Demand Response Authorization Permits for Secure Endpoint Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing demand response management systems (DRMS) face challenges in securely generating and managing demand response control events, leading to issues such as unintentional or unauthorized actions by endpoint devices, which can negatively impact the electrical system.

Innovation Solution

A secure DRMS is implemented, featuring an event generator within a secure environment that authenticates operators and processes demand response control event requests. The system generates secure messages, including signed event indications and authorization permits, to ensure the authenticity and authorization of demand response events.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If demand response control events are generated without secure authorization, then the system can respond quickly to forecasted energy supply issues, but the system risks unintentional or unauthorized actions that negatively impact the electrical system

Engineering Contradiction:
Improveintentionality and validity of demand response actionsVSAvoidsecurity authorization system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary authentication of the operator and validation of the demand response control event request before generating the event. The event generator validates the request against policies and generates signed authorization permits in advance, ensuring that only authorized and valid events are executed, thereby preventing unintentional or unauthorized actions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The event generator acts as an intermediary between the operator and the endpoint devices. It receives control requests, validates them against policies, generates signed authorization permits, and only then transmits the control events to endpoint devices. This intermediary layer ensures security and authorization without requiring complex security systems at every endpoint device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system implements comprehensive security validation for all demand response events, then unauthorized actions are prevented, but the response time to address energy supply issues increases

Engineering Contradiction:
Improveauthorization securityVSAvoiddemand response event generation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs authentication and validation in advance before the actual demand response event is needed. The event generator authenticates the operator and validates the control request beforehand, generating signed authorization permits that enable rapid execution of approved events without repeated validation delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system replaces manual or repeated mechanical validation processes with automated cryptographic verification. Endpoint devices can quickly verify the authenticity of control events by checking digital signatures against published public keys, eliminating the need for time-consuming interactive authentication during event execution.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If endpoint devices operate outside the secured computing environment, then the system can control large quantities of distributed devices, but the risk of receiving unauthorized commands increases

Engineering Contradiction:
Improveability to control distributed energy resourcesVSAvoidunauthorized or improper control commands
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The event generator serves as a secure intermediary that bridges the trusted control center and untrusted endpoint devices. It generates signed authorization permits that accompany control commands, enabling endpoint devices outside the secured environment to verify the authenticity and authorization of commands through cryptographic signatures, thus preventing unauthorized control actions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the security model from requiring endpoint devices to be physically located within a secured environment to using cryptographic verification. By signing authorization permits with private keys and enabling verification with public keys, the system maintains security while allowing endpoint devices to operate securely outside the protected perimeter.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If the system requires all devices to be within the secured environment, then security is maintained, but the system cannot effectively manage large quantities of distributed endpoint devices

Engineering Contradiction:
Improvesecurity complianceVSAvoidscalability to distributed devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The event generator acts as a trusted intermediary that enables secure communication between the secured control environment and untrusted distributed endpoint devices. It generates and signs authorization permits that allow endpoint devices to be managed remotely without requiring them to be physically present in the secured environment, thus enabling scalability while maintaining security compliance.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system replaces physical containment within a secured environment with cryptographic security mechanisms. By using digital signatures and authorized permits, the system maintains security compliance while enabling distributed endpoint devices to operate securely outside the physical perimeter, achieving both security and scalability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250133075A1Secured authorization for demand response
Publication Date: 2025.04.24 ITRON INC
  • US20250133075A1 patent drawing
  • US20250133075A1 patent drawing
  • US20250133075A1 patent drawing

AI summary

Techniques for secured authorization for demand response include receiving, by a first computing system from a second computing system, (1) an indicator of a demand event and (2) an authorization permit, wherein the second computing system is in a secured computing environment and the first computing system is outside of the secured computing environment; generating, by the first computing system based on the indicator of the demand event, a first demand event command for a first endpoint device; and transmitting, by the first computing system to the first endpoint device, (1) the first demand event command and (2) the authorization permit, wherein the authorization permit is usable by the first endpoint device to validate the first demand event command.