Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Industrial Control”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 145 records · Page 8

Building Nuclear-Specific Cybersecurity Expertise in Higher Education

The rapid digitalization of nuclear power plants (NPPs) and the deployment of advanced and small modular reactors (A/SMRs) have expanded the cybersecurity attack surface within the nuclear sector. This evolution introduces unique challenges beyond those faced in general information technology (IT), operational technology (OT) and industrial control system (ICS) security, due to nuclear power’s regulatory rigor, safety-critical nature, and operational needs. A pressing workforce gap persists; cybersecurity graduates typically lack nuclear-specific context and retraining them for industry readiness requires 12–18 months, creating a significant burden. This paper addresses this gap by defining the domains of knowledge that nuclear cybersecurity specialists must master, spanning cybersecurity, nuclear engineering, OT/ICS security, and regulatory governance. We propose a curricular framework integrating technical, regulatory, and applied learning components to accelerate workforce readiness. Our approach builds on existing findings that current curricula inadequately integrate nuclear engineering and cybersecurity, shifting the discourse from why specialization is needed to what knowledge must be taught. The recommendations have implications for workforce development and long-term resilience of the nuclear energy sector.

99 - GENERAL AND MISCELLANEOUS↗

USPAS Digital Low-Level RF firmware and software suite (uspas_llrf) v1.0

The USPAS Digital Low-Level RF firmware and software suite was originally developed for the USPAS 2023 LLRF course, for demonstrating the close loop RF control on the BerkeleyLab Marble FPGA carrier and Zest digitizer platform in controlling the RF field for various accelerators. The suite features Register-transfer level (RTL) designs for the board-support layer, digital signal processing and verification test benches, system-on-chip architecture, and Experimental Physics and Industrial Control System (EPICS) support, utilizing a open-source tool chain.

Du, Qiang↗

From Lift-Off to Light-Off

Shuttle's propellant measurement system is produced by Simmonds Precision. Company has extensive experience in fuel management systems and other equipment for military and commercial aircraft. A separate corporate entity, Industrial Controls Division was formed due to a number of non-aerospace spinoffs. One example is a "custody transfer" system for measuring and monitoring liquefied natural gas (LNG). LNG is transported aboard large tankers at minus 260 degrees Fahrenheit. Value of a single shipload may reach $15 million. Precision's LNG measurement and monitoring system aids accurate financial accounting and enhances crew safety. Custody transfer systems have been provided for 10 LNG tankers, built by Owing Shipbuilding. Simmonds also provided measurement systems for several liquefied petroleum gas (LPG) production and storage installations. Another spinoff developed by Simmonds Precision is an advanced ignition system for industrial boilers that offers savings of millions of gallons of fuel, and a computer based monitoring and control system for improving safety and reliability in electrical utility applications. Simmonds produces a line of safety systems for nuclear and non-nuclear electrical power plants.

Source record↗

The Role of Coupled Feedbacks in the Decadal Variability of the Southern Hemisphere Eddy-Driven Jet

The Southern Hemisphere summertime eddy-driven jet and storm tracks have shifted poleward over the recent few decades. In previous studies, explanations have mainly stressed the influence of external forcing in driving this trend. Here we examine the role of internal tropical SST variability in controlling the austral summer jet’s poleward migration, with a focus on interdecadal time scales. The role of external forcing and internal variability are isolated by using a hierarchy of Community Earth System Model version 1 (CESM1) simulations, including the pre-industrial control, large ensemble, and pacemaker runs. Model simulations suggest that in the early twenty-first century, both external forcing and internal tropical Pacific SST variability are important in driving a positive southern annular mode (SAM) phase and a poleward migration of the eddy-driven jet. Additionally, Tropical Pacific SST variability, associated with the negative phase of the interdecadal Pacific oscillation (IPO), acts to shift the jet poleward over the southern Indian and southwestern Pacific Oceans and intensify the jet in the southeastern Pacific basin, while external forcing drives a significant poleward jet shift in the South Atlantic basin. In response to both external forcing and decadal Pacific SST variability, the transient eddy momentum flux convergence belt in the middle latitudes experiences a poleward migration due to the enhanced meridional temperature gradient, leading to a zonally symmetric southward migration of the eddy-driven jet. This mechanism distinguishes the influence of the IPO on the midlatitude circulation from the dynamical impact of ENSO, with the latter mainly promoting the subtropical wave-breaking critical latitude poleward and pushing the midlatitude jet to higher latitudes.

54 ENVIRONMENTAL SCIENCES↗

Role of Tropical Variability in Driving Decadal Shifts in the Southern Hemisphere Summertime Eddy-Driven Jet

The Southern Hemisphere summertime eddy-driven jet and storm tracks have shifted poleward over the recent few decades. In previous studies, explanations have mainly stressed the influence of external forcing in driving this trend. Here we examine the role of internal tropical SST variability in controlling the austral summer jet’s poleward migration, with a focus on interdecadal time scales. The role of external forcing and internal variability are isolated by using a hierarchy of Community Earth System Model version 1 (CESM1) simulations, including the pre-industrial control, large ensemble, and pacemaker runs. Model simulations suggest that in the early twenty-first century, both external forcing and internal tropical Pacific SST variability are important in driving a positive southern annular mode (SAM) phase and a poleward migration of the eddy-driven jet. Tropical Pacific SST variability, associated with the negative phase of the interdecadal Pacific oscillation (IPO), acts to shift the jet poleward over the southern Indian and southwestern Pacific Oceans and intensify the jet in the southeastern Pacific basin, while external forcing drives a significant poleward jet shift in the South Atlantic basin. In response to both external forcing and decadal Pacific SST variability, the transient eddy momentum flux convergence belt in the middle latitudes experiences a poleward migration due to the enhanced meridional temperature gradient, leading to a zonally symmetric southward migration of the eddy-driven jet. This mechanism distinguishes the influence of the IPO on the midlatitude circulation from the dynamical impact of ENSO, with the latter mainly promoting the subtropical wave-breaking critical latitude poleward and pushing the midlatitude jet to higher latitudes.

54 ENVIRONMENTAL SCIENCES↗

Performance of High Temperature Operational Amplifier, Type LM2904WH, under Extreme Temperatures

Operation of electronic parts and circuits under extreme temperatures is anticipated in NASA space exploration missions as well as terrestrial applications. Exposure of electronics to extreme temperatures and wide-range thermal swings greatly affects their performance via induced changes in the semiconductor material properties, packaging and interconnects, or due to incompatibility issues between interfaces that result from thermal expansion/contraction mismatch. Electronics that are designed to withstand operation and perform efficiently in extreme temperatures would mitigate risks for failure due to thermal stresses and, therefore, improve system reliability. In addition, they contribute to reducing system size and weight, simplifying its design, and reducing development cost through the elimination of otherwise required thermal control elements for proper ambient operation. A large DC voltage gain (100 dB) operational amplifier with a maximum junction temperature of 150 C was recently introduced by STMicroelectronics [1]. This LM2904WH chip comes in a plastic package and is designed specifically for automotive and industrial control systems. It operates from a single power supply over a wide range of voltages, and it consists of two independent, high gain, internally frequency compensated operational amplifiers. Table I shows some of the device manufacturer s specifications.

Patterson, Richard↗

Generating Safety-Critical PLC Code From a High-Level Application Software Specification

The benefits of automatic-application code generation are widely accepted within the software engineering community. These benefits include raised abstraction level of application programming, shorter product development time, lower maintenance costs, and increased code quality and consistency. Surprisingly, code generation concepts have not yet found wide acceptance and use in the field of programmable logic controller (PLC) software development. Software engineers at Kennedy Space Center recognized the need for PLC code generation while developing the new ground checkout and launch processing system, called the Launch Control System (LCS). Engineers developed a process and a prototype software tool that automatically translates a high-level representation or specification of application software into ladder logic that executes on a PLC. All the computer hardware in the LCS is planned to be commercial off the shelf (COTS), including industrial controllers or PLCs that are connected to the sensors and end items out in the field. Most of the software in LCS is also planned to be COTS, with only small adapter software modules that must be developed in order to interface between the various COTS software products. A domain-specific language (DSL) is a programming language designed to perform tasks and to solve problems in a particular domain, such as ground processing of launch vehicles. The LCS engineers created a DSL for developing test sequences of ground checkout and launch operations of future launch vehicle and spacecraft elements, and they are developing a tabular specification format that uses the DSL keywords and functions familiar to the ground and flight system users. The tabular specification format, or tabular spec, allows most ground and flight system users to document how the application software is intended to function and requires little or no software programming knowledge or experience. A small sample from a prototype tabular spec application is shown.

Source record↗

Real-time evaluation of cybersecurity threats to DER inverter grid-support functions

In this project we aim to contribute to the understanding of the type and severity of potential cybersecurity attacks to the grid-support functionalities of DER systems interconnected to the AC distribution grid via inverters. Our preliminary work focused on developing a small-scale testbed allowing to study cybersecurity threats to an isolated photovoltaic-battery system using a real-time simulator (Typhoon HIL602+) with a real DNP3 communication connection over TCP/IP, allowing for safe and efficient monitoring and manipulation of data traffic between the simulated hardware and supervisory control and data acquisition (SCADA) system. In this project we propose to expand upon this development by utilizing a) a recently acquired NovaCor RTDS (Real Rime digital Simulator) to emulate the DER-inverter-grid topology including main grid-support functions as defined by IEEE Std. 1547-2018, and b) an industrial control and automation device to enable realistic evaluation of control functions and utilization of communication protocols for real-time data transmission.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Implementation of an ICS Ransomware Testbed: Scenarios, Variants, and Evaluation Methods

Ransomware attacks on Industrial Control Systems (ICS) have emerged as a formidable threat to the United States’ critical infrastructure, eliciting grave concerns regarding national security. In March 2023, the FBI Internet Crime Complaint Center (IC3) unveiled its 2022 Internet Crime Report, highlighting a concerning 870 complaints related to ransomware impacting U.S. critical infrastructure. Of the country's 16 critical infrastructure sectors, 14 encountered at least one ransomware attack. Notably, while the Healthcare and Public Health sector suffered the most, reporting 210 attacks, sectors pivotal to ICS networks and governmental organizations were also targeted: the Defense Industrial Base reported 1 attack, Water and Wastewater Systems 3, Chemical 19, Energy 15, Government Facilities 115, and Critical Manufacturing 157. For instance, a ransomware attack on a major chemical company could jeopardize not only its production but also pose environmental risks should systems controlling hazardous materials be compromised. In 2022, three ransomware variants predominantly targeted U.S. critical infrastructure: HIVE, with 87 attacks; ALPHV/BlackCat, with 114; and LOCKBIT, with 149. Several cyber-attacks, such as the MOVEit data breach in May 2023 and the Colonial Pipeline ransomware attack in May 2021, have been so impactful that they commanded national attention. The DarkSide hacking group's assault on the Colonial Pipeline, initiated on May 6th, 2021, stands as one of the most substantial and publicly acknowledged cyber-attacks against U.S. critical infrastructure. The group exploited an exposed Virtual Private Network (VPN) password, paving the way for initial intrusion and subsequent data theft. A mere day later, DarkSide unleashed a ransomware attack that compromised vital accounting and billing systems, prompting an immediate shutdown of the pipeline to mitigate further ransomware proliferation across its network. This crisis spurred a robust response from the U.S. president and regulators, culminating in a national emergency declaration related to the pipeline shutdown on May 9th, 2021. This incident mirrors the 2017 NotPetya ransomware attack that significantly impacted the shipping giant Maersk, highlighting an urgent need for fortified cybersecurity across various industries. Future incidents, akin to the Colonial Pipeline attack, could potentially be mitigated—or entirely averted—should government agencies and private entities scrutinize system vulnerabilities, exploring various ransomware types and entry points. Proactive measures, such as conducting experiments on VPN accounts or auditing passwords to pinpoint duplicate usage across diverse systems and software, might illuminate feasible entry points and vulnerability zones within an organization's systems.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Precursor Analysis Report: SQL Slammer Worm Infection of Davis-Besse Nuclear Power Plant 2003

The SQL Slammer Worm Infection of Davis-Besse Nuclear Power Plant 2003 Precursor Analysis Report leverages publicly available information about Davis-Besse’s 2003 cyber attack and catalogs anomalous observables for each technique employed in the attack. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. On 25 January 2003, the SQL Slammer worm infected more than 90% of vulnerable hosts and crashed the internet in 10 to 15 minutes, making it one of the fastest spreading worms in history. SQL Slammer is a fileless, memory-resident worm that remotely exploits a stack-based buffer overflow vulnerability on local hosts to intensively scan and rapidly self-propagate across the internet. The worm infected approximately 300,000 unpatched hosts running Microsoft Structured Query Language (SQL) Server 2000 or Microsoft Desktop Engine (MSDE) 2000 with SQL Server Resolution Service. The SQL Slammer worm indirectly infected FirstEnergy’s Davis-Besse nuclear power plant by first infecting a consultant’s company network server and then propagating through an external misconfigured connection into Davis-Besse’s site network. The infection caused major network congestion, slow performance, data overloads, and the inability of local hosts to communicate with each other, which eventually caused a loss of availability and a loss of view when the Safety Parameter Display System (SPDS) and Plant Process Computer (PPC) crashed. At the time of the infection, the plant was already offline, the digital monitoring systems had redundant analog backups, and the plant control and safety functions were not affected, so there were no concerns of a safety breach. However, this incident resulted in many lessons learned and spawned important discussions about cybersecurity’s role in nuclear safety and electric power reliability regulation, policy, and guidance. Researchers and analysts identified 10 unique techniques utilized during the attack with a total of 640 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Eight of the identified techniques used during Davis-Besse cyber attack were precursors to the triggering event. Analysis identified 596 observables associated with these precursor techniques, 428 of which were assessed to have an increased likelihood of being perceived in the 331 days preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Network Slicing for Federated Learning in Operational Technology Environment

Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) environments are essential to modern infrastructure, facing challenges in ensuring low-latency, high-throughput communication while mitigating cyber threats. This paper presents a framework integrating Federated Learning (FL) and network slicing with Quality of Service (QoS) to enable real-time monitoring without disrupting OT operations. Leveraging digital twin technology and Network Function Virtualization (NFV), the architecture supports predictive analytics and Industry 4.0 requirements. FL facilitates decentralized model training, preserving data privacy and scalability, though it introduces potential throughput constraints. Network slicing addresses this by creating dedicated virtualized segments optimized for performance and security. Advanced fault tolerance at the container and instance levels enhances system reliability. The proposed architecture ensures high throughput, low latency, and secure orchestration for real-time anomaly detection in OT networks. Performance evaluations validate its efficiency in throughput, deployment, and learning accuracy, providing a robust foundation for future ICS automation and data-driven decision-making.

Delgado, Brian G. Rodiles [University of Texas at ↗

Status of the data acquisition, trigger, and slow control systems of the Mu2e experiment at Fermilab

The Mu2e experiment at the Fermilab will search for a coherent neutrinoless conversion of a muon into an electron in the field of an aluminum nucleus with a sensitivity improvement by a factor of 10,000 over existing limits. In this work, the Mu2e Trigger and Data Acquisition System (TDAQ) uses otsdaq framework as the online Data Acquisition System (DAQ) solution. Developed at Fermilab, otsdaq integrates several framework components — an artdaq-based DAQ, an art-based event processing, and an EPICS-based detector control system (DCS), and provides a uniform multi-user interface to its components through a web browser. Data streams from the Mu2e tracker and calorimeter are handled by the artdaq-based DAQ and processed by a one-level software trigger implemented within the art framework. Events accepted by the trigger have their data combined, post-trigger, with the separately read out data from the Mu2e Cosmic Ray Veto system. Foundation of the Mu2e DCS, EPICS – an Experimental Physics and Industrial Control System – is an open-source platform for monitoring, controlling, alarming, and archiving. A prototype of the TDAQ and the DCS systems has been built and tested over the last three years at Fermilab’s Feynman Computing Center, and now the production system installation is underway. This work presents their status and focus on the installation plans and procedures for racks, workstations, network switches, gateway computers, DAQ hardware, slow controls implementation, and testing.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Slow control and TDAQ systems installation and tests in the Mu2e experiment

The Mu2e experiment at Fermilab will attempt to detect a coherent neutrinoless conversion of a muon into an electron in the field of an aluminum nucleus, with a sensitivity that is 10,000 times greater than existing limits. The Mu2e trigger and data acquisition system (TDAQ) uses the otsdaqframework as its online Data Acquisition System (DAQ) solution. Developed at Fermilab, otsdaq integrates several components, such as an artdaq-based DAQ, an art-based event processing, and an EPICS-based detector control system (DCS), and provides a uniform multi-user interface toits components through a web browser. The data streams from the Mu2e tracker and calorimeter are handled by the artdaq-based DAQ and processed by a one-level software trigger implemented within the art framework. Events accepted by the trigger have their data combined, post-trigger, with the separately read-out data from the Mu2e Cosmic Ray Veto system. The foundation of Mu2e DCS, EPICS, an Experimental Physics and Industrial Control System, is an open-source platform for monitoring, controlling, alarming, and archiving. Over the last three years, a prototype ofthe TDAQ and DCS systems has been built and tested at Fermilab’s Feynman Computing Center.Currently, the production system installation is underway. At the end, this work presents a brief update on the installation of racks and DAQ hardware.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

CIE Curriculum Guide (V.2.0)

The Cyber-Informed Engineering (CIE) Curriculum Guide offers a comprehensive framework, guidance, and resources for integrating CIE into university-level engineering programs and related educational activities. The primary goal is to help educators adopt CIE principles into their teaching to produce future engineers and technicians who understand digital risks in modern engineered systems, thereby addressing the nation’s infrastructure resilience needs. This guide outlines practical integration examples, links to resources to accelerate CIE adoption, and shares insights from partner academic institutions on various implementation strategies. CIE is a framework for embedding engineered controls that mitigate the impact of cyber-attacks in any cyber-physical system used in critical energy infrastructure and other sectors. Developed by the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER), the National Cyber-Informed Engineering Strategy emphasizes embedding CIE into formal education, training, and credentialing. This guide supports this strategic objective by providing examples of integrating CIE concepts into engineering curricula, from class activities to new courses and certificate programs. The importance of educating cyber-informed engineers is underscored by the evolving cybersecurity threats facing engineered systems. As industrial control systems (ICS) increasingly incorporate digital technologies, the responsibility for security extends to both cyber professionals and engineers. CIE addresses critical gaps in designing and protecting physical systems with digital components against cyber risks, ensuring engineers consider digital risk throughout the engineering design lifecycle. Currently, engineering education does not routinely include cyber-informed principles, highlighting a gap in addressing modern engineering system risks. This guide advocates for updating engineering curricula to include digital risk management as a fundamental element. By doing so, future engineers will be equipped to design resilient systems that mitigate digital risks from the outset. Through this guide, engineering faculty can integrate CIE into their curricula, bridging the gap between digital risk and engineering. This approach prepares a cyber-informed workforce capable of safeguarding the cyber-physical systems crucial to national security and public welfare. By embedding CIE into education and training, institutions can produce engineers and technicians who can effectively mitigate cyber impacts throughout the engineering design lifecycle, resulting in more secure critical infrastructures.

42 - ENGINEERING↗

Regioisomer-Specific Crystallization of Diglycidyl Ether of Bisphenol F Epoxy Resin

Diglycidyl ether of bisphenol F (DGEBF) is a common industrial epoxy resin, desired for its possible replacement of the bisphenol A (BPA) analogue DGEBA due to potential health hazards of BPA. During curing, crystallization of the DGEBF resin can cause inaccurate resin-to-hardener ratios, resulting in incomplete crosslinking; therefore, understanding the crystallization of DGEBF is important for proper industrial control of the material. Here, in this work, we utilized a combination of single-crystal x-ray diffraction, Raman spectroscopy, and 1 H-NMR to investigate the crystallization of DGEBF. We observed crystallization of two DGEBF regioisomers: ortho-ortho’-DGEBF and ortho-para’-DGEBF, and report their crystal structures. Notably, para-para’-DGEBF crystallization is not observed, indicating crystallization of this regioisomer does not occur under ambient conditions. Density functional theory calculations were performed to describe the phonon modes of the ortho-ortho’- and ortho-para’-DGEBF structures, corroborating Raman signatures for the respective isomers. Using a phonon mode analysis, we identify the presence of three specific optical vibrational modes at 631.3, 344.1, and 345.6 cm -1 that are unique to the para monomer. This work offers insights into the crystallization behavior of DGEBF resins under ambient conditions and may inform potential industrial application of this material.

Neu, Jennifer [Oak Ridge National Laboratory (ORNL↗

Are System Baselines within OT Environments Feasible?

Critical infrastructure stakeholders need to baseline their systems to understand expected protocol communications.Baseline behaviors may vary based on operational context.Expected operations during a maintenance window, for example, may be different from normal operations.Furthermore, constructing system baselines for Industrial Control Systems (ICS) is difficult and time-consuming.ICS processes generate artifacts expressed across heterogeneous data sources such as network and device logs. There needs to be a corpus of data in order to develop and compare methods that evaluate the feasibility, performance, and generality of approaches to construct baselines for ICS events. Standalone repositories of network packet captures are insufficient to develop methods to classify or recognize operational events expressed across multiple data sources. Moreover, static data corpora do not enable researchers to compare the impact of changing the underlying system for which a baseline is being constructed and this limits the ability to evaluate the performance of system baselines given system changes (e.g. patches, configuration, maintenance events). In order to address these limitations within the community, this talk intends to promote discussion about the state of the practice of constructing baselines. In this manner, we can continue to understand requirements within industry that are not being met by current approaches to baseline construction. This talk builds on two previous talks on the topic of system baselines for OT environments. First, Weaver co-presented at the RSA Conference ICS Sandbox with Dan Gunter. The talk confirmed the need within industry to construct baselines across multiple types of data sources relative to the semantics of specific business processes. Second, Weaver presented at IEEE Security and Privacy Workshop on Language-Theoretic Security.

02 PETROLEUM↗

Oak Ridge National Laboratory Pilot Demonstration of an Attestation and Anomaly Detection Framework using Distributed Ledger Technology for Power Grid Infrastructure

This report summarizes the design and pilot demonstration of a framework called Grid Guard that was created to provide increased data and device trustworthiness to electric grid devices by leveraging distributed ledger technology (DLT), specifically blockchain. Grid Guard contains a combination of core cryptographic methods such as the secure hash algorithm (SHA), and asymmetric cryptography, private permissioned blockchain, baselining configuration data, consensus algorithm (Raft) and the Hyperledger Fabric (HLF) framework. The system implements a low energy, fast, and robust enhancement to system trustworthiness within and across electric grid systems such as substations, control centers and metering infrastructures. Blockchain is a distributed database structured that provides a practically unalterable (immutable) timeline of stored transactions. By relying on hashing and the Raft consensus algorithm, if an entity tries to illegitimately alter a record at one instance of the database the other ledger nodes are not altered. They work to cross-reference each other and easily locate any incorrectly added data and remove it. The bulk raw data is stored in an off-chain storage (outside of the blockchain ledger) and a hash of this baseline data is stored in the Blockchain ledger via hashing windows of time-series and configuration data, after aggregation and filtering. The bulk off-chain data repository is then considered to be trust-anchored using the hashes stored in the blockchain. To secure the electric grid testbed devices and data, device configuration baselines were compared to those baselines that had been previously stored in the ledger. Statistical baselines for device configurations, network communication patterns, and high-speed sensor data are calculated and then stored off-chain and hashes stored in the ledger. Measurements such as three-phase voltage and current, frequency, breaker status, protection scheme settings, network configuration settings (and other device configuration artifacts) and network traffic features (packet interarrival times) are compared every minute or other selected time windows. During phase 1 of the Grid Guard DLT project different DLT technologies were studies, and an assessment was performed on DLT technology vulnerabilities, uses, and key characteristics. DLT consensus protocols were studies (e.g., RAFT, named after Reliable, Replicated, Redundant, And Fault-Tolerant). Also, cryptography, public, private and permissioned or permissionless systems were assessed. Grid Guard implements a permissioned private DLT. Consensus algorithm selection and choice of DLT implementation depended heavily on the use-case. For this use-case, parameters were selected to measure performance and existing tools for assessment. Benchmarking was performed theoretically and practically. During phase 2 hashed transactions/blocks were inserted into the ledger every second. During phase 2 of the Grid Guard DLT project, a prototype framework was developed and demonstrated for attestation of critical substation devices and data using precision timing systems that use PTP and IRIG-B protocols) on a testbed of operational devices that emulated a distribution substation, control center, and power metering infrastructure using real Operational Technology (OT). The testbed includes OT devices such as protective relays, human machine interfaces (HMI), and power meters. To determine when to collect and compare system and network baselines, an initial examination of an anomaly detection capability to identify malicious manipulation of data streams was conducted. The resulting anomaly detection was demonstrated in a set of experiments and leveraged to trigger device artifact attestation checks. Attestation checks occur against device configuration baselines when compared with the immutable blockchain-stored baselines, which provided a cryptographically supported means by which to store baselines. The electrical substation-grid testbed was created to test the Grid Guard framework. The testbed emulates the operations of a portion of a power grid and SCADA systems as closely as possible. The testbed integrates real protocols, mainly IEC 61850 standard protocols, such as the Sampled Value (SV) and the GOOSE protocols. The testbed also supports DNP3 and other layer 2 and layer 3 protocols such as Telnet, SSH, SFTP/FTP and other proprietary protocols needed to connect to industrial control system equipment. The testbed emulates real power conditions using the OpalRT hardware-in-the-loop (HIL) device which can create fault situations that cannot be easily tested on real systems. The electrical substation-grid testbed was created using real measurement, communication, and protection devices that electrical utilities commonly use.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cybersecurity Resiliency of Marine Renewable Energy Systems Part 2: Cybersecurity Best Practices and Risk Management

Marine renewable energy (MRE) is an emerging source of power for marine applications, marine devices, and coastal communities. This energy source relies on industrial control systems and IT to support operations and maintenance activities, which create a pathway for an adversary to gain unauthorized access to systems and data and disrupt operations. Incorporating cybersecurity risk prevention measures and mitigation capabilities from inception, development, operation, to decommissioning of the MRE system and components is paramount to the protection of energy generation and the security of network architecture and infrastructure. To improve the resilience of MRE systems as a predictable, affordable, and reliable source of energy, cybersecurity guidance was developed to enable operators to assess cybersecurity risks and implement security measures commensurate with the risk. This publication is the second of a two-part series, with Part 1 addressing a framework to determine cybersecurity risk by assessing the vulnerability of an MRE system to potential cyber threats and the consequences a cyberattack would have on the end user. This Part 2 publication describes an approach to select appropriate cybersecurity best practices commensurate with the MRE system's cybersecurity risk. The guidance includes 86 cybersecurity best practices, which are associated with 36 cybersecurity domains and grouped into nine categories. The best practices follow the core functions of the National Institute of Science and Technology Cybersecurity Framework (e.g., identify, detect, protect, respond, and and recover) and insights from both maritime and energy industry guidance documents to identify security measures effective in protecting information and operational technology assets prevalent in MRE systems.

97 MATHEMATICS AND COMPUTING↗