Microgrid Controller Architecture
The microgrid controller coordinates units, storage, and loads - but the critical safety and forming functions run locally.
Coordination above, autonomy below
A microgrid needs a controller to dispatch units, manage storage, and execute load priorities. But putting all intelligence in one central controller creates a single point of failure. The Aegis architecture splits the job: a supervisory controller optimises and coordinates, while the critical voltage-forming and protection functions run locally in each unit and can act without it.
The two tiers
The supervisory tier handles priority-based dispatch, state-of-charge management, load-priority enforcement, and connected/islanded mode changes. The local tier — in each unit's conditioning and protection — forms the bus, shares load by droop, and trips on fault, all without waiting for the supervisor. Lose the supervisor and the island keeps running on local control.
- Supervisory tier: dispatch, storage, mode changes
- Local tier: bus forming, droop sharing, protection
- Droop lets units share load with no central master
- Island survives loss of the controller network
Resilience and security together
This structure serves both resilience and cybersecurity: fewer critical functions depend on the network, so both a network failure and a network intrusion are less able to cause an outage. Local autonomy is the design's answer to the single-point-of-failure and attack-surface problems at once.
Described at concept level, the essential property is that coordination lives above the machines while forming and protecting live inside them, so a failure of the supervisor degrades optimisation but never removes power. This division also bounds the blast radius of a controller fault: the worst case is loss of optimisation and coordination, not loss of power, because the forming and protecting functions never left the units.