Methods and systems for authentication and authorization

By deploying a local computer system within the private network of wind turbines, authenticating and authorizing user access, and updating credentials and authorization lists as needed, the problems of hacking attacks and insufficient data security are solved, achieving higher security and autonomous maintenance.

CN114830166BActive Publication Date: 2025-11-21VESTAS WIND SYSTEMS AS
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202080087169.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-12-23
Filing Date
2020-12-16
Publication Date
2025-11-21
Estimated Expiration
2040-12-16

AI Technical Summary

Technical Problem

Existing technologies are insufficient to effectively prevent hacker attacks and unwanted access to the control systems of wind turbine private networks, and data security is inadequate.

Method used

Deploy a local computer system within the private network of the wind turbine to authenticate and authorize user access. Check access requests by querying local credentials and authorization lists, and update the central computer system as necessary to ensure that the transmission is initiated locally.

Benefits of technology

It improves data security, reduces the risk of hacker attacks and unwanted access, and enables local computer self-maintenance and protection of sensitive data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114830166B_ABST
    Figure CN114830166B_ABST
Patent Text Reader

Abstract

The present disclosure provides a method for authenticating and authorizing user access to components of a power plant within a private network comprising one or more wind turbine generators. The method comprises the step of providing at a local computer system in the private network credentials and an authorization list of identifiers and authenticators representing a plurality of users and corresponding access authorizations. The local computer is in direct communication with components of the power plant and is configured to receive access requests from users via computer interfaces in the components in the private network. The method comprises the step of checking whether the requested access can be granted by querying the credentials and authorization list, and in case the access can be granted, transmitting the grant from the local computer to the computer interfaces in the components, and in case the access cannot be granted, transmitting a request to update the credentials and authorization list at the local computer system from the local computer system to a central computer system outside the private network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to a method for authenticating and authorizing users to access components of a power plant within a private network. Background Technology

[0002] Wind turbines typically have different control systems operated by internal computer networks. Security and preventing hacking are important issues. Summary of the Invention

[0003] The purpose of embodiments of this disclosure is to provide an improved method for authenticating and authorizing user access to components.

[0004] In a first aspect, this disclosure provides a method for authenticating and authorizing users to access components of a renewable power plant within a private network comprising one or more wind turbine generators, wherein the method includes:

[0005] Identifiers and authentication tokens representing multiple users, as well as corresponding authorized credentials and authorization lists, are provided at a local computer system in the private network. The local computer system communicates directly with components of the power plant and is configured to receive access requests from users via computer interfaces in the components of the private network.

[0006] Check whether the requested access can be granted by querying credentials and the authorization list, and

[0007] Where access is permitted, data will be allowed to be transmitted from the local computer system to the computer interface within the component, and

[0008] If access is denied, a request to update the credentials and authorization list on the local computer system is transmitted from the local computer system to a central computer system outside the private network.

[0009] Because the local computer system is responsible for transmitting requests, it ensures that the transmission is initiated by the local computer system. Therefore, data security is improved, while the risk of hacking and unwanted access to power plants within private networks is greatly reduced, as all access, including unwanted access, can be denied.

[0010] Furthermore, local computer self-maintenance can be achieved; that is, the local computer can be maintained without external help and / or intervention. Therefore, all maintenance, including local computer updates, can be performed proactively by the local computer.

[0011] It is also possible to make relevant information from the central computer (such as credentials and authorization lists) available closer to the components that need that information; that is, available at the local computer.

[0012] Security can be further enhanced because sensitive data in the form of credentials and authorization lists can be protected on the local computer, rather than providing a high level of security at each component.

[0013] In one embodiment, the private network may include autonomous execution software configured to execute requests. The autonomous execution software may reside on a local computer.

[0014] Components of a power plant can be components of a wind turbine, sensors within a private network, a wind turbine controller, another subsystem of the wind turbine, a power plant controller, a local SCADA server, a weather mast (a measuring tower carrying measuring instruments with meteorological instruments) or components thereof, components of a control station within a private network, portable measuring devices temporarily located within a private network, or other components associated with the operation, maintenance, and monitoring of the power plant. These components can be those with restricted access, or those requiring authorization credentials.

[0015] Provide a local computer system within the private network, and provide a list of credentials representing multiple user IDs and corresponding authorizations on the local computer system. This list may include credentials for each component that requires authentication and / or authorization.

[0016] Credentials are used to control access to information or other resources. A “credential” is understood as a combination of a user identifier (such as an account or name) and an authentication token (such as a password, biometrics (fingerprint, voice recognition, retinal scan), X.509, public key certificates, etc.). In one embodiment, an identifier may be associated with multiple authentication tokens.

[0017] "Authentication" is understood as the process of ensuring that a user is who they say they are; that is, comparing the access qualification statement (the provided credentials) with a local copy of the credentials.

[0018] "Authorization" is understood as the process of establishing a list of functions a user can perform on a given system and / or specific datasets for which access is granted. For example, if a user wants to perform an administrator-type task on a system, they can be authorized to do so. Depending on the control scheme associated with a particular organization, this may require approval from the system owner. Once authorized, the user can access the system and perform administrative functions. Furthermore, in some systems, a user may only be able to read (view) certain subsets of data; that is, authorization may apply to both functionality and data (functionality: read / update access; data: the assigned case).

[0019] The local computer system communicates directly with the components of the power plant and is configured to receive access requests from users via computer interfaces in the components within a private network.

[0020] "Private network" is understood to be common in the art, and in particular to be a network in which restrictions are established to promote a secure environment, such that devices outside the private network cannot access it except via a selected, strictly defined subset of devices. A private network is understood to inherently include multiple devices (such as processors, computers, servers, and / or clients) interconnected within the private network.

[0021] "Power plant" is understood in the context of common usage, and particularly as an entity capable of producing electricity, such as capable of (rated) producing at least 0.1 megawatts (MW), such as at least 1.0 MW, such as at least 10 MW. A power plant includes one or more wind turbine generators (where wind turbine generators may be abbreviated as "WTG" and are used interchangeably with "wind turbine" as commonly known in the art), such as one or more horizontal axis wind turbines, each optionally having a rated power of at least 0.1 MW, and in this case may be referred to as a wind farm (WPP). Where a wind farm comprises multiple wind turbines, it may be referred to as a wind farm or wind power plant.

[0022] When a user wants to access a component (such as logging into the component), the local computer system receives the access request from the user via the computer interface in the component within the private network. The local computer system checks whether the requested access can be granted by querying credentials and an authorized list. If access is granted, the local computer system will allow the request to be sent to the computer interface in the component, thereby logging the user into the component.

[0023] If access is not permitted based on the actual state of the local credentials and authorization list, the local computer system will send a request to update the credentials and authorization list on the local computer system to the central computer system outside the private network.

[0024] The central computer system may include a central list of identifiers and authentication tokens representing multiple users, along with corresponding authorizations. This central list can be updated with new users and associated credentials and authorizations, and / or with new credentials and / or authorizations for existing users. Updates to the central list at the central computer system can be scheduled, such as weekly, daily, every six hours, every two hours, hourly, twice an hour, every five minutes, or even more frequently. Alternatively, the central list can be updated whenever a new user is created and / or whenever authorization credentials change, thus ensuring that the central list is always up-to-date or at least substantially always up-to-date. It should be understood that server downtime, maintenance, and updates to the central computer system may restrict access to and updates to the central computer system.

[0025] This method may include the step of updating the list of credentials and authorizations on the local computer system in response to a request from the local computer to the central computer system. Therefore, when the local computer system requests an update, the update can be delivered to the local computer system, and the list of credentials and authorizations on the local computer system can be updated. To improve security, it can be ensured that only credentials related to a specific private network are delivered in response to a request.

[0026] In one embodiment, the steps of updating credentials and the authorization list can take effect only upon request from the local computer system. Since the local computer system is responsible for transmitting the request, this ensures that the transmission is initiated by the local computer system. Therefore, the local computer system can obtain the updates itself, rather than relying on updates forwarded unsolicited. This improves data security while significantly reducing the risk of hacking and unauthorized access to the power plant within the private network.

[0027] After the update, the process of checking whether the requested access can be granted can be performed by querying the updated list of licenses on the local computer system. If authorization is granted when querying the updated list of licenses and credentials, the local computer system will allow the transfer to the computer interface in the component.

[0028] This method may include a step of denying access if the requested access cannot be granted by querying an updated list of authorization credentials. Thus, the user seeking access (such as logging into a component of a power plant) will not be logged in. Therefore, since the user is not yet authorized to log into the specific component, login is not allowed, and as an example, the user will receive a message stating that access has been denied.

[0029] This method may include further steps such as requesting updates to the list of authorized credentials from the local computer system to the central computer system according to a schedule. This could be weekly, daily, every six hours, every two hours, hourly, twice an hour, every ten minutes, or even more frequently. When updates are requested periodically, the list of credentials and authorizations at the local computer system can be made to include the most up-to-date credentials and authorizations most of the time. This minimizes the risk of downtime due to failures associated with transmitting requests for updated credentials and authorizations from the local computer system to the central computer system, such as in the event of a communication breakdown.

[0030] In one embodiment, a central computer system may be configured to communicate with multiple local computer systems, each provided within a private network of a separate renewable power plant. The central computer system may include credentials and authorizations for each of the multiple local computer systems. The step of transmitting a request to update the list of credentials and authorizations at a specific local computer system may include filtering the credentials at the central computer system to include only those for the specific private network. Therefore, it can be ensured that only credentials related to the specific private network are transmitted to the local computer systems in response to a request.

[0031] In one embodiment, a single local computer system, located within a private network, can be configured to handle access to all restricted components of the renewable power plant. Therefore, the step of requesting authorization via the computer interface within a component can be routed to this single local computer system within the private network, configured to handle access to all restricted components of the renewable power plant. This limits the risk of hacking because a single local computer system would require a high level of security protection for stored credentials and authorizations, rather than having to protect multiple distributed local computer systems (each communicating with a subset of components within the private network).

[0032] The central computer system can be contained within a second private network in an external data center. The process of transmitting requests from the local computer system to the central computer system can be performed, at least in part, via a public network. As an example, this could be done via a VPN tunnel.

[0033] The method may include further steps of validating the updated list of credentials and authorizations. The validity testing step may include checking that the updated list of authorization credentials is in the correct format and has not been corrupted or tampered with. This is typically done by comparing the encrypted checksum of the transmitted data generated at the central computer system with a checksum calculated at the local computer system using the same method. The validity testing step may additionally or alternatively include checking whether the updated credentials and authorizations were received from the central computer system; that is, verifying the authenticity of the sender by confirming that the sender of the credentials and authorizations is indeed the sender of the sender mentioned above.

[0034] In a second aspect, this disclosure provides a system comprising:

[0035] - A power plant, the power plant comprising:

[0036] - One or more wind turbine generators, and

[0037] -Private network,

[0038] - Local computer systems located within the private network, and

[0039] -A central computer system located outside the private network,

[0040] The system is configured to perform the method according to the first aspect of this disclosure.

[0041] In a third aspect, this disclosure provides a computer program product including instructions for causing a system according to a second aspect to perform the steps of the method according to a first aspect.

[0042] The first, second, and third aspects of this disclosure may each be combined with any of the other aspects. These and other aspects of the invention will become apparent from the embodiments described below and will be elucidated with reference to the embodiments described below. Attached Figure Description

[0043] The method, corresponding system, and computer program product for authorizing users to access components of a power plant within a private network of a power plant, according to the present disclosure, will now be described in more detail with reference to the accompanying drawings. The drawings illustrate one mode of implementing the present disclosure and should not be construed as limiting other possible embodiments falling within the scope of the appended claims.

[0044] Figure 1 The illustration shows a wind turbine.

[0045] Figure 2 An embodiment of a system according to one aspect of this disclosure is illustrated, and

[0046] Figure 3 This is a flowchart illustrating a method for authorizing users to access components of a power plant within a private network. Detailed Implementation

[0047] It should be understood that the detailed description is given by way of illustration only, as various changes and modifications within the spirit and scope of this disclosure will become apparent to those skilled in the art from the detailed description.

[0048] Figure 1A wind turbine 100 (also referred to as a wind turbine generator (WTG)) is shown, comprising a tower 101 and a rotor 102 having at least one rotor blade 103 (such as three blades). The rotor is connected to a nacelle 104, which is mounted on top of the tower 101 and adapted to drive a generator located within the nacelle. The rotor 102 can be rotated by the action of wind. The wind-induced rotational energy of the rotor blades 103 is transferred to the generator via a shaft. Thus, the wind turbine 100 is able to convert the kinetic energy of the wind into mechanical energy by means of the rotor blades, and subsequently into electrical energy by means of the generator. The generator may include a power converter for converting alternating current (AC) to direct current (DC) and a power inverter for converting DC to AC for injection into the public power grid. The generator is controllable to produce power corresponding to a power request. The blades 103 can be pitched to change the aerodynamic characteristics of the blades, for example, to maximize the absorption of wind energy and to ensure that the rotor blades are not subjected to excessive loads during strong winds. The blades are pitched by a pitch system, which has a pitch force system controlled by a pitch control system, wherein the pitch force system includes actuators for pitching the blades in response to pitch requests from the pitch control system. The wind turbine can be an asset of a (wind) power plant, and parts of the wind turbine (such as one or more actuators for pitching the blades) can similarly be considered (sub)assets of both the wind turbine and the power plant.

[0049] Figure 2 The diagram illustrates a system 220 including a power plant 222, wherein the power plant 222 includes one or more wind turbine generators. Figure 2 Not shown in the image, see [link / reference]. Figure 1 The power plant 222 includes multiple components 226, 228, some of which are separate components and some of which form parts of a wind turbine. In the illustrated embodiment, the components are exemplified by component A 226 and component B 228, where component A 226 may be a controller in the wind turbine. Multiple wind turbines may each include a controller. As an example, component B 228 may be a local SCADA server of the power plant 222, a computer in a weather mast, or a power plant controller.

[0050] Local computer system 230 is located within private network 224, while central computer system 232 is located outside the private network. In the illustrated embodiment, the central computer system is located within a second private network 234.

[0051] System 220 is configured to perform method 350 for authenticating and authorizing users to access components 226, 228 within private network 224.

[0052] The local computer system 230 communicates directly with components 226 and 228 of the power plant 222 and is configured to receive access requests from users via computer interfaces (not shown) in components 226 and 228 of the private network 224. The access request is indicated by arrow 221.

[0053] The local computer system 230 checks whether the requested access can be granted by querying the credential list 223, and if access can be granted, grants permission from the local computer system 230 to the computer interfaces in components 226 and 228. This permission may include authorization for component-specific functions.

[0054] If access is denied, a request to update the credentials and authorization list at local computer system 230 is transmitted from local computer system 230 to central computer system 232 outside private network 224. In the illustrated embodiment, the step of transmitting the request from local computer system 230 to central computer system 232 is performed in part via a public network 235 in the form of a VPN tunnel 236. Public network 235 may be the Internet. The update request is indicated by arrows 231A and 231B. Since local computer system 230 is responsible for transmitting requests 231A and 231B, it is ensured that the transmission is initiated by local computer system 230. Therefore, data security is improved, while the risk of hacking and unwanted access to the power plant 222 in private network 224 is greatly reduced, because all access, including unwanted access, can be denied.

[0055] Central computer system 232 can access identifiers and authentication tokens representing multiple users, as well as corresponding authorized central credentials and authorization lists 237. The central list 237 is stored in central memory 238. Other computers in or outside system 220 can access central computer 232 and are able to update the central credential and authorization list 237. Central computer system 232 can be configured to verify the contents of the credential list. The identifiers and authentication tokens representing multiple users, as well as the corresponding authorized credentials and authorizations 237, may have expiration data associated with those identifiers.

[0056] Central computer system 232 can be configured to communicate with multiple local computer systems 230, each provided within a private network 224 of a separate renewable power plant. Central computer system 232 can include credentials and authorizations 237 for each of the multiple local computer systems 230. When a request to update the list of credentials and authorizations 223 at a specific local computer system 230 is transmitted, the credentials and authorizations 237 at central computer system 232 can be filtered, so that only the credentials and authorizations 223 for the specific private network are passed to the local computer systems 230. Therefore, the local list 223 is smaller than the central list 237. This results in high security even if the local private network 224 is compromised, because only the specific credentials and authorizations 223 for the specific power plant 222 are compromised.

[0057] Security is further enhanced because sensitive data in the form of credentials and authorization lists 223 is protected at the local computer 230, rather than at each component 226, 228 where a high level of security is provided.

[0058] Figure 3 This is a flowchart illustrating a method 350 for authenticating and authorizing user access to components 226, 228 of a renewable power plant 222 within a private network 224 comprising one or more wind turbine generators, and wherein method 350 includes:

[0059] A list of credentials representing multiple users’ identifiers and authentication tokens, along with corresponding authorizations, is provided at the local computer system 230 in the private network 224. The local computer system 230 communicates directly with components 226 and 228 of the power plant 222 and is configured to receive access requests 354 from users via computer interfaces in components 226 and 228 of the private network 224.

[0060] Check whether 356 can grant the requested access by querying the credentials and authorization list, and

[0061] If 358 access is permitted, then 360 will be allowed to be transmitted from the local computer system to the computer interface in the component, and

[0062] If authorization cannot be granted at 362, a request to update the credentials and authorization list at local computer system 230 will be transmitted from local computer system 230 to central computer system 232 outside private network 224.

[0063] After updating the local computer system 230, the system checks whether the requested authorization can be granted by querying the updated list of authorization credentials 223 on the local computer system. If authorization can be granted when querying the updated credential and authorization list 223, the local computer system 230 will grant permission to transmit to the computer interfaces in components 226 and 228.

[0064] If the requested authorization cannot be granted by querying the updated credentials and authorization list 223, access can be denied. Alternatively, a new request to update the credentials and authorization list at the local computer system 230 can be transmitted from the local computer system 230 to the central computer system 232. If the requested access still cannot be granted by querying the updated credentials and authorization list 223, access can be denied. Alternatively, a third request to update the credentials and authorization list can be transmitted. As an example, two or three requests to update the credentials and authorization list 223 at the local computer system can be transmitted before denying access.

Claims

1. A method for authenticating and authorizing user access to components of a renewable power plant within a private network comprising one or more wind turbine generators, wherein, The method includes: Identifiers and authentication tokens representing multiple users, as well as corresponding authorized credentials and authorization lists, are provided at a local computer system in the private network. The local computer system communicates directly with components of the power plant and is configured to receive access requests from users via computer interfaces in the components of the private network. The requested access is checked by querying the credentials and authorization list, and... Where access is permitted, data transfer from the local computer system to the computer interface in the component will be allowed, and If access is denied, a request to update the credentials and authorization list at the local computer system will be transmitted from the local computer system to a central computer system outside the private network. The step of updating the credentials and authorization list can only take effect upon request from the local computer system.

2. The method of claim 1, further comprising the steps of updating a list of credentials and authorizations at the local computer system in response to a request from the local computer to the central computer system, and checking whether the requested access can be permitted by querying the updated list of credentials and authorizations.

3. The method according to claim 2, wherein, Access is denied if the requested access cannot be granted by querying the updated credentials and authorization list.

4. The method of claim 1, further comprising the step of requesting an update of the credentials and authorization list from the local computer system to the central computer system according to a schedule.

5. The method according to claim 1, wherein, The central computer system is configured to communicate with multiple local computer systems, each provided in a private network of a separate renewable power plant. The central computer system includes credentials and authorizations for each of the multiple local computer systems. The step of transmitting a request to update the list of credentials and authorizations at a particular local computer system includes filtering the credentials at the central computer system to include only credentials for the particular private network.

6. The method according to claim 1, wherein, The step of requesting access via the computer interface in the component is transmitted to a single local computer system in the private network, which is configured to handle access to all access-restricted components of the renewable power plant.

7. The method according to claim 1, wherein, The central computer system is contained within a second private network in an external data center.

8. The method according to claim 1, wherein, The step of transmitting a request from the local computer system to the central computer system is performed at least in part via a public network.

9. The method of claim 2, further comprising the step of performing a validity test on the updated credentials and authorization list.

10. A system for authentication and authorization, the system comprising: - A power plant, the power plant comprising: - One or more wind turbine generators, and -Private network, - Local computer systems located within the private network, and -A central computer system located outside the private network, The system is configured to perform the method according to any one of claims 1-9.

11. A computer program product comprising instructions for causing the system of claim 10 to perform the steps of the method according to any one of claims 1-9.

Citation Information

Patent Citations

  • Method for user management and a power plant control system thereof for a power plant system

    CN103984295A