The digitalization and decentralization of the electric power grid are key thrusts towards an economically and environmentally sustainable future. Towards this goal, distributed energy resources (DER), including rooftop solar panels, battery storage, electric vehicles, etc., are becoming ubiquitous in power systems, effectively replacing fossil-fuel based generation. Power utilities benefit from DERs as they minimize transmission costs, provide voltage support through ancillary services, and reduce operational risks via their autonomous operation. Similarly, DERs grant users and aggregators control over the power they produce and consume. Apart from their sustainability and operational objectives, the cybersecurity of DER-supported power systems is of cardinal importance. DERs are interconnected, interoperable, and support remotely controllable features, thus, their cybersecurity should be thoroughly considered. DER communication dependencies and the diversity of DER architectures (e.g., hardware/software components of embedded devices, inverters, controllable loads, etc.) widen the threat surface and aggravate the cybersecurity posture of power systems. In this work, we focus on security oversights that reside in the cyber and physical layers of DERs and can jeopardize grid operations. We analyze adversarial capabilities and objectives when manipulating DER assets, and then present how protocol and device -level vulnerabilities can materialize into cyberattacks impacting power system operations. Finally, we provide mitigation strategies to thwart adversaries and directions for future DER cybersecurity.
翻译:电力电网的数字化和分散化是通向经济和环境上可持续的未来的关键动力。为实现这一目标,分配的能源资源(DER),包括屋顶太阳能板、电池储存、电动车辆等,正在成为电力系统中无处不在的能源,有效取代化石燃料发电;电力公用事业受益于DERs,因为它们最大限度地降低了传输成本,通过辅助服务提供电压支持,并通过自主运作减少业务风险;同样,DERs给用户和聚合器提供对其生产和消费的电力的控制。除了可持续性和业务目标外,DERs支持的电力系统的网络安全至关重要。DERs相互连接、互操作、支持远程控制功能,因此,应彻底考虑其网络安全;DERs通信依赖和DERs结构的多样性(例如,嵌入装置的硬件/软件组成部分,可控制负荷等),扩大威胁表面,并加剧电力系统的网络安全态势。我们在此工作中,除了其可持续性和业务目标外,DERS支持的电力系统的网络和实体安全监督至关重要。DERs是相互联系、相互操作、相互操作、支持远程控制功能,因此,应当彻底考虑其网络安全;DERs通信依赖和电网结构结构结构结构结构结构结构结构结构结构,从而破坏我们如何分析和电路流能和电路能。