Demand Response Authorization Permits for Secure Endpoint Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing demand response management systems (DRMS) face challenges in securely generating and managing demand response control events, leading to issues such as unintentional or unauthorized actions by endpoint devices, which can negatively impact the electrical system.
Innovation Solution
A secure DRMS is implemented, featuring an event generator within a secure environment that authenticates operators and processes demand response control event requests. The system generates secure messages, including signed event indications and authorization permits, to ensure the authenticity and authorization of demand response events.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If demand response control events are generated without secure authorization, then the system can respond quickly to forecasted energy supply issues, but the system risks unintentional or unauthorized actions that negatively impact the electrical system
Solution Approach 1:
The system performs preliminary authentication of the operator and validation of the demand response control event request before generating the event. The event generator validates the request against policies and generates signed authorization permits in advance, ensuring that only authorized and valid events are executed, thereby preventing unintentional or unauthorized actions.
Solution Approach 2:
The event generator acts as an intermediary between the operator and the endpoint devices. It receives control requests, validates them against policies, generates signed authorization permits, and only then transmits the control events to endpoint devices. This intermediary layer ensures security and authorization without requiring complex security systems at every endpoint device.
2Reliability
If the system implements comprehensive security validation for all demand response events, then unauthorized actions are prevented, but the response time to address energy supply issues increases
Solution Approach 1:
The system performs authentication and validation in advance before the actual demand response event is needed. The event generator authenticates the operator and validates the control request beforehand, generating signed authorization permits that enable rapid execution of approved events without repeated validation delays.
Solution Approach 2:
The system replaces manual or repeated mechanical validation processes with automated cryptographic verification. Endpoint devices can quickly verify the authenticity of control events by checking digital signatures against published public keys, eliminating the need for time-consuming interactive authentication during event execution.
3Adaptability or versatility
If endpoint devices operate outside the secured computing environment, then the system can control large quantities of distributed devices, but the risk of receiving unauthorized commands increases
Solution Approach 1:
The event generator serves as a secure intermediary that bridges the trusted control center and untrusted endpoint devices. It generates signed authorization permits that accompany control commands, enabling endpoint devices outside the secured environment to verify the authenticity and authorization of commands through cryptographic signatures, thus preventing unauthorized control actions.
Solution Approach 2:
The system changes the security model from requiring endpoint devices to be physically located within a secured environment to using cryptographic verification. By signing authorization permits with private keys and enabling verification with public keys, the system maintains security while allowing endpoint devices to operate securely outside the protected perimeter.
4Reliability
If the system requires all devices to be within the secured environment, then security is maintained, but the system cannot effectively manage large quantities of distributed endpoint devices
Solution Approach 1:
The event generator acts as a trusted intermediary that enables secure communication between the secured control environment and untrusted distributed endpoint devices. It generates and signs authorization permits that allow endpoint devices to be managed remotely without requiring them to be physically present in the secured environment, thus enabling scalability while maintaining security compliance.
Solution Approach 2:
The system replaces physical containment within a secured environment with cryptographic security mechanisms. By using digital signatures and authorized permits, the system maintains security compliance while enabling distributed endpoint devices to operate securely outside the physical perimeter, achieving both security and scalability.
Data Source
AI summary
Techniques for secured authorization for demand response include receiving, by a first computing system from a second computing system, (1) an indicator of a demand event and (2) an authorization permit, wherein the second computing system is in a secured computing environment and the first computing system is outside of the secured computing environment; generating, by the first computing system based on the indicator of the demand event, a first demand event command for a first endpoint device; and transmitting, by the first computing system to the first endpoint device, (1) the first demand event command and (2) the authorization permit, wherein the authorization permit is usable by the first endpoint device to validate the first demand event command.


