Cyber Resilient Design Framework for Hybrid Energy Systems
This report is a summary of the cyber-resilient design framework for hybrid renewable energy systems, for the Renewable Energy and Storage Cybersecurity (RESCue) research project.
Engineering topics
Publications and source records attributed to Culler, Megan.
This report is a summary of the cyber-resilient design framework for hybrid renewable energy systems, for the Renewable Energy and Storage Cybersecurity (RESCue) research project.
As the nuclear industry develops new advanced reactor technologies, many companies are embracing this advancement by pursuing the development of microreactors. The term microreactor generally refers to a nuclear reactor with an operating power of 20 MW(thermal) or less. The power range of microreactors makes them appealing for many use cases, such as powering remote communities, mining sites, and military bases. Most of the microreactor designs being pursued are expected to incorporate remote facility operations into the final product. However, no framework has yet been developed to determine what remote operations systems require for reliable, resilient, and secure operation of a microreactor. Here, this work identifies the research needs for challenges that are unique to remote operations and monitoring for microreactors, specifically regarding instrumentation and control, communication methods, regulatory requirements, and operational policies. The types of commands and sensor measurements that must be transmitted between the facilities, as well as methods for verifying the trustworthiness of these signals, are assessed. This work evaluates the security, reliability, and performance requirements that must be met when considering the selection of communication hardware and protocols for use in remote operations. Also, an assessment was performed to study how remote operations fit within current regulatory requirements and what may need to be updated in regulatory policy to allow for remote operation. Finally, the operational contingencies unique to remote operations that must be in place for responses to abnormal events are identified. This paper identifies the challenges and research opportunities within the areas of importance for the design of remote operation systems.
Not Available
For individuals, businesses, and communities focused on building resilient electrical grid infrastructure, wind energy can provide an affordable, accessible, and compatible distributed energy resource option that also enhances the capabilities of local grid operations. The Microgrids, Infrastructure Resilience, and Advanced Controls Launchpad (MIRACL) project is a multi-year distributed wind research effort, driven through a partnership between four Department of Energy National Laboratories and industry to develop and improve the planning, design, and operation of wind-centered microgrids to complement solar, energy storage, and other distributed energy resources for grid-tied and isolated operation (U.S. Department of Energy, 2021). This report documents the application of methods developed through the initial three years of the MIRACL project to two real-world distributed wind reference systems. Specifically, the methods demonstrated in this report include 1) a market valuation framework to comprehensively value the services distributed wind can provide and 2) a resilience framework that enables stakeholders to characterize distribution system resilience and compare grid investment decisions from a resilience perspective. Additional methods mentioned in this report include distributed hybrid system design methods for grid resilience, advanced control co-simulation platforms, and power hardware-in-the-loop (PHIL) models. Preliminary results from these additional methods are presented in this report and will be demonstrated and/or applied to the reference systems in the coming year. The purpose of applying these methods to reference systems is to drive technology transfer of the theories, methodologies, and technologies developed under the MIRACL project and increase the number of referenceable case studies available to stakeholders interested in additional value-added capabilities of wind systems beyond bulk energy supply (i.e. kilowatt-hours).
The share of renewable and distributed energy resources (DERs), like wind turbines, solar photovoltaics and grid-connected batteries, interconnected to the electric grid is rapidly increasing due to reduced costs, rising efficiency, and regulatory requirements aimed at incentivizing a lower-carbon electricity system. These distributed energy resources differ from traditional generation in many ways including the use of many smaller devices connected primarily (but not exclusively) to the distribution network, rather than few larger devices connected to the transmission network. DERs being installed today often include modern communication hardware like cellular modems and WiFi connectivity and, in addition, the inverters used to connect these resources to the grid are gaining increasingly complex capabilities, like providing voltage and frequency support or supporting microgrids. To perform these new functions safely, communications to the device and more complex controls are required. The distributed nature of DER devices combined with their network connectivity and complex controls interfaces present a larger potential attack surface for adversaries looking to create instability in power systems. To address this area of concern, the steps of a cyberattack on DERs have been studied, including the security of industrial protocols, the misuse of the DER interface, and the physical impacts. These different steps have not previously been tied together in practice and not specifically studied for grid-connected storage devices. In this work, we focus on grid-connected batteries. We explore the potential impacts of a cyberattack on a battery to power system stability, to the battery hardware, and on economics for various stakeholders. We then use real hardware to demonstrate end-to-end attack paths exist when security features are disabled or misconfigured. Our experimental focus is on control interface security and protocol security, with the initial assumption that an adversary has gained access to the network to which the device is connected. We provide real examples of the effectiveness of certain defenses. This work can be used to help utilities and other grid-connected battery owners and operators evaluate the severity of different threats and the effectiveness of defense strategies so they can effectively deploy and protect grid-connected storage devices.
The IEEE 1547 standard addresses the integration of Distributed Energy Resources (DER) into Area Electric Power Systems (AEPS). The updated standard, released in 2018 with revisions ongoing, specifies the need for more flexible settings, requiring the DER to remain connected during certain disturbances and provide voltage support via active and reactive power modes. With these increased capabilities comes increased risks, and our analysis of the standard has produced potential settings combinations, which, while allowable under the standard, may actually create instability. This contradicts the main purpose of the revised standard. Since the DER must support a communication interface through which the AEPS operator can change settings, adversarial mode changes are possible via a cyberattack. This concern is heightened as DER penetration increases, where under a reasonable threat model, an attacker could affect multiple DER simultaneously. We have conducted a simulation analysis of potentially adverse combinations of mode change and ridethrough parameters on a hypothetical AEPS with varying degrees of DER penetration. We conclude that certain adverse mode changes, whether through error or cyberattack, can lead to unstable conditions with DER penetrations as low as 24% of the AEPS system capacity.