Substation Cybersecurity via Power Flow Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Electric power substations are vulnerable to cyber-attacks that can manipulate circuit breaker control commands, potentially leading to cascading failures and grid collapse, as existing cyber-mitigation techniques have limitations in detection accuracy and can be compromised by sophisticated intrusions.

Innovation Solution

A method and system that utilize a modified extended power flow model of the substation and its neighboring substations to predict the impact of circuit breaker control commands, blocking malicious commands if predicted voltages exceed allowable ranges or if power flow calculations indicate potential voltage collapse or singularity in the Jacobian matrix.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing cyber-mitigation techniques are used to detect malicious control commands, then detection capability is provided, but detection accuracy is limited and can be compromised by sophisticated intrusions

Engineering Contradiction:
Improvedetection accuracyVSAvoidsecurity against sophisticated intrusions
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces an intermediary verification mechanism that uses power flow analysis as a mediator to validate circuit breaker control commands. Instead of relying solely on existing cyber-mitigation techniques that can be compromised, the system uses physical power flow calculations as an intermediate layer to verify whether commanded operations are physically reasonable. This intermediary check adds a layer of security that is difficult to bypass since it is based on fundamental physical laws rather than software-based detection alone.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces reliance on software-based cyber-mitigation detection systems with physics-based power flow analysis. By substituting mechanical/software-based detection with physics-based validation, the system achieves higher detection accuracy that cannot be easily compromised by sophisticated intrusions. The power flow analysis uses fundamental electrical engineering principles to verify command legitimacy, making the detection mechanism more reliable against advanced attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If power flow analysis is performed to predict operational consequences, then security against malicious commands is improved, but computational complexity increases

Engineering Contradiction:
Improvesecurity against malicious commandsVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the power flow analysis into focused, targeted calculations that only evaluate the local impact of specific circuit breaker commands rather than performing comprehensive system-wide analyses. By segmenting the analysis to focus only on relevant portions of the power system affected by a commanded operation, the computational complexity is reduced while maintaining security effectiveness. The system divides the complex power system into manageable segments for analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action by performing power flow analysis only when circuit breaker control commands are received, rather than continuously monitoring all system parameters. The analysis is triggered selectively based on control events, reducing overall computational burden while maintaining security. This partial action approach performs detailed analysis only when necessary, rather than excessive continuous monitoring.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If real-time power flow analysis is performed for each control command, then timely detection of malicious commands is achieved, but processing time may increase

Engineering Contradiction:
Improvetimely security detectionVSAvoidcommand processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary power flow analysis to pre-calculate and store baseline operational characteristics and expected voltage ranges under normal conditions. When control commands are received, the system compares commanded operations against these pre-established benchmarks rather than performing complete real-time analysis. This preliminary action preparation significantly reduces the processing time required for security verification while maintaining timely detection capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a streamlined verification process that skips detailed power flow calculations for commands that clearly fall within expected operational parameters. The system rapidly validates commands by checking key parameters against pre-established thresholds, rushing through the verification process for obviously legitimate commands while performing more thorough analysis only when anomalies are detected. This selective approach maintains timely detection while reducing average processing time.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS11283257B2Securing against malicious control of circuit breakers in electrical substations
Publication Date: 2022.03.22 HITACHI ENERGY LTD
  • US11283257B2 patent drawing
  • US11283257B2 patent drawing
  • US11283257B2 patent drawing

AI summary

An example method for detecting and mitigating attacks on electric power substations comprises detecting a command to open or close a circuit breaker in the electric power substation. A modified extended substation model for the electric power substation is generated, based on the detected command and based on measurements in substation, where the modified extended substation model is a power flow model for the substation and for one or more directly connected neighboring substations. A power flow analysis is performed, using the modified extended substation model, to generate a predicted voltage for each of a plurality of nodes in the substation and in the one or more directly connected neighboring substations. Each predicted voltage is compared to a corresponding allowable voltage range, and execution of the command is blocked in response to determining that one or more of the voltages is outside the corresponding allowable voltage range.