Fostering Trust in Smart Inverters: A Framework for Firmware Update Management and Tracking in VPP Context

Thusitha Dayaratne,Carsten Rudolph,Tom Shirley,Sol Levi,David Shirley
2024-04-29
Abstract:Ensuring the reliability and security of smart inverters that provide the interface between distributed energy resources (DERs) and the power grid becomes paramount with the surge in integrating DERs into the (smart) power grid. Despite the importance of having updated firmware / software versions within a reasonable time frame, existing methods for establishing trust through firmware updates lack effective historical tracking and verification. This paper introduces a novel framework to manage and track firmware update history, leveraging verifiable credentials. By tracking the update history and implementing a trust cycle based on these verifiable updates, we aim to improve grid resilience, enhance cybersecurity, and increase transparency for stakeholders.
Cryptography and Security,Systems and Control
What problem does this paper attempt to address?
### What problems does this paper attempt to solve? This paper aims to solve the reliability and security problems faced by intelligent inverters during firmware updates in the virtual power plant (VPP) environment. Specifically, the paper focuses on the following key issues: 1. **Insufficient tracking and verification of firmware updates**: - Existing firmware update methods lack effective historical tracking and verification mechanisms, making it difficult to ensure that inverters are always running the latest firmware version without known security vulnerabilities. - For attackers, they can mimic inverters with the latest firmware version while actually running an old - version firmware with vulnerabilities. 2. **Improving grid resilience and enhancing cybersecurity**: - As distributed energy resources (DERs) are increasingly integrated into the smart grid, ensuring the security and reliability of inverters becomes crucial. This not only helps improve the resilience of the grid but also enhances cybersecurity. - By introducing verifiable credentials (VCs), the paper proposes a new framework to manage and track firmware update history, thereby establishing a more secure interaction environment. 3. **Increasing transparency**: - The proposed framework provides higher transparency for stakeholders by recording the complete firmware update history. This enables VPP operators to better assess risks and determine the level of interaction with inverters based on the update history. ### Overview of the solution To address the above problems, the paper proposes the following solutions: 1. **Firmware update tracking system based on verifiable credentials (VCs)**: - Use VCs to record and verify the history of firmware updates, ensuring that inverters are always running the latest, verified firmware version. - This method can not only prevent attackers from mimicking the latest firmware version but also provide a complete update history record for auditing and verification. 2. **Trust cycle**: - Introduce a trust cycle to establish a secure interaction between inverters and VPP operators by tracking the firmware update history. This mechanism ensures that inverters remain in a trusted state throughout their life cycle. 3. **Performance evaluation**: - Compare the proposed scheme with the existing IEEE 2030.5 - 2018/CSIP standard protocol and demonstrate its unique advantages and performance improvements through a proof - of - concept implementation. Through these measures, the paper aims to improve the security of VPP operations, enhance the resilience and transparency of the grid, and thus promote the effective management of distributed energy resources.