Circuit Breaker Command Validation in Digital Substations
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern electric power substations are vulnerable to cyber-attacks due to the use of digitized sample value streams and Ethernet technology, which can lead to false trips and potentially cause grid collapse, and there is a lack of effective detection for malicious direct control commands on circuit breakers.
Innovation Solution
A measurement-based security approach is implemented, where the dynamic operating state of the electric power network is predicted in response to circuit breaker control commands, and these predictions are compared to operational limits to block commands that would violate those limits, ensuring secure operation and preventing undesirable consequences.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If digitized sample value streams and Ethernet technology are used in modern substations, then communication efficiency and data processing capability are improved, but vulnerability to cyber-attacks increases
Solution Approach 1:
The patent introduces an intermediary security validation layer between the network communication interface and the circuit breaker control system. This intermediary component validates control commands against current system state parameters before execution, blocking malicious commands while allowing legitimate operations. The intermediary acts as a security gatekeeper that maintains communication efficiency while filtering out cyber threats.
Solution Approach 2:
The system performs preliminary validation of control commands by predicting future system states and comparing them against operational limits before actual command execution. This preliminary action prevents malicious commands from reaching the circuit breaker by identifying and blocking them in advance based on their potential to violate operational constraints.
2Speed
If direct control commands can be executed without validation, then system responsiveness and operational speed are improved, but system security deteriorates
Solution Approach 1:
The validation process performs preliminary prediction of system states and comparison against operational limits before command execution. This preliminary security check is integrated into the command processing pipeline, allowing rapid validation without significant delay to command execution speed.
Solution Approach 2:
The system uses its own operational parameters and state information to perform self-validation of control commands. By comparing predicted future states against its own operational limits, the system autonomously determines command validity without requiring external validation, maintaining fast response times while ensuring security.
3Reliability
If comprehensive state parameter validation is performed before command execution, then system security is improved, but processing time and computational complexity increase
Solution Approach 1:
The system performs validation only on the critical state parameters necessary to determine command safety, rather than comprehensively checking all possible system parameters. This partial validation approach focuses computational resources on the most important security-relevant parameters, reducing processing time while maintaining adequate security validation.
Solution Approach 2:
The validation process uses efficient prediction algorithms that quickly estimate future system states without performing exhaustive calculations. The system rushes through the essential validation steps by using approximate prediction methods that are sufficiently accurate for security determination but computationally much lighter than complete analysis.
Data Source
AI summary
Methods and systems for secured control of circuit breakers in an electric power substation against undesired direct operation. Consequences of a malicious action are prevented or mitigated using a validation approach that either blocks the command or ensures a negligible effect on system operation. An example method, suitable for implementation in a monitoring device in an electric power substation, includes receiving a command to open or close a circuit breaker. In response, one or more state parameters for the electric power network that comprises the substation are then predicted, the predicted state parameters reflecting an operating state for the network under the assumption that the received command is executed. The method further comprises comparing the predicted one or more state parameters to corresponding operational limits. Execution of the command is then blocked, in response to determining that one or more of the predicted state parameters violate the corresponding operational limits.


