Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Integrating Cybersecurity”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 163 records · Page 9

Tale of Two Domains: Cyber - Physical

As devices and systems continue to modernize and adopt integrated circuits, the use of cyber technology to deploy an application is the expectation. This deployment through cyber assets brings new cyber risk and cybersecurity is the practice of managing this risk. Cyber-risk is constantly changing due to the speed of technology advancement and the changing quality of the adversary. Cyber-Informed Engineering (CIE) mitigates cyber-risk through engineering controls where as the traditional practice of cybersecurity mitigates cyber-risk through cybersecurity controls. By clearly defining the cyber-physical boundary, engineering controls and cybersecurity controls can clearly demonstrate their complementary nature to provide layered defenses and successfully mitigate cyber-risk through independent controls. In this paper, a layered model of device decomposition of the the cyber-physical boundary is presented to provide clarity where engineering controls are used to reduce cyber-risk within the physics, functional materials, electronic, or integrated circuit layers and where cybersecurity controls are used to reduce cyber-risk within the machine code and application layers. By implementing both traditional cybersecurity controls and engineering controls, a more holistic approach to cybersecurity is achieved in protecting modern devices and systems, as well as a clear awareness in identifying, documenting, and authorizing the system’s cybersecurity protection scheme is achieved.

42 - ENGINEERING↗

Caribbean Energy Sector Cybersecurity Forum: Modernizing and Securing the Grid

This presentation on Modernizing and Securing the Grid brought together regional and NREL cybersecurity expertise for USAID's Caribbean Energy Sector Cybersecurity Forum. The presentation's overall purpose was to provide a deep dive into the changes underway in the electric grid, including the greater integration of renewables and distributed energy resources. The presentation also reviewed best practices for building cybersecurity into modern energy systems, including in the areas of vendor assessment and supply chain cybersecurity.

Caribbean↗

ARIES Annual Report FY25

Advanced Research on Integrated Energy Systems (ARIES) at the National Laboratory of the Rockies (NLR) is the U.S. Department of Energy's (DOE's) test bed for energy system demonstration and de-risking. ARIES comprises the largest collection of physical and digital assets in the DOE laboratory complex, supporting flexible configuration across a broad range of energy scenarios. In Fiscal Year 2025, ARIES provided a platform for system-level research to anticipate and address future energy needs in energy security, system reliability, and technology deployment.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cybersecurity Standards for Distributed Energy Resources: Gaps and Harmonization Strategy

This report examines cybersecurity standards for Distributed Energy Resources (DERs) in light of their rapid growth and increasing integration into energy systems. It identifies critical gaps in existing frameworks, including inadequate coverage of DER-specific challenges, complexities in implementing comprehensive standards, integration issues with legacy systems, adoption hurdles for newer standards, and a lack of harmonization across regulatory landscapes. The analysis highlights vulnerabilities such as data integrity risks, unauthorized device control, and denial-of-service attacks across various DER technologies like solar PV, wind turbines, energy storage systems, and hydrogen fuel cells. The report proposes a harmonization strategy to address these deficiencies by developing unified cybersecurity requirements, certification programs, and training resources while fostering collaboration among stakeholders such as government agencies, industry groups, DER operators, manufacturers, and research institutions. A phased roadmap is outlined to refine and implement these measures through pilot testing and widespread adoption. Ultimately, the report underscores the urgent need for coordinated efforts to enhance DER cybersecurity and ensure the reliable operation of future energy systems.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

A full-scope, high-fidelity simulator-based hardware-in-the-loop testbed for comprehensive nuclear power plant cybersecurity research

Nuclear power plant (NPP) cybersecurity research often relies on hardware-in-the-loop (HIL) testbeds that integrate real hardware components into simulated environments. These testbeds allow researchers to identify vulnerabilities, evaluate attack impacts, and test security measures in a controlled setting. Furthermore, previous HIL testbeds lacked fidelity to accurately represent real nuclear systems, limiting the scope of cybersecurity analysis. This study presents the creation of a HIL testbed, devised upon a full-scope, high-fidelity NPP simulator, to facilitate realistic and comprehensive cybersecurity research. To demonstrate its capabilities, the control logic for the steam generator water level was migrated from the simulator to an external programmable logic controller. As a practical application of the developed testbed, supply chain attack scenarios were simulated by injecting malicious code into the controller logic, and the effects of manipulating sensor inputs and control commands were observed. While this HIL testbed provides more detailed simulations, enhanced realism, and wider applicability compared to other options utilizing a less complex simulator, it is also more intricate and costly. For this reason, we include a detailed comparison with some alternative architectures to aid fellow researchers and practitioners in the selection of a suitable HIL architecture based on specific research objectives.

47 OTHER INSTRUMENTATION↗

Bayesian Attack Model (BAM) User Story

This document presents a user story for the Bayesian Attack Model (BAM) tool designed to aggregate and analyze cyber-attack observables for operational technology (OT) systems. BAM aims to empower cybersecurity analysts by providing a streamlined interface for collecting observable data from various sources, enabling real-time analysis of potential adversary activity. By enhancing the response capabilities of security teams, BAM facilitates risk-informed decision-making and improves organizational security posture. This user story outlines the key functionalities, user interactions, and requirements necessary to successfully integrate BAM with other security information and event management (SIEM) technology and cybersecurity operations centers (CSOCs).

97 MATHEMATICS AND COMPUTING↗

Security Evaluation of Smart Cards and Secure Tokens: Benefits and Drawbacks for Reducing Supply Chain Risks of Nuclear Power Plants

The supply chain attack pathway is being increasingly used by adversaries to bypass security controls and gain unauthorized access to sensitive networks and equipment (e.g., Critical Digital Assets). Cyber-attacks targeting supply chain generally aim to compromise the environments, products, or services of vendors and suppliers to inject, add, or substitute authentic software and hardware with malicious elements. These malicious elements are deemed to be authentic as they arise from the vendor or supplier (i.e., the supply chain). This research aims to leverage findings and assumptions made from the previous report to determine the security benefits and drawbacks of a smart card- based hardware root of trust. Smart cards can provide devices inside Nuclear Power Plants (NPP) with a secure environment to store keys in and perform sensitive operations such as digital signature generation. These abilities can be leveraged to increase supply chain cybersecurity by autonomously providing NPP Licensees with reports on device integrity, authenticity and measurements of executable and non-executable data.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

A Real-Time Testbed for Smart Inverter Cyber Security Studies

Distributed energy resources (DER) have become a popular solution to modern-day issues surrounding the efficiency and reliability of power generation, as well as climate change concerns. Energy centers are shifting towards incorporating smart inverters with embedded functionalities such as high voltage ride through (HVRT), low voltage ride through (LVRT), active and reactive power compensation. However, the integration of smart inverters leave DER systems highly vulnerable to cybersecurity threats. The distributed network protocol 3 (DNP3) is a common method of communication between grid-tied hardware. Despite its popularity, the level of security leaves all hardware connected to the grid at risk of severe cyber-attacks. Thus, it is important to study any potential cybersecurity threats towards grid-tied smart inverters to mitigate cybersecurity vulnerabilities and refine existing cyber-security protections. This report describes the proposed testbed design to study cybersecurity threats to smart inverters. The testbed utilizes a real-time simulation case in RSCAD that includes a grid-tied wind turbine (WT) topology featuring two back-to-back two-level voltage source converters (BTB,2L-VSCs) and a permanent magnet synchronous machine (PMSM). The simulated case runs within the NovaCor real time digital simulator (RTDS). This report focuses on the design and implementation of a single module of the GTNETx2 card as a distributed network protocol and the configuration of an IEEE 1518 DNP database file that includes input and output variables mapped to different connection points in the grid that transmit and receive discrete, analog, and binary signals on command. This allows realistic emulation of the communication between the smart inverter and the grid for cybersecurity studies.

97 MATHEMATICS AND COMPUTING↗

Technical Learning and Integration of Interns in Advanced Protection Lab Space: Enhancements to Testbed and Experiments to Improve Workflows for Producing Datasets

This report presents a successful technical learning integration of student interns in the Advanced Protection Laboratory space, located in the Grid Research Integration and Deployment Center (GRID-C) at the Department of Energy’s (DOE’s) Oak Ridge National Laboratory (ORNL). The Advanced Protection Laboratory was created for the primary goal of supporting DOE’s research projects and technical staff at ORNL. As a secondary goal, the space was used for collaborating with ORNL’s intern programs, providing support to the lab’s mentors and student interns. In 2024, three student interns spent a summer in the Advanced Protection lab space and were involved in the DarkNet Distributed Ledger Technology (DLT) project. The students had a great opportunity to gain hands-on experience with communication and protective relay equipment focused on information technology, data analytics, and cybersecurity. Experiences in the lab space with real equipment and software integration offer education and professional development for students, which is especially important because of a need in the energy industry to recruit highly skilled power and communication engineers.

42 ENGINEERING↗

Module-OT: A Turnkey Solution for Securing Energy Systems

The Modular Security Apparatus for Managing Distributed Cryptography for Command-and-Control Messages on Operational Technology Networks (Module-OT) is a flexible and lightweight solution for grid-edge devices focusing on end-to-end security. It is a bump- in- the-wire solution acting as a secure conduit for data between devices or systems across a network. It improves the cybersecurity posture of DER systems by providing authentication, authorization, and data integrity to secure DER communications. Additionally, it performs key management, provides data security through whitelisting Internet Protocol addresses and ports, blocks unauthorized connections, controls user access, and allows serial or Ethernet connections for added flexibility. The core software is portable to various Linux-based operating systems and is developed to be customized by the developer and researcher communities. Module-OT has been validated in the lab, has been demonstrated at a 500-KW PV-plus-storage site, and has been proven ready to secure operational technology devices. Its core functionality meets current standards, including validation procedures of the NIST Cryptographic Algorithm Validation Program (CAVP) and the Federal Information Processing Standard (FIPS 140-2). Because of its capability to provide an accessible and affordable option for stepping up security across modern energy systems, Module-OT can serve as an effective technological option to standardize cybersecurity moving forward.

cryptography↗

Universal Utility Data Exchange (UUDEX) – Security and Administration: Cybersecurity of Energy Delivery Systems (CEDS) Research and Development

A critical component of the Universal Utility Data Exchange (UUDEX) approach is the integrated security contained within its processing. This document describes how that security is designed and expected to be implemented by UUDEX Implementations (U-Implementations), including the UUDEX Server (U-Server) and UUDEX Clients (U-Clients). The UUDEX security hierarchy consists of three levels: 1. The UUDEX Instance (U-Instance) itself, which sits at the top of the hierarchy and contains the U-Server, the UUDEX Identity Authority (U-Identity Authority), and the UUDEX Administrator (U-Administrator) functions; 2. A group of one or more UUDEX Participants (U-Participants) that present “organizations” that participate in the U-Instance and contains the UUDEX Administrator Participant (U-U-Administrator Participant) function; 3. A group of one or more UUDEX Endpoints (U-Endpoints) that represent the individual UUDEX Publish Clients (U-Publish Client) responsible for supplying data to the U-Instance that is consumed by UUDEX Subscriber Clients (U-Subscriber Clients). U-Endpoints can be either autonomous devices that publish and subscribe data such as data exchange servers found in supervisory control and data acquisition and energy management systems, or they can be tied to users of applications that, for example, submit DOE OE-417 disturbance reports. U-Participants and U-Endpoints can be organized into UUDEX Groups (U-Groups). Any number of U-Participants or U-Endpoints can be members of a U-Group. A given U-Participant or U-Endpoint can be a member of multiple U-Groups, but a U-Group cannot contain other U-Groups. For example, a U-Group could be created to contain all U-Participant Transmission Operators within the purview of a Reliability Coordinator, and another U-Group could be created to contain all U-Participant Generator Operators within the purview of a Reliability Coordinator. U-Participants that are both Transmission Operators and Generator Operators would be members of both U-Groups. U-Participants, U-Endpoints, and U-Groups are used in the access control structures to provide access to individual UUDEX Subjects (U-Subjects). U-Groups are created by the U-Administrator and are managed by the U-Administrator or the designated U-Group Managers. U-Endpoints can be assigned UUDEX Roles (U-Roles) that can be used to further restrict access. U-Roles are assigned to individual U-Endpoints. For example, a U-Role of “Security Analyst” could be used to restrict which U-Endpoints can publish or subscribe security incident reports and vulnerability notifications, while a U-Role of “Transmission Planner” can be used to restrict which U-Endpoints can publish power system model updates. U-Role definitions are created by the U-Administrator, but the U-Roles are assigned to U-Endpoints by their respective UUDEX Participant Administrators (U-Participant Administrator). Because all information required to make security decisions is either included within the U-Endpoint’s X.509 digital certificate or stored in a datastore on the U-Server, all security decisions are performed and enforced within the U-Server. This reduces the complexity of the U-Client code and minimizes the chance for compromise of the integrity of the UUDEX security features.

97 MATHEMATICS AND COMPUTING↗

Cybersecurity for Grid Connected eXtreme Fast Charging (XFC) Station (CyberX) (Final Scientific/Technical Report)

This report summarizes the activities conducted under the DOE VTO funded project DE- EE0008451, where ABB Inc. (ABB), in collaboration with Idaho National Laboratory (INL), APS Global (APS), and XOS Trucks (XOS) pursued the development of a cyber-resilient extreme fast charging (XFC) management system. This project entitled Cybersecurity for Grid Connected eXtreme Fast Charging (XFC) Station (CyberX) focuses on a resilient architecture for smart charging EV Supply Equipment (EVSE) device control and Coordinated Anomaly Detection System (CADS) features that can be added at the charging site depot level to increase cybersecurity. The project was split into two budget periods focused first on developing the threat model and resilient control concepts and second on testing, improving, and validating those developed resilient control algorithms and features with a focus on key vulnerabilities identified during the threat assessment portion of the project. During the first budget period of the CyberX project, the ABB led team focused on activities to identify, model, and quantitatively prioritize high-impact attack scenarios with potential cyber-physical effects while also modeling and developing concepts for a resilient control system that could securely address integration of DERs and other resources with EV charging. Development of the security focused XFC management system (XMS) was accomplished first by offline simulation using a developed XFC station or depot with 480V input level and simulating measurement inputs to monitoring and control systems in concept development. A representative distribution grid model was developed supporting an EV charging site model with BESS and 6 general EV charging models. These EV charging models allowed multiple configurations of charging level, multiple connected protection and measurement devices, and simulation function to show general compromise of EV, BESS, and protection features based on parallel threat analysis. During the second budget period, the EV site and supporting systems model was developed in more detail and converted from offline model to real-time to real-time with EV charging hardware in the loop (HIL). The resilient control architecture developed as concept in the first part of the project was further tested and validated for integration of local energy resources and XFC charging station site equipment while maintaining cybersecure operating principles. The proposed resilient architecture for smart charging and cybersecurity features consists of two main concepts developed and tested within the project. The first concept is an XFC management system (XMS) consisting of a hardware gateway, software platform, and Supervisory Control and Data Acquisition (SCADA) or Distribution Management System integration components. The second concept is a Coordinated Anomaly Detection System (CADS) which forms a primarily software-related subsystem of the total CyberX solution focused on monitoring system measurements, estimation of measurement states, and predicting current at the utility point of interaction based on machine learning for anomaly detection.

33 ADVANCED PROPULSION SYSTEMS↗

Large Load Integration - Task List and Overview

Large Load Integration Tasks: Task 1 – Workshops Support stakeholder engagement across industry to promote collaboration and identify solutions to challenges that will guide other work Task 2 – Ancillary Services Characterize different types of large loads to assess under what conditions they may be utilized to provide grid stability services Task 3 – Communications Explore the cybersecurity and communications infrastructure required to enable large loads to interface with grid operations to provide ancillary services Task 4 – Nuclear Integration Explore risks and methods for supporting large load energy needs with SMRs and incorporating them into the wider power system Task 5 – Decision Support and TA Provide support to stakeholders through the creation of planning tools and direct technical assistance.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Overview and Commentary on Applying the Coordinated Vulnerability Disclosure Process to Photovoltaic System Devices

The rapid expansion of photovoltaic (PV) systems, particularly inverters, has introduced new cybersecurity challenges that threaten both local operations as well as the broader electrical grid’s stability. PV inverters, integrated into critical energy infrastructure are potential targets for cyber attacks due to vulnerabilities in firmware, remote access systems, and communication protocols. The Coordinated Vulnerability Disclosure (CVD) process, as defined by the Cybersecurity and Infrastructure Security Agency (CISA), provides a framework for identifying, reporting, and addressing these vulnerabilities in a transparent and collaborative manner. This report outlines the CVD process as it applies to PV systems, detailing the roles of key stakeholders, such as manufacturers, grid operators, and security researchers. The report also highlights specific challenges in managing vulnerabilities for new and legacy PV systems, which includes those introduced by insecure communications and third-party supply chain components. By adhering to the CVD process, the PV industry can mitigate cybersecurity risks, ensure regulatory compliance, and maintain consumer trust, while safeguarding the operational resilience of the energy grid. Ultimately, the effective coordination of vulnerability management is crucial for securing the future of PV systems within the critical electric grid infrastructure landscape.

14 SOLAR ENERGY↗

Cybersecurity Guide for Distributed Wind

Distributed wind sits at the intersection of grid-connected, off-grid and behind-the-meter cyber-physical electrical energy systems. The unique physical properties and communications requirements for distributed wind systems mean that there are unique cybersecurity considerations, but there is little to no existing guidance on best practices for cybersecurity. This document is intended to be a starting point for distributed wind stakeholders including manufacturers, installers and integrators, and operators (facility, aggregator, or utility). We discuss common distributed wind architectures and describe their role in the larger power system, pointing out some of the key connections to be aware of. Cybersecurity cannot exist in a vacuum, but rather must consider all the system and all its connections holistically. The role of distributed wind and the functions it can serve are described to gain understanding of the full range of capabilities. The purpose and application of relevant standards that may apply to certain distributed wind systems is presented. These standards may not apply to all installations, but even for systems that are not required to meet these standards they can be a good reference for best practices. A holistic threat perspective is used to describe the adversaries, threats, and potential impacts of cyberattacks, with special emphasis on what sets distributed wind systems apart from other distributed energy resources (DER). Finally, we present the recommendations for cybersecurity, both in terms of needs of the system and roles that specific stakeholders should fulfill. Distributed wind systems can come in a variety of architectures and applications, so there is no one-size-fits-all approach to cybersecurity. However, this document contains the relevant information for stakeholders to identify the cybersecurity needs of their system, refer to relevant standards, and apply best practices in a manner most consistent with their security and operational goals.

17 WIND ENERGY↗

Planning Roadmap for DER Integration in India: Industry Best Practices and Resource Guide

Ensuring safe, reliable, cost-effective DER integration at scale requires holistic planning, broad stakeholder engagement, and should address key development areas such as standards adoption, equipment testing and certification, interoperability and cybersecurity, interconnection procedures, and advanced forecasting and DER management. Each of these areas currently represent significant challenges for utilities, regulators, OEMs, developers, and even consumers worldwide. India has already seen significant growth of DERs and has announced targets for substantial growth yet to come, with the potential for DERs to make up a non-negligible portion of the country's overall generation capacity. As such, it is of critical importance that Indian stakeholders consider the potential impacts of wide-spread adoption of DERs and take preemptive action related to the five development areas listed here, among others. India should consider strategies including the adoption of key DER standards related to interconnection, testing, and cybersecurity; enabling effective and secure communication channels for DER interoperability; testing and certifying DER equipment in accredited testing laboratories; building robust, streamlined interconnection procedures; and revamping legacy system planning structures to incorporate DERs in a holistic planning framework.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Enhanced Control, Optimization, and Integration of Distributed Energy Applications (ECO-IDEA)

With support from the U.S. Department of Energy Solar Energy Technologies Office, the National Renewable Energy Laboratory (NREL) partnered with Xcel Energy, Schneider Electric, Varentec, and Electric Power Research Institute (EPRI) to meet the goals of the Enabling Extreme Real-Time Grid Integration of Solar Energy (ENERGISE) program. This project developed and validated an innovative data-enhanced hierarchical control architecture that enables the efficient, reliable, resilient, and secure operation of future distribution systems with a high penetration of distributed energy resources like solar energy. The architecture enables a hybrid control approach where a centralized control layer is complemented by distributed control algorithms for solar inverters and autonomous control of grid edge devices. It is fully interoperable and includes all the cybersecurity aspects necessary for reliable and secure system operation. The hybrid approach can seamlessly integrate multiple voltage-regulation technologies, both at central and grid-edge levels, which enables reliable and efficient system operation in the face of unpredictable conditions. The overarching goal of the Eco-Idea project is to develop, validate, and deploy a unique and innovative Data-Enhanced Hierarchical Control (DEHC) architecture that comprehensively addresses the formidable challenges associated with proliferation of high penetration of distributed PV such as reverse power flows, transients from variability of PV systems, feeder load balancing, and voltage stability. These issues are exposing the weaknesses of existing grid operations and controls - including, but not limited to, lack of grid situational awareness, heuristic and slow-acting control actions, latency of control for emergency situations, and points of failure in communications. The proposed architecture will comprehensively resolve the deficiencies of current operational settings - where monitoring and control solutions proposed across industry and academia may not be interoperable and may not coexist in the same system - and will enable an efficient, reliable, resilient, and secure operation of future distribution systems with penetration of solar energy well beyond current limits. The DEHC architecture was developed and validated rigorously through hardware-in-loop simulations in the laboratory environment and deployed on the field.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Data Centers and Digital Assurance Introduction to Supply Chain and Cybersecurity for Data Centers, Session 1

The first session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort Workshop, held on October 30, 2025, introduced foundational concepts of Digital Assurance in the context of data center and grid integration. Sponsored by the U.S. Department of Energy, the workshop brought together utilities, data center operators, developers, and vendors to address cybersecurity and supply chain vulnerabilities. The session emphasized the growing criticality of data centers within the electric grid and the need for secure, real-time, bidirectional communication. Participants explored the principles of Digital Assurance, including cybersecurity, cyber-informed engineering (CIE), and lifecycle security, and applied a threat-vulnerability-consequence framework to identify and mitigate risks at the data center–grid interface. Discussions covered a range of threats such as spoofed dispatch signals and insider threats, architectural vulnerabilities like SCADA interfaces and insecure protocols, and potential consequences including cascading grid failures. The session also raised strategic questions about business value, vendor assurance, and defining cyber boundaries and responsibilities. This foundational workshop set the stage for deeper technical analysis and the development of actionable frameworks in subsequent sessions. Session 1 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗