OPERANT NETWORKS, INC. — Department of Energy SBIR Phase II: 12b

OPERANT NETWORKS, INC. — SBIR Phase II award from Department of Energy.

Amount
$999,580
Agency
Department of Energy
Program / Phase
SBIR · Phase II
Topic
12b
Solicitation
DE-FOA-0001976
NAICS
Place of performance
CA
Period
2019-08-19 → 2021-08-18

Description

Historically, large scale power generation assets have been protected from cyberattack through isolation: carefully managed proprietary communications networks and physical access control.However, it is extremely difficult and effort-intensive to maintain totally isolated Industrial Control Systems in this era of connected devices.As power generation assets shift from a few large centralized power plants to numerous smaller-scale and geographically distributed resources such as solar, it is simply impractical to continue the methodology of securing communications via disconnection and new techniques must be developed.In concert with the shift in power generation technology, the smart grid will additionally require the interconnection of massive numbers of heterogeneous devices produced by multiple vendors at low cost.To coordinate these assets, we will need to solve this distributed cybersecurity problem in a radically different manner: we have therefore developed novel networking software, built around modern cryptographic principles, to bring strong security throughout the entirety of the new solar energy powered grid, from the central control room to the solar inverters in the field.Our Phase I project investigated cybersecurity protection of utility-scale solar energy systems that are connected to the public internet and we successfully demonstrated the key technology building blocks.We integrated a novel networking protocol with a next generation blockchain to create a distributed data ledger that cannot be modified, destroyed, or repudiated.The ledger not only stores the history of all network transactions, such as data queries and control commands, but also supports a highly available certificate revocation process to ensure that every node has access to current cyber certificates.Most importantly, we demonstrated how this technology stack provides the necessary secure communications for a highly distributed cyber intrusion detection system, which can remain functional and resilient under an ongoing cyber-attack or natural disaster.These building blocks were initially demonstrated independently; in Phase II, working with industry partners, we will define and integrate a functional and integrated prototype deployable in a real-world utility-scale solar plant.Providing a functional distributed intrusion detection system, as well as secure networking and data ledger, we will demonstrate next generation layered, defense-in-depth, cybersecurity.The current state of cybersecurity in utility solar is defined by legacy regulatory standards largely intended for fossil fuel plants.For systems sized over 75MW, NERC-CIP standards for ‘Low’ risk facilities are applied; these require only minimum effort such as an onsite firewall.For smaller systems, cybersecurity protocols are left to the discretion of the operator.However, a coordinated attack on multiple solar sites could destabilize the entire regional grid, suggesting current policy is insufficient.Industry people we spoke with that adversary nation states have already infiltrated our critical energy infrastructure but have not had a good reason yet to launch an attack.We therefore see significant benefit to the public, as well as large commercial potential, in our proposed intrusion detection and response system.Industry experts we have polled agree that we must immediately begin development of cybersecurity technology and deploy it in the next few years.