Power Subsystem Cyber-Attack Detection via Interaction Variables

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern power subsystems, including microgrids, are vulnerable to cyber-attacks that can compromise their operation by disrupting power management and control systems, posing significant operational risks.

Innovation Solution

A system comprising an interface, a controller, and a cyber-attack identification module that calculates an interaction variable from internal states of the power subsystem, compares it with external power signals, and identifies cyber-attacks by determining differences exceeding a threshold, enabling rapid detection and defense mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If computerized management systems are used to monitor and control power sources, loads, and storage elements, then system operation and power management are improved, but the system becomes susceptible to cyber-attacks that can interrupt or disrupt operations

Engineering Contradiction:
Improvepower managementVSAvoidsystem operation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary monitoring system that acts as a mediator between the computerized management system and the external environment. This intermediary layer detects cyber-attacks by monitoring anomalies in power measurements and communications, thereby protecting the management system from direct cyber threats while maintaining operational functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where measurements of power, voltage, current, and frequency are continuously monitored and compared against expected values. When deviations indicate a cyber-attack, the system provides feedback to trigger alarm conditions and defensive actions, creating a closed-loop protection system that responds to threats in real-time.

Inventive Principle:
Principle #23Feedback

2Reliability

If cyber-attack detection capabilities are added to the power subsystem, then system security is improved, but device complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoiddetection system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs the detection system to perform multiple functions using a unified approach. The same monitoring infrastructure that tracks power system performance is also used to detect cyber-attacks, eliminating the need for separate dedicated detection hardware and reducing overall system complexity while enhancing security capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses its existing measurements and operational data to detect cyber-attacks without requiring external detection equipment. By analyzing anomalies in its own power measurements, voltage, current, and frequency data, the power subsystem performs self-diagnosis and self-protection, reducing the need for additional complex detection infrastructure.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240314143A1Cyber-secure dynamic monitoring and decision systems
Publication Date: 2024.09.19 MASSACHUSETTS INST OF TECH
  • US20240314143A1 patent drawing
  • US20240314143A1 patent drawing
  • US20240314143A1 patent drawing

AI summary

Systems and methods for detecting cyber attacks of subsystems include an interface of the subsystem that provides power exchange. A processor may be configured to calculate an interaction variable from a function of one or more internal states of the subsystem. A comparator circuit is coupled to receive the output signal and the interaction variable, to determine a difference between at least one characteristic of the power signal and at least one characteristic of the interaction variable. A cyber-attack identification module is configured to identify the presence of a cyber-attack targeting the system based on the difference between the at least one characteristic of the power signal and the at least one characteristic of the interaction variable.