Top-Down Control Design Strategy for Electric Power Grid EMP (E3) Protection.
Abstract not provided.
SEARCH · Engineering Papers
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Abstract not provided.
Abstract not provided.
Abstract not provided.
Explore the source record for details and available documents.
Wide-area protection and control (WAPAC) systems are widely applied in the energy management system (EMS) that rely on a wide-area communication network to maintain system stability, security, and reliability. As technology and grid infrastructure evolve to develop more advanced WAPAC applications, however, so do the attack surfaces in the grid infrastructure. This paper presents an attack-resilient system (ARS) for the WAPAC cybersecurity by seamlessly integrating the network intrusion detection system (NIDS) with intrusion mitigation and prevention system (IMPS). In particular, the proposed NIDS utilizes signature and behavior-based rules to detect attack reconnaissance, communication failure, and data integrity attacks. Further, the proposed IMPS applies state transition-based mitigation and prevention strategies to quickly restore the normal grid operation after cyberattacks. As a proof of concept, we validate the proposed generic architecture of ARS by performing experimental case study for wide-area protection scheme (WAPS), one of the critical WAPAC applications, and evaluate the proposed NIDS and IMPS components of ARS in a cyber-physical testbed environment. Our experimental results reveal a promising performance in detecting and mitigating different classes of cyberattacks while supporting an alert visualization dashboard to provide an accurate situational awareness in real-time.
This project designs enhanced protection scheme for the real-world weak grid area with a high penetration of IBRs. As the existing protection schemes are originally designed for traditional synchronous machines, we first evaluate if the protection scheme will continue to operate reliably in systems with high levels of IBRs. Hardware relays are tested using a controller-hardware-in-the-loop setup. PSCAD electromagnetic transient simulation with IBR original equipment manufacturer black-box models is used to perform fault studies and generate COMTRADE data, which are replayed by a real-time digital simulator (RTDS) to feed input to the hardware relays. Three scenarios are analyzed: normal operation, an N-1 contingency, and an IBR-only scenario. The evaluation results reveal the following: 1) the protection scheme remains reliable under normal conditions and N-1 contingencies and 2) in IBR-only scenarios, differential protection (87L) continues to operate reliably, whereas local protection elements, such as distance and directional elements, fail because of the lack of regulated negative sequence current contributed by IBRs. Enhanced protection is designed to address the challenge of lack of negative sequence current from IBRs, including increased restraining factors a2 and k2 to block 32Q or using V instead QV ORDER for ground faults, enhanced mho distance element with voltage and phase angle supervision for L-L faults. The efficacy of enhanced protection logic is validated and proven to work reliably. Additionally, IEEE Std. 2800-2022 negative sequence current compliant GFL and GFM IBRs from another vendor are tested and proven to work reliably without need for enhanced logic. Therefore, this work provides valuable decision-making for utilities facing protection system challenges due to IBRs, either designing enhanced protection scheme or requesting their IBRs being IEEE Std. 2800-2022 compliant to produce regulated negative sequence current for protection relay to make correct decision.
griDNA is an advanced monitoring and alerting technology for protecting electrical grids and other critical infrastructure from disruptions caused by cyberattacks or system failures. griDNA provides the holistic cyber-physical situational awareness that operators require for modern infrastructure challenges.
Explore the source record for details and available documents.
Explore the source record for details and available documents.
NLR is collaborating with Florida Power & Light (FPL) and GE to investigate power system stability and protection reliability challenges in a weak-grid region with high penetration of inverter-based resources (IBRs). This presentation will primarily focus on the protection aspects of the study. We will share key insights from this real-world project, including best practices for developing high-fidelity fault study models, establishing a controller-hardware-in-the-loop (CHIL) platform for testing physical relays, identifying system-level protection challenges, and designing enhanced protection schemes to address those issues. Through this discussion, the audience will gain practical understanding of protection studies in IBR-dominated systems, the emerging challenges associated with reduced fault current and altered transient behavior, and effective mitigation strategies. In particular, we will highlight the critical importance of IBR compliance with IEEE 2800-2022 to ensure dependable and secure protection relay operation in modern transmission systems.
As inverter-based resources continue to be installed at all levels of the electric grid, the fixed protection schemes used at the distribution level will continue to be stressed until they no longer ensure the protection of the grid. Adaptive protection has been proposed as a solution with the ability to update the protection schemes in near real-time to ensure reliability and increase the resilience of the grid. However, weather variability poses a significant challenge to the ability of these methods to keep the selectivity and reliability of these schemes coordinated. If the ramp rates, due to solar variability, of the inverter-based resources change faster than the adaptive protection can issue new settings, the protection system could be uncoordinated, with the wrong device responding to a system fault. The proposed adaptive protection method ensures that due to solar variability, communication, and protection calculation latency, it can issu e coordinated protection settings promptly, in one minute or less. The hardware-in-the-loop results show the protection settings being issued and maintaining system coordination in under a minute.
This report documents the Resilience Enhancements through Deep Learning Yields (REDLY) project, a three-year effort to improve electrical grid resilience by developing scalable methods for system operators to protect the grid against threats leading to interrupted service or physical damage. The computational complexity and uncertain nature of current real-world contingency analysis presents significant barriers to automated, real-time monitoring. While there has been a significant push to explore the use of accurate, high-performance machine learning (ML) model surrogates to address this gap, their reliability is unclear when deployed in high-consequence applications such as power grid systems. Contemporary optimization techniques used to validate surrogate performance can exploit ML model prediction errors, which necessitates the verification of worst-case performance for the models.
Ac transmission protection must reliably detect, classify, and locate short-circuit faults from voltage and current measurements. At present, these functionalities, which have been classically engineered using phasors approaches, are being challenged by the dynamic behavior and fault-current limits of converter-based generation. This paper tackles these challenges by engineering a time-domain protection approach that leverages the classical Bergeron model in a new manner. Low- and high-impedance faults are detected and classified by ascertaining how well line voltage and current measurements match the Bergeron equations. Faults are located by posing a novel one-variable optimization problem, whereas voltage and current waveforms at the fault location are estimated by unveiling rigorous relationships. The proposed elements are secure against external faults, measurement errors, and variation of line parameters and sampling time. Furthermore, these advances are tested via electromagnetic transient simulations and are significant to satisfy IEEE and North American Electric Reliability Corporation requirements.
Electrical utility substations are wired with intelligent electronic devices (IEDs), such as protective relays, power meters, and communication switches. Substation engineers commission these IEDs to assess the appropriate measurements for monitoring, control, power system protection, and communication applications. Like real electrical utility substations, complex electrical substation grid testbeds (ESGTs) need to be assessed for measuring current and voltage signals in monitoring, power system protection, control (synchro check), and communication applications that are limited by small measurement percentage errors. In the process of setting an ESGT with real-time simulators and IEDs in the loop, protective relays, power meters, and communication devices must be commissioned before running experiments. In this study, an ESGT with IEDs and distributed ledger technology was developed. The ESGT with a real-time simulator and IEDs in the loop was satisfactorily assessed and commissioned. The commissioning and problem-solving tasks of the testbed are described to define a method with flowcharts to assess possible trouble-shooting in ESGTs. This method was based on comparing the simulations versus IED measurements for the phase current and voltage magnitudes, three-phase phasor diagrams, breaker states, protective relay times with selectivity coordination at electrical faults, communication data points, and time-stamp sources.
Novel power system control and new utility devices need to be tested before their actual deployment to the power grid. To assist with such a testing need, real-time digital emulators such as RTDS and Opal-RT can be used to connect to the physical world and form a hardware in the loop (HIL) emulation. However, due to the limitations of today's computational resources, the accuracy and fidelity suffer from different levels of model reductions in purely digital simulations. CURENT has developed a reconfigurable electric grid hardware testbed (HTB) to overcome the limitations of digital emulators. The HTB has been used to develop measurement, control, modeling, and actuation techniques for a national grid with a high penetration of renewables. The power electronic-based system includes emulators for synchronous generators; photovoltaics with grid-interfacing inverter; wind turbines; induction motor loads, ZIP loads, power electronic loads; batteries; ac and dc transmission lines; short circuit faults and grid relay protection; and a multiterminal HVDC overlay including power electronics interfaces. The system contains real elements of power flow, measurement, communication, protection, and control that mimic what would be seen in an actual electric grid. This paper presents an overview of the HTB and several scenarios that have been run to determine control and actions needed for the future power grid.
Traditional transmission line protection relies on predictable synchronous-based fault signatures, which frequently fail under the non-standard, current-limited fault characteristics of Inverter-Based Resources (IBRs). This study investigates how to achieve secure, communication-free fault isolation in IBR-dominated weak grids without relying on opaque, computationally heavy "black-box" machine learning algorithms. To address this, we propose a novel, standalone, and inherently interpretable data-driven protection framework. Unlike centralized methods requiring multi-terminal communication, this decentralized approach relies solely on local measurements using a hierarchical linear-kernel Support Vector Machine (SVM). The methodology decomposes the protection task into four sequential stages that mimic traditional protection elements: fault detection and fault direction identification, fault type classification, zone classification, and location estimation. This multi-stage architecture allows for specialized feature engineering at each stage, combining high computational efficiency with logic traceability. The framework's end-to-end performance was validated via C-code and PSCAD/EMTDC co-simulation, utilizing a real-world utility network and an OEM black-box IBR model. The proposed relay achieves 97.2% overall accuracy and provides a reliable trip decision within a 2.5-cycle window. The results confirm 100% accuracy in fundamental fault detection, reliable zone selectivity across low to moderate fault resistances, and robust security against non-fault transients, proving its immediate viability for integration into commercial numerical relays.
The complex interdependencies of cyber systems (sensors and communications), physical grids and associated electricity market operations make protecting electric power grids a significant challenge. The energy sector is constantly under new, targeted, advanced and dangerous cyber-attacks that have the potential to result in the loss of human life. These threats are further exacerbated by our need to modernize the grid. One focus of cyber security research in smart grids is the securing of the SCADA system through advanced intrusion detection systems (IDS) and bad data detection algorithms in state estimation. These methods either require full knowledge of the system topology and parameters or fail to understand the physical behaviors under attack. WISP (Watching grid Infrastructure Stealthily through Proxies) is designed to provide additional protection to the power grid using only publicly available data. In particular, WISP exploits the spatio-temporal nature of the real time locational marginal prices (LMPs), in conjunction with other information such as bids, weather, outages and load data to analyze anomalous power pricing behaviors and then correlate those observations to localize regions of interest and identify potential cyber events. WISP is non-intrusive as the tool is deployed as a service in the Cloud or on premise and provides reliable information to system operators for enhanced situational awareness, without impeding energy delivery functions. The WISP technology comprises three modules: the data-driven anomaly detection core, the vulnerability and risk analysis and the root cause analysis. The data-driven anomaly detection core performs the tasks of feature selection, anomaly detection and attack region localization. The vulnerability and risk analysis module provides system level information of the vulnerable variables and times, assisting the operators in selecting monitoring and protection nodes. The root cause analysis module takes the detection results and identifies potential operational conditions that contribute to the detected anomalies. In Phase I, we have demonstrated the feasibility and effectiveness of WISP. We developed a realistic electricity market simulator capable of generating normal and attack market data under various operational conditions. We developed a series of cyber-attack detection and analysis algorithms and evaluated them under multiple data sources. Finally, we integrated all modules into an end-to-end software, providing functions for data management, data analytics and visualization. Specifically, we have achieved: (i) real-time data acceptance from external utility interfaces with >99% acceptance rate; (ii) high performance anomaly detection algorithms with >98% detection accuracy and <0.1% false alarm rate; and (iii) ultra-low computing delay <50 milliseconds. Additionally, our team developed algorithms to identify the vulnerable variables in electricity market operations and root cause analysis functions to identify major contributors to the price spikes. These ancillary modules are necessary when deploying WISP in real world industry environment. In Phase II, we have demonstrated the effectiveness of WISP software on realistic largescale power systems. We performed red team testing for the Phase I WISP software and identified software vulnerabilities and implemented corresponding mitigation solutions. We adapted the electricity market simulator for the Texas synthetic 2000-bus system and generated datasets for the false data injection attacks. We created database and visualization interfaces for the Texas system and the ISO New England system. We performed software optimization in terms of operation efficiency, computing speed and detection accuracy. Finally, we tested the software on the Texas system and the ISO New England system and evaluated the detection performance. Overall, we achieved above 89% detection rate, below 3% false alarm rate and below 37 seconds of end-to-end detection delay.
The share of renewable and distributed energy resources (DERs), like wind turbines, solar photovoltaics and grid-connected batteries, interconnected to the electric grid is rapidly increasing due to reduced costs, rising efficiency, and regulatory requirements aimed at incentivizing a lower-carbon electricity system. These distributed energy resources differ from traditional generation in many ways including the use of many smaller devices connected primarily (but not exclusively) to the distribution network, rather than few larger devices connected to the transmission network. DERs being installed today often include modern communication hardware like cellular modems and WiFi connectivity and, in addition, the inverters used to connect these resources to the grid are gaining increasingly complex capabilities, like providing voltage and frequency support or supporting microgrids. To perform these new functions safely, communications to the device and more complex controls are required. The distributed nature of DER devices combined with their network connectivity and complex controls interfaces present a larger potential attack surface for adversaries looking to create instability in power systems. To address this area of concern, the steps of a cyberattack on DERs have been studied, including the security of industrial protocols, the misuse of the DER interface, and the physical impacts. These different steps have not previously been tied together in practice and not specifically studied for grid-connected storage devices. In this work, we focus on grid-connected batteries. We explore the potential impacts of a cyberattack on a battery to power system stability, to the battery hardware, and on economics for various stakeholders. We then use real hardware to demonstrate end-to-end attack paths exist when security features are disabled or misconfigured. Our experimental focus is on control interface security and protocol security, with the initial assumption that an adversary has gained access to the network to which the device is connected. We provide real examples of the effectiveness of certain defenses. This work can be used to help utilities and other grid-connected battery owners and operators evaluate the severity of different threats and the effectiveness of defense strategies so they can effectively deploy and protect grid-connected storage devices.