National labs eye cybersecurity threats to smaller nuclear reactors
As states like Utah make moves to be at the forefront of the “nuclear renaissance” race, a neighboring research lab is working on ways nuclear reactors, which are becoming smaller, can be shielded from cyberattacks with help from industry experts and academics.
The Idaho National Laboratory, a U.S. Department of Energy nuclear research institution, is taking ideas from similar programs like the Oak Ridge National Laboratory in Tennessee, which may not have a deep background in cybersecurity for nuclear but does have expertise in other operations, including energy grid, water and wastewater.
The lab hosted a nuclear cybersecurity summit in Park City looking to spur developers to start incorporating security frameworks into their reactors’ designs. The researchers aren’t expecting the effort to take cybersecurity risks down to zero, said J’Tia Hart, Idaho National Lab nuclear nonproliferation director, but to create a methodology that aims to cause as little disruption as possible.
“So really trying to push that methodology while the reactor designers are actually in the design phase, instead of thinking about it later after you’ve built this brand new shiny car,” Hart said. “It’s like building the Ferrari and thinking after you’re racing it down the road, ‘what about the brakes?’ You know, we want to think about the brakes before we build the car.”
Physical security systems exist for traditional, big, nuclear reactors, often referred to as “guns, gates and guards,” Hart said. Those protection systems ensure that nuclear materials are used as intended. But, it is still under debate whether those thorough physical systems will be applicable for small modular reactors, which will probably be closer to population centers.
“We have to figure out what is that going to be and how much is required, and there will probably be more communication channels with the small modular reactors than there are with the traditional reactors we employ today,” said Mason Rice, director of the Cyber Resilience and Intelligence Division at Oak Ridge National Laboratory.
Now that the cybersecurity technologies for nuclear energy are still in development, researchers are anticipating new features that may be coming online, including autonomous or digital controls that could replace analog systems that are currently in place.
Rice said that as of now, experts are looking at threats other industrial control systems face.
Imagine a garage door opener, he said. A bad actor could either break it via its cyber system, or manipulate its status view on a controller, so, say, it could tell the user the door is closed when it is actually open. Hackers could also hack a Wi-Fi network to open or close the door, and “perhaps the most nefarious thing you can do is disable the safety mechanisms,” he said.
“What we try to do is try to figure out how to stop adversaries from doing all four of those things,” Rice said. “And it almost doesn’t matter whether it’s a water plant, wastewater plant, the electric grid, or a nuclear reactor … you want to make sure that all of those things are functioning the way they’re supposed to do.”
While some of the solutions could be generic, there’s an aspect that’s unique to nuclear reactors, Rice said — fear.
“We want to build it in such a way that if somebody does attack them, the physics involved actually prevent something bad from happening,” he said. “So no matter what you do via cyber, at worst the plant gets shut off without any external harm.”
In the case of water systems, for example, one of the worst things a hacker could do is to manipulate the system to overchlorinate it. But, there are solutions to prevent that from happening.
“A cyber-informed engineering technique would be don’t fill up the chlorine container beyond a certain amount because if somebody hacks it, only so much chlorine can get into the system. So if you physically limit it, you can’t cause any real harm,” Rice said. “And so we’re trying to look for techniques like that on the nuclear side to make sure that the physics of whatever is involved can’t possibly be manipulated by cyber to cause harm.”
Nuclear development companies are showing interest in the research advances, including Blue Energy, a startup that’s looking at how to build nuclear power plants in a more efficient way. The company is working on establishing a partnership with the Idaho National Lab to research support systems and infrastructure adjacent to nuclear plants.
Tom O’Neill, chief commercial officer at Blue Energy said the company hopes to support a prototype that would help the industry implement cybersecurity protections, and to test potential vulnerabilities.
“We’re in the early stages of talking with Idaho National Lab about that, but I would say in the next several months we should have a structure set up,” O’Neill said.