EV Charging Cyber-Attack Detection via Sensor Spoof Observer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Electric vehicle charging infrastructures are vulnerable to cyber-attacks that can disrupt power generation and distribution, cause vehicle malfunctions, and result in catastrophic damage, with existing protection methods failing to adequately detect stealthy attacks at the physical domain layer, especially when multiple attacks occur simultaneously.

Innovation Solution

A framework that includes a sensor spoof observer and controller to detect grid voltage disturbances using an AC filter dynamic model, a system stability assurance platform to monitor current and voltage for resonance and apply adaptive damping control, and a user interface to alert distribution system operators of cyber-attacks via a graphical interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing IT and OT protection methods are used, then basic cybersecurity is maintained, but stealthy attacks at the physical domain layer can still penetrate and cause damage

Engineering Contradiction:
Improvecybersecurity protectionVSAvoidstealthy attacks penetration
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a new detection dimension at the physical domain layer (Layer 0) beyond the traditional IT and OT layers. By deploying sensors and monitoring systems directly at the physical equipment level (chargers, batteries, power grid), the system creates a new defensive dimension that can detect attacks before they cause damage, preventing stealthy penetrations that bypass upper-layer protections.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent segments the charging infrastructure into multiple independent monitoring zones, each with its own sensors and detection algorithms. Individual chargers, battery systems, and power grid components are monitored separately, allowing the system to identify and isolate specific attack points without compromising the entire system, thereby maintaining reliability while blocking harmful factors.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If multiple sensors and monitoring nodes are deployed to detect simultaneous attacks, then detection accuracy improves, but system complexity and cost increase

Engineering Contradiction:
Improveattack detection accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent designs multi-functional monitoring nodes that can detect multiple types of attacks simultaneously using the same sensor infrastructure. The sensors are configured to monitor electrical parameters (current, voltage, frequency) that reveal various attack patterns including sensor spoofing, actuator manipulation, and communication intercepts, thereby improving detection accuracy without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces a centralized analysis platform that acts as an intermediary between distributed sensors and the control system. This platform aggregates data from multiple sensors, applies advanced algorithms to detect coordinated attacks, and generates unified alerts, thereby managing the complexity of multi-sensor systems while maintaining high detection precision for simultaneous attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If rapid response mechanisms are implemented to maintain electrical stability during attacks, then system availability is preserved, but control system complexity increases

Engineering Contradiction:
Improvesystem availabilityVSAvoidcontrol system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent pre-configures emergency response protocols and control algorithms that automatically execute upon attack detection. The system maintains pre-computed remediation strategies for various attack scenarios, allowing rapid response without requiring complex real-time decision-making, thereby preserving system availability while managing control complexity through automation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements closed-loop feedback mechanisms where sensor data continuously monitors system state, and control actions are automatically adjusted based on detected anomalies. The feedback loop enables the system to self-correct during attacks by comparing actual performance against expected behavior and applying compensatory control, maintaining availability through automated responses rather than complex manual intervention systems.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11305665B2Cyber-attack detection and electrical system stability for electric vehicle charging infrastructure
Publication Date: 2022.04.19 GENERAL ELECTRIC CO
  • US11305665B2 patent drawing
  • US11305665B2 patent drawing
  • US11305665B2 patent drawing

AI summary

Some embodiments provide a system to protect an electric vehicle charging infrastructure. An electric vehicle charging site may receive Alternating Current (“AC”) power from a power grid and provides Direct Current (“DC”) power to electric vehicles. A sensor spoof observer and controller may receive information from at least two AC current sensors, wherein the observer calculates a grid voltage disturbance using a structure based on an AC filter dynamic model. A system stability assurance platform may: (i) monitor current and voltage to detect resonance, (ii) identify impedance associated with a detected resonance, and (iii) apply a result of an analysis of the identified impedance to an adaptive damping control algorithm. A user interface platform may then provide information about a component of the charging infrastructure being cyber-attacked to a distribution system operator via a graphical user interface display.