Search NASA⌕ Search

Engineering topics

Lawrence, Jeremy

Publications and source records attributed to Lawrence, Jeremy.

Blockchain Research and Development Activities Sponsored by the U.S. Department of Energy and Utility Sector

This article provides an in-depth analysis of blockchain research in the energy sector, focusing on projects funded by the U.S. Department of Energy (DOE) and comparing them with industry-funded initiatives. A total of 110 funded activities within the U.S. power industry were successfully tracked and mapped into a newly developed categorization framework. This framework is designed to help research agencies to systematically understand their funded portfolio. Such characterization is expected to help them make effective investments, identify research gaps, measure impact, and advance technological progress to meet national goals. In line with this need, the proposed framework proposes a 2-D categorization matrix to systematically classify blockchain efforts within the energy sector.Under the proposed framework, the Energy System Domain serves as the primary classification dimension, categorizing use cases into 30 distinct applications. The second dimension, Blockchain Properties, captures the specific needs and functionalities provided by Blockchain technology. The aim was to capture blockchain’s applicability and functionality: where and why blockchain? Principles behind the selection of the viewpoint dimensions were carefully defined based on consensus obtained through the Blockchain for Optimized Security and Energy Management (BLOSEM) project. The mapped results show that activities within the Grid Automation, Coordination, and Control (31.8%), Marketplaces and Trading (25.5%), Foundational Blockchain Research (19.1%), and Supply Chain Management (17.3%) domains have been actively pursued to date. The three leading specific use case applications were identified as Transactive Energy Management for Marketplaces and Trading, Asset Management for Supply Chain Management, and Fundamental Blockchain for Foundational Blockchain Research. The Marketplaces and Trading and Retail Services Enablement domains stood out as being favored by industry by a factor greater than 2 (2.3 and 2.6, respectively), yet there seemed to be little to zero investment from DOE. Approximately 76% of the total projects prioritized Immutability, Identity Management, and Decentralization and/or Disintermediation compared to Asset Digitization and/or Tokenization, Automation, and Privacy and/or Anonymity. The greatest discrepancies between DOE and industry were in Asset Digitization and/or Tokenization and Automation. The industry efforts (36% in Asset Digitization/Tokenization and 22% in Automation) was 14 times and 2.4 times, respectively, more intensive than the DOE-sponsored efforts, indicating a significant discrepancy in industry versus government priorities. Overall, quantifying DOE-sponsored projects and industry activities through mapping provides clarity on portfolio investments and opportunities for future research.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Quantum Key Distribution for Critical Infrastructures: Towards Cyber-Physical Security for Hydropower and Dams

Hydropower facilities are often remotely monitored or controlled from a centralized remote control room. Additionally, major component manufacturers monitor the performance of installed components, increasingly via public communication infrastructures. While these communications enable efficiencies and increased reliability, they also expand the cyber-attack surface. Communications may use the internet to remote control a facility’s control systems, or it may involve sending control commands over a network from a control room to a machine. The content could be encrypted and decrypted using a public key to protect the communicated information. These cryptographic encoding and decoding schemes become vulnerable as more advances are made in computer technologies, such as quantum computing. In contrast, quantum key distribution (QKD) and other quantum cryptographic protocols are not based upon a computational problem, and offer an alternative to symmetric cryptography in some scenarios. Although the underlying mechanism of quantum cryptogrpahic protocols such as QKD ensure that any attempt by an adversary to observe the quantum part of the protocol will result in a detectable signature as an increased error rate, potentially even preventing key generation, it serves as a warning for further investigation. In QKD, when the error rate is low enough and enough photons have been detected, a shared private key can be generated known only to the sender and receiver. We describe how this novel technology and its several modalities could benefit the critical infrastructures of dams or hydropower facilities. The presented discussions may be viewed as a precursor to a quantum cybersecurity roadmap for the identification of relevant threats and mitigation.

97 MATHEMATICS AND COMPUTING↗

Fossil Power Plant Cyber Security Life-Cycle Risk Reduction, A Practical Framework for Implementation

Market conditions are forcing fossil electricity generation facility owners and operators to implement advanced digital technologies. These technologies enable efficiencies, operational flexibility, operations and maintenance efficiencies, and adapting to a transitioning workforce. These digital technologies, however, can increase the cybersecurity attack surface. The purpose of this research was to develop a holistic cybersecurity risk reduction framework for fossil generation facilities. The framework begins with assessing how cyber risk changes across facility life cycles, including plant, system, vendor, and business life cycles. The next phase performs consequence analysis to prioritize high consequence events. Focusing on high consequence events allows owners to use a graded, risk-informed approach to prioritize cybersecurity efforts. The final phase identifies the digital asset attack surface in sensors and instrumentation and control equipment. After the vulnerabilities are identified, the owner selects mitigating cybersecurity control measures (or countermeasures) based on the risk analysis from the previous phases. This report describes the current industry cybersecurity best practices in fossil generation that are based on the first principles for cybersecurity engineering. The report is divided into five sections that describe the implementation of the risk reduction framework and present identified research, methodological, and technology gaps that were identified through this course of research and development.

01 COAL, LIGNITE, AND PEAT↗

Fossil Power Plant Cyber Security Life-Cycle Risk Reduction: A Practical Framework for Implementation

Market conditions are forcing fossil electricity generation facility owners and operators to implement advanced digital technologies. These technologies enable efficiencies, operational flexibility, operations and maintenance efficiencies, and adapting to a transitioning workforce. These digital technologies, however, can increase the cybersecurity attack surface. The purpose of this research was to develop a holistic cybersecurity risk reduction framework for fossil generation facilities. The framework begins with assessing how cyber risk changes across facility life cycles, including plant, system, vendor, and business life cycles. The next phase performs consequence analysis to prioritize high consequence events. Focusing on high consequence events allows owners to use a graded, risk-informed approach to prioritize cybersecurity efforts. The final phase identifies the digital asset attack surface in sensors and instrumentation and control equipment. After the vulnerabilities are identified, the owner selects mitigating cybersecurity control measures (or countermeasures) based on the risk analysis from the previous phases. This report describes the current industry cybersecurity best practices in fossil generation that are based on the first principles for cybersecurity engineering. The report is divided into five sections that describe the implementation of the risk reduction framework and present identified research, methodological, and technology gaps that were identified through this course of research and development.

20 FOSSIL-FUELED POWER PLANTS↗

Fossil Power Plant Cyber Security Life-Cycle Risk Reduction: A Practical Framework for Implementation

Market conditions are forcing fossil electricity generation facility owners and operators to implement advanced digital technologies. These technologies enable efficiencies, operational flexibility, operations and maintenance efficiencies, and adapting to a transitioning workforce. These digital technologies, however, can increase the cybersecurity attack surface. The purpose of this research was to develop a holistic cybersecurity risk reduction framework for fossil generation facilities. The framework begins with assessing how cyber risk changes across facility life cycles, including plant, system, vendor, and business life cycles. The next phase performs consequence analysis to prioritize high consequence events. Focusing on high consequence events allows owners to use a graded, risk-informed approach to prioritize cybersecurity efforts. The final phase identifies the digital asset attack surface in sensors and instrumentation and control equipment. After the vulnerabilities are identified, the owner selects mitigating cybersecurity control measures (or countermeasures) based on the risk analysis from the previous phases. This report describes the current industry cybersecurity best practices in fossil generation that are based on the first principles for cybersecurity engineering. The report is divided into five sections that describe the implementation of the risk reduction framework and present identified research, methodological, and technology gaps that were identified through this course of research and development.

20 FOSSIL-FUELED POWER PLANTS↗