Cyber-Physical System for Resilient Monitoring and Containment of Electrical and Computational Infrastructure
The cyber-physical system addresses the limitations of existing cybersecurity by integrating electrical and computational monitoring, using adaptive hardware-software interaction and hierarchical coordination, enabling scalable and resilient defense with continuous learning.
Patent Information
- Authority / Receiving Office
- GB · GB
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-12-15
- Publication Date
- 2026-04-08
AI Technical Summary
Existing cybersecurity systems lack integration of electrical and computational domains, fail to incorporate hardware-based sacrificial layers, operate with static defensive configurations, and do not leverage hierarchical compute resources effectively, leading to inadequate detection and response to adaptive anomalous behavior in modern, coupled power and data environments.
A cyber-physical monitoring and containment system integrating electrical sensing, adaptive hardware-software interaction, and hierarchical coordination, with sentinel nodes and a centralised compute node, employing sacrificial layers and a digital twin environment for learning and containment.
Enables integrated monitoring and adaptive, graduated containment, leveraging hierarchical compute resources for scalable and resilient defense against evolving threats, with continuous learning and improved system performance.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to cyber-physical resilience and monitoring of civilian electrical and computational infrastructure, and in particular, to systems for detecting, containing, and learning from anomalous behaviour affecting coupled power and data environments. Background of the Invention
[0002] Existing cybersecurity approaches are predominantly software-centric and are generally focused on monitoring and analysing data pipelines, network traffic, or applicationlevel behaviour. Such systems typically operate independently of the physical power infrastructure that supports computational workloads.
[0003] As a result, conventional systems often lack visibility into electrical conditions, such as voltage instability, harmonic distortion, or transient disturbances, that may correlate with or influence anomalous computational behaviour. This separation limits the ability of existing defences to detect or interpret cyber-physical interactions in modern infrastructure environments.
[0004] Modern computational infrastructure is increasingly coupled to complex electrical environments, including microgrids, distributed energy resources, and power-electronic systems. However, current cybersecurity solutions generally do not incorporate direct sensing or interpretation of electrical grid or microgrid conditions as part of their monitoring or response logic. This lack of integration reduces situational awareness in environments where electrical and computational behaviour are interdependent.
[0005] Conventional defensive systems are typically designed as monolithic protection mechanisms, in which a single software stack or control plane is responsible for detecting and responding to anomalous behaviour. In such architectures, defensive outcomes are often binary: either the system successfully blocks an anomaly, or the system is compromised as a whole. There is generally no concept of hardware-based sacrificial layers that can be intentionally isolated, degraded, or replaced to preserve the integrity of the wider system.
[0006] Many existing defences operate as static barriers, analogous to fixed walls or perimeters, with predefined rules and configurations. While such approaches may be effective against known patterns, they are less suited to dynamic or evolving conditions. Static defensive postures may be insufficient in environments where anomalous behaviour adapts over time or exploits interactions across multiple system layers.
[0007] Current cybersecurity systems commonly apply the same defensive logic across heterogeneous hardware environments, regardless of differences in computational capability. More powerful hardware resources are typically used to improve performance or throughput, rather than being leveraged as graduated or hierarchical defensive layers. As a result, existing systems often do not exploit the potential of higher-capacity compute resources to act as enhanced containment or analysis layers when simpler defences are insufficient.
[0008] Emerging forms of anomalous behaviour increasingly exhibit adaptive or learningbased characteristics, in which behaviour changes in response to defensive actions. Conventional “detect and block” or “stop and remove” strategies may be inadequate in such contexts, as they provide limited opportunity for structured observation, learning, or longterm improvement of defensive responses.
[0009] There is therefore a need for a civilian cyber-physical resilience system that: (a) integrates monitoring of both electrical and computational domains; (b) incorporates hardware-based sacrificial layers to prevent system-wide compromise; (c) supports dynamic and adaptive defensive behaviour rather than static configurations; (d) leverages hierarchical compute capability to provide graduated levels of containment and analysis; and (e) enables structured learning from anomalous interactions to improve future system performance.
[0010] The present invention addresses these needs. Summary of the Invention
[0011] The present invention provides a cyber-physical monitoring, resilience, and containment system for civilian electrical and computational infrastructure. The system integrates electrical sensing, data pipeline observation, adaptive hardware-software interaction, and hierarchical coordination within a unified architecture.
[0012] In one aspect, the invention comprises a plurality of distributed cyber-physical sentinel nodes deployed within a civilian electrical network or associated computational environment. Each sentinel node is configured to monitor electrical parameters of a local power system together with data processing activity that is electrically coupled to the monitored system. Local parallel computation enables real-time analysis of these combined inputs.
[0013] Each sentinel node further includes a dynamically reconfigurable external interface and a multi-layer protective architecture comprising an outer adaptive layer and one or more inner sacrificial layers. The sacrificial layers are configured to be isolated in response to anomalous conditions, thereby preventing system-wide disruption while preserving operational continuity.
[0014] Operational data associated with isolation events is recorded and used to improve subsequent system behaviour. In preferred embodiments, learning is performed locally at individual sentinel nodes, and learning outcomes are aggregated into a shared distributed model, enabling collective improvement without transfer of raw sensor data.
[0015] The plurality of sentinel nodes is coordinated by an orchestration controller that implements a hierarchical step-up and step-down control process. Local responses are prioritised, with escalation to higher levels of coordination occurring only when predefined thresholds are exceeded. This pyramidal coordination structure enables scalable and efficient system operation.
[0016] The system further includes a centralised high-capacity compute node configured to function as a final containment layer. When local and intermediate responses are insufficient, the centralised compute node is configured either to terminate the anomalous interaction or to redirect the interaction into a logically isolated digital twin environment. The digital twin environment preserves behavioural fidelity while enabling safe analysis and system learning.
[0017] In optional embodiments, communications between system components are encrypted, and control actions or escalation decisions are cryptographically verified prior to execution. Such mechanisms enhance trust, auditability, and resilience in distributed deployments.
[0018] The invention thereby provides an improved cyber-physical system that integrates electrical and computational monitoring, enables graduated and sacrificial containment, leverages hierarchical compute capability, and supports continuous learning in dynamic civilian infrastructure environments. Description of the Drawings
[0019] FIG. 1 illustrates the overall system architecture of the cyber-physical sentinel system. Detailed Description of the Invention Overview
[0020] The present invention relates to a cyber-physical monitoring, resilience, and containment system for civilian electrical and computational infrastructure. In particular, the invention provides a distributed architecture in which a plurality of cyberphysical sentinel nodes monitor electrical grid conditions and associated data processing activity, adapt dynamically to anomalous conditions, and coordinate responses through a hierarchical orchestration controller.
[0021] Unlike conventional cybersecurity or grid monitoring systems that operate purely in the digital or physical domain, the disclosed system integrates electrical sensing, computational analysis, adaptive interfaces, and learning-based coordination within a unified framework. The invention further provides mechanisms for containment, isolation, and redirection of anomalous interactions into a controlled digital twin environment for analysis and system improvement. Sentinel Node Architecture
[0022] Each sentinel node is deployed at a location within a civilian electrical network, microgrid, or associated computational environment, such as within or adjacent to power-electronic equipment, computing nodes, or infrastructure interfaces.
[0023] A sentinel node comprises: (a) one or more sensors configured to measure electrical parameters including voltage, frequency, phase, harmonic distortion, transient disturbances, or other indicators of electrical stability; (b) one or more interfaces configured to observe data pipeline activity associated with computational workloads that are electrically coupled to the monitored power system; (c) a local parallel-compute platform, such as a graphics processing unit or equivalent, configured to analyse the sensed electrical and data parameters in real time.
[0024] The sentinel node further comprises a positioning and environmental awareness module, which may include a global positioning receiver, timing reference, weather input, or other contextual data source. This module enables correlation of sensed anomalies with time, location, or environmental conditions. Adaptive External Interface and Sacrificial Layers
[0025] Each sentinel node includes a dynamically reconfigurable external interface configured to alter its cyber-physical signature over time. Such reconfiguration may include modification of communication patterns, timing characteristics, protocol behaviour, or physical operating parameters.
[0026] The sentinel node further comprises a multi-layer protective architecture, including an outer adaptive layer and one or more inner sacrificial layers. The sacrificial layers are configured to absorb, isolate, or terminate anomalous interactions without compromising the continued operation of the overall system.
[0027] In certain embodiments, sacrificial layers are implemented as modular or hot-swappable functional components that can be isolated, replaced, or reinitialised following an isolation event. Event Recording and Learning
[0028] When a sacrificial layer is isolated or deactivated, the sentinel node records operational data associated with the period preceding and during the event. Such data may include electrical measurements, data pipeline characteristics, internal system state, and response actions.
[0029] The recorded data is structured as an event record and made available for learning and analysis. In some embodiments, the event record is cryptographically protected to ensure integrity and provenance.
[0030] Sentinel nodes contributing event records may subsequently be reconfigured or redeployed based on learned resilience characteristics derived from prior events. Federated Learning and Shared Distributed Model
[0031] The system includes a shared distributed model that aggregates learning outcomes generated by individual sentinel nodes. In preferred embodiments, learning is performed locally at each sentinel node, and only model parameters, updates, or abstracted outcomes are shared.
[0032] This approach enables a federated learning process, in which raw sensor data remains local while collective intelligence is continuously improved. The shared distributed model may be used to refine anomaly detection thresholds, response strategies, or adaptive behaviours across the plurality of sentinel nodes. Orchestration Controller and Hierarchical Coordination
[0033] An orchestration controller coordinates the operation of the plurality of sentinel nodes using a hierarchical step-up and step-down control process.
[0034] Local responses are prioritised at the sentinel node level. Escalation to higher levels of coordination occurs only when predefined stability, integrity, or performance thresholds are exceeded. Conversely, once stability is restored, control may be stepped down to local autonomy.
[0035] This pyramidal coordination structure reduces unnecessary central intervention while enabling system-wide response when required. Centralised Compute Node and Containment
[0036] The system further comprises a centralised high-capacity compute node that functions as a final containment layer for unresolved anomalous interactions.
[0037] Upon detection of a predefined escalation condition, the centralised compute node is configured to either: (a) terminate the anomalous interaction, or (b) redirect the interaction into a high-fidelity digital twin environment that is logically isolated from the operational system. Digital Twin Redirection Environment
[0038] The digital twin environment is configured to preserve temporal continuity and behavioural fidelity of redirected interactions while remaining isolated from live infrastructure. This environment enables safe observation, analysis, and characterisation of anomalous behaviours without risk to operational systems.
[0039] Insights derived from the digital twin environment may be used to improve future system responses, update the shared distributed model, or refine orchestration strategies. Secure Telemetry and Verification
[0040] In some embodiments, telemetry exchanged between sentinel nodes, the orchestration controller, and the centralised compute node is encrypted. Control actions, configuration updates, or escalation decisions may be cryptographically signed and verified prior to execution.
[0041] Such mechanisms enhance trust, auditability, and resilience of the system, particularly in distributed deployments. Variations and Implementations
[0042] The invention is not limited to the specific embodiments described herein. Sentinel nodes may be deployed in a variety of civilian infrastructure contexts, including electrical substations, distributed energy resources, data processing facilities, or integrated powercompute devices.
[0043] The scope of the invention is defined by the claims. Key to Figure Reference Numerals 1: Cyber attack 2: Outer concentric layer of cyber-physical sentinel nodes 3: High capacity compute node in final containment layer 4: Isolated digital twin environment 5: Infrastructures such as data centres or electrical stations Figure Caption FIG. 1 Illustrates the overall architecture of the cyber-physical sentinel system.
Claims
1. A cyber-physical monitoring and containment system, comprising:(a) a plurality of distributed sentinel nodes deployed within a civilian electrical network and an associated data processing environment;(b) wherein each sentinel node comprises(i) one or more sensors configured to measure electrical parameters of a local power system including at least voltage, frequency, phase, harmonic content, or transient disturbances,(ii) one or more interfaces configured to observe data pipeline activity associated with computational workloads coupled to the power system, and (iii) a local parallel-compute platform configured to perform real-time analysis of the sensed electrical and data parameters;(c) wherein each sentinel node further comprises(i) a positioning and environmental awareness module comprising at least one of a global positioning receiver, a timing reference, or a weather or environmental data input, and(ii) a dynamically reconfigurable external interface configured to alter its cyber-physical signature over time;(d) a multi-layer protective architecture comprising an outer adaptive layer and one or more inner sacrificial layers configured to absorb anomalous interactions;(e) an orchestration controller configured to coordinate the plurality of sentinel nodes using a hierarchical step-up and step-down control process;(f) a shared distributed model configured to aggregate learning, anomaly characterisations, or response outcomes generated by individual sentinel nodes; and(g) a centralised high-capacity compute node configured, upon detection of a predefined escalation condition, to either(i) terminate the anomalous interaction, or(ii) redirect the interaction into a high-fidelity digital twin environment that is logically isolated from the operational system.
2. The system of claim 1, wherein the electrical parameters are sampled synchronously with data pipeline activity to establish causal relationships between power disturbances and computational behaviour.
3. The system of claim 1, wherein the local parallel-compute platform comprises a graphics processing unit or equivalent massively parallel processor.
4. The system of claim 1, wherein the environmental awareness module is configured to contextualise sensed anomalies using time, location, or environmental conditions.
5. The system of claim 1, wherein the dynamically reconfigurable external interface alters at least one of communication patterns, timing characteristics, protocol signatures, or physical operating parameters.
6. The system of claim 1, wherein the sacrificial layers comprise modular, hot-swappable functional components configured to be isolated or replaced without system shutdown.
7. The system of claim 6, wherein the sacrificial layers are configured to record operational data preceding and during an isolation or shutdown event.
8. The system of claim 1, wherein operational data captured during a sentinel node isolation event is retained as a structured event record.
9. The system of claim 8, wherein the structured event record is used to update the shared distributed model.
10. The system of claim 9, wherein sentinel nodes that have contributed event records are preferentially reconfigured or redeployed based on learned resilience characteristics.
11. The system of claim 1, wherein the orchestration controller operates using a pyramidal coordination structure in which local responses are prioritised before escalation to higher-level coordination.
12. The system of claim 11, wherein step-up escalation occurs only when predefined stability or integrity thresholds are exceeded.
13. The system of claim 1, wherein the shared distributed model is updated without transfer of raw sensor data between sentinel nodes.
14. The system of claim 1, wherein the centralised high-capacity compute node comprises a final containment layer for unresolved anomalies.
15. The system of claim 14, wherein redirection into the digital twin environment preserves temporal continuity and behavioural fidelity of the anomalous interaction.
16. The system of claim 15, wherein the digital twin environment is used to analyse, characterise, and improve future system responses.
17. A method of cyber-physical monitoring and containment, comprising:(a) sensing electrical parameters of a civilian power system and data pipeline activity associated with computational workloads;(b) analysing the sensed parameters locally using parallel computation;(c) dynamically adapting a cyber-physical interface of a sentinel node;(d) isolating or sacrificing one or more system layers upon detection of anomalous behaviour;(e) recording operational data associated with the isolation event;(f) updating a shared distributed model using the recorded data;(g) and, upon escalation, either terminating the anomalous interaction or redirecting it into a digital twin environment isolated from the operational system.
18. A computer-readable medium comprising instructions which, when executed by one or more processors, cause the system of claim 1 to perform the method of claim 17.
19. The system of claim 1, wherein telemetry exchanged between sentinel nodes and the orchestration controller is encrypted.
20. The system of claim 1, wherein control actions, configuration updates, or escalation decisions are cryptographically signed and verifiable prior to execution.A
Citation Information
Patent Citations
Voltage control strategy of power information physical system under data tampering attack
CN111817290A
Electric power big data-based central monitoring platform and monitoring analysis method
CN119561227A