Dual Security Authentication for 5G Smart Grid IEDs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The deployment of 5G wireless networks in smart electrical grids raises concerns about securing data exchanges between Intelligent Electronic Devices (IEDs) and application servers, as existing security measures have not adequately addressed the authentication and verification processes.

Innovation Solution

A method is proposed that employs dual security functions within the data communication system, utilizing a first security function for the EPS network and a second security function for the IP network to authenticate IEDs, involving a preconfigured database for verification and a timer to manage authentication requests, ensuring secure access to application servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dual security functions are implemented for authentication in 5G smart grid systems, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsecurity function complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process is divided into two distinct security functions: first security function for EPS network authentication and second security function for application server authentication. This segmentation allows each function to operate independently with its own security mechanisms, improving overall reliability while maintaining manageable complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an authentication management unit as an intermediary component that coordinates between the two security functions. This mediator manages the interaction between EPS network authentication and application server authentication, simplifying the complexity by providing a centralized control point rather than requiring direct integration between all security components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If equipment identifier verification is performed before authentication, then security reliability is improved, but authentication time increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The equipment identifier verification is performed as a preliminary check before the main authentication process. By validating the equipment identifier in advance against the database, the system ensures that only registered equipment proceeds to full authentication, improving security reliability while minimizing time loss through early filtering of unauthorized devices.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3840443A1Method for managing authentication of an equipment in a system for data communication and a system for performing said method.
Publication Date: 2021.06.23 ELECTRICITE DE FRANCE
  • EP3840443A1 patent drawingFigure 1~2a
  • EP3840443A1 patent drawingFigure 2b~2c
  • EP3840443A1 patent drawingFigure 3

AI summary

A method for managing the authentication of equipment in a data communication system for the exchange of data between the equipment and an application server of the system, the system comprising a first data communication network using a first security function to secure data communications within the first network, operationally coupled to a second data communication network using a second security function to secure data communications within the second network, is proposed, which includes, in an authentication management unit of the system implemented in a node of the second communication network: receiving an authentication request from the equipment according to the second security function for access to the application server;determine if an equipment identifier in the first communication network has been received following the receipt of an equipment authentication request according to the second function; and when the equipment identifier has not been received, generate an equipment authentication failure response.