System Operation and Security

REPORT ID: 05-SYSTEM-OPERATION · 7 MIN READ

Operating states

Dy Liacco’s classification, still the standard framing, divides system conditions into states by whether equality constraints (supply–demand balance) and inequality constraints (equipment limits) are satisfied, and whether they would remain satisfied after a credible contingency.1

StateBalanceLimitsSurvives N-1
Normal (secure)yesyesyes
Alertyesyesno
Emergencyyesviolated
In extremisviolated (islanding, load loss)violated
Restorativerecovering

The operator’s task is to stay in the normal state, and to return there from alert before a contingency arrives. Nearly all operational grid modelling exists to answer “which state are we in, and what moves us back?”

The N-1 criterion

The system must withstand the loss of any single significant element — a line, a transformer, a generating unit, a busbar, an HVDC pole — without violating operational security limits.2 Three refinements matter in practice:

What counts as one element. A double-circuit tower carries two circuits that a single tower failure removes together; a busbar fault can remove everything connected to it. Sensible contingency lists include such common-mode groups, so “N-1” in a real study is a defined list, not a mechanical enumeration of single components.

Preventive versus corrective. A preventive standard requires the post-contingency state to be acceptable with no action. A corrective standard permits defined automatic or fast manual actions — HVDC setpoint changes, special protection schemes, fast-start units — within a time limit. Corrective security is cheaper and is increasingly used, at the price of a model that must also represent the remedial actions.

Temporary admissibility. Post-contingency limits are typically looser than continuous ones: a line may be allowed 115% of rating for 15 minutes while the operator restores security. Encoding this correctly changes which contingencies bind and is a frequent source of disagreement between studies.

Beyond N-1, operators run N-k and probabilistic risk assessments for high-impact combinations, and the shift toward explicitly probabilistic security is a live topic in both research and regulation.3

Frequency control

Frequency is the system-wide indicator of active power balance. Surplus generation accelerates the rotating mass and frequency rises; deficit slows it and frequency falls. In the European synchronous areas the nominal value is 50 Hz, and control is layered.4

Inertial response (instantaneous, physics not control). The kinetic energy stored in synchronous rotating masses is released or absorbed automatically, setting the initial rate of change of frequency:

RoCoF ≈ (ΔP · f_0) / (2 · H_sys · S_sys)

where H_sys is aggregate inertia constant and S_sys the connected rated capacity. Lower inertia means a steeper initial fall for the same loss — which is the core operational consequence of displacing synchronous plant with inverters, and why systems such as Ireland’s and Great Britain’s now enforce explicit minimum-inertia or maximum-RoCoF constraints.5

FCR — Frequency Containment Reserve (seconds). Proportional droop response that arrests the deviation and stabilises frequency at a new steady value, offset from nominal.

aFRR — automatic Frequency Restoration Reserve (seconds to minutes). Centrally controlled by each TSO’s load-frequency controller to return frequency to nominal and restore the scheduled area exchange.

mFRR / RR (minutes). Manually activated, replacing aFRR so it is available again.

Defence measures. If control fails, automatic under-frequency load shedding disconnects demand in stages to save the system, and generators trip on their own protection outside defined frequency and RoCoF bands. The January 2021 Continental European separation is a clean case study: the area split, the two islands settled at different frequencies, automatic countermeasures acted, and resynchronisation followed within an hour.6

Voltage and reactive power control

Unlike frequency, voltage is local. Control operates through generator setpoints, tap changers, switched shunts, and power-electronic compensators, coordinated in a hierarchy (primary at the device, secondary over a region, tertiary optimised system-wide) in several European systems.

The failure mode to understand is voltage collapse: as loading increases, a heavily stressed corridor approaches the nose of its P–V curve, beyond which no operating point exists. It is aggravated by load behaviour — tap changers and thermostatic loads restore power consumption after a voltage dip, which increases current and depresses voltage further. The dynamics are slow enough (tens of seconds to minutes) that operators can intervene, and fast enough that they often do not.7

Congestion management

The market clears without full knowledge of the network — completely so in a zonal design, and to a lesser degree in a nodal one with simplified constraints. The result can be a schedule the grid cannot carry. The operator’s toolkit, roughly in ascending cost:

  1. Topological measures — busbar splitting, opening a line, changing PST taps or HVDC setpoints. Near-zero marginal cost, and systematically under-used because the optimisation is combinatorial.
  2. Redispatch — pay a generator on the exporting side down and one on the importing side up. Volume-neutral, cost-positive, and the dominant instrument in Germany, where redispatch and related congestion measures have run into the billions of euros annually.8
  3. Curtailment of renewables — often the cheapest available downward action per MWh in practice, given compensation rules, and a direct emissions and revenue loss.
  4. Countertrading — cross-border commercial reversal of the flow.
  5. Load shedding — last resort.

Modelling congestion management well requires the network model and an accurate representation of the market outcome that created the problem — which is why this is a use case that spans two disciplines and, usually, two teams.

Capacity calculation and the market interface

In Europe, the interface between the physical grid and the day-ahead market is the capacity calculation process defined in the CACM Regulation.9 Two methodologies:

  • NTC (Net Transfer Capacity) — a single MW limit per border direction, computed in advance. Simple, and blind to the fact that flows on one border depend on exchanges on all others.
  • Flow-based — the constraint set is expressed as zonal PTDFs onto a list of critical network elements, with remaining available margins. The market algorithm then optimises net positions directly against branch limits, which recognises interdependence and typically yields more usable exchange for the same physical network.

Flow-based capacity calculation is where grid modelling and market modelling become the same activity: the inputs are TSO grid models and generation shift keys, and the output is a constraint set that determines prices in a dozen countries. Module 6 takes this apart.

Adequacy versus security

A distinction routinely conflated:

  • Security is short-term: can the system survive disturbances from its present operating point?
  • Adequacy is long-term and probabilistic: is there enough capacity to meet demand across the distribution of possible conditions? Measured by loss-of-load expectation (LOLE, hours/year) and expected energy not served (EENS), estimated by Monte Carlo simulation over weather years, outage draws, and demand scenarios. ENTSO-E’s European Resource Adequacy Assessment is the regional instance, and its results feed capacity-mechanism decisions.10

Adequacy models often use a coarse network (zonal, NTC) and a very large number of scenarios; security models use a detailed network and a small number of carefully chosen ones. Same system, opposite modelling budgets — a good illustration of the abstraction ladder from module 1.

Summary

Operation is the continuous maintenance of a secure state under the N-1 criterion, with frequency held by a layered reserve hierarchy resting on shrinking inertia, voltage held locally by reactive resources, and congestion resolved by topology, redispatch, and curtailment. The market–grid interface in Europe is capacity calculation, increasingly flow-based, which is where grid models directly set prices.

Module 6 turns to building models for specific questions.

References


  1. T. E. Dy Liacco, “The Adaptive Reliability Control System”, IEEE Trans. Power Apparatus and Systems, vol. PAS-86, no. 5, 1967. ↩︎

  2. Commission Regulation (EU) 2017/1485 (System Operation Guideline), Art. 33–35. eur-lex.europa.eu/eli/reg/2017/1485/oj ↩︎

  3. L. Wehenkel et al., “Probabilistic Reliability Management Approaches and Tools for Transmission System Operators” (GARPUR project deliverables). garpur-project.eu ↩︎

  4. ENTSO-E, Operation Handbook and Load-Frequency Control & Reserves documentation. entsoe.eu ↩︎

  5. EirGrid and SONI, DS3 Programme — System Services and Operational Constraints. eirgrid.ie ↩︎

  6. ENTSO-E, Continental Europe Synchronous Area Separation on 8 January 2021 — Final Report, 2021. entsoe.eu ↩︎

  7. T. Van Cutsem and C. Vournas, Voltage Stability of Electric Power Systems, Springer, 1998. ↩︎

  8. Bundesnetzagentur, Monitoring Report (annual) and quarterly grid-congestion reporting. bundesnetzagentur.de ↩︎

  9. Commission Regulation (EU) 2015/1222 establishing a guideline on capacity allocation and congestion management (CACM). eur-lex.europa.eu/eli/reg/2015/1222/oj ↩︎

  10. ENTSO-E, European Resource Adequacy Assessment (ERAA). entsoe.eu/eraa ↩︎