Entropy Device for Secure MACsec Key Generation in Power Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Establishing a secure communication link between intelligent electronic devices (IEDs) in electric power distribution systems is challenging due to difficulties in ensuring the integrity and confidentiality of data transmission.

Innovation Solution

The implementation of an entropy device that generates and distributes input entropy data, allowing IEDs to generate keys for establishing Media Access Control Security (MACsec) communication links, enabling secure communication even when the entropy device is not directly connected or available.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an entropy device is used to generate and distribute keys for MACsec communication links, then communication security is improved, but device complexity and dependency increase

Engineering Contradiction:
Improvecommunication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The entropy device generates and distributes entropy data in advance before secure communication is needed. This preliminary action allows IEDs to have the necessary entropy data stored locally, enabling them to generate cryptographic keys independently when needed, thus improving communication security without requiring the entropy device to be continuously available or directly connected.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of copying the entropy device itself to each IED, the patent copies the essential entropy data to multiple IEDs. Each IED independently generates cryptographic keys from the received entropy data, eliminating the need for multiple entropy devices while maintaining security. This reduces overall system complexity while preserving the security benefits.

Inventive Principle:
Principle #26Copying

2Reliability

If direct connection to entropy device is required for key generation, then key security is improved, but system availability deteriorates when entropy device is unavailable

Engineering Contradiction:
Improvekey securityVSAvoidsystem availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary action by distributing entropy data to IEDs in advance through a secure channel. Once received, each IED stores the entropy data locally and can independently generate cryptographic keys without requiring continuous connection to the entropy device. This ensures both key security (through secure initial distribution) and system availability (through independent local key generation).

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The entropy data acts as an intermediary that transfers the security function from the central entropy device to distributed IEDs. The entropy data carries the necessary randomness information, enabling IEDs to generate secure keys independently. This intermediary approach maintains the security benefits of centralized entropy generation while achieving distributed operational independence.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If entropy data is distributed to multiple IEDs, then communication link establishment is improved, but data transmission security requirements increase

Engineering Contradiction:
Improvecommunication link establishment speedVSAvoiddata transmission security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The entropy data is distributed in advance through a secure communication channel before it is needed for key generation. This preliminary secure distribution ensures that the entropy data itself is protected during transmission. Once distributed, the data enables rapid local key generation at multiple IEDs, achieving both fast communication link establishment and maintained security through the initial protected transmission.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11502825B2Systems and methods for using entropy data in an electric power distribution system
Publication Date: 2022.11.15 SCHWEITZER ENGINEERING LABORATORIES INC
  • US11502825B2 patent drawing
  • US11502825B2 patent drawing
  • US11502825B2 patent drawing

AI summary

A system includes an entropy device configured to generate and distribute input entropy data and an intelligent electronic device (IED) of an electric power distribution system. The IED is configured to perform operations that include receiving the input entropy data distributed by the entropy device, generating a set of keys using the input entropy data, and establishing a Media Access Control Security (MACsec) communication link using the set of keys.