Power System Stability
An electric power system is disturbed all the time. Loads change from second to second, lightning faults trip lines, and generators fail without warning. Power system stability is the property that lets the system absorb such events and settle into a new steady state instead of drifting apart, oscillating, or collapsing. When it fails, the damage spreads far beyond the initiating event: generators lose synchronism and trip, voltages collapse, and protective relays split the network into islands.
The IEEE/CIGRE Joint Task Force on Stability Terms and Definitions, reporting in IEEE Transactions on Power Systems in August 2004, defined power system stability as “the ability of an electric power system, for a given initial operating condition, to regain a state of operating equilibrium after being subjected to a physical disturbance, with most system variables bounded so that practically the entire system remains intact.” A 2021 revision of the classification kept that definition unchanged.
This article develops the swing equation, the power–angle curve, and the equal-area criterion and applies them to a worked example of critical clearing time. It then treats electromechanical oscillations and power system stabilizers, frequency response after a loss of generation, voltage stability, resonance and converter-driven stability, and the tools of stability studies. Quantities are in per unit, and phasors are fundamental-frequency RMS values, unless stated otherwise.
Classes of Stability
Stability problems differ in the quantity that runs away, the size of the disturbance, the equipment that must be modeled, and the time span of interest. The 2004 task force report, published by P. Kundur and colleagues, therefore divided stability into rotor angle, voltage, and frequency stability. N. Hatziargyriou and colleagues revisited the scheme in “Definition and Classification of Power System Stability – Revisited & Extended” (IEEE Transactions on Power Systems, July 2021), a paper based on the 2020 IEEE Power & Energy Society technical report PES-TR77. They added two classes, converter-driven stability and resonance stability, because the controls of converter-interfaced generation act in times from a few microseconds to several milliseconds and extend the phenomena of interest down to electromagnetic transients.
| Class | Subdivisions | Main participants |
|---|---|---|
| Rotor angle | Transient; small-disturbance | Generator rotors, excitation systems, the network |
| Voltage | Large- and small-disturbance; short-term and long-term | Loads and their controls, reactive sources, tap changers, generator current limiters, HVDC links |
| Frequency | Short-term; long-term | Inertia, governors, load, automatic generation control |
| Resonance | Electrical; torsional | Series capacitors, turbine-generator shafts, induction generators |
| Converter-driven | Fast interaction; slow interaction | Phase-locked loops, current and power control loops, weak networks |
The classification rests on the intrinsic dynamics that produce an instability, not on the event that starts it, and one event can pass through several classes. A single remote generator or converter plant that loses synchronism without causing cascading instability does not make the system unstable, because practically the entire system remains intact. The 2021 paper also notes that the phasor approximation used in conventional stability programs properly models rotor angle, voltage, and frequency stability, but usually not converter-driven or resonance stability, the possible exception being slow-interaction converter-driven stability.
The Swing Equation
Rotor Dynamics
The rotor of a synchronous generator obeys Newton's second law for rotation. With J the combined moment of inertia of the generator and its turbine, ωm the mechanical angular velocity, Tm the mechanical torque of the prime mover, and Te the electromagnetic torque of the generator,
J dωm/dt = Tm − Te
In steady state the torques balance and the rotor turns at synchronous speed. A fault or a switching event changes Te almost instantly, while Tm changes only as fast as the turbine controls allow. The difference accelerates or decelerates the rotor, and its angle relative to the rest of the system changes.
The Inertia Constant H
Stability studies describe inertia by the inertia constant H, the kinetic energy stored in the rotating mass at synchronous speed divided by the machine's rated apparent power:
H = ½ J ωsm2 / Srated
With J in kg·m2, ωsm the synchronous mechanical speed in rad/s, and Srated in volt-amperes, H is in seconds, usually quoted as MW·s/MVA on the machine rating. A two-pole 60 Hz turbine-generator turns at 3,600 r/min, or 377 rad/s; with an illustrative J of 50,000 kg·m2, it stores 3,553 MJ, an H of 5.92 s on a 600 MVA rating. ERCOT, the operator of the Texas Interconnection, gives the physical reading: a 200 MVA unit with an inertia constant of 3 s would use up all of its kinetic energy in 3 s if producing at full output. Twice H is the mechanical starting time, the time rated torque would take to accelerate the rotor from standstill to rated speed.
| Resource type | MVA base range | H range (s, on machine MVA base) |
|---|---|---|
| Nuclear | 1,410–1,504 | 3.8–4.34 |
| Coal | 194–1,120 | 2.9–4.5 |
| Combustion turbine | 7–235 | 1–12.5 |
| Gas steam | 14–887 | 1–5.4 |
| Combined cycle | 25–1,433 | 1.1–9 |
| Hydro | 9–36 | 2–3 |
| Reciprocating engine | 10–70 | 1.1–2.1 |
| Wind | — | 0 |
| Solar PV | — | 0 |
The Per-Unit Form and Its Conventions
Let δ be the electrical angle of the rotor measured against a reference that rotates at synchronous speed, so that δ is constant in steady state. For a machine with p poles, electrical angles are p/2 times mechanical angles, and ωs = (p/2)ωsm = 2πf0 is the synchronous speed in electrical radians per second, where f0 is the nominal frequency. Substituting H and dividing by the rating gives the swing equation in its usual form:
(2H / ωs) d2δ/dt2 = Pm − Pe
- Pm is the mechanical input power and Pe the electrical output power, both in per unit on the machine rating, the same base as H.
- H is in seconds, δ in electrical radians, and t in seconds; ωs is 377 rad/s on a 60 Hz system and 314 rad/s on a 50 Hz system.
- The derivation takes per-unit torque as equal to per-unit power, which is accurate while speed stays close to synchronous, as it does during electromechanical swings.
- Damping is neglected. A term DΔω subtracted from the right side, with Δω = (1/ωs) dδ/dt the per-unit speed deviation and D in per-unit power per per-unit speed, represents damper windings and the frequency sensitivity of load.
With δ in electrical degrees the equation becomes (H / 180f0) d2δ/dt2 = Pm − Pe. A positive right side, more mechanical input than electrical output, advances the rotor ahead of the synchronous reference.
Several Machines on a Common Base
A multimachine study writes one swing equation per machine on a common system base, converting H by the power ratio alone: Hsys = Hmach Smach / Ssys. Machines that swing together, such as the units of one plant, can be combined into one equivalent machine whose H·S is the sum of theirs. The network couples the equations, so the complete model joins differential equations for the machines and controls with algebraic equations for the network.
The Power–Angle Curve
The Classical Model
The simplest useful model for rotor angle studies, called the classical model, rests on four assumptions:
- Each generator is a constant voltage magnitude E′ behind its direct-axis transient reactance X′d, the reactance described in Fault Analysis and Symmetrical Components, and the angle of E′ stands in for the rotor angle δ.
- Mechanical power stays constant, because turbine governors act over seconds.
- Damping and the actions of excitation systems are neglected.
- The network is lossless and in sinusoidal steady state at nominal frequency, and loads are constant impedances.
The model suits the first swing after a fault, which in the worked example below peaks within about 0.7 s, but not later swings that controls can make grow. Production programs add detailed models of field and damper windings, exciters, and governors from synchronous machine theory.
Power Transfer and Equilibrium
Consider a generator connected to an infinite bus, a bus whose voltage magnitude V and frequency stay constant whatever the generator does, through a total transfer reactance X that includes X′d. Its electrical power is
Pe = (E′V / X) sin δ = Pmax sin δ
The curve rises to Pmax = E′V/X at δ = 90° and falls beyond it. A horizontal line at Pm crosses it twice, at δs = arcsin(Pm/Pmax) and at δu = 180° − δs. The first crossing is stable: if the rotor advances past δs, electrical output exceeds mechanical input and the rotor decelerates back. The second is unstable: a rotor carried past δu finds electrical output below mechanical input, keeps accelerating, and slips poles. The same sine law governs the power carried by a line between two buses, and Transmission and Distribution Lines uses it for line loadability, including the St. Clair curve and its 30 percent steady-state stability margin.
Synchronizing Power
The slope of the curve at the operating point is the synchronizing power coefficient, in per unit of power per electrical radian:
Ks = dPe/dδ = Pmax cos δs
A positive Ks pulls the rotor back after a small displacement. Heavier loading moves δs toward 90° and reduces Ks, and a weaker network, with a larger X and a lower Pmax, does the same. At δs = 90°, Ks reaches zero and no steady-state margin remains.
A solved power flow, found as Power Flow Analysis describes, supplies the starting point for any stability study. From a generator's terminal voltage Vt and current I, the internal voltage of the classical model is E′ = Vt + jX′dI, as the worked example shows.
Transient Stability and the Equal-Area Criterion
Transient stability concerns large disturbances, most often a short circuit on a transmission line that protection clears by opening the line. The event has three stages, each with its own power–angle curve. Let P1, P2, and P3 denote the peaks of the prefault, fault-on, and postfault curves.
- Before the fault, the machine runs at δ0 on the prefault curve, where P1 sin δ0 = Pm.
- During the fault, the transfer reactance rises, so the fault-on curve P2 sin δ lies well below the prefault curve; electrical output drops at once while mechanical input does not, and the rotor accelerates.
- After clearing, the machine moves onto the postfault curve, usually lower than the prefault one because a line is out of service. Where electrical output exceeds mechanical input, the rotor decelerates, but it keeps advancing until it has returned the kinetic energy it gained.
The Criterion
Multiply both sides of the swing equation by dδ/dt and integrate. Starting at synchronous speed at δ0, the rotor satisfies
(H / ωs) (dδ/dt)2 = ∫ (Pm − Pe) dδ, integrated from δ0 to δ
The left side is proportional to the kinetic energy of the rotor's motion relative to the synchronous reference, and the right side is a net area on the power–angle diagram. The rotor turns back where its speed deviation, and with it the net area, returns to zero. The system therefore survives the first swing if the decelerating area available above the Pm line on the postfault curve, up to δu, at least equals the accelerating area gained below that line before clearing. This equal-area criterion applies exactly to one machine against an infinite bus, or to two machines, under the assumptions of the classical model.
Critical Clearing Angle and Time
If the fault clears at the angle δc, the accelerating area is A1 = ∫ (Pm − P2 sin δ) dδ from δ0 to δc, and the largest decelerating area is A2 = ∫ (P3 sin δ − Pm) dδ from δc to δu, where δu = 180° − arcsin(Pm/P3). The critical clearing angle δcr makes the two equal. Evaluating the integrals, with angles in radians, gives
cos δcr = [Pm(δu − δ0) + P3 cos δu − P2 cos δ0] / (P3 − P2)
The result applies only when P3 > Pm, so that the postfault curve has an equilibrium. The textbook special case is an idealized temporary fault at the generator's high-voltage bus that removes all transfer while it lasts (P2 = 0) and clears without any change to the network (P3 = P1). Then δu = π − δ0 and Pm = P1 sin δ0, and the formula reduces to
δcr = arccos[(π − 2δ0) sin δ0 − cos δ0]
Protection engineers need a time rather than an angle. While Pe = 0, the rotor has the constant acceleration ωsPm/2H, so δ = δ0 + ωsPmt2/4H, and the critical clearing time is
tcr = √[4H(δcr − δ0) / (ωsPm)]
with angles in radians. This expression holds for any fault with P2 = 0, whether or not the postfault network matches the prefault one. When some power still flows during the fault (P2 > 0), the area formula still gives δcr, but finding the time at which the rotor reaches it requires integrating the swing equation numerically. Either way, H only rescales time in the classical model: δcr does not depend on H, and every critical clearing time grows with the square root of H.
Assumptions and Limits
- The criterion tests the first swing only. A system can survive the first swing and lose synchronism on a later one when controls or interacting machines feed energy into the oscillation.
- A constant E′ ignores both the decay of field flux and the field forcing of a fast excitation system, which raises the internal voltage during the fault and helps.
- Neglecting damping usually makes the first-swing result conservative.
- A system of many machines has no single power–angle diagram. Numerical integration of all the machine equations is the working method, and direct methods based on transient energy functions extend the area idea to many machines.
Comparing tcr with the actual clearing time of the protection, including the longer backup clearing when a breaker or relay fails, is the core of a transient stability check. Power System Protection describes the relays and breakers that set that time. The same area picture explains the usual remedies: faster clearing shrinks the accelerating area; single-pole tripping, additional lines, series capacitors, and fast excitation enlarge the decelerating area; and fast valving of steam turbines, braking resistors, and generator tripping schemes reduce the accelerating power.
Worked Example: A Generator on Two Parallel Lines
A 600 MVA, 60 Hz generator sends power to a large system, represented by an infinite bus at 1.0 pu, through a step-up transformer and two identical lines in parallel. The illustrative data are in per unit on the 600 MVA rating, and the calculations use the classical model with resistance and damping neglected.
| Quantity | Value |
|---|---|
| Inertia constant H | 4.0 s |
| Transient reactance X′d | 0.30 |
| Transformer reactance XT | 0.12 |
| Reactance of each line XL | 0.50 |
| Infinite-bus voltage V | 1.0 |
| Generator terminal voltage |Vt| | 1.0 |
| Power delivered, Pm = Pe | 0.90 (540 MW) |
The Prefault Operating Point
- The reactance from the generator terminals to the infinite bus is XT + XL/2 = 0.37. From P = |Vt|V sin θt / 0.37, the terminal voltage leads the infinite bus by θt = arcsin(0.90 × 0.37) = 19.45°, so Vt = 0.9429 + j0.3330 pu.
- The current is I = (Vt − V) / j0.37 = 0.9000 + j0.1543 pu, so the generator also supplies 0.154 pu of reactive power at its terminals.
- The internal voltage is E′ = Vt + j0.30I = 0.8967 + j0.6030 pu, or 1.0806 ej33.92° pu, so δ0 = 33.92°.
Three Networks
- Prefault. X1 = 0.30 + 0.12 + 0.25 = 0.67, so P1 = 1.0806/0.67 = 1.6128 pu. As a check, 1.6128 sin 33.92° = 0.900.
- Fault on. A bolted three-phase fault at the midpoint of line 2 leaves three branches at the high-voltage bus: 0.42 toward E′, 0.50 through line 1 toward the infinite bus, and 0.25 through half of line 2 to ground. Converting that wye into a delta gives the transfer reactance X2 = (0.42 × 0.50 + 0.50 × 0.25 + 0.25 × 0.42) / 0.25 = 1.76, so P2 = 0.6139 pu.
- Postfault. Breakers at both ends open line 2, leaving X3 = 0.30 + 0.12 + 0.50 = 0.92 and P3 = 1.1745 pu. This curve crosses Pm at δs = 50.02° and δu = 129.98°, or 2.2686 rad.
Clearing the Midpoint Fault
With δ0 = 0.5920 rad, the terms of the area formula are Pm(δu − δ0) = 1.5089, P3 cos δu = −0.7546, and P2 cos δ0 = 0.5095. Then
cos δcr = (1.5089 − 0.7546 − 0.5095) / (1.1745 − 0.6139) = 0.2448 / 0.5606 = 0.4367
so δcr = 64.11°, where both areas equal 0.2328. Integrating the fault-on swing equation numerically gives tcr = 0.2085 s, or 12.5 cycles. The rotor then runs 4.684 electrical rad/s, or 1.24 percent, above synchronous speed, and (H/ωs)(dδ/dt)2 = (4.0/377.0) × 4.6842 = 0.2328, the accelerating area, as the energy relation requires. Holding the initial acceleration of 26.27 rad/s2 constant would give 0.2003 s, slightly short, because the acceleration falls as P2 sin δ grows.
Swing Curves
| Time (s) | Cleared at 0.100 s | Cleared at 0.204 s | Cleared at 0.214 s |
|---|---|---|---|
| 0.0 | 33.9 | 33.9 | 33.9 |
| 0.1 | 41.3 | 41.3 | 41.3 |
| 0.2 | 56.5 | 61.9 | 61.9 |
| 0.3 | 69.7 | 85.7 | 86.9 |
| 0.4 | 77.7 | 102.6 | 105.2 |
| 0.5 | 79.1 | 113.0 | 117.2 |
| 0.6 | 73.7 | 118.3 | 125.3 |
| 0.8 | 47.3 | 118.6 | 139.1 |
| 1.0 | 26.2 | 103.5 | 169.9 |
Cleared at 0.100 s, the rotor peaks at 79.4° at 0.47 s and swings back to 25.9° at 1.02 s, an oscillation period of 1.11 s. Cleared at 0.204 s, just inside the critical time, it peaks at 120.1°, close to δu, and still returns. Cleared at 0.214 s, it passes δu at 0.67 s and slips poles until out-of-step protection separates it. Without damping in the model, the stable swings never decay; in a real machine, damper windings, load, and stabilizers damp them.
Fault Location and Inertia
| Fault and clearing | P2 (pu) | δcr (deg) | tcr (s) |
|---|---|---|---|
| Line 2 at its high-voltage-bus end, line 2 removed | 0 | 50.0 | 0.115 |
| One quarter along line 2, line 2 removed | 0.416 | 57.4 | 0.164 |
| Midpoint of line 2, line 2 removed | 0.614 | 64.1 | 0.209 |
| Three quarters along line 2, line 2 removed | 0.730 | 70.5 | 0.251 |
| Temporary fault at the high-voltage bus, prefault network restored | 0 | 74.8 | 0.183 |
The closer the fault lies to the generator, the less power gets through while it lasts and the shorter the critical time: a close-in fault that also costs a line leaves only 0.115 s, about 7 cycles. The last row follows from the closed-form expressions, δcr = arccos 0.2626 = 74.78° and tcr = 0.183 s, a longer time than for the close-in fault with the line removed because the prefault network returns.
Inertia acts through time, not angle. With H = 2, 3, 4, and 6 s, the midpoint fault has critical clearing times of 0.147, 0.181, 0.209, and 0.255 s, and the close-in fault 0.081, 0.100, 0.115, and 0.141 s. Both sets are exactly proportional to the square root of H. The 2021 stability paper makes the system-level point: lower total system inertia can produce larger and faster rotor swings.
Small-Signal Stability and Electromechanical Oscillations
Linearizing the Swing Equation
For a small deviation Δδ about δs, the electrical power changes by KsΔδ, and the swing equation with damping becomes linear:
(2H / ωs) d2Δδ/dt2 + (D / ωs) dΔδ/dt + KsΔδ = 0
Its undamped natural frequency is ωn = √(ωsKs / 2H) in rad/s, and its damping ratio is ζ = D / (4Hωn). In the worked example, the prefault operating point has Ks = 1.338 pu/rad, so ωn = √(377.0 × 1.338 / 8.0) = 7.94 rad/s, an oscillation of 1.26 Hz. After line 2 opens, the weaker network and the higher angle reduce Ks to 0.755 and the frequency to 0.95 Hz. The large swings of the simulation are slower still, 1.11 s per cycle, or 0.90 Hz, because the power–angle curve flattens at large angles.
Too little synchronizing power lets the angle drift away without oscillating, and too little damping lets an oscillation grow; in practice, small-disturbance rotor angle problems usually appear as poorly damped oscillations.
Eigenvalues, Mode Shapes, and Participation
A large system is linearized about its operating point into the state-space form dx/dt = Ax, with states for every machine, exciter, governor, and control. Each complex pair of eigenvalues λ = σ ± jω of A is an oscillatory mode with frequency f = ω/2π and damping ratio ζ = −σ / √(σ2 + ω2). A mode at λ = −0.20 ± j6.28, for example, oscillates at 1.00 Hz with a damping ratio of 0.032, or 3.2 percent. Oscillatory instability occurs when such a pair moves into the right half of the complex plane.
Eigenvectors give each mode's shape, the relative amplitude and phase of each machine's swing, and participation factors show which states, and so which machines and controls, influence a mode most. State-Space Analysis and Control develops eigenvalues, modes, and eigenvectors.
Local and Inter-Area Modes
The North American Electric Reliability Corporation (NERC) sorts natural power system oscillations into four types in its report Interconnection Oscillation Analysis (July 2019):
- Local: one plant or unit swinging against the rest of the system, generally caused by heavy loading and generator controls.
- Intra-plant: units within one plant swinging against each other.
- Inter-area: groups of machines in one area swinging against groups in another, often where the ties between areas are relatively weak.
- Torsional: subsynchronous oscillations from resonance between highly compensated lines and the mechanical modes of a steam turbine-generator.
Inter-area modes are slow because each end carries the inertia of many machines and the tie between them is weak. From recorded events in the three major North American interconnections, the report identified the dominant modes in the table, with average damping ratios from 9.26 to 16.45 percent. It treats damping above 10 percent as well damped, without calling lower damping poor, and leaves damping criteria to each reliability coordinator's system operating limit methodology.
| Interconnection | Mode shape | Frequency range (Hz) |
|---|---|---|
| Eastern | Northeast against south | 0.16–0.22 |
| Eastern | Northeast and northwest against south | 0.23–0.24 |
| Eastern | Northwest against south | 0.29–0.32 |
| Texas | North against southeast | 0.62–0.73 |
| Western | North–south | 0.24–0.27 |
| Western | North–south | 0.37–0.42 |
Against those figures, the worked example's 0.95 to 1.26 Hz is a local-mode frequency. The report also describes forced oscillations, sustained oscillations driven by external inputs such as equipment failures or control interactions; near the frequency of a natural mode, they can excite it across an interconnection. On June 17, 2016, a control valve malfunction at the Grand Gulf Nuclear Station in Mississippi drove a 200 MW oscillation near 0.27 Hz that excited an Eastern Interconnection mode, producing 40 MW swings on a tie line between New York and New England about 1,400 miles away.
When an Oscillation Breaks a System
The Western Interconnection breakup of August 10, 1996, summarized in NERC's 2019 report, shows how such a mode can end. During heavy transfers from Canada through the Pacific Northwest into California, erroneous relay operations removed all 13 generating units at McNary, and a poorly damped inter-area oscillation began and became negatively damped. When the swings reached about 1,000 MW and 60 kV peak to peak at the Malin 500 kV substation, voltage collapsed, and the interconnection separated into four islands.
Excitation Control and Power System Stabilizers
The excitation system affects rotor angle stability in two opposite ways. Fast field forcing during a fault raises the internal voltage and the synchronizing power, which improves transient stability. But a fast, high-gain voltage regulator also responds to the voltage swings that accompany rotor oscillations, and the field current it produces lags behind them; on a heavily loaded unit feeding a weak network, the resulting torque can oppose damping. F. P. de Mello and C. Concordia analyzed how excitation control changes synchronizing and damping torques in “Concepts of Synchronous Machine Stability as Affected by Excitation Control” (IEEE Transactions on Power Apparatus and Systems, April 1969).
Synchronizing and Damping Components
For small oscillations, the change in electrical power splits into a component in phase with the angle deviation and a component in phase with the speed deviation:
ΔPe = KsΔδ + KDΔω
Ks is the synchronizing coefficient and KD the damping coefficient. A voltage regulator contributes to both, and the phase lag of the exciter and field winding can make its contribution to KD negative.
How a Stabilizer Works
A power system stabilizer (PSS) adds a supplementary signal at the voltage regulator's summing point so that the excitation produces a component of electrical power in phase with speed deviation, which is pure damping. A typical design has four parts:
- An input that reflects rotor speed deviation: shaft speed, terminal frequency, electrical power, or a combination, such as dual-input designs that synthesize the integral of accelerating power from speed and electrical power.
- A washout, a high-pass filter that passes the oscillations but blocks steady offsets, so that the stabilizer does not fight slow changes in speed or voltage.
- Lead–lag phase compensation to offset the lag between the stabilizer output and the electrical power it produces, a lag introduced by the exciter, the field winding, and the network.
- A gain and output limits, with filters that keep shaft torsional frequencies in a speed signal from reaching the exciter.
Because the lag to be compensated varies with frequency, one stabilizer must provide useful phase compensation across the modes it should damp, from inter-area modes of a few tenths of a hertz to local modes near and above 1 Hz. IEEE Std 421.5-2016, IEEE Recommended Practice for Excitation System Models for Power System Stability Studies, gives standard stabilizer models along with its exciter models. Hydroelectric Power Electronics describes stabilizers, excitation systems, and governors in hydro plants, where dual-input designs avoid spurious output when gate movements change mechanical power.
Tuning and Placement
Engineers tune a stabilizer from the measured or computed frequency response of the generator, exciter, and network and confirm the settings with field tests, and participation factors show where stabilizers will most affect a poorly damped mode. Power oscillation damping controls on FACTS devices, such as static VAR compensators and STATCOMs, and on HVDC links also damp oscillations by modulating reactive or real power. The 2021 paper sees similar potential in supplemental controls on converter-interfaced generation, and it warns that displacing synchronous generators can remove machines whose stabilizers are crucial.
Frequency Stability After a Loss of Generation
Frequency stability is the ability of a power system to maintain steady frequency after a severe upset unbalances generation and load. Once the first electromechanical swings pass, frequency is nearly the same across a synchronous area, so studies can lump the machines together.
The Rate of Change of Frequency
Writing each machine's swing equation in megawatts with speed expressed as frequency, and summing over all synchronized machines, gives the relation for the frequency f of the center of inertia:
df/dt = f0 (Pm − Pe) / (2∑HiSi)
Here f0 is nominal frequency in hertz, Pm − Pe is the imbalance in megawatts, and ∑HiSi is the kinetic energy, in megawatt-seconds, of the machines still synchronized, each Hi on its own rating Si. A loss of generation makes the imbalance negative, so frequency falls. The relation gives the initial rate of change of frequency (RoCoF), before load relief and governors act; tripped units are left out of the sum, because their kinetic energy leaves with them. If a 60 Hz system loses 1,200 MW with 240 GW·s still synchronized, such as 60,000 MVA of machines at an average H of 4.0 s, the initial RoCoF is 60 × (−1,200) / (2 × 240,000) = −0.15 Hz/s.
Three Periods of Response
The 2021 paper illustrates three periods in the response of a system dominated by synchronous generators to a major loss of generation, with typical times taken from a 2013 IEEE Power & Energy Society report on turbine-governor models:
- Inertial response. Kinetic energy flows out of the rotating machines at once, with no control action, and the system inertia sets the initial slope of the decline.
- Primary frequency response. Governors open valves and gates in proportion to the frequency deviation, and frequency-sensitive load, such as motors, draws less power. Together they arrest the decline at the frequency nadir, typically 5 to 10 s after the event, and hold frequency at a settling value below nominal, typically reached 20 to 30 s after it.
- Automatic generation control. Secondary control changes generator setpoints to return frequency to nominal and restore scheduled interchange between areas, typically within 5 to 10 min.
Droop and Deadband
Droop is the per-unit frequency change that moves a unit across its full output range: in the example of the Federal Energy Regulatory Commission (FERC), 5 percent droop means that 3 Hz, 5 percent of 60 Hz, moves the prime mover's control from fully closed to fully open. In Order No. 842, issued February 15, 2018, FERC required newly interconnecting generating facilities, synchronous and non-synchronous, to have governors or equivalent controls with a maximum 5 percent droop, based on nameplate capacity, and a maximum deadband of ±0.036 Hz, the band of small deviations that draws no response. The order also requires a deadband without a step, so response starts from zero at its edge. With 5 percent droop, a 0.1 Hz fall on a 60 Hz system then raises a 100 MW unit's output by 100 × [(0.1 − 0.036)/60] / 0.05 = 2.1 MW, provided the unit has headroom to rise.
Once governors settle, the steady-state deviation depends on the load damping D, the per-unit change in load per per-unit change in frequency, and on the governors' combined 1/Reff, both on the system base:
Δf / f0 = −ΔP / (D + 1/Reff)
where ΔP is the lost generation in per unit.
An Illustrative Event
A lumped model shows how inertia and governors divide the work. Take the system above and assume, for illustration, D = 1 and governors at 5 percent droop with no deadband on 30 percent of the capacity, each responding with a first-order lag of 8 s, while the other units sit at their limits. The combined 1/Reff is 0.30/0.05 = 6, so frequency settles at −(1,200/60,000) / (1 + 6) × 60 = −0.171 Hz from nominal, a response of 700 MW per 0.1 Hz, the unit North American practice uses. At that frequency, load relief supplies 171 MW of the loss and the governors 1,029 MW.
| Average H (s) | Kinetic energy (GW·s) | Initial RoCoF (Hz/s) | Nadir (Hz) | Time of nadir (s) | Settling frequency (Hz) |
|---|---|---|---|---|---|
| 6.0 | 360 | −0.10 | 59.66 | 6.6 | 59.83 |
| 4.0 | 240 | −0.15 | 59.61 | 5.1 | 59.83 |
| 2.0 | 120 | −0.30 | 59.51 | 3.3 | 59.83 |
Halving the inertia doubles the initial RoCoF and deepens the nadir but leaves the settling frequency unchanged, because inertia stores energy and supplies none in steady state. Faster excursions, the 2021 paper notes, put more emphasis on fast-acting controllers that arrest frequency drops as soon as they are detected.
Operating Criteria and Inertia Limits
Commission Regulation (EU) 2017/1485, the EU guideline on electricity transmission system operation, sets the reference incident for continental Europe, the largest instantaneous imbalance for which frequency containment reserves are dimensioned, at 3,000 MW. For imbalances up to that size it sets a maximum instantaneous frequency deviation of 800 mHz and a maximum steady-state deviation of 200 mHz, and for deviations of 200 mHz or more it requires at least half of the full reserve within 15 s and all of it within 30 s.
ERCOT's white paper Inertia: Basic Concepts and Impacts on the ERCOT Grid also sets a floor on system inertia. Its critical inertia is the minimum at which load resources on under-frequency relays, set no lower than 59.7 Hz and responding in about 0.416 s, can act before frequency falls below 59.3 Hz, where under-frequency load shedding begins, after the simultaneous loss of its two largest units, 2,750 MW. Simulations put that level at 94 GW·s, which ERCOT raised to 100 GW·s for margin; its lowest inertia by then had been 130 GW·s, on October 27, 2017. If 100 GW·s remained synchronized after that loss, the relation above would give an initial RoCoF of 0.825 Hz/s.
Under-frequency load shedding is the last line of defense, disconnecting blocks of load in stages as frequency falls. Converter-interfaced generation provides no inherent inertial response, but the 2021 paper notes that it can deliver primary response faster and with smaller droop settings, since electronics rather than boilers limit its speed, and that battery storage can contribute decisively. Grid Synchronization and Control describes fast frequency response and synthetic inertia from converters.
Voltage Stability
Voltage stability is the ability of a power system to maintain steady voltages close to nominal at all buses after a disturbance. It depends on the ability of generation and transmission to supply the power that loads request, an ability limited by the maximum power transfer to a set of buses and by the voltage drops of power flowing through the inductive network. Voltage instability can cause a loss of load in an area, trip lines and other elements, and lead to cascading outages, and generators can lose synchronism along the way.
The Nose of the PV Curve
The mechanism appears in the simplest case: a source of fixed voltage Vs feeding a constant-power load P + jQ through a lossless reactance X. Solving for the load voltage V gives
V2 = [Vs2 − 2QX ± √((Vs2 − 2QX)2 − 4X2(P2 + Q2))] / 2
Below a maximum load there are two voltages for each load, a high one at which the system normally operates and a low one. Plotting V against P at constant power factor traces the PV curve, or nose curve, whose two branches meet at the tip where the square root vanishes. For a load of power factor cos φ, with φ positive for a lagging (inductive) load, the maximum power and the voltage at which it occurs are
Pmax = Vs2 cos φ / [2X(1 + sin φ)], at V = Vs / √[2(1 + sin φ)]
| Load power factor | Pmax (pu) | Voltage at Pmax (pu) | Voltage at P = 0.5 pu (pu) |
|---|---|---|---|
| 0.90 lagging | 0.627 | 0.590 | 0.798 |
| 0.95 lagging | 0.724 | 0.617 | 0.862 |
| 1.00 | 1.000 | 0.707 | 0.966 |
| 0.95 leading | 1.381 | 0.853 | 1.050 |
| 0.90 leading | 1.595 | 0.941 | 1.085 |
Reactive support, represented here by a leading power factor at the load bus, raises the maximum transfer, but it also raises the voltage at the nose: at 0.90 leading, the limit arrives at 0.94 pu, so a heavily compensated system can near collapse with voltages that still look acceptable. Near the nose, a small load increase causes a large voltage drop, and at the nose the power flow Jacobian becomes singular, as Power Flow Analysis shows along with the continuation power flow that locates the limit.
QV Curves and Reactive Reserves
A QV curve plots the reactive power that a fictitious synchronous condenser at a bus would have to supply to hold each voltage, with real loads fixed. The bus operates where the curve crosses zero, the bottom of the curve marks the voltage stability limit, and its depth below zero is the bus's reactive power margin. For the two-bus system with a load of 0.5 pu at 0.95 lagging, the curve crosses zero at 0.862 pu, matching the table, and reaches a minimum of −0.211 pu at 0.559 pu. The bus could therefore take on about 0.21 pu more reactive load, or lose that much reactive support, before no operating point remains.
In practice, reactive reserves are the capability of generators, synchronous condensers, static VAR compensators, and STATCOMs that remains after a contingency. Shunt capacitors help least when most needed, because their output falls with the square of voltage, and generators that reach their field or armature current limits further limit voltage support and the maximum transfer. Static VAR Compensators describes the fast-acting compensators.
Short-Term and Long-Term Mechanisms
Voltage stability is subdivided by the size of the disturbance and by time frame.
- Short-term voltage stability involves fast-acting loads and devices over several seconds: induction motors, electronically controlled loads, HVDC links, and inverter-based generators. In the typical case, induction motors slow during a fault and draw more current and reactive power; after clearing, a motor that has fallen below a critical speed stalls and draws starting current until protection disconnects it, holding voltage low and possibly stalling nearby motors in turn. HVDC links with line-commutated converters on weak AC systems can become voltage unstable within about a second; voltage-source converters have significantly raised those limits.
- Long-term voltage stability involves slower equipment over several minutes: tap-changing transformers, thermostatically controlled loads, and generator current limiters. It is usually set off not by a fault itself but by the outage of transmission or generation that follows it. Tap changers and thermostats restore load power after a voltage drop, and if the restored demand exceeds the maximum transfer of the weakened network, voltages decline progressively toward collapse.
Overvoltage instability has also occurred in a few cases: lines below their surge impedance loading, shunt capacitors, and HVDC filter banks can drive voltage up while underexcitation limiters keep generators and synchronous condensers from absorbing the excess reactive power.
Planners express long-term voltage stability as a margin, the load increase from the operating point to the maximum transfer, measured along a defined direction of stress: which loads grow, and which generators pick up the increase. Countermeasures include dynamic reactive reserves, fast switching of capacitors, blocking of tap changers during low-voltage emergencies, and undervoltage load shedding.
Resonance and Converter-Driven Stability
Resonance Stability
Resonance stability covers subsynchronous resonance in both of its forms. Torsional resonance exchanges energy between a series-compensated network and the torsional modes of a turbine-generator shaft, and its oscillations can be poorly damped or even growing, threatening the shaft. Electrical resonance, the induction generator effect, is a purely electrical self-excitation between a series capacitor and a machine that presents negative resistance at subsynchronous frequencies. According to the 2021 paper, it has never been observed with conventional synchronous generation, but wind turbines with doubly fed induction generators are susceptible: the first field event occurred in ERCOT in 2009, and similar events followed in the Xcel Energy network in Minnesota. Such events are called subsynchronous control interaction because the converter controls supply much of the negative damping. Fast controls on HVDC links, static VAR compensators, STATCOMs, and power system stabilizers can also interact with shaft torsional modes, although such interaction can improve torsional damping as well as degrade it.
Converter-Driven Stability
Converter-driven stability concerns oscillations that the controls of power electronic converters drive through their coupling with the network, with machines, and with each other. The 2021 paper divides it by frequency:
- Slow interaction, typically below 10 Hz, involves outer power and voltage loops and phase-locked loops interacting with slow system dynamics. It resembles voltage instability in that a weak connection limits power transfer, but converter controls rather than loads drive it. The paper reports that the phase-locked loop and inner current loop of a converter plant can become oscillatory below a short-circuit ratio typically between 1.5 and 2, depending on the vendor and the network, and that a high-gain phase-locked loop can inject current at the wrong phase angle during nearby faults on weak networks.
- Fast interaction, typically tens to hundreds of hertz and possibly into the kilohertz range, involves fast inner current loops interacting with the transmission network, filters, and other converters, a family that power electronics engineers call harmonic instability. Reported cases include oscillations between 500 Hz and 2 kHz in large wind plants connected through VSC HVDC links, and oscillations at 2.5 Hz and 97.5 Hz between a STATCOM and weak AC and DC grids in the China Southern Grid.
The paper lists remedies: lower gains in the phase-locked and current loops, supplemental controls, emerging control strategies, and equipment that strengthens the network, such as synchronous condensers. Grid-forming control, which regulates an internal voltage instead of injecting a current aligned by a phase-locked loop, is one such strategy. Grid-Forming Inverters explains its control laws and its own stability questions.
Converters also change rotor angle stability. The 2021 paper notes that they alter flows on major ties, displace large synchronous generators and their stabilizers, and can raise or lower the damping of nearby machines. It finds no general consensus on their net effect on electromechanical modes and reports that they can help or harm transient stability, depending on grid layout, location, and control.
Stability Studies and Tools
Time-Domain Simulation
Time-domain simulation is the workhorse of stability analysis. A program initializes every dynamic model from a solved power flow, applies a scripted sequence of events, such as a fault, its clearing, and generator tripping, and integrates the machine and control equations with the network equations, over seconds for angle stability and minutes for long-term voltage and frequency studies. Engineers judge the resulting swing curves, voltages, and frequencies against criteria for synchronism, damping, and voltage recovery.
RMS and Electromagnetic-Transient Models
Root-mean-square (RMS), or phasor, simulation represents the network by fundamental-frequency phasors, which makes it efficient enough for studies of whole interconnections. Electromagnetic-transient (EMT) simulation solves instantaneous voltages and currents with much shorter time steps and captures converter controls, harmonics, and switching. Co-simulation tools combine electromechanical and electromagnetic models when fast converter phenomena matter. The Power System Analysis overview describes programs of both kinds, such as PSS/E, PowerFactory, and PSCAD.
Other Methods
Eigenvalue analysis finds modes, damping ratios, and participation factors; energy-function methods estimate transient stability margins without full simulation; PV and QV analysis, often with continuation power flow, finds voltage stability margins; and synchrophasor measurements track modes and forced oscillations in real time.
Planning Criteria
In North America, NERC reliability standard TPL-001-5.1 requires transmission planners to show that the system remains stable, without cascading or uncontrolled islanding, for its planning events. Those events range from the loss of a single element to faults with stuck breakers or failed protection, which lengthen clearing times and so test critical clearing directly. Utilities validate the generator, exciter, governor, stabilizer, and inverter models behind such studies against recorded disturbances and field tests.
Summary
Power system stability is the ability to regain an operating equilibrium after a disturbance with practically the entire system intact. The 2004 IEEE/CIGRE classification separated rotor angle, voltage, and frequency stability, and the 2021 extension added resonance and converter-driven stability.
The swing equation, (2H/ωs) d2δ/dt2 = Pm − Pe, governs rotor angles, and the equal-area criterion turns it into critical clearing angles and times. In the worked example, a midpoint fault on one of two lines had to clear within 0.209 s and a close-in fault within 0.115 s, and each critical time scaled with the square root of H. Linearized for many machines, the swing equations yield local modes near and above 1 Hz and inter-area modes of a few tenths of a hertz, which stabilizers and damping controls must keep well damped.
Frequency stability rests on inertia in the first seconds, governors and load relief within tens of seconds, and automatic generation control over minutes, and falling inertia raises the rate of change of frequency. Voltage stability is bounded by the nose of the PV curve and by reactive reserves. Converter controls add interactions that phasor models often miss, so studies of modern grids increasingly add electromagnetic-transient simulation.