Power distribution network system risk coupling quantitative analysis method and system

By establishing a cyber-physical system model, quantifying information system risks and calculating risk coupling degree, the problem of identifying weak links in power distribution network information risk analysis is solved, and system risk coupling degree indicators and security configuration schemes are provided, reducing the impact of information attacks on the power system.

CN119363391BActive Publication Date: 2025-12-30SHANGHAI NENGYOUWANG POWER TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411371117.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-29
Publication Date
2025-12-30
Estimated Expiration
2044-09-29

AI Technical Summary

Technical Problem

Existing technologies, when analyzing information risks in distribution networks, fail to effectively quantify the risk gains brought to the system by abnormal states of information nodes, and fail to identify weak links in the system.

Method used

By establishing a cyber-physical system model, we can identify and quantify information system risks, define the risk coupling degree between the system and nodes, conduct simulation analysis, and calculate the risk coupling degree of the distribution network under different attack types.

Benefits of technology

It enables quantitative analysis of information risks in power distribution networks, identifies weak links, provides a system risk coupling degree index, clarifies the negative impact of information attacks on power systems, and proposes security configuration schemes to reduce system risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119363391B_ABST
    Figure CN119363391B_ABST
Patent Text Reader

Abstract

The application discloses a power distribution network system risk coupling quantitative analysis method and system, comprising: collecting power distribution network system operation data, establishing an information physical fusion system model; determining the potential risk type of the information system, identifying and quantifying the information system risk; establishing an information attack model, defining system risk coupling degree and node risk coupling degree; simulating and analyzing the risk coupling degree, calculating the system and node risk coupling degree under different attack types, and completing the power distribution network system risk analysis. The power distribution network system risk coupling quantitative analysis method provided by the application directly and clearly reflects the risk superposition effect of the information system and the power system under information attack through the system risk coupling degree index; the negative impact of integrity attack on the power distribution network is greater than that of availability attack, so the information attack should be prevented in the power distribution network information system; the security configuration scheme based on the node risk coupling degree can effectively reduce the system risk.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power system engineering technology, specifically to a method and system for quantitative analysis of risk coupling in distribution network systems. Background Technology

[0002] With the widespread application of communication, computer, and control technologies in power distribution networks, traditional power distribution networks are gradually evolving into CPDS (Content-Physical Distribution System), a deep integration of physical and information systems. In CPDS, the information and physical systems are heterogeneous and possess complex interactive relationships. Energy flow in the physical system changes continuously under the monitoring of the information system, with a focus on the time-domain characteristics of energy flow. The information system monitors, analyzes, and controls the operating status of the physical system, focusing on the transformation relationships of discrete events. The information system enhances the distribution network's ability to perceive system status, improves the stability of power supply, and optimizes energy utilization efficiency. However, risks in the information system can be transmitted to the physical system through the dynamic interaction of information and energy flows, thereby affecting the stable operation of the distribution network and potentially triggering cascading failures. Therefore, it is necessary to clarify the causes and transmission mechanisms of CPDS risks and analyze the superposition effect of risks between the power system and information system under cyber-physical coupling.

[0003] Numerous scholars have already conducted research on the security risks of power systems under information threats. Existing technologies propose a vulnerability assessment method for CPDS (Content-Based Distributed Control System) under a distributed cooperative control mode, which assesses the vulnerability of distributed energy resources in the system by analyzing the power deficit caused by attack events involving multiple components. However, the aforementioned quantitative assessment methods often neglect potential faults in the physical system, focusing instead on the impact of information system risk transmission or abnormal information system states on the power system. Summary of the Invention

[0004] The purpose of this section is to outline some aspects of embodiments of the present invention and to briefly describe some preferred embodiments. Simplifications or omissions may be made in this section, as well as in the abstract and title of this application, to avoid obscuring the purpose of these documents; however, such simplifications or omissions should not be construed as limiting the scope of the invention.

[0005] In view of the above-mentioned problems, the present invention is proposed.

[0006] Therefore, the technical problem solved by this invention is: how to analyze the information risks faced by the power distribution network, quantify the importance of the risk gains brought to the system by the abnormal state of information nodes, and identify the weak links in the system.

[0007] To address the aforementioned technical problems, this invention provides the following technical solution: a method for quantitative analysis of risk coupling in a power distribution network system, comprising:

[0008] Collect operational data from the power distribution network system and establish a cyber-physical system model;

[0009] Identify the potential risk types of information systems, and identify and quantify information system risks;

[0010] Establish an information attack model and define the system risk coupling degree and node risk coupling degree;

[0011] Simulation analysis is conducted to assess the risk coupling degree. Under different attack types, the risk coupling degree of the system and nodes is calculated to complete the risk analysis of the power distribution network system.

[0012] As a preferred embodiment of the risk coupling quantitative analysis method for distribution network systems described in this invention, the establishment of the cyber-physical system model includes an information system and a power physical system.

[0013] The power physics system includes traditional primary equipment and new energy equipment such as photovoltaic and wind power, as well as energy storage equipment; the information system includes a control center, communication network, and smart terminal equipment; the control center is the core of the information system, which analyzes the power system status data transmitted from the communication network and issues control commands to achieve control and optimization of different distribution network scenarios.

[0014] As a preferred embodiment of the risk coupling quantitative analysis method for distribution network systems described in this invention, the determination of potential risk types of information systems includes, for example, information attacks against distribution networks include active attacks, passive attacks, proximity attacks, insider attacks, and software / hardware integration attacks; and from the perspective of attack effectiveness, attack types are classified into integrity attacks and availability attacks.

[0015] As a preferred embodiment of the risk coupling quantitative analysis method for distribution network systems described in this invention, the identification and quantification of information system risks includes: based on the analysis of potential risk types, it is found that an availability attack against the RTU will cause it to refuse to execute instructions from the control center; if the RTU refuses to serve due to an information attack when a fault occurs, the faulty line will be in a power outage state, and the fault range will be expanded to the downstream, upstream and adjacent feeder branches of the feeder.

[0016] The impact of availability attacks on downstream regions of failures can be expressed as follows:

[0017]

[0018] in, This represents the impact of a fault in the i-th feeder segment during an information attack on the downstream power supply area; L e λ represents the load power on the e-th feeder line; iThis represents the failure rate of the i-th feeder segment; This represents the set of downstream feeder segments of the i-th feeder segment; P represents the failure probability of the feeder e's transfer path. If there is no transferable line downstream of feeder e, then P... Tie =1, otherwise the value is equal to the probability that the corresponding contact switch fails to operate; S represents the probability that all switches on the path from feeder i to feeder e will fail to operate due to the attack; i,e This represents the set of terminal devices corresponding to all switches along the path from feeder i to feeder e; d represents the probability that an availability attack will cause terminal device k to fail; mttr This represents the average repair time, including manual inspection, network forensics, and fault repair; d rst Indicates the remote control switch time;

[0019] The availability attack caused the fault to extend to the upstream power supply area, including adjacent branch feeders of the fault;

[0020] The formula for the impact of availability attacks on the upstream region of a failure is as follows:

[0021]

[0022] in, This represents the impact of a fault in the i-th feeder segment under an information attack on the upstream power supply area; the set of upstream feeder segments of the i-th feeder segment;

[0023] The effect of availability attacks on feeders near faulty branches is expressed by the formula:

[0024]

[0025] in, This indicates the impact of a fault in the i-th feeder segment on adjacent power supply areas under an information attack. Represents the set of neighboring branch feeders of the i-th feeder segment; This represents the probability that all switches within the range from the i-th feeder segment to the m-th branch of the adjacent feeder will fail to operate due to the attack. This represents the set of all feeder segments on the neighboring feeder m; This represents the set of terminal devices corresponding to all switches within the range from the i-th feeder segment to the m-th branch of the adjacent feeder; This represents the probability that all switches upstream of feeder f on the feeder branch will fail to operate due to the attack. This represents the set of terminal devices corresponding to all switches upstream of feeder f on the feeder branch; the distribution network risk formula under availability attack is expressed as:

[0026]

[0027] Where B represents the set of all feeder segments.

[0028] As a preferred embodiment of the risk coupling quantitative analysis method for distribution network systems described in this invention, the establishment of the information attack model includes the following: the impact of an integrity attack on the downstream feeder area of ​​the attacked equipment terminal can be expressed as follows:

[0029]

[0030] in, This represents the impact of a failure of the j-th terminal device under an information attack on the downstream power supply area; This represents the availability of the upstream feeder area of ​​the j-th terminal device; This represents the probability that the j-th terminal device is attacked, and all terminal devices in its upstream feeder area are operating normally. This represents the set of all feeders in the upstream region of terminal device j; This represents the set of all feeders in the downstream region of terminal device j; This represents the set of all terminal devices in the upstream feeder area of ​​terminal device j; This represents the probability that an integrity attack will cause terminal device j to malfunction;

[0031] The impact of integrity attacks on fault recovery under fault conditions can be expressed as follows:

[0032]

[0033] in, This indicates the impact of a fault recovery on the i-th feeder segment under an information attack. This represents the probability that any terminal device in the downstream area of ​​feeder h will fail due to an attack; This represents the set of all terminal devices downstream of the feeder; This represents the probability that an information attack will cause the terminal device j to malfunction.

[0034] The risk to the distribution network under integrity attacks can be expressed as:

[0035]

[0036] Where S represents the set of all terminal devices.

[0037] As a preferred embodiment of the risk coupling quantitative analysis method for distribution network systems described in this invention, the system risk coupling degree and node risk coupling degree include, in CPDS, not only considering the impact of line faults and equipment failures in the distribution network, but also the direct and indirect impacts caused by the stable operation of the power grid; then the CPDS risk formula is expressed as:

[0038] R CPDS =RP +R C→P

[0039] Among them, R CPBS This indicates the risk of power distribution network attacks considering information attacks; R P This represents the risk of a traditional distribution network, i.e., the risk of a distribution network without considering information attacks; R C→P This indicates the risk gains that information attacks bring to the power distribution network.

[0040] System risk coupling degree is used to characterize the risk gain of an abnormal state of an information system to a power system under cyber-physical coupling conditions; the formula for system risk coupling degree is expressed as:

[0041]

[0042] in, This represents the system risk coupling degree, with a value range of [0, +∞]. The system risk coupling degree is directly proportional to the risk gain of information threats to the power system; if A value of 0 indicates that the information threat will not affect the operation of the power distribution network;

[0043] Taking the distribution network under information attack as the research object, this paper analyzes the impact of availability attacks and integrity attacks on the fault handling process of centralized FA system; the inter-system coupling degree under availability attacks and integrity attacks is expressed as:

[0044]

[0045] in, This indicates the degree of system risk coupling under availability attacks; R represents the system risk coupling degree under integrity attack; p This means that the probability of a successful information attack is set to 0, which means that information attacks will not affect the fault handling process of the FA system.

[0046] Node risk coupling degree is used to characterize the risk gain of abnormal states of information nodes to the power system under cyber-physical coupling.

[0047] The node risk coupling degree in a distribution network information system can be expressed as:

[0048]

[0049] in, This represents the node coupling degree of information node j; This represents the impact of the abnormal state of information node j on the distribution network, with a value range of [0, +∞]. A value of 0 indicates that the abnormal state of this node will not affect the operation of the distribution network.

[0050] As a preferred embodiment of the risk coupling quantitative analysis method for distribution network systems described in this invention, the simulation analysis of risk coupling degree includes: when information attacks CPDS, the nodes in the information system are independent of each other, and an attack on a single node will not affect the operating status of other nodes. To quantify the degree of gain of a node being attacked by information on the distribution network risk, all attack events involving nodes need to be considered.

[0051] The proportional allocation method is used to distribute the harm caused by an attack involving multiple target nodes. Based on the weight coefficients of different nodes, the harm of an attack involving multiple nodes is distributed to different nodes. The update formula is expressed as:

[0052]

[0053] in, This represents the set of all instances in an information attack event that contain the target node j. S represents the probability of attack event k occurring; k S represents the set of all target nodes in attack event k; k This indicates that it belongs to set S and does not belong to set S. k The set of nodes; This represents the probability that information node z will fail due to an information attack. c represents the risk gain ratio of node j in attack event k; v This represents the proportional allocation coefficient for information node ν; This represents the risk gain that attack event k causes to the power system; This indicates the damage to the power system caused by the attack.

[0054] By combining the analysis scenarios, the node coupling degree under availability attacks and integrity attacks can be obtained; under availability attacks, This represents the probability that the z-th RTU is attacked and malfunctions. This represents the harm caused to the power system by attack event k; under an integrity attack, This is the probability that the z-th RTU will fail due to an integrity attack. This indicates that an integrity attack event k causes harm to the power system.

[0055] A risk coupling quantitative analysis system for distribution network systems employing any of the methods described in this invention, wherein:

[0056] The Cyber-Physical System (CPDS) module establishes and maintains the cyber-physical system model of the distribution network; the data collection submodule collects operational data from the power physical system and information system, including equipment status, load data, and communication data; the model building submodule establishes a CPDS model that includes the power physical system and information system; the power physical system includes traditional primary equipment, new energy equipment, and energy storage equipment.

[0057] The information system risk identification and quantification module identifies and quantifies the potential risks of information systems, and classifies attack types into integrity attacks and availability attacks based on the attack effects.

[0058] The information attack model module establishes an information attack model and calculates the risk coupling degree between the system and nodes.

[0059] The simulation analysis module performs simulation verification and result analysis on the power distribution network system. It verifies the rationality of the proposed risk coupling degree index and calculation method through simulation results, analyzes the simulation results, and evaluates the effectiveness of different protection measures in reducing system risks.

[0060] A computer device includes: a memory and a processor; the memory stores a computer program, wherein: when the processor executes the computer program, it implements the steps of the method described in any one of the present invention.

[0061] A computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the method described in any one of the present invention.

[0062] The beneficial effects of this invention are as follows: Compared with traditional risk assessment indicators, the system risk coupling degree index proposed in this invention can more directly and clearly reflect the risk superposition effect between information systems and power systems under information attacks; integrity attacks have a greater negative impact on distribution networks than availability attacks, therefore, this type of information attack should be the focus of prevention in distribution network information systems; the impact of both attack methods on distribution networks increases with the increase of system automation level, indicating that although informatization enhances the system automation level, information risks are also more likely to affect the distribution network with the increase of automation level; the security configuration scheme based on node risk coupling degree can effectively reduce system risks. Attached Figure Description

[0063] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Wherein:

[0064] Figure 1 A flowchart illustrating the overall process of a risk coupling quantitative analysis method for a power distribution network system, as provided in the first embodiment of the present invention.

[0065] Figure 2 This is a diagram illustrating the impact of integrity attacks on power supply restoration in a risk coupling quantitative analysis method for power distribution networks provided in the first embodiment of the present invention.

[0066] Figure 3 An IEEE 33-node system diagram for a risk coupling quantitative analysis method for a power distribution network system provided in the second embodiment of the present invention;

[0067] Figure 4 The second embodiment of the present invention provides a method for quantitative analysis of risk coupling in a distribution network system, including an RTU risk coupling degree diagram under integrity attack.

[0068] Figure 5 This is a diagram illustrating the risk coupling degree of RTU under an availability attack following a secure configuration of a power distribution network system risk coupling quantitative analysis method, as provided in the second embodiment of the present invention. Detailed Implementation

[0069] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.

[0070] Example 1

[0071] Reference Figure 1 As an embodiment of the present invention, a method for quantitative analysis of risk coupling in a power distribution network system is provided, comprising:

[0072] S1: Collect data on the operation of the power distribution network system and establish a cyber-physical system model.

[0073] Furthermore, the establishment of the Cyber-Physical System Model (CPDS) includes an information system and a power-physical system.

[0074] Furthermore, the power physical system includes traditional primary equipment and new energy equipment such as photovoltaic and wind power, as well as energy storage equipment; the information system includes a control center, communication network, and smart terminal equipment; the control center is the core of the information system, which analyzes the power system status data transmitted from the communication network and issues control commands to achieve control and optimization of different distribution network scenarios.

[0075] It should be noted that FA systems have high requirements for real-time data transmission, and protection methods that require significant computation time, such as data verification, may negatively impact the operation of the distribution network. Smart terminal devices in the distribution network typically possess limited computing, storage, and communication resources, which restricts the information protection measures that can be applied to these devices, such as encryption protocols and data verification. Therefore, improving the information protection capabilities of terminal devices often requires a comprehensive upgrade of both hardware and software.

[0076] S2: Determine the types of potential risks to the information system, identify and quantify the risks of the information system.

[0077] Furthermore, the determination of potential risk types for information systems includes, for example, information attacks targeting the power distribution network, including active attacks, passive attacks, proximity attacks, insider attacks, and software / hardware integration attacks; from the perspective of attack effectiveness, attack types are classified into integrity attacks and availability attacks.

[0078] Furthermore, the identification and quantification of information system risks includes: based on the analysis of potential risk types, determining that an availability attack against the RTU would cause it to refuse to execute instructions from the control center; if the RTU refuses service due to an information attack when a fault occurs, the faulty line will be in a power outage state, and the fault range will be expanded to the downstream, upstream and adjacent feeder branches of the feeder.

[0079] Furthermore, the impact of availability attacks on downstream regions of a failure can be expressed as follows:

[0080]

[0081] in, This represents the impact of a fault in the i-th feeder segment during an information attack on the downstream power supply area; L e λ represents the load power on the e-th feeder line; i This represents the failure rate of the i-th feeder segment; This represents the set of downstream feeder segments of the i-th feeder segment; P represents the failure probability of the feeder e's transfer path. If there is no transferable line downstream of feeder e, then P... Tie =1, otherwise the value is equal to the probability that the corresponding contact switch fails to operate; S represents the probability that all switches on the path from feeder i to feeder e will fail to operate due to the attack; i,e This represents the set of terminal devices corresponding to all switches along the path from feeder i to feeder e; d represents the probability that an availability attack will cause terminal device k to fail; mttr This represents the average repair time, including manual inspection, network forensics, and fault repair; d rst Indicates the remote control switch time.

[0082] Furthermore, availability attacks can cause the fault to extend to upstream power supply areas, including neighboring branch feeders.

[0083] Furthermore, the formula for the impact of availability attacks on the upstream region of a failure can be expressed as:

[0084]

[0085] in, This represents the impact of a fault in the i-th feeder segment on the upstream power supply area under an information attack; the set of upstream feeder segments of the i-th feeder segment.

[0086] Furthermore, the impact of availability attacks on feeders in proximity to faulty branches can be expressed as follows:

[0087]

[0088] in, This indicates the impact of a fault in the i-th feeder segment on adjacent power supply areas under an information attack. Represents the set of neighboring branch feeders of the i-th feeder segment; This represents the probability that all switches within the range from the i-th feeder segment to the m-th branch of the adjacent feeder will fail to operate due to the attack. This represents the set of all feeder segments on the neighboring feeder m; This represents the set of terminal devices corresponding to all switches within the range from the i-th feeder segment to the m-th branch of the adjacent feeder; This represents the probability that all switches upstream of feeder f on the feeder branch will fail to operate due to the attack. This represents the set of terminal devices corresponding to all switches upstream of feeder f on the feeder branch; the distribution network risk formula under availability attack is expressed as:

[0089]

[0090] Where B represents the set of all feeder segments.

[0091] Furthermore, the establishment of the information attack model includes the following: the impact of an integrity attack on the downstream feeder area of ​​the attacked device terminal can be expressed as follows:

[0092]

[0093] in, This represents the impact of a failure of the j-th terminal device under an information attack on the downstream power supply area; This represents the availability of the upstream feeder area of ​​the j-th terminal device; This represents the probability that the j-th terminal device is attacked, and all terminal devices in its upstream feeder area are operating normally. This represents the set of all feeders in the upstream region of terminal device j; This represents the set of all feeders in the downstream region of terminal device j; This represents the set of all terminal devices in the upstream feeder area of ​​terminal device j; This represents the probability that an integrity attack will cause terminal device j to malfunction.

[0094] Furthermore, the impact of integrity attacks on fault recovery under fault conditions can be expressed as follows:

[0095]

[0096] in, This indicates the impact of a fault recovery on the i-th feeder segment under an information attack. This represents the probability that any terminal device in the downstream area of ​​feeder h will fail due to an attack; This represents the set of all terminal devices downstream of the feeder; This represents the probability that an information attack will cause a malfunction in terminal device j.

[0097] Furthermore, the risk to the distribution network under integrity attacks can be expressed as:

[0098]

[0099] Where S represents the set of all terminal devices.

[0100] It should be noted that integrity attacks targeting terminal equipment can cause their corresponding switches to malfunction. If a switch malfunctions due to an information attack on its corresponding RTU, it will not only cause a power outage in the distribution network under normal operating conditions, but may also affect the power transfer path under fault conditions, thereby expanding the scope of the power outage. When an integrity attack causes the switch corresponding to the RTU to malfunction, regardless of the state of the downstream line, its downstream feeder will be in a state of power outage due to the loss of connection with the upstream power source.

[0101] S3: Establish an information attack model and define the system risk coupling degree and node risk coupling degree.

[0102] Furthermore, the system risk coupling degree and node risk coupling degree include the fact that CPDS must consider not only the impact of line faults and equipment failures in the distribution network, but also the direct and indirect impacts caused by the stable operation of the power grid; therefore, the CPDS risk formula is expressed as:

[0103] R CPDS =R P +R C→P

[0104] Among them, R CPBSThis indicates the risk of power distribution network attacks considering information attacks; R P This represents the risk of a traditional distribution network, i.e., the risk of a distribution network without considering information attacks; R C→P This indicates the risk gains that information attacks bring to the power distribution network.

[0105] Furthermore, such as Figure 2 As shown, when a line fault occurs in the distribution network, if a transfer path exists in the downstream feeder area, the control center will isolate the faulty area and transfer the load in the downstream non-faulty area to a nearby feeder. During this process, if the RTU of the faulty downstream feeder malfunctions due to an information attack, it may affect the power transfer restoration process for the load in the non-faulty area, thereby expanding the power outage area caused by the fault. If the information system is reliable, and a fault occurs at B4, the control center will disconnect switches S3 and S4 to isolate the fault and close switch S10 to transfer the load in areas B5 to B7 to a nearby feeder. When a fault occurs at B4, if R6 is attacked by an information attack causing switch S6 to trip, the power transfer restoration path in the non-faulty area will be blocked. Only the load on B7 in all downstream areas of S4 can be successfully transferred to a nearby feeder.

[0106] Furthermore, the system risk coupling degree is used to characterize the risk gain that abnormal states of the information system bring to the power system under cyber-physical coupling conditions; the formula for the system risk coupling degree is expressed as:

[0107]

[0108] in, This represents the system risk coupling degree, with a value range of [0, +∞]. The system risk coupling degree is directly proportional to the risk gain of information threats to the power system; if A value of 0 indicates that the information threat will not affect the operation of the power distribution network.

[0109] Furthermore, taking the distribution network under information attacks as the research object, this paper analyzes the impact of availability attacks and integrity attacks on the fault handling process of centralized FA systems; the inter-system coupling degree under availability attacks and integrity attacks is expressed as:

[0110]

[0111] in, This indicates the degree of system risk coupling under availability attacks; R represents the system risk coupling degree under integrity attack; p This means that the probability of a successful information attack is set to 0, which means that the information attack will not affect the fault handling process of the FA system.

[0112] Furthermore, the node risk coupling degree is used to characterize the risk gain that abnormal states of information nodes bring to the power system under cyber-physical coupling.

[0113] The node risk coupling degree in a distribution network information system can be expressed as:

[0114]

[0115] in, This represents the node coupling degree of information node j; This represents the impact of the abnormal state of information node j on the distribution network, with a value range of [0, +∞]. A value of 0 indicates that the abnormal state of this node will not affect the operation of the distribution network.

[0116] It should be noted that, on the one hand, terminal equipment monitors the operating status of the power system and uploads this data to the control center via the communication network. On the other hand, the control center analyzes the received data and issues control commands, allowing system operators to observe and control the power system through a human-machine interface. When the information system is operating normally, the control center can promptly and accurately detect problems such as line faults and voltage exceedances in the power system, and formulate handling plans or take control measures to ensure the safe and efficient operation of the system. When the data acquisition, transmission, and control processes in the information system are affected, the control center may be unable to effectively monitor and control the power system, thus worsening the system's operating status. For example, tampering with monitoring data may lead to misjudgments by the control center, or the terminal equipment may be unable to execute control center commands, causing the fault range to expand.

[0117] S4: Perform simulation analysis on risk coupling degree, calculate the risk coupling degree of the system and nodes under different attack types, and complete the risk analysis of the power distribution network system.

[0118] Furthermore, the simulation analysis of risk coupling includes the following: when CPDS is attacked by information, the nodes in the information system are independent of each other, and an attack on a single node will not affect the operating status of other nodes. To quantify the degree of gain of a node being attacked by information on the distribution network risk, all attack events involving nodes need to be considered.

[0119] Furthermore, a proportional sharing method is used to distribute the harm caused by an attack involving multiple target nodes. Based on the weight coefficients of different nodes, the harm of an attack involving multiple nodes is distributed to different nodes. The update formula is expressed as:

[0120]

[0121] in, This represents the set of all instances in an information attack event that contain the target node j. S represents the probability of attack event k occurring; k S represents the set of all target nodes in attack event k; k This indicates that it belongs to set S and does not belong to set S. k The set of nodes; This represents the probability that information node z will fail due to an information attack. c represents the risk gain ratio of node j in attack event k; v This represents the proportional allocation coefficient for information node ν; This represents the risk gain that attack event k causes to the power system; This indicates the damage to the power system caused by the attack.

[0122] Furthermore, by combining the analysis scenarios, the node coupling degree under availability attacks and integrity attacks can be obtained; under availability attacks, This represents the probability that the z-th RTU is attacked and malfunctions. This represents the harm caused to the power system by attack event k; under an integrity attack, This is the probability that the z-th RTU will fail due to an integrity attack. This indicates that an integrity attack event k causes harm to the power system.

[0123] It should be noted that availability attacks refer to attacks where attackers maliciously intrude into the terminal equipment to disrupt its status monitoring and information transmission capabilities, thereby affecting the observability and controllability of the control center and impacting the safe and stable operation of the distribution network. A typical form of this type of attack is a denial-of-service attack, where attackers send a large number of forged data packets into the communication network, rendering the target communication link or terminal equipment unusable. Based on the different layers of the information system, availability attacks can be categorized into attacks targeting the physical layer, MAC layer, network and transport layer, and application layer. This article primarily analyzes information attacks targeting the application layer, specifically those that exhaust the communication bandwidth or computing power of the target RTU in the distribution network, rendering it unable to respond to commands from the control center. When the RTU is unusable, it cannot execute control commands issued by the master station, indirectly affecting the handling of line faults in the distribution network. When there are no faults in the distribution network, the RTU unavailability caused by an availability attack will not affect users. However, when a fault occurs in the distribution network, RTU denial-of-service will affect the fault handling process of the FA system, leading to an expansion of the fault scope.

[0124] On the other hand, this embodiment also provides a risk coupling quantitative analysis system for distribution network systems, which includes:

[0125] The Cyber-Physical System (CPDS) module establishes and maintains the cyber-physical system model of the distribution network; the data collection submodule collects operational data from the power physical system and information system, including equipment status, load data, and communication data; the model building submodule establishes a CPDS model that includes the power physical system and information system; the power physical system includes traditional primary equipment, new energy equipment, and energy storage equipment.

[0126] The information system risk identification and quantification module identifies and quantifies the potential risks of information systems, and classifies attack types into integrity attacks and availability attacks based on the attack effects.

[0127] The information attack model module establishes information attack models and calculates the risk coupling degree between the system and nodes.

[0128] The simulation analysis module performs simulation verification and result analysis on the power distribution network system. It verifies the rationality of the proposed risk coupling degree index and calculation method through simulation results, analyzes the simulation results, and evaluates the effectiveness of different protection measures in reducing system risks.

[0129] If the above functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0130] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device.

[0131] More specific examples of computer-readable media (a non-exhaustive list) include: electrical connections (electronic devices) having one or more wires, portable computer disk drives (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.

[0132] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0133] Example 2

[0134] Reference Figure 3-5 As an embodiment of the present invention, a method for quantitative analysis of risk coupling in a power distribution network system is provided. To verify the beneficial effects of the present invention, scientific demonstration is carried out through economic benefit calculation and simulation experiments.

[0135] IEEE 33-node system, such as Figure 3 As shown, the control center algorithm is a centralized FA algorithm, which can locate, isolate, and restore line faults within the feeder area. The example includes 32 switches, each monitored by an RTU and communicating with the control center via a communication network. The feeder fault rate is 0.05 times / (km·a), and the FA system action time and average fault repair time are set to 5 minutes and 4 hours, respectively. The probability of a terminal device refusing to operate due to an availability attack is set to 6%. The probability of a terminal device malfunctioning due to an integrity attack is set to 0.06 per ten thousand. The proportional weight of all terminal devices is set to 1.

[0136] like Figure 4 As shown, under integrity attacks, the RTU risk coupling degree corresponding to the feeder outlet side switch is high, and the RTU coupling degree is positively correlated with the load downstream of the corresponding switch.

[0137] To analyze the impact of information attacks on system coupling, simulations were performed on the distribution network under availability attacks and integrity attacks, and the results are shown in Table 1.

[0138] Table 1 System Risk Coupling Degree under Two Types of Information Attacks

[0139] Attack type Ignoring information attacks Consider information attacks System risk coupling Availability attack 10.0625 10.4572 0.0392 Integrity attack 10.0625 11.6770 0.1604

[0140] Simulation results show that compared to the system risk without considering information attacks, the system risk increases under both availability attacks and integrity attacks, by 0.3947 MWh and 1.6144 MWh, respectively. This indicates that although FA systems help reduce power outage time caused by line faults, the impact of information attacks cannot be ignored, especially given the trend of deep integration between information and physical systems in future power systems. The system risk coupling degrees under availability attacks and integrity attacks are 0.0392 and 0.1604, respectively. The coupling degree under availability attacks is lower than that under integrity attacks, approximately four times higher. This is mainly because switch failures caused by availability attacks may only lead to an expansion of the fault range when a line fault occurs, while switch maloperations caused by integrity attacks may lead to power outages or expand the scope of the fault impact in both normal and fault states of the power system.

[0141] Under an integrity attack, the risk coupling of the securely configured RTU decreases significantly, while the coupling of other RTUs in the system remains almost unchanged. In this attack, a single device's malfunction causing a switch to trip can result in a power outage for downstream loads, without requiring coordination with other device failures. For the distribution network, the probability of it being in a normal state is far higher than the probability of it being in a fault state. Therefore, although the probability of a fault caused by an integrity-based information attack is much lower than that of an availability-based information attack, the impact of this type of attack on the distribution network is greater.

[0142] like Figure 5 As shown, under an availability attack, the risk coupling of the RTU with secure configuration is reduced to 0. This indicates that secure configuration can effectively improve the RTU's ability to resist information attacks. Furthermore, besides the RTU with secure configuration, the risk coupling of other RTUs in the system is reduced to some extent. This is mainly because under this type of attack, an attack event may involve multiple target devices. When one of the target devices is securely configured, the probability of the attack event occurring decreases to 0, thus affecting the coupling of all devices involved in the attack event.

[0143] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. A method for risk coupling quantification analysis of power distribution network system, characterized in that, The system comprises: Collecting power distribution network system operation data to establish a cyber-physical system model; Determining potential risk types of the information system, identifying and quantifying information system risks; Establishing an information attack model, defining system risk coupling degree and node risk coupling degree; Simulating and analyzing the risk coupling degree, calculating the system and node risk coupling degree under different attack types, and completing the power distribution network system risk analysis; The system risk coupling degree and the node risk coupling degree include, in the CPDS, not only the influence of line fault and equipment failure of the power distribution network, but also the direct and indirect influence of the stable operation of the power grid; the CPDS risk formula is represented as: R CPDS = R P + R C→P where R CPBS represents the power distribution network risk considering information attacks; R P represents the traditional power distribution network risk, i.e., the power distribution network risk without considering information attacks; R C→P represents the risk gain brought by information attacks to the power distribution network; The system risk coupling degree is used to represent the risk gain brought by the abnormal state of the information system to the power system under the cyber-physical coupling state; the system risk coupling degree formula is represented as: wherein, represents the system risk coupling degree, whose value interval is [0, +∞], the system risk coupling degree is proportional to the risk gain of the information threat to the power system; if is 0, it indicates that the information threat will not affect the operation of the distribution network. Taking the power distribution network under information attack as the research object, the influence of availability attack and integrity attack on the fault handling process of centralized FA system is analyzed; the system coupling degree under availability attack and integrity attack is represented as: wherein, represents the system risk coupling degree under availability attack; represents the system risk coupling degree under integrity attack; p represents that the information attack does not affect the failure handling process of the FA system by setting the information attack success probability to 0. The node risk coupling degree is used to represent the risk gain brought by the abnormal state of the information node to the power system under the cyber-physical coupling state; The node risk coupling degree in the power distribution network information system can be represented as: wherein, represents the node coupling degree of information node j; represents the influence of the abnormal state of information node j on the power distribution network, and the value interval is [0, +∞]. If is 0, it indicates that the abnormal state of the node will not affect the operation of the power distribution network.

2. The power distribution system risk coupling quantification analysis method of claim 1, wherein: The establishment of the cyber-physical system model includes that the cyber-physical system model CPDS includes an information system and a power physical system; The power physical system includes traditional primary equipment and photovoltaic, wind power and energy storage equipment; the information system includes a control center, a communication network and intelligent terminal equipment; the control center is the core of the information system, which analyzes the power system state data transmitted from the communication network and issues control instructions to realize control and optimization of different power distribution network scenarios.

3. The power distribution system risk coupling quantification analysis method of claim 2, wherein: The determination of the potential risk types of the information system includes that the information attack on the power distribution network includes active attack, passive attack, proximity attack, internal personnel attack and software and hardware matching attack; From the aspect of attack effect, the attack types are divided into integrity attack and availability attack.

4. The power distribution system risk coupling quantification analysis method of claim 3, wherein: The identification and quantification of information system risks include that based on the analysis of potential risk types, it is obtained that the availability attack on the RTU will cause it to refuse to execute the instructions from the control center; if the RTU refuses to serve when the fault occurs due to the information attack, the fault line will be in a power-off state, and the fault range will be expanded to the downstream, upstream and adjacent feeder branch of the feeder; The influence formula of the availability attack on the downstream area of the fault is represented as: wherein, represents the impact of the failure of the ith feeder on the downstream power supply area under information attack; L e represents the load power on the e-th feeder; λ i represents the failure rate of the i-th feeder; represents the set of feeder segments downstream of the i-th feeder; represents the failure probability of the feeder e transfer path, if there is no transferable line downstream of the feeder e, then P Tie = 1, otherwise the value is equal to the probability of corresponding tie switch failure to act; represents the probability that all switches on the path from feeder i to feeder e are failed to act due to attack; S i,e represents the set of terminal devices corresponding to all switches on the path from feeder i to feeder e; represents the probability that the availability attack causes the terminal device k to fail; d mttr represents the average repair time, including manual inspection, network forensics and fault repair; d rst represents the remote switch time; The availability attack causes the fault range to expand to the upstream power supply area of the fault, including the adjacent branch feeder of the fault; The influence formula of the availability attack on the upstream area of the fault is represented as: wherein, represents the impact of a failure of the ith feeder segment on the upstream power supply area under an information attack; a set of feeder segments upstream of the ith feeder segment. The influence formula of the availability attack on the adjacent branch feeder of the fault is represented as: wherein, represents the impact of a failure of the ith feeder segment on the adjacent service area under information attack; represents the set of adjacent branch feeders of the ith feeder segment; represents the probability that all switches within the branch range of the ith feeder segment to adjacent feeder m fail to operate due to attack; represents the set of all feeder segments on adjacent feeder m; represents the set of terminal devices corresponding to all switches within the branch range of the ith feeder segment to adjacent feeder m; represents the probability that all switches upstream of feeder f on the feeder branch fail to operate due to attack; represents the set of terminal devices corresponding to all switches upstream of feeder f on the feeder branch; the risk formula of distribution network under availability attack is represented as: Wherein, B represents the set of all feeder segments.

5. The power distribution system risk coupling quantification analysis method of claim 4, wherein: The establishment of the information attack model includes that the influence of the integrity attack on the downstream feeder area of the attacked equipment terminal can be represented as: wherein, represents the impact of the failure of the jth terminal device under information attack on the downstream power supply area; represents the availability rate of the upstream feeder area of the jth terminal device; represents the probability that the jth terminal device is attacked and all the terminal devices in the upstream feeder area thereof are normally operated; represents the set of all feeders in the upstream area of the terminal device j; represents the set of all feeders in the downstream area of the terminal device j; represents the set of all terminal devices in the upstream feeder area of the terminal device j; represents the probability that the integrity attack causes the failure of the terminal device j; The influence of the integrity attack on the fault recovery under the fault state can be represented as: wherein, represents the impact of failure recovery on the ith section feeder under information attack; represents the probability of any end device downstream of feeder h failing due to attack; represents the set of all end devices downstream of feeder h; represents the probability of end device j failing due to information attack; The power distribution network risk under the integrity attack can be represented as: Wherein, S represents the set of all terminal equipment.

6. The power distribution system risk coupling quantification analysis method of claim 5, wherein: The simulation analysis on the risk coupling degree includes that nodes in the information system are independent of each other when the information attack CPDS, a single node suffering from an attack does not affect the running state of other nodes, the gain degree of the power distribution network risk caused by the information attack on the node is quantified, and all attack events including the node are considered; The proportional allocation method is used to allocate the damage caused by the attack on multiple target nodes, the information attack damage including multiple nodes is allocated to different nodes according to the weight coefficients of different nodes, and the update formula is represented as: wherein, denotes all the sets containing target node j in information attack events; denotes the probability of attack event k; S k denotes all the target nodes in attack event k; S\S k denotes the node set belonging to set S and not belonging to set S k ; denotes the probability of information node z being attacked and failing; denotes the risk gain ratio of node j in attack event k; c v denotes the proportional allocation coefficient of information node v; denotes the risk gain caused by attack event k to the power system; denotes the damage to the power system caused by attack events; Combining the analysis scenarios, the coupling degree of nodes under availability attack and integrity attack can be obtained; under availability attack, denotes the probability of the zth RTU failing due to the attack denotes the damage caused by attack event k to the power system; under integrity attack, denotes the probability of the zth RTU failing due to the integrity attack denotes the damage caused by integrity attack event k to the power system.

7. A power distribution network system risk coupling quantization analysis system using the method of any one of claims 1-6, characterized in that: An information-physical integrated system module is configured to establish and maintain an information-physical integrated system model of the power distribution network; A data collection sub-module is configured to collect operation data of the power physical system and the information system, including device state, load data, and communication data; A model establishment sub-module is configured to establish a CPDS model including the power physical system and the information system; the power physical system includes traditional primary equipment, new energy equipment, and energy storage equipment; An information system risk identification and quantization module is configured to identify and quantify potential risks of the information system, and divide attack types into integrity attacks and availability attacks from the attack effect aspect; An information attack model module is configured to establish an information attack model and calculate the risk coupling degree of the system and the node; A simulation analysis module is configured to simulate, verify, and analyze the power distribution network system, verify the rationality of the proposed risk coupling degree index and calculation method through simulation results, analyze the simulation results, and evaluate the effect of different protection measures on reducing system risks.

8. A computer device comprising: A memory and a processor; The memory stores a computer program, and the processor executes the computer program to implement the steps of the method of any one of claims 1 to 6.

9. A computer readable storage medium having stored thereon a computer program, characterized in that: The computer program is executed by the processor to implement the steps of the method of any one of claims 1 to 6.

Citation Information

Patent Citations

  • Power grid information physical fusion system risk assessment method

    CN110022293A

  • Power distribution network node risk assessment method and system based on information physical fusion

    CN113111537A