Energy Management System Security via Segmented Network Gateway
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The next-generation power network's Energy Management System (EMS) faces security risks due to illegal access threats from the Internet, as conventional security measures like intrusion detection systems are impractical for systems that require low latency and real-time communication with power systems, potentially disrupting power control and supply-demand balance.
Innovation Solution
The EMS employs a dual-network interface configuration with a policy-based access control system, where applications are registered and permitted to access specific network interfaces based on stored policies, preventing unauthorized access without affecting power control operations, and utilizing a CIM database to manage network topology and access permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security measures like intrusion detection systems are installed on the EMS, then security against illegal access is improved, but system complexity and processing load increase significantly
Solution Approach 1:
The patent divides the security function into a separate network gateway device that operates independently from the EMS. The gateway handles all security-related processing including intrusion detection, while the EMS focuses on power management. This segmentation prevents security processing from adding complexity to the EMS system while maintaining robust security through a dedicated security appliance.
2Reliability
If intrusion detection systems are installed on the EMS, then security is improved, but latency increases and real-time power control is affected
Solution Approach 1:
By separating the intrusion detection system from the EMS into an independent gateway device, security processing occurs in parallel without interfering with the EMS's real-time power control operations. The gateway handles security traffic while the EMS maintains its low-latency response for power management tasks.
Solution Approach 2:
The network gateway acts as an intermediary between external networks and the EMS. It filters and secures traffic before it reaches the EMS, allowing the EMS to operate at full speed without processing security-related overhead. The gateway absorbs all security processing latency while the EMS experiences no delay.
3Reliability
If the EMS performs complicated security processes, then security detection capability is improved, but power control performance deteriorates
Solution Approach 1:
The patent assigns security detection functions to a dedicated gateway device while the EMS focuses exclusively on power control productivity. This functional segmentation allows the gateway to perform comprehensive security analysis without impacting the EMS's ability to rapidly respond to power management needs.
Solution Approach 2:
The gateway serves as an intermediary that handles all security detection and filtering operations. It preprocesses and secures traffic before forwarding it to the EMS, enabling the EMS to maintain high power control performance while the gateway performs thorough security inspections on external communications.
4Adaptability or versatility
If the EMS is connected to the Internet for maintenance and power demand prediction, then system functionality is improved, but vulnerability to illegal access increases
Solution Approach 1:
The network gateway acts as a protective intermediary between the Internet and the EMS. It enables the EMS to access Internet resources for maintenance and power demand prediction while blocking illegal access attempts. The gateway filters traffic bidirectionally, allowing legitimate functionality while preventing harmful factors from reaching the EMS.
Solution Approach 2:
The system separates network access functions into the gateway while keeping the EMS isolated from direct Internet exposure. This segmentation allows the EMS to gain Internet connectivity for necessary functions through the gateway's controlled access, reducing vulnerability while maintaining adaptability.
Data Source
AI summary
An energy management system has an application storage, an application executing unit, a plurality of network interfaces, a policy setting unit configured to set whether each application should be permitted to access each of the network interfaces, a policy storage configured to store identification information for each application set by the policy setting unit, and access permit/inhibit information showing whether the application is permitted to access each of the network interfaces, an I/F management unit managing a correspondence relationship between a network address and each of the network interfaces, and to specify a network interface used by the application executed by the application executing unit, and an access controller configured to judge whether the application executed by the application executing unit is permitted to access the network interface to be used thereby, based on the access permit/inhibit information stored in the policy storage.


