Method for providing authentication data of a user to an energy-transforming device and energy-transforming device - Patents.com
The method addresses the challenge of secure user authentication in energy conversion devices by requiring users to disconnect the device from the grid within a preset time window to update authentication data, ensuring security and user presence.
Patent Information
- Application Number
- JP2023516516
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-04-21
- Filing Date
- 2022-04-08
- Publication Date
- 2025-05-19
- Estimated Expiration
- 2042-04-08
AI Technical Summary
Existing methods for user authentication in energy conversion devices, such as inverters, lack a secure and user-friendly mechanism for updating authentication data, particularly when users lose or forget their credentials, or when unauthorized access occurs.
A method that allows users to request and store new authentication data in an energy conversion device by disconnecting the device from the grid within a preset time window, ensuring the user is physically present and enhancing security against unauthorized access.
This method provides a secure and user-friendly way to update authentication data, ensuring that only authorized users can access the energy conversion device while preventing unauthorized access, even during temporary power outages.
Smart Images

Figure 0007679460000001 
Figure 0007679460000002 
Figure 0007679460000003
Abstract
Description
Technical Field
[0001] The present invention relates to a method for defining user authentication data for an energy conversion device connected to a grid and a source via a network connection. The present invention further relates to an energy conversion device configured to execute the method, in particular an energy conversion device in the form of an inverter.
Background Art
[0002] User access to an energy conversion device, in particular an inverter, via a network connection is a widespread function and is often required for operation and maintenance. The user authentication data required during an access attempt is stored in the energy conversion device for this purpose, in order to authenticate the user, for example the device owner or service technician. It may be, for example, a password with which the user can log in to the energy conversion device.
[0003] For example, document US2011 / 0184575A1 describes a method in which the supply of power in a connection within a smart grid is carried out in response to the successful authentication of a user or device. Further, document JP2008-108022A describes a management system protected from abuse for maintaining a device, by which a service technician registers in advance, specifies a maintenance plan, and acquires individual components of the maintenance plan during maintenance via URLs respectively assigned to the components of this maintenance plan.
[0004] By the way, when a user loses or forgets authentication data, or when an unauthorized third party obtains information on the authentication data, the user may lose access rights to the energy conversion device, or an unauthorized third party may gain access to the energy conversion device. For this reason, there is a need to provide a method for the user to send new authentication data to the energy conversion device so that the authentication data can be accepted in subsequent access attempts. Such a method is intended to be easily executable by the user alone, but at the same time, it satisfies security requirements to prevent unauthorized users from abusing this method. For example, it is also intended to enable the user to store their authentication data on the energy conversion device and use the data in subsequent access attempts, or to block unauthorized users from the energy conversion device.
Summary of the Invention
[0005] Therefore, an object of the present invention is to show a method for defining a user's authentication data for an energy conversion device that is easy to execute but protected from abuse, and an energy conversion device configured to be able to define a user's authentication data by such a method.
[0006] This object is achieved by a method having the features of claim 1 and an energy conversion device having the features of claim 13. Preferred embodiments are described in the claims that depend on those claims.
[0007] In a first aspect of the present invention, a method for defining a user's authentication data for an energy conversion device connected to a grid and a source via a network connection is - a step in which the energy conversion device receives a request from the user to newly assign authentication data via the network connection; - a step in which the energy conversion device receives the user's desired authentication data via the network connection; - Only when the energy conversion device is disconnected from the grid to which it is connected within a first preset time window after receiving a request, a step of permanently storing desired authentication data in the energy conversion device for user authentication during subsequent attempts to access the energy conversion device is provided.
[0008] A request from the user to newly assign authentication data and / or desired authentication data can include information related to the identity of the user. At the completion of the method, the user can later log in as an authorized user to the energy conversion device with the permanently stored authentication data. The authentication data can include, for example, a password, a certificate, or a token generated by the user.
[0009] The method is preferably executed by a communication processor of the energy conversion device that manages the network connection of the energy conversion device. The communication processor can preferably receive power supply from the grid and the source as needed for this purpose, so that sufficient supply of the communication processor can be ensured even while the energy conversion device is disconnected from the grid. It is also conceivable to temporarily supply power to the communication processor by an energy source incorporated in the energy conversion device, such as a battery, while it is disconnected from the grid and / or the source.
[0010] By associating the permanent storage of desired authentication data in an energy conversion device with disconnecting the energy conversion device from a connected grid within a preset time window, it can be ensured that when a user sends a request to newly assign authentication data to the energy conversion device, the user must stay in the immediate vicinity of the energy conversion device. Otherwise, the user cannot deliberately disconnect the energy conversion device from the connected grid within the preset time window. When the user is in the immediate vicinity of the energy conversion device, the user can send a request to newly assign authentication data via a mobile data device such as a smartphone or a laptop. Thereafter, the user manually disconnects the energy conversion device from the connected grid, for example, by operating a disconnect switch or by cutting a fuse.
[0011] To prevent an unauthorized user from accidentally succeeding in a request to newly assign authentication data due to a temporary power outage, it can be additionally required that the energy conversion device be reconnected to the grid within a second time window with respect to the time point of disconnecting the energy conversion device from the connected grid. The second time window can preferably be preset to start, for example, 10 seconds after the energy conversion device is disconnected from the connected grid for this purpose. Furthermore, the duration of the second time window can be limited to, for example, a duration of 20 seconds or less. This ensures that unauthorized users cannot succeed in saving authentication data even if a randomly occurring short power outage, usually less than 10 seconds, or a long power outage exceeding 30 seconds occurs. Since it is almost impossible to deliberately cause a power outage starting within the preset first time window and having a duration defined by the second time window from a remote location, such abuse of this method can generally be eliminated.
[0012] However, to permanently store the desired authentication data, it may be sufficient to simply disconnect the energy conversion device from the connected grid and leave the energy conversion device disconnected from the grid until the permanent storage is performed.
[0013] To facilitate the user to perform disconnection of the energy conversion device from the grid or reconnection of the energy conversion device to the grid within the first time window, the energy conversion device can notify the start and / or end of the first time window. This type of notification can be performed visually or audibly. Then, the user can manually activate the disconnection element, typically a disconnection switch or fuse, within the indicated period. If the energy conversion device notifies the start and / or end of the first time window in any case, the start and / or end of the time window can also be randomly selected within a preset value range. This further prevents the abuse of the method.
[0014] To enable the user to easily select the correct time for reconnecting the energy conversion device to the grid, the start and end of the second time window can be similarly indicated visually or audibly.
[0015] In an advantageous aspect, before disconnecting the energy conversion device from the connected grid, it is possible to receive the desired authentication data, especially together with a request to newly assign the authentication data. In this case, the desired authentication data is permanently stored immediately after disconnecting or reconnecting the energy conversion device to the grid.
[0016] In a further advantageous aspect, it can be stipulated that, in order to permanently store the desired authentication data in the energy conversion device, after disconnecting the energy conversion device from the connected grid, the desired authentication data must be received within a third preset time window. The start of this time window can be associated with the time of disconnection or reconnection of the energy conversion device from the grid, coincide with either of those times, or occur after a preset duration. In order to further enhance the security of this method against abuse in this aspect, it is possible to stipulate that the third preset time window ends at the latest 10 minutes after the energy conversion device is disconnected from the grid.
[0017] In order to further prevent the possibility of unauthorized use of this method by unauthorized users, it can be stipulated that if the communication processor of the energy conversion device involved in the execution of this method is restarted within the first time window, this method ends and the received desired authentication data is discarded.
[0018] To enhance the security of this method against abuse, it is further possible and appropriate to record in the energy conversion device the number of consecutive received events including a request to newly assign authentication data that did not result in the permanent storage of the desired authentication data in the energy conversion device, i.e., also count the number of unsuccessful requests. Permanently storing the desired authentication data in the energy conversion device is blocked permanently or for a predetermined period if the number of times exceeds a maximum number. This maximum number can be specified, for example, as 2 or 3. However, in order to prevent the possibility of a legitimate user being permanently blocked by an unauthorized unsuccessful attempt, it is recommended to block this method only for a preset period.
[0019] To monitor the network connection of an energy conversion device, it is possible to report to the portal from the energy conversion device via the network connection a received event that includes a request to newly assign authentication data. Also, it is possible to report whether each request has succeeded in permanently storing the desired authentication data in the energy conversion device or has remained a failure. In this way, unauthorized attempts can be quickly detected and appropriate countermeasures against this type of security threat can be initiated.
[0020] In a further aspect of the present invention, the energy conversion device is configured to execute the method described above. The energy conversion device can be an inverter, and the source can be a DC power source, particularly a battery or a photovoltaic generator. The energy conversion device is preferably configured to be powered from the source while disconnected from the grid. However, it is also conceivable to provide a dedicated energy source within the energy conversion device to power the communication processor, and this source ensures the power supply to the communication processor during disconnection of the energy conversion device from the grid and / or during disconnection from the source in the described method.
[0021] Since an energy conversion device connected to the grid usually has a sensor system that enables it to monitor the active connection to the grid in some way, additional hardware is usually not required for the energy conversion device to be able to execute this method. For example, adaptation of communication software executable on a communication processor that manages the network connection of the energy conversion device is often sufficient. This makes the method according to the present invention attractive also in terms of cost.
[0022] In one aspect of the present invention that is not currently claimed, it is also possible to replace or supplement the check for disconnection from the connected grid by a check that determines whether an operating sensor of the energy conversion device has been activated within a first preset time window. An operating sensor of this type can be a switch or button of the energy conversion device. It is particularly advantageous to implement the operating sensor as a knocking sensor, and the knocking of the energy conversion device can be used for the permanent storage of desired authentication data. Thereby, wear of the disconnection element for disconnecting the energy conversion device from the grid can be avoided. In this case, in the energy conversion device connected to the grid and the source via a network connection, the method for defining the user's authentication data is - a step in which the energy conversion device receives a request from the user for newly allocating authentication data via a network connection; - a step in which the energy conversion device receives the desired authentication data of the user via a network connection; - permanently storing the desired authentication data in the energy conversion device for user authentication during subsequent attempts to access the energy conversion device, only if an operating sensor of the energy conversion device, particularly a knock sensor, is activated within a first preset time window after receiving the request.
[0023] Further embodiments disclosed in the description of the method according to the present invention can likewise be used in aspects of the method.
Brief Description of the Drawings
[0024] Hereinafter, the present invention will be described in detail with reference to the drawings.
Figure 1
Figure 2
Figure 3
Embodiments for Carrying Out the Invention
[0025] Figure 1 shows a flowchart of a first embodiment of the method according to the present invention. This method starts from a first step S1 (ST), in which a request from a user who newly assigns authentication data is received by the conversion device via a network connection. In response to receiving the request, the energy conversion device can invalidate the user's previous authentication data permanently or for a preset period, and this action can also be performed according to whether the previous execution of this method has failed. This action can also be performed according to how long ago the last successful execution of this method was for this user or for general users. However, in order to prevent the improper blocking of authorized users, the previous user data can also be kept valid.
[0026] In the subsequent second step S2, the energy conversion device receives the desired authentication data of the user via the network connection. The first step S1 and the second step S2 can be continuously executed in separate communication procedures or together in one communication procedure.
[0027] In the third step S3, a check is performed to determine whether the energy conversion device has been disconnected from the connected grid within a first preset time window. Optionally, in the third step S3, an additional check can also be performed to determine whether reconnection to the grid has also occurred within the first time window. The first time window starts either immediately after the request is received or after a preset period. A second time window within the first time window defines the allowable period for disconnecting the energy conversion device from the connected grid, and that period is set to a minimum of 10 seconds and a maximum of 30 seconds. The start of the first time window, and optionally also the end of the second time window, can be indicated by the energy conversion device, for example, in an audible or visual format. Thereby, the user present at the energy conversion device can easily manually perform disconnecting the energy conversion device from the grid within the first time window to confirm the request for newly allocating authentication data.
[0028] Only if the check in the third step S3 ends with a positive result, that is, only if the disconnection of the energy conversion device from the connected grid and optionally the reconnection to the grid have occurred within the first time window, the desired authentication data is permanently stored in the energy conversion device in the fourth step S4 instead of the user's previous authentication data to authenticate the user during subsequent attempts to access the energy conversion device. Thereafter, the method ends (EN).
[0029] If the result of the check in the third step S3 is negative, the method ends (AB).
[0030] The successful result and / or end of the method can be indicated visually or audibly in an appropriate manner by the energy conversion device.
[0031] Figure 2 shows a flowchart of a second embodiment of the method according to the present invention. The second embodiment differs from the first embodiment of the method according to the present invention in that the energy conversion device receives the user's desired authentication data in the second step S2 only after the execution of the check in the third step S3 is successful. A third time window, which can be started immediately after the successful end of the check in step S3, is provided for receiving the desired authentication data. The duration of the third time window is set to a length such that an authorized user can easily transmit the desired authentication data to the energy conversion device within the time window. The time window can continue for, for example, 1 to 10 minutes.
[0032] The result of the check in step S3 with a positive result causes the energy conversion device to be temporarily switched to a state where the desired authentication data can be received and permanently stored within the energy conversion device for use in future access attempts by the user. In the fourth step S4, the received valid authentication data is permanently stored in the energy conversion device and the method ends (EN). If no valid authentication data is received within the third time window, the method ends by continuing to use the previous authentication data (EN).
[0033] If the check in step S3 ends with a negative result, all of the received user's desired authentication data is ignored and the method ends (AB).
[0034] In connection with the notification of the start and / or end of the first time window described in relation to the first design, the energy conversion device can further, in the second design, visually or auditorily notify the start and / or end of the second time window, and further the start and / or end of the third time window. Furthermore, the successful result of the method with persistent storage of the desired authentication data and / or the end of the method without persistent storage can be indicated visually or auditorily. This makes it easier for the user to timely transmit the desired authentication data to the energy conversion device via the network connection and receive notification that the new assignment of the authentication data has been successfully completed.
[0035] A series of events in time sequence for successfully executing the method according to the present invention is accurately shown in FIG. 3, where time is plotted on the X-axis and the state of the connection of the energy conversion device to the grid is plotted on the Y-axis. The connection of the energy conversion device to the grid is represented by the value 1, and the disconnection from the grid is represented by the value 0. At time point t 0 the energy conversion device receives a request from the user to newly assign authentication data. As a result, from time point t 1 to time point t 7 a first time window A is defined, and in order to enable the new assignment of the authentication data, within that time, it is necessary to disconnect the energy conversion device from the grid and, optionally, reconnect. Time point t 1 occurs after a preset duration, for example 10 seconds, from time point t 0 but it is also possible to make it the same as time point t 0 . Time point t 7 can occur 20 minutes after time point t 0 (or time point t 1 ).
[0036] In the illustrated case, the disconnection from the grid actually occurs at time point t 2 . As a result, a second time window B starts at time point t 3 and ends at time point t 5It is defined to end at, and in order to enable a new allocation of authentication data, it is necessary to reconnect the energy conversion device to the grid within that time. Time point t 3 is the time point t 2 Occurs after a preset duration from, for example, 10 seconds later. After that, time point t 5 is, for example, time point t 2 (or time point t 3 ) can occur 30 seconds later.
[0037] In the illustrated case, the reconnection to the grid is actually performed at time point t 4 . As a result, the third time window C is defined to start at time point t 4 and end at time point t 6 . In order to enable a new allocation of authentication data, within that time, the desired authentication data of the user needs to be received by the energy conversion device. After that, time point t 6 is, for example, time point t 4 (or time point t 2 ) can occur 2 minutes later.
[0038] If one of the necessary events, namely, the disconnection of the energy conversion device from the grid, the reconnection to the grid, and the reception of the desired authentication data, is not performed within the corresponding time windows A, B, C, then the desired authentication data will not be permanently stored in the energy conversion device for the user's authentication during subsequent access attempts.
[0039] In the first embodiment of this method, since the authentication data has actually already been received by the energy conversion device before the energy conversion device is disconnected from the connected grid, it is not necessary to receive the desired authentication data within time window C.
[0040] The start and end of time windows A and B can be indicated by the energy conversion device, preferably in visually or audibly distinguishable forms from each other. The completion of the storage of the desired authentication data can also be indicated in an audible or visual form.
[0041] The method according to the present invention can be supplemented by further means well known to those skilled in the art, for example, by encrypted transmission of data between the user and the energy conversion device, two-factor authentication, or similar means, to enhance security against abuse.
Claims
1. 1. A method for defining authentication data of a user in an energy conversion device connected to a grid and a source via a network connection, the method comprising: - receiving (S1) a request for new allocation of authentication data from a user via said network connection; - receiving (S2) by said energy-transforming device via said network connection desired authentication data of a user; - persistently storing (S4) the desired authentication data in the energy conversion device for authentication of the user during subsequent attempts to access the energy conversion device only if the energy conversion device is disconnected from the grid to which it is connected within a first preset time window (A) after receiving the request (S3).
2. 10. The method of claim 1 , 11. The method according to claim 1, further comprising the step of: receiving (S2) the desired authentication data before the energy conversion device is disconnected from the grid to which it is connected in order to achieve persistent storage of the desired authentication data in the energy conversion device.
3. 10. The method of claim 1 , The method according to claim 1, characterized in that in order to achieve persistent storage of the desired authentication data in the energy transforming device, the desired authentication data must be received (S2) within a third preset time window (C) after the energy transforming device is disconnected from the grid to which it is connected.
4. 4. The method of claim 3, The method, characterized in that the third preset time window (C) ends after a preset duration, in particular at the latest 10 minutes, after the energy conversion device is disconnected from the grid to which it is connected.
5. The method according to any one of claims 1 to 4, wherein, in order to effect a persistent storage (S4) of the desired authentication data in the energy transforming device within the first pre-defined time window (A), it is also necessary to reconnect the energy transforming device to the connected grid within a second time window (B) relative to a time when the energy transforming device is disconnected from the connected grid.
6. 6. The method of claim 5, 4. The method of claim 3, wherein the second time window (B) begins at the earliest 10 seconds after the energy conversion device is disconnected from the grid to which it is connected.
7. 6. The method of claim 5, The method of claim 1, wherein the second time window (B) has a duration of 20 seconds or less.
8. The method according to any one of claims 1 to 4, 11. A method according to claim 10, characterized in that the first pre-defined time window (A) ends at the latest 20 minutes after receiving a request for new allocation of authentication data in the energy-transforming device.
9. The method according to any one of claims 1 to 4, 13. A method according to claim 12, characterized in that the energy-transforming device signals the start and end of the first time window (A) and / or the second time window (B).
10. The method according to any one of claims 1 to 4, A method characterized in that if a communication processor of an energy-transforming device involved in the execution of the method is rebooted, the method is terminated and the received desired authentication data is discarded.
11. The method according to any one of claims 1 to 4, A method according to claim 1, characterized in that in the energy conversion device, a number of consecutive received events, including requests for newly allocating authentication data, which have not resulted in the desired authentication data being permanently stored in the energy conversion device, is identified, and if said number exceeds a maximum number, persistent storage (S4) of the desired authentication data in the energy conversion device is prevented permanently or for a pre-defined period of time.
12. The method according to any one of claims 1 to 4, A method comprising: identifying a received event including a request for new allocation of authentication data that did not result in the desired authentication data being persistently stored in the energy-converting device; and reporting the received event by the energy-converting device to a portal via the network connection.
13. An energy-transforming device adapted to carry out the method according to any one of claims 1 to 4.
14. 14. The energy-transforming device according to claim 13, 10. An energy conversion device, characterized in that it is realized as an inverter and said source is a direct current source, in particular a battery or a photovoltaic generator.
15. 14. The energy-transforming device according to claim 13, 13. An energy conversion device configured to be powered by the source during disconnection from the grid.
Citation Information
Patent Citations
Systems and methods for operating a commercial power grid
JP2019534675A
Automatic service registration in a communications network
JP2020533676A
Universal smart energy transformer module
US20170285081A1
A distributed power outlet power monitoring system
WO2017124142A1