Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Control Systems Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 145 records · Page 8

Security Constrained Economic Optimization of Photovoltaic and Other Distributed Assets

The rapid growth of distributed energy resources (DERs), especially photovoltaic (PV) systems, has introduced new complexities in maintaining grid reliability, stability, and cost-effective operation. This project addresses these challenges by developing and demonstrating a scalable GridOS Distributed Energy Resource Management System (DERMS) that enables secure, real-time optimization and control of DERs at the distribution feeder level.

14 SOLAR ENERGY↗

Advancing Conduction-Cooled 650 MHz SRF Technology for Industrial Accelerators at Fermilab's IARC

The National Nuclear Security Administration (NNSA) funds the Illinois Accelerator Research Center (IARC) at Fermilab in developing a high-power, conduction-cooled Superconducting Radio Frequency (SRF) accelerator tailored for industrial applications requiring robust and efficient operation. A 650 MHz, 1.6 MeV, 20 kW SRF accelerator is currently under development, employing a conduction cooling approach to simplify cryogenic requirements and enhance accessibility for industrial use. The accelerator’s control system is implemented on the Blinky Lite platform, selected for its open-source architecture, secure remote access capabilities, and operational flexibility—attributes advantageous for industrial deployment and sustained operation. A dedicated beamline is designed to measure essential beam parameters and test the integrated performance of the accelerator and control systems, thereby validating their operational readiness for intended applications

Ji, Y. [Fermilab] (ORCID:0000000233981752)↗

Advancing Conduction-Cooled 650 MHZ SRF Technology for Industrial Accelerators at Fermilab S IARC

The National Nuclear Security Administration (NNSA) funds the Illinois Accelerator Research Center (IARC) at Fermilab in developing a high-power, conduction-cooled Superconducting Radio Frequency (SRF) accelerator tailored for industrial applications requiring robust and efficient operation. A 650 MHz, 1.6 MeV, 20 kW SRF accelerator is currently under development, employing a conduction cooling approach to simplify cryogenic requirements and enhance accessibility for industrial use. The accelerator's control system is implemented on the Blinky Lite platform, selected for its open-source architecture, secure remote access capabilities, and operational flexibility attributes advantageous for industrial deployment and sustained operation. A dedicated beamline is designed to measure essential beam parameters and test the integrated performance of the accelerator and control systems, thereby validating their operational readiness for intended applications.

Ji, Yichen [Fermilab]↗

Industrial control system device classification using network traffic features and neural network embeddings

Characterization of modern cyber–physical Industrial Control System (ICS) devices is critical to the evaluation of their security posture and an understanding of the underlying industrial processes with which they interact. In this work, we address two related ICS device identification tasks: (1) separating ICS from non-ICS devices and (2) identifying specific ICS device types. We propose two distinct methods (one based on the existing IP2Vec method, and a novel traffic-features-based method) for achieving the first task. For transferability of the first task between two datasets, the traffic-features-based method performs significantly better (75% overall accuracy) compared to IP2Vec (22.5% overall accuracy). We further propose a novel method called DNP2Vec to address the second task. DNP2Vec is evaluated on two different datasets and achieves perfect multi-class classification accuracy (100%) for both datasets.

42 ENGINEERING↗

Enhancing Security and Resiliency in Operational Technology Environments Through Network Slicing and Federated Learning

The growing convergence of Information Technology (IT) and Operational Technology (OT) within Industry 4.0 environments has introduced new demands on industrial network infrastructure. As cyber-physical systems become increasingly interconnected, ensuring the secure, timely, and efficient exchange of critical data is essential. This thesis explores how network slicing, a method of creating isolated virtual network segments, can be applied within OT environments to address challenges such as latency, security, and resource allocation. The first research question addressed in this thesis is: How can OT networks take advantage of NFV and SDN technology to become cyber resilient? This study examines the operational, security, and architectural implications of introducing network slicing into traditionally static OT infrastructures such as Industrial Control Systems (ICS) and SCADA. Through simulated deployments and case studies, the research demonstrates how slicing enables better isolation between critical and non-critical services, thereby improving response time, throughput, and security in sensitive environments. The second question considers: How to dynamically implement network slicing and take advantage of network resources towards integrating decentralized machine learning? In response, this thesis proposes a framework that combines Software-Defined Networking (SDN), Network Function Virtualization (NFV), and Federated Learning (FL) to enable real-time analytics while maintaining data locality. The proposed approach reduces the burden on centralized infrastructure and minimizes privacy risks by supporting on-site training of models across distributed OT nodes, coordinated through dynamically allocated network slices. The third focus explores: How slicing helps to increase the resiliency of OT networks through the orchestration of a dynamic DMZ? To answer this, the thesis presents a method for creating and managing Dynamic Demilitarized Zones (DMZs) using network slicing. This enables flexible and automated isolation of sensitive subsystems during threat scenarios or high-risk operations. Coupled with intelligent orchestration and containerized security services, the dynamic DMZ significantly enhances the system's ability to respond to cyber incidents without halting production. Ultimately, this thesis contributes a comprehensive architecture that blends network slicing with machine learning, secure segmentation, and automation, paving the way for resilient, adaptive, and intelligent OT environments. Performance evaluations across multiple scenarios show improvements in system reliability, threat response time, model accuracy, and resource utilization, providing a strong foundation for future industrial automation systems.

Rodiles Delgado, Brian G↗

Networked Microgrid Cybersecurity Architecture Design Guide: A New Jersey TRANSITGRID Use Case

Microgrids require reliable communication systems for equipment control, power delivery optimization, and operational visibility. To maintain secure communications, Microgrid Operational Technology (OT) networks must be defensible and cyber-resilient. The communication network must be carefully architected with appropriate cyber-hardening technologies to provide security defenders the data, analytics, and response capabilities to quickly mitigate malicious and accidental cyberattacks. In this work, we outline several best practices and technologies that can support microgrid operations (e.g., intrusion detection and monitoring systems, response tools, etc.). Then we apply these recommendations to the New Jersey TRANSITGRID use case to demonstrate how they would be deployed in practice.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Lightfall v0.0.1

Lightfall is a desktop application for synchrotron beamline instrument control, data acquisition, and live analysis at the Advanced Light Source (ALS). Built on Python and Qt, it provides a native graphical interface for operating beamline hardware, configuring and executing experimental scans, and visualizing results in real time. Key features include direct integration with EPICS control systems, a built-in electronic logbook, remote beamline access over secure tunnels, and an interprocess communication (IPC) architecture that coordinates with external analysis applications via ZMQ and EPICS process variables. This IPC approach allows Lightfall to orchestrate specialized analysis tools—including GPU-accelerated streaming correlators—without embedding them, avoiding the dependency conflicts common in monolithic scientific software platforms. Compared to prior approaches such as Xi-CAM's plugin-based architecture, Lightfall's design cleanly separates instrument control from domain-specific analysis, enabling feedback-driven acquisition where live analysis results can adjust scan parameters during an experiment. Its native Qt interface provides responsive performance for real-time data visualization that web-based alternatives struggle to match. Lightfall is designed for use by beamline scientists and staff operating synchrotron instruments at national user facilities.

Pandolfi, Ronald [Lawrence Berkeley National Labor↗

A Cybersecurity Threat Profile for a Connected Lighting System

In this paper we analyze a threat profile performed on a fault-detection use case for streetlights. A threat profile establishes security requirements, justifies security measures, yields actionable controls, and effectively communicates risk to stakeholders. This effort provides critical information for making threat-based decisions to increase security at a reasonable cost, and can effectively be used by development teams, software architects, and managers to make cybersecurity a part of their ongoing culture of awareness, training, and prevention. This leads to more secure systems and better-understood security. On-premise, cloud, and hybrid architectures with different authentication mechanisms were modeled and later categorized using the Microsoft STRIDE framework. An analysis of the recommended controls for each threat was performed to determine which controls could and should be put in place by manufacturers or third-party suppliers, and which controls need to be left up the end-user to implement.

97 MATHEMATICS AND COMPUTING↗

Modbus RTU for Embedded Cyber Secure Inverter Controller

The Modbus communication protocol is a widely adopted communication standard in industrial control systems. This communication protocol is known for being reliable and straightforward to implement while being versatile in terms of its operating parameters while supporting multiple formats over various hardware infrastructures and architectures. Many intelligent devices such as Programmable Logic Controllers (PLCs), Human-Machine Interfaces (HMIs), Internet-of-Things (IoT), and various Operational Technologies (OT) utilize Modbus for their communication systems. These types of systems must communicate with each other through a standardized and central communication process. To support the integration of these modular systems, a Field-Programmable Gate Array (FPGA) can act as an embedded central routing fabric for this communication to take place. Embedded systems are versatile enough to interface with various devices and systems to accomplish various goals. Additionally, embedded systems require relatively small physical designs to minimize the required resources to facilitate the intended application by providing low-level system access. This minimization of system resources goes hand in hand with reducing the financial cost of a proposed solution or system. As remotely collaborating researchers often use FPGAs to prototype designs that are required to have a method for data transmission among systems, it is imperative to provide a baseline standard for communications among devices and systems. A typical method of implementing the Modbus RTU communication protocol in an embedded environment is using integrated logic architectures within the FPGA called “Intellectual Property (IP) cores.” IP cores can be designed using integrated logic or circuit designs to function as an embedded processor. These IP cores can then perform the required computational actions to support the Modbus RTU communication protocol by utilizing high-level programming languages such as the C programming language. The hardware description language of Very High-Speed Integrated Circuit Hardware Description Language (VHDL) allows for the control of real hardware at the logic gate and signal level. These logic gates and signals can be designed and controlled to perform desired actions based on the system design. Programming an FPGA using VHDL allows an individual to access the lowest abstraction level of the system during FPGA development. This level of abstraction is referred to as the register-transfer level (RTL), which gives access to manipulating values and variables at the register level. This register-level manipulation provides precision over creating the logical circuit within the FPGA, thus minimizing the required code to perform desired operations. The Modbus RTU communication protocol can be implemented within an FPGA using VHDL programming to establish a standardized and embedded serial communication pathway. This implementation provides a standardized communication protocol to streamline research efforts among researchers, thus increasing the efficiency of research efforts. Additionally, this Modbus RTU implementation requires fewer resources when compared to typical communication protocol implementations that utilize an IP core, reducing the hardware requirement for effective research efforts.

communication↗

Outline for Feasibility Study on a Nuclear Material Accounting and Control System for Measurement of High-Activity Waste at Tokai Reprocessing Plant during Decommissioning

The objective of this collaboration between the DOE/NNSA International Nuclear Security Program (INS) and JAEA is to conduct a feasibility study on nuclear material accounting and control needs and requirements for NDA measurement of high-activity waste at TRP during the decommissioning process. Under this study, both sides will exchange information, perform an assessment of needs and requirements, and develop joint recommendations for development of the A-HMMS.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

A Scalable Quantum Cryptography Network for Protected Automation Communication (Final Report)

This is the final report for a CEDS-funded project aimed at developing a new quantum technology for securing utility communication networks used to control and monitor electrical grid equipment. Securing these control networks represents a unique challenge as the performance of the security solution has a direct impact on the stability and reliability of the electrical grid. Traditional, software-based solutions - developed for information networks - are not suitable for utility control networks because they introduce latency, require burdensome maintenance and upgrades, are often incompatible with legacy equipment, and introduce operational complexity that reduces grid reliability. Consequently, many U.S. utilities do not use existing solutions and, instead, protect their critical control networks through the careful isolation and obscuration of their networked equipment. With more utilities embracing grid automation, the attack surface that utilities must defend from hackers has grown to an unmanageable size. To address this situation, Qubitekk and its partners proposed and developed a hardware-based solution that can secure critical control networks without negatively impacting grid performance. This new solution is based on quantum key distribution (QKD) techniques that guarantee secure key generation and distribution across a utility control network. Through deployment and field testing of a prototype QKD system, we have shown that this solution delivers long-term network security, is technically feasible to implement and maintain on a utility’s distribution substation network and does not negatively impact grid operations. In addition, the project has identified and solved key challenges associated with generating, transmitting, and measuring coherent photonic quantum states on a real-world fiber optic network. These additional findings are playing a critical role in advancing quantum networks for quantum computing applications. An overview of the QKD prototype development effort, field testing activities and results, and additional findings relevant to emerging quantum networks are presented in this report.

71 CLASSICAL AND QUANTUM MECHANICS, GENERAL PHYSIC↗

Protecting and Defending against Autonomous Control Systems and Digital Twin Cyber Attacks: Response Strategy for Hyperparameter attacks of Digital Twin Machine Learning Models in Nuclear Power Plants (Final)

Navigating through the complex tapestry of technological advancements, "Response Strategy for Hyperparameter attacks of Digital Twin Machine Learning Model in Nuclear Power Plants" stands at the intersection of cybersecurity and nuclear power plant operations, embarking on a journey through the intricacies of securing digital twins against malicious cyber activities. As nuclear power plants progressively integrate digital twin technology and machine learning models to optimize operations and ensure system reliability, they inadvertently expose themselves to a new spectrum of vulnerabilities, notably in the realm of hyperparameter attacks. Hyperparameters, integral in machine learning model tuning and optimal performance of digital twins, have emerged as a target for adversaries aiming to destabilize the predictive capabilities and therefore, the operational accuracy of these digital entities within critical infrastructures like nuclear plants. This paper, therefore, meticulously threads the needle through the development of a robust response strategy, poised to shield these digital reflections against calculated hyperparameter manipulations, ensuring that the digital twin can effectively and securely function as a reliable proxy for its physical counterpart. The ensuing sections delve into the orchestrated maelstrom of multi-rate time-changing intelligent coordinated hyperparameter attacks and the implementation of event-triggered predictive control, laying down a structured, predictive, and responsive framework that safeguards the nexus where the digital and physical realms of nuclear power plants coalesce. The operational integrity of digital twins in nuclear power plants depends critically on the security of machine learning hyperparameters. This study makes two different contributions. First, a decision-based idea known as a multi-rate time changing intelligent coordinated hyperparameter attack is put forth. In this attack, many hyperparameters are repeatedly changed using both random and intelligent optimal techniques by the attacker. These assaults introduce varied rates at different attack steps, compromise various amounts of hyperparameters, and improve stealth and flexibility. Second, a technique is developed for event triggered predictive control to rapidly respond to potential hyperparameter attacks. This control integrates a sliding window framework, retaining a history of previous data points and employing linear regression to predict the next data point from the current dataset. The control gain K is determined using the Lyapunov-Krasovskii method, and subsequently, an action is developed. Finally, the outcome of the simulation demonstrates the viability of the proposed method for defending nuclear power plant digital twins from hyperparameter attacks.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Virtualizing Industrial Control Networks for Cyber Resilience Experiments

Industrial control systems (ICS) networks are undergoing constant shifts to accommodate new security measures. It is challenging to test varying network configurations and security tools with physical systems as they typically include large, expensive equipment. Not only this, but researchers often do not have access to this type of equipment for development of new security tools and techniques. As a solution to these issues, this work presents a set of tools for utilizing GNS3 and Docker as a virtual ICS network. Additionally, the virtual network can be attached to physical devices including network switches, hardware simulations, and intelligent electronic devices (IEDs). Two case studies showcase a relatively complex automatically generated network and an attack on a simple ICS network with an example mitigation.

42 ENGINEERING↗

Grid-Connected Modular Soft-Switching Solid State Transformers (M-S4T)

The objective of this project is to develop and verify the concept of a flexible and modular soft-switching solid-state transformer (M-S4T) for direct grid-connected applications. The ability to directly connect power electronics converters to the medium voltage grid (4 kV – 13 kV), and to potentially replace the passive and bulky, but ubiquitous 60 hertz service transformer in the 25 kVA to 100 kVA range, with a more flexible and controllable device, has been regarded as the ‘holy grail’ in grid control. However, this has proven to be extremely difficult. This project has developed the solutions to several key challenges of the direct grid-connected power electronics and realized a 7.2 kV M-S4T prototype. First, a protection method to protect the M-S4T from the high voltages (110 kV for the 13 kV system) that occur on the grid due to transients and lightning strikes have been developed and experimentally verified. Second, the realization and the operation of the M-S4T based on high-voltage SiC devices (>3.3 kV) and a medium-frequency medium-voltage low-leakage transformer in a single-stage solid-state transformer with zero-voltage switching, low dv/dt, and low electromagnetic interference has been successfully demonstrated up to 7.5 kV peak. Third, an oil-cooling system and stable communication and distributed control system for converter module voltage sharing have been developed and experimentally verified. The developed M-S4T has realized a modular universal high-performance power conversion system. This conversion system is scalable to different voltage and power levels and adaptable to four-quadrant bidirectional operation. Moreover, the use of passive cooling techniques meets the equipment life requirements, and the lightning protection scheme fulfills the basic insulation level specifications for direct grid connection. Such power conversion system opens up near-term opportunities, including energy storage, solar PV, or electric vehicle charging with significant cost and footprint savings. In the longer term, the possibility of replacing the utility distribution transformer with an M-S4T will be transformative for future distribution grids with a compact footprint and full controllability to enable high renewable energy and storage penetration. In addition to the main project, this report expands on the Plus-Up projected including as part of the main award. This project developed and demonstrated the technology for autonomous collaborative inverters that can be connected in an ad hoc manner to the grid. The aim of the project was to: (1) evaluate the existing techniques for grid-connected inverters and find their limitations; (2) develop detailed requirements for grid-connected inverters in the modern grid with millions of active nodes; (3) design a unified control strategy that brings more autonomy and intelligence to grid-connected inverters, and addresses parts of the issues with the existing techniques. The proposed technique, called UniCon, enables inverters to 1) connect/disconnect to/from the grid in an ad hoc manner; (2) work based on local sensing. Slow communication could be used for a more optimized behavior; (3) work automatically in both grid-forming/grid-following mode; (4) handle large disturbances, e.g., big load step and fault, in an oscillation-free manner; (5) work collaboratively with other inverters in steady-state and during transients. UniCon can be implemented in the middle-level control; hence it is agnostic to the vendor and to the implementation of the inner voltage/current and protection loops. Furthermore, a new synchronization scheme, based on deep learning, was developed that can extract the grid voltage phase and amplitude in a stable manner. The method is cheap to implement can improve the dynamic performance of the grid-connected inverters during fast transients, e.g., fault. The proposed control scheme was validated by (1) MATLAB/Simulink; (2) hardware-in-the-loop results, and; (3) experimental results using three inverters that form a microgrid in a down-scaled feeder. Lastly, both the M-S4T and UniCon have achieved promising tangible paths to markets. In the case of the M-S4T, the underlying technology — the Soft Switching Solid State Transformer (S4T) developed at the Georgia Tech Center for Distributed Energy (GT-CDE) has been licensed by GridBlock from the Georgia Tech Research Corporation, and GridBlock has been working with manufacturing partner Jabil (one of the largest US-based contract manufacturers) and system integrator Power Secure (largest deployer of microgrids in the US with 4.7 GW under management), to meet the strong initial demand. Similarly, GridBlock has an exclusive license to the UniCon technology, developed under this award by GT-CDE. The UniCon provides an intermediate control layer that enables the implementation of the higher-level ‘transactive’ control commands for the system. The architecture of the system - slow communications with the cloud for system optimization and setpoints, and the use of locally measured quantities for real-time control, provide a very robust and secure way of implementing a real-time must-run grid that is also secure and stable. This is a brand-new functionality that is critical for the future grid and key to GridBlock’s business model.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Frequency Injection Based HVDC Attack-Defense Control Via Squeeze-Excitation Double CNN

Due to the independent controllability and fast power regulation capability, the High Voltage Direct Current (HVDC) system could be a prospective technology to provide multiple ancillary services to the system besides conventional bulk power transmission. However, with the increase of False Data Injection Attacks (FDIAs) on PMU data, the HVDC system could have the wrong response once the collected data that the HVDC system relied on is attacked, thus threatening the system operating security. How to ensure the security of the PMU-based HVDC ancillary service control become an urgent issue. To mitigate the risk, this paper proposed an HVDC attack-defense control based on the FDIAs detection method. Firstly, the Squeeze-Excitation based Double Convolutional Neural Networks (SE-DCNN) is proposed to realize fast identification of the attacking frequency type based on the time and frequency domain signals. Furthermore, the duration time of FDIAs is detected by the local outlier factor. Then, utilizing the results from SE-DCNN, HVDC ancillary service control framework is reorganized and an HVDC attack defense control is proposed for suppressing the potential influence of various types of FDIAs on the HVDC system ancillary service. Different experiments results demonstrate that the proposed method has the ability to significantly mitigate the frequency deviation and oscillation under the FDIA.

42 ENGINEERING↗

Adaptive Power System Emergency Control using Deep Reinforcement Learning

Power system emergency control is generally regarded as the final safety net for grid security and resiliency. Existing emergency control schemes are usually designed off-line based on either the conceived “worst” case scenarios or a few typical operation scenarios. These schemes are facing significant adaptiveness and robustness issues as increasing uncertainties and variations occur in modern electrical grids. To address these challenges, for the first time, this paper proposes a novel adaptive emergency control scheme using deep reinforcement learning (DRL), by leveraging the high-dimensional feature extraction and non-linear generalization capabilities DRL has for complex systems with high-dimensional variations. Furthermore, an open-source platform named DeepGrid has been designed for the first time to assist the DRL development and benchmarking processes in power system emergency control. Details of the platform, DRL, and emergency control schemes that use dynamic braking or under-voltage load shedding are presented. Extensive case studies performed in both two-area four-machine system and IEEE 39-Bus system have demonstrated the excellent performance and robustness of the proposed schemes.

Deep reinforcement learning, emergency control, lo↗

Impact of Wide-Area Oscillation Damping Control using Measurement-Driven Approach on System Separation - Saudi Grid Case Study

In any interconnected power grid, low-frequency oscillations is a major problem that can limit the power transfer capability and deteriorate power system security due to potential low-damped or even undamped oscillations. Synchronized measurements provided by PMUs enable the design and development of wide-area oscillation damping controllers (WADC) based on measurement-driven model to overcome the limitations of traditional controllers. This work focuses on the impact of a W ADC based on a measurement-driven approach on system separation for the Saudi Electricity Company (SEC) grid. A grid model is provided by SEC for this study. Modal analysis is performed to identify the oscillation mode of interest for which the controller is designed. Damping the dominant oscillation mode helps slightly to improve transient stability of the system. Considering bus frequency at different locations in SEC's system as the candidate observation signals, the optimal observation signal is chosen for the W ADC by using the FFT method. The system transfer function model is constructed by utilizing probing measurements. Then, the W ADC parameters are calculated based on the identified model. The performance of the designed W ADC is tested under different contingencies.

Altarjami, Ibrahim↗