Abstract:To address the system vulnerability issue induced by strong cyber-physical coupling in smart substations, a wide-area critical node identification and risk assessment method tailored to time-sequence security scenarios is proposed. First, based on the IEC 61850 protocol stack object model and communication patterns, the core functional boundaries of typical messages, time-synchronization dependency mechanisms, and inherent vulnerability characteristics are analyzed. Second, given the unauthorized access threats in open protocols, substation network risk propagation paths and generalized trip-type disturbance patterns are proposed. Then, in response to the characteristics of state-sponsored attacks featuring wide-area incapacitation and link-layer stealth, a multi-site, stealth-infiltration-based concurrent precise time-synchronization disturbance method is proposed. Finally, based on the DC optimal power flow model and the sequential Monte Carlo method, a substation disturbance risk assessment framework is constructed. The proposed framework is validated through simulations on the IEEE-RTS79 test system. The results demonstrate that coordinated attacks targeting critical node combinations can induce severe system cascading failures. Compared with single-point attacks, coordinated attacks significantly increase the system load-loss risk, thereby validating the effectiveness of conducting multi-site disturbances using time synchronization protocols.