A security control method, device, and medium for wind farm tampering attacks
By establishing a wind turbine dynamics and data tampering model, designing an estimator and security controller, the data tampering attack problem of the wind farm SCADA system and the unit communication link was solved, and the normal operation of the wind farm and the improvement of power output performance were achieved.
Patent Information
- Application Number
- CN202410929219.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-11
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2044-07-11
AI Technical Summary
Existing technologies are unable to effectively defend against data tampering attacks on wind farm SCADA systems and unit communication links, which threaten wind farm power generation and the power supply balance of the large power grid. Existing defense strategies are also unable to cope with the nonlinear characteristics of wind turbines.
Establish a wind turbine dynamic model and data tampering attack model, design an estimator and distributed security controller, estimate attack information through a dynamic signal compensation mechanism, and make control adjustments for different units to ensure the normal operation of the wind farm and achieve the expected power output under data tampering attacks.
It effectively solves the attack and defense problems under the nonlinear characteristics of the wind farm, ensures the normal operation of each unit in the wind farm, and improves the power output performance and power generation balance.
Smart Images

Figure CN118646591B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of wind farm information security, and in particular to a security control method, device, and medium for wind farm tampering attacks. Background Art
[0002] As wind power capacity continues to grow in the power grid, the cybersecurity requirements for the wind power industry are becoming increasingly stringent. However, due to incomplete construction and lax requirements, the wind power industry's current power monitoring systems suffer from numerous cybersecurity blind spots. The security of the communication link between the SCADA system and each turbine in a wind farm is crucial for ensuring wind farm operation and power output. An attack on the SCADA-to-turbine communication link poses a significant threat to wind farm power generation and the overall power grid balance. Data tampering attacks targeting the Ethernet communication links between the wind farm SCADA system and turbines, as well as within the turbines themselves, can directly result in erroneous power output information being received by the attacked turbine's local controller and the SCADA system, potentially impacting the entire wind farm.
[0003] Existing research on wind farm information security defenses uses information credibility-based attack suppression strategies that strictly limit the number of vulnerable nodes and impact the connectivity and performance of communication networks. Security control-based defense strategies primarily focus on the power grid system and struggle to address the nonlinear characteristics of wind turbine operation. Therefore, further research is needed on the information security of wind farm power distribution. Therefore, a security control method that can effectively defend against power information tampering attacks is needed for wind farms with nonlinear characteristics. Summary of the Invention
[0004] The purpose of the present invention is to address the deficiencies of the prior art and provide a wind farm security control method, device, and medium for tampering attacks.
[0005] The object of the present invention is achieved through the following technical solutions:
[0006] The present invention provides a security control method for wind farm tampering attacks, the method comprising the following steps:
[0007] Establish the wind turbine dynamics model and wind farm system dynamic equations based on the wind turbine structure;
[0008] Based on the characteristics of data tampering attacks, a data tampering attack model is established for the wind turbine output power transmitted on the internal communication link of the wind turbine and the wind turbine-SCADA system communication link;
[0009] An estimator is designed for the attacked wind turbine, and the erroneous information injected by the attacker is estimated through a dynamic signal compensation mechanism. A distributed safety controller is designed for all wind turbines, and corresponding control adjustments are made for different units to ensure that each unit and the entire wind farm can operate normally and achieve the expected power output performance under data tampering attacks.
[0010] Furthermore, the expression of the wind turbine dynamic model is:
[0011]
[0012] Among them, ω r is the rotor angular velocity, J t is the equivalent moment of inertia, T a is the aerodynamic torque, K t is the damping coefficient, T g is the generator torque.
[0013] Furthermore, the wind farm system dynamic equation is:
[0014]
[0015] Where k=1,...,n represents the number of wind turbines in the wind farm, n is the total number of wind turbines, ω rk (t), T ak , T gk (t), P gk (t) represent the rotor angular velocity, aerodynamic torque, generator torque and output power of the kth wind turbine respectively, P F (t) represents the output power of the entire wind farm.
[0016] Furthermore, the expression of the data tampering attack model is:
[0017] P gia (t) = P gi (t)+a i (t)
[0018] Among them, P gia (t) represents the sensor measurement value after the attack, P gi (t) represents the sensor measurement value before the attack, a i (t) represents the error information value injected by the attacker.
[0019] Furthermore, for a known attacked wind turbine, the design method of the estimator is specifically as follows:
[0020] Set the expected reference power signal of the wind turbine to P di (t) = P d (t), where Pd (t) is the average distribution value of the total expected output power of the wind farm, and the dynamic model of the wind turbine is:
[0021]
[0022] Where i = 1, ..., n a Indicates the number of the attacked wind turbine in the wind farm, n a is the total number of attacked wind turbines; ω ri (t), T ai , T gi (t), P gi (t) represent the rotor angular velocity, aerodynamic torque, generator torque and output power of the i-th attacked wind turbine respectively;
[0023] Introduction As a i The estimated parameters of (t) are updated adaptively according to the following rules:
[0024]
[0025] Among them, k a >0 is the adaptive law gain, L>0 represents the Lipschitz constant, k i >0 indicates the controller gain of the i-th attacked wind turbine.
[0026] Furthermore, for a known attacked wind turbine, the expression of the safety controller is as follows:
[0027]
[0028] Furthermore, for known normal wind turbines that have not been attacked, the design method of the safety controller is specifically as follows:
[0029] The expected output power reference value of the normal wind turbine that is not attacked is proportional to the total expected output power reference value of the wind farm P. D Dynamically adjust the power output value of the attacked wind turbine after compensation, which is set to:
[0030]
[0031] Where j = 1, ..., nn a Indicates the number of normal wind turbines in the wind farm;
[0032] The dynamic model of normal operation of the wind turbine is:
[0033]
[0034] Among them, ωrj (t), T aj , T gj (t), P gj (t) represent the rotor angular velocity, aerodynamic torque, generator torque and output power of the jth normal wind turbine respectively;
[0035] The expression of the safety controller of the normal wind turbine is as follows:
[0036]
[0037] Among them, k j >0 indicates the controller gain of the first normal wind turbine.
[0038] The present invention also provides a security control device for wind farm tampering attacks, comprising a memory and one or more processors, wherein the memory stores executable code, and when the processor executes the executable code, it is used to implement the above-mentioned security control method for wind farm tampering attacks.
[0039] The present invention also provides a computer-readable storage medium having a program stored thereon. When the program is executed by a processor, the above-mentioned security control method for wind farm tampering attacks is implemented.
[0040] This paper proposes a wind farm security control method based on signal compensation under data tampering attacks. It has the following beneficial effects: It proposes a method for modeling and defending against attacks targeting wind turbines and wind farms, effectively addressing the attack and defense issues in wind farms with nonlinear characteristics. It ensures the normal operation of each wind turbine in the wind farm, improves the wind farm's power output performance, and ensures the wind farm's power generation balance. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0042] Figure 1 This is a flow chart of a security control method for wind farm tampering attacks provided by an embodiment of the present invention;
[0043] Figure 2 This is a diagram of a distributed safety control framework for multiple units in a wind farm provided by an embodiment of the present invention;
[0044] Figure 3 This is a diagram of the wind farm operation status in the absence of an attack provided by an embodiment of the present invention;
[0045] Figure 4 This is a diagram of the wind farm operation status under a data tampering attack provided by an embodiment of the present invention;
[0046] Figure 5 This is a wind farm operating status diagram obtained by applying the security control method provided by the present invention under a data tampering attack provided by an embodiment of the present invention;
[0047] Figure 6 This is a structural diagram of a security control device for wind farm tampering attacks provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0048] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific embodiments of the present invention are described in detail below with reference to the accompanying drawings.
[0049] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention may also be implemented in other ways different from those described herein. Those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.
[0050] The present invention provides a security control method for wind farm tampering attacks, such as Figure 1 As shown, the following steps are included:
[0051] Step 1: Establish the wind turbine dynamic model and wind farm system dynamic equations based on the wind turbine structure.
[0052] Specifically, the wind turbines in the wind farm described in the present invention are all variable speed wind turbines; the dynamic model expression of the wind turbine is:
[0053]
[0054] Among them, ω r is the rotor angular velocity, J t is the equivalent moment of inertia, T a is the aerodynamic torque, K t is the damping coefficient, T g is the generator torque;
[0055] Furthermore, the dynamic equation of the wind farm system is:
[0056]
[0057] Where k=1,..., n represents the number of wind turbines in the wind farm, n is the total number of wind turbines, t represents the time t, ω rk (t) represents the rotor angular velocity of the kth wind turbine, T akrepresents the aerodynamic torque of the kth wind turbine, T gk represents the generator torque of the kth wind turbine, i.e., the control instruction output by the local controller, P gk (t) represents the output power of the kth wind turbine, P F (t) represents the output power of the entire wind farm.
[0058] Step 2: Based on the characteristics of data tampering attacks, a data tampering attack model is established for the wind turbine output power transmitted on the internal communication link of the wind turbine and the wind turbine-SCADA system communication link, and the attack impact is analyzed.
[0059] Specifically, consider the data tampering attack on the wind turbine output power transmitted on the sensor-controller link in the wind turbine and the communication link between a single wind turbine in the wind farm and the SCADA system. The attack model for the attacker to tamper with the output power of the target wind turbine is:
[0060] P gia (t) = P gi (t)+a i (t)
[0061] Among them, P gia (t) represents the sensor measurement value after the attack, that is, the output power of the wind turbine, P gi (t) represents the sensor measurement value before the attack, a i (t) represents the error information value injected by the attacker.
[0062] This attack will directly cause the local controller of the attacked wind turbine and the wind farm SCADA system to generate erroneous control instructions and power allocation requirements, thereby reducing the power generation efficiency and operational safety of the wind farm.
[0063] Step 3: Design an estimator for known attacked wind turbines, and estimate the attacker's injected error information through a dynamic signal compensation mechanism; design a distributed safety controller for all wind turbines, and make corresponding control adjustments based on whether the attack occurs or not, to ensure that each turbine and the entire wind farm can operate normally and achieve the expected power output performance under data tampering attacks. Specifically, there are two control scenarios:
[0064] ① For known attacked wind turbines, the wrong output power information will be sent to the local controller of the wind turbine and the wind farm SCADA system. At this time, the expected reference power signal of the wind turbine is set to P di (t) = P d (t), where P d (t) is the average distribution value of the total expected output power of the wind farm. The dynamic model of the wind turbine is:
[0065]
[0066] Where i = 1, ..., n a Indicates the number of the attacked wind turbine in the wind farm, n a is the total number of attacked wind turbines in the wind farm; ω ri (t) represents the rotor angular velocity of the i-th attacked wind turbine, T ai represents the aerodynamic torque of the i-th attacked wind turbine, T gi (t) represents the generator torque of the i-th attacked wind turbine, i.e., the control command output by the local controller; P gi (t) represents the output power of the i-th attacked wind turbine.
[0067] To compensate for the false information value a injected by the attacker i (t), design an estimator for the attacked wind turbine, introduce As a i The estimated parameters of (t) are updated adaptively according to the following rules:
[0068]
[0069] Among them, k a >0 is the adaptive law gain, L>0 represents the Lipschitz constant, k i >0 indicates the controller gain of the i-th attacked wind turbine.
[0070] Then, a safety controller for the attacked wind turbine is designed in the following form:
[0071]
[0072] ② When the wind turbine is operating in a reliable communication environment and no attack occurs, the correct power output value of the wind turbine will be transmitted to the local controller of the wind turbine and the wind farm SCADA system. In order to maintain the overall power generation balance of the wind farm, the expected output power reference value of the normal wind turbine that has not been attacked will be proportional to the total expected output power reference value P of the wind farm. D Dynamically adjust the power output value of the attacked wind turbine after compensation, which is set to:
[0073]
[0074] Where j = 1, ..., nn d Indicates the number of normal wind turbines in the wind farm.
[0075] In this case, the dynamic model of the normal operation of the wind turbine can be expressed as:
[0076]
[0077] Among them, ω rj (t) represents the rotor angular velocity of the jth normal wind turbine, T aj It represents the aerodynamic torque of the jth normal wind turbine, T gj (t) represents the generator torque of the jth normal wind turbine, that is, the control command output by the local controller; P gj (t) represents the output power of the jth normal wind turbine.
[0078] Then, a safety controller for the wind turbine that has not been attacked, i.e., a normal wind turbine, is designed in the following form:
[0079]
[0080] Among them, k j >0 indicates the controller gain of the first normal wind turbine.
[0081] The anomaly estimator designed in the present invention can estimate the false data injected by the attacker, and the designed distributed security controller makes different control strategy adjustments when a data tampering attack occurs / does not occur on each unit in the wind farm, so as to ensure the expected control targets of the wind farm and each unit under the data tampering attack.
[0082] Figure 2 The overall control framework for distributed safety control of multiple units in a wind farm provided by an embodiment of the present invention is demonstrated.
[0083] In practical applications, Lyapunov stability theory can be used to verify the stability of all wind turbine control systems under the proposed safety control strategy.
[0084] The above-mentioned safety control method provided by the present invention is described below with specific examples, as follows:
[0085] Step 1: Establish a wind turbine dynamics model and a wind farm system dynamic equation based on the wind turbine structure;
[0086] Specifically, Figure 3 The simulation of the wind farm with 9 wind turbines in the non-attack state is shown. D is the total expected output power reference value of the entire wind farm, p F The actual output power of the entire wind farm is the actual output power of the entire wind farm. The entire wind farm and all units can achieve the expected power output tracking performance during the operation cycle, and the tracking error is kept within a very small range.
[0087] Step 2: Based on the data tampering attack characteristics, a data tampering attack model is established for the wind turbine output power transmitted on the wind turbine internal communication link and the wind turbine-SCADA system communication link;
[0088] In this example, the attacker launches a data tampering attack on four wind turbines in the wind farm within the time interval of [30s, 70s], causing the output power of the wind turbines to increase by 10%, 15%, 15%, and 20% respectively.
[0089] Figure 4 The simulation operation of a wind farm with four wind turbines under attack is demonstrated. The wind farm can still achieve the expected power output tracking performance during the non-attack operation period, but the output performance deteriorates significantly and the tracking error increases significantly during the attack period [30s, 70s].
[0090] Step 3: Design an estimator and a distributed security controller to restore the output performance of the wind farm under attack.
[0091] Figure 5 The simulation operation of a wind farm obtained by applying the control scheme proposed in the present invention when four wind turbines are attacked is demonstrated. The simulation results show that the wind farm can maintain the expected power output performance during the entire operation period, and the output error remains within a small range corresponding to the non-attack situation, verifying that the proposed scheme can effectively mitigate the impact of the attack and restore system performance.
[0092] These simulation results verify the effectiveness of the security control method proposed in this invention for wind farm tampering attacks.
[0093] Corresponding to the aforementioned embodiment of the security control method against tampering attacks on wind farms, the present invention further provides an embodiment of a security control device against tampering attacks on wind farms.
[0094] See also Figure 6 The security control device for wind farm tampering attacks provided in an embodiment of the present invention includes a memory and one or more processors. The memory stores executable code. When the processor executes the executable code, it is used to implement the security control method for wind farm tampering attacks in the above embodiment.
[0095] The embodiment of the security control device for wind farm tampering attacks of the present invention can be applied to any device with data processing capabilities, and the device with data processing capabilities can be a device or apparatus such as a computer. The device embodiment can be implemented through software, or through hardware or a combination of software and hardware. Taking software implementation as an example, as a device in a logical sense, it is formed by the processor of any device with data processing capabilities in which it is located reading the corresponding computer program instructions in the non-volatile memory into the memory for execution. From the hardware level, if Figure 6 As shown in the figure, it is a hardware structure diagram of any device with data processing capability where the security control device for wind farm tampering attack of the present invention is located. Figure 6 In addition to the processor, memory, network interface, and non-volatile memory shown, any device with data processing capabilities in which the apparatus in the embodiment is located may also include other hardware, generally based on the actual functions of the device with data processing capabilities, which will not be described in detail.
[0096] The implementation process of the functions and effects of each unit in the above-mentioned device is specifically described in the implementation process of the corresponding steps in the above-mentioned method, and will not be repeated here.
[0097] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to the partial description of the method embodiments. The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the present invention. A person of ordinary skill in the art can understand and implement the present invention without inventive work.
[0098] An embodiment of the present invention further provides a computer-readable storage medium having a program stored thereon. When the program is executed by a processor, the security control method for wind farm tampering attacks in the above embodiment is implemented.
[0099] The computer-readable storage medium may be an internal storage unit of any device with data processing capabilities described in any of the aforementioned embodiments, such as a hard disk or memory. The computer-readable storage medium may also be an external storage device of any device with data processing capabilities, such as a plug-in hard disk, a smart media card (SMC), an SD card, a flash card, etc. equipped on the device. Furthermore, the computer-readable storage medium may also include both an internal storage unit and an external storage device of any device with data processing capabilities. The computer-readable storage medium is used to store the computer program and other programs and data required by any device with data processing capabilities, and may also be used to temporarily store data that has been output or is to be output.
[0100] The above description is merely a preferred embodiment of one or more embodiments of this specification and is not intended to limit one or more embodiments of this specification. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of one or more embodiments of this specification shall be included in the scope of protection of one or more embodiments of this specification.
Claims
1. A security control method for wind farm tampering attacks, characterized in that: include: Establish the wind turbine dynamics model and wind farm system dynamic equations based on the wind turbine structure; The expression of the wind turbine dynamic model is: Among them, ω r is the rotor angular velocity, J t is the equivalent moment of inertia, T a is the aerodynamic torque, K t is the damping coefficient, T g is the generator torque; The dynamic equation of the wind farm system is: Where k = 1,…,n represents the wind turbine group number in the wind farm, n is the total number of wind turbine groups, ω rk (t),T ak ,T gk (t),P gk (t) represent the rotor angular velocity, aerodynamic torque, generator torque and output power of the kth wind turbine respectively, P F (t) represents the output power of the entire wind farm; According to the characteristics of data tampering attacks, a data tampering attack model for the wind turbine output power transmitted on the internal communication link of the wind turbine and the wind turbine-SCADA system communication link is established; the expression of the data tampering attack model is: P gia (t)=P gi (t)+a i (t) Among them, P gia (t) represents the sensor measurement value after the attack, P gi (t) represents the sensor measurement value before the attack, a i (t) represents the error information value injected by the attacker; An estimator is designed for the attacked wind turbine, and the erroneous information injected by the attacker is estimated through a dynamic signal compensation mechanism. A distributed safety controller is designed for all wind turbines, and corresponding control adjustments are made for different units to ensure that each unit and the entire wind farm can operate normally and achieve the expected power output performance under data tampering attacks.
2. The security control method for wind farm tampering attacks according to claim 1 is characterized in that: For a known attacked wind turbine, the design method of the estimator is specifically as follows: Set the expected reference power signal of the wind turbine to P di (t) = P d (t), where P d (t) is the average distribution value of the total expected output power of the wind farm, and the dynamic model of the wind turbine is: Where i = 1,…,n a Indicates the number of the attacked wind turbine in the wind farm, n a is the total number of attacked wind turbines; ω ri (t),T ai ,T gi (t),P gi (t) represent the rotor angular velocity, aerodynamic torque, generator torque and output power of the i-th attacked wind turbine respectively; Introduction As a i The estimated parameters of (t) are updated adaptively according to the following rules: Among them, k a >0 is the adaptive law gain, L>0 represents the Lipschitz constant, k i >0 indicates the controller gain of the i-th attacked wind turbine.
3. The wind farm tamper attack-resistant security control method according to claim 2, characterized in that: For a known attacked wind turbine, the expression of the safety controller is as follows:
4. The security control method for wind farm tampering attacks according to claim 1 is characterized in that: For known normal wind turbines that have not been attacked, the design method of the safety controller is as follows: The expected output power reference value of the normal wind turbine that is not attacked is proportional to the total expected output power reference value of the wind farm P. D Dynamically adjust the power output value of the attacked wind turbine after compensation, which is set to: Where j = 1,…,nn a Indicates the number of normal wind turbines in the wind farm; The dynamic model of normal operation of the wind turbine is: Among them, ω rj (t),T aj ,T gj (t),P gj (t) represent the rotor angular velocity, aerodynamic torque, generator torque and output power of the jth normal wind turbine respectively; The expression of the safety controller of the normal wind turbine is as follows: Among them, k j >0 indicates the controller gain of the jth normal wind turbine.
5. A wind farm tamper-resistant security control device comprising a memory and one or more processors, wherein the memory stores executable code, characterized in that: When the processor executes the executable code, it is used to implement the security control method for wind farm tampering attacks according to any one of claims 1 to 4.
6. A computer-readable storage medium having a program stored thereon, characterized in that: When the program is executed by a processor, the security control method for wind farm tampering attacks according to any one of claims 1 to 4 is implemented.