Search NASASearch

Engineering topics

Cryar, Ryan

Publications and source records attributed to Cryar, Ryan.

Electric Vehicle Supply Equipment Security Solutions

The EVs@Scale cybersecurity pillar deep dive focuses on the three main tasks that NREL has in the consortium: (1) Analysis of EV charging mobile applications, (2) Cybersecurity risk assessments of EVSE through DER-CF, and (3) PKI for EVSE.

ADVANCED PROPULSION SYSTEMS,MATHEMATICS AND COMPUT

Investigate the Security of Electric Vehicle (EV) Ecosystem Applications

Apps that run on mobile devices are one of critical components of the electric vehicle (EV) ecosystem and pose possible threat actor points of entry that may impact the trust and security of EV charging systems in the future. Mobile apps often rely on communication between cloud servers and users, thereby creating potential points of entry for cyberattacks. Although app stores such as Apple App Store or Google Play Store generally test the security of apps, the cyber aspects may not be sufficient for many entities including DOD, federal fleets, and commercial entities. A more thorough inspection and the ability to influence developers is imminently needed. This research studies security attributes and vulnerabilities of a sample of mobile applications that support key user functions in the EV ecosystem. The study shows that all analyzed apps have security risks, categorized as either high or medium or both and a comprehensive cybersecurity guideline for developing mobile apps is necessary.

33 ADVANCED PROPULSION SYSTEMS

Electric Vehicle Supply Equipment Cybersecurity Through Emulation

As the grid evolves, it is paramount to understand the risks that cyberattacks pose before assets are deployed. Leveraging the ARIES Cyber Range, NREL has created a platform to conduct analysis of EV charging protocol cybersecurity to understand the risks and impacts that cyberattacks may pose to critical infrastructure.

bug bounty prize

IBR Digital Supply Chain Gap Analysis and Recommendations

The adoption of clean energy technologies, including solar photovoltaics, continues to introduce non-traditional stakeholders to the operations and planning of the electric system. Stakeholders such as manufacturers, vendors, owners, aggregators, and others are enabling the adoption, integration, and optimum operations of solar technologies at accelerated rates. Inverters form the foundation of many digitally controlled energy sources for clean energy technologies, including Solar, Battery Energy Storage Systems, Hybrid Systems, and Hydrogen Fuel Cells. Their supply chain is complex, a series of microchips, electronic switches and other components making up its primary functions. The complexity of this space and the growing digitization associated with these components can create supply chain cyber risks. One measure to mitigate cybersecurity attacks is proper digital supply chain security. The U.S. Department of Energy (DOE) Solar Energy Technologies Office (SETO), in partnership with the Cybersecurity, Energy, Security, and Emergency Response (CESER) office, is hosting a workshop to bring together solar vendors and services providers to discuss digital supply chain security for solar systems and challenges and opportunities in the transitioning to a fully domestic supply chain for solar energy in the U.S. This workshop will support the Securing Solar for the Grid (S2G) and Energy Cyber Sense program activities. During the workshop, industry experts and researchers from DOE National Laboratories will discuss the current solar supply chain landscape and the transition to domestic manufacturing of solar components in the U.S. Tools and techniques to better manage and secure the digital supply chain of solar devices and systems will be discussed.

cybersecurity

Securing Solar for the Grid (S2G)

The first slide deck provides an overview of the goals and objectives of the DOE Grid Modernization Initiative's Project entitled "Assessment and Coordination of DER Cybersecurity Standards." It covers the project's ongoing efforts to create a library of standards related to the cybersecurity of DER. The presentation will review the progress of this effort to-date and solicit feedback from participants on future directions. The second slide deck summarizes NREL's accomplishments for last three years under S2G project in a 10-12 min presentation.

clean energy

Assessment and Coordination of EVSE Cybersecurity Standards

Cybersecurity certification programs for Electric Vehicle Supply Equipment (EVSE) are fragmented due to no single certification covering all aspects of the device and additionally the existence of multiple programs and under different levels of regulation. These devices are also confronted by the intricate assembly of product software, firmware, and hardware. Devices contain both logical and physical interfaces. These multifaceted devices have vulnerabilities at many levels and interconnect with other potentially vulnerable systems including the electric vehicle, the cloud where data and payment information are stored, and the electric grid and electric grid equipment including utilities. Of the EVSE certification programs that are found, none are directly for the cybersecurity of EVSE. Many standards are for safety, specifically battery safety, some are cybersecurity standards for other types of equipment and can be modeled for EVSE. In specific, ISA/IEC 62443 is found to be significantly in line with EVSE security needs and will be used in future testing to certify EVSE and help guide the project to demonstrate where gaps exist, where strengths lie in the standard and how this can be used to lead the certification efforts in harmonizing EVSE cybersecurity standards. In addition, there are multiple efforts that are currently seeking to build EVSE standards or revise existing standards to address gaps. This effort is seeking to establish a cybersecurity program for EVSE that will inform customers and help increase the level of security across products and state EVSE procurements to achieve consistency across different jurisdictions.

33 ADVANCED PROPULSION SYSTEMS