Engineered Control Layer for Cyberattack Detection in Grid Converters

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cyberattacks on grid-connected systems, including systems with grid-connected communications equipment, power-conversion devices, or power-generation devices, can cause maloperation and compromise grid stability due to manipulated control settings and falsified data, posing a significant threat to power system reliability.

Innovation Solution

Implementing an engineered control system with intrusion detection and prevention systems (IDS/IPS) that utilize pre-programmed malicious signatures, context-aware settings, and behavioral rules to detect and mitigate falsified messages and abnormal operations in grid-connected systems, incorporating data streams from various sources for accurate estimation and validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If grid-connected systems use standardized communication interfaces and shared networks for control and monitoring, then system versatility and grid integration capability are improved, but the attack surface expands and security vulnerability increases

Engineering Contradiction:
Improvegrid integration capabilityVSAvoidcyber attack exposure
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an engineered control system as an intermediary layer between the grid-connected devices and the communication network. This intermediary validates all commands and measurements before they enter the control system, effectively isolating the critical control functions from potential cyber threats while still allowing full grid integration functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary validation of commands and measurements against expected physical constraints and operational ranges before executing them. This preventive approach blocks malicious inputs before they can cause harm, while allowing legitimate grid operations to proceed uninterrupted.

Inventive Principle:
Principle #9Preliminary anti-action

2Reliability

If intrusion detection and prevention systems are implemented to detect and mitigate cyberattacks, then system security is improved, but device complexity increases

Engineering Contradiction:
ImprovecybersecurityVSAvoidcontrol system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The engineered control system performs self-validation by automatically comparing incoming commands and measurements against pre-established physical constraints and operational ranges. This self-service approach embeds security functionality within the control logic itself, eliminating the need for separate complex security systems while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the operational parameters of the control system by incorporating validation thresholds and expected range definitions. These parameter changes enable the control system to inherently reject unauthorized commands without requiring additional complex detection infrastructure.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If validation rules and expected ranges are enforced to prevent unauthorized operations, then system reliability is improved, but operational flexibility may be reduced

Engineering Contradiction:
Improveoperational stabilityVSAvoidoperational flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The validation rules and expected ranges are configured dynamically based on the specific device type, operational mode, and physical constraints. This dynamic configuration allows the system to adapt validation parameters to different operating conditions, maintaining both reliability through enforced constraints and flexibility through configurable parameters.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes validation parameters dynamically according to the operational context. Different devices and operating modes have different expected ranges and constraints, allowing the system to adjust these parameters to match the current operational state while maintaining security through enforced validation rules.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20260012478A1Systems and Methods for Detecting and Mitigating Cyber Attacks on Converter-Based Energy Equipment and Associated Communication Networks
Publication Date: 2026.01.08 DER SECURITY CORP
  • US20260012478A1 patent drawing
  • US20260012478A1 patent drawing
  • US20260012478A1 patent drawing

AI summary

Extensive deployment of interoperable grid-connected systems and devices, such as grid-connected communications equipment, power-conversion devices, or power-generation devices, including inverter-based resources (IBR), distributed energy resources (DER), electric vehicle supply equipment (EVSE), and similar devices is increasing the power system cybersecurity attack surface. Systems and methods are provided for minimizing the risks to grid-connected systems using an engineered control system to detect and mitigate malicious system operations. Malicious operations are mitigated by analyzing measurement data from grid-connected devices for consistency or comparing this data against other grid-connected devices, models of devices, or other parameters, such as simulations, on-site or remote power sensors, power system simulations, historical operations, or known operating characteristics for such grid-connected devices. Communication-based cybersecurity detection capabilities are also provided based on non-permitted writing or reading values, attempts at writing read-only points, or capturing protocol-specific errors or exceptions.