APL-探索浪潮_去中心化电网的弹性策略(英)-2025_156页_2mb
报告摘要
Summary of "Resilience Strategies for the Decentralizing Grid"
Core Content
The document "Resilience Strategies for the Decentralizing Grid" discusses the security challenges and opportunities arising from the transformation of the US electric grid towards decentralization. It highlights the role of distributed energy resources (DERs), energy storage systems (BESS), and decentralized control mechanisms in reshaping the grid's architecture. While these advancements offer significant benefits for reliability and resilience, they also introduce new vulnerabilities that must be addressed to protect the grid from cyber threats, especially from the People's Republic of China (PRC).
Main Points
-
Decentralization and Resilience: The decentralization of power generation, storage, and control systems is creating a more resilient grid. By increasing the number of targets, it complicates adversarial attack planning. Advanced batteries and their grid-forming capabilities can aid in power restoration after outages.
-
Supply Chain Risks: The US grid is heavily reliant on components from the PRC, which poses a serious risk. The document recommends prohibiting the purchase of products identified as catastrophic risks and implementing a phased approach to ensure the reliability of the grid through domestic alternatives.
-
Cybersecurity Gaps: Current cybersecurity standards for DERs lag behind the rapid deployment of digital and AI-enabled technologies. Voluntary guidelines are insufficient, and the US needs to enforce mandatory cybersecurity requirements to secure these systems.
-
Attack Vectors: The document emphasizes the need to address "Living off the Land" (LotL) attacks, where adversaries exploit existing systems to cause wide-area outages. It also warns about the risks of load manipulation through electric vehicles and IoT devices.
-
Deterrence by Denial: The US should leverage AI-enabled microgrids and advanced power restoration systems to deny the benefits that adversaries seek from attacking the grid. This approach can help deter cyberattacks by making the consequences more severe for attackers.
-
Role of AI: AI is playing a crucial role in managing decentralized grid operations, offering tools for coordination and reliability. However, it also introduces new attack surfaces that need to be secured.
Key Information
-
Decentralized Generation: DERs such as solar, wind, and battery systems are becoming more prevalent, with inverter-based resources (IBRs) making up 85% of new generation under development. These systems are more numerous and geographically dispersed than traditional power sources.
-
Energy Storage Growth: Battery energy storage systems (BESS) are expanding rapidly, with the EIA projecting a near doubling in 2024 and reaching 40 gigawatts in 2025. BESS are critical for managing intermittency from renewable sources and aiding in power restoration.
-
Decentralized Control: The rise of DERMS and VPPs is enabling more flexible control of power flows, but it also introduces complexity and new cybersecurity challenges. AI is being used to enhance grid management, but its integration requires robust security measures.
-
Cybersecurity Challenges: The integration of digital technologies and the lack of enforceable cybersecurity standards for DERs and distribution systems create significant vulnerabilities. Adversaries can exploit these to cause widespread outages and disrupt critical infrastructure.
-
Regulatory Framework: The BPS is regulated by NERC and FERC, which have established cybersecurity standards. However, local distribution systems lack similar mandatory requirements, leading to a regulatory gap that must be addressed.
Recommendations
-
Prohibit High-Risk Products: Implement prohibition orders for products identified as posing catastrophic risks to the grid, especially those from the PRC.
-
Secure by Design: Ensure that DERs and IBRs are secured by design, with layered defenses to mitigate LotL attacks and other cyber threats.
-
Enhance Load Security: Address the risks of load manipulation by integrating and accelerating measures to secure controllable loads such as electric vehicles and IoT devices.
-
Enforce Cybersecurity Standards: Develop and enforce mandatory cybersecurity standards for DERs and distribution systems, especially for energy aggregators and VPPs.
-
Leverage AI for Resilience: Use AI to enhance grid resilience and deter attacks by improving the grid's ability to respond and restore power quickly.
-
Strengthen Cloud Security: Implement robust cloud security measures to protect against adversarial exploitation of cloud-based management systems.
Conclusion
The transformation of the US grid is inevitable and offers numerous benefits. However, it also brings new security challenges that must be proactively managed. The US must adopt a comprehensive, risk-based cybersecurity strategy to secure the evolving grid and deter adversarial attacks. This strategy should focus on both enhancing the resilience of the grid and shaping its evolution to minimize the benefits adversaries can gain from attacking it.
试读结束,高清完整版pdf/doc/ppt,请点下载