Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “DER systems”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Cybersecurity of DER Systems: Cybersecurity Training for State Commissions

NARUC regularly hosts multi-day cybersecurity training events for commissioners and their staff to gain knowledge of IT/OT technologies, understand the spectrum of state and federal approaches to cybersecurity, and explore cybersecurity cost recovery challenges and innovative solutions to address them. About 300 commissioners and staffers typically register for these virtual events.

cybersecurity cost recovery↗

DER Cybersecurity Detection and Response Suite

SAND2024-08475O The Distributed Energy Resource (DER) Cybersecurity Detection and Response Suite is a solution for distributed energy resource (DER) systems. The DER Security Orchestration, Automation, and Response (SOAR) solution that uses alerts from signature- and behavior-based Intrusion Detection Systems are intended to be deployed as bump-in-the-wire (BITW) devices in front of DER equipment. The fielded application would use multiple intrusion detection systems that report data to SOAR to respond to cyberattacks. The suite consists of two software components: • The proactive intrusion detection and mitigation system (PIDMS) secures grid-edge photovoltaic smart inverters and other equipment in distributed energy resource systems. It is a distributed BITW solution; cyber and physical data are automatically processed using network inspection tools and custom machine learning algorithms to detect abnormal events and correlate cyber-physical events. • The Security Orchestration, Automation, and Response for Distributed Energy Resources (SOAR4DER) application ingests data from several intrusion detection systems to quickly block attacks and revert DER systems to good states. Using a collection of intrusion detection system technologies on a BITW device, it incorporates physical and cyber data to detect abnormal and potential malicious behaviors. Multiple SOAR playbooks then use the intrusion detection system data streams to automatically defend the system. SOAR4DER system testing showed detection and response times under 30 seconds for all adversary reconnaissance, denial-of-service attacks, malicious Modbus commands, brute-force logins, and machine-in-the-middle attacks. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Johnson, Jay↗

Cybersecurity Baselines for Electric Distribution Systems and DER

The National Association of Regulatory Utility Commissioners (NARUC) has partnered with the Department of Energy (DOE) to develop a set of cybersecurity baselines for electric distribution systems and the distributed energy resources (DERs) that connect to them. Cybersecurity is an integral underpinning of power system resilience, and this initiative builds on work that states have undertaken over the last decade to mitigate cybersecurity risk across their critical infrastructures.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Real-Time Hardware-in-the-Loop Distributed Energy Resources System Testbed using IEEE 2030.5 Standard

IEEE 2030.5 standard is drawing special attention among communication protocols for smart inverters and distributed energy resources (DER). Moreover, California Rule 21 mandates new DER must be ready to communicate to a host utility using the IEEE 2030.5 standard. Therefore, development of an effective real-time simulation method for managing DER using IEEE 2030.5 network is crucial. This paper presents a real-time hardware-in-the-loop (HIL) DER system testbed using the IEEE 2030.5 standard. The proposed real-time co-simulation testbed consists of a DER physical system simulation using OP AL-RT real-time simulator and a cyber system simulation including DER gateways and a DER management system (DERMS) cloud server. Custom-built client and server programs are developed to meet the compliant with IEEE 2030.5-2018 standard and implemented in the DER gateways and a DERMS server, respectively. Furthermore, the feasibility of the proposed testbed for DER systems is validated by experiments.

42 ENGINEERING↗

Distributed Energy Resources Cybersecurity Framework & Risk Manager

Distributed Energy Resource Cybersecurity Framework (DER-CF) provides a holistic assessment for evaluating the cybersecurity posture of DER systems - filling an important gap that expands upon existing cybersecurity frameworks for more modern energy systems. The DER-CF is available as a written framework and an interactive Web tool. Distributed Energy Resource Risk Manager (DER-RM) process adheres closely to NIST's seven risk management steps: prepare, categorize, select, implement, assess, monitor, and authorize. This added feature is independent of the DER-CF's existing self-assessment and allows managers to focus on the RMF process.

cybersecurity↗

Cybersecurity Certification Requirements for Distributed Energy Resources: A Survey of SunSpec Alliance Standards

This survey paper explores the cybersecurity certification requirements defined by the SunSpec Alliance for Distributed Energy Resource (DER) devices, focusing on aspects such as software updates, device communications, authentication mechanisms, device security, logging, and test procedures. The SunSpec cybersecurity standards mandate support for remote and automated software updates, secure communication protocols, stringent authentication practices, and robust logging mechanisms to ensure operational integrity. Furthermore, the paper discusses the implementation of the SAE J3072 standard using the IEEE 2030.5 protocol, emphasizing the secure interactions between electric vehicle supply equipment (EVSE) and plug-in electric vehicles (PEVs) for functionalities like vehicle-to-grid (V2G) capabilities. This research also examines the SunSpec Modbus standard, which enhances the interoperability among DER system components, facilitating compliance with grid interconnection standards. This paper also analyzes the existing SunSpec Device Information Models, which standardize data exchange formats for DER systems across communication interfaces. Finally, this paper concludes with a detailed discussion of the energy storage cybersecurity specification and the blockchain cybersecurity requirements as proposed by SunSpec Alliance.

Tsikteris, Sean (ORCID:0009000524202250)↗

Integration of a DER Management System in Riverside. Final report

The tasks in this project covered various aspects, including algorithm development, algorithm integration into a commercial Active Network Management (ANM) platform, hardware-in-the-loop (HIL) testing in an industry-standard testing platform, pilot demonstration in Riverside, California, and also cost and benefit analysis. The DERMS platform in this project can host different algorithms developed on different platforms (e.g., MATLAB and Python) and it can interact with different hardware devices (e.g., different PV inverters, battery inverters, and different sensors). The DER control solution are based on an advanced model-free, layered, and clustered DER control paradigm. At the core of the DER control algorithms was the concept of Extremum Seeking (ES), which is a model-free probing-based control technique. The ES-based control algorithms were tested on major real-world inverters; both individually and in a cluster. It was shown that even legacy equipment (or when paired with a few additional advanced equipment) can support such advanced control. The monitoring algorithms utilize a heterogeneous set of legacy and advanced sensor measurements, such as behind-the-meter DER sensors, distribution-level Phase Measurement Units, distribution-substation Supervisory Control and Data Acquisition (SCADA), and line current sensors, with their limited availability; in order to infer practical network conditions. Sensor data are utilized to achieve resource forecasting, phase identification, and distribution system state estimation. The technology that was developed and demonstrated in this project could be transformational to utilities, including the smaller municipal utilities such as in Riverside, which may not have the resources to deploy advanced distribution system and DERMS solutions in order to support high penetration of solar power integration. This project created a real-world prototype to provide utilities with an assessment of smart grid monitoring and control technologies.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Sizing and Location Selection of Medium‐Voltage Back‐to‐Back Converters for DER‐Dominated Distribution Systems

Medium‐voltage back‐to‐back (MVB2B) converters can connect two distribution systems and quantifiably transfer power between them. This function can enable the MVB2B converter to exchange distributed energy resource (DER)‐generated power between two systems and bring significant value to enhancing distribution system DER adoption. Our previous work analysed and demonstrated the value MVB2B converter can bring to DER integration. As continuous work, this paper presents a methodology that helps address the MVB2B converter sizing and location selection problem in distribution systems with high DER penetrations. The proposed methodology aims to address three critical problems for MVB2B converter implementation in the real world: (1) which distribution systems are better to be connected, (2) what converter size is appropriate for connecting the distribution systems, and (3) where the optimal connection points are in the systems for connecting the MVB2B converter. The proposed methodology has been demonstrated by case studies that include various scenarios involving distribution systems with different dominated load types and high photovoltaic penetrations. The results demonstrate that selecting the optimal converter size based on net revenue and time of return considerations leads to a balance between maximizing energy savings and minimizing financial payback periods. Furthermore, feeder pair selection based on load profile standard deviation effectively identifies systems that derive the greatest value from MVB2B integration. Finally, an optimized connection point selection approach using a voltage load sensitivity matrix ensures minimal system impact while facilitating efficient power exchange. These findings provide practical insights for the real‐world deployment of MVB2B converters to enhance DER hosting capacity and improve grid resilience.

14 SOLAR ENERGY↗

Module-OT: A Turnkey Solution for Securing Energy Systems

The Modular Security Apparatus for Managing Distributed Cryptography for Command-and-Control Messages on Operational Technology Networks (Module-OT) is a flexible and lightweight solution for grid-edge devices focusing on end-to-end security. It is a bump- in- the-wire solution acting as a secure conduit for data between devices or systems across a network. It improves the cybersecurity posture of DER systems by providing authentication, authorization, and data integrity to secure DER communications. Additionally, it performs key management, provides data security through whitelisting Internet Protocol addresses and ports, blocks unauthorized connections, controls user access, and allows serial or Ethernet connections for added flexibility. The core software is portable to various Linux-based operating systems and is developed to be customized by the developer and researcher communities. Module-OT has been validated in the lab, has been demonstrated at a 500-KW PV-plus-storage site, and has been proven ready to secure operational technology devices. Its core functionality meets current standards, including validation procedures of the NIST Cryptographic Algorithm Validation Program (CAVP) and the Federal Information Processing Standard (FIPS 140-2). Because of its capability to provide an accessible and affordable option for stepping up security across modern energy systems, Module-OT can serve as an effective technological option to standardize cybersecurity moving forward.

cryptography↗

Risk Management for Distributed Energy Resources

The National Institute of Standards and Technology will be hosting on Tuesday, February 2 and Wednesday, February 3, 2021, the second workshop in a new series focusing on the Open Security Controls Assessment Language. NREL extended the scope of the DERCF to include the NIST Risk Management Framework (RMF), addressing the challenges faced by federal energy managers when complying with the NIST RMF for DER systems. The NIST RMF is a cyclical process designed to incorporate principles of security and risk management into an organization’s system policies and procedures. The DER-RM will be downloadable application that runs locally and documents all the major requirements for achieving Authority to Operate the DER.

cybersecurity↗

Distributed Energy Resource Cybersecurity Framework and Cyber Range Integration

Distributed energy resource (DER) systems feature complex, data-driven communications networks that require careful system coordination and constant vigilance to ensure that grid assets are secure. Because DERs are an important component of the decarbonization strategy, agencies need to secure energy data that could implicate issues of national security if compromised. To help federal energy managers assess, monitor, and manage cybersecurity while achieving decarbonization, the National Renewable Energy Laboratory's (NREL's) Distributed Energy Resource Cybersecurity Framework (DER-CF) offers a comprehensive, web-based assessment tool focusing on cyber governance or policies, technical management, and physical security. The DER-CF currently presents users with a series of pertinent cybersecurity questions that are used to generate a site-specific report and recommendations. This paper outlines a plan to integrate the DER-CF with another key asset-NREL's cyber range-to visualize cybersecurity resilience and compliance and to enhance the usability and accessibility of the DER-CF for federal facility energy managers and planners. This integration will result in a visualization environment to interpret and interact with compliance data. Its development will include regular conversations with stakeholders to assess the effectiveness of these efforts, refine the visualization capability, and ensure its value to our partners.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cybersecurity Assessment Tools for Distributed Energy Resources

This growing number of smart devices that support DERs can increase the number of access points outside a utility’s administrative domain, which can increase the potential for cyberattack. With the integration of DERs at federal sites, the cybersecurity vulnerabilities of DER systems must be understood and addressed. This presentation covers two NREL tools available. The Distributed Energy Resource Cybersecurity Framework (DER-CF) is a web-based holistic tool for evaluating cybersecurity posture including governance, physical security and technical management. The Distributed Energy Resource Risk Manager (DER-RM) extends the DER-CF by applying it to the NIST risk management framework process. It will be downloadable application that runs locally and documents all the major requirements for achieving Authority to Operate the DER.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

A Photovoltaic MPPT Charge Controller Real-Time Testbed for Cybersecurity Applications

The increasing deployment of distributed energy resources (DER) over the last decade is a great ally to combat climate change and strengthen the grid during increasingly common extreme weather events. However, DER systems, combined with the ongoing transition to a digital power grid, also pose substantial cybersecurity threats. One of the most common communication protocols used in DER integration is the Distributed Network Protocol 3 (DNP3), which is known to have many security vulnerabilities. Thus, it is essential to investigate cyberattack behaviors and mitigation on power systems using DNP3. In this paper, we designed and implemented a cybersecurity testbed for a simulated photovoltaic (PV) maximum power point tracking (MPPT) charge controller. Our testbed uses an MPPT charge controller simulated on a Typhoon HIL602+ real-time simulator with a real DNP3 communication connection over TCP/IP, allowing for safe and efficient monitoring and manipulation of data traffic between the simulated hardware and supervisory control and data acquisition (SCADA) systems.

14 SOLAR ENERGY↗

Data-Driven Generic Turbines for Distributed Wind Modeling, Optimization, and Economic Studies

As distributed energy resources (DER) become less expensive and more popular, utilities, project developers, and customers have an increasing need to model the performance of existing and proposed DER systems. Distributed wind has been shown to have widespread economic potential but is often represented by a simplified model in - or excluded from - DER modeling tools and studies. There is often no economic imperative to extend models and studies to give full consideration to distributed wind. We present a set of data-driven generic turbines derived from 16 years of annual distributed wind market survey data. The proposed methodology can be used to derive generic turbines from separate or updated data sets. Finally, a mixed-integer linear programming approach to optimal distributed wind project sizing is used to demonstrate the generic turbine models. Combined, these models and methods can reduce barriers to considering distributed wind in modeling tools and studies.

Reiman, Andrew P.↗

Applying the Risk Management Framework: The Distributed Energy Resource Risk Manager

As part of a multiyear effort, the National Renewable Energy Laboratory (NREL) has dedicated resources to understand and identify cybersecurity weaknesses in distributed energy resources (DERs) by performing assessments. Due to a lack of standardization and rapidly increasing adoption of DERs, there is a critical need to address cybersecurity needs for DER systems in an interactive way. Furthermore, federal agencies, which are required to obtain an authority to operate, are challenged by the complexities of including their DERs. To help meet this need, in early 2020, NREL released the Distributed Energy Resources Cybersecurity Framework (DERCF) and accompanying Web application. This process is supported by the Risk Management Framework (RMF) developed by the National Institute of Standards and Technology. This project, referred to as the DERCF RMF application, expands on the existing DERCF work to include methods that support walking a user through the seven RMF steps. The tool will be available for download at no cost from [link ]. The purpose of this paper is to describe the steps the DERCF team at NREL took to understand Steps 1-5 of the RMF process. Additionally, this document will identify future work on the first five steps as well as a plan for Steps 6 and 7.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Real-time evaluation of cybersecurity threats to DER inverter grid-support functions

In this project we aim to contribute to the understanding of the type and severity of potential cybersecurity attacks to the grid-support functionalities of DER systems interconnected to the AC distribution grid via inverters. Our preliminary work focused on developing a small-scale testbed allowing to study cybersecurity threats to an isolated photovoltaic-battery system using a real-time simulator (Typhoon HIL602+) with a real DNP3 communication connection over TCP/IP, allowing for safe and efficient monitoring and manipulation of data traffic between the simulated hardware and supervisory control and data acquisition (SCADA) system. In this project we propose to expand upon this development by utilizing a) a recently acquired NovaCor RTDS (Real Rime digital Simulator) to emulate the DER-inverter-grid topology including main grid-support functions as defined by IEEE Std. 1547-2018, and b) an industrial control and automation device to enable realistic evaluation of control functions and utilization of communication protocols for real-time data transmission.

24 POWER TRANSMISSION AND DISTRIBUTION↗