DS Blackstart Restoration Fundamentals
- DS blackstart restoration is a staged process that restores de-energized feeders using local DERs and grid-forming inverters to form stable microgrids.
- It employs advanced optimization methods and mixed-integer formulations to sequence feeder energization, load pickup, and microgrid synchronization.
- Robust control laws, transient simulation, and resilient communication strategies are critical for ensuring frequency security and safe load recovery.
Distribution system (DS) blackstart restoration is the process of re-energizing de-energized feeders and loads without support from the bulk transmission system by using local distributed energy resources (DERs), advanced inverters, storage, situational awareness, and distribution automation. In contrast to traditional top-down restoration, which starts from large plants and transmission infrastructure, DS blackstart adopts a bottom-up paradigm in which grid-forming inverters initialize local voltage and frequency references, form stable microgrids, energize cranking paths for grid-following inverters, and ultimately support interconnection into networked microgrids and resynchronization to the upstream grid once transmission recovers (Shi et al., 2 Oct 2025).
1. Operational scope and architectural structure
The contemporary DS blackstart literature treats restoration as a staged process of island formation, feeder energization, staged load pickup, feeder reconfiguration, microgrid interconnection, and eventual synchronization to the transmission grid. In DER-rich feeders, blackstart units increasingly take the form of battery energy storage system (BES)-based grid-forming inverters, while many non-blackstart resources are renewable grid-following inverters that require an energized bus and an established voltage-frequency reference before they can contribute power (Maharjan et al., 2024).
A recurring architectural abstraction is the use of “bus blocks” or feeder sections as restoration units. In the DER-aided restoration framework with synchronization and frequency security constraints, the IEEE-123-bus feeder is partitioned into 11 bus-blocks, and restoration decisions explicitly distinguish energizing switches from synchronizing switches (Maharjan et al., 2024). In the synchronization-safe dynamic microgrid formation framework, the underlying feeder is abstracted as a backbone graph whose vertices are bus blocks and whose edges are switchable lines; this permits dynamic microgrid boundaries while preserving radiality and tracking the number of islands through the number of slack buses (Bai et al., 17 Apr 2026).
The literature also distinguishes between single-step end-state restoration and explicitly sequential restoration. A single-step mixed-integer linear program can form optimal islands without heuristically pre-identifying reference buses and can coordinate multiple distributed generators within the same island through PV/PQ mode hierarchies (Singh et al., 2018). By contrast, sequential and rolling-horizon formulations model staged switching, staged load pickup, and time-coupled constraints such as cold load pickup (CLPU), state of charge, synchronization timing, and transmission-grid recovery (Zhang et al., 2021).
This division of scope is consequential. A single-step formulation is well suited to final topology selection and source assignment, whereas sequential formulations are designed to represent the actual restoration chronology: blackstart source initialization, energization of adjacent feeder sections, bringing grid-following DERs online after intentional delay, and safe merging of energized islands.
2. Blackstart resources, control laws, and dynamic security
The central technical distinction in DS blackstart is between grid-forming and grid-following resources. Grid-forming inverters exhibit voltage-source behavior, establish voltage and frequency references, share power via droop control, and may provide synthetic inertia via virtual synchronous machine or virtual synchronous generator control. Grid-following inverters exhibit current-source behavior, synchronize through a phase-locked loop to the grid-forming reference, and inject commanded active and reactive power once the microgrid is energized (Shi et al., 2 Oct 2025).
The basic steady-state control laws appear throughout the literature. The review on renewable-energy-based DS blackstart gives the active-power/frequency and reactive-power/voltage droops as
and the virtual synchronous machine swing-equation analog as
These relations are used to characterize bottom-up restoration with grid-forming inverters, energy storage, and renewable DERs (Shi et al., 2 Oct 2025).
The real-time EMT-TS feeder blackstart testbed refines this control picture by representing a 2 MVA battery energy storage system as a grid-forming voltage source converter with outer power/voltage regulation, inner current control, dq0 transformation, and virtual impedance
with frequency–active power droop
and voltage–reactive power droop
The same work recommends the voltage unbalance factor
for monitoring unbalance during blackstart (Paduani et al., 2021).
Frequency security has become a distinct design layer rather than an ex post validation step. In the DER-aided synchronization framework, virtual synchronous generator-based control is used to estimate quasi-steady-state frequency, rate-of-change-of-frequency, and nadir from only initial and final quasi-steady-state points, and the estimation is validated against DigSILENT RMS simulations with more than 92% estimation accuracy for RoCoF, nadir, and steady-state (Maharjan et al., 2024). In the stochastic black-start resource allocation framework, the same security concepts are expressed through three transient indices—maximum RoCoF, quasi-steady-state frequency, and frequency nadir—with limits
and are enforced across sixteen uncertainty scenarios (Bai et al., 18 Aug 2025).
A common misconception is that DS blackstart security can be reduced to steady-state voltage feasibility. The inverter-dominated restoration literature instead treats frequency nadir, RoCoF, and synchronization conditions as first-class constraints, especially when BES-based blackstart units have finite energy capacity and when grid-following DERs must be brought online in weak-grid conditions.
3. Restoration methodologies and optimization paradigms
The methodological core of DS blackstart restoration is a family of time-indexed mixed-integer formulations that co-optimize switch operations, microgrid formation, DER dispatch, and load pickup. The review paper surveys deterministic MILP and MINLP, robust optimization, stochastic programming, distributionally robust optimization, rolling-horizon model predictive control, Markov decision processes, dynamic programming, and reinforcement learning, all under radiality, voltage, thermal, reserve, and synchronization constraints (Shi et al., 2 Oct 2025).
A representative sequential formulation is the two-level simulation-assisted restoration model with frequency dynamics constraints. It uses a rolling-horizon MILP for topology and dispatch decisions, interfaces that MILP with transient simulation of inverter-dominated microgrids, and updates a maximum-load-step constraint according to the measured frequency nadir. On a modified IEEE 123-bus system with four islanded microgrids, the method restored 1773 kW after 5 stages, whereas the baseline without frequency dynamics constraints reached the same total only after 6 stages and exhibited unstable oscillation in the heaviest island during the first stage (Zhang et al., 2021).
A different direction is the model predictive black start framework with explicit inrush-current feasibility. That framework uses short-term forecasts of DER output and transmission-grid availability, formulates a receding-horizon MILP over bus blocks, then subjects proposed switch closures to an analytical transformer inrush model. The analytical model estimates peak inrush from residual flux, switching angle, and nodal impedance, and achieves estimation accuracies exceeding 90% against electromagnetic transient simulations in PowerFactory. When predicted inrush threatens fuse or recloser operation, the framework applies emergency-operation-inspired voltage reduction or a switch-blocking mechanism before re-solving (Bai et al., 16 Jul 2025).
Graph-based preprocessing has also been used to dimension the temporal horizon itself. In islanded microgrid restoration studies with graph-based analysis, the feeder is reduced into bus blocks and connected subgraphs, and conservative and generous step estimates are derived from eccentricity, radius, and diameter over blackstart vertices. On the modified IEEE 123-node feeder, the conservative and generous estimates were and , and a seven-step MILP achieved the highest restored load with an optimal solution time of approximately 168.5 s (Bassey et al., 2021).
At the opposite end of the centralization spectrum, multi-agent rolling optimization identifies communication-connected parts and solves a multi-time-interval restoration problem separately inside each part. In the modified IEEE 123-bus case, a 30-minute rescheduling gap restored approximately 1221.1 kW by 90 minutes, compared with approximately 1111.3 kW for a 45-minute gap, illustrating the operational value of frequent rescheduling under evolving communication and resource availability (Feng et al., 2018).
These formulations differ in state representation and solver structure, but they share a common operational sequence: select blackstart-capable sources, energize local buses, restore critical loads first, maintain radiality, stage non-critical load pickup, and merge microgrids only when security constraints are satisfied.
4. Modeling fidelity: unbalanced power flow, EMT–TS co-simulation, and transient limits
A major line of research addresses the mismatch between tractable restoration optimization and device-level transient fidelity. The real-time electromagnetic-transient and transient-stability architecture for feeder blackstart simulations explicitly partitions the problem into an EMT subsystem and a phasor subsystem. The EMT subsystem contains the grid-forming inverter/BESS, utility-scale PV, diesel generator, grounding transformer, PCC voltage measurement, and PLL; the phasor subsystem contains the unbalanced IEEE 123-node feeder, rooftop PV, shunt capacitor banks, voltage regulators, and ZIP loads. The EMT side acts as the slack bus for the overall island, while the feeder is reflected back into EMT as per-phase current sources (Paduani et al., 2021).
The coupling is phase-specific and unbalanced. Phase currents are exchanged from TS to EMT as per-phase sinusoidal waveforms, whereas phase voltages at the point of common coupling are exchanged from EMT to TS as phasors computed from a one-cycle window through Fourier integrals. The paper departs from linear time interpolation and adopts direct waveform reconstruction,
0
followed by a first-order low-pass filter with time constant equal to the EMT step, in order to avoid smoothing of transients (Paduani et al., 2021).
The resulting fidelity claims are specific. With identical network parameters and operating conditions in the EMT-only benchmark and the EMT–TS testbed, the steady-state nodal voltage magnitude error distribution is negligible, with max error 1 p.u. and interquartile range within 2 p.u. At the point of common coupling, the largest active and reactive power mismatches at peak load are 1.0 kW and 2.6 kVAR. For transient load steps, the max RMS voltage error is approximately 0.006 p.u. at about 50% of BESS rating and approximately 0.03 p.u. near rated loading (Paduani et al., 2021).
The same paper also delineates where hybrid phasor–EMT representations cease to be sufficient. Increasing the TS time step from 1 ms to 10 ms increases the maximum event propagation delay from about 2.1 ms to 20.1 ms, inducing point-on-wave drift and larger mismatch. Time interpolation smooths voltage and frequency transients and underestimates their magnitudes. For capacitor switching, worst-case peak energization at voltage peak produces 1.6 p.u. bus voltage in EMT, whereas EMT–TS with TS-side shunt capacitor modeling does not reproduce that peak. Multi-point coupling that relocates the capacitor into EMT restores fidelity for both currents and voltages (Paduani et al., 2021).
This evidence has become a practical modeling rule: keep the grid-forming BESS and fast transient devices in EMT, use TS for feeder-scale restoration logic, and selectively pull sensitive devices into EMT when local transient fidelity is required.
5. Communication resilience, observability, and decentralized coordination
A second major theme is that DS blackstart restoration is often constrained not by generation adequacy alone but by communication failures, loss of observability, and impaired feeder automation. The communication-interruption letter formalizes the post-disaster DS into known-state buses and branches, unknown-state buses and branches, and DG buses. It then infers the states of unobservable components through three mechanisms: power-flow determination from measured active and reactive power at observable ends, power-supply-path determination through path counting on adjacency matrices generated by the Floyd algorithm, and power-disturbance determination through controlled cut-off or pick-up operations whose effects are inferred from DG output changes (Zhong et al., 2024).
This framework imposes an explicit safety rule: buses without observability and power supply cannot be connected to DGs until communication is reestablished. The case study on the IEEE 37-node distribution system with three DGs reports three outcomes. Without restoration actions during communication interruptions, the total picked-up load is 3 MVA. Applying the inference algorithm and then picking up loads by the single-commodity-flow method increases the total picked-up load to 4 MVA. Attempting direct restoration through a spanning-tree search without topology inference yields only 5 MVA and causes DG2 and DG3 to overload and exit operation (Zhong et al., 2024).
Zhong et al. extend this cyber-physical coupling by restoring communication itself through software-defined networking. Their integrated model jointly allocates communication routes and physical switching actions so that the operation center regains connectivity to the terminal devices needed for DS automation. On the IEEE 33-node feeder, the integrated cyber-and-load-recovery model restores 23, then 26, then 29 electrified buses across three stages and increases load restoration from 1470 kW in the power-only benchmark and 1740 kW in the separated cyber-and-load benchmark to 2590, 2990, and finally 3200 kW (Zhong et al., 2024). The same idea appears in the drone-small-cell formulation: communication failure made 45 switches on 23 branches inoperable, but deploying 3 drone small cells increased restored load from 46.2 MW to 53.1 MW on the IEEE 33-node feeder (Zhang et al., 2022).
Decentralized coordination has been treated separately from communication recovery. In the multi-agent restoration model, each bus hosts an agent, average consensus identifies communication-connected parts, and each part solves its own restoration problem without centralized authority (Feng et al., 2018). In the large-scale distributed restoration framework, a relax–drive–polish non-convex ADMM solves switch status, DER scheduling, and load pickup across clusters, and the method is demonstrated on the IEEE 123-node and IEEE 8500-node feeders (Nejad et al., 2020).
A different privacy-preserving communication architecture appears in Grid Edge Intelligence-assisted black start. There, residential GEI devices do not share detailed asset information with the utility. They transmit only upper and lower flexibility bounds, and the utility sends dispatch signals that must lie within those bounds. The modified IEEE 123-bus study reports that restored load-hours before transmission-grid synchronization increase from 5.36 MWh at 15% GEI penetration to 6.44 MWh at 100% GEI penetration (Zheng et al., 18 Aug 2025).
Taken together, these results refute the assumption that DS blackstart is solely an electrical reconfiguration task. In communication-degraded settings, topology inference, SDN-assisted routing, drone-based feeder-automation recovery, distributed optimization, and privacy-preserving edge coordination all directly affect how much load can be restored and how safely that restoration can proceed.
6. Benchmarks, empirical performance, limitations, and research directions
Empirical evaluation across the literature is dominated by IEEE radial feeders, especially the IEEE 37-, 33-, 123-, and 8500-node systems, and by performance metrics such as restoration time, number of stages, served load, customer-hours, voltage deviation, frequency nadir, RoCoF, and computational time (Shi et al., 2 Oct 2025).
The DER-aided synchronization framework on the IEEE-123-bus feeder quantifies the value of explicit inter-microgrid synchronization. With two GFMIs and transmission-grid recovery at 12:00, the proposed method restores 23.67 MWh versus 23.33 MWh for the benchmark and reduces DS restoration time from 240 minutes to 225 minutes. With four GFMIs, the same transmission-grid recovery instant yields 23.96 MWh versus 22.64 MWh and reduces restoration time by 45 minutes, from 270 minutes to 225 minutes (Maharjan et al., 2024).
The stochastic black-start resource allocation framework validates dynamic formation of networked microgrids under sixteen uncertainty scenarios. On the modified IEEE 123-node feeder, the risk-averse allocation places BESS at buses 18, 62, and 98 with ratings 2.294 MW/3.942 MWh, 1.283 MW/2.471 MWh, and 2.222 MW/3.587 MWh, and places smart synchronizing switches at branches 6, 7, and 8. Across all scenarios, frequency nadirs lie within 9 Hz and maximum RoCoFs lie between 0 and 1 Hz/s (Bai et al., 18 Aug 2025).
The model predictive black start framework with inrush-current impacts restores all bus blocks by 10:00 and synchronizes to the transmission grid by 11:15 on the modified IEEE 123-node feeder. At 9:00, the predicted inrush at fuse F2 reaches 1362 A, above its two-cycle melting threshold of 1200 A, so voltage reduction is used to avoid misoperation. At 9:30, predicted recloser pickup above 2600 A causes the framework to block selected energizing switches. The same study reports BESS energy savings of approximately 76 kWh at bus 149 and 114 kWh at bus 98 over the 08:45–10:00 interval (Bai et al., 16 Jul 2025).
The newest synchronization-safe dynamic microgrid formation framework adds computational acceleration rather than new electrical constraints alone. On the modified IEEE 123-node feeder, its constraint-aware warm start achieves a 32.32% average speed-up in optimal solution time, while an oracle-solution warm start gives 55.78% (Bai et al., 17 Apr 2026).
The limitations are equally recurrent. Several communication-focused letters do not include AC power-flow verification, voltage and thermal operational constraints, explicit radiality enforcement, DER dispatch optimization, droop laws, synchronization procedures, or protection adaptation (Zhong et al., 2024). Linearized restoration models often ignore losses, omit explicit voltage-angle synchronism, or approximate synchronization through near-zero power flow at switch closure (Maharjan et al., 2024). Fast transient phenomena such as capacitor peak energization, protection operations involving sub-cycle dynamics, and transformer inrush remain fundamentally EMT-domain problems (Paduani et al., 2021). Rolling and predictive formulations still simplify uncertainty, inverter inner-loop dynamics, and communications latency (Zheng et al., 18 Aug 2025).
The surveyed research directions therefore converge on a recognizable agenda: embedding inverter transients and frequency constraints into restoration optimization, expanding situational awareness through AMI and 2PMUs, improving communication resilience and cybersecurity, scaling to city-scale DER-rich feeders, validating through hardware-in-the-loop and field trials, and formalizing grid-forming requirements through evolving standards such as IEEE 2800 and IEEE 1547 (Shi et al., 2 Oct 2025). This suggests that DS blackstart restoration is becoming a joint problem of inverter control, network optimization, synchronization logic, communication recovery, and real-time cyber-physical coordination rather than a feeder switching problem in isolation.