Search NASA⌕ Search

SEARCH · Search NASA

Results for “Cybersecurity for Renewables”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Renewable Energy and Storage Cybersecurity Research (RESCue) Pilot Final Report

The Renewable Energy and Storage Cybersecurity Research (RESCue) project is a collaborative effort aimed at securing the rapidly growing deployment of distributed energy resources (DERs) and transmission-connected hybrid renewable energy systems against escalating cyber threats. This project brings together major original equipment manufacturers (OEMs) of wind, solar, and energy storage, along with major asset owners and DOE National Laboratories, to collectively identify cyber threats, assess risks, and develop robust cybersecurity strategies and solutions. This publication the final report for the first year of the project.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Securing Future Energy Supplies: From Renewables to Microreactors

This session will provide insight into how future energy deployments, critical to national-level programs focused on reducing carbon emissions, can be secured-by-design using lessons learned from current energy infrastructure. It will begin with an overview of current threats and risks associated with renewable energy assets and systems, primarily wind and solar, focusing on their control architecture and key system functions for both efficient and safe operations. This talk will then translate the key takeaways from current renewable infrastructure into applications for securing future energy systems, including microreactors and small modular reactors (SMRs), based on planned concepts of operations and control. Microreactors and SMRs are intended to be factory-assembled with commercially available components and deployed in more remote or distributed environments, necessitating centralized control centers, remote monitoring, and offsite maintenance and technical support. All of these factors lead these assets to a security posture and controls more similar to today's renewable energy assets than today's nuclear reactors, which represents a significant shift in mindset for the nuclear industry. This talk will provide justification for this shift as well as a path forward to motivate securing these groundbreaking technologies from the outset of their design and deployment.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

DER Cybersecurity R&D

The National Renewable Energy Laboratory (NREL) conducted more than 30 assessments for utilities across the United States with a cybersecurity assessment tool based on the U.S. Department of Energy (DOE) Cybersecurity Capability Maturity Model (C2M2) and the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) and focused on business process. With funding from the DOE Office of Renewable Energy and Energy Efficiency Federal Energy Management Program, NREL modified the current cyber governance assessment tool to include an assessment process specifically for distributed energy resources (DERs). The Distributed Energy Resources Cybersecurity Framework (DER-CF) was developed to help federal agencies mitigate gaps in their cybersecurity posture for distributed energy systems.

cybersecurity valuation↗

Cyber100 Compass: Quantification of Cybersecurity Risks for Systems Transitioning to High Levels of Renewables (Final Report)

The shift to high levels of renewable deployment will entail a significant re-engineering of the grid. As investors, utilities, customers, and others prepare for clean energy transitions, there is need to understand how restructuring the grid to accommodate renewables will change the attack surface of the grid and accompanying cyber risk. However, today the cyber-physical risks associated with electric grids incorporating high levels of renewable deployment remain largely unknown. The Cyber100 Compass proof-of-concept application attempts to quantify future cyber-physical security risks by combining risk data gathered from subject matter experts (SMEs) with input from system planners about conditions they expect to be true about their electric systems in the future. Users provide data about their organization’s tolerance for risk; the value they place on avoiding the consequences of different cyber events; and conditions that they expect to be true on their systems at some point in the future. The SMEs provide baseline probabilities for different cyber events; the probability that an event will be low-, moderate-, or high-impact; and the amount by which user-identified conditions on their systems will change the likelihood of the cyber events. The application takes both the user and SME input and performs a series of Monte Carlo simulations to arrive at a quantification of risk.

24 POWER TRANSMISSION AND DISTRIBUTION↗

RESCue Model (RESCue Experiment and Model) [SWR-24-84]

The Renewable Energy and Storage Cybersecurity Research (RESCue) project is a collaborative effort aimed at securing the rapidly growing deployment of transmission-connected hybrid renewable energy systems, consisting of a combination of wind, solar, and/or energy storage equipment, against escalating cyber threats. This project brings together major original equipment manufacturers (OEMs) of wind, solar, and energy storage, along with major asset owners and DOE National Laboratories, to collectively identify cyber threats, assess risks, and develop robust cybersecurity strategies and solutions. The development of hybrid reference architectures has provided comprehensive blueprints for the secure design and integration of hybrid renewable energy systems, accounting for their unique characteristics and interdependencies. Additionally, NREL has created a cyber-resilient design framework that integrates cybersecurity considerations from the start of the system lifecycle, ensuring security is "baked in" from the initial design phase. The research thrusts for the project included (i) development of hybrid reference architectures and (ii) a cyber-resilient design framework for hybrid energy systems. The reference architectures has provided comprehensive blueprints for the secure design and integration of hybrid renewable energy systems, accounting for their unique characteristics and interdependencies. Additionally, NREL has created a cyber-resilient design framework that integrates cybersecurity considerations from the start of the system lifecycle, ensuring security is "baked in" from the initial design phase. A demonstration experiment was developed for one of the architectures using NREL's Cyber Range resources. This experiment configuration, deployable using open-source tools, is provided here in this repository. Additional models were developed for the wind and solar architectures as well, however the configurations for only the Energy Storage scenario are provided here: https://www.nrel.gov/docs/fy24osti/89921.pdf

Hasandka, Adarsh↗

Distributed Energy Resource Visual Emulator: Phase 1

To help federal energy managers assess, monitor, and manage cybersecurity while achieving decarbonization, the National Renewable Energy Laboratory's Distributed Energy Resource Cybersecurity Framework (DER-CF) offers a comprehensive, web-based assessment tool focusing on cyber governance or policies, technical management, and physical security. The DER-CF currently presents users with a series of pertinent cybersecurity questions, which are used to generate a site-specific report and recommendations. This paper outlines a technical approach to integrate the DER-CF with another key asset—NREL's Advanced Research on Integrated Energy Systems (ARIES) Cyber Range—to visualize cybersecurity resilience and compliance and to enhance the usability and accessibility of the DER-CF. The result is a new tool called the Distributed Energy Resource Visual Emulator (DER-VE). Its development will include regular conversations with stakeholders to assess the effectiveness of these efforts, refine the visualization capability, and ensure its value to our partners. Phase 0 of the integration project was concluded in 2021. Phase 1, completed in 2022, has two components: The first is developing a working visualization of system compliance using the DER-CF, and the second is planning the design of a server application that takes input data from the DER-CF and creates a personal emulated environment of the user's system or a selected reference architect. Major components that were addressed in this phase are the DER-CF output, compliance visualization, data model, and compliance server design.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber SHIELD Flyers

Fliers and introductory program power point documents. The goal of these documents are to provide renewable owner/operators with information about DOE funded programs being led by INL. Fliers and intro ppt's describe why renewable owner/operators should consider using INL programs under these projects. Cyber SHIELD - SOLAR Cyber SHIELD -WIND Cyber SHIELD - HYDRO

14 SOLAR ENERGY↗

International Cybersecurity: Capabilities and Overview [Slides]

Innovations in clean energy technology are beginning to transform electric grids around the world. It is more important than ever to understand and improve the resiliency and security of the grid against natural and human disruptions as our energy systems become more distributed, intelligent, and interconnected. Through its advanced cybersecurity technical assistance portfolio, experts at the National Renewable Energy Laboratory (NREL) work with international governments to support secure and resilient deployment of renewable energy assets and address grid interconnection challenges. Cybersecurity technical assistance is tailored to the needs of our international partners.

24 POWER TRANSMISSION AND DISTRIBUTION↗

OT Operational Anomaly Detection (OAD) T&D + DER

The growth of utility-scale renewable energy resources, distributed energy resources (DER), and transportation electrification has increased uncertainty and cybersecurity risks in power grids. The Purdue Enterprise Reference Architecture model which is widely adopted by the utility industry is now insufficient to protect the power grid against cyber-attacks. There is a need to identify what cybersecurity model is effective on Energy Management System (EMS), Advanced Distribution Management System (ADMS), and DER Management System (DERMS) to address the fundamental cybersecurity challenges in the age of increasing renewable energy and DER share as well as consumer participation in the electric energy industry. The next generation of cybersecurity model for OT network should be able to detect inside attackers, mitigate the cybersecurity risks arising from the new grid participants including DER aggregators, electric vehicle owners, and behind-the-meter consumers outside the utility company, and develop the strategy to trust consumer measurement data. This panel will discuss the challenges and pathways for the development of an ensemble cybersecurity model based on predictive state estimation to detect cybersecurity anomalies in OT network including EMS, ADMS, and DERMS.

cybersecurity↗

Cybersecurity Value-at-Risk Framework

As more variable renewable energy sources are added to the grid, the role of hydropower as a reliable baseline and firming resource is growing more critical. However, the U.S hydropower fleet is not fully prepared to face modern issues such as cybersecurity threats. Hydropower accounts for 37% of U.S. utility-scale renewable electricity but is challenged by diverse infrastructure and legacy devices that predate modern security practices. While new cybersecurity solutions cannot simply be added to current hydropower generation and operation technologies, custom cybersecurity assessments can reveal system-specific threats and risk probabilities and identify mitigating enhancements.

cybersecurity valuation methodology↗

Cyber100 Compass [SWR 23-64]

Cyber100 Compass ("Compass") is a unique risk assessment framework that will enable grid system planners to understand and mitigate cybersecurity risk for grids transitioning to high levels of renewable generation, including 100%. The idea for Compass was developed by NREL based on past work on high-renewable grids and a series of discussions with DOE. Compass is part of Cyber100, a portfolio of proposed research activities that would greatly expand understanding of cybersecurity for high-renewable grids. Compass is a desktop application designed with a user-friendly interface. The tool gathers information from users, conducts probabilistic backend calculations, and outputs a series of visualizations to help users understand and analyze their cybersecurity risks based on the unique features of their future grid. Compass will take as inputs the values for different conditions and produce a risk score of the resulting grid. By trying different configurations, system planners can compare the resultant risks against their own risk tolerance and decide which system-of-system controls to implement as they transition toward a 100% renewable grid.

Martin, Maurice↗

CyberStrike STORMCLOUD

This presentation will be shared at the "Securing Solar for the Grid (S2G)" workshop at RE+ 2023. It provides an overview of the work INL and Sandia have done to develop CyberStrike STORMCLOUD, a training program was designed to enhance the ability of renewable energy and operators to prepare for a cyber incident impacting industrial control systems with specific considerations of the architectures and limitations of renewable energy.

14 SOLAR ENERGY↗

Cybersecurity Value-at-Risk Framework: Preprint

As more variable renewable energy sources are added to the grid, the critical role of hydropower as a reliable baseline and firming resource is rapidly growing. However, the U.S hydropower fleet is not fully prepared to face modern issues such as cybersecurity threats. Hydropower accounts for 37% of U.S. utility-scale renewable electricity but is challenged by diverse infrastructure and legacy devices that predate modern security practices. While new cybersecurity solutions cannot simply be added to current hydropower generation and operation technologies, custom cybersecurity assessments can reveal system-specific threats and risk probabilities and identify mitigating enhancements.

cybersecurity valuation↗

Cyber100 Compass User Guide

This document provides an overview of the Cyber100 Compass tool and serves as a guide to users interested in understanding the cybersecurity risks facing their clean energy transition. The National Renewable Energy Laboratory (NREL) developed the Cyber100 Compass tool for cyber risk assessment at the system-of-systems level for system planners trying to reach high levels of renewables. Two offices of the U.S. Department of Energy (DOE) - the Office of Electricity and the Office of Cybersecurity, Energy Security, and Emergency Response-funded NREL to develop this framework that will enable grid system planners to understand and mitigate cybersecurity risk for grids transitioning to high levels of renewable generation, including 100%. Cyber100 Compass can help systems planners apply the principle of security-by-design at scale. Investing in an upfront understanding of system-of-systems (where the constituent systems are operating entities of the different renewable resources) risks from high-renewable grids will result in a more resilient grid at a lower long-term cost.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cybersecurity Assessment for a Behind-the-Meter Solar PV System: A Use Case for the DER-CF

The world's energy production is shifting toward lower-cost, cleaner, more efficient, and sustainable sources. The increasing numbers of distributed energy resources (DERs) are allowing for the rapid transformation of electric grids toward achieving the goal of energy decarbonization. Along with cleaner and more efficient energy, however, we must also aim for a secure energy future. Solar photovoltaic (PV) systems are an important part of this transition. This paper discusses a cybersecurity risk assessment for behind-the-meter DERs using a solar PV system as a use case of the Distributed Energy Resource Cybersecurity Framework (DER-CF) developed by the National Renewable Energy Laboratory. This poster presents a conference paper on the risk assessment processes and summarizes the DER-CF's use case recommendations to strengthen the cybersecurity posture of the electric grid.

cybersecurity↗

Cybersecurity for Clean Energy Resources [Slides]

This presentation provides motivation for research in clean energy cybersecurity and highlights INL projects and capabilities to address clean energy cybersecurity needs. The projects are broken down by device level, plant level, utility level, regulation level, and implementation. This introduction to INL capabilities creates opportunity for further conversations around how cohort members can improve their own organizational security postures.

14 SOLAR ENERGY↗