Abstract
Data centers are increasingly exploring dedicated,
on-site generation to address rapid load growth, interconnection
delays, and the reliability requirements of AI-scale computing.
Nuclear power ranging from the existing reactor fleet to advanced
and small modular reactor (A/SMR) designs is frequently cited
as a candidate for providing firm, low carbon energy to
these facilities through behind the meter arrangements, direct
connections, or campus-scale microgrids. Co-location can reduce
transmission constraints and accelerate deployment, but it also
creates a new class of cyber-physical interdependencies between
two critical infrastructures whose safety, reliability, and security
regimes were historically engineered and regulated separately.
This paper examines co-location architectures (grid-supplied
with nuclear power purchase agreements, behind-the-meter
arrangements, direct connections, and fully islanded microgrids)
and identifies the security-relevant seams that emerge where
operational control, jurisdiction, and threat surfaces overlap.
Drawing on recent systems studies of nuclear-powered data
center scenarios and on digital risk engineering concepts for
nuclear integrated energy systems, we develop a seam-based
threat model that highlights cross-domain attack paths. We
conclude with a set of design-time and operational controls
to reduce digital risk, clarify responsibility at regulatory
boundaries, and improve resilience against both adversarial and
non-adversarial disruptions.
on-site generation to address rapid load growth, interconnection
delays, and the reliability requirements of AI-scale computing.
Nuclear power ranging from the existing reactor fleet to advanced
and small modular reactor (A/SMR) designs is frequently cited
as a candidate for providing firm, low carbon energy to
these facilities through behind the meter arrangements, direct
connections, or campus-scale microgrids. Co-location can reduce
transmission constraints and accelerate deployment, but it also
creates a new class of cyber-physical interdependencies between
two critical infrastructures whose safety, reliability, and security
regimes were historically engineered and regulated separately.
This paper examines co-location architectures (grid-supplied
with nuclear power purchase agreements, behind-the-meter
arrangements, direct connections, and fully islanded microgrids)
and identifies the security-relevant seams that emerge where
operational control, jurisdiction, and threat surfaces overlap.
Drawing on recent systems studies of nuclear-powered data
center scenarios and on digital risk engineering concepts for
nuclear integrated energy systems, we develop a seam-based
threat model that highlights cross-domain attack paths. We
conclude with a set of design-time and operational controls
to reduce digital risk, clarify responsibility at regulatory
boundaries, and improve resilience against both adversarial and
non-adversarial disruptions.
| Original language | American English |
|---|---|
| State | Published - Mar 16 2026 |
| Event | Twentieth IFIP Working Group 11.10 International Conference on Critical Infrastructure Protection - , Singapore Duration: Mar 16 2026 → Mar 17 2026 |
Conference
| Conference | Twentieth IFIP Working Group 11.10 International Conference on Critical Infrastructure Protection |
|---|---|
| Country/Territory | Singapore |
| Period | 03/16/26 → 03/17/26 |
Keywords
- Critical Infrastructure Protection
- data centers
- small modular reactors
- microreactors
- behind-the-meter
- microgrids
- cyber-physical security
- digital risk engineering
- regulation
- jurisdiction
- co-location
INL Publication Number
- INL/CON-26-89791
- 211749
Fingerprint
Dive into the research topics of 'Security and Jurisdictional Seams in Co-locating Data Centers with Nuclear Power Generation'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver