Endpoint Communication Security via Internal Pairing Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Metering networks in resource management systems, such as electricity, are vulnerable to tampering due to unsecured communication within endpoints, which can lead to unauthorized access and destabilization of the distribution grid, as existing security solutions primarily focus on securing communication from the head-end system to the endpoint without ensuring secure communication within the endpoint itself.

Innovation Solution

A method is implemented to establish a secure communication channel within a meter by exchanging pairing keys between a communication module and a metrology module via an external communication path, ensuring secure data exchange and preventing unauthorized access, while maintaining uninterrupted network flow.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Area of stationary object

If meters are geographically dispersed to enable resource monitoring at multiple locations, then the coverage and utility of the metering network is improved, but the vulnerability to tampering and security breaches increases

Engineering Contradiction:
Improvecoverage areaVSAvoidvulnerability to tampering
Core Design Contradiction:
Area of stationary objectVSObject-affected harmful factors

Solution Approach 1:

The meter is divided into separate functional modules (communication module and metrology module) that can be independently secured. Each module can have its own security credentials and authentication mechanisms, allowing security to be enforced at the module level rather than requiring security for the entire dispersed network infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Security credentials and paired channels are established before the modules are physically connected or before communication begins. This preliminary security setup prevents tampering during operation, as any attempt to intercept or alter communication would be detected against the pre-established security credentials.

Inventive Principle:
Principle #9Preliminary anti-action

2Reliability

If security measures are implemented at the endpoint to protect against tampering, then the security of internal communication is improved, but the complexity of the endpoint device increases

Engineering Contradiction:
Improvesecurity of internal communicationVSAvoidendpoint device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security functionality is merged into the existing communication module rather than adding separate security hardware or software layers. The communication module handles both communication protocols and security credential verification, reducing overall device complexity while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The communication module serves multiple functions: it handles data communication with the head-end system, manages security credential storage, performs authentication, and establishes paired channels. This multi-functionality reduces the need for separate dedicated security components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If paired channels with pairing keys are established between communication module and metrology module, then the security of internal data exchange is improved, but the time required for module pairing and setup increases

Engineering Contradiction:
Improvesecurity of module communicationVSAvoidpairing setup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Pairing keys and security credentials are pre-configured in the modules before deployment or before physical connection. This preliminary action eliminates the need for time-consuming pairing procedures at installation, as the security relationship is already established when modules are brought together.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The modules automatically perform authentication and establish paired channels using their pre-configured credentials without requiring manual intervention or complex pairing procedures. The security setup is self-service, reducing both time and complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3053324B2Securing communication within a network endpoint
Publication Date: 2020.12.09 LANDIS & GYR INNOVATIONS INC
  • EP3053324B2 patent drawingFigure 1
  • EP3053324B2 patent drawingFigure 2
  • EP3053324B2 patent drawingFigure 3

AI summary

Systems and methods for securing communication within a network endpoint, for example, a meter. The meter may include a communication module and a metrology module where the modules are connected via a communication path that is external to both modules. The modules exchange a pairing key to establish a paired channel of communication. When the communication module receives a communication through a network for establishing a secure channel to the endpoint, the communications module sends some or all of the security data to the metrology module to establish a secure communication from a head-end system through the communication module to the metrology module.