Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “DER security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 163 records · Page 9

Master Services Agreement - Flexible Feeder/Distribution System Support: Cooperative Research and Development (Final Report)

PGE will engage NREL on a broad range of projects related to the integration of distributed energy resources (DERs) into the utility's operations. This portfolio of work could include projects focused on DER adoption models, advanced distribution management system (ADMS) and distributed energy management system (DERMS) design, DER dispatch strategy development, and DER valuation framework development. Additional topics could include long-term energy planning, renewable energy, energy efficiency and demand-side management. As well as technology evaluations and design guidance for building retrofits and new construction projects, energy and energy infrastructure planning, policies, and markets (and their analysis), energy storage, energy security and resilience (including energy system-related cybersecurity), transportation and mobility, technology integration analysis. Additionally, other assistance as requested by PGE consistent with NREL’s expertise.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Programmable intrusion detection for distributed energy resources in cyber–physical networked microgrids

We present a programmable intrusion detection method is presented to identify the malicious attacks to distributed energy resources (DERs) in the cyber-physical networked microgrids. The proposed method injects small programmable signals into the system and uses the response to identify abnormal conditions. Because of the low or even zero inertia induced by integrations of DER power-electronic-interfaces, microgrids have very limited resilience capability; and thus, being sensitive to attacks. One microgrid's malfunction caused by attacks can easily propagate to its neighboring systems when several microgrids are connected, leading to catastrophic electricity supply failures. Through the presented method, malicious intrusions can be effectively detected, located, and defended for securing microgrids. Theoretical derivations are provided to define the programmable detection rules. The detection rule is easy and flexible to update, making it difficult for attack actors to gain the knowledge of the detection rules, in order to avoid being detected. Numerical results on a cyber-physical networked microgrids system show that the proposed method is effective and efficient in precisely locating intrusion attacks to the microgrids system.

42 ENGINEERING↗

Providencia Island White Papers: Potential for Increasing the Physical Resilience of Distributed Energy Resources

Using technologies such as solar photovoltaics (PV) to provide power to a site during a large-scale grid outage can be an effective solution for enhancing resilience, if designed appropriately. This paper discusses storm-hardening strategies including wind-loading standards, secure racking systems, balance of electrical systems and pre-storm preparations.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cybersecurity Certification Standard for Distributed Energy Resources

Cybersecurity Certification Standard for Inverter Based Resources led by UL, and contributed to by NREL, is a certification standard for devices and their cyber security practices. The standard, which is being developed and led by UL, contains certification and testing processes for the devices to be certified before they are deployed in the field. The importance of the standard is to ensure that all DER devices have all the five pillars of cybersecurity, in which the baseline cybersecurity posture of the DER industry will be elevated.

certification standard↗

Emerging Technologies for Privacy Preservation in Energy Systems

This study explores the intersection of digitalization and privacy within the energy sector, focusing on the emerging challenges and opportunities presented by integrating Distributed Energy Resources (DERs) and advanced metering infrastructure. The need for robust digital privacy measures has become crucial as the energy industry evolves towards a more decentralized, digitalized, and decarbonized future. This study delves into four cutting-edge privacy-preserving technologies—Homomorphic Encryption (HE), Secure Multiparty Computation (SMPC), Differential Privacy (DP), and Federated Learning (FL)—each offering unique solutions to safeguard consumer data by increasing digital connectivity and data exchange. Through a detailed examination of these methods, the study explains how each technology operates, its applications within the energy sector, and the specific privacy challenges it addresses. Homomorphic Encryption allows for secure computations on encrypted data, enabling data analysis without compromising privacy. Secure Multiparty Computation enables collaborative data analysis across different entities while protecting the confidentiality of the inputs. Differential Privacy introduces randomness into the assembled data set, preventing the identification of individual records in statistical databases. Lastly, Federated Learning offers a paradigm shift in data analysis, where machine learning models are trained at the edge, minimizing the centralization of sensitive data. The research underscores the significance of implementing these privacy-enhancing technologies to comply with strict data protection regulations, foster consumer trust, and enhance the security of the energy infrastructure. By providing a comprehensive overview of these methodologies and their practical implications for the energy sector, this study aims to contribute to the ongoing discourse on digital privacy, offering insights into how the energy industry can navigate the complexities of data privacy in the digital age.

Cali, Umit↗

Safe and Private Forward-trading Platform for Transactive Microgrids

Power grids are evolving at an unprecedented pace due to the rapid growth of distributed energy resources (DER) in communities. These resources are very different from traditional power sources, as they are located closer to loads and thus can significantly reduce transmission losses and carbon emissions. However, their intermittent and variable nature often results in spikes in the overall demand on distribution system operators (DSO). To manage these challenges, there has been a surge of interest in building decentralized control schemes, where a pool of DERs combined with energy storage devices can exchange energy locally to smooth fluctuations in net demand. Building a decentralized market for transactive microgrids is challenging, because even though a decentralized system provides resilience, it also must satisfy requirements such as privacy, efficiency, safety, and security, which are often in conflict with each other. As such, existing implementations of decentralized markets often focus on resilience and safety but compromise on privacy. In this article, we describe our platform, called TRANSAX, which enables participants to trade in an energy futures market, which improves efficiency by finding feasible matches for energy trades, enabling DSOs to plan their energy needs better. TRANSAX provides privacy to participants by anonymizing their trading activity using a distributed mixing service, while also enforcing constraints that limit trading activity based on safety requirements, such as keeping planned energy flow below line capacity. We show that TRANSAX can satisfy the seemingly conflicting requirements of efficiency, safety, and privacy. We also provide an analysis of how much trading efficiency is lost. Trading efficiency is improved through the problem formulation, which accounts for temporal flexibility, and system efficiency is improved using a hybrid-solver architecture. Lastly, we describe a testbed to run experiments and demonstrate its performance using simulation results.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Joint scheduling of energy, fast and primary frequency response reserves in integrated transmission–distribution networks

Inverter-based distributed energy resources (DERs) connected to distribution networks (DNs) can provide fast frequency support, but their reserve deliverability depends on feeder constraints and differs from synchronous primary frequency response (PFR). Existing transmission–distribution coordination studies usually treat reserve generically or neglect feeder-level feasibility, while frequency-security scheduling studies rarely represent distribution feeders explicitly. This paper develops a bi-level day-ahead scheduling framework for integrated transmission–distribution networks that jointly clears energy, transmission-side PFR, and distribution-side fast frequency response (FFR) under exogenous hourly inertia and largest-loss inputs from an external unit commitment (UC) schedule. The transmission problem is modeled with DC-optimal power flow (OPF) and closed-form second-order cone (SOC) frequency-security constraints, whereas each DN is represented by a reserve-aware branch-flow AC-OPF so that scheduled fast reserves remain deliverable during activation. The bi-level problem is reformulated through Karush–Kuhn–Tucker (KKT) conditions into a mixed-integer SOC program, and a penalty term is used to tighten the distribution-network relaxation. In the reduced test system, lower exogenous inertia increased the required primary response from 179.64 MW to 191.08 MW, distribution-side fast response reduced total frequency-response procurement by up to 4.9%, and neglecting distribution constraints overstated the combined distribution-side energy and reserve award by up to 18%. In the expanded study, the largest case was solved in 2.02 s with a 0.00% optimality gap. Time-domain simulations kept the frequency nadir above 59.0 Hz in all tested hours. These results demonstrate the value of fast-response modeling and distribution-feasible reserve delivery in coordinated market clearing.

Noh, Seung-Gil↗

Active High Assurance Authentication Protocol (AHAAP)

The AHAAP Maturation Project involves maturation and evaluation of a patented zero-trust tamper-resistant high-assurance session-less dynamic and active device authentication protocol that simultaneously authenticates identity and provides integrity verification in a single step, substantially reducing the risk of cyberattack, and eliminating the need for costly and complex conventional communication security systems requirements (i.e., cryptography, Public Key Infrastructure (PKI), and key management). These cybersecurity attributes of the technology must be preserved when applying the technology to different cybersecurity solutions, including Command & Control (C&C), Over-the-Air (OTA) update, Common Access Card (CAC), and distributed energy resource (DER) implementations, among others. The technology research objective is to test and verify that the cybersecurity attributes of the technology are not degraded in different cybersecurity applications. The primary technology development objective is to build minimum viable products to demonstrate the technology addresses today’s cybersecurity threats so that prospective investors, strategic partners, regulatory agencies, and commercial customers can interact with and assess the protection assured by the technology. The AHAAP Maturation Project goal is to develop, test, and validate one or more AHAAP implementations. The AHAAP Maturation Project tasks are: (i) engineer AHAAP implementation software, (ii) build a functional prototype that implements the AHAAP software for demonstration, testing, analysis, and evaluation purposes, and (iii) generate a report detailing the results of the AHAAP C&C software and hardware implementation. The final project deliverables are: (i) AHAAP software implementation and prototype, (ii) a report from Sandia National Laboratories detailing the results of the AHAAP implementations.

97 MATHEMATICS AND COMPUTING↗

DER Translate

SAND2024-13723O This software translates and maps any .xlsx-based distributed energy resource (DER) device from the SunSpec certification registry (https://sunspec.org/certified-registry/) to a JSON-based DER models map. It is then read by DER monitoring tools for applications such as network intrusion detection and system health monitoring. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Fragkos, Georgios↗

AGGREGATE: dAta-driven modelinG preservinG contRollable dEr for outaGe mAnagemenT and rEsiliency (Report for Task 11 & 12: Components and Capabilities of the Resiliency Driven Outage Management and Feeder Restoration System (Deliverable D8))

This report provides progress update for the development of a outage management, feeder restoration, and restoration action feasibility check modules as part of the AGGREGATE project. Details for integration with controllability module, data driven situational awareness of network and distributed energy resources as well cyber security plan for these modules integrated with GE ADMS are also presented in the report. These three modules for outage management, feeder restoration, and restoration action feasibility check modules are developed in MATLAB and validated with a modified IEEE 123-node feeder. Results demonstrate ability of these new modules to improve the restoration process post-disaster to enhance the system resilience.

42 ENGINEERING↗

CReST-VCT System Integration Framework

In this paper, we propose a system integration framework for deploying the Coordinated Real-time Sub-Transmission Volt-var Control Tool (CReST VCT) functionality between the transmission system, the distribution system, and DERs. This represents one possible set of design choices to implement the coordinated optimization capabilities in an operating environment. The framework provides the following: An architectural reference model that describes how the CReST VCT solution maps into a broader grid architecture that accommodates and enables higher levels of DER penetration and utilization: A system integration reference model that defines a possible allocation of CReST VCT functionality within a utility’s operational environment. This includes one possible system design approach for allocation of functionality within software and protocol selections across the various interfaces; A list of potential performance and security issues that should be considered during an implementation. This framework does not represent a specific implementation of the CReST VCT algorithm or integration into a specific utility environment. It is intended to serve as a reference for those who plan to implement such a solution into their environment. The general model provided by the framework can be tailored to a specific environment based on its specific constraints and requirements.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber Resilient Design and Controls for Energy Systems

As the grid of today is evolving into a highly distributed and autonomous cyber-physical system with higher penetration of Distributed Energy Resources (DERs) and autonomous controls that are dependent on the cyber infrastructure, there are novel and increasing challenges to cyber-resilient operation of the grid. While the traditional mechanisms take a "bolt on" approach to cybersecurity and resiliency, this talk presents two novel technologies developed at NREL that "bake in" security and resilience into the design and control of the grid. An Adaptive Resilience Metrics framework is a novel mechanism for system owners and operators to understand the impact of cyber and physical system design and topology on the resilient operation, while also helping determine optimal policies in response to adverse cyber events. Along with that a zero-knowledge proof-based technique helps incorporate security into the controls layer by focusing on computational integrity rather than data integrity. By leveraging design and control properties unique to Operational Technology systems these technologies will not only help enhance cyber-resilience for the grid of today, but a highly distributed and autonomous grid of tomorrow.

cyber resilience↗

Role-Based Access Control for Distributed Energy Resources v.1.0

The Role-Based Access Control (RBAC) for Distributed Energy Resources (DER) software is an automated and transparent stack for RBAC administrators to interact with RBAC policy. The package includes demonstrations of centralized and decentralized RBAC implementation. Both include simulated DER entities that are stored automatically in a centralized Lightweight Directory Access Protocol (LDAP) server. It also includes a REST-API to serve the HTTP requests of the RBAC administrators. A complete front-end is included to serve the users' needs. This software may be used by industry (DER vendors/utilities) as well as the research community to determine if a centralized or decentralized solution fits better the needs of an RBAC model in a DER environment. Additionally, parts of this software may be useful for developing implementations for specific needs. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525. SAND2021-8292 O

Johnson, Jay↗

Trust-Based Detection and Mitigation of Cyber Attacks in Distributed Cooperative Control of Islanded AC Microgrids

In this study, we address the challenge of detecting and mitigating cyber attacks in the distributed cooperative control of islanded AC microgrids, with a particular focus on detecting False Data Injection Attacks (FDIAs), a significant threat to the Smart Grid (SG). The SG integrates traditional power systems with communication networks, creating a complex system with numerous vulnerable links, making it a prime target for cyber attacks. These attacks can lead to the disclosure of private data, control network failures, and even blackouts. Unlike machine learning-based approaches that require extensive datasets and mathematical models dependent on accurate system modeling, our method is free from such dependencies. To enhance the microgrid’s resilience against these threats, we propose a resilient control algorithm by introducing a novel trustworthiness parameter into the traditional cooperative control algorithm. Our method evaluates the trustworthiness of distributed energy resources (DERs) based on their voltage measurements and exchanged information, using Kullback-Leibler (KL) divergence to dynamically adjust control actions. We validated our approach through simulations on both the IEEE-34 bus feeder system with eight DERs and a larger microgrid with twenty-two DERs. The results demonstrated a detection accuracy of around 100%, with millisecond range mitigation time, ensuring rapid system recovery. Additionally, our method improved system stability by up to almost 100% under attack scenarios, showcasing its effectiveness in promptly detecting attacks and maintaining system resilience. These findings highlight the potential of our approach to enhance the security and stability of microgrid systems in the face of cyber threats.

Computer Science↗

Epistemology of voltage control in DER-rich power system

Despite the recent development of several scalable, robust, and resilient control approaches with superior convergence properties considering an increasing penetration of distributed energy resources (DERs), cognitive oversights often simplify several aspects of the cyber–physical power system in the controller development. Here, following the identification of the limitations of classical controller definitions, we justify alternative definitions of voltage control approaches classifiers considering three inter-disciplinary domains: (i) power system, (ii) optimization and decision-making, and (iii) networking and cyber-security, to develop a taxonomy for helping in real-world comparative performance analysis and deployability of these controllers. We observe that classical and introduced domain-based definitions together can better classify the control algorithms.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Bayesian GAN-Based False Data Injection Attack Detection in Active Distribution Grids With DERs

Advancements in information and communication technologies have revolutionized monitoring and control capabilities within smart grids. However, it also brings new vulnerabilities to data acquisition systems and state estimation functions, which attackers can subtly tamper with the measurement data through compromising the communication network. Moreover, the high penetration of renewable energy sources with the inherited characteristics of uncertainty and variability further complicates the design of effective intrusion detection systems. In this paper, a Bayesian deep learning-based approach is developed to detect cyber attacks and maintain the security of smart grids. Our method specifically addresses the prevalent issue of imbalanced data in real power systems, which arises from the predominance of normal system operations over compromised or attacked states. Employing a novel Bayesian GAN-based technique, our approach successfully discriminates between secure and compromised measurement data, even in scenarios with significant data imbalance. Furthermore, the proposed method accommodates various practical application factors, ensuring accurate intrusion detection despite the presence of measurement noise. The feasibility and effectiveness of the proposed detection mechanism are validated by testing on IEEE 13-node and 123-node test systems. Simulation results and comparisons with literature methods demonstrate the superiority of proposed cybersecurity solutions.

Bayesian GAN↗

Threat Hunt Guide for BESS Environments

The rapid digitalization of the electric grid - driven by the integration of inverter-based resources (IBRs), battery energy storage systems (BESS), and advanced grid control platforms - has significantly enhanced grid efficiency, visibility, and flexibility. However, this evolution also introduces new cybersecurity risks, particularly through supply chain dependencies and operational blind spots at the grid edge. To address these challenges, Idaho National Laboratory (INL), through the Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) Rapid Risk initiative, conducted a series of rapid risk assessment engagements with energy organizations across the United States. Drawing on lessons learned from these engagements, INL developed the following threat hunting guide for asset owners and operators (AOOs) to enhance their cybersecurity visibility within BESS and IBR systems. The guide demonstrates how to use passive network monitoring to baseline device behavior, detect adversarial activity, and investigate anomalies without disrupting operations. By implementing these practices, energy sector stakeholders can improve coordination between cybersecurity and operations teams and strengthen the resilience of distributed energy resources (DERs) within the modern power grid. Prior to implementing any network monitoring, packet capture, or threat hunting activity described in this guide, AOOs are strongly advised to review applicable governance frameworks, legal requirements, and organizational policies. This guide is intended for informational and educational purposes only. It does not replace compliance with any federal, state, or local cybersecurity mandates or industry standards. Implementation of described configurations, technologies, or analytic workflows is performed at the discretion and responsibility of the asset owner and operator.

25 - ENERGY STORAGE↗