Search NASA⌕ Search

SEARCH · Search NASA

Results for “Modbus”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Modbus RTU for Embedded Cyber Secure Inverter Controller

The Modbus communication protocol is a widely adopted communication standard in industrial control systems. This communication protocol is known for being reliable and straightforward to implement while being versatile in terms of its operating parameters while supporting multiple formats over various hardware infrastructures and architectures. Many intelligent devices such as Programmable Logic Controllers (PLCs), Human-Machine Interfaces (HMIs), Internet-of-Things (IoT), and various Operational Technologies (OT) utilize Modbus for their communication systems. These types of systems must communicate with each other through a standardized and central communication process. To support the integration of these modular systems, a Field-Programmable Gate Array (FPGA) can act as an embedded central routing fabric for this communication to take place. Embedded systems are versatile enough to interface with various devices and systems to accomplish various goals. Additionally, embedded systems require relatively small physical designs to minimize the required resources to facilitate the intended application by providing low-level system access. This minimization of system resources goes hand in hand with reducing the financial cost of a proposed solution or system. As remotely collaborating researchers often use FPGAs to prototype designs that are required to have a method for data transmission among systems, it is imperative to provide a baseline standard for communications among devices and systems. A typical method of implementing the Modbus RTU communication protocol in an embedded environment is using integrated logic architectures within the FPGA called “Intellectual Property (IP) cores.” IP cores can be designed using integrated logic or circuit designs to function as an embedded processor. These IP cores can then perform the required computational actions to support the Modbus RTU communication protocol by utilizing high-level programming languages such as the C programming language. The hardware description language of Very High-Speed Integrated Circuit Hardware Description Language (VHDL) allows for the control of real hardware at the logic gate and signal level. These logic gates and signals can be designed and controlled to perform desired actions based on the system design. Programming an FPGA using VHDL allows an individual to access the lowest abstraction level of the system during FPGA development. This level of abstraction is referred to as the register-transfer level (RTL), which gives access to manipulating values and variables at the register level. This register-level manipulation provides precision over creating the logical circuit within the FPGA, thus minimizing the required code to perform desired operations. The Modbus RTU communication protocol can be implemented within an FPGA using VHDL programming to establish a standardized and embedded serial communication pathway. This implementation provides a standardized communication protocol to streamline research efforts among researchers, thus increasing the efficiency of research efforts. Additionally, this Modbus RTU implementation requires fewer resources when compared to typical communication protocol implementations that utilize an IP core, reducing the hardware requirement for effective research efforts.

communication↗

MSU IETC ML for Modbus (AN EDGE)

This study explores machine learning for decoding Modbus RTU data using K-Nearest Neighbors (KNN) models. An initial KNN model trained on 8,000 packets achieved 95.15% accuracy. Although ML improves generalization, accuracy still falls short of deterministic methods. These findings have implications for Modbus traffic analysis, intrusion detection in industrial networks, and adaptive error correction in real-time monitoring systems. By refining ML-based decoding, future work could enable more efficient anomaly detection and predictive maintenance in industrial automation and cybersecurity applications.

Communication Protocol↗

Development of a Practical Secondary Control for Hardware Microgrids

Practical, vendor-agnostic interoperability guidelines for the secondary control architecture of microgrids (MGs) with multiple grid-forming (GFM) inverter-based resources (IBRs) have not yet been developed. Therefore, this paper proposes a generic and vendor-agnostic secondary control architecture that operates with all GFM IBRs and synchronous generators. This secondary control does not require the use of additional measurement devices in the MG and utilizes the inherent communication systems of the GFM units, such as Modbus TCP/IP. The practical challenges of Modbus registers, such as packet loss and quantization error, and their detrimental impacts on secondary control actions are investigated. The proposed three-stage modification for any secondary control architecture to mitigate these impacts includes: 1) averaging the data read, 2) situational event-triggering of the controller, and 3) finite iteration of the controlling action. The proposed method is validated using a 3-..phi.., 480 V, 60 Hz, 500 kVA laboratory hardware microgrid with commercial two GFM IBRs and one diesel generator. The experimental results corroborates the fact the proposed modification in the secondary control architecture is advantageous for practical usage under erroneous measurements.

communication systems↗

Mooring Load Monitoring of a Wave Energy Converter Using a Self-Synchronizing Underwater Acoustic Network

A self-synchronizing underwater acoustic network, designed for remote monitoring of mooring loads in Wave Energy Converters (WEC), has been developed and tested. This network uses Time Division Multiple Access and operates self-contained with the ability for users to remotely transmit commands to the network as needed. Each node is a self-contained unit, consisting of a protocol adaptor board, an underwater acoustic modem and a battery pack. A node can be connected to a load cell, to a topside user or to the WEC. Every node is swapable. The protocol adaptor board, named Protocol Adaptor for Digital LOad Cell (PADLOC) supports a variety of digital load cell message formats (CAN, MODBUS, custom ASCII) and underwater acoustic modem serial formats. PADLOC enables topside users to connect to separate load cells through a user-specific command.

acoustic↗

Achieving Runtime State Verification Assurance in Critical Cyber-Physical Infrastructures

Industrial Cyber-Physical Systems (ICPS) are an essential backbone of national critical infrastructures. They help monitor and control crucial cyber-enabled services such as energy generation. Commonly ICPS monitors the physical process through Supervisory Control and Data Acquisition (SCADA) systems. The SCADA ecosystem takes critical real-time and future system operational decisions based on the runtime state behavior of field sensors. Traditional SCADA systems use legacy and insecure communication protocols such as the Modbus protocol that lack adequate security mechanisms to provide robust runtime state behavior assurance of constrained field sensors. Therefore, constrained field sensors are commonly vulnerable to standard semantic attacks that gradually change the behavior state of infected devices. This paper discusses process integrity assurance techniques necessary to enhance the security of behavior-based protocols such as the Modbus protocol. The Runtime State Verification (RSV) protocol proposed in this paper aims to address semantic attacks in the SCADA ecosystem by integrating behavior-based Mandatory Results Automata (MRA) and a Hyperledger Fabric (HLF) network. The RSV protocol provides high process integrity assurance through enhanced behavior-based MRA suitable for the constrained field devices. A proof of concept of the RSV protocol has been evaluated in an emulated water-tube boiler. Preliminary evaluations of the RSV protocol aimed to measure the efficiency of the proposed protocol by monitoring an Combustion Efficiency (CE) process necessary to preserve optimal combustion, thus minimizing costs and future maintenance of water-tube boilers. We analyze the overall network overhead and latency of the proposed RSV protocol by evaluating the HLF network performance and comparing the proposed RSV protocol with the state-ofart BloSPAI protocol. Through the preliminary evaluations of the proposed RSV protocol, this paper demonstrates that the proposed RSV protocol overcomes the shortcomings and network overhead of the BloSPAI protocol by integrating behavior-based authentication through novel MRAs and HLF networks.

Rivera, Abel Gomez↗

Development of a Practical Secondary Control for Hardware Microgrids

Practical, vendor-agnostic interoperability guidelines for the secondary control architecture of microgrids (MGs) with multiple grid-forming (GFM) inverter-based resources (IBRs) have not yet been developed. Therefore, this paper proposes a generic and vendor-agnostic secondary control architecture that operates with all GFM IBRs and synchronous generators. This secondary control does not require the use of additional measurement devices in the MG and utilizes the inherent communication systems of the GFM units, such as Modbus TCP/IP. The practical challenges of Modbus registers, such as packet loss and quantization error, and their detrimental impacts on secondary control actions are investigated. The proposed three-stage modification for any secondary control architecture to mitigate these impacts includes: 1) averaging the data read, 2) situational event-triggering of the controller, and 3) finite iteration of the controlling action. The proposed method is validated using a three-phase electric power, 480 V, 60 Hz, 500 kVA laboratory hardware microgrid with commercial two GFM IBRs and one diesel generator. The experimental results corroborates the fact the proposed modification in the secondary control architecture is advantageous for practical usage under erroneous measurements.

grid-forming inverter↗

Development of a Practical Secondary Control for Hardware Microgrids: Preprint

Practical vendor-agnostic interoperability guidelines for the secondary control architecture of microgrids (MGs) with multiple grid-forming (GFM) inverter-based resources (IBRs) have not yet been developed. Therefore, this paper proposes a generic and vendor-agnostic secondary control architecture that works with all GFM IBRs and synchronous generators. This secondary control does not need to employ any additional measurement devices in the MG and uses the inherent communication systems of the GFM units, such as Modbus TCP/IP. The practical challenges of Modbus holding registers such as packet loss, quantization error, etc. and their deteriorating impacts on the secondary control action are investigated. The proposed three-stage modification of any secondary control architecture to eliminate these impacts includes 1) averaging the data read, 2) situational event-triggering of the controller, and 3) the finite iteration of the controlling action. The proposed method is validated using a laboratory hardware MG with commercial GFM units.

inverter based resources↗

Toward Wireless Smart Grid Communications: An Evaluation of Protocol Latencies in an Open-Source 5G Testbed

Fifth-generation networks promise wide availability of wireless communication with inherent security features. The 5G standards also outline access for different applications requiring low latency, machine-to-machine communication, or mobile broadband. These networks can be advantageous to numerous applications that require widespread and diverse communications. One such application is found in smart grids. Smart grid networks, and Operational Technology (OT) networks in general, utilize a variety of communication protocols for low-latency control, data monitoring, and reporting at every level. Transitioning these network communications from wired Wide Area Networks (WANs) to wireless communication through 5G can provide additional benefits to their security and network configurability. However, introducing these wireless capabilities may also result in a degradation of network latency. In this paper, we propose utilizing 5G for smart grid communications, and we evaluate the latency impacts of encapsulating GOOSE, Modbus, and DNP3 for transmission over a 5G network. The OpenAirInterface open-source library is utilized to deploy an in-lab 5G Core Network and gNB for testing with off-the-shelf User Equipment (UE). This creates an effective 5G test platform for experimenting with different OT protocols such as GOOSE. The results are validated by measuring two different Intelligent Electronic Devices’ contact closure times for each network configuration. These tests are also conducted for varying packet sizes in order to isolate different sources of network latency. Our study outlines the latency impact of communication over 5G for time-critical and non-critical applications regarding their transition toward private 5G-based OT network implementations. The conducted experiments illustrate that in the case of GOOSE packets, simple encapsulation may exceed the protocol’s time-critical nature, and, therefore, additional measures must be taken to ensure a viable transition of GOOSE to 5G services. However, non-critical applications are shown to be viable for migration to 5G.

42 ENGINEERING↗

Exponential Backoff and Its Security Implications for Safety-Critical OT Protocols over TCP/IP Networks

The convergence of Operational Technology (OT) and Information Technology (IT) networks has become increasingly prevalent with the growth of Industrial Internet of Things (IIoT) applications. This shift, while enabling enhanced automation, remote monitoring, and data sharing, also introduces new challenges related to communication latency and cybersecurity. Oftentimes, legacy OT protocols were adapted to the TCP/IP stack without an extensive review of the ramifications to their robustness, performance, or safety objectives. To further accommodate the IT/OT convergence, protocol gateways were introduced to facilitate the migration from serial protocols to TCP/IP protocol stacks within modern IT/OT infrastructure. However, they often introduce additional vulnerabilities by exposing traditionally isolated protocols to external threats. This study investigates the security and reliability implications of migrating serial protocols to TCP/IP stacks and the impact of protocol gateways, utilizing two widely used OT protocols: Modbus TCP and DNP3. Our protocol analysis finds a significant safety-critical vulnerability resulting from this migration, and our subsequent tests clearly demonstrate its presence and impact. A multi-tiered testbed, consisting of both physical and emulated components, is used to evaluate protocol performance and the effects of device-specific implementation flaws. Through this analysis of specifications and behaviors during communication interruptions, we identify critical differences in fault handling and the impact on time-sensitive data delivery. The findings highlight how reliance on lower-level IT protocols can undermine OT system resilience, and they inform the development of mitigation strategies to enhance the robustness of industrial communication networks.

DNP3↗

A critical review of cyber-physical security for building automation systems

Modern Building Automation Systems (BASs), as the brain that enable the smartness of a smart building, often require increased connectivity both among system components as well as with outside entities, such as the cloud, to enable low-cost remote management, optimized automation via outsourced cloud analytics, and increased building-grid integrations. As smart buildings move towards open communication technologies, providing access to BASs through the building's intranet, or even remotely through the Internet, has become a common practice. However, increased connectivity and accessibility come with increased cyber security threats. BASs were historically developed as closed environments with limited cyber-security considerations. As a result, BASs in many buildings are vulnerable to cyber-attacks that may cause adverse consequences, such as occupant discomfort, excessive energy usage, and unexpected equipment downtime. Therefore, there is a strong need to advance the state-of-the-art in cyber-physical security for BASs and provide practical solutions for attack mitigation in buildings. However, an inclusive and systematic review of BAS vulnerabilities, potential cyber-attacks with impact assessment, detection & defense approaches, and cyber resilient control strategies is currently lacking in the literature. This review paper fills the gap by providing a comprehensive up-to-date review of cyber-physical security for BASs at three levels in commercial buildings: management level, automation level, and field level. The general BASs vulnerabilities and protocol-specific vulnerabilities for the four dominant BAS protocols (i.e., BACnet, KNX, LonWorks, and Modbus) are reviewed, followed by a discussion on four attack targets and seven potential attack scenarios. Furthermore, the impact of cyber-attacks on BASs is summarized as signal corruption, signal delaying, and signal blocking. The typical cyber-attack detection and defense approaches are identified at the three levels. Cyber resilient control strategies for BASs under attack are categorized into passive and active resilient control schemes. Open challenges and future opportunities are finally discussed.

97 MATHEMATICS AND COMPUTING↗

FL‐ADS: Federated learning anomaly detection system for distributed energy resource networks

Abstract With the ongoing development of Distributed Energy Resources (DER) communication networks, the imperative for strong cybersecurity and data privacy safeguards is increasingly evident. DER networks, which rely on protocols such as Distributed Network Protocol 3 and Modbus, are susceptible to cyberattacks such as data integrity breaches and denial of service due to their inherent security vulnerabilities. This paper introduces an innovative Federated Learning (FL)‐based anomaly detection system designed to enhance the security of DER networks while preserving data privacy. Our models leverage Vertical and Horizontal Federated Learning to enable collaborative learning while preserving data privacy, exchanging only non‐sensitive information, such as model parameters, and maintaining the privacy of DER clients' raw data. The effectiveness of the models is demonstrated through its evaluation on datasets representative of real‐world DER scenarios, showcasing significant improvements in accuracy and F1‐score across all clients compared to the traditional baseline model. Additionally, this work demonstrates a consistent reduction in loss function over multiple FL rounds, further validating its efficacy and offering a robust solution that balances effective anomaly detection with stringent data privacy needs.

Purohit, Shaurya [Iowa State University Ames Iowa ↗

A Secondary Control Framework for Microgrid Interoperability With Vendor-Agnostic Grid-Forming Units: Design, Implementation, and Demonstration via Large-Scale Hardware Setup

The reliable operation of islanded microgrids increasingly depends on secondary controls that restore voltage and frequency to nominal values and ensure accurate active and reactive power sharing. Centralized secondary control architectures achieve high accuracy through global coordination at the cost of single-point failures and limited scalability compared with decentralized/distributed approaches. But a critical gap remains in addressing the interoperability and vendor-agnostic operation of secondary controls in real-world microgrids where heterogeneous diesel generator(s) and grid-forming (GFM) inverter(s) from multiple manufacturers always coexist. Practical and vendor-agnostic interoperability guidelines for the secondary control architecture of microgrids with multiple GFM units have not yet been developed; therefore, this paper proposes an interoperable and vendor-agnostic secondary control framework that operates seamlessly across GFM units from different vendors without relying on proprietary controls and protocols, hardware, or lock-ins. The framework leverages existing communication infrastructures (e.g., Modbus TCP/IP) to enable cost-effective deployment while addressing practical challenges, such as packet loss and quantization errors. Mitigation strategies-including data averaging, situational event-triggered control, and finite-iteration execution-are introduced to enhance reliability under real-world conditions. A generalized modeling and design framework is also presented, supported by robustness analysis to demonstrate independence from vendor-specific implementations. The proposed framework is validated through a large-scale hardware demonstration using a 3-$\phi$, 480-V, 60-Hz, 713-kVA laboratory hardware microgrid involving a heterogeneous diesel generator and multiple GFM inverters, showcasing its effectiveness in achieving stable voltage and frequency restoration and accurate power sharing under practical constraints. The results highlight the framework's potential as a scalable and practical solution for next-generation microgrids requiring openness, standard framework, and interoperability.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Machine Learning-based False Data Injection Attack Detection and Localization in Power Grids

Cyberattacks on critical infrastructures can be catastrophic and bring nations to their knees. Therefore, detecting these attacks is crucial and challenging. This paper presents a novel approach for detecting and locating cyberattacks affecting an electrical power system. The adversary employs a man-in-the-middle technique to inject false data into the communication between distributed energy resources (DER) and Microgrid Controller (MGC) with the goal of disrupting power delivery. The approach for detection and localization is based on integrating multiple machine learning-based anomaly detection models that combine network traffic data and grid measurements. Experiments are performed to assess the method's performance using a hardware-in-the-loop real-time simulation testbed which includes Modbus TCP/IP communication. Power system topology and operating conditions are based on actual topology and real-world data provided by the Holy Cross Energy utility network. Results confirm that the method can be successfully employed for detecting and localizing cyberattacks.

Leao, Bruno P.↗

Real-time Implementation of Grid Code Compliant Grid Edge Energy Management System

Integrated distributed energy resources (DER) in a distribution system need to follow grid codes to avoid violations that result in DER/circuit segment disconnection. To comply with grid code requirements at the grid edge level, network constrained grid edge energy management system (EMS) can be deployed. The objective of grid edge EMS is to provide economic solution for active and reactive power DER setpoints at each dispatch interval and ensure voltage regulation to support secure interconnection of the grid edge segment to the distribution system with multiple inverter based DER units. In this work, real-time simulation of grid code compliant grid edge EMS is deployed in a realistic feeder circuit segment. For real-time simulation, communication between the grid edge EMS and DERs is done exploiting IEC 61850-7-420. It enables interoperability among different DERs and grid edge EMS. No prior art has deployed IEC 61850-7-420 GOOSE communication protocol for grid edge EMS. Conversion of IEC 61850 GOOSE messages to Modbus communication protocol is also performed to communicate with grid edge EMS in commodity-off the shelf embedded boards in this work. The real-time simulation in OPAL-RT real-time digital simulator shows the out-performance of grid edge EMS by reducing the voltage violation in the distribution circuit.

Energy management system↗

A Communication Testbed for Testing Power Electronic Agent Systems

Power electronic systems (PES) incorporate complex intra-system communication, which are of vital importance for the successful operation of these systems. This paper proposes and outlines a communication testbed that will help in the development and testing of the communications between the components of PES. It allows for the comparison and evaluation of different communication methods, such as MQTT, Modbus, or User Datagram Protocol (UDP), and for the characterization of how these communication protocols perform.

Dean, Ben↗

VAC: A Software Approach to Resilient SCADA Automation

To better secure critical infrastructure, especially power systems, this paper introduces a virtual SCADA automation controller. The automation controller is a gateway into a power subsystem, making it a valuable target for cyber-attacks that could cut it off from the control center and cause a loss of view and control. To prevent this, the Virtual Automation Controller (VAC) is a backup device that mirrors the capabilities of the physical controller. It can communicate via Modbus and DNP3 and is containerized so it can be deployed on a variety of platforms. Furthermore, it utilizes software-defined networking to quickly disconnect a failed automation controller and preserve its state for forensics. The VAC gives system operators time to replace the failed controller and prevents dangerous and costly damage to power systems. The VAC is compared against the SEL 3505-3 RTAC and shown to have the necessary features to act as a failover controller.

Johnson, Jordan↗