Source-linked AI summary
Modelling interdependencies between the electricity and information infrastructures
Jean-Claude Laprie, Karama Kanoun, Mohamed Kaaniche
TL;DR
The paper addresses the risk created by interdependencies between electricity and information infrastructures. It develops qualitative models of cascading, escalating, and common-cause failures, covering accidental information-infrastructure failures and briefly malicious attacks. The models describe high-level relationships between infrastructure states while remaining preliminary and requiring refinement for quantitative resilience assessment.
Problem
Existing models simplify power systems and omit explicit electricity–ICT interdependencies and escalating failures, despite interdependencies increasing failure exposure and severity.
Method
The paper develops qualitative, global models describing likely cascading, escalating, and common-cause failure scenarios between electricity and information infrastructures.
Results
The models describe high-level relationships between the states of electricity and information infrastructures under accidental failures and malicious information-infrastructure attacks.
Takeaways & Limitations
The models provide a preliminary framework for analyzing how failures in either infrastructure affect the other across accidental and malicious scenarios.
Takeaways & Limitations
The high-level models require refinement to evaluate quantitative impacts on resilience, critical outages, and blackouts.
Abstract
from arXiv · showhide
The aim of this paper is to provide qualitative models characterizing interdependencies related failures of two critical infrastructures: the electricity infrastructure and the associated information infrastructure. The interdependencies of these two infrastructures are increasing due to a growing connection of the power grid networks to the global information infrastructure, as a consequence of market deregulation and opening. These interdependencies increase the risk of failures. We focus on cascading, escalating and common-cause failures, which correspond to the main causes of failures due to interdependencies. We address failures in the electricity infrastructure, in combination with accidental failures in the information infrastructure, then we show briefly how malicious attacks in the information infrastructure can be addressed.
1 Introduction
The paper examines interdependency-related failures between electricity and information infrastructures, using qualitative models for cascading, escalating, and common-cause scenarios, including accidental and malicious information-infrastructure failures.
- 1 Introduction: Electricity and information infrastructures are increasingly interconnected, creating interdependency-related failure risks across power-grid operations.The information infrastructure supports power-system control, monitoring, maintenance, and exploitation.
- 1 Introduction: The paper models interdependency-related failures between the electric power infrastructure and information infrastructures supporting management, control, and maintenance.
- 1 Introduction: The qualitative models address cascading, escalating, and common-cause failures as principal interdependency-related failure classes.They represent infrastructures globally and describe likely scenarios based on assumptions about mutual infrastructure behavior.
- 1 Introduction: The analysis first considers electricity failures combined with accidental information-infrastructure failures, then briefly addresses malicious information-infrastructure attacks.
- 1 Introduction: The paper is organized around background, interdependency modelling for accidental information-infrastructure failures, malicious attacks, and a concluding section.
2. Background and Related Work
Interdependencies create error-propagation channels that can amplify infrastructure failures, while prior models largely simplify power-system behavior and omit explicit ICT interactions and escalating failures.
- 2. Background and Related Work: Interdependencies create multiple error-propagation channels, making failures more severe and harder to foresee than failures confined to a single infrastructure.A single equipment failure can cascade when it is not properly handled by the SCADA system.
- 2. Background and Related Work: Interdependencies are classified by dimensions including interdependency type, infrastructure environment, and coupling characteristics.
- 2. Background and Related Work: Cascading failures transfer failure from one infrastructure to another, escalating failures worsen an independent failure, and common-cause failures affect infrastructures simultaneously.These classes can interact; common-cause failures can cause cascading failures.
- 2. Background and Related Work: Prior cascading-failure research includes analytical component-load models, power-transmission models, and complex-network resilience models.These approaches examine component thresholds, power-system operating limits, or network responses to node and arc removal.
- 2. Background and Related Work: Existing models generally simplify power systems and do not explicitly represent power–ICT interactions or escalating failures.The paper presents a preliminary attempt to address these gaps.
3. Accidental failures in the information infrastructure
The paper progressively models accidental interdependencies between electricity and information infrastructures through cascading, escalating, and common-cause failures. Qualitative state-machine and Petri-net models represent how failures and mutual constraints alter infrastructure states and restoration needs.
- The modelling proceeds from one-way constraints to bidirectional constraints, then addresses common-cause failures.
- 3.1.1 Impact of information infrastructure failures (i-failures): Accidental information failures may be masked or signalled, producing latent errors, partial outages, or configuration changes affecting electricity operations.
- 3.1.2 Impact of electricity infrastructure failures (e-failures): Electricity failures can produce partial outages and constrain information functions, while escalation may cause loss of grid control.
- 3.2. Modelling cascading and escalating failures: The global state-machine model distinguishes cascading failures from escalating failures and represents different restoration times and severities.
- 3.2. Modelling cascading and escalating failures: The August 2003 blackout illustrates how monitoring-software failure prevented confinement of an electrical-line incident before propagation across the power grid.
- 3.2. Modelling cascading and escalating failures: The associated Petri net exposes cascading and escalating mechanisms as synchronizations between infrastructure events but deliberately aggregates individual states.
- 3.2. Modelling cascading and escalating failures: The extended model includes electricity constraints on information infrastructure, accumulated electricity failures, and common-cause failures that can lead to escalation.
4. Malicious attacks of the information infrastructure
The paper extends its qualitative interdependency model to malicious information-infrastructure attacks by distinguishing real from apparent infrastructure states. It represents deceptive and perceptible attacks, including cases where operators or systems receive misleading status information.
- Malicious-attack modelling distinguishes each infrastructure’s real status from its apparent status, with electricity status reported by the information infrastructure.
- Attacks are classified as deceptive, causing unperceived malfunctions, or perceptible, creating detected damage.
- Deceptive attacks may be passive or active, with active attacks provoking configuration changes in the electricity infrastructure.
- The malicious-attack model preserves the earlier state-machine structure but changes the semantics of states and transitions.
- Passive and active deceptive attacks can make the information infrastructure appear operational while weakening electricity operations through misleading or undisclosed changes.
- After attack detection, apparent states align with real states, and information, configuration, and electricity restoration may be required.
Conclusion
The paper introduces high-level qualitative models for analyzing how failures in electricity and information infrastructures affect each other. It distinguishes accidental and malicious information-infrastructure failures, while identifying refinement toward quantitative resilience measures as future work.
- The models describe high-level scenarios and relationships between the states of the electricity and information infrastructures during failures.
- The paper presents separate models for accidental information-infrastructure failures and malicious attacks.
- A unified model covering both classes of information-infrastructure failures remains under investigation.
- The models require refinement before they can evaluate quantitative impacts on infrastructure resilience, critical outages, and blackouts.