ModuleOT: A Hardware Security Module for Operational Technology: Preprint

Research output: Contribution to conferencePaper

Abstract

With increasing penetration levels of distributed energy resources (DERs) on the distribution grid, as well as new technological advancements in the cyber space, new cyberattack vectors are being introduced, and the available attack surface is constantly increasing. Despite this increasing risk, the standard IEEE 1547-2018 does not yet recommend cybersecurity measures for DERs. To address this and to better protect data on the distribution grid - from the standpoints information security as well as operational security - ModuleOT has been developed. The module aims to significantly reduce cyberattack vectors by improving data privacy for user applications. This is accomplished by performing the core functions of encryption, authentication, authorization, certificate management, and user access control. The module integrates a custom security application with hardware cryptographic acceleration. The application secures all communications using Transmission Control Protocol over Internet Protocol (TCP/IP). These include the three most commonly used communications protocols for power systems information exchange: Modbus, Distributed Network Protocol 3 (DNP3), and Smart Energy Profile 2.0 (SEP2.0). These three protocols are also supported by IEEE 1547-2018 for all DER devices. This paper tests the data encryption/decryption feature on a physical networking test bed with emulated Modbus devices reporting grid data and presents the results.
Original languageAmerican English
Number of pages9
StatePublished - 2020
EventIEEE Texas Power and Energy Conference (TPEC) - College Station, Texas
Duration: 6 Feb 20207 Feb 2020

Conference

ConferenceIEEE Texas Power and Energy Conference (TPEC)
CityCollege Station, Texas
Period6/02/207/02/20

Bibliographical note

See NREL/CP-5R00-77159 for paper as published in IEEE proceedings

NREL Publication Number

  • NREL/CP-5R00-74697

Keywords

  • cyber security
  • DNP3
  • encryption
  • Modbus
  • SCADA
  • smart grid

Fingerprint

Dive into the research topics of 'ModuleOT: A Hardware Security Module for Operational Technology: Preprint'. Together they form a unique fingerprint.

Cite this