Entropy Device for Secure MACsec Key Generation in Power Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing a secure communication link between intelligent electronic devices (IEDs) in electric power distribution systems is challenging due to difficulties in ensuring the integrity and confidentiality of data transmission.
Innovation Solution
The implementation of an entropy device that generates and distributes input entropy data, allowing IEDs to generate keys for establishing Media Access Control Security (MACsec) communication links, enabling secure communication even when the entropy device is not directly connected or available.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an entropy device is used to generate and distribute keys for MACsec communication links, then communication security is improved, but device complexity and dependency increase
Solution Approach 1:
The entropy device generates and distributes entropy data in advance before secure communication is needed. This preliminary action allows IEDs to have the necessary entropy data stored locally, enabling them to generate cryptographic keys independently when needed, thus improving communication security without requiring the entropy device to be continuously available or directly connected.
Solution Approach 2:
Instead of copying the entropy device itself to each IED, the patent copies the essential entropy data to multiple IEDs. Each IED independently generates cryptographic keys from the received entropy data, eliminating the need for multiple entropy devices while maintaining security. This reduces overall system complexity while preserving the security benefits.
2Reliability
If direct connection to entropy device is required for key generation, then key security is improved, but system availability deteriorates when entropy device is unavailable
Solution Approach 1:
The system performs preliminary action by distributing entropy data to IEDs in advance through a secure channel. Once received, each IED stores the entropy data locally and can independently generate cryptographic keys without requiring continuous connection to the entropy device. This ensures both key security (through secure initial distribution) and system availability (through independent local key generation).
Solution Approach 2:
The entropy data acts as an intermediary that transfers the security function from the central entropy device to distributed IEDs. The entropy data carries the necessary randomness information, enabling IEDs to generate secure keys independently. This intermediary approach maintains the security benefits of centralized entropy generation while achieving distributed operational independence.
3Productivity
If entropy data is distributed to multiple IEDs, then communication link establishment is improved, but data transmission security requirements increase
Solution Approach 1:
The entropy data is distributed in advance through a secure communication channel before it is needed for key generation. This preliminary secure distribution ensures that the entropy data itself is protected during transmission. Once distributed, the data enables rapid local key generation at multiple IEDs, achieving both fast communication link establishment and maintained security through the initial protected transmission.
Data Source
AI summary
A system includes an entropy device configured to generate and distribute input entropy data and an intelligent electronic device (IED) of an electric power distribution system. The IED is configured to perform operations that include receiving the input entropy data distributed by the entropy device, generating a set of keys using the input entropy data, and establishing a Media Access Control Security (MACsec) communication link using the set of keys.


