IP Library Granted Patent US 12,560,639
Granted Patent B2
US 12,560,639 · App. 17/811,843 · Granted Feb 24, 2026

Tracking of health and resilience of physical equipment and related systems

Inventors: Jacob P. Lehmer (Idaho Falls, ID); Craig G. Rieger (Pocatello, ID); Bjorn C. Vaagensmith (Idaho Falls, ID); Tyler B. Phillips (Idaho Falls, ID); Timothy R. McJunkin (Idaho Falls, ID); Robert C. Ivans (Ammon, ID); Vivek Kumar Singh (Ammon, ID); Justin J. Welch (Idaho Falls, ID); Ruixuan Li (Idaho Falls, ID); Daniel Marino Lizarazo (Richmond, VA); Chathurika Mudiyanselage Wickramasinghe Brahmana Mudiyanselage (Richmond, VA); Milos Manic (Henrico, VA); Brian Johnson (Richmond, VA)
Assignees: Battelle Energy Alliance, LLC; Virginia Commonwealth University; University of Idaho
G01R31/086G01R31/36G06T11/206H02S50/10H04L43/028G06T2200/24
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,560,639
App. No.
17/811,843
Granted
Feb 24, 2026
Kind
B2
Abstract

Tracking of health and resilience of physical equipment and related systems are disclosed. A system includes physical equipment and one or more processors. The physical equipment includes one or more assets. The one or more processors are configured to determine a resilience metric for the physical equipment. The resilience metric includes a real power component and a reactive power component based, at least in part, on an aggregation of real components and reactive components of adaptive capacities of the one or more assets. A cyber-physical system includes physical equipment, network equipment configured to enable the physical equipment to communicate over one or more networks, a physical anomaly detection system (ADS) configured to detect anomalies in operation of the physical equipment and provide a physical component of a cyber-physical metric, and a cyber ADS configured to detect anomalies in network communications over the one or more networks.

Claims (51)

1 . A system, comprising:

physical equipment including one or more assets;

network equipment to enable at least one of the one or more assets to engage in network communications over one or more networks, the network communications including network communications of packets over the one or more networks;

a human machine interface (HMI) operably coupled to the physical equipment and to the network equipment; and

one or more processors configured to:

determine a physical health metric indicating a physical health of the physical equipment, the physical health metric determined based, at least in part, on detected anomalies in operation of the physical equipment;

determine a cyber health metric indicating a cyber health of the network equipment, the cyber health metric determined based, at least in part, on detected anomalies in traffic behavior of the network communications of the packets, the detected anomalies in the traffic behavior corresponding to cyberattacks on the one or more networks, the traffic behavior of the network communications of the packets identified from captured and analyzed packet header features of the packets;

determine a resilience metric for the physical equipment, the resilience metric including a real power component and a reactive power component determined based, at least in part, on an aggregation of real components and reactive components of adaptive capacities of the one or more assets;

generate a graphical user interface for display in the HMI, the graphical user interface including a diagram having a physical condition indicator, a cybernetic condition indicator, and a resilience condition indicator, the physical condition indicator based, at least in part, on the physical health metric, the cybernetic condition indicator based, at least in part, on the cyber health metric, and the resilience condition indicator based, at least in part, on the resilience metric; and

receive, via the HMI, a corrective action for processing in response to an adverse condition or threat indicated by the diagram of the graphical user interface, the corrective action to correct or prevent a system violation relating to a physical fault associated with the detected anomalies in the operation of the physical equipment when indicated by at least the physical condition indicator in the diagram, the corrective action to correct or prevent a system violation relating to a cyberattack-induced fault associated with the detected anomalies in the traffic behavior corresponding to a cyberattack when indicated by at least the cybernetic condition indicator in the diagram.

2 . The system of claim 1 , wherein the resilience metric is indicative of a magnitude and a duration of a disturbance during which the physical equipment is predicted to continue to operate within predefined normal operational parameters.

3 . The system of claim 1 , wherein the one or more processors are further configured to generate the graphical user interface including the diagram comprising a resilience-icon diagram, the resilience-icon diagram including the physical condition indicator, the cybernetic condition indicator, and the resilience condition indicator.

4 . The system of claim 3 , wherein the one or more processors are further configured to display resilience-icon diagrams for each of a plurality of aggregated system resources of an electrical power distribution system.

5 . The system of claim 1 , wherein the physical equipment includes electrical power distribution equipment.

6 . The system of claim 1 , wherein the physical equipment includes a solar generator asset.

7 . The system of claim 6 , wherein the one or more processors are configured to determine a solar resilience metric for the solar generator asset, the solar resilience metric based, at least in part, on a real component and a reactive component of an adaptive capacity of the solar generator asset, the solar resilience metric taking into consideration an uncertainty of the adaptive capacity of the solar generator asset.

8 . The system of claim 6 , wherein the physical equipment further includes a battery power storage asset.

9 . The system of claim 8 , wherein the one or more processors are configured to determine a battery resilience metric for the battery power storage asset, the battery resilience metric taking into consideration operation of the battery power storage asset as a power source during battery power discharge and as a power sink during battery power storage asset charging.

10 . The system of claim 1 , wherein the detected anomalies in the traffic behavior corresponding to the cyberattacks include multiple ones of a Denial-of-Service (DoS) attack, a reconnaissance attack, a replay attack, a data-insertion attack, a false-data-insertion attack, a Distributed Network Protocol 3 (DNP3) data injection attack, an IP scan attack, and a port scan attack.

11 . The system of claim 1 , wherein, in the graphical user interface, the diagram having the cybernetic condition indicator, the physical condition indicator, and the resilience condition indicator provides differentiation between physical faults associated with the physical equipment and cyber-attack-induced faults associated with the network equipment.

12 . A cyber-physical system, comprising:

physical equipment;

network equipment configured to enable the physical equipment to engage in network communications over one or more networks, the network communications including network communications of packets over the one or more networks;

a physical anomaly detection system (ADS) configured to detect anomalies in operation of the physical equipment and provide a physical component of a cyber-physical metric based on the detected anomalies in the operation of the physical equipment;

a cyber ADS configured to detect anomalies in traffic behavior of the network communications of the packets over the one or more networks and provide a cyber component of the cyber-physical metric based on the detected anomalies in the traffic behavior, the detected anomalies in the traffic behavior corresponding to cyberattacks on the one or more networks, the traffic behavior of the network communications of the packets identified based on analysis of packet header features extracted from the packets; and

human machine interface (HMI) operably coupled to the physical equipment and to the one or more networks, the HMI to:

present, for display, integrated information from the physical ADS and the cyber ADS, the integrated information including the cyber-physical metric indicating the physical component and the cyber component; and

receive a corrective action for processing in response to an adverse condition or threat indicated by the displayed integrated information, the corrective action to correct or prevent a system violation relating to a physical fault associated with the detected anomalies in the operation of the physical equipment when indicated by at least the physical component of the cyber-physical health metric, the corrective action to correct or prevent a system violation relating to a cyberattack-induced fault associated with the detected anomalies in the traffic behavior corresponding to a cyberattack when indicated by at least the cyber component of the cyber-physical health metric.

13 . The cyber-physical system of claim 12 , wherein the cyber ADS is configured to detect the anomalies in the behavior of the network communications of the packets by:

dissecting the packets communicated through the one or more networks;

extracting the packet header features from dissected packets; and

detecting anomalies in the traffic behavior of the network communications of the packets based on analysis of the extracted packet header features.

14 . The cyber-physical system of claim 13 , wherein the cyber ADS is configured to detect the anomalies in the traffic behavior of the network communications of the packets using a machine learning algorithm.

15 . The cyber-physical system of claim 14 , wherein:

the cyber ADS is configured to train the machine learning algorithm using normal extracted packet header features from normal traffic behavior of the network communications of the packets corresponding to normal operation of the cyber-physical system; and

the machine learning algorithm is configured to detect the anomalies in the behavior of the network communications responsive to differences between the extracted packet header features and the normal extracted packet header features.

16 . The cyber-physical system of claim 13 , wherein the cyber ADS is configured to use a rolling window to analyze the packets.

17 . The cyber-physical system of claim 16 , wherein the rolling window is substantially one second in length.

18 . The cyber-physical system of claim 17 , further comprising one or more processors configured to determine a resilience metric for the physical equipment, the resilience metric including a real power component and a reactive power component based, at least in part, on an aggregation of real components and reactive components of adaptive capacities of one or more assets of the physical equipment.

19 . The cyber-physical system of claim 12 , wherein, in the HMI, the cyber-physical metric indicating the physical component and the cyber component indicates an extent to which respective ones of the detected anomalies in the operation of the physical equipment and the detected anomalies in the traffic behavior corresponding to the cyberattack affect an overall cyber-physical health of the cyber-physical system.

20 . The cyber-physical system of claim 12 , wherein respective ones of the physical ADS and the cyber ADS are configured in temporal synchronization with each other to detect anomalies substantially in real-time.

21 . An electrical power distribution system, comprising:

physical equipment including a solar generator asset and a battery power storage asset;

network equipment configured to enable the physical equipment to engage in network communications over one or more networks, the network communications including network communications of packets over the one or more networks;

a human machine interface (HMI) operably coupled to the physical equipment and to the network equipment; and

one or more processors configured to:

determine a physical health metric indicating a physical health of the physical equipment, the physical health metric determined based, at least in part, on detected anomalies in operation of the physical equipment;

determine a cyber health metric indicating a cyber health of the network equipment, the cyber health metric determined based, at least in part, on detected anomalies in traffic behavior of the network communications of the packets, the detected anomalies in the traffic behavior corresponding to cyberattacks on the one or more networks, the traffic behavior of the network communications of the packets identified from captured and analyzed packet header features of the packets;

determine a resilience metric for the physical equipment, the resilience metric including a real power component and a reactive power component based, at least in part, on the physical health of the physical equipment and the cyber health of the network equipment;

generate integrated information for display in the HMI, the integrated information indicating an overall cyber-physical health of the system, the integrated information including the physical health metric, the cyber health metric, and the resilience metric; and

receive, via the HMI, a corrective action for processing in response to an adverse condition or threat indicated by the displayed integrated information, the corrective action to correct or prevent a system violation in the system relating to a physical fault associated with the detected anomalies in the operation of the physical equipment when indicated by at least the physical health metric in the displayed integrated information, the corrective action to correct or prevent a system violation in the system relating to a cyberattack-induced fault associated with the detected anomalies in the traffic behavior corresponding to a cyberattack when indicated by at least the cyber health metric in the displayed integrated information.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2023
From: MANIC, MILOS; MARINO, DANIEL L.; WICKRAMASINGHE BRAHMANA, CHATHURIKA S.
To: VIRGINIA COMMONWEALTH UNIVERSITY
Reel/Frame 063502/0262 →
CONFIRMATORY LICENSE Recorded Oct 3, 2022
From: BATTELLE ENERGY ALLIANCE, LLC
To: UNITED STATES DEPARTMENT OF ENERGY
Reel/Frame 061588/0984 →
Continuity (2)
Provisional Application 63203146 · Jul 9, 2021
Related Publication 20230021214A1 · Jan 19, 2023
References Cited (56)
US 9203859B2 · Sampigethaya · 2015 [cited by applicant]
US 9405900B2 · Dixit et al. · 2016 [cited by applicant]
US 9652213B2 · Maccleery et al. · 2017 [cited by applicant]
US 10686806B2 · Abbaszadeh et al. · 2020 [cited by applicant]
US 10826932B2 · Abbaszadeh et al. · 2020 [cited by applicant]
US 10841322B2 · Giani et al. · 2020 [cited by applicant]
US 10896261B2 · Rieger et al. · 2021 [cited by applicant]
US 10931706B2 · Sant-Miller et al. · 2021 [cited by applicant]
US 11005870B2 · Yan et al. · 2021 [cited by applicant]
US 11902318B2 · Rivera · 2024 [cited by examiner]
US 20120077527A1 · Santiago · 2012 [cited by examiner]
US 20140156031A1 · Anderson et al. · 2014 [cited by applicant]
US 20180262525A1 · Yan et al. · 2018 [cited by applicant]
US 20190188797A1 · Przechocki et al. · 2019 [cited by applicant]
US 20190228110A1 · Yan · 2019 [cited by examiner]
US 20200026253A1 · Fuhr · 2020 [cited by examiner]
US 20200112573A1 · Adamski · 2020 [cited by applicant]
US 20200233956A1 · Wang · 2020 [cited by examiner]
US 20200292608A1 · Yan · 2020 [cited by examiner]
US 20200322366A1 · Yan et al. · 2020 [cited by applicant]
US 20200327205A1 · Wang · 2020 [cited by examiner]
US 20200389478A1 · Abbaszadeh et al. · 2020 [cited by applicant]
US 20210037044A1 · Achanta et al. · 2021 [cited by applicant]
US 20210089661A1 · Rieger et al. · 2021 [cited by applicant]
US 20210110319A1 · Gourisetti et al. · 2021 [cited by applicant]
US 20210112090A1 · Rivera et al. · 2021 [cited by applicant]
CN 107704670A · 2018 [cited by applicant]
CN 111953657A · 2020 [cited by applicant]
CN 112966375A · 2021 [cited by examiner]
WO WO2014116888A1 · 2014 [cited by examiner]
WO WO2020096560A1 · 2020 [cited by examiner]
WO 2021095051A1 · 2021 [cited by applicant]
Best et al., “7 Key Challenges for Visualization in Cyber Network Defense”, VizSec '14: Proceedings of the Eleventh Workshop on Visualization for Cyber Security, (Nov. 2014), (https://doi.org/10.1145/2671491.2671497), 8… [cited by applicant]
Chang et al., “Enabling Situational Awareness in Operational Technology Environments Through Software Defined Networking”, Journal of Information Warfare, Winter 2019, vol. 18, No. 4, Preparing for a Future of Critical … [cited by applicant]
Cicilio et al., “Resilience in an Evolving Electrical Grid”, MDPI Journal, Energies, 2021, 14, 694, 25 pages. [cited by applicant]
Fink et al., “Visual Correlation of Host Processes and Network Traffic”, Workshop on Visualization for Computer Security, IEEE, 2005, 9 pages. [cited by applicant]
Hasandka et al., “NREL's Cyber-Energy Emulation Platform for Research and System Visualization”, Golden, CO: National Renewable Energy Laboratory, NREL/TP-5R00-74142, (available at: https://www.nrel.gov/docs/fy20osti/74… [cited by applicant]
Huang et al., “Integration of Preventive and Emergency Responses for Power Grid Resilience Enhancement”, IEEE Transactions on Power Systems, vol. 32, No. 6, Nov. 2017, 13 pages. [cited by applicant]
Le Blanc et al., “Characterizing Cyber Tools for Monitoring Power Grid Systems: What Information is Available and Who Needs It?”, IEEE International Conference on Systems, Man, and Cybernetics (SMC), Oct. 2017, 6 pages. [cited by applicant]
Lohfink et al., “Security in Process: Visually Supported Triage Analysis in Industrial Process Data”, IEEE Transactions on Visualization and Computer Graphics, vol. 26, No. 4, Apr. 2020, 12 pages. [cited by applicant]
Matuszak et al., “CyberSAVe—Situational Awareness Visualization for Cyber Security of Smart Grid Systems”, VizSec '13: Proceedings of the Tenth Workshop on Visualization for Cyber Security, Oct. 2013, (https://doi.org/1… [cited by applicant]
Naseem et al., “CSPoweR-Watch: A Cyber-Resilient Residential Power Management System”, International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Phys… [cited by applicant]
National Academies of Sciences, Engineering, and Medicine, “Enhancing the Resilience of the Nation's Electricity System”, Washington, DC: The National Academies Press. https://doi.org/10.17226/24836, (2017), 171 pages. [cited by applicant]
Panel Details, IEEE ISGT NA 2020: “Enabling Intelligent and Resilient Communities”, (available at: https://attend.ieee.org/isgt-na-2020/plenary-sessions/panel-details/), accessed Jun. 10, 2021, 27 pages. [cited by applicant]
Phillips et al., “A Framework for Evaluating the Resilience Contribution of Solar PV and Battery Storage on the Grid”, IEEE, 2020 Resilience Week (RWS), 2020, pp. 133-139, doi: 10.1109/RWS50334.2020.9241296. [cited by applicant]
Phillips et al., “An Operational Resilience Metric for Modern Power Distribution Systems”, IEEE 20th International Conference on Software Quality, Reliability and Security Companion (QRS-C), 2020, 9 pages. [cited by applicant]
Rieger et al., “Resilient Control Systems—Basics, Benchmarking and Benefit”, IEEE Access, vol. 9, 2021, 13 pages. [cited by applicant]
Saxena et al., “CPSA: A Cyber-Physical Security Assessment Tool for Situational Awareness in Smart Grid”, Session: Threat Analysis and Risk Assessment, CPS-SPC'17, Nov. 2017, 11 pages. [cited by applicant]
Scholtz et al., “Cybersecurity Awareness in the Power Grid”, Springer International Publishing Switzerland, 2016, D. Nicholson (ed), Advances in Human Factors in Cybersecurity, Advances in Intelligent Systems and Comput… [cited by applicant]
Scholtz et al., “Employing a User-Centered Design Process for Cybersecurity Awareness in the Power Grid”, Journal of Human Performance in Extreme Environments, vol. 14, Issue 1, Article 4, 2018, 16 pages. [cited by applicant]
Sivils et al., “Integrated Cyber Physical Assessment and Response for Improved Resiliency”, Springer International Publishing AG, part of Springer Nature 2019, F. Cicirelli et al. (eds), The Internet of Things for Smart… [cited by applicant]
Staheli et al., “Visualization Evaluation for Cyber Security: Trends and Future Directions”, VizSec '14: Proceedings of the Eleventh Workshop on Visualization for Cyber Security, Nov. 2014, (available at: https://doi.or… [cited by applicant]
The Electric Power Research Institute, Inc., “Electric Power System Resiliency: Challenges and Opportunities”, (Feb. 2016), 56 pages. [cited by applicant]
U.S. Department of Energy, “Solar Energy Technologies Office 2020 Portfolio”, Office of Energy Efficiency & Renewable Energy, (available at: https://www.energy.gov/sites/default/files/2020/07/f76/SETO%20Portfolio%20Book… [cited by applicant]
Vaagensmith et al., “Review of Design Elements Within Power Infrastructure Cyber-Physical Test Beds as Threat Analysis Environments”, MDPI Journal, Energies, 2021, 14, 1409, 24 pages. [cited by applicant]
Wadhawan et al., “A Comprehensive Analysis of Smart Grid Systems Against Cyber-Physical Attacks”, MDPI Journal, Electronics 2018, 7, 249, 25 pages. [cited by applicant]