Synchrophasor Cyber-Risk Evaluation via Event Tree Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The synchrophasor systems in power grids are vulnerable to cyber-attacks, which can disrupt the timing information and lead to erroneous monitoring and control actions, potentially causing damage to electrical components.

Innovation Solution

A risk model using event tree analysis is implemented to quantify and prioritize cyber-risks, identifying vulnerabilities and potential impacts on phasor measurement data, allowing for resource allocation and security controls to mitigate timing intrusion attacks, and adapting the system architecture in real-time to protect against cyber-attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If synchrophasor systems are deployed to enable time-synchronized monitoring of electrical systems at high speed and over wide area, then the monitoring capability and system reliability are improved, but the vulnerability to cyber-attacks and timing intrusion attacks increases

Engineering Contradiction:
Improvesystem reliabilityVSAvoidcyber-attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary risk assessment and vulnerability identification before cyber-attacks occur. The system continuously evaluates cyber-risk by analyzing threat intelligence, system configurations, and potential attack vectors, allowing preventive measures to be taken in advance to protect synchrophasor systems from timing intrusion attacks

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary risk assessment layer between the cyber-attack and the synchrophasor system. This intermediary component evaluates and prioritizes risks, filters out false positives, and determines which security controls need to be activated, thereby protecting the system without disrupting its normal monitoring operations

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If security controls and cyber-risk mitigation measures are implemented, then the protection against cyber-attacks is improved, but the system complexity and operational overhead increase

Engineering Contradiction:
Improvecyber-attack protectionVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies local quality by tailoring security controls to specific risk scenarios rather than implementing uniform security measures across the entire system. The risk assessment identifies which components are most vulnerable to specific attack types, and security controls are selectively applied only where needed, reducing overall system complexity while maintaining effective protection

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent uses parameter changes to dynamically adjust security controls based on the current risk state. The system monitors threat intelligence and system conditions, changing security parameters (such as authentication requirements, encryption levels, or access controls) in response to changing risk levels, thereby optimizing protection without consistently increasing complexity

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If real-time adaptation of system architecture is implemented to respond to cyber-risks, then the responsiveness to threats is improved, but the computational resources and processing requirements increase

Engineering Contradiction:
Improvesystem adaptabilityVSAvoidcomputational resources
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent applies partial action by implementing real-time adaptation only for the most critical risk scenarios and system components. Rather than continuously adapting the entire system architecture, the risk assessment prioritizes which components need real-time adjustments based on their vulnerability levels and the current threat landscape, reducing computational resource consumption while maintaining effective adaptability

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11206287B2Evaluating cyber-risk in synchrophasor systems
Publication Date: 2021.12.21 BATTELLE MEMORIAL INST
  • US11206287B2 patent drawing
  • US11206287B2 patent drawing
  • US11206287B2 patent drawing

AI summary

Technology related to evaluating cyber-risk for synchrophasor systems is disclosed. In one example of the disclosed technology, a method includes generating an event tree model of a timing-attack on a synchrophasor system architecture. The event tree model can be based on locations and types of timing-attacks, an attack likelihood, vulnerabilities and detectability along a scenario path, and consequences of the timing-attack. A cyber-risk score of the synchrophasor system architecture can be determined using the event tree model. The synchrophasor system architecture can be adapted in response to the cyber-risk score.