Cryptographic Lockout System for Smart Grid Remote Terminal Units

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional methods for locking out terminal units in power systems are inconvenient and inefficient, particularly when technicians are not physically present, leading to delays and increased resource expenditure, and lack monitoring capabilities for back office systems.

Innovation Solution

A system using public and private keys in a three-entity system to enable and disable lockouts on remote terminal units, allowing for secure, remote management and monitoring through cryptographic commands, ensuring that lockouts are placed and removed accurately and securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical locks are used on terminal units, then safety of field personnel is improved, but convenience of operation deteriorates when technicians are not physically present

Engineering Contradiction:
Improvesafety of field personnelVSAvoidconvenience of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical physical lockout system with an electronic/cryptographic lockout system. Instead of requiring physical locks and keys, the system uses electronic lockout commands transmitted through the network, with cryptographic verification (public/private keys) to ensure security. This substitution maintains safety while enabling remote operation capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a back office system as an intermediary between field personnel and terminal units. The back office system receives lockout requests, verifies permissions, generates cryptographic lockout permits, and transmits lockout commands to terminal units. This intermediary enables centralized monitoring and management while maintaining the security and reliability of the lockout process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If physical locks are used on terminal units, then safety of field personnel is improved, but productivity deteriorates due to delays and resource expenditure

Engineering Contradiction:
Improvesafety of field personnelVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By replacing physical locks with electronic lockout commands transmitted through the network, the system eliminates the need for technicians to be physically present at terminal units to place or remove locks. This substitution dramatically reduces travel time and resource expenditure while maintaining safety through cryptographic verification and centralized monitoring.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs preliminary actions by pre-configuring cryptographic key pairs for users and terminal units, and by establishing the back office system with permission verification capabilities before actual lockout operations are needed. This preparation enables rapid lockout and unlock operations without requiring physical presence or complex on-site procedures.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If physical locks are used on terminal units, then simplicity of the system is maintained, but monitoring capability deteriorates for back office systems

Engineering Contradiction:
Improvesimplicity of the systemVSAvoidmonitoring capability
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The patent implements feedback mechanisms where the back office system receives lockout requests, processes permission verification, generates lockout permits, and transmits lockout commands to terminal units. The system also receives acknowledgments and status information from terminal units, enabling continuous monitoring of lockout states. This feedback loop provides comprehensive visibility into field operations while maintaining a relatively simple overall system architecture.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10229291B2Method and system for cryptographically enabling and disabling lockouts for critical operations in a smart grid network
Publication Date: 2019.03.12 ITRON NETWORKED SOLUTIONS INC
  • US10229291B2 patent drawing
  • US10229291B2 patent drawing
  • US10229291B2 patent drawing

AI summary

A method for locking out a remote terminal unit includes: receiving a lockout request, wherein the lockout request includes at least a public key associated with a user, a user identifier, and a terminal identifier; identifying a user profile associated with the user based on the user identifier included in the received lockout request; verifying the public key included in the received lockout request and permission for the user to lockout a remote terminal unit associated with the terminal identifier included in the received lockout request based on data included in the identified user profile; generating a lockout permit, wherein the lockout permit includes at least the public key included in the received lockout request; and transmitting at least a lockout request and the generated lockout permit, wherein the lockout request includes an instruction to place a lockout on the remote terminal unit.