Distributed configuration management and incident response in an energy delivery system
A hierarchical configuration management system with local and central components addresses scalability and cybersecurity issues in energy distribution networks, enabling rapid detection and response to unauthorized IED configurations, ensuring timely system recovery and reducing failure risks.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- EATON INTELLIGENT POWER LTD
- Filing Date
- 2026-01-14
- Publication Date
- 2026-07-23
AI Technical Summary
Energy distribution networks face challenges in managing and updating a large number of Intelligent Electronic Devices (IEDs) due to tedious processes, resource intensity, and lack of cybersecurity, leading to potential catastrophic consequences from unauthorized configuration manipulations, and existing CM technologies lack scalability and timely detection of such incidents.
A hierarchical configuration management system with local Subsystem CMs and a Central CM, employing mutual authentication and continuous polling of hash values to detect unauthorized changes, enabling fast response and resilient reconfiguration.
Enhances scalability and efficiency in configuration management, allowing for rapid detection and response to unauthorized manipulations, reducing the risk of catastrophic failures and ensuring timely system recovery.
Smart Images

Figure IB2026050322_23072026_PF_FP_ABST
Abstract
Description
Attorney Docket No.: 15720.2005WOU1Distributed Configuration Management and Incident Response in an Energy Delivery SystemRelated Application
[0001] This application claims priority to U.S. Provisional Patent Application No.63 / 745,153, filed January 14, 2025, the disclosure of which is incorporated herein by reference in its entirety.Technical Field
[0002] The present disclosure relates generally to an energy delivery system, and more particularly to distribution configuration management and incident response in an energy delivery automation system.Background
[0003] Energy delivery systems, such as, electric power grids are one of the most critical infrastructures for modern societies. Essential services such as defense installations, transportation, water supply, school, city halls, and airports all rely on a steady supply of energy. The requirements of increased demand and higher reliability are burdening an already overtaxed energy distribution networks. In order to meet these needs, ever larger numbers of Intelligent Electronic Devices (lEDs) and edge gateways are being installed throughout energy distribution networks.
[0004] Typically, these lED's are highly configured and tailored / customized to the specific applications and functional requirements. Updating and managing a large number of lEDs can be a very tedious, time consuming and resource intensive, i.e. expensive, process, requiring highly skilled personnel. Especially if the distribution network runs an expansive operation and / or fails to keep track of the different IED configurations that are already in place. In addition, due to the lack of cybersecurity measures, particularly advanced authentication in the legacy lEDs, role-based access control, and active traffic filtering in a typical field network an adversary with the knowledge of IED credentials (e.g., a disgruntled employee) can inject manipulatedAttorney Docket No.: 15720.2005WOU1configurations into the lEDs. A stealthily manipulated configuration, if persists long, can potentially result in catastrophic consequences including loss of life, business, and / or trust through hidden failure mechanism. Configuration management tools are not fast enough to detect and eliminate such manipulations in a timely manner.Brief Description of the Drawings
[0005] Aspects of the present disclosure are best understood from the following detailed description when read with the accompanying figures. It is noted that, in accordance with the standard practice in the industry, various features are not drawn to scale. In fact, the dimensions of the various features may be arbitrarily increased or reduced for clarity of discussion.
[0006] FIG. 1 illustrates an example Energy Delivery System (EDS) architecture.
[0007] FIG. 2 illustrates an Intelligent Electronic Device (FED) deployment and reconfiguration process in a EDS.
[0008] FIG. 3 illustrates a configuration lookup table for a EDS.
[0009] FIG. 4 illustrates a monitoring process for lEDs of a EDS.
[0010] FIGS. 5-12 illustrate flow diagrams of methods for enhancing resilience of a EDS.
[0011] FIG. 13 is a diagram of a computing device.Detailed Description
[0012] In the following Detailed Description, reference is made to the accompanying drawings, which form a part hereof, and in which is shown by way of illustration specific embodiments in which the invention may be practiced. In this regard, directional terminology, such as top, bottom, front, back, etc., is used with reference to the orientation of the Figure(s) being described. Because components of embodiments can be positioned in a number of different orientations, the directional terminology is used for purposes of illustration and is in no way limiting. It is to beAttorney Docket No.: 15720.2005WOU1understood that other embodiments may be utilized and structural or logical changes may be made without departing from the scope of the present invention. The following detailed description, therefore, is not to be taken in a limiting sense.
[0013] Secure configuration management and resilient response orchestration in an Energy Distribution System (EDS) is provided. An EDS (sometimes also referred to as a Distributed Energy Delivery Automation System (DEDAS)) includes multiple networked Intelligent Electronic Devices (lEDs), for example, sensors, controllers, actuators, protective relays, etc. These lEDs are remotely configurable to accommodate various modes of operation of infrastructure, for example, an electrical distribution grid topology and asset composition. Managing configurations of such a multitude of lEDs, including their deployment, reconfiguration, runtime monitoring, or access control, is challenging. The disclosure provides an automated Configuration Manager (CM) that employs a hierarchical scheme to achieve scalability and enables fast detection of unauthorized configuration manipulation followed by a resilient response orchestration and system recovery after an event has occurred.
[0014] Majority of the existing CM technologies for EDS lack scalability since they employ a central agent to sequentially poll lEDs to retrieve their operational configuration. In case of a large EDS (for example, one having thousands of lEDs), a single polling cycle through the entire fleet of lEDs is time-consuming and demands a large network bandwidth. As a result, the frequency of polling cycles in such applications may not exceed a few times a day, rendering real time monitoring difficult. Additionally, handling configuration changes due to variability in the system operation conditions (e.g., variability introduced by Distributed Energy Resources (DERs) in EDS) are becoming challenging. Moreover, enforcement of a configuration update can be prolonged since several lEDs often share a common configuration.
[0015] As more and more smart devices are being deployed, EDS is facing a burgeoning level of cyber threats and incidents. The existing legacy lEDs as well as many of the modern ones, due to economic reasons, lack the security level desired today. To be able to manipulate an lED’s configuration, often an adversary or a rogue agent may only need knowledge of its credentials, which are prone to be compromisedAttorney Docket No.: 15720.2005WOU1since those may be shared among multiple operators or using defaults (particularly in environments not subject to the North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) requirements). Also, due to lack of advanced authentication in the legacy lEDs and the absence of active traffic filtering in a typical field network, an adversary with the knowledge of IED credentials (e.g., a disgruntled employee) can inject manipulated configurations into the lEDs. A stealthily manipulated configuration, if it persists long, can potentially result in catastrophic consequences including electrical failures, loss of life, business, and / or trust. The existing CMs tools are not fast enough to be able to detect and eliminate such manipulations in a large EDS in a timely manner.
[0016] For operational resilience, an EDS may need to adapt in the face of cyber incidents since the functionalities of directly impacted subsystems may be compromised. The existing CMs may not be capable of orchestrating a resilient incident response through automated reconfiguration of the unimpacted lEDs. Consequently, adaptation following an incident is often manual, potentially causing a prolonged reduced level of performance or a complete failure. The operation of the directly impacted subsystems is commonly prohibited until a root cause is identified, which often takes a long time, for example, several days (if not weeks), further aggravating the issue.
[0017] A CM in an EDS traditionally performs the following key functions: (i) deployment of new lEDs and their reconfiguration, (ii) maintaining a database of EDS-wide IED configurations and monitoring the current state of IED configurations, and (iii) maintaining an operator’s database and implement role-based access control. The processes disclosed herein enhances a state-of-the-art of CM by enhancing scalability and communication efficiency. In addition, the processes disclosed herein integrate automated fast unauthorized manipulation detection and response orchestration capabilities.
[0018] FIG. 1 illustrates an example EDS 100 in accordance with embodiments of the present disclosure. EDS 100 provides a highly scalable and flexible hierarchical CM architecture. As shown in FIG. 1, EDS 100 may include a Central CM (CCM) 102 and a plurality of systems, for example, a first system 104i, ..., and an Mth systemAttorney Docket No.: 15720.2005WOU1104M. Each of the plurality of systems may represent a portion of an energy distribution system, for example, a substation of an electric power grid, a power plant, or a microgrid.
[0019] Each of the plurality of systems may include a plurality of subsystems. That is, first system 104i may include a first plurality of subsystems, for example, first subsystem IO61.1, ..., and a Nth subsystem 106I.N. Similarly, Mth system 104M may include a Mth plurality of subsystems, for example, first subsystem 106M.I, ..., and a Nth subsystem 106M.N. Although, each of the plurality of systems are shown to include a same number of subsystems, they may include a different number of subsystems.
[0020] Each of the plurality of subsystems of each of the plurality of systems may include one or more lEDs. That is, first subsystem IO61.1 of first system 104i may include a plurality of lEDs, for example, a first IED IO81.1.1, ..., and IO81.1.P. Similarly, Nth subsystem 106I.N of first system 104i may include a plurality of lEDs, that is, a first IED 108I.N I, ..., and 108I.N.P. Moreover, first subsystem IO61.1 of Mth system 104M may include a plurality of IED s, for example, a first IED 108M.I.I, ... , and 108M. I.P. Finally, Nth subsystem 106M.N of Mth system 104M may include a plurality of lEDs, that is, a first IED 108M.N.I, ..., and 108M.N.P. Although, each of the plurality of subsystems are shown to include a same number of lEDs, each may include a different number of lEDs. Each of the plurality of lEDs in a subsystem may be connected to a network, for example, a Local Area Network (LAN) or a Virtual LAN (VLAN).
[0021] Moreover, each of the plurality of subsystems may be associated with or include a Subsystem CM (SCM) (also referred to a as a proxy CM or an edge CM) and a traffic monitor for the VLAN. For example, and as shown in FIG. 1, first subsystem IO61.1 of first system 104i may include a SCM IIO1.1 and a traffic monitor 112i.i. Similarly, Nth subsystem 106I.N of first system 104i may include a SCM I IOI.N and a traffic monitor 112I.N. Moreover, first subsystem 106M.I of Mth system 104M may include a SCM I IOM.I and a traffic monitor 112M.I. Finally, Nth subsystem 106M.N of Mth system 104M may include a SCM I IOM.N and a traffic monitor 112M.N. In some examples, the traffic monitors may be a network traffic controller, for example, a Software defined Network (SDN), a Layer 3 (L3), or a L2 switch.Attorney Docket No.: 15720.2005WOU1
[0022] Thus, EDS 100 may be viewed as a network of a plurality of systems (for example, substations, DER plants, or microgrids) in general, where each system may logically include a plurality of subsystems (e.g., a collection of bays in a substation), interchangeably referred as EDS edges, each of which include a set of lEDs and local monitoring agents (that is, a SCM and a traffic monitor). In addition, each subsystem is equipped with a dedicated VLAN, the traffic through which is monitored by a first local agent (that is, a traffic monitor) to detect any standard rule-based anomaly, and a second local agent (that is, a SCM) that is responsible for managing configurations of the local lEDs.
[0023] SCMs are capable of blocking a network traffic within their respective VLANs. In addition, SCMs within a system may mutually authenticate each other and communicate their current state and other signals. In addition, each SCM may retrieve from each IED within its VLAN either a hash value of a configuration (if the IED supports this feature) or a full configuration with all parameters along with their current values. CCM 102 is a central agent that establishes a mutually authenticated communication link with each SCM across the plurality of systems to maintain a snapshot of the current EDS-wide configuration state of lEDs. In some examples, implementation of the mutual authentications may be performed using a public key distribution mechanism.
[0024] The set of lEDs for each subsystem can be automatically determined by CCM 102 or manually allotted by a system administrator. In some examples, the set of lEDs for each subsystem are determined based on geographical proximity or functionality they are assigned to perform. For example, all lEDs in a substation can be part of one subsystem. In another example, all of the circuit breakers in a substation can be part of a subsystem.
[0025] As discussed in greater details in the following sections of the disclosure, the continuous polling of the IED configurations to monitor their state is performed by SCMs, as opposed to CCM 102, thereby minimizing the volume of traffic to / from CCM 102. Any unauthorized manipulation detected by a SCM is reported to CCM 102 eliminating the need of continuous polling by CCM 102. Moreover, the ability of a SCM to poll a hash value of the IED configurations as an alternate to the fullAttorney Docket No.: 15720.2005WOU1configuration helps to reduce the polling cycle time and network bandwidth requirement within the subsystems. The overall speed of configuration monitoring and efficiency depends on the number of subsystems within each system, which can be decided by the end user depending on the need and budget availability. The above features embellish EDS 100 with high scalability and implementational flexibility.
[0026] In EDS 100, a new IED may be deployed manually and a configuration change for the new / existing IED may be invoked either manually or automatically. FIG. 2 illustrates an IED deployment and reconfiguration process 200. At stage 202 of process 200, a local operator can initiate deployment of a new IED or reconfiguration of an existing IED in first subsystem IO61.1 of first system 104i. The local operator for example, may login through a Human Machine Interface (HMI) associated with SCM IIO1.1 of first subsystem IO61.1 of first system 104i. After logging in at stage 202, process 200 proceeds to stage 204 where the local operator can use multi-factor authentication to authenticate with SCM 1 IO1.1. Once having been authenticated at stage 206, process 200 proceeds to stage 206 where the local operator may enter a target lED’s user credentials. Target IED user credentials may include identifying information of the target IED, for example, a name, a number, a location, etc.
[0027] At stage 208 of process 200, the local operator may specify if the target IED is a new IED that is being deployed first subsystem IO61.1 of first system 104i. If a new IED is being deployed or added to first subsystem IO61.1 of first system 104i, a local configuration database is updated to include details of the new IED. The details may include new IED user credentials and its configurations. As discussed in greater detail with respect to FIG. 3, configurations may include a golden configuration (also referred to as a desired configuration) and one or more emergency mode configurations. The local configuration database may be stored in a local database 210 accessible to SCM 1 IO1.1. At stage 212 of process 200, the new IED is deployed (if applicable). In addition, a desired configuration is uploaded in the target IED. For example, if a new IED is not being deployed then stage 208 may be skipped and, at stage 212, a desired configuration may be uploaded in the target IED (that is, an existing IED) to update its configuration.Attorney Docket No.: 15720.2005WOU1
[0028] Thus, the local operator can, using an HMI of SCM 1 IO1.1, add a new IED in or update a configuration of an existing IED of first subsystem IO61.1 of first system 104i. In examples, each local operator of an IED or of a subsystem along with a rolebased access information (for example, whether permitted to reconfigure) is registered by an administrator either through CCM 102 or through a local SCM (that is, SCM IIO1.1). For manual IED deployment and reconfiguration, the authorized local operator may use the HMI that is accessible through the multi-factor authentication. Any manual reconfiguration performed from anywhere else in the network other than this HMI is regarded as unauthorized and may automatically be reversed by SCM 1 lOi.i. In addition, whenever a new IED is deployed, the local operator can optionally upload its emergency mode configurations, in addition to the normal configuration that may be used for deployment. As discussed in greater detail with respect to FIG.3, each emergency mode of an IED may uniquely correspond to the compromised state of one of the other lEDs in EDS 100. The compromised state of each IED may correspond to an emergency state of one or more other lEDs. Thus, the disclosed framework allows enforcement of sophisticated preventive and mitigative security policies even in presence of legacy lEDs.
[0029] In some examples, SCM 1 IO1.1 may also process a compromised IED configuration. An automated reconfiguration may also be invoked by a SCM if an lED’s configuration is compromised, and a corresponding emergency mode configuration is available. For example, at stage 214 of process 200, SCM 1 IO1.1 may determine that a local IED is compromised. The local IED may be compromised when its configuration is altered from a desirable or intended configuration. A process to determine a compromised IED is discussed in greater detail with respect to FIG. 4, of the disclosure. In response to determining that a local IED is compromised, SCM IIO1.1 at stage 212 of process 200, may upload or attempt to upload a desired configuration into the target IED (that is, the compromised IED). Successful uploading of the desired configuration may turn the comprised IED to a healthy IED.
[0030] In some examples, SCM 1 IO1.1 may also process a compromised IED configuration notification from another SCM or CCM 102. For example, at stage 220 of process 200, SCM 1 IO1.1 may receive a IED compromised signal from CCM 102 or any other SCM of EDS 100. In examples, a SCM may receive a compromised IEDAttorney Docket No.: 15720.2005WOU1configuration notification directly from another SCM only if peer-to-peer communication is supported. Otherwise, such communication is routed through CCM 102. After receiving the IED compromised signal at stage 220, process 200 may proceed to stage 222 where SCM 1 lOi.i may authenticate the received signal to ensure that the signal is being received from an authorized source. Once having authenticated the signal at stage 222, process 200 may proceed to stage 214, where SCM 1 lOi.i may upload a desired configuration into the target IED (that is, the compromised IED).
[0031] In some examples, in addition to manual reconfiguration, an automated reconfiguration invoked at CCM 102 by either an external (after due authentication) or an internal reconfiguration engine that autogenerates updated IED configurations analyzing EDS-wide operational data. For example, at stage 230 of process 200, a remote operator may login with CCM 102. The remote operator may login to either add a new IED to a subsystem or update a configuration of an existing IED of a subsystem.
[0032] After login by the remote operator at stage 230, method 200 may proceed to stage 232 where the remote operator may perform multi-factor authentication. Once having completed the multi-factor authentication at stage 234, process 200 may proceed to stage 234 where the remote operator may enter a target lED’s user credential. The lED’s user credentials may include an identifying information of the target IED. The target IED may be a new IED being added to EDS 100 or an existing IED of EDS 100.
[0033] Once having provided the target lED’s user credentials at stage 234, process 200 proceeds to stage 236 where the remote operator may specify if a new IED is being deployed. That is, the remote operator may specify that the target IED is a new IED being deployed in first subsystem IO61.1. In response to the target IED being a new IED, a local configuration database of CCM 102 is updated to include the new lED’s configuration. The local configuration database of CCM 102 may be maintained in a global database 238 at CCM 102. In addition, a notification is sent to SCM 1 IO1.1 of first subsystem IO61.1 of reconfiguration. After receiving the notification, SCM IIO1.1, at stage 240 of process 200, may authenticate that the notification is indeedAttorney Docket No.: 15720.2005WOU1coming from CCM 102. After authenticating that the notification is indeed coming from CCM 102, SCM IIO1.1, at stage 208, process 200 may loop to stage 208.
[0034] In some implementation, at stage 242 of process 200, a configuration server may initiate a reconfiguration of an IED. For example, the reconfiguration server may initiate a configuration update process on one or more lEDs of EDS 100. Alternatively, the configuration server may provide an updated configuration for one or more lEDs of EDS 100. Once initiated by the configuration server at stage 200, process 200 may continue to stage 236.
[0035] In some other implementations, at stage 244 of process 200, an external configuration server may initiate a reconfiguration of an IED. Once the external configuration server initiates the reconfiguration, CCM 102 may receive a reconfiguration notification and may, at stage 246 of process 200, perform an authentication to determine if the reconfiguration indeed is being received from an authorized external configuration server. After performing the authentication at stage 246, process 200 may continue to stage 236. In some examples, when an external configuration server initiates the reconfiguration action, a local operator may be notified of the same and a confirmation may be received from the local operator before processing the reconfiguration action.
[0036] Before uploading any normal mode configuration into an IED, regardless of whether it is manually or automatically invoked, local database 212 is updated, and any modification of information related to any IED or its operator at CCM’s global database 238 is notified to a corresponding SCM for replication, and vice versa. This ensures consistency of the databases at the central and the subsystem levels. If a multitude of target lEDs, possibly dispersed across multiple subsystems or systems, are to be reconfigured with a common reconfiguration file from CCM 102, the latter can either send the reconfiguration file to each corresponding SCMs, or to reduce the communication burden further, it can send the reconfiguration file to only one preassigned SCM per system, which will then forward the file to the neighboring SCMs containing at least one of the target lEDs.
[0037] FIG. 3 illustrates an example configuration lookup table 300. Configuration lookup table 300 for a subsystem, for example, first subsystem IO61.1 may be storedAttorney Docket No.: 15720.2005WOU1at local database 212. As shown in FIG. 3 configuration lookup table 300 may include a metric of cells arranged in matrix of a plurality of rows and a plurality of columns. In configuration lookup table 300, an (i,i)th cell contains configuration of an ith IED for a normal condition, that is when no IED in EDS 100 is compromised. An (i,j)th cell satisfying i j, optionally, contains the configuration of the ith IED for the emergency condition corresponding to a compromised state of a jth IED, where i and j respectively denote the row and column indices of configuration lookup table 300. CCM 102 and each of the SCMs share a tabular structure of configuration lookup table 300. In case of a SCM, the (i,j)th cell is empty unless the corresponding subsystem contains either the ith and the jth IED. If the cell is otherwise empty and satisfies i^j, it may imply that no reconfiguration in the ith IED is applicable if the jth one is compromised. Although, for simplicity of illustration, configuration lookup table 300 assumes that at most one IED can be compromised at a time in EDS 100, the process disclosed here apply to the general case of a greater number of compromised lEDs by employing a higher dimensional table.
[0038] In example embodiments, each SCM may monitor configurations of each lEDs in its LAN, VLAN, or subsystem. Monitoring of the IED configurations at the SCM level as opposed to CCM 102 enables fast detection of unauthorized configuration and / or manipulation. FIG 4 illustrates monitoring process 400 of an IED configuration in a subsystem of EDS 100. Monitoring process 400 may be performed after the IED is deployed or reconfigured in EDS 100. In summary, in process 400, the corresponding SCM of the subsystem repeatedly polls or retrieves a hash value of the lED’s current configuration (or the full configuration if sharing / computing the hash value is not supported) at a predetermined time interval and compares that with the golden (or desired) configuration stored in local database 212 until a mismatch is encountered. In case of a mismatch, that may indicate an unauthorized configuration manipulation, the SCM attempts to restore the golden version of configuration in the IED and blocks any further network traffic to / from the source that requested the configuration manipulation as identified by the local traffic monitoring agent. Such incident response, if successful can bring EDS system 100 back to normalcy. The stored event logs can be investigated by system administrators and operators for root-cause-analysis (RCA).Attorney Docket No.: 15720.2005WOU1
[0039] If the SCM fails too many times to restore the golden version of configuration (possible if, for example, the adversary managed to change credentials of the IED), then the SCM blocks the outbound traffic from the IED to protect EDS 100 from adverse consequences of malicious signals from the IED. To enhance EDS’s 100 resilience while facing such a failure, the SCMs will upload the corresponding emergency mode configurations into the healthy lEDs of EDS 100 as applicable.
[0040] In example implementations, monitoring process 400 starts when an IED, for example, first IED IO81.1.1, is deployed or any reconfiguration took place in an existing IED of first subsystem IO61.1. For example, monitoring process 400 may start if first IED 1081.1.1 is deployed in first subsystem IO61.1 of first system 104i or when reconfiguration took place first IED 1081.1.1. Although, process 400 is being described with reference to first IED 1081.1.1, process 400 is performed for each member IED of first subsystem IO61.1.
[0041] At stage 404 of monitoring process 400, SCM 1 IO1.1 retrieves a hash value of a current configuration from first IED 1081.1.1 if supported. Otherwise, SCM IIO1.1 retrieves the full configuration of the current configuration from first IED IO81.1.1. After retrieving the full configuration or its value at stage 404, monitoring process 400 proceeds to stage 406 where SCM IIO1.1 determines whether the retrieved configuration, or its hash value matches with that in local database 212. As discussed above local database 212 may store a golden configuration for each the plurality of lEDs of first subsystem IO61.1. If the retrieved configuration, or its hash value matches with that in local database 212 at stage 406, monitoring process 400 may loop back to stage 404 where SCM 1 IO1.1 continues to again retrieve the configuration of first IED 1081.1.1 after expiry of the predetermined interval.
[0042] If the retrieved configuration, or its hash value does not match with that in local database 212 at stage 406, monitoring process 400 proceeds to stage 408 where SCM IIO1.1 attempts to restore the golden configuration for first IED IO81.1.1 stored in local database 212 into first IED IO81.1.1. Once having attempted to restore the golden configuration for first IED IO81.1.1 stored in local database 212 into first IED 1081.1.1 at stage 408, monitoring process 400 proceeds to stage 410 where SCM 1 IO1.1 identifies the adversary using traffic monitor 112i.i and blocks any relatedAttorney Docket No.: 15720.2005WOU1inbound / outbound traffic from first IED 1081.1.1 and / or from the identified adversary. For example, SCM 1 lOi.i may analyze login details or configuration files to identify the unauthorized actor that created unauthorized configuration in first IED IO81.1.1. The adversary may be an unauthorized entity or actor that made configuration changes to first IED 1081.1.1. First IED IO81.1.1 with unauthorized changes to its configuration may also be labeled as a compromised IED.
[0043] Once having identified the adversary and blocked the inbound / outbound traffic from first IED IO81.1.1 at stage 410, monitoring process 400 proceeds to stage 412 where SCM 1 lOi.i logs the event, that is, detection of unauthorized configuration in first IED IO81.1.1. In addition, at stage 412, SCM 1 lOi.i may notify CCM 102 and other local SCMs of the event. Furthermore, SCM 1 lOi.i may also notify a local operator of the event. The local operator may be notified on a personal device or a monitoring console.
[0044] Once having attempted to restore the golden configuration for first IED 1081.1.1 stored in local database 212 into first IED IO81.1.1 at stage 408, monitoring process 400 also proceeds to stage 414 where SCM 1 lOi.i determines whether a legitimate configuration (that is, the golden configuration) was successfully restored in first IED IO81.1.1. In response to determining that the legitimate configuration (that is, the golden configuration) was successfully restored in first IED IO81.1.1 at stage 414, monitoring process 400 may loop back to stage 404 and can continue monitoring of the configuration of first IED IO81.1.1.
[0045] In response to determining that the legitimate configuration (that is, the golden configuration) was not successfully restored in first IED IO81.1.1 at stage 414, monitoring process 400 proceeds to stage 416 where SCM 1 lOi.i determines whether a number of failed restoration attempts is greater than a predetermined value. In response to determining that the number of failed restoration attempts is not greater than the predetermined value at stage 416, monitoring process 400 loops back to stage 408 where SCM 1 lOi.i again attempts to restore the golden configuration for first IED 1081.1.1 stored in local database 212 into first IED IO81.1.1. However, in response to determining that the number of failed restoration attempts is greater than the predetermined value at stage 416, monitoring process 400 proceeds to stage 418 whereAttorney Docket No.: 15720.2005WOU1SCM llOi.i blocks outbound traffic from first IED IO81.1.1. At this stage, first IED IO81.1.1 is also labeled as a compromised IED. In some examples, a user may not enable blocking of the network traffic from the compromised IED.
[0046] Once having blocked outbound traffic from the compromised IED (that is, first IED 1081.1.1) at stage 418, monitoring process 400 proceeds to stage 410 where SCM IIO1.1 logs the event, and notifies CCM 102, other local SCMs, and / or a local operator of the event (that is, detection of an unauthorized configuration in first IED 1081.1.1). In addition, after blocking outbound traffic from the compromised IED (that is, first IED 1081.1.1) at stage 418, monitoring process 400 proceeds to stage 420 where post-event analysis is performed. Post-event analysis may include performing a root cause analysis to determine a source of the compromised configuration file. In some examples, an alarm may be raised at stage 418.
[0047] Once the post-event analysis is performed at stage 420, monitoring process 400 proceeds to stage 422 where it is determined whether the compromised IED (that is, first IED IO81.1.1) is ready for redeployment. The compromised IED (that is, first IED 1081.1.1) is ready for redeployment when the compromised IED (that is, first IED 1081.1.1) is reformatted to remove the compromised configuration and any other malicious files, and a golden configuration being installed.
[0048] In response to determining that the compromised IED (that is, first IED 1081.1.1) is not ready for redeployment at stage 422, monitoring process 400 proceeds to stage 424 where the compromised IED (that is, first IED IO81.1.1) is replaced. In addition, at stage 424, processes for hardening subsystem IO61.1 may be performed. The hardening process may include cleaning the login system, access grants, and authentication processes. In response to determining that the compromised IED (that is, first IED IO81.1.1) is ready for redeployment at stage 422, monitoring process 400 loops back to stage 402.
[0049] Thus, continuous polling of the IED configurations to monitor their state is performed by the SCM at a subsystem level, as opposed to CCM 102 minimizing the volume of traffic to / from CCM 102. This also results in speedy detection of any unauthorized manipulation as a lesser number of lEDs are monitored by the SCMs.Attorney Docket No.: 15720.2005WOU1Any unauthorized manipulation detected by a SCM is reported to CCM 102 eliminating the need of continuous polling by CCM 102.
[0050] FIG. 5 is a flow diagram of a method 500 for enhancing resilience of EDS 100. Method 500 may be implemented using a SCM of EDS 100, for example, SCM llOi.i of first subsystem IO61.1 as described in more detail above with respect to FIG.1. Ways to implement the stages of method 500 will be described in greater detail below.
[0051] At stage 510 of method 500, SCM IIO1.1 retrieves a current configuration for each of the plurality of lEDs of first subsystem IO61.1 at a predetermined time interval. The predetermined interval is defined by a system administrator of EDS 100. In some examples, SCM IIO1.1 may retrieve a hash of the current configuration instead of retrieving the full configuration. In some examples, SCM IIO1.1 may retrieve the current configuration for each of the plurality of lEDs at once or one at a time.
[0052] At stage 520 of method 500, SCM IIO1.1 compares the retrieved current configuration with a golden configuration for each of the plurality of lEDs. The golden configuration for each of the plurality of lEDs of first subsystem IO61.1 may be stored in local database 212. SCM IIO1.1 compares the current configuration for an IED with a golden configuration for that IED.
[0053] At stage 530 of method 500, SCM IIO1.1 determines whether the retrieved current configuration matches with the golden configuration for each of the plurality of lEDs. SCM IIO1.1 may perform a one-to-one comparison to determine a match.
[0054] At stage 540 of method 500, SCM IIO1.1 attempts to restore the golden configuration from a local database into the IED in response to determining that the retrieved current configuration does not match with the golden configuration for an IED of the plurality of lEDs. SCM IIO1.1 may retrieve the corresponding golden configuration from local database 212. SCM IIO1.1 re-attempts to restore the golden configuration into the IED for a predetermined number of times in response to failing to restore the golden configuration into the IED. After failing to restore the golden configuration into the IED for a predetermined number of times, SCM IIO1.1 blocks an outbound traffic from the IED. In addition, and as discussed above, SCM IIO1.1Attorney Docket No.: 15720.2005WOU1may log an event for the compromised IED and notify a local operator. Furthermore, SCM llOi.i may upload an emergency mode configuration in remaining lEDs of first subsystem IO61.1.
[0055] FIG. 6 is a flow diagram of a method 600 for enhancing resilience of EDS 100. Method 600 may be implemented using a SCM of EDS 100, for example, SCM IIO1.1 as described in more detail above with respect to FIG. 1. Ways to implement the stages of method 600 will be described in greater detail below.
[0056] At stage 610 of method 500, SCM IIO1.1 polls a current configuration of each of the plurality of lEDs of first subsystem IO61.1 at a predetermined interval. The predetermined interval is defined by a system administrator of EDS 100. In some examples, SCM IIO1.1 may poll a hash of the current configuration instead of retrieving the full configuration.
[0057] At stage 620 of method 500, SCM IIO1.1 detects an unauthorized configuration manipulation in one of the plurality of lEDs. SCM IIO1.1 may detect an unauthorized configuration manipulation in an IED of subsystem IO61.1 by retrieving a current configuration of the IED and comparing it with the golden configuration for the IED. If the retrieved configuration does not match with the golden configuration, then unauthorized configuration manipulation is detected.
[0058] At stage 630 of method 600, SCM IIO1.1 attempts, in response to detecting the unauthorized configuration manipulation, to restore a corresponding golden configuration from local database 212 into the one of the plurality of lEDs. Thus, SCM IIO1.1 may try to restore the compromised IED by restoring the golden configuration. If SCM IIO1.1 fails to restore the compromised IED, then SCM IIO1.1 may create an event log and block incoming / outgoing network traffic from the compromised IED. In addition, SCM 1 IO1.1 may notify CCM 102 and a local operator of the compromised IED. Furthermore, SCM IIO1.1 may upload an emergency mode configuration in remaining lEDs of first subsystem IO61.1.
[0059] FIG. 7 is a flow diagram of a method 700 for enhancing resilience of EDS 100. Method 700 may be implemented using a SCM of EDS 100, for example, SCM IIO1.1 of first subsystem IO61.1 as described in more detail above with respect to FIG.Attorney Docket No.: 15720.2005WOU11. Ways to implement the stages of method 700 will be described in greater detail below.
[0060] At stage 710 of method 700, SCM 1 lOi.i of first subsystem 106 i.i of EDS100 authenticates an operator of EDS 100. As discussed above, EDS 100 includes a plurality of subsystems, each of the plurality of subsystems including a plurality of lEDs and an associated SCM connected to the plurality of lEDs through a LAN or a VLAN. The operator may access SCM 1 lOi.i using the HMI and login to SCM 1 lOi.i. After logging in, the operator may use multi-factor authentication to authenticate itself.
[0061] At stage 720 of method 700, SCM 1 lOi.i receives an identifying information of an IED to be added to first subsystem IO61.1 of the EDS 100. The identifying information may include a serial number, a name, a location, etc. of the IED to be added.
[0062] At stage 730 of method 700, SCM 1 IO1.1 receives a golden configuration of the IED to be added. In some examples, SCM 1 IO1.1 may also receive emergency mode configurations for the IED to be added. SCM 1 IO1.1 may receive the golden configuration and the emergency mode configurations from the operator, a configuration server, or CCM 102.
[0063] At stage 740 of method 700, SCM 1 IO1.1 creates a record in local database 212 of SCM IIO1.1 for the IED to added and the golden configuration for the IED to be added. In some example, SCM 1 IO1.1 may update configuration lookup table 300 to include a row and a column for the IED and include the golden configuration and the emergency mode configurations in configuration lookup table 300.
[0064] At stage 750 of method 700, SCM 1 IO1.1 synchronizes, after creating the record at local database 212, local database 212 with global database 238 associated with CCM 102. As discussed above, before uploading any normal mode configuration into an IED, regardless of whether it is manually or automatically invoked, local database 212 is updated, and any modification of information related to any IED or its operator at the CCM’s database is notified to the corresponding SCM for replication,Attorney Docket No.: 15720.2005WOU1and vice versa. This ensures consistency of the databases at the central and the subsystem levels.
[0065] At stage 760 of method 700, SCM 1 lOi.i uploads the golden configuration in the IED to be added. Thus, the IED is added to first subsystem IO61.1 and becomes part of EDS 100.
[0066] FIG. 8 is a flow diagram of a method 800 for enhancing resilience of EDS 100. Method 800 may be implemented using a SCM of EDS 100, for example, SCM IIO1.1 of first subsystem IO61.1 as described in more detail above with respect to FIG.1. Ways to implement the stages of method 800 will be described in greater detail below.
[0067] At stage 810 of method 800, SCM 1 IO1.1 of first subsystem 1061.1 of EDS 100 receives an indication to update a configuration of an IED of EDS 100. As discussed above, EDS 100 includes a plurality of subsystems, each if the plurality of subsystems including a plurality of lEDs and an associated SCM connected to the plurality of lEDs through a network, for example, a LAN or a VLAN. The indication may be received from a local operator, a remote operator, CCM 102, a remote configuration manager, etc.
[0068] At stage 820 of method 800, SCM 1 IO1.1 authenticates the indication to determine that it originated from an authorized source. The authentication may be performed using multi-factor authentication process.
[0069] At stage 830 of method 800, SCM 1 IO1.1 uploads a desired configuration for the IED. The desired configuration can be a golden configuration or an emergency mode configuration for the IED. SCM 1 IO1.1 may retrieve the desired configuration from local database 212.
[0070] FIG. 9 is a flow diagram of a method 900 for enhancing resilience of EDS 100. Method 900 may be implemented using a SCM of EDS 100, for example, SCM IIO1.1 of first subsystem IO61.1 as described in more detail above with respect to FIG.1. Ways to implement the stages of method 900 will be described in greater detail below.Attorney Docket No.: 15720.2005WOU1
[0071] At stage 910 of method 900, SCM 1 lOi.i of first subsystem 106 i.i of EDS 100 receives a signal indicating that an IED of first subsystem IO61.1 is compromised. As discussed above, EDS 100 includes a plurality of subsystems, each of the plurality of subsystems including a plurality of lEDs and an associated SCM connected to the plurality of lEDs through a network, for example, a LAN or a VLAN. The signal indicating a compromised IED may be received from a local operator, a remote operator, CCM 102, etc.
[0072] At stage 920 of method 900, SCM 1 IO1.1 attempts, in response to receiving the signal indicating a compromised IED, to restore a golden configuration for the compromised IED from local database 212 into the compromised IED.
[0073] At stage 930 of method 900, SCM 1 IO1.1 invokes an emergency mode configuration in the plurality of lEDs of first subsystem IO61.1 after attempting to restore the golden configuration for the compromised IED for a predetermined number of times.
[0074] At stage 9400 of method 900, SCM 1 IO1.1 sends a notification to CCM 102 of the compromised IED. In some examples, SCM 1 IO1.1 may also send a notification to a local operator of the compromised IED.
[0075] FIG. 10 is a flow diagram of a method 1000 for enhancing resilience of EDS 100. Method 1000 may be implemented using a SCM of EDS 100, for example, SCM IIO1.1 of first subsystem IO61.1 as described in more detail above with respect to FIG.1. Ways to implement the stages of method 1000 will be described in greater detail below.
[0076] At stage 1010 of method 1000, SCM 1 IO1.1 of first subsystem IO61.1 of EDS 100 determines that an IED of first subsystem IO61.1 is compromised. As discussed above, EDS 100 includes a plurality of subsystems, each of the plurality of subsystems including a plurality of lEDs and an associated SCM connected to the plurality of lEDs through a network, for example, a LAN or a VLAN. SCM 1 IO1.1 may determine a compromised IED in first subsystem IO61.1 by comparing a current configuration with a respective golden configuration for each lEDs of first subsystem IO61.1.Attorney Docket No.: 15720.2005WOU1
[0077] At stage 1020 of method 1000, SCM HOi.i attempts, in response to determining a compromised IED, to restore a golden configuration for the compromised IED from local database 212 into the compromised IED.
[0078] At stage 1030 of method 1000, SCM HOi.i invokes an emergency mode configuration in the plurality of lEDs of first subsystem IO61.1 after failing to restore the golden configuration for the compromised IED after a predetermined number of attempts.
[0079] At stage 1030 of method 1000, SCM IIO1.1 sends a notification to CCM 102 of the compromised IED. In addition, SCM IIO1.1 may create an event log for the compromised IED and block inbound / outbound network traffic from the compromised IED. In some examples, SCM 1 IO1.1 may send a notification to a local operator of the compromised IED.
[0080] FIG. 11 is a flow diagram of a method 1100 for enhancing resilience of EDS 100. Method 1100 may be implemented using a SCM of EDS 100, for example, SCM IIO1.1 of first subsystem IO61.1 as described in more detail above with respect to FIG.1. Ways to implement the stages of method 1100 will be described in greater detail below.
[0081] At stage 1110 of method 1100, SCM 1 IO1.1 of first subsystem IO61.1 of EDS 100 receives a signal indicating that an IED of first subsystem IO61.1 is compromised. As discussed above, EDS 100 includes a plurality of subsystems, each of the plurality of subsystems including a plurality of IED s and an associated SCM connected to the plurality of lEDs through a VLAN. SCM IIO1.1 may receive the signal from a local operator, a remote operator, CM 102, etc.
[0082] At stage 1120 of method 1100, SCM 1 IO1.1 attempts, in response to receiving indication of a compromised IED, to restore a golden configuration for the compromised IED from local database 212 into the compromised IED.
[0083] At stage 1130 of method 1100, SCM 1 IO1.1 blocks both inbound and outbound network traffic from the compromised IED. In some examples, traffic monitor 112i.i of first subsystem IO61.1 may block the inbound and outbound traffic from the compromised IED. In some examples, the network traffic is blocked after failing toAttorney Docket No.: 15720.2005WOU1restore the golden configuration into the compromised IED after a predetermined number of attempts.
[0084] At stage 1140 of method 1100, SCM 1 lOi.i sends a notification to CCM 102 of the compromised IED. In addition, SCM 1 lOi.i may create an event log for the compromised IED and block inbound / outbound network traffic from the compromised IED. In some examples, SCM 1 lOi.i may send a notification to a local operator of the compromised IED.
[0085] FIG. 12 is a flow diagram of a method 1200 for enhancing resilience of EDS 100. Method 1200 may be implemented using a SCM of EDS 100, for example, SCM llOi.i of first subsystem IO61.1 as described in more detail above with respect to FIG.1. Ways to implement the stages of method 1200 will be described in greater detail below.
[0086] At stage 1210 of method 1200, SCM IIO1.1 of first subsystem IO61.1 of EDS 100 determines that an IED of first subsystem IO61.1 is compromised. As discussed above, EDS 100 includes a plurality of subsystems, each of the plurality of subsystems including a plurality of lEDs and an associated SCM connected to the plurality of lEDs through a network, for example, a LAN or a VLAN. SCM 1 IO1.1 may determine a compromised IED in first subsystem IO61.1 by comparing a current configuration with respective golden configuration for each lEDs.
[0087] At stage 1220 of method 1200, SCM IIO1.1 attempts, in response to receiving indication of a compromised IED, to restore a golden configuration for the compromised IED from local database 212 into the compromised IED.
[0088] At stage 1230 of method 1200, SCM 1 IO1.1 blocks both inbound and outbound network traffic from the compromised IED. In some examples, traffic monitor 112i.i of subsystem IO61.1 may block the inbound and outbound traffic from the compromised IED. In other examples, the network traffic is blocked after failing to restore the golden configuration into the compromised IED after a predetermined number of attempts.
[0089] At stage 1240 of method 1200, SCM IIO1.1 sends a notification to CCM 102 of the compromised IED. In addition, SCM IIO1.1 may create an event log for theAttorney Docket No.: 15720.2005WOU1compromised IED and block inbound / outbound network traffic from the compromised IED. In some examples, SCM 1 IO1.1 may send a notification to a local operator of the compromised IED.
[0090] FIG. 13 shows computing device 1300. As shown in FIG. 13, computing device 1300 may include a processing unit 1310 and a memory unit 1315. Memory unit 1315 may include a software module 1320 and a database 1325. While executing on processing unit 1310, software module 1320 may perform, for example, deployment and reconfiguration process as described above with respect to FIG. 2 and monitoring process as described above with respect to FIG. 4. In addition, while executing on processing unit 1310, software module 1320 may perform process for enhancing resilience of EDS 100 as described above with respect to FIGS. 5-12.
[0091] Computing device 1300, for example, may provide an operating environment for CM 102, lEDs, SCMs, traffic monitors of EDS 100. CM 102, lEDs, SCMs, traffic monitors of EDS 100 may operate in other environments and are not limited to computing device 1300.
[0092] Computing device 1300 may be implemented using a Wi-Fi access point, a tablet device, a mobile device, a set-top box, a network computer, a router, a switch, a server cluster, a network relay device, or other similar microcomputer-based device. Computing device 1300 may comprise any computer operating environment, such as hand-held devices, multiprocessor systems, microprocessor-based or programmable sender electronic devices, minicomputers, mainframe computers, and the like. The aforementioned systems and devices are examples, and computing device 1300 may comprise other systems or devices.
[0093] Embodiments of the disclosure, for example, may be implemented as a computer process (method), a computing system, or as an article of manufacture, such as a computer program product or computer readable media. The computer program product may be a computer storage media readable by a computer system and encoding a computer program of instructions for executing a computer process. The computer program product may also be a propagated signal on a carrier readable by a computing system and encoding a computer program of instructions for executing a computer process. Accordingly, the present disclosure may be embodied in hardware and / or inAttorney Docket No.: 15720.2005WOU1software (including firmware, resident software, micro-code, etc.). In other words, embodiments of the present disclosure may take the form of a computer program product on a computer-usable or computer-readable storage medium having computer-usable or computer-readable program code embodied in the medium for use by or in connection with an instruction execution system. A computer-usable or computer-readable medium may be any medium that can contain, store, communicate, propagate, or transport the program for use by or in connection with the instruction execution system, apparatus, or device.
[0094] The computer-usable or computer-readable medium may be, for example but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, device, or propagation medium. More specific computer-readable medium examples (a non-exhaustive list), the computer-readable medium may include the following: an electrical connection having one or more wires, a portable computer diskette, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, and a portable compact disc read-only memory (CD-ROM). Note that the computer-usable or computer-readable medium could even be paper or another suitable medium upon which the program is printed, as the program can be electronically captured, via, for instance, optical scanning of the paper or other medium, then compiled, interpreted, or otherwise processed in a suitable manner, if necessary, and then stored in a computer memory.
[0095] While certain embodiments of the disclosure have been described, other embodiments may exist. Furthermore, although embodiments of the present disclosure have been described as being associated with data stored in memory and other storage mediums, data can also be stored on, or read from other types of computer-readable media, such as secondary storage devices, like hard disks, floppy disks, or a CD-ROM, a carrier wave from the Internet, or other forms of RAM or ROM. Further, the disclosed methods’ stages may be modified in any manner, including by reordering stages and / or inserting or deleting stages, without departing from the disclosure.
[0096] Furthermore, embodiments of the disclosure may be practiced in an electrical circuit comprising discrete electronic elements, packaged or integrated electronicAttorney Docket No.: 15720.2005WOU1chips containing logic gates, a circuit utilizing a microprocessor, or on a single chip containing electronic elements or microprocessors. Embodiments of the disclosure may also be practiced using other technologies capable of performing logical operations such as, for example, AND, OR, and NOT, including but not limited to, mechanical, optical, fluidic, and quantum technologies. In addition, embodiments of the disclosure may be practiced within a general purpose computer or in any other circuits or systems.
[0097] Embodiments of the disclosure may be practiced via a system-on-a-chip (SOC) where each or many of the element illustrated in FIG. 1 may be integrated onto a single integrated circuit. Such an SOC device may include one or more processing units, graphics units, communications units, system virtualization units and various application functionality all of which may be integrated (or “burned”) onto the chip substrate as a single integrated circuit. When operating via an SOC, the functionality described herein with respect to embodiments of the disclosure, may be performed via application-specific logic integrated with other components of computing device 400 on the single integrated circuit (chip).
[0098] Embodiments of the present disclosure, for example, are described above with reference to block diagrams and / or operational illustrations of methods, systems, and computer program products according to embodiments of the disclosure. The functions / acts noted in the blocks may occur out of the order as shown in any flowchart. For example, two blocks shown in succession may in fact be executed substantially concurrently or the blocks may sometimes be executed in the reverse order, depending upon the functionality / acts involved.
[0099] While the specification includes examples, the disclosure’s scope is indicated by the following claims. Furthermore, while the specification has been described in language specific to structural features and / or methodological acts, the claims are not limited to the features or acts described above. Rather, the specific features and acts described above are disclosed as example for embodiments of the disclosure.
Claims
1. Attorney Docket No.: 15720.2005WOU1CLAIMS1. An Energy Delivery System (EDS), comprising:a central configuration manager; andat least one subsystem comprising:a plurality of Intelligent Electronic Devices (lEDs), anda subsystem configuration manager connected to the central configuration manager, wherein the subsystem configuration manager is connected to the plurality of lEDs through a network, wherein the subsystem configuration manager is configured to:retrieve a current configuration for each of the plurality of lEDs at a predetermined time interval,compare, for each of the plurality of lEDs, the retrieved current configuration with a golden configuration,determine, for each of the plurality of lEDs, that the retrieved current configuration matches with the golden configuration, andattempt, in response to determining that the retrieved current configuration does not match with the golden configuration for an IED of the plurality of lEDs, to restore the golden configuration into the IED.
2. The EDS of claim 1, wherein the subsystem configuration manager is further configured to:re-attempt, in response to failing to restore the golden configuration into the IED, to restore the golden configuration into the IED for a predetermined number of times; and block, after failing to restore the golden configuration into the IED for a predetermined number of times, outbound traffic from the IED.
3. The EDS system of claim 2, wherein the subsystem configuration manager is further configured to:upload a corresponding emergency mode configuration into the plurality of lEDs.Attorney Docket No.: 15720.2005WOU14. The EDS system of claim 3, wherein the corresponding emergency mode configuration of the plurality of lEDs is stored in a local database accessible to the subsystem configuration manager.
5. The EDS of claim 2, wherein the subsystem configuration manager is further configured to:log an event comprising a compromised IED; andnotify the central configuration manager of the compromised IED.
6. The EDS of claim 1, wherein the at least one subsystem further comprising a traffic monitor, wherein the traffic monitor is configured to determine a source of the current configuration in response to determining that the retrieved current configuration does not match with the golden configuration.
7. The EDS system of claim 6, wherein the traffic monitor is configured to block inbound / outbound network traffic from the IED.
8. The EDS system of claim 1, wherein the subsystem configuration manager is further configured to:retrieve a hash value of the current configuration for each of the plurality of lEDs at the predetermined time interval.
9. The EDS system of claim 1, wherein the golden configuration is stored in a configuration lookup table in a local database accessible to the subsystem configuration manager.
10. An Energy Delivery System (EDS), comprising:a central configuration manager;at least two subsystems, where each of the at least two subsystems comprising:a plurality of Intelligent Electronic Devices (IED)s, anda subsystem configuration manager connected the plurality of lEDs over a network, and wherein the subsystem configuration manager is configured to:Attorney Docket No.: 15720.2005WOU1poll a current configuration of each of the plurality of ZEDS in at a predetermined interval,detect an unauthorized configuration manipulation in one of the plurality of ZEDS, andattempt, in response to detecting the unauthorized configuration manipulation, to restore a corresponding golden configuration from a local database into the one of the plurality of ZEDs.
11. The EDS of claim 10, wherein the subsystem configuration manager is further configured to:re-attempt, in response to failing to restore the corresponding golden configuration into the ZED, to restore the corresponding golden configuration into the ZED for a predetermined number of times; andblock, after failing to restore the corresponding golden configuration into the ZED for a predetermined number of times, outbound traffic from the ZED.
12. The EDS system of claim 11, wherein the subsystem configuration manager is further configured to:upload a corresponding emergency mode configuration into the plurality of ZEDs.
13. The EDS system of claim 12, wherein the corresponding emergency mode configuration of the plurality of ZEDs is stored in a local database accessible to the subsystem configuration manager.
14. The EDS system of claim 10, wherein the corresponding golden configuration is stored in a configuration lookup table in a local database accessible to the subsystem configuration manager.
15. A method of updating an Zntelligent Electronic Device (ZED) in an Energy Delivery System (EDS), the method comprising:authenticating, by a subsystem configuration manager of a subsystem of an EDS, an authorized operator for an Energy Delivery System (EDS), wherein the EDS comprises aAttorney Docket No.: 15720.2005WOU1plurality of subsystems, each of the plurality of subsystems comprising a plurality of Intelligent Electronic Devices (lEDs) and an associated subsystem configuration manager connected to the plurality of lEDs through a Virtual Local Area Network (VLAN);receiving, by the subsystem configuration manager, an identifying information of an IED to be added to the subsystem of the EDS;receiving, by the subsystem configuration manager, a golden configuration of the IED to be added;creating, by the subsystem configuration manager, a record in a local database of the subsystem configuration manager for the IED to added and the golden configuration for the IED to be added;synchronizing, by the subsystem configuration manager after creating the record at the local database, the local database with a global database associated with a central configuration manager; anduploading, by the subsystem configuration manager, the golden configuration in the IED to be added.
16. A method of adding an Intelligent Electronic Device (IED) in an Energy Delivery System (EDS), the method comprising:receiving, by a subsystem configuration manager of a subsystem of an Energy Delivery System (EDS), an indication to update a configuration of an Intelligent Electronic Device (IED) of the EDS, wherein the EDS comprises a plurality of subsystems, each of the plurality of subsystems comprising a plurality of Intelligent Electronic Devices (lEDs) and an associated subsystem configuration manager connected to the plurality of lEDs through a Virtual Local Area Network (VLAN);authenticating, by the subsystem configuration manager, the indication to determine that it is originating from an authorized source; anduploading, by the subsystem configuration manager, a desired configuration for the IED;17. A method of managing Intelligent Electronic Devices (lEDs) of an Energy Delivery System (EDS), the method comprising:receiving, by a subsystem configuration manager of a subsystem of an Energy Delivery System (EDS), a signal indicating that an Intelligent Electronic Device (IED) of theAttorney Docket No.: 15720.2005WOU1subsystem is compromised, wherein the EDS comprises a plurality of subsystems, each of the plurality of subsystems comprising a plurality of lEDs and an associated subsystem configuration manager connected to the plurality of lEDs through a Virtual Local Area Network (VLAN);attempting, by the subsystem configuration manager in response to receiving the signal indicating a compromised IED, to restore a golden configuration for a compromised IED from a local database into the compromised IED;invoking, by the subsystem configuration manager, an emergency mode configuration in the plurality of lEDs of the subsystem after failing to restore the golden configuration for the compromised IED after a predetermined number of attempts; andsending, by the subsystem configuration manager, a notification to a central configuration manager of the compromised IED.
18. A method of managing Intelligent Electronic Devices (lEDs) of an Energy Delivery System (EDS), the method comprising:determining, by a subsystem configuration manager of a subsystem of an Energy Delivery System (EDS), that an Intelligent Electronic Device (IED) of the subsystem is compromised, wherein the EDS comprises a plurality of subsystems, each of the plurality of subsystems comprising a plurality of lEDs and an associated subsystem configuration manager connected to the plurality of lEDs through a Virtual Local Area Network (VLAN);attempting, by the subsystem configuration manager in response to determining a compromised IED, to restore a golden configuration for the compromised IED from a local database into the compromised IED;invoking, by the subsystem configuration manager, an emergency mode configuration in the plurality of lEDs of the subsystem after failing to restore the golden configuration for the compromised IED after a predetermined number of attempts; andsending, by the subsystem configuration manager, a notification to a central configuration manager of the compromised IED.
19. A method of managing Intelligent Electronic Devices (lEDs) of an Energy Delivery System (EDS), the method comprising:receiving, by a subsystem configuration manager of a subsystem of an Energy Delivery System (EDS), a signal indicating that an Intelligent Electronic Device (IED) of theAttorney Docket No.: 15720.2005WOU1subsystem is compromised, wherein the EDS comprises a plurality of subsystems, each of the plurality of subsystems comprising a plurality of lEDs and an associated subsystem configuration manager connected to the plurality of lEDs through a Virtual Local Area Network (VLAN);attempting, by the subsystem configuration manager in response to receiving the signal indicating a compromised IED, to restore a golden configuration for a compromised IED from a local database into the compromised IED;blocking, by the subsystem configuration manager, both inbound and outbound network traffic from the compromised IED; andsending, by the subsystem configuration manager, a notification to a central configuration manager of the compromised IED.
20. A method of managing Intelligent Electronic Devices (lEDs) of an Energy Delivery System (EDS), the method comprising:determining, by a subsystem configuration manager of a subsystem of an Energy Delivery Automation System (EDS), that an Intelligent Electronic Device (IED) of the subsystem is compromised, wherein the EDS comprises a plurality of subsystems, each of the plurality of subsystems comprising a plurality of lEDs and an associated subsystem configuration manager connected to the plurality of lEDs through a Virtual Local Area Network (VLAN);attempting, by the subsystem configuration manager in response to determining a compromised IED, to restore a golden configuration for a compromised IED from a local database into the compromised IED;blocking, by the subsystem configuration manager, both inbound and outbound network traffic from the compromised IED; andstoring, by the subsystem configuration manager, an event log for the compromised IED.