Digital Twin for Cyber-Physical Microgrid Resilience

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Distributed control systems in networked microgrids are vulnerable to cyber threats due to the absence of centric oversight and low-security levels, making them susceptible to coordinated attacks that can disrupt consensus among controllers and compromise the entire microgrid cluster.

Innovation Solution

An IoT-based digital twin (DT) platform is implemented as a centric oversight for cyber-physical networked microgrids, hosting controllers and sensors in the cloud IoT core, which generates a real-time digital replica of the physical and cyber layers to detect false data injection and denial of service attacks, and takes corrective action to mitigate attacks through a Luenberger Observer and what-if scenarios.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If distributed control architecture is used in networked microgrids, then system flexibility and plug-and-play capability are improved, but vulnerability to cyber attacks increases

Engineering Contradiction:
Improveplug-and-play capabilityVSAvoidsecurity against cyber attacks
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a centralized security monitoring system that acts as an intermediary between distributed controllers and the external network. This mediator monitors communication traffic, detects anomalies, and coordinates security responses across the distributed architecture, thereby maintaining both decentralization benefits and centralized security oversight.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security system is segmented into multiple distributed security agents deployed at different microgrid nodes, each capable of local threat detection and response. This segmentation allows the system to maintain distributed control while implementing layered security defenses that can operate autonomously or coordinate centrally depending on threat levels.

Inventive Principle:
Principle #1Segmentation

2Difficulty of detecting and measuring

If centralized security monitoring is implemented, then detection capability against coordinated attacks is improved, but system complexity increases

Engineering Contradiction:
Improveattack detection capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The security monitoring system is designed as a multi-functional platform that performs threat detection, anomaly analysis, coordinate attack identification, and automated response coordination. By consolidating these functions into a universal security operating system, the patent reduces overall system complexity compared to implementing separate specialized systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system creates virtual copies of security agents that run in simulated environments to model attack scenarios and test detection algorithms. These digital twins of security functions allow for comprehensive attack detection capability development without adding physical hardware complexity to the actual microgrid infrastructure.

Inventive Principle:
Principle #26Copying

3Reliability

If security measures are strengthened in distributed control systems, then system reliability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity resilienceVSAvoidsystem operation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security system implements automated self-service capabilities including autonomous threat detection, automatic anomaly classification, self-coordinated response activation, and automated security policy updates. This self-service approach maintains high security resilience while minimizing the operational burden on human operators who only need to monitor high-level security dashboards rather than manually managing complex security protocols.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11381582B1Energy cyber-physical system digital twin playground
Publication Date: 2022.07.05 FLORIDA INTERNATIONAL UNIVERSITY
  • US11381582B1 patent drawing
  • US11381582B1 patent drawing
  • US11381582B1 patent drawing

AI summary

Systems and methods for enhancing resiliency of a power system (e.g., an energy cyber-physical system (ECPS)) against cyber-attacks are provided. An internet of things (IoT)-based digital twin (DT) for cyber-physical networked microgrids (NMGs) can be implemented to be a centric oversight for the NMG system. A cloud system can host the controllers (cyber things) and the sensors (physical things) of the power system into the cloud IoT core in terms of the IoT shadow. The DT can cover the digital replica for the physical layer, the cyber layer(s), and their hybrid interactions.