Communication Gateway Physical Intrusion Detection and Security Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unauthorized physical access to enclosures containing intelligent electronic devices (IEDs) in electric power delivery systems poses a significant security risk, as these devices often have unencrypted communication channels and can be compromised, potentially leading to disruptions or changes in IED settings.

Innovation Solution

A communication gateway is implemented with physical access detection capabilities, which detects unauthorized access and takes security actions such as blocking untrusted communications, logging all communications, and adjusting cybersecurity profiles to an elevated state, ensuring that communications from compromised devices are no longer trusted and are quarantined.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical access detection and security response mechanisms are implemented in communication gateways, then security against unauthorized access is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by detecting physical access attempts before unauthorized communication can occur. The physical intrusion detection system continuously monitors for unauthorized access and triggers security responses in advance, preventing potential compromises rather than reacting after damage occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The communication gateway acts as an intermediary between the IED and the network. It includes a physical intrusion detection system and security response mechanisms that mediate all communications, blocking suspicious traffic and preventing direct access to the IED while allowing legitimate communications to pass through.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If communications are encrypted to protect against unauthorized access, then security is improved, but communication overhead and processing time increase

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The encrypted communication channel serves as a secure intermediary layer between the IED and the network. All communications pass through this encrypted channel, which protects against eavesdropping and unauthorized access while maintaining relatively efficient communication protocols that minimize overhead.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9130945B2Detection and response to unauthorized access to a communication device
Publication Date: 2015.09.08 SCHWEITZER ENGINEERING LABORATORIES INC
  • US9130945B2 patent drawing
  • US9130945B2 patent drawing
  • US9130945B2 patent drawing

AI summary

A communication gateway consistent with the present disclosure may detect unauthorized physical or electronic access and implement security actions in response thereto. A communication gateway may provide a communication path to an intelligent electronic device (IED) using an IED communications port configured to communicate with the IED. The communication gateway may include a physical intrusion detection port and a network port. The communication gateway may further include control logic configured to evaluate physical intrusion detection signal. The control logic may be configured to determine that the physical intrusion detection signal is indicative of an attempt to obtain unauthorized access to one of the communication gateway, the IED, and a device in communication with the gateway; and take a security action based upon the determination that the indication is indicative of the attempt to gain unauthorized access.