Event-Driven Key Management in Smart Grids

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current key management systems in smart grids face challenges due to lack of processing power, random-number generation resources, and inadequate communication capabilities in devices, leading to difficulties in implementing end-to-end data security, especially with asymmetric cipher systems being computationally intensive and requiring robust strategic management across multiple business systems.

Innovation Solution

A security management system comprising a key management sub-system, an asset/workload management sub-system, and an event management sub-system that automatically orchestrates key creation, revocation, and refresh across impacted components, ensuring end-to-end data security by correlating events with assets and facilitating key management operations across diverse business systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If asymmetric cipher systems are used for key management in smart grid devices, then security is improved, but computational resource consumption increases significantly

Engineering Contradiction:
Improvedata securityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent divides key management into two segments: asymmetric keys for initial secure channel establishment and symmetric keys for ongoing data protection. This segmentation allows the computationally intensive asymmetric operations to be performed only once during key exchange, while less resource-intensive symmetric operations handle the bulk of data security requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a key management server as an intermediary that performs the computationally intensive asymmetric key generation and exchange operations centrally. Field devices with limited resources can rely on this intermediary to handle the heavy computational burden, while still benefiting from strong asymmetric key-based security for establishing secure communication channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If robust key management schemes are implemented across multiple business systems, then end-to-end data security is improved, but system complexity increases

Engineering Contradiction:
Improveend-to-end data securityVSAvoidkey management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal key management framework that works across multiple business systems and vendors through standardized interfaces and protocols. The key management server provides multi-functional capabilities including key generation, distribution, rotation, and revocation that can serve diverse applications (billing, control, monitoring) without requiring separate key management implementations for each system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The key management server acts as a central intermediary that simplifies complex key management across multiple systems. Instead of each business system implementing its own key management, the intermediary handles all key-related operations centrally, reducing the complexity burden on individual systems while maintaining end-to-end security across the entire smart grid infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If cryptographic key management is implemented in field devices with limited resources, then data security is improved, but device processing requirements increase

Engineering Contradiction:
Improvecryptographic key managementVSAvoiddevice processing power
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent introduces a key management server as an intermediary that performs the computationally intensive cryptographic operations centrally. Field devices with limited processing power can rely on this intermediary to handle key generation, exchange, and management, while still benefiting from strong cryptographic security. The intermediary performs asymmetric key operations that would be too resource-intensive for constrained field devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments cryptographic operations between the key management server and field devices. The server handles asymmetric key generation and exchange (computationally intensive), while field devices perform symmetric encryption/decryption (less resource-intensive) using keys obtained from the server. This segmentation allows field devices to maintain strong security without requiring high processing power.

Inventive Principle:
Principle #1Segmentation

4Productivity

If symmetric cipher systems are used for key management, then computational efficiency is improved, but coordination requirements between key producer and consumers increase

Engineering Contradiction:
Improvecomputational efficiencyVSAvoidcoordination among key producer and consumers
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The key management server acts as a central intermediary that automatically coordinates symmetric key distribution among multiple consumers. Instead of requiring direct coordination between key producers and consumers, the intermediary receives key material from producers and automatically distributes appropriate keys to all authorized consumers, simplifying the coordination process while maintaining computational efficiency of symmetric operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9584314B2Event-driven, asset-centric key management in a smart grid
Publication Date: 2017.02.28 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9584314B2 patent drawing
  • US9584314B2 patent drawing
  • US9584314B2 patent drawing

AI summary

A security management system comprises a key management sub-system, an asset/workload management sub-system, and an event management sub-system. The event management sub-system detects events. The asset/workload management sub-system correlates events (irrespective of type) with the assets that generate them, and the key management sub-system uses the event-asset associations determined by the asset/workload management sub-system to automatically orchestrate the necessary key management activities (e.g., key creation, revocation, refresh, etc.) across the impacted components in the information technology and operational realms to ensure data security. In one use case, a security event detected by the event management sub-system triggers one or more actions within the asset/workload management sub-system. Service configuration records are identified from this scan, and assets defined in those records are identified. An event-asset association is then supplied to the key management sub-system, which uses this information to determine a key management operation.