Review on Energy Resilience

profileharsh55
MeasuringCommunityandMulti-IndustryImpactsofCascadingFailuresinPowerSystems_ext.pdf

IEEE SYSTEMS JOURNAL, VOL. 12, NO. 4, DECEMBER 2018 3585

Measuring Community and Multi-Industry Impacts of Cascading Failures in Power Systems

Bing Li , Graduate Student Member, IEEE, Kash Barker , and Giovanni Sansavini , Member, IEEE

Abstract—Many economic activities strongly depend on criti- cal infrastructure systems, especially the electric power system. Failures in the electric power infrastructure not only cause the disruption of power supply but also result in losses in productiv- ity across other dependent industries. This paper aims to develop a framework that uniquely integrates an ac power flow based cascad- ing failure analysis for the electric network with a multiregional, multi-industry interdependence model to quantify the short-term economic impacts of electric power disruption due to cascading failures. An ac power flow based cascading failure analysis is de- veloped to enable the accurate reproduction and consequences esti- mation of a cascading event. We use the economic interdependence model to evaluate the economic impact of a cascading event tak- ing into account spatial explicitness and cross-border effects. The economic impacts due to both the direct power supply disruption and the workforce unavailability are estimated. A case study was conducted on the Swiss electric network, accounting for the in- ternational impact on other related countries. The results provide guidance for ranking the criticality of the elements in the electric network and for identifying the vulnerable regions and economic sectors that could be strengthened through preparedness planning.

Index Terms—Cascading failure analysis, component criticality, multi-industry impacts, power systems, risk analysis.

I. INTRODUCTION

C ASCADING outages in power systems are defined as oneor more sequential dependent component outages that suc- cessively weaken the system [1]. Cascading outages can either terminate before interrupting the electricity service or continue until a blackout occurs. If the cascade process extends to the system level, it can cause massive disruption to electric power service. In August 14, 2003, the blackout event in the Northeast- ern US and Southeastern Canada led to a disruption in power for 50 million people. The power supply disruption (i.e., 63 GW) accounted for approximately 11% of the total load demand in the affected area. Despite their infrequency, blackout events sig- nificantly affect system safety and reduce customer perception of power supply reliability [2], [3]. To maintain the security of the power supply and limit the potential societal impact of the

Manuscript received February 3, 2017; revised June 20, 2017 and Septem- ber 20, 2017; accepted October 21, 2017. Date of publication November 16, 2017; date of current version November 22, 2018. This work was supported in part by the National Science Foundation under Award 1635813, in part by the CTI—Commission for Technology and Innovation (CH), and in part by the SCCER-FURIES—Swiss Competence Center for Energy Research—Future Swiss Electrical Infrastructure. (Corresponding author: Giovanni Sansavini.)

B. Li and G. Sansavini are with the Reliability and Risk Engineering Labora- tory, Department of Mechanical and Process Engineering, ETH Zurich, Zurich 8092, Switzerland (e-mail: [email protected]; [email protected]).

K. Barker is with the School of Industrial and Systems Engineering, Univer- sity of Oklahoma, Norman, OK 73019 USA (e-mail: [email protected]).

Digital Object Identifier 10.1109/JSYST.2017.2768603

cascading events, it is important to assess system vulnerabil- ities and identify critical components that ensure the reliable operations of the power system.

Vulnerability analysis is an emerging approach used in the risk management of critical infrastructures. It assesses the con- sequence in the system when a set of its elements is removed or when the system is operating in extreme conditions [4]. Sys- tem vulnerability can be measured from two perspectives: 1) global vulnerability analysis and 2) critical component analy- sis [4], which provide different insights into a system’s ability in withstanding disturbances and stress. A global vulnerability analysis is carried out by removing an increasing number of components or changing the loading of the system to increase the stress on the system and uses a model of system response to estimate the resulting consequences. In critical component anal- ysis, a component, or set of components, is identified as critical if, when failed, it gives rise to significant adverse consequences. Criticality measures serve as useful tools to identify weak links that may affect the performance of a system and to prioritize reliability improvement activities, among other uses [5]. Sev- eral analytical and empirical component importance measures have been proposed to rank the components according to their criticality in the system [6].

Traditional vulnerability analyses often narrowly focus on the direct consequences of each individual infrastructure. How- ever, the increasing functional and geographical interdepen- dence among critical infrastructures that make them more efficient also makes them more complex and vulnerable to the propagation of malfunctions [7]. As such, vulnerability mea- sures should account for larger scale impacts, including across infrastructures and across multiple industries that rely upon them. Adapted from [8], the term cascading effects used here refers to the inoperability that occurs internally to a network (e.g., flow redistribution due to capacity exceedances), and in- terdependent effects refers to the inoperability that occurs ex- ternal to the network as a result of its disruption (e.g., often experienced in communities and different industries that rely on electric power).

In a power system, a dc/ac power flow based cascading failure analysis has been proposed to estimate the consequence of a cas- cading event caused by various scenarios, e.g., ORNL-PSerc- Alaska model [9] or Manchester model [10]. These analyses measure the severity of a cascading event based on the direct impact in the power sector, such as the power supply disrup- tion. Due to the strong dependence of economic activities on the electric power supply [11], a cascading failure in the electric power sector may propagate its impact to interconnected indus- tries. According to Andersson et al. [12], the total cost to the US caused by the 2003 Northeast Blackout ranges between $4 and $10 billion. Over 10 sectors experienced economic losses

1937-9234 © 2017 IEEE. Personal use is permitted, but republication/redistribution requires IEEE permission. See http://www.ieee.org/publications standards/publications/rights/index.html for more information.

daiya
Highlight
连锁故障
daiya
Highlight
daiya
Highlight
daiya
Highlight
daiya
Highlight
空间显化
daiya
Highlight
跨国的
daiya
Highlight
daiya
Highlight
daiya
Highlight
连锁故障
daiya
Highlight
连续的
daiya
Highlight
封网
daiya
Highlight
罕见
daiya
Highlight
daiya
Highlight
daiya
Highlight
daiya
Highlight
抗扰
daiya
Highlight
daiya
Highlight
daiya
Highlight
daiya
Highlight
故障传播

3586 IEEE SYSTEMS JOURNAL, VOL. 12, NO. 4, DECEMBER 2018

of more than $100 million, with the business services, electric power, and depository institutions and brokers industries among the most affected in terms of three-day economic losses [13]. The extensive societal impact of the cascading events on de- pendent economic sectors stresses the necessity of a systematic evaluation of the consequence of their disruption. Additionally, the direct infrastructure consequences and the societal effects caused by the component failure may differ to a large extent, which can lead to a different measure of component criticality and incorrect vulnerability reduction decisions [14]. Therefore, it is significant to account for the societal impact when identi- fying critical components in power systems.

The inoperability input–output model (IIM) is proposed for quantifying the interdependent inoperability and economic losses experienced across multiple industries. The model takes into account both direct and higher order economic effects caused by a disruptive event (e.g., a regional blackout). The IIM has wide applications in various vulnerability studies. Pant et al. [15] developed an integrated model with the IIM and a simulation model of port operations to assess the interdependent impact caused by disruptions at an inland port terminal and to inland waterways, respectively. In [14], a model of the Swedish power transmission system and a regional IIM (RIIM) are inte- grated for measuring the long-term societal effects of a power supply reduction.

The use of the IIM for quantifying the interdependence among economic sectors relies on large-scale databases that support the model, and such databases has resulted in the maturity of the field of input–output analysis. The wide application of IIM, es- pecially in the study of the societal impacts of disruptive events [16], validates the application of IIM here. For instance, Ander- son et al. [13] applied an IIM analysis to the 2003 US blackout, the results obtained are very similar to other estimations of published empirical studies. As the base IIM only provides an averaged estimation across geography, model results may be insufficient for preparedness decision making within and across regions [17]. To address such spatial disruptions, Crowther et al. [17] introduced a multiregional IIM (MRIIM) to extend the IIM for modeling the multiregional interdependencies among the various regions. The MRIIM captures cross-border effects by accounting for the spatial explicitness in intraregional and multiregional interdependence matrices.

The contributions of this paper are three-fold. First, an ac power flow based cascading failure analysis is developed for estimating the consequence of cascading events caused by a set of failure scenarios. Second, the cascading failure analysis is validated against historical blackout data to demonstrate the model’s capability in capturing important statistical character- istics of cascading events. Third, the cascading failure analysis for the electric network is uniquely integrated with the MRIIM to quantify the short-term societal impacts of power supply dis- ruption caused by cascading events. This paper extends prior work by the authors [18] by including the important step of the cascading failure analysis validation and taking into account the interregional commodity and services exchanged to effectively capture the interdependent effects of economic consequences across the border. In the proposed framework, random failures of physical components are introduced in the power system to trigger a cascading event. The direct power supply disruption in the electric sector and the workforce unavailability in each sector with reliance on power supply are structured as inputs to the MRIIM. The analysis of interdependencies estimates the

propagation of the losses among industries at the regional and international levels. Both global vulnerability with respect to in- creasing load factors (LFs) and critical component analysis are conducted. The case study on the Swiss electric network and af- fected countries provide an estimate of the large-scale economic impacts of disruptions due to cascading failures at the local and international level. The criticality of system components can be ranked based on the severity of these impacts. Furthermore, by aggregating the losses caused in each region and in each industry for various failure scenarios, it is possible to identify the vulner- able regions and economic sectors that should be strengthened for the risk management of cascading failures.

This paper is structured as follows. Section II introduces the cascading failure analysis model, the MRIIM used for the in- terdependence study in the integrated model, and the metrics used for evaluating the societal impact of the cascading fail- ures. The results of the case study on the Swiss electric network and the related countries and their implications are discussed in Section III. Section IV concludes the work and offers thoughts on future work.

II. METHODOLOGY

A. AC PF Based Cascading Failure Analysis

In cascading events, the initial contingency can be unexpected outages of generators or transmission lines, a sudden unantici- pated increase in demand, fluctuations of the generator output, or outage of other equipment [19]. The outages may be local and terminate before causing power supply disruption, or they may propagate to wide areas and lead to blackouts. Cascad- ing phenomena are complicated because there are many fail- ure mechanisms involved, which include cascading overloads, failures of protection equipment, reactive power problems, and voltage collapse. Cascading line overloads is one of the most common propagation mechanisms [3]. When a transmission line is overloaded, it triggers a dynamic of automatic disconnection from the network by a circuit breaker to prevent system damage. The load that is originally carried by the disconnected line is redistributed to other lines, which may lead to additional line overloads. FACTS can be applied to nudge power flows in de- sired directions and mitigate the line overloads [20]. Topology changes can lead to the formation of disconnected clusters of buses, i.e., the so-called “island operation” in the system. Un- der these conditions, the newly formed islands are affected by power surplus or deficit, and power imbalance is compensated by frequency control, which activates within seconds to min- utes depending on the type of control. The process of restoring power balance and eliminating frequency deviation through pri- mary and secondary frequency controls is modeled according to [21]. In case of severe load/generation imbalance, frequency and voltage values may exit their safety margins (indicated as “Stability Check” in Fig. 1), and dynamic instability and system collapse may occur. In such a case, under frequency load shed- ding (UFLS) and under voltage load shedding (UVLS), which act on timescales well under 1 s, may be implemented to ensure frequency and voltage stability before the frequency control can be fully deployed. These protection schemes are activated only if system collapse may be impending. Additionally, load shedding is implemented as a last resort to correct the frequency deviation after frequency control has deployed, if power imbalance still persists in the island due to generation capacity deficit.

LI et al.: MEASURING COMMUNITY AND MULTI-INDUSTRY IMPACTS OF CASCADING FAILURES IN POWER SYSTEMS 3587

Fig. 1. Algorithm applied in the simulation model.

To simulate the evolution of cascading failures and to assess potential adverse consequences, the steady-state operations of the power system is simulated with an approximate model. The model represents the dynamical process of cascading events that is consistent with some basic network and operational con- straints. The cascading failure analysis is based on ac power flow. The linear nature of the dc PF method leads to efficient computation and applicability to large-scale systems. However, the voltage profile of buses and reactive power have significant impacts on the system conditions, and by disregarding their effects, the underlying assumptions in the dc PF method may provide underestimated results. This approach can model com- binations of several types of failures, such as cascading line overloads, frequency deviation, reactive power problems, and voltage drop. The nonsequential Monte Carlo method [22], [23] is applied to power system risk analysis, where the states of the components are sampled and a nonchronological system state is obtained. The model captures following phenomena.

1) It simulates critical scenarios that may trigger a cascading event.

2) The postcontingency power flow on the transmission lines is computed with an ac power flow algorithm.

3) Primary and secondary frequency controls of generators are activated in case of power generation/consumption imbalance in island operation [1], the frequency devia- tion are computed and the frequency control is modeled according to [21];

4) The lines are disconnected automatically when they reach the failure limit [24].

5) It identifies blackout conditions when there is frequency instability due to the large power imbalance in the island [1], [25], and UFLS is conducted when the frequency exceeds the acceptable threshold [25].

6) UVLS is performed when the voltage magnitude at a bus is under the limit [26].

7) If there is not enough generation capacity in the island, load shedding is conducted as a last resort.

Constant load demand from the customer during the cas- cading event is assumed. In addition, the probability of having additional random failures of transmission equipment in the evo- lution of the cascading event is very low and is not considered. Demand not served (DNS) is used to measure the consequences of the cascading event, which is a commonly used reliability measure for power systems [1], [27].

Steady-state line currents and bus voltages can lead to line overload and voltage protection relay activation and topology changes in the network [28]. The transient process following topology change after the failure (e.g., the dynamic frequency characteristics of the generator/load) is not involved in the analysis.

1) Frequency Control: The steady-state frequency deviation after the cascading failure is evaluated according to the follow- ing equation [29]:

Δf = −ΔP

∑N b u s h= 1 1/Dd,h +

∑N b u s h= 1 1/Rh

(1)

where ΔP is the power imbalance in megawatt. Dd,h and Rh are the frequency characteristics of the demand and generator at bus h, respectively.

Here, we restrict ourselves to a single-area system, where the objective of secondary control is power balancing within the area and to release the capacity used for the primary frequency con- trol. The contribution of each generator to secondary frequency control is computed from the nodal balance at bus h [21]

0 = P nomg ,h + P prim ary g ,h + P

secondary g ,h − Pd,h −

k∈n h Pl,hk (2)

where P nomg ,h is the nominal power generation, and P prim ary g ,h =

−Δf /Rh and P secondaryg ,h = ug ,h are the power delivery for primary frequency control and secondary control, respectively. Pd,h is the power demand at bus h , nh is the set of the buses that are connected to bus h, and Pl,hk is the flow on line {h, k}, respectively. By summing up (2) for all the buses, we obtain

Δf =

( N b u s∑

h= 1

P nomg ,h + N b u s∑

h= 1

ug ,h − N b u s∑

h= 1

Pd,h

− N b u s∑

h= 1

k∈n h Ploss,hk

)

· N b u s∑

h= 1

Rh (3)

where the left-hand side denotes the measurable system frequency deviation Δf , the term Ploss,hk depicts the power loss on the transmission line {h, k}, and the term in brackets on the right-hand side denotes the total power imbalance. Observe that Δf is zero if and only if the power injections and losses are balanced by means of the secondary control input ug .h . The sec- ondary control action ug .h is implemented via integral control of the frequency error Δf with integral gain equal to the generation participation factor βg ,h for each generator, which represents the ratio of generator h’s capacity to the total capacity, i.e., βg ,h = P

capacity g ,h /

∑N b u s h= 1 P

capacity g ,h . Thus, the steady state of the

3588 IEEE SYSTEMS JOURNAL, VOL. 12, NO. 4, DECEMBER 2018

secondary integral control input achieving Δf = 0 is given by

ug ,h = βg ,h · (

N b u s∑

h= 1

Pd,h + N b u s∑

h= 1

k∈n h Ploss,hk −

N b u s∑

h= 1

P nomg ,h

)

.

(4) 2) Load Shedding: Underfrequency/voltage load shedding

plans are predominantly deterministic [30]. In the model, a pre- defined amount of loads is shed when the system frequency/bus voltage falls below a certain threshold, specifically, 25% of the total load for frequency under 47.5 Hz [31] and 25% of the bus load for bus voltage under 0.92 of the nominal voltage value [26]. The frequency deviation and the bus voltages are evaluated based on the postcontingency conditions. In UFLS, load shed- ding is distributed among the buses in amounts proportional to the precontingency load flow [31], whereas UVLS is applied to the load directly connected to the bus at which the voltage vio- lation occurs [32]. Additional load shedding is performed if the frequency/bus voltage remains below the activation threshold. In case of generation capacity deficit, the amount of load shedding is estimated based on the difference between the total power demand and the available generation capacity in the island.

The simulation algorithm, depicted in Fig. 1, is as follows. 1) For each failure scenario

a) Initialize the system (topology, load/generation at each bus) with the output from the optimal power flow with the objective of generation costs mini- mization.

b) Run random component failure (for each compo- nent, a random number is sampled, the component is supposed to be failed if the number is smaller than the failure probability of the component, Pr). This paper only focuses on the line failures.

c) Check for an island in the system based on the new topology.

2) For each island a) Evaluate the system frequency deviation and the

voltage magnitude of each bus. b) Apply UFLS if the frequency deviation exceeds the

acceptable threshold [25] (e.g., 2.5 Hz). c) Apply UVLS if the voltage magnitude at a bus is

lower than 92% of nominal [26]. d) Restore load/generation balance through primary

and secondary frequency controls. Load shedding is implemented in case of generation capacity deficit.

e) Run the ac power flow model. f) Remove lines with flow higher than the line trip-

ping threshold Tl . If there are new islands, return to step 1-c).

3) Output total load shed (DNS) and total line outages.

B. Inoperability Input–Output Model

The IIM is derived from Leontief’s input–output (I–O) model [33], which is used to quantify the interconnectedness within sectors of the economy. Extending from the traditional I–O model, inoperability is expressed as a proportional lack of pro- ductivity relative to its “as-planned” production capacity [34]. This normalized production loss is calculated as

Normalized production loss

= (as-planned production)–(degraded production)

as-planned production . (5)

The IIM is constructed based on two assumptions. The first is the equilibrium assumption (i.e., all production is consumed). The supply inoperability of an industry is equal to the sum of the direct perturbation to the industry’s production and cascad- ing inoperability from interconnected industries. The second is that interdependent industries receive proportional impact from disruptive sectors. The basic formulation of IIM is found in (6), where A� is an industry interdependence matrix that is modified from the Leontief technical coefficient matrix A according to [34] (i.e., A� = 1/x̂ · A · x̂. Matrix x̂ is the diagonal matrix de- rived from the production vector x. Each element a�ij describes the amount of inoperability occurred in industry i due to the inoperability in industry j. f∗ is a vector of direct perturbation to an industry’s production. The inoperability vector q is a real- valued vector of normalized production losses for each industry at the national level. qi > 0 and qi < 0 represent the ratios of unrealized and excessive production with respect to the nomi- nal production level of the sector, respectively. The unrealized production represents the proportional extent to which indus- tries are not producing. Inoperability can also be understood as the supply unreliability of a sector [35]: qi = 0 if industry i is operating at its nominal level—it experiences no inoperability in such a case. qi = 1 if industry i is completely inoperable relative to nominal. The element of f∗ f ∗i is the change to the final demand with respect to nominal production output for industry i

q = A∗q + f∗ ⇔ ⎧ ⎨

⎩ qi =

j

a∗ij qj + f ∗ i

⎫ ⎬

⎭ . (6)

Equation (6) estimates supply inoperability from intermedi- ate economic exchanges between industries. To calculate the inoperability resulting from a given disruption, q is represented in (7) as a function of a prespecified perturbation vector f∗, the interdependence matrix A∗, and a conformable identity matrix I

q = (I − A∗)−1 × f∗. (7) Note that (7) is linear in nature, therefore an increased per-

turbation results in a proportional increase in inoperability. In- operability can be converted into economic loss by multiplying inoperability by the production vector x.

To reflect the spatially explicit intraregional interdependen- cies, which are likely to differ from those at the national level, the IIM is regionalized by adding spatial explicitness to the model. Generally, the regional interdependence coefficients are esti- mated through the use of regional multipliers, which indicate the regional production compared to the national production. In [17], a specific type of regional multiplier called a location quotient is used for the estimation of regional interdependence coefficients. The location quotient represents the proportion of demand for industry i in region s that can be satisfied regionally, compared to the nation’s ability to satisfy the nation’s internal demand for industry i. The location quotient for industry i and region s, lqsi , is found in (8), where x

s i and x

N i indicate the

overall production from industry i in region s and nation N , respectively, and xs and xN indicate the overall production from all sectors in region s and nation N , respectively. Equation (9) provides the calculation for a�sij , the amount of inoperabil- ity incurred in industry i due to the inoperability in industry j specifically in region s. a�ij is the amount of inoperability ex- perienced in industry i due to total inoperability in industry j in

LI et al.: MEASURING COMMUNITY AND MULTI-INDUSTRY IMPACTS OF CASCADING FAILURES IN POWER SYSTEMS 3589

the nation. When lqsi is less than 1, it means that the production output of industry i is insufficient to satisfy the regional supply demand, otherwise there is no adjustment to a�ij

lqsi = xsi /x

s

xNi /x N

(8)

a∗sij =

{ lqsi a

∗ ij , lq

s i < 1

a∗ij , lq s i ≥ 1.

(9)

To assess the international impact of a disruption that occurs in one country, an MRIIM was introduced to connect all coun- tries based on international trade [36]. The bilateral trade data between countries are used to construct an interregional matrix T r ti , which indicates the percentage of commodities and ser- vices in industry i that are produced in country r and consumed by country t, as illustrated in the following equation:

T r ti =

⎧ ⎪⎪⎨

⎪⎪⎩

mr ti xti + m

t i − eti

, if t �= r xti − eti

xti + m t i − eti

, if t = r (10)

where mr ti is the value of industry i’s commodities and ser- vices that are imported by country t from country r, and mti and eti are country t’s total imports from and exports to all other countries included in the model for industry i, respectively. The commodities and services that are both produced and consumed in country t are represented as T tti . Both exports and imports are included in the calculation in order to ensure that T r ti cap- tures all the production in industry i and that

∑ ∀r T

r t i = 1. The

interregional matrix T is shown in (11), where each T r ti is of size n and the ith element on the diagonal is T r ti . Variable b is the number of countries that are considered in the model

T =

⎢ ⎢ ⎢ ⎢ ⎢ ⎣

T11 T12 · · · T1b T21 T22 · · · T2b

... ...

. . . ...

Tb1 Tb2 · · · Tbb

⎥ ⎥ ⎥ ⎥ ⎥ ⎦

. (11)

The IIM is extended to the MRIIM by incorporating the interregional matrix, as shown in (12). For notational sim- plicity, the notation ya:b = [(ya )T , (ya+ 1 )T , . . . , (yb )

T ]T is

adopted to represent a vector of length n(b − a + 1) for coun- tries a, a + 1, . . . , b, where yc is a vector of interest (e.g., pro- duction, final demand, and changes in production). The square matrix is of order nb, where T� = 1/x̂ · T · x̂. The right-hand side of (12) illustrates how the demand level in one or more countries can affect the production in b countries

q1:b = T� A� q1:b + T� f �1:b = (I − T� A� )−1 T� f �1:b . (12) The IIM enterprise has successfully deployed to provide an

account of how a disruption that adversely impacts a particular industry can lead to inoperable conditions in other industries in several domains, including waterways [15], [37], inventory [38], and electric power outages [13]. The IIM enterprise and more broadly interdependence models of multi-industry impact, were among the 10 Most Important Accomplishments in Risk Analysis: 1980–2010 [39]. The assumption of model linearity is overshadowed by the amount of real data describing inter- dependencies (A� ) and total production from the US Bureau

of Economic Analysis, the Organization of Economic Cooper- ation and Development (OECD), and dozens of other countries worldwide.

C. Integrating Cascading Failures With Interdependent Impacts

As introduced in [13], in a blackout event, the initial sector perturbation f � can be decomposed into: 1) the direct impact of a power supply disruption in electric power sector, and 2) the direct impact of reduced workforce productivity in each sec- tor with reliance on power supply. The former is only applied to electric power sector directly, whereas the latter can have impacts practically on all the sectors and is the largest source of the overall economic losses [40]. For example, Anderson et al. [13] concluded that the Northeast Blackout 2003 caused an approximately $6.5 billion reduction of earnings, of which $4.2 billion could be attributed to the income losses suffered by the workers and investors. It is difficult to capture the per- turbation effects of an electric power disruption in a macrolevel analysis (i.e., without looking at industry-specific operations in each disrupted region). The workforce perturbation is meant to work as a proxy for the lack of productivity in industries that rely on electric power, particularly in workforce-intensive industries.

1) Losses Resulting From Unfulfilled Electric Power De- mand: To evaluate the direct effect on the electric sector and the higher order effect on other dependent sectors, the percentage of DNS at the national and regional levels are translated in (13) and (14) as an electricity sector perturbation in the national and regional IIM

f ∗Nelectricity = DNSN

P Nload (13)

f ∗selectricity = DNSs

P sload (14)

where f ∗Nelectricity and f ∗s electricity are used as a perturbation to the

electricity sector in the national and regional IIM, respectively. DNSN and DNSs are the DNS values in nation N and in region s, respectively. P Nload and P

s load denote the national total load

demand and load demand in region s, respectively 2) Losses Resulting From Workforce Impacts: Inoperabil-

ity due to unfulfilled electric power demand does not provide the complete picture of how industries require and use electric power. Another perspective accounts for a lack of productiv- ity due to facilities being inoperable. A proxy for measuring the effects of this disruption is to estimate the extent to which productivity requires labor, suggesting that workforce unavail- ability resulting from a power supply disruption leads to reduced productivity [40]. For instance, in the manufacturing industry, a proxy for measuring the production that is interrupted in a blackout could be a function of labor requirements. An elec- tric power blackout may affect the mobility of the workforce in terms of unavailable power-dependent transportation modes [40]. There are two layers of interdependencies: the workforce’s dependence on the electric power and the industry’s dependence on the workforce. First, by examining each industry’s contribu- tion to the workforce, the effect on the workforce due to a perturbation originating from the electric power sector is esti- mated. To quantify an industry’s dependence on the workforce, the amount spent on labor costs is estimated. To do so, the lo- cal area personal income (LAPI), which reflects the amount of

3590 IEEE SYSTEMS JOURNAL, VOL. 12, NO. 4, DECEMBER 2018

Fig. 2. Integration of cascading failure and interdependent impact models.

an industry’s economic production spent on workforce, is used. Therefore, it is assumed that the effect on industry i of a dis- ruption in the workforce is proportional to LAPI. The direct workforce effects can cause other higher order effects on the productivity of interdependent sectors.

The procedure to construct the perturbation vector consider- ing the effect of workforce unavailability is as follows.

1) For each industry i, evaluate LAPIi , which is the product of personal income in industry i and the number of people employed in industry i.

2) Calculate the ratio of LAPIi to total production in industry i by dividing LAPIi by the industry’s output xi to estimate the proportional contribution of workforce to the total output of industry i.

3) Estimate the direct workforce perturbation to sector i at region s with the following:

f ∗si,workforce × ci xi

× LAPIi xi

. (15)

This equation is based on two assumptions: 1) The direct impact of workforce unavailability on the productivity of each sector is estimated by converting the supply constraints into equivalent demand reduction (i.e., f ∗si,electricity × ci /xi , where ci is the final demand in industry i); and 2) workforce intensity is proportional to the percentage of an industry’s total economic output that is spent on salaries (i.e., LAPIi /xi ).

Repeat steps 1–3 for all industries and regions to find the vector of the direct workforce perturbation at each re- gion s, f ∗si,workforce . The national direct workforce perturbation f ∗Ni,workforce is calculated as

∑ s f

∗s i,workforce .

3) Integrating the Failure and Impact Models: The cascad- ing failure analysis is integrated with the RIIM and the MRIIM to capture the direct and higher order effects of the consequence of a cascading event, illustrated in Fig. 2.

The cascading failure analysis evaluates the DNS for a cas- cading event in a country N . The DNS at each substation is mapped into the DNS at each region of the country. To evaluate the economic losses in each region, the DNS is used to con- struct the direct perturbation f ∗selectricity and f

∗s i,workforce , which

are the inputs for each RIIM. The disruption of the power ex- change between the neighboring countries M is modeled as the direct perturbation on the electricity sector of country M (i.e., f ∗Melectricity ). The international economic impact can be estimated by introducing the inputs of direct perturbation on country N (i.e., f ∗Nelectricity and f

∗N i,workforce ), and the direct perturbation on

the dependent countries M (i.e., f ∗Melectricity in the MRIIM).

Fig. 3. Rank function for the normalized load shed from cascading failure analysis for the reduced WECC network (red line) compared with the data for the western interconnect (blue line).

The severity of the consequence of a cascading event in the electric transmission system is measured as the DNS to cus- tomers and the economic losses at the regional and international levels. The risk of a cascading event is evaluated by incorporat- ing the probability of the initial contingency (i.e.,

∏k i= 1 Pri for

k initial line failures) and the severity of the consequence.

III. CASE STUDIES

We deploy the framework to estimate national and interna- tional impacts following a cascading disruption in the Swiss electric system.

A. Validation of the Cascading Failure Analysis

The validation of the cascading failure analysis is essential, because it is inherently infeasible to include all the cascading failure mechanisms, and assumptions have to be made in choos- ing the mechanisms to be modeled in particular applications [41]. In this paper, the cascading failure analysis model is val- idated on a reduced Western Electricity Coordinating Council (WECC) network system [42] by comparing the simulation re- sults with real blackout data. In the WECC network, the main source of blackouts data is the frequency of blackouts from 1984 to 2006 [43], which is provided by the North American Electri- cal Reliability Council. Another available failure dataset is the TADS transmission line outage data for 8864 outages, which was recorded by a utility company in WECC for a period of ten years [44].

The parameters of the cascading failure analysis model (i.e., the probability of random line failure Pr and the trip- ping threshold of overloaded lines Tl ) are calibrated to repro- duce historical WECC blackout statistics. When Pr = 0.001 and TI = 110% of the line capacity, the distribution of the load shedding after the simulated cascade event captures the distri- bution of the historical blackout size, as shown in Fig. 3. Fur- thermore, the probability distribution for the total line outages is consistent between the model results and the historical data for cascading events involving up to six line outages, as shown in Fig. 4. This effort is important as it represents one of the first attempts to validate cascading failure models against real power outage statistics.

LI et al.: MEASURING COMMUNITY AND MULTI-INDUSTRY IMPACTS OF CASCADING FAILURES IN POWER SYSTEMS 3591

Fig. 4. Distribution of the total outages from cascading failures for the reduced WECC network (red line) compared with the historical data (blue line).

B. Test System

For the electric network, the cascading failure analysis is built on the data describing the Swiss grid system. The Swiss transmission network consists of 161 buses, 34 generation units, and 229 transmission lines (220 kV and 380 kV). The snapshots, provided by Swissgrid, served as a basis for estimating power demand. The total generation capacity is 10 098 MW, and the total load consumption in the given snapshot is 5214.4 MW. To simulate different operating conditions, the power demand is scaled with an LF. Due to the deficiency of reliability data for the Swiss network transmission lines, the line failure probabilities are derived from the fault data of the electric components in the German transmission network for 2004–2011 [45]. The system is modeled in accordance with the modeling approach described in Section II-A.

The OECD [46] provides I–O data and bilateral trade data in U.S. dollars for all of the OECD countries and for 11 non-OECD countries in Asia and South America. Each national economy is divided into 34 industries. Data from 2011 (the most recent available) are used, and it is assumed that the coefficients for the economic structure do not change drastically over time. Seven countries in addition to Switzerland are included in the model: Austria, China, Germany, Italy, France, the United States, and the United Kingdom. These countries represent more than 80% of all of Switzerland’s importing activities. The technical co- efficient matrices and the vectors for the production and final consumption are constructed based on the I–O data. The location quotient and the LAPI are developed from the data provided by Swiss Federal Statistical Office. Bilateral trade matrices for 19 of the 34 industries are available from OECD. An assumption is made that the fraction that country t imports from country r for the other 15 industries is equal to the overall proportion that country t imports from that country r. The T matrix for OECD countries is generated based on the trade data.

In the IIM, the economic losses are typically estimated on an annual basis. When a load shedding is operated, it is assumed that the load shedding recovery will take one day. Therefore, a uniform-loss assumption is made that losses are evenly dis- tributed throughout the year, and the annual losses divided by 365 gives an estimate of the daily economic loss [13]. Differ- ent durations of load shedding recovery can be modeled in the

Fig. 5. Cantons in Switzerland [47].

current framework, and the associated economic consequences of a loss of power supply can be estimated. There are 26 can- tons in Switzerland, as shown in Fig. 5, with all the substations geographically located in 18 cantons. To evaluate the economic losses at each Canton, the IIM is regionalized by the locational quotient.

C. Results for Application of the Integrated Model

Contingencies in the power system caused by the random line outages (i.e., independent line failure and common-mode failure) are simulated with respect to increasing loading condi- tions (i.e., LF = 1.1, 1.15, 1.2, 1.25). An optimal power flow is used to solve the economic dispatch problem at the four load conditions and to determine the initial output of each gen- erator. For each loading condition, 100 000 simulations were conducted considering a low failure probability of transmission lines and to ensure the convergence of the results. The percent- age of single-line failure or multiline failures are determined by the failure probability of each transmission line. In this study, there are 99.32% of simulations with single-line failure, 0.68% of simulations with double-line failure, and 0.0004% of simu- lations with triple-line failure. Furthermore, 30% of the initial failures can lead to cascading failures. Each cascade simulation takes 0.057 s on average on a desktop with Core i7 processor and 16 GB RAM. The load shedding caused by the cascading events at each substation is mapped into the DNS at each canton. The economic losses for the DNS at each canton are evaluated with the RIIM for each canton. The electric power imports and ex- ports between Switzerland and other neighboring countries can be disrupted when load shedding is conducted at the nodes on the border. The economic losses due to the direct perturbation on each sector of Switzerland (i.e., unfulfilled electric power demand and workforce unavailability) and the direct perturba- tion on the electric sectors of the countries, which have power import/export with Switzerland, are evaluated with the MRIIM for Switzerland and the dependent countries.

1) Correlation: Power Supply Losses and Economic Losses in Switzerland: For each scenario, the economic losses in Switzerland estimated with the RIIM (from direct power per- turbation and workforce unavailability) are plotted against DNS with respect to the initial power demand, which is the pertur- bation input f ∗selectricity to the IIM. In Fig. 6, the comparison

3592 IEEE SYSTEMS JOURNAL, VOL. 12, NO. 4, DECEMBER 2018

Fig. 6. Correlation plot for the risk of economic losses from the RIIM (vertical axis) and the risk of DNS (horizontal axis) given the same scenario.

Fig. 7. Probability of the initial contingency against the DNS in a cascading event.

with the linear regression trend line indicates that the economic impact of a power loss of supply does not scale proportionally with the DNS. This is due to the fact that the power dependence of economic sectors varies in different cantons. Therefore, when different cantons are affected by the power disruption, the same DNS can translate into different magnitudes of economic losses.

2) Risk Analysis of Cascading Events: The consequences of a cascading event (e.g., DNS and economic losses) are plotted against the probability of the initial contingency in Figs. 7 and 8. The cascading events in the bottom left cor- ner have a low level of risk. As illustrated in the figures, most of the events are associated with relatively lower consequences (i.e., lower than 2000 MW in terms of DNS and less than $150 million in multi-industry economic losses). It can be observed that the contingencies with different probabilities can lead to the same consequences. This is due to the fact that when differ- ent contingencies occur, the same island condition with certain generation insufficiency can be formed when the cascade stops.

Fig. 8. Probability of the initial contingency against the economic losses in each cascading event.

Fig. 9. (a) Risk of DNS at each canton and (b) its geographical distribution.

The cascading events toward the top right corner have higher risk. These events, marked with red circles in Figs. 7 and 8, are associated with a higher priority in risk management because they have a high probability of occurring and can cause large DNS and economic losses.

3) Regional Vulnerability: In Fig. 9, the risk of DNS caused at each canton for these scenarios is plotted. It can be observed that canton Zug (ZG), Graubünden (GR), and Aargau (AG) suf- fered the largest DNS in the scenarios. The losses in Canton Zug (ZG) are twice the losses experienced by the second most im- pacted canton. The power losses are translated into the economic losses through the RIIM, and Fig. 10 illustrates the cumulative economic losses at each canton. The result demonstrates that

LI et al.: MEASURING COMMUNITY AND MULTI-INDUSTRY IMPACTS OF CASCADING FAILURES IN POWER SYSTEMS 3593

Fig. 10. (a) Risk of economic losses at each canton and (b) its geographical distribution.

Fig. 11. Economic losses in each country.

the power supply robustness of each canton is ranked differ- ently based on the risk of DNS and on the risk of economic losses. For instance, Canton AG has the third largest power supply losses but ranked on the top of economic losses among regions because this canton has many energy intensive compa- nies and therefore a strong dependence on the electric power supply.

Fig. 11 provides important insight into the interdependent im- pacts that large disruptions might have in different countries. In Europe, Switzerland assumes a key role as an electricity hub of Europe. Switzerland imports power from Germany, Austria, and France and exports power to Italy. Table I presents the amount power that is imported and exported between Switzerland the neighboring countries for the considered operating condition.

Due to the strong dependence of the electricity supply be- tween Switzerland and the neighboring countries, a power sup- ply disruption caused by cascading events in Switzerland can lead to a significant change in production in the electric sec- tors of neighboring countries. The neighboring countries that have grid connection and electricity exchange with Switzerland

TABLE I AMOUNT OF POWER, IN MEGAWATTS, THAT SWITZERLAND IMPORTED

FROM AND EXPORTED TO EACH COUNTRY

Countries Austria France Germany Italy

Import 845.7 1144.2 2212.7 0 Export 0 157.9 165.9 2560.8

Fig. 12. Economic losses in Swiss industries.

(i.e., Austria, France, Germany, and Italy) suffered more sig- nificant impacts in this disruptive scenario than the countries without electricity exchange with Switzerland (i.e., China, U.K., and US). The power that exports from Austria to Switzerland is 15% of Austria’s total electric power consumption, therefore Austria is the most impacted country. The direct perturbation can lead to further economic losses in interdependent industries. The higher order impacts on the interdependent industries are obvious. For instance, the indirect economic losses Switzerland constitute 20% of the total economic losses, and for Austria the indirect economic losses are higher than the direct losses.

4) Industry Vulnerability: To identify the most susceptible sectors to power supply disruption, the distribution of the over- all economic losses among sectors is analyzed. We aggregated the 34 industries into 10 related industries and explore the im- pacts in each. Fig. 12 shows the interdependent economic losses in each industry in Switzerland for the disruption scenario. It can be observed that the economic losses caused by the work- force unavailability significantly contribute to total losses. As expected, the energy, utility, and construction industry suffered the greatest production losses, as these losses consist of the impact of disruption in electric sector and the workforce un- availability in the construction sector. The wholesale and retail trade, business services, and education and health industries have high economic losses caused by workforce unavailability as these industries are labor intensive. The electric disruption scenario also caused economic losses in the transportation and telecommunication services, which requires electricity for op- erating facilities.

Fig. 13 demonstrates the macroeconomic impact on the se- lected countries. Disaggregating the production losses by indus- try reveals that except from the energy, utility, and construction industry, the cascading event that occurred in Switzerland also has a strong international impact on the business services sector.

5) Criticality of Transmission Lines: For each transmission line, its contribution to the risk of DNS and economic losses is analyzed. Figs. 14 and 15 display the criticality of the lines mea- sured in the terms of DNS and economic losses in Switzerland, respectively. It can be observed that the criticalities of lines are

3594 IEEE SYSTEMS JOURNAL, VOL. 12, NO. 4, DECEMBER 2018

Fig. 13. Economic losses in the industries of the selected countries.

Fig. 14. Line criticalities ranked based on the risk of DNS occurring in Switzerland.

Fig. 15. Line criticalities ranked based on the risk of economic losses occur- ring in Switzerland.

ranked differently when measured with these two metrics. In Fig. 14, there are two lines significantly contributed to the DNS, line 35 and line 198, which are associated with risk of DNS for 10.93 MW and 13.35 MW, respectively. Although line 35 and line 198 are ranked as the most critical lines in DNS in Fig. 14, they are less critical compared to the line 200 in economic losses in Fig. 15.

To better understand the observations, Fig. 16 illustrates the DNS that is caused by the failure of lines 35, 198, and 200 in each canton. As expected, the line failures lead to high losses in Canton ZG, AG, andGR, which are identified as the most vulnerable regions in power supply disruption in Section III-C3.

Fig. 16. Risk of DNS caused by the failure of lines 35, 198, and 200 in each region.

Fig. 17. Line criticality ranks based on international economic losses occur- ring in selected countries.

TABLE II CRITICALITY RANK OF LINES IN TERMS OF RISK OF DNS, RISK OF ECONOMIC LOSSES IN SWITZERLAND, AND RISK OF INTERNATIONAL ECONOMIC LOSSES

Rank Risk of Economic Losses Economic Losses DNS (Switzerland) (international)

1 198 200 198 2 35 198 35 3 89 35 200 4 186 206 89 5 76 201 206 6 200 39 186 7 9 186 76 8 207 192 212 9 201 161 9 10 99 76 207

The failure of line 200 leads to high DNS in region AG, which is the region with strong dependence on the power supply and therefore the DNS is translated into high economic losses. In Fig. 17, the international impacts of the cascading events are considered for line criticality. Note that line 35, which exports power from Switzerland to Italy, has the highest criticality. The failure of this line can lead to direct power supply disruption of 1773 MW. The high economic losses caused within Switzerland adding the international economic losses make line 35 as the most critical line in terms of the multicountry economic losses. The results demonstrate the necessity of using economic impact as a measure for the component criticality.

Table II illustrates the ten most critical lines ranked based on the risk of DNS, risk of economic losses in Switzerland, and risk of international economic losses that can be caused by the failure

LI et al.: MEASURING COMMUNITY AND MULTI-INDUSTRY IMPACTS OF CASCADING FAILURES IN POWER SYSTEMS 3595

of the line. The line criticality ranks vary for different criteria, and decision makers can determine which criterion to use based on their interests (e.g., reducing power supply losses versus economic losses), or apply a multicriteria decision analysis.

IV. CONCLUSION AND OUTLOOK

The effects of regional blackout events spread across multiple industries and regions. Moreover, they not only directly impact the electric power sector, but they have distributed direct im- pacts on many other sectors due to reduced productivity. Due to the complexity of the impacts, no single metric can adequately measure the consequence of such a disruption and provide in- formation for identifying system vulnerabilities. To quantify the direct and higher order effects that can result from a cas- cading event in a large scale and complex system, we propose a framework that integrates: 1) cascading failure analysis for the electric power network with 2) a multiregional, multi-industry interdependent impact model.

The Swiss electric power case study, with impacts to several related countries, demonstrates the significance of including so- cietal consequences as an additional metric for measuring the vulnerability of a system and the criticality of components in the infrastructure. The dependence on power of different indus- tries varies in different cantons, thus the DNS and economic losses caused by the cascading event provide different perspec- tives, and are thus different, for the same canton. The framework identifies the cantons that are more dependent on the power sup- ply and are vulnerable to power supply disruption (e.g., canton AG has the third largest DNS and the highest economic losses). The I–O analysis provides complementary insight into the im- pacts on individual industries. Except from the electricity sector, the sectors that are labor intensive (e.g., wholesale and retail trade, business services and education and health industry) and the sectors that require electricity to operate the facilities (e.g., transportation and telecommunication services) can have high economic losses. Based on the results, policymakers can de- cide which region should increase the redundancy of the power supply or which industries may be best suited to have backup power generation capabilities. Additionally, ranking the criti- cality of components based on the societal consequences can provide a complementary insight for strengthening the compo- nent in the electric network. The interregional cascading effects of economic losses are captured by the commodity and service exchange among countries. If the cross-region impact is ne- glected, the total societal consequence due to a power supply reduction may be underestimated. The case study based on the OECD member countries demonstrates the significance of cap- turing the cascading effects of economic consequences across the border through the MRIIM.

In the future work, the risk management strategies would be proposed and compared to mitigate the risk of cascading failures. The restoration duration has an impact on the economic losses evaluation (e.g., for big cascades, longer restoration time is required). More specific restoration time data for cascading events of different sizes would be used. Furthermore, economic and other societal impacts can help guide recovery optimization decisions.

ACKNOWLEDGMENT

The authors would like to acknowledge the CTI - Commis- sion for Technology and Innovation (CH) and the SCCER- FURIES—Swiss Competence Center for Energy Research—

Future Swiss Electrical Infrastructure for their technical support to the research activity presented in this paper.

REFERENCES

[1] D. S. Kirschen, K. R. W. Bell, D. P. Nedic, D. Jayaweera, and R. N. Allan, “Computing the value of security,” IEE Proc. Gener., Transm. Distrib, vol. 150, no. 6, pp. 673–678, 2003.

[2] J. Kim, K. R. Wierzbicki, I. Dobson, and R. C. Hardiman, “Estimating propagation and distribution of load shed in simulations of cascading blackouts,” IEEE Syst. J., vol. 6, no. 3, pp. 548–557, Sep. 2012.

[3] M. Vaiman et al., “Risk assessment of cascading outages: Methodologies and challenges,” IEEE Trans. Power Syst., vol. 27, no. 2, pp. 631–641, May 2012.

[4] J. Johansson, H. Hassel, and E. Zio, “Reliability and vulnerability analyses of critical infrastructures: Comparing two approaches in the context of power systems,” Reliab. Eng. Syst. Saf., vol. 120, pp. 27–38, 2013.

[5] J. F. Espiritu, D.W. Coit, and U. Prakash, “Component criticality impor- tance measures for the power industry,” Elect. Power Syst. Res., vol. 77, no. 5, pp. 407–420, 2007.

[6] E. Zio and G. Sansavini, “Component criticality in failure cascade pro- cesses of network systems,” Risk Anal., vol. 31, no. 8, pp. 1196–1210, 2011.

[7] A. A. Ghorbani and E. Bagheri, “The state of the art in critical infrastruc- ture protection: A framework for convergence,” Int. J. Crit. Infrastruct., vol. 4, no. 3, pp. 215–244, 2008.

[8] I. Hernandez-Fajardo and L. Duenas-Osorio, “Probabilistic study of cas- cading failures in complex interdependent lifeline systems,” Reliab. Eng. Syst. Saf., vol. 111, pp. 260–272, 2013.

[9] B. A. Carreras et al., “Complex dynamics of blackouts in power trans- mission systems,” Chaos, Interdiscip. J. Nonlinear Sci., vol. 14, no. 3, pp. 643–652, 2004.

[10] M. A. Rios, D. S. Kirschen, D. Jayaweera, D. P. Nedic and R. N. Allan, “Value of security: Modeling time-dependent phenomena and weather conditions,” IEEE Trans. Power Syst., vol. 17, no. 3, pp. 543–548, Aug. 2002.

[11] P. Korba and I. A. Hiskens, “Operation and control of electrical power systems,” in System of Systems Engineering, M. Jamshidi, Ed. Hoboken, NJ, USA: Wiley, 2008.

[12] G. Andersson et al., “Causes of the 2003 major grid blackouts in North America and Europe, and recommended means to improve sys- tem dynamic performance,” IEEE Trans. Power Syst., vol. 20, no. 4, pp. 1922–1928, Nov. 2005.

[13] C. W. Anderson, J. R. Santos, and Y.Y. Haimes, “A risk-based input– output methodology for measuring the effects of the August 2003 northeast blackout,” Econ. Syst. Res., vol. 19, no. 2, pp. 183–204, 2007.

[14] J. Johansson, H. Hassel, and L. Svegrup, “The effect of including so- cietal consequences for decisions on critical infrastructure vulnerability reductions,” in Proc. Probab. Saf. Assess. Manage. Conf., 2014, pp. 1–47.

[15] R. Pant, K. Barker, and T. L. Landers, “Dynamic impacts of commodity flow disruptions in inland waterway networks,” Comput. Ind. Eng., vol. 89, pp. 137–149, 2015.

[16] Y. Okuyama and J. R. Santos, “Disaster impact and input–output analysis,” Econ. Syst. Res., vol. 26, no. 1, pp. 1–12, 2014.

[17] K. G. Crowther and Y. Y. Haimes, “Development of the multiregional inoperability input-output model (MRIIM) for spatial explicitness in pre- paredness of interdependent regions,” Syst. Eng., vol. 13, no. 1, pp. 28–46, 2010.

[18] B. Li, K. Barker, and G. Sansavini, “Measuring the societal and multi- industry impact of cascading failures in power systems,” in Safety and Reliability of Complex Engineered Systems. Boca Raton, FL, USA: CRC Press, 2015, pp. 4445–4453.

[19] B. Talukdar et al., “A computationally simple method for cost-efficient generation rescheduling and load shedding for congestion management,” Int. J. Elect. Power Energy Syst., vol. 27, no. 5, pp. 379–388, 2005.

[20] A. Oudalov and P. Korba, “Coordinated power flow control using FACTS devices,” IFAC Proc. Vol., vol. 38, no. 1, pp. 29–34, 2005.

[21] B. Li, G. Sansavini, S. Bolognani, and F. Dörfler, “Linear implicit AC PF cascading failure analysis with power system operations and automation,” in IEEE Power Energy Soc. Gen. Meeting, Boston, MA, USA, 2016, pp. 1–5.

[22] R. Billinton and A. Sankarakrishnan, “A comparison of Monte Carlo simulation techniques for composite power system reliability assessment,” in Proc. IEEE WESCANEX 95, Conf. Commun., Power, Comput., 1995, pp. 145–150.

3596 IEEE SYSTEMS JOURNAL, VOL. 12, NO. 4, DECEMBER 2018

[23] R. Billinton and P. Wang, “Teaching distribution system reliability eval- uation using Monte Carlo simulation,” IEEE Trans. Power Syst., vol. 14, no. 2, pp. 397–403, May 1999.

[24] L. Staszewski and W. Rebizant, “The differences between IEEE and CI- GRE heat balance concepts for line ampacity considerations,” in Proc. IEEE Int. Symp. Modern Elect. Power Syst., 2010, pp. 1–4.

[25] O. A. Mousavi et al., “Inter-area frequency control reserve assessment regarding dynamics of cascading outages and blackouts,” Elect. Power Syst. Res., vol. 107, pp. 144–152, 2014.

[26] C. W. Taylor, “Concepts of undervoltage load shedding for voltage stabil- ity,” IEEE Trans. Power Del., vol. 7, no. 2, pp. 480–488, Apr. 1992.

[27] R. Billinton, Y. Gao, and R. Karki, “Composite system adequacy assess- ment incorporating large-scale wind energy conversion systems consid- ering wind speed correlation,” IEEE Trans. Power Syst., vol. 24, no. 3, pp. 1375–1382, Aug. 2009.

[28] P. Kundur et al., “Definition and classification of power system stability IEEE/CIGRE joint task force on stability terms and definitions,” IEEE Trans. Power Syst., vol. 19, no. 3, pp. 1387–1401, Aug. 2004.

[29] P. Kundur, N. J. Balu, and M. G. Lauby, Power System Stability and Control, vol. 7. New York, NY, USA: McGraw-Hill, 1994.

[30] V. V. Terzija, “Adaptive underfrequency load shedding based on the mag- nitude of the disturbance estimation,” IEEE Trans. Power Syst., vol. 21, no. 3, pp. 1260–1266, Aug. 2006.

[31] B. Delfino et al., “Implementation and comparison of different under fre- quency load-shedding schemes,” in Proc. IEEE Power Eng. Soc. Summer Meeting, vol. 1, 2001, pp. 307–312.

[32] H. M. Dola and B. H. Chowdhury, “Intentional islanding and adaptive load shedding to avoid cascading outages,” in Proc. IEEE Power Eng. Soc. Gen. Meeting, 2006, pp. 1–8.

[33] W. W. Leontief, Input-Output Economics. London, U.K.: Oxford Univ. Press, 1986.

[34] Y. Y. Haimes and P. Jiang, “Leontief-based model of risk in com- plex interconnected infrastructures,” J. Infrastruct. Syst., vol. 7, no. 1, pp. 1–12, 2001.

[35] J. R. Santos and Y. Y. Haimes, “Modeling the demand reduction input- output (I-O) inoperability due to terrorism of interconnected infrastruc- tures,” Risk Anal., vol. 24, no. 6, pp. 1437–1451, 2004.

[36] W. Isard et al., Methods of Interregional and Regional Analysis, vol. 490. Farnham, U.K.: Ashgate Aldershot, 1998.

[37] C. A. MacKenzie, K. Barker, and F. H. Grant, “Evaluating the conse- quences of an inland waterway port closure with a dynamic multiregional interdependence model,” IEEE Trans. Syst., Man, Cybern. A, Syst. Hum., vol. 42, no. 2, pp. 359–370, Mar. 2012.

[38] C. A. MacKenzie, J. R. Santos, and K. Barker, “Measuring changes in international production from a disruption: Case study of the Japanese earthquake and tsunami,” Int. J. Prod. Econ., vol. 138, no. 2, pp. 293–302, 2012.

[39] M. Greenberg et al., “Ten most important accomplishments in risk anal- ysis, 1980–2010,” Risk Anal., vol. 32, no. 5, pp. 771–781, 2012.

[40] P. L. Anderson and I. K. Geckil, “Northeast blackout likely to reduce US earnings by $6.4 billion,” AEG Working Paper 2003-2, Anderson Econ. Group, Lansing, MI, USA, 2003.

[41] B. A. Carreras et al., “Validating OPA with WECC Data,” in Proc. 6th Hawaii Int. Conf. Syst. Sci., 2013, pp. 2197–2204.

[42] J. E. Price and J. Goodin, “Reduced network modeling of WECC as a market design prototype,” in Proc. IEEE Power Energy Soc. Gen. Meeting, 2011, pp. 1–6.

[43] NERC, “Information on blackouts in North America,” Disturbance Anal- ysis Working Group Database, North American Electric Reliability Coun- cil, Princeton, NJ, USA. [Online]. Available: http://www.nerc.com/∼ dawg/database.html

[44] Bonneville power administration transmission services operations & re- liability. [Online]. Available: http://transmission.bpa.gov/Business/Oper ations/Outage.

[45] FNN, “Determination of the input data for the reliability of calculation from the FNN Statistics, 2013,” Sep. 15, 2016. [Online]. Available: http://www.fgh.rwth-aachen.de/verein/publikat/veroeff/FGH_IAEW_Ein gangsdaten_Zuverlaessigkeitsberechnung_2013.pdf

[46] Organization for Economic Co-Operation and Development. OECD. StatsExtrats 2016, Sep. 16, 2016. [Online]. Available: http://stats.oecd. org/Index.aspx

[47] Swiss Conference of Cantonal Ministers of Education.[Online]. Available: http://www.edk.ch/dyn/11553.php

Bing Li (GS’16) received the B.S. degree from the Politecnico di Torino, Turin, Italy, in 2011, and the M.S. degree in 2013 from ETH Zürich, Zürich, Switzerland, where she is currently working toward the Ph.D. degree at the Reliability and Risk Engineer- ing Laboratory.

Her research interests include the development of cascading failure analysis tools in power systems, so- cietal impacts of cascading failures on the economic sectors, and the impacts of the electricity markets on the security of the power system.

Kash Barker received the B.S. and M.S. degrees in industrial engineering from the University of Okla- homa, Norman, OK, USA, and the Ph.D. degree in systems engineering from the University of Virginia, Charlottesville, VA, USA.

He is currently an Associate Professor and an Anadarko Petroleum Corporation Presidential Pro- fessor with the School of Industrial and Systems En- gineering, University of Oklahoma. His work broadly dealing with reliability, resilience, and economic im- pacts of infrastructure networks, which has resulted

in more than 45 refereed journal publications. Dr. Barker is an Associate Editor of IISE Transactions and is on the Editorial

Board of Risk Analysis.

Giovanni Sansavini (M’16) received the B.S. de- gree in energy engineering and M.A. and Ph.D. de- grees in nuclear engineering from the Politecnico di Milano, Milan, Italy, in 2003, 2005, and 2010, respectively.

He is currently an Assistant Professor of reliabil- ity and risk engineering with ETH Zurich, Zürich, Switzerland. His research interest focuses on the de- velopment of hybrid analytical and computational tools suitable for analyzing and simulating failure behaviors of engineered complex systems. He aims

to quantitatively define reliability, vulnerability, resilience, and risk within these systems using a computational approach based on advanced Monte Carlo sim- ulation, soft computing techniques, and optimization heuristics.

<< /ASCII85EncodePages false /AllowTransparency false /AutoPositionEPSFiles true /AutoRotatePages /None /Binding /Left /CalGrayProfile (Gray Gamma 2.2) /CalRGBProfile (sRGB IEC61966-2.1) /CalCMYKProfile (U.S. Web Coated \050SWOP\051 v2) /sRGBProfile (sRGB IEC61966-2.1) /CannotEmbedFontPolicy /Warning /CompatibilityLevel 1.4 /CompressObjects /Off /CompressPages true /ConvertImagesToIndexed true /PassThroughJPEGImages true /CreateJobTicket false /DefaultRenderingIntent /Default /DetectBlends true /DetectCurves 0.0000 /ColorConversionStrategy /sRGB /DoThumbnails true /EmbedAllFonts true /EmbedOpenType false /ParseICCProfilesInComments true /EmbedJobOptions true /DSCReportingLevel 0 /EmitDSCWarnings false /EndPage -1 /ImageMemory 1048576 /LockDistillerParams true /MaxSubsetPct 100 /Optimize true /OPM 0 /ParseDSCComments false /ParseDSCCommentsForDocInfo true /PreserveCopyPage true /PreserveDICMYKValues true /PreserveEPSInfo false /PreserveFlatness true /PreserveHalftoneInfo true /PreserveOPIComments false /PreserveOverprintSettings true /StartPage 1 /SubsetFonts false /TransferFunctionInfo /Remove /UCRandBGInfo /Preserve /UsePrologue false /ColorSettingsFile () /AlwaysEmbed [ true /Algerian /Arial-Black /Arial-BlackItalic /Arial-BoldItalicMT /Arial-BoldMT /Arial-ItalicMT /ArialMT /ArialNarrow /ArialNarrow-Bold /ArialNarrow-BoldItalic /ArialNarrow-Italic /ArialUnicodeMS /BaskOldFace /Batang /Bauhaus93 /BellMT /BellMTBold /BellMTItalic /BerlinSansFB-Bold /BerlinSansFBDemi-Bold /BerlinSansFB-Reg /BernardMT-Condensed /BodoniMTPosterCompressed /BookAntiqua /BookAntiqua-Bold /BookAntiqua-BoldItalic /BookAntiqua-Italic /BookmanOldStyle /BookmanOldStyle-Bold /BookmanOldStyle-BoldItalic /BookmanOldStyle-Italic /BookshelfSymbolSeven /BritannicBold /Broadway /BrushScriptMT /CalifornianFB-Bold /CalifornianFB-Italic /CalifornianFB-Reg /Centaur /Century /CenturyGothic /CenturyGothic-Bold /CenturyGothic-BoldItalic /CenturyGothic-Italic /CenturySchoolbook /CenturySchoolbook-Bold /CenturySchoolbook-BoldItalic /CenturySchoolbook-Italic /Chiller-Regular /ColonnaMT /ComicSansMS /ComicSansMS-Bold /CooperBlack /CourierNewPS-BoldItalicMT /CourierNewPS-BoldMT /CourierNewPS-ItalicMT /CourierNewPSMT /EstrangeloEdessa /FootlightMTLight /FreestyleScript-Regular /Garamond /Garamond-Bold /Garamond-Italic /Georgia /Georgia-Bold /Georgia-BoldItalic /Georgia-Italic /Haettenschweiler /HarlowSolid /Harrington /HighTowerText-Italic /HighTowerText-Reg /Impact /InformalRoman-Regular /Jokerman-Regular /JuiceITC-Regular /KristenITC-Regular /KuenstlerScript-Black /KuenstlerScript-Medium /KuenstlerScript-TwoBold /KunstlerScript /LatinWide /LetterGothicMT /LetterGothicMT-Bold /LetterGothicMT-BoldOblique /LetterGothicMT-Oblique /LucidaBright /LucidaBright-Demi /LucidaBright-DemiItalic /LucidaBright-Italic /LucidaCalligraphy-Italic /LucidaConsole /LucidaFax /LucidaFax-Demi /LucidaFax-DemiItalic /LucidaFax-Italic /LucidaHandwriting-Italic /LucidaSansUnicode /Magneto-Bold /MaturaMTScriptCapitals /MediciScriptLTStd /MicrosoftSansSerif /Mistral /Modern-Regular /MonotypeCorsiva /MS-Mincho /MSReferenceSansSerif /MSReferenceSpecialty /NiagaraEngraved-Reg /NiagaraSolid-Reg /NuptialScript /OldEnglishTextMT /Onyx /PalatinoLinotype-Bold /PalatinoLinotype-BoldItalic /PalatinoLinotype-Italic /PalatinoLinotype-Roman /Parchment-Regular /Playbill /PMingLiU /PoorRichard-Regular /Ravie /ShowcardGothic-Reg /SimSun /SnapITC-Regular /Stencil /SymbolMT /Tahoma /Tahoma-Bold /TempusSansITC /TimesNewRomanMT-ExtraBold /TimesNewRomanMTStd /TimesNewRomanMTStd-Bold /TimesNewRomanMTStd-BoldCond /TimesNewRomanMTStd-BoldIt /TimesNewRomanMTStd-Cond /TimesNewRomanMTStd-CondIt /TimesNewRomanMTStd-Italic /TimesNewRomanPS-BoldItalicMT /TimesNewRomanPS-BoldMT /TimesNewRomanPS-ItalicMT /TimesNewRomanPSMT /Times-Roman /Trebuchet-BoldItalic /TrebuchetMS /TrebuchetMS-Bold /TrebuchetMS-Italic /Verdana /Verdana-Bold /Verdana-BoldItalic /Verdana-Italic /VinerHandITC /Vivaldii /VladimirScript /Webdings /Wingdings2 /Wingdings3 /Wingdings-Regular /ZapfChanceryStd-Demi /ZWAdobeF ] /NeverEmbed [ true ] /AntiAliasColorImages false /CropColorImages true /ColorImageMinResolution 150 /ColorImageMinResolutionPolicy /OK /DownsampleColorImages false /ColorImageDownsampleType /Bicubic /ColorImageResolution 900 /ColorImageDepth -1 /ColorImageMinDownsampleDepth 1 /ColorImageDownsampleThreshold 1.00111 /EncodeColorImages true /ColorImageFilter /DCTEncode /AutoFilterColorImages false /ColorImageAutoFilterStrategy /JPEG /ColorACSImageDict << /QFactor 0.76 /HSamples [2 1 1 2] /VSamples [2 1 1 2] >> /ColorImageDict << /QFactor 0.40 /HSamples [1 1 1 1] /VSamples [1 1 1 1] >> /JPEG2000ColorACSImageDict << /TileWidth 256 /TileHeight 256 /Quality 15 >> /JPEG2000ColorImageDict << /TileWidth 256 /TileHeight 256 /Quality 15 >> /AntiAliasGrayImages false /CropGrayImages true /GrayImageMinResolution 150 /GrayImageMinResolutionPolicy /OK /DownsampleGrayImages false /GrayImageDownsampleType /Bicubic /GrayImageResolution 1200 /GrayImageDepth -1 /GrayImageMinDownsampleDepth 2 /GrayImageDownsampleThreshold 1.00083 /EncodeGrayImages true /GrayImageFilter /DCTEncode /AutoFilterGrayImages false /GrayImageAutoFilterStrategy /JPEG /GrayACSImageDict << /QFactor 0.76 /HSamples [2 1 1 2] /VSamples [2 1 1 2] >> /GrayImageDict << /QFactor 0.40 /HSamples [1 1 1 1] /VSamples [1 1 1 1] >> /JPEG2000GrayACSImageDict << /TileWidth 256 /TileHeight 256 /Quality 15 >> /JPEG2000GrayImageDict << /TileWidth 256 /TileHeight 256 /Quality 15 >> /AntiAliasMonoImages false /CropMonoImages true /MonoImageMinResolution 1200 /MonoImageMinResolutionPolicy /OK /DownsampleMonoImages false /MonoImageDownsampleType /Bicubic /MonoImageResolution 1600 /MonoImageDepth -1 /MonoImageDownsampleThreshold 1.00063 /EncodeMonoImages true /MonoImageFilter /CCITTFaxEncode /MonoImageDict << /K -1 >> /AllowPSXObjects false /CheckCompliance [ /None ] /PDFX1aCheck false /PDFX3Check false /PDFXCompliantPDFOnly false /PDFXNoTrimBoxError true /PDFXTrimBoxToMediaBoxOffset [ 0.00000 0.00000 0.00000 0.00000 ] /PDFXSetBleedBoxToMediaBox true /PDFXBleedBoxToTrimBoxOffset [ 0.00000 0.00000 0.00000 0.00000 ] /PDFXOutputIntentProfile (None) /PDFXOutputConditionIdentifier () /PDFXOutputCondition () /PDFXRegistryName () /PDFXTrapped /False /CreateJDFFile false /Description << /CHS <FEFF4f7f75288fd94e9b8bbe5b9a521b5efa7684002000410064006f006200650020005000440046002065876863900275284e8e55464e1a65876863768467e5770b548c62535370300260a853ef4ee54f7f75280020004100630072006f0062006100740020548c002000410064006f00620065002000520065006100640065007200200035002e003000204ee553ca66f49ad87248672c676562535f00521b5efa768400200050004400460020658768633002> /CHT <FEFF4f7f752890194e9b8a2d7f6e5efa7acb7684002000410064006f006200650020005000440046002065874ef69069752865bc666e901a554652d965874ef6768467e5770b548c52175370300260a853ef4ee54f7f75280020004100630072006f0062006100740020548c002000410064006f00620065002000520065006100640065007200200035002e003000204ee553ca66f49ad87248672c4f86958b555f5df25efa7acb76840020005000440046002065874ef63002> /DAN <FEFF004200720075006700200069006e0064007300740069006c006c0069006e006700650072006e0065002000740069006c0020006100740020006f007000720065007400740065002000410064006f006200650020005000440046002d0064006f006b0075006d0065006e007400650072002c0020006400650072002000650067006e006500720020007300690067002000740069006c00200064006500740061006c006a006500720065007400200073006b00e60072006d007600690073006e0069006e00670020006f00670020007500640073006b007200690076006e0069006e006700200061006600200066006f0072007200650074006e0069006e006700730064006f006b0075006d0065006e007400650072002e0020004400650020006f007000720065007400740065006400650020005000440046002d0064006f006b0075006d0065006e0074006500720020006b0061006e002000e50062006e00650073002000690020004100630072006f00620061007400200065006c006c006500720020004100630072006f006200610074002000520065006100640065007200200035002e00300020006f00670020006e0079006500720065002e> /DEU <FEFF00560065007200770065006e00640065006e0020005300690065002000640069006500730065002000450069006e007300740065006c006c0075006e00670065006e0020007a0075006d002000450072007300740065006c006c0065006e00200076006f006e002000410064006f006200650020005000440046002d0044006f006b0075006d0065006e00740065006e002c00200075006d002000650069006e00650020007a0075007600650072006c00e40073007300690067006500200041006e007a006500690067006500200075006e00640020004100750073006700610062006500200076006f006e00200047006500730063006800e40066007400730064006f006b0075006d0065006e00740065006e0020007a0075002000650072007a00690065006c0065006e002e00200044006900650020005000440046002d0044006f006b0075006d0065006e007400650020006b00f6006e006e0065006e0020006d006900740020004100630072006f00620061007400200075006e0064002000520065006100640065007200200035002e003000200075006e00640020006800f600680065007200200067006500f600660066006e00650074002000770065007200640065006e002e> /ESP <FEFF005500740069006c0069006300650020006500730074006100200063006f006e0066006900670075007200610063006900f3006e0020007000610072006100200063007200650061007200200064006f00630075006d0065006e0074006f0073002000640065002000410064006f00620065002000500044004600200061006400650063007500610064006f007300200070006100720061002000760069007300750061006c0069007a00610063006900f3006e0020006500200069006d0070007200650073006900f3006e00200064006500200063006f006e006600690061006e007a006100200064006500200064006f00630075006d0065006e0074006f007300200063006f006d00650072006300690061006c00650073002e002000530065002000700075006500640065006e00200061006200720069007200200064006f00630075006d0065006e0074006f00730020005000440046002000630072006500610064006f007300200063006f006e0020004100630072006f006200610074002c002000410064006f00620065002000520065006100640065007200200035002e003000200079002000760065007200730069006f006e0065007300200070006f00730074006500720069006f007200650073002e> /FRA <FEFF005500740069006c006900730065007a00200063006500730020006f007000740069006f006e00730020006100660069006e00200064006500200063007200e900650072002000640065007300200064006f00630075006d0065006e00740073002000410064006f006200650020005000440046002000700072006f00660065007300730069006f006e006e0065006c007300200066006900610062006c0065007300200070006f007500720020006c0061002000760069007300750061006c00690073006100740069006f006e0020006500740020006c00270069006d007000720065007300730069006f006e002e0020004c0065007300200064006f00630075006d0065006e00740073002000500044004600200063007200e900e90073002000700065007500760065006e0074002000ea0074007200650020006f007500760065007200740073002000640061006e00730020004100630072006f006200610074002c002000610069006e00730069002000710075002700410064006f00620065002000520065006100640065007200200035002e0030002000650074002000760065007200730069006f006e007300200075006c007400e90072006900650075007200650073002e> /ITA (Utilizzare queste impostazioni per creare documenti Adobe PDF adatti per visualizzare e stampare documenti aziendali in modo affidabile. I documenti PDF creati possono essere aperti con Acrobat e Adobe Reader 5.0 e versioni successive.) /JPN <FEFF30d330b830cd30b9658766f8306e8868793a304a3088307353705237306b90693057305f002000410064006f0062006500200050004400460020658766f8306e4f5c6210306b4f7f75283057307e305930023053306e8a2d5b9a30674f5c62103055308c305f0020005000440046002030d530a130a430eb306f3001004100630072006f0062006100740020304a30883073002000410064006f00620065002000520065006100640065007200200035002e003000204ee5964d3067958b304f30533068304c3067304d307e305930023053306e8a2d5b9a3067306f30d530a930f330c8306e57cb30818fbc307f3092884c3044307e30593002> /KOR <FEFFc7740020c124c815c7440020c0acc6a9d558c5ec0020be44c988b2c8c2a40020bb38c11cb97c0020c548c815c801c73cb85c0020bcf4ace00020c778c1c4d558b2940020b3700020ac00c7a50020c801d569d55c002000410064006f0062006500200050004400460020bb38c11cb97c0020c791c131d569b2c8b2e4002e0020c774b807ac8c0020c791c131b41c00200050004400460020bb38c11cb2940020004100630072006f0062006100740020bc0f002000410064006f00620065002000520065006100640065007200200035002e00300020c774c0c1c5d0c11c0020c5f40020c2180020c788c2b5b2c8b2e4002e> /NLD (Gebruik deze instellingen om Adobe PDF-documenten te maken waarmee zakelijke documenten betrouwbaar kunnen worden weergegeven en afgedrukt. De gemaakte PDF-documenten kunnen worden geopend met Acrobat en Adobe Reader 5.0 en hoger.) /NOR <FEFF004200720075006b00200064006900730073006500200069006e006e007300740069006c006c0069006e00670065006e0065002000740069006c002000e50020006f0070007000720065007400740065002000410064006f006200650020005000440046002d0064006f006b0075006d0065006e00740065007200200073006f006d002000650072002000650067006e0065007400200066006f00720020007000e5006c006900740065006c006900670020007600690073006e0069006e00670020006f00670020007500740073006b007200690066007400200061007600200066006f0072007200650074006e0069006e006700730064006f006b0075006d0065006e007400650072002e0020005000440046002d0064006f006b0075006d0065006e00740065006e00650020006b0061006e002000e50070006e00650073002000690020004100630072006f00620061007400200065006c006c00650072002000410064006f00620065002000520065006100640065007200200035002e003000200065006c006c00650072002e> /PTB <FEFF005500740069006c0069007a006500200065007300730061007300200063006f006e00660069006700750072006100e700f50065007300200064006500200066006f0072006d00610020006100200063007200690061007200200064006f00630075006d0065006e0074006f0073002000410064006f00620065002000500044004600200061006400650071007500610064006f00730020007000610072006100200061002000760069007300750061006c0069007a006100e700e3006f002000650020006100200069006d0070007200650073007300e3006f00200063006f006e0066006900e1007600650069007300200064006500200064006f00630075006d0065006e0074006f007300200063006f006d0065007200630069006100690073002e0020004f007300200064006f00630075006d0065006e0074006f00730020005000440046002000630072006900610064006f007300200070006f00640065006d0020007300650072002000610062006500720074006f007300200063006f006d0020006f0020004100630072006f006200610074002000650020006f002000410064006f00620065002000520065006100640065007200200035002e0030002000650020007600650072007300f50065007300200070006f00730074006500720069006f007200650073002e> /SUO <FEFF004b00e40079007400e40020006e00e40069007400e4002000610073006500740075006b007300690061002c0020006b0075006e0020006c0075006f0074002000410064006f0062006500200050004400460020002d0064006f006b0075006d0065006e007400740065006a0061002c0020006a006f0074006b006100200073006f0070006900760061007400200079007200690074007900730061007300690061006b00690072006a006f006a0065006e0020006c0075006f00740065007400740061007600610061006e0020006e00e400790074007400e4006d0069007300650065006e0020006a0061002000740075006c006f007300740061006d0069007300650065006e002e0020004c0075006f0064007500740020005000440046002d0064006f006b0075006d0065006e00740069007400200076006f0069006400610061006e0020006100760061007400610020004100630072006f0062006100740069006c006c00610020006a0061002000410064006f00620065002000520065006100640065007200200035002e0030003a006c006c00610020006a006100200075007500640065006d006d0069006c006c0061002e> /SVE <FEFF0041006e007600e4006e00640020006400650020006800e4007200200069006e0073007400e4006c006c006e0069006e006700610072006e00610020006f006d002000640075002000760069006c006c00200073006b006100700061002000410064006f006200650020005000440046002d0064006f006b0075006d0065006e007400200073006f006d00200070006100730073006100720020006600f60072002000740069006c006c006600f60072006c00690074006c006900670020007600690073006e0069006e00670020006f006300680020007500740073006b007200690066007400650072002000610076002000610066006600e4007200730064006f006b0075006d0065006e0074002e002000200053006b006100700061006400650020005000440046002d0064006f006b0075006d0065006e00740020006b0061006e002000f600700070006e00610073002000690020004100630072006f0062006100740020006f00630068002000410064006f00620065002000520065006100640065007200200035002e00300020006f00630068002000730065006e006100720065002e> /ENU (Use these settings to create PDFs that match the "Suggested" settings for PDF Specification 4.0) >> >> setdistillerparams << /HWResolution [600 600] /PageSize [612.000 792.000] >> setpagedevice