Dual Security Authentication for 5G Smart Grid IEDs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The deployment of 5G wireless networks in smart electrical grids raises concerns about securing data exchanges between Intelligent Electronic Devices (IEDs) and application servers, as existing security measures have not adequately addressed the authentication and verification processes.
Innovation Solution
A method is proposed that employs dual security functions within the data communication system, utilizing a first security function for the EPS network and a second security function for the IP network to authenticate IEDs, involving a preconfigured database for verification and a timer to manage authentication requests, ensuring secure access to application servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dual security functions are implemented for authentication in 5G smart grid systems, then security reliability is improved, but device complexity increases
Solution Approach 1:
The authentication process is divided into two distinct security functions: first security function for EPS network authentication and second security function for application server authentication. This segmentation allows each function to operate independently with its own security mechanisms, improving overall reliability while maintaining manageable complexity through modular design.
Solution Approach 2:
The patent introduces an authentication management unit as an intermediary component that coordinates between the two security functions. This mediator manages the interaction between EPS network authentication and application server authentication, simplifying the complexity by providing a centralized control point rather than requiring direct integration between all security components.
2Reliability
If equipment identifier verification is performed before authentication, then security reliability is improved, but authentication time increases
Solution Approach 1:
The equipment identifier verification is performed as a preliminary check before the main authentication process. By validating the equipment identifier in advance against the database, the system ensures that only registered equipment proceeds to full authentication, improving security reliability while minimizing time loss through early filtering of unauthorized devices.
Data Source
Figure 1~2a
Figure 2b~2c
Figure 3
AI summary
A method for managing the authentication of equipment in a data communication system for the exchange of data between the equipment and an application server of the system, the system comprising a first data communication network using a first security function to secure data communications within the first network, operationally coupled to a second data communication network using a second security function to secure data communications within the second network, is proposed, which includes, in an authentication management unit of the system implemented in a node of the second communication network: receiving an authentication request from the equipment according to the second security function for access to the application server;determine if an equipment identifier in the first communication network has been received following the receipt of an equipment authentication request according to the second function; and when the equipment identifier has not been received, generate an equipment authentication failure response.