Search NASASearch

SEARCH · Search NASA

Results for “electric grid security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Clean Energy Cybersecurity Accelerator: Cohort 2 - Asimily Public Report

The U.S. Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) sponsors the Clean Energy Cybersecurity Accelerator (TM) (CECA) to expedite the deployment of emerging security technologies that address the most urgent security concerns facing modern and future electric grids. CECA Cohort 2 assessed solutions focused on hidden risks due to incomplete system visibility and device security and configuration. Improving visibility can be achieved through operational technology (OT) asset identification solutions, including capabilities like automatic discovery, vulnerability reporting, and configuration monitoring. Solutions that monitor and identify assets in information technology (IT) networks in other domains are widely used; however, there is far less adoption of monitoring solutions for operational technology environments. Wider adoption may increase with increased confidence in the ability for these solutions to understand and respond to the specific requirements of OT environments. CECA Cohort 2 evaluated the active and passive asset discovery capabilities of market-ready solutions, documented and analyzed results, and identified gaps in functionality or capabilities. This report and describes how these results can help advance the adoption of these and similar solutions in the electric sector.

24 POWER TRANSMISSION AND DISTRIBUTION

Commercialization of Pumped Storage Hydropower Technologies

Argonne National Laboratory and the National Laboratory of the Rockies were tasked by the U.S. Department of Energy’s Water Power Technology Office (WPTO) to conduct the Commercialization of Pumped Storage Hydropower Technologies study to investigate commercialization challenges faced by developers of pumped storage hydropower (PSH) projects and technologies by going beyond literature review to gather direct industry insights, lessons learned and best practices from interviews and webinars with industry specialists to create this report for PSH stakeholders and the general public. Researchers explored key challenges faced by PSH developers and innovators seeking to commercialize new technologies to improve PSH design, siting, construction, and operations. Along with highlighting challenges, the study sought to identify the best practices in developing and deploying new PSH projects and innovations. This report is designed to present insights, lessons learned, and best practices relevant to those with an interest in highlighting, informing, or advancing these PSH commercialization efforts. Along with highlighting challenges and best practices, the study sought to identify avenues by which DOE and national laboratories can help support and streamline PSH commercialization and project development processes.

13 HYDRO ENERGY

Data Centers and Digital Assurance Introduction to Supply Chain and Cybersecurity for Data Centers, Session 1

The first session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort Workshop, held on October 30, 2025, introduced foundational concepts of Digital Assurance in the context of data center and grid integration. Sponsored by the U.S. Department of Energy, the workshop brought together utilities, data center operators, developers, and vendors to address cybersecurity and supply chain vulnerabilities. The session emphasized the growing criticality of data centers within the electric grid and the need for secure, real-time, bidirectional communication. Participants explored the principles of Digital Assurance, including cybersecurity, cyber-informed engineering (CIE), and lifecycle security, and applied a threat-vulnerability-consequence framework to identify and mitigate risks at the data center–grid interface. Discussions covered a range of threats such as spoofed dispatch signals and insider threats, architectural vulnerabilities like SCADA interfaces and insecure protocols, and potential consequences including cascading grid failures. The session also raised strategic questions about business value, vendor assurance, and defining cyber boundaries and responsibilities. This foundational workshop set the stage for deeper technical analysis and the development of actionable frameworks in subsequent sessions. Session 1 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION

Overview and Commentary on Applying the Coordinated Vulnerability Disclosure Process to Photovoltaic System Devices

The rapid expansion of photovoltaic (PV) systems, particularly inverters, has introduced new cybersecurity challenges that threaten both local operations as well as the broader electrical grid’s stability. PV inverters, integrated into critical energy infrastructure are potential targets for cyber attacks due to vulnerabilities in firmware, remote access systems, and communication protocols. The Coordinated Vulnerability Disclosure (CVD) process, as defined by the Cybersecurity and Infrastructure Security Agency (CISA), provides a framework for identifying, reporting, and addressing these vulnerabilities in a transparent and collaborative manner. This report outlines the CVD process as it applies to PV systems, detailing the roles of key stakeholders, such as manufacturers, grid operators, and security researchers. The report also highlights specific challenges in managing vulnerabilities for new and legacy PV systems, which includes those introduced by insecure communications and third-party supply chain components. By adhering to the CVD process, the PV industry can mitigate cybersecurity risks, ensure regulatory compliance, and maintain consumer trust, while safeguarding the operational resilience of the energy grid. Ultimately, the effective coordination of vulnerability management is crucial for securing the future of PV systems within the critical electric grid infrastructure landscape.

14 SOLAR ENERGY

The Future of Vehicle Grid Integration: Harnessing the Flexibility of EV Charging

This document lays out a shared vision for a beneficial, EV-integrated future where EVs are safely and securely connected, reliably served, and harmonized with the electric grid. It was developed as part of the U.S. Department of Energy’s (DOE) EVGrid Assist initiative. Stakeholder input was gathered through individual and collective conversations, including eight listening sessions with more than 100 participants representing utilities of different sizes and operating structures, manufacturers of vehicles and chargers, national associations, standards organizations, Tribes, fleet managers, consumer advocates, charging network operators, community-based organizations, utility regulators, consultants, vendors, labor, and environmental justice organizations. This document focuses on the future of electric on-road U.S. transportation, specifically the integration of light-duty vehicles (LDV) and medium- and heavy-duty vehicles (MHDV) and their charging infrastructure with the electric grid. However, many of the insights here may apply to electrifying other transportation modes, as well as other distributed energy resources (DER).

EVGrid Assist initiative, EV-integrated future, el

The Future of Vehicle Grid Integration: Harnessing the Flexibility of EV Charging

This document lays out a shared vision for a beneficial, EV-integrated future where EVs are safely and securely connected, reliably served, and harmonized with the electric grid. It was developed as part of the U.S. Department of Energy’s (DOE) EVGrid Assist initiative. Stakeholder input was gathered through individual and collective conversations, including eight listening sessions with more than 100 participants representing utilities of different sizes and operating structures, manufacturers of vehicles and chargers, national associations, standards organizations, Tribes, fleet managers, consumer advocates, charging network operators, community-based organizations, utility regulators, consultants, vendors, labor, and environmental justice organizations. This document focuses on the future of electric on-road U.S. transportation, specifically the integration of light-duty vehicles (LDV) and medium- and heavy-duty vehicles (MHDV) and their charging infrastructure with the electric grid. However, many of the insights here may apply to electrifying other transportation modes, as well as other distributed energy resources (DER).

EVGrid Assist initiative, EV-integrated future, el

Securing Grid Communications Infrastructure: Addressing Gaps Beyond NERC CIP Facility Perimeters

The North American electric grid relies on a complex communications infrastructure that extends beyond facility perimeters traditionally covered by NERC Critical Infrastructure Protection (CIP) standards. While CIP requirements have significantly strengthened cybersecurity within Electronic Security Perimeters, many operational communications—such as those between control centers, substations, and third-party networks—fall outside current regulatory scope. As grid modernization introduces new technologies and connectivity models, these external pathways present evolving security challenges. This brief explores the nature of these challenges, including emerging attack vectors and supply chain considerations, and highlights how ongoing grid transformation increases exposure to sophisticated threats. It outlines practical strategies and policy options to complement existing standards, such as expanding secure communications practices, enhancing supply chain transparency, and fostering collaboration among federal, state, and industry stakeholders. Near-term actions like encryption, authentication, and contractual safeguards can help reduce risk while longer-term frameworks are developed to ensure resilient and secure grid operations.

24 - POWER TRANSMISSION AND DISTRIBUTION

From Modular ADMS to Plug-and-Play Ops: Distribution Grid Operations with Platform-Level Orchestration to Enable Ambitious App Hosting

The core function of the distribution grid is to provide electricity to consumers affordably, reliably, and securely. In pursuing these core objectives, distribution utilities are accountable to customers, regulators, and in some cases, shareholders. Other third parties such as aggregators and microgrids can also have a stake in the smooth operation of the grid. Each of these stakeholders has economic, business, and/or governance objectives that inform their expectations of the distribution grid. This multi-objective, multi-stakeholder environment creates tension that must be reconciled to successfully design and operate the distribution grid. Innovative companies are competing to bring high-tech solutions to electric utilities and their customers that address each of these objectives. Many developers of advanced distribution management systems (ADMS) and distributed energy resource management systems (DERMS) have adopted a modular architecture that allows grid operators to select functions and features according to their individual system needs. A modular platform also allows the solution provider to develop and integrate specific new product modules; however, the need to pursue multiple objectives with a fixed set of controllable devices makes integration expensive whether it is done at the product development stage or the deployment stage. This cost creates a significant barrier to adoption and can lengthen the product to market time of new solutions. To fundamentally address the complexity of system integration for distribution grid operations, the U.S. Department of Energy Office of Electricity has funded the GridAPPS-D project at PNNL, which streamlines integration by contributing to standards development, defining system architecture, applying advanced mathematics, and developing open-source software to demonstrate the concept of an open data-integration platform for distribution operations. The open data-integration platform concept enables system operators and solution providers to deploy ambitious, best-of-breed applications (or apps) without continually reengineering for integration. Ambitious apps developed by different solution providers will inevitably attempt to achieve different control objectives with the same set of controllable devices. If the open platform itself can resolve these conflicts in a way that achieves the best available outcomes for all apps, doesn’t restrict the ambitious design of apps, and ensures safe and secure operations, apps will be able to plug-and-play with the platform at the same time as other ambitious apps. In this paper, we describe a framework called App Deconfliction that empowers a platform to assign setpoints to controllable devices based on the values preferred by different apps (and even external stakeholder entities like customers or aggregators). The App Deconfliction framework is compatible with several methods for determining setpoint values. We present two methods based on game theory that provide a subtle built-in incentive structure for developers to adapt their apps to the fact that they will be operating in a moderated multi-app environment and to favor device setpoints that have the most effect on their objectives over those that have the least effect. Our simulation-based demonstrations have shown that game-theory-based deconfliction can lead to a 7% improvement in control space utilization compared to design-based methods.

24 POWER TRANSMISSION AND DISTRIBUTION

Battery Storage Unlocked: Lessons Learned From Emerging Economies

The Clean Energy Ministerial (CEM) is a global forum that promotes policies and programs that advance clean energy technology. The CEM's mission is to bring together a community of global leaders to scale clean energy, amplifying the impact to all the sectors of the economy and applying a whole-of-society approach to meet collective climate and clean energy goals. At COP28 in Dubai, United Arab Emirates, the CEM announced the Supercharging Battery Storage Initiative as a vehicle to accelerate battery storage deployment around the world. The initiative supports countries around the world in co-creating strategies that enhance policy, regulation, supply chain, manufacturing, and financing solutions for battery energy storage deployment. Additionally, the initiative seeks to reduce the cost of the technology and promote diversified, sustainable, and secure supply chains (CEM n.d.). Through international collaboration, the initiative supports the integration of renewable energy globally, while securing the stability and reliability of the electricity grid.

batteries

DEReliction: A Cybersecurity Vulnerability Assessment Methodology for Distributed Energy Resources

With the increasing integration of Distributed Energy Resources (DER) into the electric grid, maintaining grid reliability and resilience requires that these devices remain secure. This paper discusses a cybersecurity vulnerability assessment methodology that incorporates best practices from Sandia National Laboratories, SANS Institute, OWASP Foundation, and other web and Internet of Things (IoT) penetration testing (“pen testing”) programs, courses, and frameworks for assessing the security posture of devices. The methodology involves five sequential steps: (1) Collect Public Information, (2) Extract Hardware Details, (3) Inventory Software Components, (4) Identify Vulnerabilities, and (5) Test Vulnerabilities. Each step uncovers potential weaknesses in both hardware and software components of DER devices, considering adversary tactics, techniques, and procedures (TTPs), and potential attack vectors along the way. The results from the execution of this method on multiple residential- and small commercial-scale photovoltaic (PV) inverters reveled hardware and software vulnerabilities, which highlight the benefit of taking a methodical approach to discover vulnerabilities. While the specific vulnerability details are not shared here, a generalized overview of findings underscore the importance of robust security assessments for DER devices. Adoption of an assessment framework of this kind will identify and mitigate cybersecurity threats and bolster the resilience of DER-integrated electric grids.

24 POWER TRANSMISSION AND DISTRIBUTION

Security constrained optimal power shutoff for wildfire risk mitigation

Abstract Electric grid faults are increasingly the source of ignition for major wildfires. To reduce the likelihood of such ignitions in high risk situations, utilities use preemptive de‐energization of power lines, commonly referred to as Public Safety Power Shutoffs (PSPS). Besides raising challenging trade‐offs between power outages and wildfire safety, PSPS removes redundancy from the network at a time when component faults are likely to happen. This may leave the network particularly vulnerable to unexpected line faults that may occur while the PSPS is in place. Previous works have not explicitly considered the impacts of these outages. To address this gap, the Security Constrained Optimal Power Shutoff problem is proposed which uses post‐contingency security constraints to model the impact of unexpected line faults when planning a PSPS. This model enables, for the first time, the exploration of a wide range of trade‐offs between both wildfire risk and pre‐ and post‐contingency load shedding when designing PSPS plans, providing useful insights for utilities and policy makers considering different approaches to PSPS. The efficacy of the model is demonstrated using the EPRI 39‐bus system as a case study. The results highlight the potential risks of not considering security constraints when planning PSPS and show that incorporating security constraints into the PSPS design process improves the resilience of current PSPS plans.

29 ENERGY PLANNING, POLICY, AND ECONOMY

Surface modification of cathode material enhances electrochemical performance in dry-processed Li-ion battery electrodes

The transition to electric vehicles (EVs) is pivotal for achieving energy security and integrating grid stability, with lithium-ion batteries (LIBs) playing a central role in this transformation. However, the conventional wet electrode manufacturing relying on N-methyl-2-pyrrolidone (NMP) solvent is energy intensive and costly. Dry processing (DP) has emerged as a promising alternative, eliminating solvents and using polytetrafluoroethylene (PTFE) binder for electrode fabrications. Despite its advantages, DP faces a critical challenge: poor interfacial adhesion between the hydrophobic PTFE binder and the hydrophilic cathode active material (CAM), particularly LiNi 0.8 Mn 0.1 Co 0.1 O 2 (NMC811), which undermines electrode performance. Here, to address this, we introduced a novel vapor-phase trimethoxymethylsilane (TMMS) coating to hydrophobize the CAM surface, enhancing compatibility with PTFE. This surface modification significantly enhances binder – CAM interactions, enabling uniform mixing and robust electrode integrity without damaging the CAM particles. Our findings advance the feasibility of environmentally sustainable and cost-effective dry processing, representing a significant step toward sustainable battery manufacturing.

Choi, Junbin [Oak Ridge National Laboratory (ORNL)

Human-Centered and Explainable Artificial Intelligence in Nuclear Operations

Nuclear power plants in the United States are critical to the nation’s energy security, accounting for 20% of all electricity produced for the power grid. As energy needs grow, 100 gigawatts of additional nuclear power will be necessary by 2050, more than double the current capacity. Realizing this target requires cutting-edge technology like artificial intelligence (AI) and machine learning (ML) that can bring about significant increases in the level of automation. Human-centered AI (HCAI) is a combination of human-centered design (human factors, human-in-the-loop, etc.) with AI/ML to help produce an efficient and reliable system with full consideration for human engagement. This paper provides a comprehensive and novel discussion of HCAI considerations in nuclear power, introducing unique applications for the existing fleet as well as new advanced reactor designs. We include real-life use cases of AI applications to work management processes at nuclear power sites and highlight lessons learned for HCAI.

Hall, Anna

A Blockchain and PKI-Based Secure Vehicle-to-Vehicle Energy-Trading Protocol

With the increasing awareness for sustainable future and green energy, the demand for electric vehicles (EVs) is growing rapidly, thus placing immense pressure on the energy grid. To alleviate this, local trading between EVs should be encouraged. In this paper, we propose a blockchain and public key infrastructure (PKI)-based secure vehicle-to-vehicle (V2V) energy-trading protocol. A permissioned blockchain utilizing the proof of authority (PoA) consensus and smart contracts is used to securely store data. Encrypted communication is ensured through transport layer security (TLS), with PKI managing the necessary digital certificates and keys. A multi-leader, multi-follower Stackelberg game-based trade algorithm is formulated to determine the optimal energy demands, supplies, and prices. Finally, we propose a detailed communication protocol that ties all the components together, enabling smooth interaction between them. Key findings, such as system behavior and performance, scalability of the trade algorithm and the blockchain, smart contract execution costs, etc., are presented through numerical results by implementing and simulating the protocol in various scenarios. This work not only enhances local energy trading among EVs, encouraging efficient energy usage and reducing burden on the power grid, but also paves a way for future research in sustainable energy management.

Stackelberg game

A census of fish passage facilities at US hydropower developments across the conterminous United States

Hydropower provides reliable and secure electricity and contributes significantly to the flexibility and stability of the US electricity grid. Hydropower dams generally are aquatic barriers and hazards to migratory fish in rivers. Fish passage facilities mitigate risks from hydropower to migratory fish, but information on these facilities is incomplete for the conterminous United States (CONUS). Here, we present the first CONUS-scale dataset of fish passage facilities at US hydropower developments in over 30 years. The existence of fish passage facilities (presence or absence) was specified for 1909 hydropower features, 390 of which had at least one facility. Most features had a single passage facility that provided passage in only one direction, with downstream being more common than upstream passage. Bypasses and ladders accounted for 60 % of the fish passage facility types. While we documented 659 fish passage facilities across CONUS, facilities were most common in the New England, Pacific Northwest, Mid-Atlantic, and Great Lakes regions. In general, fish passage facilities were more common at features that were closer to the ocean, at lower elevations, and at shorter dams, but not related to installed electrical generation capacity. Hydrologic sub-basins containing salmonids also contained the largest number of hydropower features, but the proportion of features with passage was generally higher in sub-basins containing multiple migratory taxa. This census provides valuable information on existing fish passage mitigation and is a benchmark to gauge progress toward a modernized hydropower fleet that provides affordable, reliable energy while protecting fishery resources and river ecosystems.

13 HYDRO ENERGY

Fast-Tracking Technology Solutions to Boost Cybersecurity in Virtual Power Plant and Aggregator Operations

This presentation was presented at the Aggregation and Grid Security Workshop - held on June 17-18, 2025, at NREL in Golden, Colorado. The goal of the two-day workshop was to address the critical cybersecurity challenges for the future electric grid. This presentation overviews NREL's work in evaluating cybersecurity technology solutions for virtual power plant and aggregator operations.

24 POWER TRANSMISSION AND DISTRIBUTION

Standards Library for Distributed Energy Resources

This presentation was presented at the Aggregation and Grid Security Workshop - held on June 17-18, 2025, at NREL in Golden, Colorado. The goal of the two-day workshop was to address the critical cybersecurity challenges for the future electric grid. This presentation overviews the evolution and need for harmonized distributed energy resource standards and a new distributed energy resource standards library.

29 ENERGY PLANNING, POLICY, AND ECONOMY

TrustDER: Trusted, Private and Scalable Coordination of Distributed Energy Resources

In this project, the Stanford and SLAC Teams have developed a Trusted, Private and Scalable platform for coordinating Coordination of Distributed Energy Resources (TrustDER). This is a layered system that ensures private, trusted and scalable coordination and monitoring of DERs. It accommodates a variety of resources, such as solar generation, gensets and loads, with a particular focus on battery systems-based resources, as they are a transformational technology experiencing fast growth in adoption by large critical facilities. The platform can be used as standalone or added to existing aggregation systems to enable trust, privacy and resilience. TrustDER consists of layers that address each of the shortcomings of the existing state of the art. Each layer in the platform can operate independently but provides information to the layers above it to enable a novel form of overall coordination architecture. The project consists of several tasks, with each task dedicated to the design of each layer. Task 2 Resource Virtualization defined a software abstraction layer for distributed energy resources (DERs). The goal of this abstraction was to simplify the implementation of algorithms utilizing cooperation of DERs resources in a variety of use cases. Task 3 is on Secure ID for Asset Authentication. Identity Management Systems (IDMS) are a foundational infrastructure for interactions between entities (organizations, users, devices, and services). Secure ID is blockchain-based a distributed identity management system allowing (1) identity provisioning, (2) authentication, (3) authorization, and (4) identity data sharing for IoT-enabled assets on the electricity grid. In this project, the SLAC team focused on designing and testing Keymaker, a protocol for authenticating device identity managed by Secure ID. Task 5 Private and Safe Integration is focused on the design and evaluation of a DER cooperation scheme which allows for the aggregation of DERs without impacting network reliability. The approach is designed based on realistic assumptions regarding data availability, communication infrastructure limitations, and privacy. Task 6 Scalable Distributed Privacy for Information explored how virtualized batteries could be managed privately. Specifically, it examined the case in which a principal provides a partitioned battery to multiple clients. Task 7 Use Cases was to ensure that this technology was applied in relevant situations and scenarios. Primarily, this means that virtualization needed to be employed in a manner that either improved flexibility, bolstered security or privacy, or decreased costs.

25 ENERGY STORAGE