Review on Energy Resilience

profileharsh55
StructuralvulnerabilityofenergydistributionsystemsIncorporatinginfrastructuraldependencies.pdf

Electrical Power and Energy Systems 31 (2009) 531–537

Contents lists available at ScienceDirect

Electrical Power and Energy Systems

j o u r n a l h o m e p a g e : w w w . e l s e v i e r . c o m / l o c a t e / i j e p e s

Structural vulnerability of energy distribution systems: Incorporating infrastructural dependencies

Arild Helseth a,*, Arne T. Holen b

a SINTEF Energy Research, Sem S�lands Vei 11, NO-7465 Trondheim, Norway b Norwegian University of Science and Technology, O.E. Bragstads Plass 2E, N-7034 Trondheim, Norway

a r t i c l e i n f o

Article history: Received 26 September 2008 Received in revised form 15 March 2009 Accepted 19 March 2009

Keywords: Power distribution District heating Vulnerability Network constraints Genetic algorithms (GAs)

0142-0615/$ - see front matter � 2009 Elsevier Ltd. A doi:10.1016/j.ijepes.2009.03.023

* Corresponding author. Tel.: +47 73597238; fax: + E-mail addresses: [email protected] (A. He

(A.T. Holen).

a b s t r a c t

In this paper a novel method for assessing the structural vulnerability of two coupled energy distribution systems is presented. The co-existing of an electric power distribution system and a district heating sys- tem is described and modelled, under the assumption that the operation of the district heating system is directly dependent on electric power. The structural vulnerability of the two systems subject to single failures or a set of simultaneous failures in the power system is found. Thus, the consequences of power system failures for the energy supply as a whole are quantified.

� 2009 Elsevier Ltd. All rights reserved.

1. Introduction

Reliability analysis of electric power systems is a rather mature field of study, covering all essential parts of the system [1,2]. Ana- lysing simultaneous failures in addition to single failures at distri- bution system level will normally not significantly influence the reliability indices, due to low probability of occurrence and modest increase in consequences. For this reason, most methods for reli- ability analysis of distribution systems put emphasis on single failures.

On the other hand, simultaneous failures may be a result of extraordinary circumstances – such as adverse weather, malicious attacks and loss of supporting infrastructures – and will challenge the use of both human and equipment resources. The occurrence of such events is not easily predicted and the use of generic failure rates and repair times may not be appropriate for analysing the system impact of these. In this work we emphasise on finding the consequences of multiple simultaneous failures in the electric power distribution system, leaving considerations on probability of occurrence and duration of such failure sets to the judgment of the analyst.

Power system outages will in some cases degrade the perfor- mance of parallel energy infrastructures, such as natural gas or dis-

ll rights reserved.

47 73597250. lseth), [email protected]

trict heating systems, which are more or less dependent on electricity for proper operation. As these parallel energy infrastruc- tures are often meshed networks with redundant supply sources, they are generally robust to single failures in the power distribu- tion system. However, little emphasis has usually been placed on their response to larger power system outages.

A novel method for assessing the structural vulnerability of two coupled energy distribution systems is presented in this paper. The method is described and illustrated for an electric power distribu- tion system (EPDS) co-existing with a district heating system (DHS), where the operation of the DHS is directly dependent on electricity. The overall aim is to find the consequences for the en- ergy system as a whole when experiencing single or simultaneous failures in the EPDS. The structural vulnerability of the two sys- tems with respect to failures in the power system is defined as the consequences caused in both systems. Thus, the concept of vul- nerability, as defined here, is not related to the probability of such failure sets to occur.

Several recent studies have addressed the concept of vulnerabil- ity in electric power systems, ranging from graph theoretical inves- tigations in [3–5] to investigations based on more physical models in [6–9]. These studies all refer to the transmission system, and the applied definitions of vulnerability differ significantly. In [10], the vulnerability to failures at distribution level is analysed using a network analytic approach. Here, the electric properties of the net- work are neglected and vulnerability is defined as the degree of loss or damage to the system when exposed to a perturbation of a given type and magnitude.

532 A. Helseth, A.T. Holen / Electrical Power and Energy Systems 31 (2009) 531–537

Some studies have been conducted regarding infrastructural dependency modelling. In [11] a general overview of different kinds of interdependencies in critical infrastructures is given. A network analytic approach is presented in [12], identifying vulner- abilities in local distribution systems of electricity, natural gas and water. Furthermore, [13,14] describe and analyse the impact of natural-gas system reliability on electric power transmission systems.

Unlike the studies addressed above, this paper concerns the tight coupling between electric power and district heating systems and provides a measure for quantifying the vulnerability of such coupled systems. In the following section the system modelling ap- proach and the corresponding underlying assumptions for both the EPDS and DHS are outlined. Section 3 presents the simulation logic together with a screening strategy used for finding the most critical failure sets in the EPDS. In Section 4, a simple example is elabo- rated, before the method is applied in a case study in Section 5.

2. System modelling

Both the EPDS and the DHS are modelled as networks, compris- ing a set of nodes N and a set of branches B, following an object- oriented modelling approach.

System consequences are denoted CEPDS and CDHS for the EPDS and DHS, respectively. Various indices may be applied for quantifi- cation of consequences associated with interruption of supply in the two systems. In this study, the frequency and duration of inter- ruptions are not calculated, and the consequences are simply de- scribed in terms of interrupted electric and thermal power. It should be noted that other relevant system indices, e.g. indices re- lated to the number and type of consumers having their supply interrupted could easily be incorporated in the presented method.

2.1. The electric power distribution system

Fig. 1 shows a network model resembling a simple EPDS, com- prising nodes 1–8 and branches b1–b9. The system serves seven load points (nodes 2–8). All branches have switches at both their sending and receiving ends. Branches b3 and b9 are load-transfer branches, having normally open switches at both ends. Node 1 rep- resents the energy in-feed point, typically being a HV/MV substation.

Branch and node failures in the EPDS have the potential to interrupt the service to load points. Interrupted load points may be classified depending on the corresponding interruption dura- tion; some load points will have their supply restored after a net- work reconfiguration, while others will have to wait for the repair of one or more of the faulted components. In this study an idealised system representation was assumed, treating network reconfigura- tion as an instantaneous operation. Thus, a load point is considered interrupted only if supply cannot be restored before at least one of the faulted components has been repaired.

Fig. 1. A network model of a simple electric power distribution system.

For the further analysis, the following assumptions were made in addition to the ones stated above.

– Only permanent branch failures are considered; – All switchgear is fully reliable; – Upstream supply from substations is fully reliable; – Load points are either fully supplied or not supplied at all.

For each failure set in the EPDS, the minimum interrupted power CEPDS is found as follows: first, the faulted branches are iso- lated by using the available switches. Subsequently, the EPDS is reconfigured. In case there are multiple load-transfer options, a GA (Genetic algorithm) from the library GAlib [16] is used to find the combination of load-transfer branches to utilise giving the minimum CEPDS.

A simple binary GA was defined for this optimisation problem. A thorough description of the basic operators of the GA may e.g. be found in [15]. It should be noted that the GA has no convergence guarantee in arbitrary problems. In order to improve the conver- gence properties, hybrid GA schemes incorporating local search techniques may be constructed. In this study repeatability of the results was used as a convergence guarantee.

For a network reconfiguration to be valid, the following con- straints should be met:

a. For all nodal load-point voltages Vi: Vi P Vmin, b. For all branch currents Ib: Ib 6 Ib,max, c. Radial system operation,

where Vmin is the minimum nodal voltage allowed and Ib,max the maximum branch current.

2.2. The district heating system

For the purpose of evaluating the cascading consequences of EPDS failures in a DHS, a simplified thermal power-flow model was developed. This model fully decouples the pressure and tem- perature responses, considering the steady-state solution only.

As a first step to describe this model and its assumptions, con- sider the flow in the simple DHS in Fig. 2. The system comprises the following components: two thermal power production units (TP1 and TP2), four pumps (PU1–PU4), four heat exchangers (HE1–HE4) and a set of pipelines. Nodal demand and production in terms of mass flow Q, and thermal power demand D and production G are indicated in the figure. Production units, pumps and heat exchang- ers are all considered as nodes in the DHS network model, and are normally directly dependent on electric power for proper operation.

The DHS consists of both supply and return pipelines. Water is flowing through heat exchangers and into the return pipeline net- work. Heat exchangers can be viewed as aggregated load points serving underlying customers and distribution systems. Con- versely, water is injected into the supply pipeline network through

Fig. 2. A network model of a simple district heating system, indicating nodal demand and production in terms of mass flow Q, and thermal powers D and G.

A. Helseth, A.T. Holen / Electrical Power and Energy Systems 31 (2009) 531–537 533

the production units. Note that only the supply pipelines are shown in Fig. 2. At steady-state, the mass balance in (1) is always fulfilled. X i2N

Q i ¼ 0 ð1Þ

Fig. 3. Class diagram illustrating the node hierarchy.

2.2.1. A network flow model A general formulation of thermal power flowing in a DHS may

be obtained by applying a conventional network flow model, explicitly considering thermal power flow rather than tempera- tures and pressures. In this type of model, the thermal power flow is described by conservation laws only. Network flow models have been applied in investigations related to optimisation of multi-car- rier energy systems in [17,18].

When thermal power production does not meet demand, the following linear programming formulation will find the minimum curtailed thermal power (Ptcurt ):

Min: : Ptcurt ¼ X i2N ð1 � xiÞDi ð2aÞ

s:t: : X

j:bðj;iÞ2B Ptbðj;iÞ �

X j:bði;jÞ2B

Ptbði;jÞ þ Gi � xi Di ¼ 0 ð2bÞ

jPtbj 6 P t b;max ð2cÞ

Gi 6 Gi;max ð2dÞ

0 6 xi 6 1 ð2eÞ

where xi is the ratio between supplied thermal power and total de- mand at load-point node i. Restriction (2b) describes the thermal power balance at each node. Ptbði;jÞ denotes thermal power flow in the pipeline connecting nodes i and j, being constrained by (2c). Gi and Di denote thermal power production and demand at node i, respectively, where Gi is constrained by its maximum power Gi,max in (2d).

The network flow model relies on two major underlying assumptions. First, as the system is described at steady-state, tran- sient changes in thermal power flow due to network reconfigura- tions and redispatch of production units and pumps are not considered. Second, the formulation does not consider the physical law linking mass flows and pressures. Thus, the model relies on the assumption that there is sufficient pressure at all load nodes.

Although applicable for general investigations of system behav- iour, the network flow model was not considered appropriate for analysing the consequences of nodal failures, due to its inability to deal with deactivation and failure of pumps. For this reason, it was decided to make some assumptions regarding thermal power-flow control in DHSs, in order to arrive at a more accurate model.

2.2.2. A simplified thermal power-flow model It is possible to control the thermal power flow in a DHS by pre-

defining the mass flow Q through each heat exchanger and produc- tion unit, as illustrated in Fig. 2. Q has a positive reference out of the supply network. This control principle is based on a constant temperature differential DT at each load point and production unit. G is the injected thermal power and D is the consumed thermal power, so that {G,D} /jQj.

The thermal power flow in a pipeline b, Ptb is expressed as:

Ptb ¼ Cp � Q b � DT ð3Þ

where Cp = heat capacity of water; Qb = mass flow in pipeline b; DT = temperature difference between supply and return flow.

Mass flows and nodal pressures were found by running flow studies based on the Newton nodal-loop method described in [19].

All thermal power production units have an associated pump responsible for providing flow through the unit and into the supply network. In case this pump fails, the flow rate through the pump is set to zero. Similarly, in case the production unit fails itself, the flow rate through the associated pump is set to zero. Accordingly, a production unit together with its associated pump may be viewed as one aggregated unit, as indicated by the dotted-line boxes in Fig. 2.

Some pumps are operated independently of production units, such as PU2 and PU3 in Fig. 2. These pumps will usually have the ability to circulate flow in both directions. In case an independently operating pump fails, it is bypassed.

Based on the mass-flow control principle described above, it is now possible to define a model which is not limited by the assumption of sufficient nodal pressures, as was the case with the network model in Section 2.2.1. Being still a steady-state mod- el, redispatch of production units and pumps are considered instantaneous. For each set of faulted DHS nodes, the minimum interrupted thermal power CDHS is found as follows:

(i) Deactivate or bypass the faulted nodes; (ii) Run a Newton nodal-loop flow study to find pressures (p)

and pipeline mass flows (Qb); (iii) Find thermal power flows (Ptb ) from (3); (iv) If network constraints are not met, run a simple binary GA to

find the minimum curtailed thermal power CDHS.

Partial supply of load points were not allowed. For a network configuration to be valid, the following network constraints have to be met:

a. For all nodal load-point pressures pi: pi P pmin, b. For all pipeline flows Ptb : P

t b 6 P

t b;max ,

c. For all thermal power production Gi: Gi 6 Gi,max

2.3. Dependency modelling

Fig. 3 shows an excerpt of the Unified Modelling Language (UML) class diagram for the node hierarchy applied in the joint modelling of the two systems. Instance variables and functions are omitted for brevity.

3. System simulation

Applying the presented method to large scale infrastructures analysing higher-order failure sets is computationally intensive. A screening strategy inspired by [20] was applied in order to fully analyse only the most critical failure sets. Thus, computation time is reduced as well as the number of failure sets to be evaluated after the simulation has been performed. The strategy is based on the concept of synergy, as explained below.

Fig. 4. Flowchart of the structural vulnerability assessment method.

Fig. 5. Dependency of a DHS on electric power. Couplings between EPDS load points and DHS nodes are indicated by arrows.

534 A. Helseth, A.T. Holen / Electrical Power and Energy Systems 31 (2009) 531–537

3.1. Failure set synergy

Consider the EPDS under study consisting of n components being subject to a failure set Fki . The failure set is set number i of order k. The maximum number of failure sets of order k is found by (4).

ikmax ¼ n!

ðn � kÞ!k! ð4Þ

In case k is larger than 1, it will be possible to divide Fki into a set of divisions D, where each division d 2 D comprises the same components as in Fki . As an example, consider a set of order 3, comprising components a, b and c. There are four possible divisions (d1 � d4) of F3ðabcÞ, as shown below.

D F3ðabcÞ � �

¼

d1 : F 2ðabÞþF1ðcÞ;

d2 : F 2ðacÞþF1ðbÞ;

d3 : F 2ðbcÞþF1ðaÞ;

d4 : F 1ðaÞþF1ðbÞþF1ðcÞ

8 >>>< >>>:

If Fki gives rise to larger consequences in the EPDS (CEPDS) than the largest sum of consequences for all sets Fd in any of its divi- sions, Fki is said to be synergistic, as formulated in (5). Thus, the synergy concept relates to network connectivity and reconfigura- tion capability of the EPDS.

CEPDSðFki Þ > MAX X Fd2d

CEPDSðFdÞ 8d 2 D

0 @

1 A ð5Þ

It is possible to screen higher-order failure sets according to their synergy. A failure set of order k may cause large conse- quences, but if the failure set is not synergistic, it indicates that these consequences were counted for when analysing sets of lower order. Thus, running the simulation with an increasing value of k, allows us to emphasise on the synergistic failures sets.

3.2. Simulation logic

The screening strategy was implemented in the structural vul- nerability assessment method as illustrated in Fig. 4. First, the depth of the analysis is set by choosing the highest failure-set or- der to be considered (kmax). Determining kmax is the choice of the analyst, depending on how many simultaneous failures that are considered possible. For each k, ikmax is found from (4).

For each Fki , CEPDS is found as described in Section 2.1. In case Fki is synergistic and there are DHS nodes without electric power, CDHS is found as described in Section 2.2. Consequently, a tuple of consequences (CEPDS,CDHS) is found for each synergistic failure set.

3.3. Component criticality

Although the non-synergistic failure sets are screened out, a thorough interpretation of the remaining synergistic failure sets Fsyn can be tedious. Finding the EPDS branches contributing the most to consequences in Fksyn of a given order k, will provide a measure of component criticality. The contribution R to conse- quences C (either CEPDS or CDHS) of branch b for a failure set order k is defined as the ratio between the sum of the consequences caused by synergistic failure sets including branch b and the sum of consequences for all synergistic failure sets:

Rðb; kÞ¼ P

Fk i 2Fksyn;b2F

k i

CðFki Þ � �

P Fk

i 2Fksyn

CðFki Þ � � ð6Þ

This metric provides a measure for finding the components being the major contributors in synergistic failure sets of a certain order. One can interpret R(b,k) as the average relative conse- quences due to the simultaneous failure of component b together with k � 1 other randomly chosen components.

4. Example

In order to illustrate the method described in the previous sec- tions, an example is presented based on the two systems shown in Figs. 1 and 2. Fig. 5 illustrates the couplings between EPDS load points and DHS nodes. For clarity and simplicity, we assume that the EPDS is unconstrained in this example. It is assumed that all EPDS load point demands are equal.

Pipeline and nodal data for the DHS system are listed in Tables A.1 and A.2 in the Appendix, along with thermal power flows and

Fig. 7. A network model of the central district heating system.

A. Helseth, A.T. Holen / Electrical Power and Energy Systems 31 (2009) 531–537 535

pressures for the system in its initial, healthy state. Pumps PU2 and PU3 were set to deliver a constant outlet pressure of 1.0 per unit (p.u.), and the minimum pressure requirement was set to pmin = 0.9 p.u. The Hazen–Williams equation was applied as described in [21], using a roughness coefficient of 130. A constant DT of 50 degrC and an operating pressure of 16 bar was applied.

Failure sets comprising three or less branches are considered. As the EPDS has 9 branches, there are 129 failure sets in total. A total of 36 failure sets were found to be synergistic; 27 third and 9 sec- ond-order sets. These synergistic sets are treated further in the DHS analysis. A scatter plot of the resulting consequences for the EPDS (CEPDS) and DHS (CDHS) for the synergistic failure sets is pre- sented in Fig. 6. Consequences are measured in interrupted electric and thermal power, in percentage of the total load demand in each of the two systems. Open circles indicate failure sets of second or- der and filled circles indicate third-order failure sets. For each cir- cle in Fig. 6, there is a set of failure sets causing this tuple of consequences. All synergistic second-order sets are listed in the figure, and some of these are commented on below.

The failure set F2ðb1; b3Þ is the second-order failure set causing the highest consequences. EPDS load points 2 and 3 are isolated, which in turns directly interrupts supply to heat exchangers HE1 and HE3.

Two failure sets give rise to the consequence tuple (CEPDS = 29%, CDHS = 24%). The failure set F

2ðb4; b6Þ results in interruption of supply to EPDS load points 4 and 5. As a result, supply to HE4 and PU2 is interrupted. Both the heat exchanger and the pump are bypassed, and the subsequent flow study – based on the new DHS configuration – reveals that no network constraints are vio- lated. The failure set F2ðb7; b9Þ isolates load points 7 and 8 in the EPDS, which in turn interrupts supply to TP2 and its associated pump PU4, and PU3. The flow rate through TP2 and PU4 is set to zero and PU3 is bypassed. With this DHS configuration, TP1 has enough capacity to supply all load points; however, as both the minimum pressure and maximum pipeline capacity constraints are binding in this case, the GA reveals that HE4 is the minimum load to be cur- tailed while meeting the network constraints.

All third-order failure sets isolating EPDS load points 6 and 7 will leave the DHS completely without thermal power production capacity, giving CDHS = 100 %. As all synergistic third-order failure sets will cause isolation of EPDS node 6, at least three DHS heat exchangers will experience interruption of supply.

5. Case study

In this section a case study is presented, analysing the structural vulnerability of the coupled EPDS and DHS located in the city

Fig. 6. Interrupted power for both the EPDS (CEPDS) and the DHS (CDHS). Failure sets of second order are marked with � and third order with �.

centre of Trondheim, Norway. The defined system boundary in- cludes only the central parts of the two systems. Figs. 7 and 8 pres- ent the structural topologies of the two networks. It should be noted that both network models are simplified, but still reflect the basic design of the real systems.

The central part of the DHS is shown in Fig. 7. This system com- prises three pumping stations, eight thermal power production units and 11 aggregated load points, and the total installed capac- ity and maximum load is 149 MW and 106 MW, respectively. The surrounding EPDS is a medium-voltage cable network fed by three HV/MV substations and serving 34 load points. The voltage and pressure constraints were set to Vmin = 0.95 p.u. and pmin = 0.90 p.u. Couplings between the two systems are mapped as in Fig. 5, but are not presented here for practical reasons.

A simulation was performed for failure sets comprising three or less components, considering only EPDS branch failures. In total there are 40 first, 780 second and 9880 third-order failure sets. From the simulation it was found that 12 first, 64 second and 176 third-order failure sets have synergistic consequences. A scat- ter plot of the consequence tuples caused by these synergistic fail- ure sets is presented in Fig. 9. Consequences are measured in interrupted electric and thermal power, in percentage of the total load demand in each of the two systems.

In Table 1 the synergistic failure sets causing maximum conse- quences, both in terms of CEPDS and CDHS, are listed. The maximum CEPDS in second and third-order synergistic failure sets was found to be 27.6% and 36.3% of the total demand in the EPDS, respec- tively. For comparison, the maximum CEPDS in second and third-or- der non-synergistic failure sets was found to be 20.0% and 34.0%.

At most 1.9% of the DHS load is interrupted due to single branch failures in the EPDS. This result indicates that the DHS is not par- ticularly vulnerable to single failures in the EPDS. In fact, all the major DHS load points, pumps and thermal power production units can receive power from more than one EPDS feeder.

Fig. 8. A network model of the electric power distribution system. Branches are enumerated.

5 10 15 20 25 30 35 40

10

20

30

40

50

60

Fig. 9. Interrupted power in percentage of total demand for both the EPDS (CEPDS) and DHS (CDHS). Failure sets of first order are marked with j, second order with * and third order with �.

Table 1 Maximum consequences for synergistic failure sets of different orders.

Order Maximum Set CEPDS (%) CDHS (%)

1st CEPDS b26 13.7 0.0 CDHS b18 0.0 1.9

2nd CEPDS b11, b26 27.6 6.6 CDHS b5, b16 8.8 18.9

3rd CEPDS b8, b26, b37 36.3 20.9 CDHS b1, b12, b35 20.5 52.8

Table 2 Branch contribution to consequences in synergistic failure sets.

Order Maximum Branch REPDS RDHS

1st REPDS b26 0.20 0.00 RDHS b18 0.09 0.50

2nd REPDS b26 0.20 0.07 RDHS b16 0.07 0.29

3rd REPDS b8 0.23 0.12 RDHS b35 0.07 0.26

536 A. Helseth, A.T. Holen / Electrical Power and Energy Systems 31 (2009) 531–537

Studying the two second-order failure sets listed in Table 1, it is evident that the set causing the highest value of CEPDS causes only minor consequences in the DHS. On the contrary, if branches b5 and b16 fail simultaneously, violation of EPDS network constraints limits the reconfiguration capability, resulting in EPDS load point interruptions. The system is reconfigured to minimise the inter- rupted electric power. Cascading consequences in the DHS are not considered when finding the optimal use of load-transfer

Table A.1 Pipeline parameters and initial thermal power flows.

Nr. Send. node Rec. node Length (km)

1 1 2 1.00 2 1 3 1.00 3 2 3 0.50 4 2 4 2.00 5 3 6 2.00 6 4 5 2.00 7 5 7 0.50 8 5 8 1.00 9 6 7 2.00

10 7 8 1.00

branches in the EPDS. For this particular failure set a vulnerable DHS node looses electric power supply, giving a high value of CDHS.

The third-order failure set comprising branches b1, b12 and b35 isolates a part of the EPDS which is crucial for proper DHS opera- tion; thus, more than 50% of the total DHS load is interrupted.

Table 2 shows the single components that contributed the most to consequences for different failure set orders, both in terms of CEPDS and CDHS.

Branch b26 is the most critical single component in terms of interrupted power in the EPDS. It is also the component contribut- ing the most in second-order synergistic failure sets. Considering third-order failure sets, b8 has a higher rank than b26. For compar- ison, b8 has no impact when failing alone, and only a rank REPDS = 0.08 when failing together with one arbitrary second component. This indicates that b26 is critical for failure sets of lower order, whereas b8 is only critical when simultaneously failing together with at least two other components.

Comparing Tables 1 and 2, we recognise that the most critical components for each failure set order also are contributors in the most critical failure sets in Table 1.

6. Conclusions

A method was proposed, suitable for analysing the structural vulnerability of an electric power distribution system co-existing with a district heating system. The structural vulnerability of these systems with respect to failures in the power system was defined as the consequences caused in both systems. The cascading conse- quences due to loss of electric power to essential components in the district heating system was discussed and modelled. The meth- od enables the analyst to consider higher-order failure sets in the electric power system and find the consequences caused in both systems. Furthermore, a screening strategy was applied to identify and fully analyse only the most critical failure sets.

The method was applied to a case study, where the failure sets causing the highest consequences were identified. It was discussed and shown how to rank power system components in terms of criticality.

Acknowledgements

The authors would like to thank May Toril Moen and Arnvid Syl- te at Trondheim Energi for interesting discussions and for provid- ing data for the case study.

Appendix A

Tables A.1 and A.2 contains data used in the example in Section 4.

Diameter (m) Capacity (MW) Initial Flow (MW)

0.20 21 19.00 0.20 21 19.00 0.15 21 �0.95 0.20 21 4.95 0.20 21 5.05 0.20 21 4.95 0.15 21 0.92 0.15 7 �5.97 0.20 7 5.05 0.15 7 �6.03

Table A.2 Nodal demand, supply and initial pressures.

Node name Node nr D (MW) Gmax (MW) pinit (p.u.)

TP1 1 – 50 1.00 HE1 2 15 – 0.92 HE2 3 13 – 0.92 HE3 5 10 – 0.99 HE4 7 12 – 0.99 TP2 8 – 12 1.02

A. Helseth, A.T. Holen / Electrical Power and Energy Systems 31 (2009) 531–537 537

References

[1] Endrenyi J. Reliability modeling in electric power systems. John Wiley & Sons Ltd.; 1978.

[2] Billinton R, Allan RN. Reliability evaluation of power systems. 2nd ed. Plenum Press; 1996.

[3] Albert R, Albert I, Nakarado GL. Structural vulnerability of the north american power grid. Phys Rev E 2004;69:4.

[4] Crucitti P, Latora V, Marchiori M. A topological analysis of the Italian electric power grid. Phys A: Statist Mech Appl 2004;338:92–7.

[5] Holmgren ÅJ. Using graph models to analyze the vulnerability of electric power networks. Risk Anal 2006;26:955–69.

[6] Doorman G, Uhlen K, Kjølle GH, Huse ES. Vulnerability analysis of the nordic power system. IEEE Trans Power Syst 2006;21:402–10.

[7] Yu X, Singh C. A practical approach for integrated power system vulnerability analysis with protection failures. IEEE Trans Power Syst 2004;19:1811–20.

[8] Nedic DP, Dobson I, Kirschen DS, Carreras BA, Lynch VE. Criticality in a cascading failure blackout model. Electr Power Energy Syst 2006;28:627–33.

[9] Koonce AM, Apostolakis GE, Cook BK. Bulk power risk analysis: ranking infrastructure elements according to their risk significance. Electr Power Energy Syst 2008;30:169–83.

[10] Jönsson H, Johansson J, Johansson H. Analysing the vulnerability of electric distribution systems: a step towards incorporating the societal consequences of disruptions. Int J Emerg Manage 2007;4:4–17.

[11] Rinaldi SM. Modeling and simulating critical infrastructures and their interdependencies. In: Proceedings of the Hawaii international conference on system sciences, vol. 37, Hawaii, USA; 2004. p. 873–80.

[12] Apostolakis GE, Lemon DM. A screening methodology for the identification and ranking of infrastructure vulnerabilities due to terrorism. Risk Anal 2005;2:361–76.

[13] Munoz J. Natural gas network modeling for power systems reliability studies. In: Power tech conference, vol. 4, Bologna, Italy; 2003.

[14] Shahidehpour M, Fu Y, Wiedman T. Impact of natural gas infrastructure on electric power systems. Proc IEEE 2005;93(5):1042–56.

[15] Goldberg DE. Genetic algorithms in search, optimization, and machine learning. Reading, MA: Addison-Wesley; 1989.

[16] Wall M, GAlib: A C++ library of genetic algorithm components, [online]. Available: http://lancet.mit.edu/ga/.

[17] Quelhas AM, Gil E, McCalley JD. Nodal prices in an integrated energy system. Int J Crit Infrastruct 2006;2(1):50–69.

[18] Geidl M, Andersson G. A modeling and optimization approach for multiple energy carrier power flow. In: Proc of IEEE PES PowerTech, St. Petersburg, Russian Federation; 2005.

[19] Osiadacz A. Simulation and analysis of gas networks. Gulf Publishing Company; 1987.

[20] Jönsson H, Johansson J, Johansson H. Identifying critical components in electric power systems: a network analytic approach. In: Proceedings of the European safety and reliability conference (ESREL), Stavanger, Norway; 2007.

[21] Jeppson RW. Analysis of flow in pipe networks. Ann Arbor Science; 1977.

  • Structural vulnerability of energy distribution systems: Incorporating infrastructural dependencies
    • Introduction
    • System modelling
      • The electric power distribution system
      • The district heating system
        • A network flow model
        • A simplified thermal power-flow model
      • Dependency modelling
    • System simulation
      • Failure set synergy
      • Simulation logic
      • Component criticality
    • Example
    • Case study
    • Conclusions
    • Acknowledgements
    • Appendix A
    • References