Search NASA⌕ Search

SEARCH · Search NASA

Results for “programmable logic controllers”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Automated Programmable Logic Controller Memory Forensics Using RGB Image Analysis and Deep Learning

The introduction of Industry 4.0 and Internet-based technologies has enhanced industrial control system operations but have inadvertently increased their vulnerabilities to cyber attacks. When an industrial control system is compromised, security analysts need to identify the root cause quickly to start the recovery process and develop mitigation strategies. Memory forensics is critical in the incident analysis process to ascertain what occurred. Approaches for analyzing the persistent memory in industrial control devices are limited and almost nonexistent for volatile memory. This chapter proposes an automated methodology for programmable logic controller memory dump analysis using computer vision and deep learning techniques. The methodology converts the sequences of bytes in a programmable logic controller memory dump to red-green-blue pixels and employs a deep learning model that learns the underlying patterns and features of pre-labeled forensic artifacts in images and segments them into distinct regions. The trained model is employed to automatically segment new memory images and identify forensic artifacts. Evaluation of the methodology on a Schneider Electric Modicon M221 programmable logic controller under code injection and code modification attacks demonstrates its ability to detect attack artifacts in memory dumps.

Asmar Awad, Rima [ORNL] (ORCID:0000000233407742)↗

Calibration of the analog beam-signal hardware for the credited engineered beam power limit system at the Proton Power Upgrade Project at the Spallation Neutron Source

A programmable signal processor-based credited safety control that calculates pulsed beam power based on beam kinetic energy and charge was designed as part of the Proton Power Upgrade (PPU) project at the Spallation Neutron Source (SNS). The system must reliably shut off the beam if the average power exceeds 2.145 MW averaging over 60 seconds. System calibration requires pedigree in measurements, calibration setup, and calculations. This paper discusses the calibration of the analog beam signal components up to and including the Analog Digital Convertors (ADCs) for implementation into the Safety Programmable Logic Controllers (PLCs) and Field Programmable Gate Arrays (FPGAs).

Bobrek, Miljko↗

Primary Pump Motor Area - Transfer Fan Replacement PLC Design

My poster is about a project that I have worked on in my time at ATR as an intern. The Heating and Ventilation Control Panel (HVB-1) controls thirty-five heating and ventilation fans within the Advanced Test Reactor. This control panel needs replacement, as many of the components inside the existing panel are becoming old and degrading. In preparation for this replacement effort, concepts and component identification for the new control panel needed to be developed. Instead of replacing the new panel with replacement mechanical components, a Programmable Logic Controller (PLC) is proposed as a solution. Although multiple fans are associated with this panel, my poster focuses on the replacement design for the Primary Pump Motor Area Transfer Fan. This will provide an example of how the entire cabinet may be upgraded.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Modeling and Power-Hardware-in-the-Loop Validation of Synchronous Machine Governor

This paper introduces the development of a high-fidelity gas turbine governor model using a programmable logic controller for power-hardware-in-the-loop (PHIL) validation. The governor model is integrated with the National Renewable Energy Laboratory's (NREL) PHIL test bed, featuring a 2-MVA synchronous machine and a 2.5-MW variable-speed drive, to emulate NG-driven HRSGs and CTs under various operational scenarios. The primary objective of this research is to study the grid-connected and islanding operations of conventional generation sources, with representative startup sequences including turbine purge, ignition, speed ramp-up, synchronization, and breaker closure. Preliminary results of the generator governor model on NREL PHIL platform, particularly using the 2.5-MW dynamometer system, offered significant insights into the modeling techniques, hardware integration, scaling, and real-world simulation dynamics.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Synchronous Machine Governor Upgrade

Conventional generation sources play a critical role in the stability and reliability of the electrical grid, particularly as we transition towards more renewable energy sources. To understand and accurately emulate their behavior for optimizing grid operations and ensuring seamless integration with renewable technologies, it is essential to better emulate the grid- and plant-level impacts of conventional generation sources, such as natural gas (NG) driven heat recovery steam generators (HRSGs) and combustion turbines (CTs). Therefore, a governor model is developed in a programmable logic controller (PLC) to investigate the performance of the conventional generator under various dynamic operating conditions and to identify the impact on grid stability in a controlled environment. The governor model aims to enable the hardware-in-the-loop (HIL) based emulation of these conventional generation sources using the existing 2 MVA synchronous machine/generator that is driven by a flexible 2.5 MW variable speed drive. This setup will allow us to replicate the dynamic characteristics and response behaviors of NG-driven HRSGs and CTs. The controls for the emulated conventional plants follow the industry standard and are adjustable, ensuring they accurately reflect the operational capabilities and limitations of real-world systems. These controls include load-following capabilities, ramp rates, startup and shutdown sequences, and emissions characteristics. By incorporating these adjustable controls, we aim to capture the nuanced impacts of conventional generation, such as their ability to provide ancillary services like frequency regulation, voltage support, and spinning reserve. In this report, we simulate two types of dynamic operations: grid-connected and islanding. For each dynamic operation, representative starting sequences are tested, including turbine purge, ignition, speed ramping up, generator excitation and synchronizing, and breaker close. The HIL based tests provides insights for field deployment, specifically the high-fidelity governor model provides results to predict the potential stability and reliability risk and suggest possible integration measures (e.g., generation and load balancing, tuning of governor control parameters). Ultimately, this enhanced emulation capability will be integrated into our Advanced Research on Integrated Energy Systems (ARIES), enabling us to conduct comprehensive studies on the interactions between conventional and renewable energy sources. By better understanding these interactions, we can develop strategies to optimize the overall performance and reliability of the grid. This will support the deployment of advanced grid management techniques, such as demand response, grid-forming inverters, and energy storage systems. The main contributions are summarized as follows: (1) This report introduces a PLC-based governor model for gas turbines. This model accurately simulates the dynamic behavior of conventional generation sources under various operational scenarios; (2) The model is integrated with an HIL testbed that includes a 2.5 MW variable speed drive and a 2 MVA synchronous machine. This setup enables realistic, real-time emulation of conventional power plants, particularly NG driven HRSGs and CTs; (3) The developed model is adaptable to various gas turbine configurations and allows for precise control over parameters such as MW ramp rates. This flexibility makes it a valuable tool for future research and industry collaboration; and (4) By incorporating the model into the National Renewable Energy Laboratory's Advanced Research on Integrated Energy Systems, the report lays the groundwork for future studies on interactions between conventional and renewable energy sources, enhancing the ability to develop advanced grid management strategies.

24 POWER TRANSMISSION AND DISTRIBUTION↗

CONTROL AND DATA ACQUISITION IN A CYBER-PHYSICAL MIDSTREAM TESTBED

This thesis presents the development of a laboratory-scale cyber–physical midstream pipeline testbed designed to address this gap and support research in industrial control systems security. The platform integrates pumps, valves, sensors, programmable logic controllers (PLCs), and a human–machine interface (HMI) to emulate the monitoring and control architecture of real pipeline operations. The physical process is implemented as a closed-loop liquid circulation system designed to replicate flow behavior characteristic of midstream pipeline infrastructure. The testbed enables real-time data acquisition of key process variables, including flow rate and pressure facilitating the generation of datasets representative of normal pipeline operation. A threat model encompassing common ICS attack vectors was developed, including sensor spoofing, command injection, false data injection, denial-of-service attacks, and relay manipulation. Multiple attack scenarios were implemented and evaluated to demonstrate how cyber intrusions targeting sensors, actuators, networks, and software propagate into measurable physical consequences in pipeline flow and pressure. The developed platform serves as a practical, cost-effective environment for experimentation, education, and future cybersecurity research in midstream pipeline systems.

42 ENGINEERING↗

Control System Upgrade for Battery State-of-Charge Indications

The Advanced Test Reactor (ATR) Complex at Idaho National Laboratory (INL) relies on Battery Backed Power (BBP) systems and Uninterruptible Power Supplies (UPS) to ensure continuous power supply to critical components. This project aims to enhance the reliability and functionality of the battery monitoring and control systems by updating the State-of-Charge (SOC) system, Programmable Logic Controller (PLC), and Human-Machine Interface (HMI) for the nuclear safety-related battery banks. The current system, while functional, has areas for improvement, particularly in recharging calculations and alarm functions. The project objectives include developing flow charts, programming the new PLC and HMI, conducting bench tests, and updating design documentation. Additionally, the project ensures compliance with safety standards, develops training materials, creates comprehensive documentation, and integrates seamlessly with existing ATR infrastructure. The new SOC system is designed to be scalable for future upgrades, improve efficiency, enhance data accuracy, implement redundancy features, and achieve project goals within budget constraints while considering environmental impact. The methodology involved familiarizing with BBP and UPS systems, collecting current readings, rescaling signals, learning ladder logic, and updating the HMI. The transition from SLC 5/03 PLC using RS Logix 500 to CompactLogix 5380 using Studio 5000 was a key step. Despite challenges in transferring outdated PLC ladder logic and HMI code, starting from scratch led to a more accurate and efficient monitoring system, contributing to improved safety and operational efficiency. The project is currently awaiting approval of the Engineering Calculation and Analysis Report (ECAR) before implementation.

42 - ENGINEERING↗

Cybersecurity Center for Offshore Wind Energy (Final Project Report)

This project establishes a Cybersecurity Center for Offshore Wind Energy with the objective of designing and operating a cyber-physical testbed for wind energy farms (WEFs) that enables comprehensive cybersecurity research. The testbed incorporates a Supervisory Control and Data Acquisition (SCADA) system connected to turbine models via industrial-grade programmable logic controllers (PLCs) and remote terminal units (RTUs). It supports side-channel data acquisition, implementation and analysis of various cyberattack scenarios, and development of attack detection, mitigation, and best-practice guidance tailored to wind energy systems. During the project, the team expanded the number and fidelity of mathematical turbine models (MTMs), integrated these models with SCADA infrastructure, and deployed a scaled physical turbine and associated sensors. High-resolution operational and side-channel data streams were collected and used to refine machine-learning (ML)-based attack detection systems and to extend the WindCRAFT framework to multi-turbine threat scenarios. The project demonstrated a realistic, scalable environment for evaluating cyber threats, validated attack detection approaches using enriched datasets, and identified new multi-turbine and inter-turbine communication attack vectors. The resulting testbed, models, and security mechanisms provide a foundation for ongoing R&D and deployment of cyber-resilient offshore wind energy systems.

17 WIND ENERGY↗

A full-scope, high-fidelity simulator-based hardware-in-the-loop testbed for comprehensive nuclear power plant cybersecurity research

Nuclear power plant (NPP) cybersecurity research often relies on hardware-in-the-loop (HIL) testbeds that integrate real hardware components into simulated environments. These testbeds allow researchers to identify vulnerabilities, evaluate attack impacts, and test security measures in a controlled setting. Furthermore, previous HIL testbeds lacked fidelity to accurately represent real nuclear systems, limiting the scope of cybersecurity analysis. This study presents the creation of a HIL testbed, devised upon a full-scope, high-fidelity NPP simulator, to facilitate realistic and comprehensive cybersecurity research. To demonstrate its capabilities, the control logic for the steam generator water level was migrated from the simulator to an external programmable logic controller. As a practical application of the developed testbed, supply chain attack scenarios were simulated by injecting malicious code into the controller logic, and the effects of manipulating sensor inputs and control commands were observed. While this HIL testbed provides more detailed simulations, enhanced realism, and wider applicability compared to other options utilizing a less complex simulator, it is also more intricate and costly. For this reason, we include a detailed comparison with some alternative architectures to aid fellow researchers and practitioners in the selection of a suitable HIL architecture based on specific research objectives.

47 OTHER INSTRUMENTATION↗

StructuredFuzzer: Fuzzing Structured Text-Based Control Logic Applications

Rigorous testing methods are essential for ensuring the security and reliability of industrial controller software. Fuzzing, a technique that automatically discovers software bugs, has also proven effective in finding software vulnerabilities. Unsurprisingly, fuzzing has been applied to a wide range of platforms, including programmable logic controllers (PLCs). However, current approaches, such as coverage-guided evolutionary fuzzing implemented in the popular fuzzer American Fuzzy Lop Plus Plus (AFL++), are often inadequate for finding logical errors and bugs in PLC control logic applications. They primarily target generic programming languages like C/C++, Java, and Python, and do not consider the unique characteristics and behaviors of PLCs, which are often programmed using specialized programming languages like Structured Text (ST). Furthermore, these fuzzers are ill suited to deal with complex input structures encapsulated in ST, as they are not specifically designed to generate appropriate input sequences. This renders the application of traditional fuzzing techniques less efficient on these platforms. To address this issue, this paper presents a fuzzing framework designed explicitly for PLC software to discover logic bugs in applications written in ST specified by the IEC 61131-3 standard. The proposed framework incorporates a custom-tailored PLC runtime and a fuzzer designed for the purpose. We demonstrate its effectiveness by fuzzing a collection of ST programs that were crafted for evaluation purposes. We compare the performance against a popular fuzzer, namely, AFL++. The proposed fuzzing framework demonstrated its capabilities in our experiments, successfully detecting logic bugs in the tested PLC control logic applications written in ST. On average, it was at least 83 times faster than AFL++, and in certain cases, for example, it was more than 23,000 times faster.

47 OTHER INSTRUMENTATION↗

CDL2PLC translator v0.1.0

The CDL-PLC translator aims at translating control sequences for building energy systems from the CDL CXF format to the PLCopen XML format. The CDL CXF developed at LBL within the OpenBuildingControl project, and now being standardized via ASHRAE Standard 231P, enables expressing control sequences developed in the simulation environment Modelica in a JSON format. The PLCopen XML is an existing exchange format standardized in IEC 61131-10 for Programmable Logic Controllers (PLCs) following the IEC 61131 standard as one target system of CDL among others. The translation from the CDL CXF to the PLCopen XML contributes to a seamless workflow from the model-based development of control sequences in simulation environments, which is not building practice today, and their digital implementation on building controllers, which replaces graphical and textual documents used for this purpose today. The translator is at a prototypical stage and enables, as a proof of concept, the translation of very simple control sequences composed of 4 selected function blocks out of 137 function blocks defined in CDL. The translation includes the connection of inputs and outputs of function blocks and the expression of a control function in CDL to the equivalent code in IEC 61131-3.

Walther, Karl↗

Hardware-Based Demonstration of Temperature Control Functions for Reactor Systems

Establishing autonomy in reactor control systems has become essential for the expansion of nuclear technologies. Thermal regulation in particular remains crucial for maintaining stable operation and ensuring the integrity of fuel. To alleviate public skepticism of the safety of nuclear reactors, demonstrating control over this key factor is pivotal. Utilizing electric heat pads to simulate the heat released in a reactor core, thermocouples for temperature monitoring, and an Arduino micro programmable logic controller (PLC) for control, a hardware-based demonstration of a reactor heating system validates the efficacy of reactor control over this key parameter. To improve precision, a proportional-integral-derivative (PID) algorithm was implemented in the heating control loop to ensure meticulous control of reactor functions. In addition, the integration of this physical system with a digital simulator tool such as RELAP5-3D establishes a foundation for a comprehensive testing environment. This allows for a refinement of temperature control under various simulated reactor conditions, bringing another layer of reliability to the operation of the system. By facilitating a physical demonstration of reactor thermal management and control strategies, this project provides a foundation for expanded testing and educational outreach. Ultimately, this system advances the broader goal of demonstrating the safety and viability of autonomous reactor operations, contributing to public trust and future reactor deployment.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Project Presentation: Hardware-Based Demonstration of Temperature Control Functions for Reactor Systems

Autonomous thermal regulation in nuclear reactors remains crucial for maintaining stable operation and ensuring the integrity of fuel. To alleviate public skepticism of the safety of nuclear reactors, demonstrating control over this key factor is pivotal. Utilizing electric heat pads to simulate the heat released in a reactor core, thermocouples for temperature monitoring, and an Arduino micro programmable logic controller (PLC) with an embedded proportional-integral-derivative (PID) algorithm for control, a hardware-based demonstration of a reactor heating system will validate the efficacy of reactor control over this key parameter. This report covers internship project presentation as well as relevant experience with nuclear and proposal for project upgrade.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Poster: Hardware-Based Demonstration of Temperature Control Functions for Reactor Systems

Autonomous thermal regulation in nuclear reactors remains crucial for maintaining stable operation and ensuring the integrity of fuel. To alleviate public skepticism of the safety of nuclear reactors, demonstrating control over this key factor is pivotal. Utilizing electric heat pads to simulate the heat released in a reactor core, thermocouples for temperature monitoring, and an Arduino micro programmable logic controller (PLC) with an embedded proportional-integral-derivative (PID) algorithm for control, a hardware-based demonstration of a reactor heating system will validate the efficacy of reactor control over this key parameter.

21 - SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLAN↗

Integrate Latimer Controls' Solution into RTAC (CRADA Final Report, CRD-23-24672)

Latimer Controls, Inc. was awarded two vouchers under the Department of Energy's American-Made Solar Prize Round 6 to conduct collaborative research at a national laboratory. The National Renewable Energy Laboratory (NREL) was selected as a partner to assist Latimer Controls in the performance evaluation of its photovoltaic (PV) control software. This collaboration focuses on developing a hardware-in-the-loop (HIL) testbed at NREL, which will be used to test and validate the Latimer PV control technology in a realistic yet de-risked environment. Both Latimer and NREL teams will work together to analyze the collected test data, derive insights, and disseminate the scientific findings. Recent studies underscore the potential of solar energy as a zero-marginal-cost and zero-emission flexibility resource within the bulk power system, particularly when integrated with advanced control systems. To enhance the performance of such systems, Latimer Controls has developed leading-edge technologies, including machine learning (ML) algorithms and hierarchical inverter set-point allocation methods. These innovations are designed to estimate the operational headroom of large PV plants for grid integration and control. However, comprehensive validation under real-world conditions remains necessary. To address this gap, the concurrent CRADA project proposes the real-world application and validation of the Latimer Control solution within a HIL environment. Initially, the Latimer algorithm was developed and tested within MATLAB Simulink, a platform suitable for research-level simulations and iterative development. However, transitioning this technology to a real solar site as an industry-ready solution necessitates implementation in a format compatible with widely used solar power plant controllers. In this additional CRADA work, the MATLAB Simulink-based logic will be translated into Structured Text, a programming language compliant with IEC 61131 standards, which is commonly used for custom logic implementations in industry-leading programmable logic controllers (PLCs), such as the Schweitzer SEL real-time automation controller (RTAC). This transition will facilitate the deployment of the Latimer Control solution in real-world solar power plants, thereby advancing the technology towards commercialization.

14 SOLAR ENERGY↗

A New Era for Modern Bubble Chamber Technology: Cooling and Real-Time Control for the MAMBA Neutrino Bubble Chamber∗

Future neutrino experiments such as DUNE will be limited less by statistics than by how well neutrino--nucleus interactions are understood, and the cleanest way to improve that understanding is to measure interactions with light nuclei such as hydrogen or deuterium. The detector best suited to the job, the bubble chamber, has not been built for a neutrino beam in about fifty years. MAMBA (Modern Adaptive Modular Bubble chamber Archetype) is a small prototype at Fermilab intended to bring the technology back with modern cryogenics and automation, cycling continuously at 1~Hz. This paper summarizes my work on two of its subsystems during a summer internship. A new solid copper thermal link brought the coldhead to 21.3~K in a commissioning cooldown, near the 20~K operating target. An Industrial Shields Raspberry Pi programmable logic controller (PLC) running OpenPLC was characterized at a median round-trip response of 0.64~ms over 20,000 trials, with 0.66\% of trials exceeding 1~ms. Both results support continuous cycling.

Williams, Nicholas [Fermilab; DuPage Coll.]↗

Real-Time Automated pH Control within Batch Processes Relying on Raman pH Measurement

Nuclear fission is an energy source that can provide consistent power with very low associated carbon emissions. However, management of the used nuclear fuel is an important aspect of the application of nuclear power. Recycling of useful components from used fuel is an attractive option, but this involves chemical processing of the fuel. Possible chemical separation technologies that might be used in this regard are sensitive to solution pH. Raman spectroscopy is a promising technique for monitoring the pH of solutions in real time. Classical pH probes are too fragile to be used in the harsh environments encountered in nuclear fuel processing. Raman probes are robust and can withstand these harsh environments to track pH. Coupled with chemometric analysis, the demonstration of the use of Raman spectroscopy to track and predict the pH in carboxylate-buffered systems is made possible. Utilizing this spectroscopy in conjunction with Programmable Logic Controllers mimics industrial control systems used in many modern industrial settings. This showcases a pragmatic approach toward leveraging Raman spectroscopy and chemometric model outputs as inputs for a real-time control system. The model to predict pH created by chemometrics proved to be successful in tracking pH. The optimal pH for TALSPEAK extraction of lanthanides and actinides from aqueous solution is known to proceed in a narrow pH range of around pH = 2.8 ± 0.1. This study uses Raman optical monitoring and automated control to return and maintain solution pH within this range after acid or base perturbations move the solution pH well outside this region. Root-mean-square errors show that pH changes measured using Raman spectroscopy on the batch process solution are reliably measured and used to automatically correct and maintain solution pH. Measurement of solution pH tracks favorably with electrochemical pH probe comparison measurements. As a result, the ability to showcase Raman spectroscopy paired with chemometrics analysis acts as a durable, better alternative data source compared to traditional pH probes to optimize the separation efficiency in the used nuclear fuel processing.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

PLC Vulnerabilities and Mitigations

Programmable Logic Controllers (PLCs) are used extensively in many high-importance industrial and nonindustrial settings including controlling elevators, manufacturing machines, and utility facilities such as power and natural gas, however cybersecurity protection for them has been neglected. Within recent years, PLCs have been put under more security scrutiny and experts have advocated for changes from the addition of protocol encryption and network segmentation to intrusion detection systems on the PLCs themselves. While PLC security is critical, a large portion of the PLCs available today will never receive these changes due to being legacy or the difficulty of overhauling the security on existing systems. Due to the infeasibility of applying many recommended security measures towards currently available machines, we aim to provide realistic and affordable best practices for hardening PLCs. We will first conduct security analysis and consider attack vectors within our target PLC. Once we’ve analyzed the device’s security, we will evaluate a variety of mitigation methods and create guidelines to effectively reduce the threat posed by PLC attacks with minimal disruption to operations.

42 ENGINEERING↗