Trusted Cyber-Attack Detection for Power System Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Networked electrical power system (NEPS) devices face challenges due to limited computing resources, communication bandwidth, and unique physical and operational conditions, which hinder effective cyber-attack detection and mitigation, especially when requiring retrofits or upgrades.

Innovation Solution

Incorporating a trusted cyber-attack detection (TCAD) component with pre-trained logic that combines physical and computational state inputs to determine an attack metric, using a neural network to predict and respond to cyber-attacks by disconnecting the NEPS device from electrical and communication networks when compromised.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional cyber-attack detection techniques are applied to NEPS devices, then detection capability is improved, but device complexity and resource requirements increase beyond available computing resources

Engineering Contradiction:
Improvecyber-attack detection capabilityVSAvoidcomputing resource requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the cyber-attack detection function into a dedicated TCAD component that operates independently from the main control logic. This component receives specific inputs (physical parameters, computational state, execution time, alarm events) and processes them separately, reducing the burden on the overall device computing resources while maintaining detection capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary TCAD component that acts as a mediator between the NEPS device operations and cyber-attack detection. This component aggregates multiple input parameters and processes them through pre-trained logic, shielding the main device from the computational complexity of attack detection while still achieving reliable detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive cyber-attack detection monitoring is implemented, then detection accuracy is improved, but communication bandwidth consumption increases

Engineering Contradiction:
Improveattack detection accuracyVSAvoidcommunication bandwidth consumption
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The system merges multiple monitoring functions into a single TCAD component that simultaneously processes physical parameters, computational state, execution time, and alarm events. By combining these inputs and processing them through unified pre-trained logic, the system achieves comprehensive detection accuracy while consolidating communication requirements into a single efficient processing stream.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If cyber-attack detection and response systems are added to existing NEPS devices, then security is improved, but hardware and software upgrade requirements increase

Engineering Contradiction:
Improvecyber-securityVSAvoidretrofit complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The TCAD component is designed with universal input interfaces that can accept various types of data (physical parameters from sensors, computational state from the controller, execution time metrics, and alarm events). This multi-functional design allows the same component to be applied across different NEPS device types and configurations, simplifying retrofitting efforts.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system utilizes existing device resources and parameters for cyber-attack detection without requiring extensive external additions. The TCAD component leverages already-available data streams (physical parameters, computational state, execution time) and existing alarm mechanisms, allowing the device to essentially detect attacks using its own operational data with minimal external modifications.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12069088B2Cyber-attack detection for networked electrical power system devices
Publication Date: 2024.08.20 ABB (SCHWEIZ) AG
  • US12069088B2 patent drawing
  • US12069088B2 patent drawing
  • US12069088B2 patent drawing

AI summary

Apparatuses, methods, systems, and techniques for detecting and effecting countermeasures against cyber-attacks on networked electrical power system (NEPS) devices include a trusted cyber-attack detection (TCAD) component including pre-trained cyber-attack detection logic which receives a first input indicating a physical parameter of a NEPS device and a second input indicating a computational state of a computer system of the NEPS device, determines an attack metric in response to the plurality of inputs. The attack metric can indicate whether the NEPS device is in the process of being attacked or whether the NEPS device has been successfully attacked and has been compromised.