Grid Edge Node Cryptographic Renewal for Secure Utility Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Field-deployed computer resources of utility grids, including microgrids, suffer from severe cybersecurity deficiencies such as a lack of cryptographic identity and limited application-patching capabilities.

Innovation Solution

A method of securely controlling utility grid edge devices by receiving renewed security information at a node with cryptographic circuitry and using this information to control the operation of the device, thereby enhancing cybersecurity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional control methods are used for utility grid edge devices, then device operation can be maintained, but cybersecurity deficiencies persist including lack of cryptographic identity and limited application-patching capabilities

Engineering Contradiction:
ImprovecybersecurityVSAvoidsecurity infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-provisioning edge devices with cryptographic identities and security certificates before deployment. The system establishes security infrastructure in advance, including digital certificates and cryptographic keys, so that devices are secured from the moment they are deployed rather than requiring retroactive security implementation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments security management into distinct components: cryptographic circuitry for key generation and storage, certificate authorities for identity issuance, and distributed security policies. This segmentation allows each component to be optimized independently and enables modular updates to security mechanisms without affecting the entire system.

Inventive Principle:
Principle #1Segmentation

2Reliability

If security information is renewed frequently to maintain security, then cybersecurity is enhanced, but communication overhead and processing time increase

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements periodic action through scheduled security information renewal at predetermined intervals. Edge devices automatically renew their cryptographic credentials and security certificates before expiration according to established time schedules, ensuring continuous security coverage while optimizing the balance between security freshness and communication efficiency.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system performs preliminary security information renewal by initiating the renewal process before existing security credentials expire. This proactive approach ensures uninterrupted security coverage and avoids the time loss that would occur if renewal had to wait for credential expiration or failure.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If cryptographic circuitry is deployed at edge devices to provide security, then cryptographic identity is established, but device cost and complexity increase

Engineering Contradiction:
Improvecryptographic identityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by implementing cryptographic circuitry selectively at specific edge devices based on their security requirements and sensitivity of operations. Not all edge devices receive identical security hardware - instead, cryptographic capabilities are deployed where locally needed, optimizing the balance between security and cost.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces certificate authorities and security management servers as intermediaries that handle complex cryptographic operations centrally. Edge devices with cryptographic circuitry can leverage these intermediary services for key management, certificate issuance, and security policy enforcement, reducing the burden on individual device hardware.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If security information is stored at edge devices, then cryptographic operations can be performed locally, but security vulnerabilities increase if the information is compromised

Engineering Contradiction:
Improvelocal cryptographic operationsVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies beforehand cushioning by implementing redundant security mechanisms and backup cryptographic credentials. Edge devices maintain multiple certificates and keys, and the system provides fallback authentication methods, so that if one security credential is compromised, other protective layers remain intact to maintain security coverage.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

The patent implements discarding and recovering by automatically invalidating and replacing compromised security credentials. When cryptographic information is suspected to be compromised or expires, the system discards the vulnerable credentials and recovers security by issuing fresh certificates and keys, ensuring that compromised information cannot be exploited long-term.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentUS12244143B2Methods of securely controlling utility grid edge devices
Publication Date: 2025.03.04 OPEN ENERGY SOLUTIONS INC
  • US12244143B2 patent drawing
  • US12244143B2 patent drawing
  • US12244143B2 patent drawing

AI summary

Methods of securely controlling a utility grid edge device are provided. A method of securely controlling a utility grid edge device includes receiving renewed security information at a node that includes cryptographic circuitry. Moreover, the method includes controlling an operation of the utility grid edge device via the node, after receiving the renewed security information. Related nodes and utility grid edge devices are also provided.