Bump-In-The-Wire Security Device for Microgrid Legacy Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Microgrid systems connected to external networks are vulnerable to cyber threats, particularly in sensitive sites like military bases, due to lack of strong security measures, with legacy devices unable to perform cryptographic operations, leading to compromised security policies and complex certification processes.

Innovation Solution

A cyber-security architecture utilizing 'Bump-In-The-Wire' (BITW) security devices for cryptographic separation and OPC UA for secure communication, enabling secure network isolation and authentication, and DIACAP certified hardware for enhanced security and scalability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If legacy devices are connected to external networks in microgrid systems, then remote monitoring and control capabilities are improved, but vulnerability to cyber threats increases

Engineering Contradiction:
Improveremote monitoring and control capabilityVSAvoidcyber threat vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a bump-in-the-wire security device as an intermediary component between legacy microgrid devices and external networks. This device provides cryptographic separation and security functions without requiring modifications to the legacy devices themselves, enabling remote monitoring and control while protecting against cyber threats through authentication and encryption mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If strong cryptographic separation is implemented in microgrid networks, then security against cyber threats is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity against cyber threatsVSAvoidcryptographic separation implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network architecture by introducing dedicated bump-in-the-wire security devices that handle cryptographic functions separately from the legacy microgrid devices. This segmentation isolates the complexity of cryptographic operations to specific security components while keeping the core microgrid devices simple and unchanged.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The bump-in-the-wire security device acts as an intermediary that handles all cryptographic operations, authentication, and security policies. This mediator approach concentrates the complexity in a specialized security component rather than distributing it across all microgrid devices, simplifying the overall system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If legacy devices without cryptographic capabilities are used in microgrids, then ease of manufacture and deployment is improved, but security policy enforcement becomes difficult

Engineering Contradiction:
Improvelegacy device deploymentVSAvoidsecurity policy enforcement
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The bump-in-the-wire security device serves as an intermediary that implements security policies for legacy devices lacking cryptographic capabilities. The security device handles authentication, encryption, and policy enforcement externally, allowing legacy devices to maintain their simple, easy-to-deploy characteristics while still enforcing strong security policies through the attached security component.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10218675B2Legacy device securitization using bump-in-the-wire security devices within a microgrid system
Publication Date: 2019.02.26 HONEYWELL INTERNATIONAL INC
  • US10218675B2 patent drawing
  • US10218675B2 patent drawing
  • US10218675B2 patent drawing

AI summary

Devices, methods, systems, and computer-readable media for legacy device securitization within a microgrid system are described herein. One or more embodiments include a system having a microgrid network with at least one remote network connection to a non-local network device and the network having at least one local legacy device in communication with the non-local network device and a bump-in-the-wire (BITW) security device between the local legacy device and the at least one remote connection.