategic foresight in a safe and responsible manner.

42 ENGINEERING↗

Octet: A coherent qubit control system for trapped-ion quantum computers

This is firmware and software designed for a Zynq UltraScale+ RFSoC chip made by Xilinx, specifically targeted to laser-based individual addressing of trapped ion qubits via a multi-channel AOM. The design features 8 dual-tone outputs with frequencies up to 409 MHz that can be controlled statically or dynamically via on-chip cubic spline interpolation engines that allow one to generate sequences of output waveforms with fast modulation of frequency, phase, amplitude, and z-rotations that are smooth/discrete and can run simultaneously across all parameters/tones. It also features global phase alignment on all tones regardless of frequency and the ability to return to a known phase/frequency at any later time on a per-tone basis without the need for manual bookkeeping. Acoustic and optical cross-talk can also be destructively canceled by adding neighboring outputs with variable amplitude/phase/delay. Each tone can be optionally frequency locked to an external RF source. SAND2020-12703 M Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Lobser, Daniel↗

Facility Energy Saving and Securing Technology Using Multi-Source Data (FEST) (Final Report)

Facility Energy Saving and Securing Technology (FEST) project focuses on developing algorithmic tools and techniques for analyzing cyber-physical security of DoD’s military site facilities, and optimal scheduling, operation and planning of their Distributed Energy Resources (DER). The project is led by LLNL with the team including University of Michigan-Dearborn and XENDEE. The military site partner providing the energy metering data is White Sands Missile Range (WSMR). This report summarizes the work performed during the project and future directions for follow-on research.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Security assessment and impact analysis of cyberattacks in integrated T&D power systems

In this paper, we examine the impact of cyberattacks in an integrated transmission and distribution (T&D) power grid model with distributed energy resource (DER) integration. We adopt the OCTAVE Allegro methodology to identify critical system assets, enumerate potential threats, analyze and prioritize risks for threat scenarios. Based on the analysis, attack strategies and exploitation scenarios are identified which could lead to system compromise. Specifically, we investigate the impact of data integrity attacks in inverted-based solar PV controllers, control signal blocking attacks in protective switches and breakers, and coordinated monitoring and switching time-delay attacks. Index Terms—Cyberattacks, security assessment, impact analysis, case studies, integrated power systems.

14 SOLAR ENERGY↗

Cybersecurity for Energy Systems: Foundational Concepts for Bangladesh Electric Utilities [Slides]

This slide deck was developed for a training for the Northern Electricity Supply Company (NESCO) in Rajshahi, Bangladesh. The topics include: understanding the cybersecurity landscape in power utilities, fundamentals of cybersecurity for power utilities, regulatory compliance and standards, and best practices and strategies. The concepts in this slide deck are relevant for electric utilities throughout Bangladesh.

24 POWER TRANSMISSION AND DISTRIBUTION↗

SOLAr Critical Infrastructure Energization (SOLACE): Leveraging Distributed Energy Resources to Provide Local Power

This document is a technical report based on a large-scale DOE-funded project conducted between 2019 and 2022. The project, called SOLAr Critical infrastructure Energization (SOLACE), is aimed at leveraging distributed energy resources (DERs) to provide local power to communities, feeders, or other regions. The project included a particular focus on high-value critical loads such as municipal water supply, telecommunication hubs, and disaster shelters. The key developments of the project were: (1) A comprehensive pre-event power system analysis methodology that identifies and characterizes the viable local power options. (2) A DMS-based example control system for activating and operating the local power solution during a time of crisis. (3) Grid-forming inverter technology to enable isolated local power operation and black-starting. (4) Cyber-security considerations for isolated systems when wider-area communication may be offline. This report describes the overall process that identifies and assesses the viable DER-based local power solutions for a given facility, region, or community. The report documents the process, including the key analysis steps, tools required, data requirements, and recommended pass/fail criteria for each step. It also provides a sample implementation of this process through a test case. Finally, it provides details of how a viable pre-event plan can be selected and activated at go-time when an event has occurred.

14 SOLAR ENERGY↗

Aggregation and Grid Security Workshop Report

The Aggregation and Grid Security Workshop - held on June 17-18, 2025, National Laboratory of the Rockies (NLR) in Golden, Colorado - brought together approximately 40 external stakeholders from the energy sector, including VPP owner/operators, aggregators, OEMs, utilities, testing & certification labs, trade associations, and cybersecurity vendors. Led by key facilitators, the workshop focused on addressing cybersecurity challenges and enhancing grid resilience for aggregated Distributed Energy Resources (DERs) and Virtual Power Plants (VPPs). The workshop was catalyzed by recognition that traditional, rearward-looking regulatory frameworks are insufficient to keep pace with technological change. There is a "missing understanding" of risk, an "absent security basis" for managing it, and an "untenable responsibility" due to unclear ownership and requirements. The workshop aimed to shift the mindset from reacting to past crises to proactively preparing for emerging threats, fostering forward resilience through risk simulation and collaborative action. This report summarizes the outcomes of the workshop, marking it a significant step toward a secure, reliable and affordable energy future.

14 SOLAR ENERGY↗

A Privacy-Aware Federated Learning Framework for Distributed Energy Resource Analytics in Constrained Environments

To be resilient against extreme weather events, the rural communities in Puerto Rico are leveraging distributed energy resources (DER). However, computing frameworks sup-porting the grid in critical decision-making are still largely centralized. Sensitive consumer data are transmitted over the Internet or cellular networks to a secondary or tertiary node. It guarantees better situational awareness at the cost of a wider attack surface, jeopardizing user privacy, as more DER come online. Cloud, Edge, and Fog computing all require data aggregation at some level. This paper introduces a privacy-aware federated learning framework that leverages the Fog model by pushing analytics all the way to the DER and load assets. These local models train on individual asset data and transmit only learned parameters (such as weights) over secure communications to a global decision-maker. By abstracting personally identifiable consumer data without impacting decision optimality, this framework better aligns with distributed power generation paradigm.

Sundararajan, Aditya↗

Dynamic Role-Based Access Control Policy for Smart Grid Applications: An Offline Deep Reinforcement Learning Approach

Role-based access control (RBAC) is adopted in the information and communication technology domain for authentication purposes. However, due to a very large number of entities within organizational access control (AC) systems, static RBAC management can be inefficient, costly, and can lead to cybersecurity threats. In this paper, a novel hybrid RBAC model is proposed, based on the principles of offline deep reinforcement learning (RL) and Bayesian belief networks. The considered framework utilizes a fully offline RL agent, which models the behavioral history of users as a Bayesian belief-based trust indicator. Thus, the initial static RBAC policy is improved in a dynamic manner through off-policy learning while guaranteeing compliance of the internal users with the security rules of the system. By deploying our implementation within the smart grid domain and specifically within a Distributed Energy Resources (DER) ecosystem, we provide an end-to-end proof of concept of our model. Finally, detailed analysis and evaluation regarding the offline training phase of the RL agent are provided, while the online deployment of the hybrid RL-based RBAC model into the DER ecosystem highlights its key operation features and salient benefits over traditional RBAC models.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Centralized and Decentralized Distributed Energy Resource Access Control Implementation Considerations.

A global transition to power grids with high penetrations of renewable energy generation is being driven in part by rapid installations of distributed energy resources (DER). New DER equipment includes standardized IEEE 1547-2018 communication interfaces and proprietary communications capabilities. Interoperable DER provides new monitoring and control capabilities. The existence of multiple entities with different roles and responsibilities within the DER ecosystem makes the Access Control (AC) mechanism necessary. In this paper, we introduce and compare two novel architectures, which provide a Role-Based Access Control (RBAC) service to the DER ecosystem’s entities. Selecting an appropriate RBAC technology is important for the RBAC administrator and users who request DER access authorization. The first architecture is centralized, based on the OpenLDAP, an open source implementation of the Lightweight Directory Access Protocol (LDAP). The second approach is decentralized, based on a private Ethereum blockchain test network, where the RBAC model is stored and efficiently retrieved via the utilization of a single Smart Contract. We have implemented two end-to-end Proofs-of-Concept (PoC), respectively, to offer the RBAC service to the DER entities as web applications. Finally, an evaluation of the two approaches is presented, highlighting the key speed, cost, usability, and security features.

42 ENGINEERING↗

Securing Solar for the Grid (S2G)

The first slide deck provides an overview of the goals and objectives of the DOE Grid Modernization Initiative's Project entitled "Assessment and Coordination of DER Cybersecurity Standards." It covers the project's ongoing efforts to create a library of standards related to the cybersecurity of DER. The presentation will review the progress of this effort to-date and solicit feedback from participants on future directions. The second slide deck summarizes NREL's accomplishments for last three years under S2G project in a 10-12 min presentation.

clean energy↗

Proactive Intrusion Detection and Mitigation System

SAND2023-05661O The proactive intrusion detection and mitigation system (PIDMS) provides grid-edge situational awareness for cybersecurity defense by capturing real-time distributed energy resource (DER) network traffic and performance data with a novel approach that improves the detection and prevention of cyber-physical attacks. The PIDMS addresses the grid-edge security gap with real-time analysis of both network traffic and photovoltaic performance data to deliver a novel, cyber-physical intrusion detection system (IDS) approach that increases the accuracy and effectiveness of detection and mitigation. This hybrid IDS analysis enables dual monitoring that increases the workload of the adversary; both cyber and physical data would have to be simultaneously spoofed to evade detection. Furthermore, monitoring and analyzing cyber data are insufficient in some cases. For example, in an insider threat aimed at disrupting inverter grid-support functions where proper credentials and authentication are achieved, only the altered PV performance would indicate abnormal behavior. All in all, the PIDMS provides novel capabilities for: • Distributed, real-time cyber-physical detection and mitigation analysis • Cybersecurity defense for grid-edge systems • Analysis framework that can provide situational awareness across the transmission, distribution, and DER systems The PIDMS sensor is designed to collect cyber-physical data, process the data using machine-learning algorithms, detect abnormal events, and deploy mitigations. With these goals, the main functional PIDMS objectives are: • Capability to collect cyber-physical data • Onboard storage of cyber-physical data • Peer-to-peer communication • Computationally efficient machine-learning algorithms • Online cyber-physical data analysis • Alerting/visualization capabilities • Mitigation deployment capability with bump-in-the-wire (BITW) implementation Each of these functional objectives enable PIDMS to perform effective cyber-physical intrusion detection and mitigation. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Jones, Christian↗