Solar Industry Manufacturer Experience with The SD2-C2M2 Assessment Tool
This whitepaper documents the experience of three solar industry manufacturers in performing self assessments of their design and development processes using the SD2-C2M2 tool.
Engineering topics
Publications and source records attributed to Mix, Scott R..
This whitepaper documents the experience of three solar industry manufacturers in performing self assessments of their design and development processes using the SD2-C2M2 tool.
The integration of distributed energy resources (DERs) in distribution networks has become a pivotal strategy for achieving decarbonization, enhancing grid resilience, and optimizing grid efficiency. Remote monitoring and control op- erations of such resources rely on a network of sensors and communication infrastructure, exposing the system to potential cyber threats. Therefore, as the deployment of DERs increases, ensuring secure monitoring and control becomes an imperative challenge. This paper utilizes real-time feeder models, which are instrumental in developing cybersecurity testbeds tailored for hardware-in-loop (HIL) systems. These models enable users to simulate cyber attacks in a real-world environment and analyze the power distribution operations during vulnerabilities. Furthermore, we discuss several practical sets of grid parameters to identify critical levels of DERs and evaluate various scenarios that simulate cyber threats on sensitive DERs. The modified IEEE 123-bus model is used as the test case for demonstrating the proposed scenarios. The findings from this study provide valuable insights into the vulnerabilities and potential consequences of cyber attacks on DERs, allowing for better mitigation strategies and improved cyber resilience in future distribution networks.
This report describes how the Universal Utility Data Exchange (UUDEX) can encapsulate and exchange information about distributed energy resources (DER) within UUDEX-formatted JSON documents. It proposes to use the existing extensible markup language (XML) information exchange format described in IEEE Std 2030.5, IEEE Standard for Smart Energy Profile Application Protocol but not other information exchange provisions of IEEE 2030.5, rather, relying on equivalent mechanisms in UUDEX. This will allow adoption of the UUDEX exchanges with minimal changes to the structure of the information exchanged and will not require a modification to the UUDEX documentation if IEEE 2030.5 makes changes to the information models.
This report describes how the Universal Utility Data Exchange (UUDEX) can encapsulate and exchange information about distributed energy resources (DER) within UUDEX-formatted JSON documents. It proposes to use the existing extensible markup language (XML) information exchange format described in IEEE Std 2030.5, IEEE Standard for Smart Energy Profile Application Protocol but not other information exchange provisions of IEEE 2030.5, rather, relying on equivalent mechanisms in UUDEX. This will allow adoption of the UUDEX exchanges with minimal changes to the structure of the information exchanged and will not require a modification to the UUDEX documentation if IEEE 2030.5 makes changes to the information models.
This Whitepaper provides an overview and synopsis of relevant standards for Control Center, Cyber Security and Continuity of Operations for electric power utilities. It also provides suggestions and recommendations for the outline of a cybersecurity plan and a business continuity plan, and suggests training and certification opportunities for both cybersecurity and business continuity.
This design document describes protocol related aspects of Universal Utility Data Exchange (UUDEX). The focus of the design is to describe the interactions between UUDEX Clients and UUDEX Servers in the UUDEX Infrastructure. This design is purposely transport and programming language agnostic.
This document describes the security and administration features of the Universal Utility Data Exchange project.
This document provides a set of high-level functional design requirements for Universal Utility Data Exchange (UUDEX). These requirements include a set of use cases, data exchanges supported by UUDEX, both for grid operations and for cyber security data, functional requirements for data exchange, data models used by UUDEX, data exchange architectures, and security considerations. These functional design requirements are intended to be used in more detailed design documents.
This workflow design document describes the process of establishing a Universal Utility Data Exchange (UUDEX) Connection between two or more UUDEX Endpoints. The existing processes required to establish a data link using Inter Control Center Communications Protocol (ICCP) are very time consuming, from both the perspectives of effort and calendar time. The intent of UUDEX is to provide a more streamlined alternative. The UUDEX Workflow is also used to establish UUDEX Connections to exchange data other than that found in traditional ICCP data exchanges such as exchanges of power system model files, security events and mitigations, disturbance reports, and market data.
This report summarizes the data structures developed for the demonstration version of UUDEX. They serve as an initial proposal for data structures to be proposed for standardization.
This is the initial version of a reference for suppliers and energy companies of all sizes to deploy networks based on software-defined networking technology (SDN) to improve reliability, reduce cyber security attack surface, and facilitate mitigation of adversarial behavior. It is a living document and will progress over the life cycle of the Software-Defined Networking for Energy Delivery Systems (SDN4EDS) project. Version 2 of this report provides information on the Red Team tabletop assessment performed against the initial reference architecture. Version 3 of this report updates the reference architecture with lessons learned from the Red Team tabletop assessment, as well as provides additional details for the use cases. It also provides information on the decision process that could be used by an organization when considering deploying SDN in their environment. The final version of this report consolidates all the interim reports generated by the project into a final report. It also draws from PNNL’s experience in deploying SDN to make recommendations on how SDN could be deployed in a utility environment, and provides rationale for those decisions allowing individual utilities to make risk-based and knowledge-based decisions on how to best deploy SDN in their own environment
This is the initial version of a reference for suppliers and energy companies of all sizes to deploy networks based on software-defined networking technology (SDN) to improve reliability, reduce cyber security attack surface, and facilitate mitigation of adversarial behavior. It is a living document and will progress over the life cycle of the Software-Defined Networking for Energy Delivery Systems (SDN4EDS) project. Version 2 of this report provides information on the Red Team tabletop assessment performed against the initial reference architecture. Version 3 of this report updates the reference architecture with lessons learned from the Red Team tabletop assessment, as well as provides additional details for the use cases. It also provides information on the decision process that could be used by an organization when considering deploying SDN in their environment. The final version of this report consolidates all the interim reports generated by the project into a final report. It also draws from PNNL’s experience in deploying SDN to make recommendations on how SDN could be deployed in a utility environment, and provides rationale for those decisions allowing individual utilities to make risk-based and knowledge-based decisions on how to best deploy SDN in their own environment. This summary report provides a higher-level overview of the project reports. Readers interested in additional detail, including results of the Red Team assessments and the final configuration, are encouraged to read the full final report.
A critical component of the Universal Utility Data Exchange (UUDEX) approach is the integrated security contained within its processing. This document describes how that security is designed and expected to be implemented by UUDEX Implementations (U-Implementations), including the UUDEX Server (U-Server) and UUDEX Clients (U-Clients). The UUDEX security hierarchy consists of three levels: 1. The UUDEX Instance (U-Instance) itself, which sits at the top of the hierarchy and contains the U-Server, the UUDEX Identity Authority (U-Identity Authority), and the UUDEX Administrator (U-Administrator) functions; 2. A group of one or more UUDEX Participants (U-Participants) that present “organizations” that participate in the U-Instance and contains the UUDEX Administrator Participant (U-U-Administrator Participant) function; 3. A group of one or more UUDEX Endpoints (U-Endpoints) that represent the individual UUDEX Publish Clients (U-Publish Client) responsible for supplying data to the U-Instance that is consumed by UUDEX Subscriber Clients (U-Subscriber Clients). U-Endpoints can be either autonomous devices that publish and subscribe data such as data exchange servers found in supervisory control and data acquisition and energy management systems, or they can be tied to users of applications that, for example, submit DOE OE-417 disturbance reports. U-Participants and U-Endpoints can be organized into UUDEX Groups (U-Groups). Any number of U-Participants or U-Endpoints can be members of a U-Group. A given U-Participant or U-Endpoint can be a member of multiple U-Groups, but a U-Group cannot contain other U-Groups. For example, a U-Group could be created to contain all U-Participant Transmission Operators within the purview of a Reliability Coordinator, and another U-Group could be created to contain all U-Participant Generator Operators within the purview of a Reliability Coordinator. U-Participants that are both Transmission Operators and Generator Operators would be members of both U-Groups. U-Participants, U-Endpoints, and U-Groups are used in the access control structures to provide access to individual UUDEX Subjects (U-Subjects). U-Groups are created by the U-Administrator and are managed by the U-Administrator or the designated U-Group Managers. U-Endpoints can be assigned UUDEX Roles (U-Roles) that can be used to further restrict access. U-Roles are assigned to individual U-Endpoints. For example, a U-Role of “Security Analyst” could be used to restrict which U-Endpoints can publish or subscribe security incident reports and vulnerability notifications, while a U-Role of “Transmission Planner” can be used to restrict which U-Endpoints can publish power system model updates. U-Role definitions are created by the U-Administrator, but the U-Roles are assigned to U-Endpoints by their respective UUDEX Participant Administrators (U-Participant Administrator). Because all information required to make security decisions is either included within the U-Endpoint’s X.509 digital certificate or stored in a datastore on the U-Server, all security decisions are performed and enforced within the U-Server. This reduces the complexity of the U-Client code and minimizes the chance for compromise of the integrity of the UUDEX security features.