Circuit Breaker Command Validation in Digital Substations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern electric power substations are vulnerable to cyber-attacks due to the use of digitized sample value streams and Ethernet technology, which can lead to false trips and potentially cause grid collapse, and there is a lack of effective detection for malicious direct control commands on circuit breakers.

Innovation Solution

A measurement-based security approach is implemented, where the dynamic operating state of the electric power network is predicted in response to circuit breaker control commands, and these predictions are compared to operational limits to block commands that would violate those limits, ensuring secure operation and preventing undesirable consequences.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If digitized sample value streams and Ethernet technology are used in modern substations, then communication efficiency and data processing capability are improved, but vulnerability to cyber-attacks increases

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidcyber-attack vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary security validation layer between the network communication interface and the circuit breaker control system. This intermediary component validates control commands against current system state parameters before execution, blocking malicious commands while allowing legitimate operations. The intermediary acts as a security gatekeeper that maintains communication efficiency while filtering out cyber threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary validation of control commands by predicting future system states and comparing them against operational limits before actual command execution. This preliminary action prevents malicious commands from reaching the circuit breaker by identifying and blocking them in advance based on their potential to violate operational constraints.

Inventive Principle:
Principle #10Preliminary action

2Speed

If direct control commands can be executed without validation, then system responsiveness and operational speed are improved, but system security deteriorates

Engineering Contradiction:
Improvecommand execution speedVSAvoidsystem security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The validation process performs preliminary prediction of system states and comparison against operational limits before command execution. This preliminary security check is integrated into the command processing pipeline, allowing rapid validation without significant delay to command execution speed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses its own operational parameters and state information to perform self-validation of control commands. By comparing predicted future states against its own operational limits, the system autonomously determines command validity without requiring external validation, maintaining fast response times while ensuring security.

Inventive Principle:
Principle #25Self-service

3Reliability

If comprehensive state parameter validation is performed before command execution, then system security is improved, but processing time and computational complexity increase

Engineering Contradiction:
Improvecommand validation securityVSAvoidcommand processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs validation only on the critical state parameters necessary to determine command safety, rather than comprehensively checking all possible system parameters. This partial validation approach focuses computational resources on the most important security-relevant parameters, reducing processing time while maintaining adequate security validation.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The validation process uses efficient prediction algorithms that quickly estimate future system states without performing exhaustive calculations. The system rushes through the essential validation steps by using approximate prediction methods that are sufficiently accurate for security determination but computationally much lighter than complete analysis.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS10365676B2Secured control of circuit breakers in a digital substation
Publication Date: 2019.07.30 HITACHI ENERGY LTD
  • US10365676B2 patent drawing
  • US10365676B2 patent drawing
  • US10365676B2 patent drawing

AI summary

Methods and systems for secured control of circuit breakers in an electric power substation against undesired direct operation. Consequences of a malicious action are prevented or mitigated using a validation approach that either blocks the command or ensures a negligible effect on system operation. An example method, suitable for implementation in a monitoring device in an electric power substation, includes receiving a command to open or close a circuit breaker. In response, one or more state parameters for the electric power network that comprises the substation are then predicted, the predicted state parameters reflecting an operating state for the network under the assumption that the received command is executed. The method further comprises comparing the predicted one or more state parameters to corresponding operational limits. Execution of the command is then blocked, in response to determining that one or more of the predicted state parameters violate the corresponding operational limits.