DER Command Filtering for Cybersecure Grid-Support Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing reliance on distributed energy resources (DER) in power systems, which communicate over public internet channels, exposes them to cyber-attacks that can disrupt voltage regulation, frequency control, and bulk system stability, leading to potential equipment damage and power outages.

Innovation Solution

Implementing an engineered control system with intrusion detection and prevention mechanisms at communication nodes between DER and management systems to detect and reject unsafe commands, using pre-programmed firmware or software rules to prevent DERs from operating in destabilizing modes, and employing defense-in-depth security to minimize power system impacts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If DERs communicate over public internet channels to enable grid-support functions, then adaptability and grid integration capability are improved, but cyber security vulnerability and system reliability deteriorate

Engineering Contradiction:
Improvegrid integration capabilityVSAvoidsystem reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

An intrusion detection system (IDS) and intrusion prevention system (IPS) are introduced as intermediary components between the public internet communication channels and the DER control systems. These intermediaries monitor, analyze, and filter communication traffic to block malicious commands while allowing legitimate grid-support functions to operate, thus resolving the contradiction between communication adaptability and system reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If engineered control systems with intrusion detection are implemented at communication nodes, then system security and reliability are improved, but device complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security system is segmented into distributed intrusion detection and prevention modules deployed at individual communication nodes near DER devices, rather than a single centralized complex system. Each module handles local security functions independently, reducing the complexity burden on any single device while collectively providing comprehensive security coverage across the power system

Inventive Principle:
Principle #1Segmentation

3Extent of automation

If pre-programmed firmware rules are used to prevent unsafe operating modes, then response time and automation are improved, but adaptability to new threats deteriorates

Engineering Contradiction:
Improveresponse timeVSAvoidadaptability to new threats
Core Design Contradiction:
Extent of automationVSAdaptability or versatility

Solution Approach 1:

The intrusion detection system incorporates continuous feedback loops that monitor communication traffic patterns, analyze detected threats, and automatically update detection rules and blocking criteria. This feedback mechanism allows the system to maintain fast automated response times through pre-programmed rules while simultaneously adapting to emerging cyber threats by learning from observed attack patterns and updating its defense strategies in real-time

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11831662B1Systems and methods for detecting and mitigating cyber attacks on power systems comprising distributed energy resources
Publication Date: 2023.11.28 NATIONAL TECHNOLOGY & ENGINEERING SOLUTIONS OF SANDIA LLC
  • US11831662B1 patent drawing
  • US11831662B1 patent drawing
  • US11831662B1 patent drawing

AI summary

Extensive deployment of interoperable distributed energy resources (DER) on power systems is increasing the power system cybersecurity attack surface. National and jurisdictional interconnection standards require DER to include a range of autonomous and commanded grid-support functions which can drastically influence power quality, voltage, and the generation-load balance. Investigations of the impact to the power system in scenarios where communications and operations of DER are controlled by an adversary show that each grid-support function exposes the power system to distinct types and magnitudes of risk. The invention provides methods for minimizing the risks to distribution and transmission systems using an engineered control system which detects and mitigates unsafe control commands.