A security analysis method and system for out-of-band electromagnetic vulnerability of photovoltaic inverters

By constructing the attack flow model of photovoltaic inverter and the vulnerability analysis of control algorithms, the out-of-electromagnetic vulnerability threat of photovoltaic inverter is solved, and the security risk analysis of photovoltaic inverter is realized, providing a theoretical basis for defense, and ensuring the security of the smart grid.

CN117040134BActive Publication Date: 2025-08-08ZHEJIANG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311143022.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-09-05
Publication Date
2025-08-08
Estimated Expiration
2043-09-05

AI Technical Summary

Technical Problem

Due to its distributed characteristics and open installation environment, photovoltaic inverters are vulnerable to off-electromagnetic vulnerability attacks, resulting in sensor actuators' perception and execution errors, threatening the safety of equipment, and the existing technology lacks effective security analysis methods.

Method used

Establish a security analysis method for the off-tape vulnerability of photovoltaic inverters, and provide theoretical basis for defense by building an attack flow model, mining off-tape vulnerability, analyzing malicious signal injection and control algorithm vulnerabilities.

Benefits of technology

A comprehensive security risk analysis of the fragility of photovoltaic inverters outside the electromagnetic tape was achieved, and the attack path and consequences were clarified, providing a theoretical basis for defense measures, and ensuring the safety of the smart grid.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117040134B_ABST
    Figure CN117040134B_ABST
Patent Text Reader

Abstract

The present invention discloses a security analysis method and system for the electromagnetic out-of-band vulnerability of photovoltaic inverters, belonging to the field of smart grid network security. First, based on the data link of the photovoltaic inverter's voltage and current sensing link, the present invention establishes an attack flow model for manipulating the sensor values of the photovoltaic inverter using the electromagnetic out-of-band vulnerability. Second, based on the control characteristics of the photovoltaic inverter and the attack flow model for manipulating the sensor values of the photovoltaic inverter using the electromagnetic out-of-band vulnerability, the present invention explores the electromagnetic out-of-band vulnerability and implements a security analysis of the electromagnetic out-of-band vulnerability of the photovoltaic inverter, guided by the photovoltaic inverter's functions. The present invention proposes a security risk analysis method for the new electromagnetic out-of-band vulnerability of the photovoltaic inverter, providing a theoretical basis for defending against cross-domain threats to the photovoltaic inverter. The analysis results can be used to provide guidance to decision makers in selecting and choosing defensive measures.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of smart grid network security, and in particular relates to a security analysis method and system for out-of-electromagnetic-band vulnerabilities of photovoltaic inverters. Background Art

[0002] To mitigate the increasingly serious problems of global warming and climate change, the emission of greenhouse gases such as CO2 has attracted increasing attention. Excessive fossil fuel consumption is one of the main culprits of greenhouse gas emissions. To address these issues, the traditional power industry, which relies primarily on fossil fuel combustion for power generation, is turning to more sustainable power generation methods, such as distributed energy generation, hydropower, and biomass power generation.

[0003] Power system cybersecurity is crucial for ensuring access to electricity for residents. Once a power system is attacked, the consequences are often severe. However, the emergence of a large number of photovoltaic power generation equipment has posed new threats to power system security. Due to the distributed nature of photovoltaic panels, photovoltaic inverters are often installed in diverse and open environments. They can be found in private homes, on commercial building rooftops, in photovoltaic power plants, and elsewhere. Compared to the centralized, closed environments of traditional thermal and hydropower plants, photovoltaic equipment, especially photovoltaic inverters, is more accessible to attackers. Furthermore, the presence of a variety of people in these settings, including residents, tourists, and employees, makes attackers more difficult to detect and track. This significantly increases the risk of new cross-domain physical information threats, such as electromagnetic injection attacks.

[0004] Electromagnetic out-of-band vulnerabilities are a new type of cross-domain attack threat. Attackers can use malicious electromagnetic means to inject malicious signals into victim devices, exposing vulnerabilities beyond the design scope of the device's sensing and execution processes. This can cause sensor and actuator errors, ultimately compromising device security. While this security threat doesn't require physical contact with the device, it does require the attacker to be in close proximity. Therefore, the distributed nature of photovoltaic inverters significantly increases the risk of cross-domain physical information threats. To address these issues, a security analysis of cross-domain physical information threats in photovoltaic inverters is urgently needed to provide a theoretical basis for photovoltaic inverter security protection and ensure the security of the entire smart grid. Summary of the Invention

[0005] To solve the above problems, the present invention starts from the photovoltaic inverter model and establishes the entire attack chain of new cross-domain threats such as electromagnetic out-of-band vulnerability from malicious signal injection to the impact on the control algorithm.

[0006] The present invention first constructs a photovoltaic inverter perception link model, and uses the model to establish an attack flow model for cross-domain electromagnetic threat device injection to obtain the electromagnetic out-of-band vulnerability utilization mechanism; at the same time, according to the control algorithm of the photovoltaic inverter and guided by the photovoltaic inverter function, the electromagnetic out-of-band vulnerability is explored, that is, the algorithm vulnerabilities that may be exploited by cross-domain attacks are explored, and the security analysis of the electromagnetic out-of-band vulnerability of the photovoltaic inverter is realized, providing a theoretical basis for the cross-domain defense of the photovoltaic inverter physical information.

[0007] In order to achieve the above object, the present invention adopts the following technical solutions:

[0008] A first object of the present invention is to provide a method for security analysis of out-of-band electromagnetic vulnerabilities of photovoltaic inverters, comprising the following steps:

[0009] 1) Based on the data link of the PV inverter voltage and current sensing link, an attack flow model is established to manipulate the sensor values of the PV inverter by exploiting the out-of-band electromagnetic vulnerability;

[0010] 2) Based on the control characteristics of the photovoltaic inverter and the attack flow model that uses electromagnetic out-of-band vulnerabilities to manipulate the values of photovoltaic inverter sensors, the electromagnetic out-of-band vulnerabilities are explored with the photovoltaic inverter function as the guide, and security analysis of the electromagnetic out-of-band vulnerabilities of the photovoltaic inverter is achieved.

[0011] Furthermore, the step 1) includes:

[0012] 1.1) Based on the data link of the internal voltage sensing link of the photovoltaic inverter, an attack flow model is established to manipulate the voltage sensor value of the photovoltaic inverter by exploiting the out-of-band vulnerability;

[0013] 1.2) Based on the data link of the internal current sensing link of the photovoltaic inverter, an attack flow model is established to manipulate the current sensor value of the photovoltaic inverter by exploiting the out-of-band vulnerability.

[0014] Furthermore, the attack flow model for manipulating the value of the photovoltaic inverter voltage sensor by exploiting the electromagnetic out-of-band vulnerability is specifically as follows:

[0015] a. Electromagnetic coupling: Different lengths of conductive loops on the victim circuit board are equivalent to different inductors, resulting in different electromagnetic wave resonant frequencies. This creates the risk that an attacker could couple electromagnetic attack signals into different nodes of the victim sensor circuit by selecting different frequencies.

[0016] b. Rectification process: The amplifier contains transistors with positive and negative junctions that can limit the current to a single conduction, thereby rectifying the input signal transmitted in the circuit;

[0017] c. Amplification and filtering process: The electromagnetic signal injected into each node of the victim circuit will be amplified by the amplifier circuit and converted into a DC bias by the filtering circuit in the amplifier circuit and the filter in the analog-to-digital converter.

[0018] Furthermore, the attack flow model for manipulating the current sensor value of a photovoltaic inverter by exploiting the electromagnetic out-of-band vulnerability is specifically as follows:

[0019] a. Malicious electromagnetic signals are directly coupled to the op amp circuit of the current sensing link, exposing the current sensing module to the same attack risks as voltage sensing.

[0020] b. The malicious electromagnetic signal is superimposed on the magnetic field generated by the measured current, generating noise at the output of the Hall sensor, which is then rectified and amplified by the amplifier circuit.

[0021] Furthermore, the step 2) includes:

[0022] 2.1) Exploring vulnerabilities in the maximum power point tracking algorithm aimed at reducing the output power of photovoltaic inverters;

[0023] 2.2) Exploring voltage control loop vulnerabilities that cause abnormal bus voltage in photovoltaic inverters;

[0024] 2.3) Exploring vulnerabilities in the current control loop that may cause abnormal output current of the photovoltaic inverter.

[0025] Furthermore, in the maximum power point tracking algorithm vulnerability mining aimed at reducing the output power of photovoltaic inverters, the MPPT algorithm vulnerability includes: injecting a false UI curve into the photovoltaic voltage / current sensor, and its maximum power point tracking algorithm finds an erroneous maximum power point, resulting in a reduction in the output power of the photovoltaic inverter.

[0026] Furthermore, in the voltage control loop vulnerability mining aimed at causing abnormal bus voltage of photovoltaic inverters, the voltage control loop vulnerability includes: injecting a false voltage signal into the DC bus voltage sensor, causing the DC bus voltage to be controlled at a false voltage value determined by the injected signal instead of the set normal voltage, resulting in damage to inverter components or abnormal shutdown of the inverter.

[0027] Furthermore, in the current control loop vulnerability mining directed at causing abnormal output current of the photovoltaic inverter, the current control loop vulnerability mining includes: injecting time-varying false signals into the grid voltage / current sensor, so that the entire control loop cannot enter a steady state and cause system oscillation, resulting in abnormal shutdown of the inverter.

[0028] A second object of the present invention is to provide a security analysis system for out-of-band electromagnetic vulnerabilities of photovoltaic inverters, comprising:

[0029] An attack flow model construction module is used to construct a photovoltaic inverter perception link model. Through the photovoltaic inverter perception link model, an attack flow model is established that uses electromagnetic out-of-band vulnerabilities to manipulate photovoltaic inverter sensor values;

[0030] The electromagnetic out-of-band vulnerability mining module is used to mine electromagnetic out-of-band vulnerabilities based on the control characteristics of photovoltaic inverters and the attack flow model that uses electromagnetic out-of-band vulnerabilities to manipulate the values of photovoltaic inverter sensors. It is guided by the functions of photovoltaic inverters and realizes security analysis of the electromagnetic out-of-band vulnerabilities of photovoltaic inverters.

[0031] The present invention has the following beneficial effects:

[0032] (1) This paper conducts a security analysis of cross-domain electromagnetic out-of-band threats targeting photovoltaic inverters from two aspects: malicious electromagnetic signal injection and control algorithm vulnerability exploitation. It explains the entire attack process from sensor to control by exploiting electromagnetic out-of-band vulnerabilities, and realizes a complete and comprehensive security risk analysis of the electromagnetic out-of-band vulnerabilities of photovoltaic inverters.

[0033] (2) This paper analyzes the data link of the photovoltaic inverter voltage and current sensing link in detail, constructs an attack flow model of the electromagnetic out-of-band vulnerability of the photovoltaic inverter voltage and current sensing link, clarifies how malicious electromagnetic cross-domain threats attack the sensors of the photovoltaic inverter, and provides a theoretical basis for blocking electromagnetic out-of-band vulnerabilities;

[0034] (3) The present invention also analyzes the control algorithm of the entire photovoltaic inverter, taking each sensor as the entry point and the inverter logic function as the guide, and conducts a security risk analysis on the algorithm vulnerabilities that may be exploited by attackers in the maximum power point tracking algorithm, voltage control loop, and current control loop in the control algorithm, providing a theoretical basis for vulnerability repair and detection;

[0035] (4) The present invention provides a complete risk analysis solution, which not only clarifies the attack path of physical information cross-domain threats in the photovoltaic inverter sensor unit, but also analyzes how physical malicious signal injection exploits vulnerabilities in the information domain control algorithm to cause damage, and clarifies the consequences of the attack. Decision makers can use this analysis to protect photovoltaic inverters against key links of physical information cross-domain threats. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] Figure 1 It is the basic structure of the differential amplifier circuit;

[0037] Figure 2 It is the attack flow model of the voltage perception link where malicious electromagnetic signals are injected;

[0038] Figure 3 It is the attack flow model of the current sensing link where malicious electromagnetic signals are injected;

[0039] Figure 4 This is the consequence analysis of the false UI curve injection vulnerability;

[0040] Figure 5 It is a false UI curve injection vulnerability model;

[0041] Figure 6 This is the voltage control loop diagram of the photovoltaic inverter;

[0042] Figure 7 This is the current control loop diagram of the photovoltaic inverter. DETAILED DESCRIPTION

[0043] The present invention will be further described below with reference to the accompanying drawings.

[0044] This paper first provides a security analysis method for the out-of-band electromagnetic vulnerability of photovoltaic inverters. By analyzing the data link of the photovoltaic inverter's internal sensing link, a malicious electromagnetic injection attack flow model for the photovoltaic inverter's sensing link is established. Based on the sensitive frequency characteristics of different sensors in the photovoltaic inverter, a numerical method for independent control of photovoltaic inverter sensors is established. The detailed steps are as follows:

[0045] 1) Attack flow model for manipulating the voltage sensor value of photovoltaic inverters using electromagnetic out-of-band vulnerabilities

[0046] The function of the voltage sensing link is to detect the controlled voltage and convert it into a readable output signal for reading by the analog to digital converter (ADC) module. Generally speaking, considering the size and cost, the voltage divider resistor is the most commonly used voltage sensor structure in photovoltaic inverters. In addition, the higher frequency dv / dt in the power electronics system often generates common-mode noise in the circuit. The differential operational amplifier circuit, also known as the subtraction input operational circuit, has a suppressive effect on common-mode signals. Therefore, it is often used to amplify signals containing common-mode interference. The basic structure of the differential operational amplifier circuit is as follows: Figure 1 As shown, the magnification can be expressed as:

[0047]

[0048] Under normal circumstances, the amplification factor is only related to the resistance of the peripheral circuit.

[0049] In the voltage sensing link, the operational amplifier circuit in the printed circuit board (PCB) contains many loops, which can be invaded by certain malicious electromagnetic signals and thus maliciously exploited by attackers to deceive the sensor values that ultimately enter the microcontroller unit (MCU). The present invention analyzes the malicious electromagnetic signal injection process and establishes an electromagnetic signal attack flow model. Among them, the voltage sensing link attack flow model is as follows: Figure 2 As shown, the main process can be divided into:

[0050] a. Electromagnetic Coupling Process: Faraday's law of electromagnetic induction states that a change in magnetic flux in an induction loop generates an induced current, which is proportional to the change in magnetic flux per unit time. When the transmitter and receiver circuits resonate simultaneously, the reactance of the coil circuits at both ends is zero, and most of the energy is transferred from the transmitter to the receiver. Conductive loops of varying lengths on the victim circuit board are equivalent to varying inductances, resulting in different electromagnetic wave resonant frequencies. Therefore, an attacker can select different frequencies to inject electromagnetic attack signals into different nodes of the victim sensing circuit.

[0051] b. Rectification process: Because amplifiers typically contain transistors with positive and negative (PN) junctions, they can limit the current to a single conduction mode, thereby rectifying the input signal transmitted in the circuit. In this way, the voltage sensing link converts the AC signal injected into the sensor circuit into a DC voltage / current signal.

[0052] c. Amplification and filtering: The electromagnetic signal injected into each node of the victim circuit is amplified by the amplifier circuit's amplitude adjustment and common-mode noise elimination. Furthermore, the filtering circuit in the amplifier circuit and the software filter in the ADC reduce the fluctuations of the attack signal and convert it into a DC offset.

[0053] Through the above steps, the attack flow model of the voltage perception link is established.

[0054] 2) Attack flow model for manipulating the current sensor value of photovoltaic inverters using electromagnetic out-of-band vulnerabilities

[0055] Generally speaking, current cannot be measured directly. The current measurement methods mainly include: First, the shunt measurement method based on Ohm's law. This method has large losses when measuring large currents and requires electrical insulation measures. Therefore, it is suitable for small current scenarios and is rarely used in photovoltaic inverters. The other is a non-contact measurement method based on Ampere's law. Hall current sensors are the main solution for this method because they have high accuracy, high linearity and high bandwidth. Its principle is:

[0056] First, assume that the current to be measured generates a magnetic field of strength B, which passes through the plates. According to Ampere's law, the magnetic field strength B generated by the current-carrying conductor is proportional to the magnitude of the current I and can be expressed as:

[0057] B∝I

[0058] According to Lorentz's law, the Lorentz force F acting on a moving charge in a magnetic field is L Proportional to the magnetic field strength B:

[0059] F L ∝B∝I

[0060] At the same time, the charges in the Hall sensor are subjected to the electric field force F E The voltage V between the two ends of the electrode plate inside the Hall sensor H is proportional to, which can be expressed as:

[0061] F E ∝V H

[0062] When F L =F E According to the previous formula, we can get V H Proportional to the current I in the nearby wire, that is, V H ∝I

[0063] This is the process of the Hall current sensor converting the current signal into a voltage signal in a non-contact manner. After converting the current signal into a voltage signal, the op amp will convert the voltage signal V H Amplification, the same principle as the voltage sensing unit.

[0064] Therefore, the current sensing link of the photovoltaic inverter includes a Hall sensor and a differential op amp circuit, that is, compared with the voltage sensing link, a Hall sensor part is added. This makes the magnetic signal transmitted by the Hall sensor part of the current sensing link also vulnerable to interference from external malicious signals. Therefore, when an attacker transmits a malicious signal, there are two possible attacks: first, the malicious electromagnetic signal may be directly coupled to the op amp circuit of the current sensing link, and the current sensing module may be attacked in the same way as the voltage sensing module; second, the malicious signal may be superimposed on the magnetic field generated by the measured current, and the output V H The noise is generated at the current sensing point, which is then rectified and amplified by the amplifier circuit. The process of using malicious electromagnetic signals to attack the current sensing link is as follows: Figure 3 We will focus on the second attack type.

[0065] As mentioned in the previous section, the output of the Hall sensor V H is proportional to the internal magnetic field B as shown below,

[0066] VH =k·B

[0067] Where k is a coefficient determined by the Hall sensor itself.

[0068] When the attacker sends the malicious signal magnetic field B A When injecting into the Hall sensor, you can get:

[0069] V′ H =k·(B+B A )=V H +k·B A

[0070] The output of the Hall sensor will change k·B A Therefore, the attacker can adjust the transmitted magnetic signal B A To control the output of the Hall sensor.

[0071] The first type of attack is similar to the voltage sensing attack and will not be described here.

[0072] Based on the above content, the attack flow model of the current sensing link is established.

[0073] The present invention then provides a security risk analysis system for photovoltaic inverter control algorithm vulnerabilities, which is used to analyze how cross-domain threats actually cause damage to the inverter after malicious electromagnetic signal injection.

[0074] The photovoltaic inverter mainly has photovoltaic voltage and current sensors V pv , I pv , bus voltage sensor V dc , grid voltage and current sensor V abc , I abc Three types of sensors, acting as inputs, impact the inverter's voltage loop, current loop, and maximum power point tracking (MPPT) module. This paper analyzes and explores potential vulnerabilities in control algorithms caused by the deception of these three types of sensors. Guided by the actual inverter's functionality, this paper establishes a security risk analysis system for photovoltaic inverter control algorithms.

[0075] 1) MPPT algorithm vulnerability mining aimed at reducing the output power of photovoltaic inverters

[0076] The photovoltaic voltage and current sensor mainly affects the MPPT algorithm and the pre-stage DC / DC control. Because it is closely related to the MPPT module, it is easy to imagine that an attacker could deceive the photovoltaic voltage and current sensor to reduce the output power of the photovoltaic panel. However, an attacker cannot change the output power by simply injecting a constant malicious signal. Figure 4As shown in (a), injecting a constant malicious signal into the photovoltaic voltage and current sensors will only cause the photovoltaic UI curve received by the MCU to shift to the right or upward. Taking the current sensor as an example, injecting a constant electromagnetic signal into the current sensor of the photovoltaic inverter will only cause all current values on the curve to add the value injected by the attack, that is,

[0077] I′=I+I a

[0078] Among them, I' is the current value after the attack, I is the actual current value, and I a It is the attack signal stacking value.

[0079] This is reflected in the UI curve, which is to lift the entire curve upward by I a This will cause the MPPT algorithm to misjudge the maximum power point (MPP) current (I max +I a ), but it will still find the correct MPP point (the actual current is still I max ), the output power does not change.

[0080] In fact, if the attacker wants to change the MPP found by the MPPT algorithm, he must inject a fake UI curve into the sensor, such as Figure 4 As shown in (b), this will cause the MPPT algorithm to find a false MPP and its corresponding voltage U f Obviously, this voltage U f Not the MPP voltage U max , the output power will decrease accordingly.

[0081] The false UI curve injection vulnerability targeting the MPPT algorithm is mainly as follows:

[0082] a. The prerequisite for completing the false UI curve injection is to prepare the UI / UP curve of the photovoltaic panel in advance, such as Figure 5 As shown in Figure 1, this can usually be obtained by consulting the product manual of the photovoltaic panel. At this time, according to the power value that the attacker wants to reduce, find the voltage required to reduce it to this power (usually two such voltages will be found).

[0083] b. Next, a new UP curve needs to be designed based on the inverter power that the attacker wants to reduce, such as Figure 5 As shown in (a), please note that the curve designed here is not unique. It is only necessary to design the maximum power point to a suitable voltage.

[0084] c. Obtaining this new UP curve means obtaining a new UI curve. The attacker only needs to inject the corresponding current signal at the corresponding voltage point (it can also be achieved by tampering with the voltage based on the current). Figure 5 As shown in (b), point U1 needs to inject a ΔI1 current signal, while point U2 needs to inject a -ΔI2 signal. It should also be noted that from the start of the attack to the designed fake MPP process, the voltage will continue to change, which means that the current signal to be injected also needs to change accordingly.

[0085] 2) Exploring voltage control loop vulnerabilities that cause abnormal bus voltage in photovoltaic inverters

[0086] Since the sensor data input to the DC-AC stage control only includes the AC side voltage, current, and DC bus voltage, the control algorithm cannot directly know the DC side input power and the corresponding output current to maintain power balance. In fact, the core of the entire control algorithm is to keep the voltage on the DC bus constant. If the power on the input side is greater than the power on the output side, the capacitor C on the DC bus will dc Will continue to charge, DC bus voltage V dc will continue to rise; on the contrary, if the power on the input side is less than the power on the output side, C dc Will discharge, V dc Therefore, as long as the DC bus voltage V dc If the voltage loop is kept constant, the input and output power will remain balanced. dc The voltage loop will have a manually set voltage reference value, which will ultimately control V dc Approximate this value.

[0087] The function of the voltage loop is to control the DC bus voltage V dc In fact, if Figure 6 As shown, the voltage loop has a reference voltage input V dcref , V dcref It is determined during product design. The control logic of the entire voltage loop is to make V dc With the reference voltage value V dcref same.

[0088] This means that there is a way to cheat the DC bus voltage sensor to control V dc Algorithm loopholes. Once V dc If the control of the DC bus voltage sensor is controlled by an attacker, it will have extremely serious consequences for the photovoltaic inverter. The following are two consequences of spoofing the DC bus voltage sensor.

[0089] Breakdown of DC bus capacitor C dc :If an attacker attempts to control V dc , and Vdc Being placed in an abnormally high voltage state will accelerate the DC bus capacitor C dc If this voltage is too high, C dc Another point to note is that the attacker cannot inject too large an attack signal V at one time. a ,Since it takes time for the control algorithm to control the transient bias back to a stable ,reference voltage, it takes time for an overly large attack signal to be injected at once ,may trigger the over / undervoltage protection of the inverter algorithm and shut down the inverter without ,achieving the purpose of burning out.

[0090] Similarly, the attacker can also force V dc Reduce (inject +V into the DC bus sensor a ). If the DC bus voltage V dc If it is too low and fails to reach the minimum voltage required for normal operation of the DC / AC stage, the entire inverter will be out of control, triggering protection and shutting down.

[0091] 3) Exploring vulnerabilities in the current control loop that cause abnormal output current of photovoltaic inverters

[0092] The goal of the current loop is to control the magnitude of the grid current. Since the grid voltage is a constant value, in order to control the inverter output power to match the photovoltaic inverter input power, the only way is to control the grid current. The current loop has two control loops, which respectively control the dq axis components I of the three-phase current after Clarke transform and Park transform. d and I q , which actually controls the actual power and reactive power outputted by the inverter to the grid. In order to control the output reactive power to 0, the q-axis component of the synthetic current vector needs to be 0, so I q The reference current of the loop I qref =0. I d Reference value of the loop I dref The actual output power needs to be controlled according to the output of the voltage loop to maintain the balance between the input and output power of the inverter.

[0093] Figure 7 The article presents the difference between the current control loop and current sensor of a typical two-stage photovoltaic inverter before and after being spoofed. In reality, injecting a constant malicious signal into the grid voltage and current sensors would produce an attack similar to that of an inverter experiencing large voltage and current fluctuations. For example, in the case of the grid current sensor, the entire system would only experience a brief transient before entering a steady state, rendering the attack ineffective.

[0094] However, due to the control characteristics, this transient process cannot be avoided. If an attacker injects a constantly changing malicious signal (such as a sinusoidal signal) into the grid voltage and current sensor, the inverter will not be able to finally enter a steady state and will remain in an unstable transient process. This is a current loop control vulnerability that an attacker can exploit.

[0095] For three-phase photovoltaic inverters, which are commonly used in industrial scenarios, control vulnerabilities are even more pronounced. As mentioned earlier, the three-phase voltage and current of a photovoltaic inverter must be transformed into a dq coordinate system through Clarke and Parke transforms before entering the control loop. The Clarke transformation matrix is given in the following equation.

[0096]

[0097] It should be noted that if an attacker injects the same malicious signal into the three-phase voltage and current sensors, the attack will not be effective. This is because it will be directly filtered out by the Clarke transform matrix, as shown in the following equation, and will not affect the voltage and current dq-axis components V of the final input control loop. dq / I dq .

[0098]

[0099]

[0100] Therefore, the vulnerability in the current loop control algorithm of a three-phase photovoltaic inverter lies in injecting unequal malicious signals into the three phase sensors. In fact, compared to the single-phase photovoltaic inverter control algorithm, which requires injecting time-varying malicious signals, the three-phase photovoltaic inverter only needs to inject a constant malicious signal into one of the voltage and current sensors to achieve the same attack effect.

[0101] This is because the dq coordinate system itself is a time-varying coordinate system (manifested as continuous rotation in the normal coordinate system), which makes the dq-axis component of the non-time-varying malicious signal time-varying.

[0102] Such malicious signals can cause the entire system to oscillate. Once the oscillation reaches a certain level, the inverter will trigger protection and shut down. Furthermore, during the system oscillation, the inverter's active power output will be affected and unnecessary reactive power will be introduced.

[0103] The present invention provides a security analysis method for the out-of-electromagnetic-band vulnerabilities of photovoltaic inverters, clarifies the attack path of physical information cross-domain threats in the photovoltaic inverter sensor unit, explores how physical malicious signal injection can exploit vulnerabilities in the information domain control algorithm to cause damage, and the consequences of the attack. Decision makers can use the security analysis results to protect photovoltaic inverters against key links of physical information cross-domain threats.

[0104] This embodiment also provides a security analysis system for out-of-band electromagnetic vulnerabilities of photovoltaic inverters. This system is used to implement the above-mentioned embodiments, and details already described are omitted. The terms "module," "unit," and the like used below may refer to a combination of software and / or hardware that implements a predetermined function. Although the systems described in the following embodiments are preferably implemented in software, implementation using hardware, or a combination of software and hardware, is also possible.

[0105] The system comprises:

[0106] An attack flow model construction module is used to construct a photovoltaic inverter perception link model. Through the photovoltaic inverter perception link model, an attack flow model is established that uses electromagnetic out-of-band vulnerabilities to manipulate photovoltaic inverter sensor values;

[0107] The electromagnetic out-of-band vulnerability mining module is used to mine electromagnetic out-of-band vulnerabilities based on the control characteristics of photovoltaic inverters and the attack flow model that uses electromagnetic out-of-band vulnerabilities to manipulate the values of photovoltaic inverter sensors. It is guided by the functions of photovoltaic inverters and realizes security analysis of the electromagnetic out-of-band vulnerabilities of photovoltaic inverters.

[0108] In this embodiment, the photovoltaic inverter function-oriented vulnerability mining includes maximum power point tracking algorithm vulnerability mining oriented towards reducing the output power of the photovoltaic inverter, voltage control loop vulnerability mining oriented towards causing abnormal photovoltaic inverter bus voltage, and current control loop vulnerability mining oriented towards causing abnormal photovoltaic inverter output current.

[0109] The implementation process of the functions and effects of each module in the above-mentioned system is specifically detailed in the implementation process of the corresponding steps in the above-mentioned method, which will not be repeated here. For the system embodiment, since it basically corresponds to the method embodiment, the relevant parts can be referred to the partial description of the method embodiment. The system embodiment described above is only schematic, wherein the modules described as separate components may or may not be physically separated, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of the present invention. Ordinary technicians in this field can understand and implement it without paying any creative work.

[0110] Embodiments of the system of the present invention can be applied to any device with data processing capabilities, such as a computer or other device. System embodiments can be implemented through software, hardware, or a combination of software and hardware. For example, a software implementation, as a logical device, is implemented by a processor of any device with data processing capabilities, reading corresponding computer program instructions from non-volatile memory into internal memory and executing them.

[0111] The above examples are merely specific embodiments of the present invention. Obviously, the present invention is not limited to the above examples, and many variations are possible. All variations that can be directly derived or imagined by a person skilled in the art from the disclosure of the present invention should be considered to be within the scope of protection of the present invention.

Claims

1. A security analysis method for out-of-band electromagnetic vulnerability of photovoltaic inverters, characterized in that: The following steps are involved: 1) Based on the data link of the PV inverter voltage and current sensing link, an attack flow model is established to manipulate the sensor values of the PV inverter by exploiting the out-of-band vulnerability; 2) Based on the control characteristics of photovoltaic inverters and the attack flow model that uses electromagnetic out-of-band vulnerabilities to manipulate the values of photovoltaic inverter sensors, this paper explores electromagnetic out-of-band vulnerabilities guided by photovoltaic inverter functions and implements security analysis of electromagnetic out-of-band vulnerabilities of photovoltaic inverters. The step 2) includes: 2.1) Exploring vulnerabilities in the maximum power point tracking (MPPT) algorithm, designed to reduce the output power of photovoltaic inverters. These MPPT vulnerabilities include injecting a false UI curve into the photovoltaic voltage / current sensor, causing the MPPT algorithm to find an incorrect maximum power point, resulting in reduced output power of the photovoltaic inverter. 2.2) Exploring voltage control loop vulnerabilities that cause abnormal bus voltage in PV inverters. These vulnerabilities include injecting false voltage signals into the DC bus voltage sensor, causing the DC bus voltage to be controlled at a false voltage value determined by the injected signal, rather than the set normal voltage. This can damage inverter components or cause the inverter to shut down abnormally. 2.3) Current control loop vulnerability discovery aimed at causing abnormal output current of the photovoltaic inverter. This includes injecting time-varying false signals into the grid voltage / current sensors, preventing the entire control loop from entering a steady state and causing system oscillations, leading to abnormal inverter shutdown.

2. The method for security analysis of out-of-band electromagnetic vulnerability of photovoltaic inverters according to claim 1, characterized in that: The step 1) includes: 1.1) Based on the data link of the internal voltage sensing link of the photovoltaic inverter, an attack flow model is established to manipulate the voltage sensor value of the photovoltaic inverter by exploiting the out-of-band vulnerability; 1.2) Based on the data link of the internal current sensing link of the photovoltaic inverter, an attack flow model is established to manipulate the current sensor value of the photovoltaic inverter by exploiting the out-of-band vulnerability.

3. The method for security analysis of out-of-band electromagnetic vulnerability of photovoltaic inverters according to claim 2, characterized in that: The attack flow model for manipulating the voltage sensor value of a photovoltaic inverter by exploiting the electromagnetic out-of-band vulnerability is as follows: a. Electromagnetic coupling: Different lengths of conductive loops on the victim circuit board are equivalent to different inductors, resulting in different electromagnetic wave resonant frequencies. This creates the risk that an attacker could couple electromagnetic attack signals into different nodes of the victim sensor circuit by selecting different frequencies. b. Rectification process: The amplifier contains transistors with positive and negative junctions that can limit the current to a single conduction, thereby rectifying the input signal transmitted in the circuit; c. Amplification and filtering process: The electromagnetic signal injected into each node of the victim circuit is amplified by the amplifier circuit and converted into a DC bias by the filter circuit in the amplifier circuit and the filter in the analog-to-digital converter.

4. The method for security analysis of out-of-band electromagnetic vulnerability of photovoltaic inverters according to claim 2, characterized in that: The attack flow model for manipulating the current sensor value of a photovoltaic inverter by exploiting the electromagnetic out-of-band vulnerability is specifically as follows: a. Malicious electromagnetic signals are directly coupled to the op amp circuit of the current sensing link, and the current sensing module is subject to the same attack risk as the voltage sensing module. b. The malicious electromagnetic signal is superimposed on the magnetic field generated by the measured current, generating noise at the output of the Hall sensor, which is then rectified and amplified by the amplifier circuit.

5. A security analysis system for out-of-band electromagnetic vulnerabilities of photovoltaic inverters, used to implement the security analysis method for out-of-band electromagnetic vulnerabilities of photovoltaic inverters according to any one of claims 1 to 4, characterized in that: The safety analysis system includes: An attack flow model construction module is used to construct a photovoltaic inverter perception link model. Through the photovoltaic inverter perception link model, an attack flow model is established that uses electromagnetic out-of-band vulnerabilities to manipulate photovoltaic inverter sensor values; The electromagnetic out-of-band vulnerability mining module is used to mine electromagnetic out-of-band vulnerabilities based on the control characteristics of photovoltaic inverters and the attack flow model that uses electromagnetic out-of-band vulnerabilities to manipulate the values of photovoltaic inverter sensors. It is guided by the functions of photovoltaic inverters and realizes security analysis of the electromagnetic out-of-band vulnerabilities of photovoltaic inverters.

6. The photovoltaic inverter out-of-band electromagnetic vulnerability security analysis system according to claim 5, characterized in that: The photovoltaic inverter function-oriented vulnerability mining includes maximum power point tracking algorithm vulnerability mining oriented towards reducing the output power of the photovoltaic inverter, voltage control loop vulnerability mining oriented towards causing abnormal photovoltaic inverter bus voltage, and current control loop vulnerability mining oriented towards causing abnormal photovoltaic inverter output current.

Citation Information

Patent Citations

  • Grid-connected inversion device in direct current microgrid

    CN105634025A

  • Design method of three-phase LCL type grid-connected conversion controller in photovoltaic power generation system

    CN112311007A