Robust Dynamic Watermarking for Cyber-Physical Security of Inverter-Based Resources in Power Distribution Systems
Not provided.
SEARCH · Search NASA
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Not provided.
The requirements for U.S. nuclear power plants to maintain a large onsite physical security force contribute to their high operational costs. The cost of maintaining the current physical security posture is approximately 10% of the overall operation and maintenance budget for commercial nuclear power plants. The goal of the Light Water Reactor Sustainability (LWRS) program’s physical security pathway is to develop tools, methods, and technologies and provide the technical basis for an optimized physical security posture. The conservatisms built into current security postures may be analyzed and minimized to reduce security costs while still ensuring adequate security and operational safety. The research performed at Idaho National Laboratory within LWRS program’s physical security pathway has successfully developed a dynamic force-on-force modeling framework using various computer simulation tools and integrating them with the dynamic assessment Event Modeling Risk Assessment using Linked Diagrams (EMRALD) tool. This integrated process for physical security analysis is named Modeling and Analysis for Safety Security using Dynamic EMRALD Framework (MASS-DEF). This document provides an update on the progress in applying the MASS-DEF process to an operating commercial nuclear power plant as well as additional industry feedback regarding use of the tool for other physical security risk-informed topics. This report is only a summary of the progress and does not contain specific modeling results as those contain sensitive security information. Previous reports described how a user could integrate their plant-specific force-on-force models with the dynamic simulation tool EMRALD, model operator actions, and integrate with probabilistic risk assessment tools, such as CAFTA (Computer Aided Fault Tree Analysis System) or SAPHIRE (Systems Analysis Programs for Hands-on Integrated Reliability Evaluations), and with thermal-hydraulic tools, such as RELAP-5 or MAAP. Previous reports applied various combinations of available simulations codes with EMRALD using generic plant models to demonstrate how to perform the analysis. This report is an update the progress of applying the dynamic computational framework to an actual nuclear facility using their security scenarios and timelines. This report also provides an update to the procedural guidance for the MASS-DEF process and an overview of the generic models available for use by utilities. This report does not contain any plant’s sensitive information and/or safeguards information. This study’s purpose was to verify that the results achieved using generic models are similar to actual plant results and refine our guidance on the use of the framework. This assessment enables further analysis, such as what-if scenarios and staff-reduction evaluation, thereby optimizing physical security at plants.
Explore the source record for details and available documents.
This report presents the regulatory requirements and directions on the physical security of advanced nuclear reactors in USA. Presently, a rule is being proposed that allows for a performance-based analysis. In determining the physical security requirements for an advanced reactor, new tools may be desired to conduct a performance-based analysis. These tools should incorporate dynamic analysis methods to provide as much realism as possible. In comparison, the security requirements for existing light water reactors (LWRs) are much more prescriptive and the analysis conducted to establish the required physical security strategies were more easily performed with static analysis. In order to achieve the cost goals that advanced reactors require for adoption; the nuclear security force required should not be excessive. Dynamic physical security analysis methods and tools have been developed by the US Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) program. This report details how the dynamic risk analysis tools developed in the LWRS program using the dynamic risk modelling tool, EMRALD, may be adapted for use in analyzing the physical security designs for advanced reactors accounting for variable performance-based requirements. This report provides an example analysis of a hypothetical SFR using publicly available information and generic assumptions to demonstrate the methods and potential presentation and analysis of the results. No actual plant information is used in this example analysis. Future work in this area will create additional models that can be adapted for any advanced reactor concept and use various security features to create a physical security system that provides adequate protection from radiological theft and sabotage.
The requirements for United States nuclear power plants to maintain a large onsite physical security force contribute to their large operational costs. The cost of maintaining the current physical security posture is approximately 10% of the overall operation and maintenance budget for commercial nuclear power plants. The goal of the Light Water Reactor Sustainability Program Physical Security Pathway is to develop tools, methods, and technologies and provide the technical basis for an optimized physical security posture. This pathway will analyze and minimize the conservatisms built into current security postures in order to reduce security costs while still ensuring adequate security and operational safety. The research performed at Idaho National Laboratory within this pathway has successfully developed a dynamic force-on-force (FOF) modeling framework using various computer simulation tools and integrated them with the dynamic assessment Event Modeling Risk Assessment using Linked Diagrams (EMRALD) tool. This document provides an overview of lessons learned in applying a dynamic computational framework that links results from a commercially available FOF simulation tool, a commercially available thermal-hydraulic tool, and EMRALD to an operating commercial nuclear power plant. This process of including plant procedures and multiple analysis results is being called Modeling and Analysis for Safety Security using Dynamic EMRALD Framework. Previous reports described how a user could integrate their plant-specific FOF models with the dynamic simulation tool EMRALD, model operator actions, integrate with probabilistic risk assessment tools, such as Computer Aided Fault Tree Analysis System or Systems Analysis Programs for Hands-on Integrated Reliability Evaluations, and with thermal-hydraulic tools, such as RELAP-5. Previous reports applied various combinations of available simulations codes with EMRALD using generic plant models to demonstrate how to perform the analysis. This report documents the results of applying the dynamic computational framework to an actual nuclear facility using their security scenarios and timelines. The purpose of this study was to verify that results achieved using generic models are similar to actual plant results and to refine our guidance of the use of the framework. Such an assessment enables further analysis, such as what-if scenarios and staff-reduction evaluation, thereby optimizing physical security at plants. NOTE: The work performed in this report is based on a generic EMRALD model with actual plant data used for the analysis. However, only the generic model and general results of the analysis are in the report. No plant’s sensitive information is discussed in this report. The discussion shows examples of insights that can be obtained from the MASS-DEF methodology.
The optimization of physical security in nuclear power plants requires sophisticated methodologies that integrate operator actions and plant behavior through advanced simulation tools. To address this, Idaho National Laboratory [JL2.1]has developed the Modeling and Analysis for Safety and Security using the Dynamic EMRALD Framework (MASS-DEF) methodology, an approach that integrates force-on-force simulations, dynamic probabilistic risk assessment, and thermal-hydraulics modeling [JL3.1]to enhance security planning while reducing costs. We developed a tool that produces reduced order models using thermal hydraulic simulations from the Modular Accident Analysis Program (MAAP) [1]. These models can quickly evaluate reactor core behavior during attack simulations, and in so doing, address two barriers of traditional methods: (1) MAAP simulations are computationally intensive, and (2) attack scenarios must be run in a secure environment, which complicates analysis and validation. By precomputing scenario outcomes for a small number of modified parameters, the reduced order model significantly decreases the computational cost and enables offsite review of the results.
The optimization of physical security in nuclear power plants requires sophisticated methodologies that integrate operator actions and plant behavior through advanced simulation tools. Idaho National Laboratory has developed the Modeling and Analysis for Safety and Security using the Dynamic EMRALD Framework (MASS-DEF) methodology, an approach that integrates force-on-force simulations, dynamic probabilistic risk assessment, and thermal hydraulics modeling to enhance security planning while reducing costs. A reduced order model for thermal hydraulic simulations performed by the Modular Accident Analysis Program (MAAP) was developed to evaluate reactor core behavior during attack scenarios. MAAP simulations are computationally intensive and must be run in a secure environment, complicating analysis and validation. By pre-computed scenario outcomes for a small number of modified parameters, the reduced order model significantly decreases the computational cost and enables offsite review of the results.
Modern Building Automation Systems (BASs), as the brain that enable the smartness of a smart building, often require increased connectivity both among system components as well as with outside entities, such as the cloud, to enable low-cost remote management, optimized automation via outsourced cloud analytics, and increased building-grid integrations. As smart buildings move towards open communication technologies, providing access to BASs through the building's intranet, or even remotely through the Internet, has become a common practice. However, increased connectivity and accessibility come with increased cyber security threats. BASs were historically developed as closed environments with limited cyber-security considerations. As a result, BASs in many buildings are vulnerable to cyber-attacks that may cause adverse consequences, such as occupant discomfort, excessive energy usage, and unexpected equipment downtime. Therefore, there is a strong need to advance the state-of-the-art in cyber-physical security for BASs and provide practical solutions for attack mitigation in buildings. However, an inclusive and systematic review of BAS vulnerabilities, potential cyber-attacks with impact assessment, detection & defense approaches, and cyber resilient control strategies is currently lacking in the literature. This review paper fills the gap by providing a comprehensive up-to-date review of cyber-physical security for BASs at three levels in commercial buildings: management level, automation level, and field level. The general BASs vulnerabilities and protocol-specific vulnerabilities for the four dominant BAS protocols (i.e., BACnet, KNX, LonWorks, and Modbus) are reviewed, followed by a discussion on four attack targets and seven potential attack scenarios. Furthermore, the impact of cyber-attacks on BASs is summarized as signal corruption, signal delaying, and signal blocking. The typical cyber-attack detection and defense approaches are identified at the three levels. Cyber resilient control strategies for BASs under attack are categorized into passive and active resilient control schemes. Open challenges and future opportunities are finally discussed.
This paper describes ongoing work within the Light Water Reactor Sustainability pathway at Idaho National Laboratory (INL) to optimize the security and cost of nuclear power plants. It introduces the dynamic risk assessment tool developed at INL, Event Modeling Risk Assessment using Linked Diagrams (EMRALD). EMRALD is leveraged to optimize the security posture of a nuclear power plant by integrating force-on-force (FOF) simulations and operator mitigation actions, including dynamic and flexible coping strategies (FLEX). To illustrate the methodology, four attack scenarios are modeled in a commercially available FOF simulation tool using a hypothetical nuclear power plant facility. The simulation results provide valuable insights into possible attack outcomes, as well as the probabilistic risk of a core damage event given these outcomes. Safety mitigation procedures are modeled in EMRALD dependent on the attack outcomes by considering human operator uncertainties. The results demonstrate that the number of armed responders can be optimized, while still maintaining the same protection level as the initial security posture. The proposed modeling and simulation framework of integrating FLEX equipment with FOF models enables the nuclear power plants to credit FLEX portable equipment in the plant security posture, resulting in an efficient and optimized physical security system.
Despite the IEEE Power Electronics Society (PELS) establishing Technical Committee 10 on Design Methodologies with a focus on the cyber-physical security of power electronics systems, a holistic design methodology for addressing security vulnerabilities remains underdeveloped. This gap largely stems from the limited integration of computer science and power/control engineering studies in this interdisciplinary field. Addressing the inadequacy of unilateral cyber or control perspectives, this article presents a novel four-layer cyber-physical security model specifically designed for electric machine drives. Central to this model is the innovative control information flow (CIF) model, residing within the control layer, which serves as a pivotal link between the cyber layer's vulnerable resources and the physical layer's state-space models. By mapping vulnerable resources to control variable space and tracing attack propagation, the CIF model facilitates accurate impact predictions based on tainted control laws. The effectiveness and validity of this proposed model are demonstrated through hardware experiments involving two typical cyber-attack scenarios, underscoring its potential as a comprehensive framework for multidisciplinary security strategies.
Cyber-Physical Systems (CPSs) are becoming increasingly complex and interconnected as they attempt to meet the demands of evolving society. As a result, monitoring and maintaining them becomes a more complex and demanding task for control system operators and cyber defenders. While the literature on visualization techniques in the context of cybersecurity is extensive, the same cannot be said for studies on visualization for the security of cyber-physical systems. This paper aims to fill that gap by: 1) defining the main features of a visualizations workflow for security visualizations in cyber-physical systems. The workflow includes the acquisition of cyber and physical data, processing of data, selection, and configuration of both visualization tools and end-user interactions. 2) Providing an overview of cyber-physical security visualization systems, with a focus on smart grids as a case study. Finally, we use the perspectives gained from this analysis to provide insights and directions for future research and design of cyber-physical visualization techniques.
As smart buildings move towards open communication technologies, providing access to the Building Automation System (BAS) through the building's intranet, or even remotely through the Internet, has become a common practice. However, BAS was historically developed as a closed environment and designed with limited cyber-security considerations. Thus, smart buildings are vulnerable to cyber-attacks with the increased accessibility. This study introduces the development and capability of a Hardware-in-the-Loop (HIT) testbed for testing and evaluating the cyber-physical security of typical BASs in smart buildings. The testbed consists of three subsystems: (1) a real-time HIL emulator simulating the behavior of a virtual building as well as the Heating, Ventilation, and Air Conditioning (HVAC) equipment via a dynamic simulation in Modelica; (2) a set of real HVAC controllers monitoring the virtual building operation and providing local control signals to control HVAC equipment in the HIL emulator; and (3) a BAS server along with a web-based service for users to fully access the schedule, setpoints, trends, alarms, and other control functions of the HVAC controllers remotely through the BACnet network. The server generates rule-based setpoints to local HVAC controllers. Based on these three subsystems, the HIL testbed supports attack/fault-free and attack/fault-injection experiments at various levels of the building system. The resulting test data can be used to inform the building community and support the cyber-physical security technology transfer to the building industry.
U.S. advanced non-light-water reactor vendors may pursue collocated on-site reprocessing activities. Therefore, these facilities are likely to possess formula quantities, or Category I quantities, of special nuclear material (SNM) during normal operations. The U.S. Nuclear Regulatory Commission (U.S. NRC) has yet to formally establish a regulatory framework for commercial reprocessing. While Category I requirements would explicitly not apply in this circumstance under current regulatory requirements, regulatory certainty does not exist. A novel framework should be developed to ensure public health and safety while also risk-informing the physical security requirements. This report reviews the relevant background of related rulemaking activities and proposes risk-informed physical protection requirements to satisfy these objectives. Insights from NRC security-related rulemaking activities provide a substantial technical basis to approach potential establishment of physical security requirements for reprocessing facilities. If a licensee can provide justification that the material satisfies a sufficient self-protecting radiation dose threshold, the material may not be subject to theft or diversion requirements and only potential sabotage requirements would apply. Furthermore, if the material can be justified to be moderately dilute, a set of risk-informed requirements could provide adequate protection of public health and safety. A revised performance objective for prevention of theft of moderately dilute Category I SNM may be detection to allow prompt recovery by a local law enforcement agency. However, a significant caveat to the proposed categorization scheme is the unknown integration of radiological sabotage with requirements for the protection against theft. Future licensees should consult with the NRC regarding treatment of this regulatory topic. Additionally, the self-protecting radiation dose threshold (either the existing or a proposed future threshold) would need to be considered. An integrated approach may apply graded potential requirements for protection against the design basis threat of radiological sabotage currently applicable to commercial nuclear power plants and Category I SNM facilities defined within 10 CFR 73.1(a).
This work proposes a dynamic evaluation methodology to relax the conservatism in physical security evaluation, by leveraging an ongoing work in the Light Water Reactor Sustainability pathway. This methodology is implemented in a dynamic risk assessment tool named Event Modeling Risk Assessment using Linked Diagrams (EMRALD). The work extends EMRALD’s capability to support a sandbox feature where analysts can easily create attack scenarios and modify advanced/small modular reactor (A/SMR) security and safety features using templates. This approach saves time and cost since the analysis does not require creating detailed computer-aided design models, as is commonly required in commercial force-on-force software tools. EMRALD is completely free to use at https://emraldapp.inl.gov. We have developed basic templates including physical barriers, intrusion sensors, physical areas, and safety actions, that can be downloaded from EMRALD’s GitHub site: https://github.com/idaholab/EMRALD. These templates use generic data commonly used for training purposes, which do not reflect any actual operating nuclear reactor. Users may adjust the data in the templates with their own dataset and/or create new templates in EMRALD. The proposed methodology combines security and safety by assessing sabotage effects up to the radiological consequence to the public instead of merely the core damage state. This practice follows the industry standard for advanced non-light-water reactors currently proposed for endorsement by the Nuclear Regulatory Commission. The combination of security and safety is expressed in an achievability-consequence chart. EMRALD can be used to generate data for this chart. A hypothetical case study using a representative sodium-cooled fast reactor (SFR) facility is presented in this report to demonstrate this methodology. This case study does not contain any actual nuclear plant information. This work will benefit A/SMR vendors and utilities to implement security by design during the reactor design iteration phase, such that they do not have to perform upgrades and retrofits to the reactor after it is installed to improve its physical protection system. The tool may also be used to analyze domestic or foreign reactor designs to support the International Nuclear Security Techniques for Advanced Reactors (INSTAR) bilateral missions. Future works are planned to implement the methodology on a reference SFR reactor and a reference high-temperature gas-cooled reactor to obtain insights and lessons-learned for the A/SMR community.
This report provides a comprehensive assessment of physical security modeling and simulation tools available for use in the vulnerability assessment (VA) process for nuclear facilities. It outlines the historical evolution of VA methodologies, emphasizing the transition from traditional layer-based approaches to a more holistic framework that integrates detection probabilities directly into combat simulations. The document details the critical components of the VA process, including the characterization of targets, threats, and protective measures, as well as the development of adversary scenarios that reflect both insider and outsider threats. It highlights the importance of performance assurance programs, emphasizing the need for continuous evaluation and testing of security systems to ensure their effectiveness against evolving threats. Additionally, the report discusses the significance of utilizing accredited modeling and simulation tools in accredited areas to accurately represent adversary actions and the corresponding responses of protective forces. By establishing a systematic approach to VA, this document aims to enhance the overall security posture of nuclear facilities, ensuring compliance with regulatory standards while effectively mitigating risks associated with potential adversarial actions.
The presentation would provide how Module-OT could provide security to the cyber physical systems that are interacting with digital, analog, physical, and human components.
Poster for ECRA poster session.
Powerpoint presentation for INSTAR annual meeting. Data and results are hypothetical and do not represent any actual nuclear plant.