Chaff Data Concealment for Power System Communication Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Power system communication links are vulnerable to eavesdropping and tampering, with existing encryption techniques susceptible to attacks and requiring secure key exchange methods that are impractical for distributed power system devices (PSDs) due to processing and communication capacity limitations.

Innovation Solution

A communication apparatus and method that uses deterministic number generators to conceal messages within chaff data, where a common initialization value is shared between sender and receiver to generate synchronized sequences of numbers, allowing the message to be encoded and later distinguished from chaff data using a winnower module, eliminating the need for secure key exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional encryption techniques are used to protect power system communications, then security against eavesdropping is improved, but the system becomes susceptible to pattern-based attacks and requires secure key exchange mechanisms that are impractical for distributed power system devices

Engineering Contradiction:
ImprovesecurityVSAvoidkey exchange complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The communication data stream is segmented into two distinct parts: chaff data (dummy information) and wheat data (actual message). This segmentation allows the system to conceal the actual message within a larger stream of innocuous data, preventing pattern-based attacks while eliminating the need for complex key exchange mechanisms. The chaff and wheat are separated using simple deterministic algorithms based on initialization vectors rather than cryptographic keys.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Chaff data acts as an intermediary that mediates between the sender and receiver by concealing the actual message. The chaff data serves as a protective layer that obscures the wheat data from eavesdroppers, while the deterministic separation algorithm acts as an intermediary mechanism that both parties use to extract the message without requiring secure key exchange.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data encryption is applied to obfuscate communicated information, then confidentiality is improved, but computational requirements increase which is unsuitable for power system devices with limited processing capacity

Engineering Contradiction:
ImproveconfidentialityVSAvoidprocessing capacity
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The system uses inexpensive, computationally lightweight deterministic algorithms based on initialization vectors instead of complex cryptographic encryption. These algorithms require minimal processing power while providing sufficient confidentiality for power system communications, making them suitable for devices with limited processing capacity.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The system changes the approach from cryptographic key-based security to parameter-based security using initialization vectors. This parameter change simplifies the computational requirements while maintaining confidentiality, as the security relies on the secrecy of the initialization vector and the deterministic separation algorithm rather than computationally intensive encryption.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If steganography is used to conceal message existence within cover data, then security against pattern attacks is improved, but the complexity of message extraction increases

Engineering Contradiction:
Improvesecurity against pattern attacksVSAvoidmessage extraction complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The chaff and wheat separation algorithm is designed to be self-serving for both sender and receiver. Both parties possess the same deterministic algorithm and initialization vector, allowing them to independently separate chaff from wheat without requiring complex coordination or extraction procedures. The system serves itself by using the same simple logic at both ends.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses parameter-based separation through initialization vectors rather than complex steganographic algorithms. This approach simplifies message extraction by relying on deterministic parameter-based separation instead of complex pattern recognition or extraction procedures, reducing the computational burden while maintaining security.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8712052B2System and method for secure power systems infrastructure communications
Publication Date: 2014.04.29 EATON INTELLIGENT POWER LTD
  • US8712052B2 patent drawing
  • US8712052B2 patent drawing
  • US8712052B2 patent drawing

AI summary

Communication apparatus and associated method for sending messages while concealing the messages among chaff data. In sending outgoing communications to and from a remote device, a stream of chaffing data is generated. A message to be communicated is inserted into the stream of chaffing data such that the beginning and ending boundaries of the first message are concealed by the chaffing data. A matching pair of deterministic number generators, one at the sending end and one at the remote device, are initialized using a common initialization value to cause generation of a common sequence of numbers with the remote device. The stream of chaffing data, or data associated with the first message, or both, are encoded with the common sequence of numbers.