Secure Gateway Enrolls IEDs via Trusted HSACD Key Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Intelligent Electronic Devices (IEDs) lack the intrinsic capabilities to enable high-level security enrollment in secure networks, particularly due to insufficient cryptographic resources and initial trust issues, hindering their communication with company networks and secure gateway devices.
Innovation Solution
A process involving trusted Highly Secured Control Access Device (HSACD) equipment generates and certifies cryptographic keys for IEDs, using user authentication through a cryptographic token and secure protocols like CMP, SCEP, or CMS, to facilitate secure network access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IEDs are equipped with cryptographic hardware and capabilities for high-level security enrollment, then security level is improved, but device complexity and cost increase
Solution Approach 1:
The patent introduces a secure gateway as an intermediary device that performs cryptographic key generation and certificate management on behalf of IEDs. The gateway acts as a mediator between the IED and the enrollment server, handling the complex cryptographic operations while the IED remains relatively simple. This resolves the contradiction by centralizing security functionality in the gateway rather than requiring it in every IED.
Solution Approach 2:
The patent extracts the cryptographic key generation and certificate enrollment functionality from the IED and places it in the secure gateway. By taking out these complex security functions from the IED, the device can maintain simplicity while still achieving high security levels through the gateway's capabilities.
2Reliability
If cryptographic material is delivered to IEDs through a controlled enrollment process, then security is improved, but enrollment time and process complexity increase
Solution Approach 1:
The patent implements preliminary action by pre-configuring the secure gateway with enrollment capabilities and pre-establishing trust relationships. The gateway is prepared in advance to handle IED enrollments, and cryptographic materials are generated and delivered in a pre-planned sequence. This reduces enrollment time by avoiding ad-hoc setup procedures.
Solution Approach 2:
The patent enables self-service enrollment where the secure gateway automatically generates cryptographic keys and manages certificate enrollment for IEDs without requiring manual intervention for each device. The system performs the enrollment process autonomously, reducing both time and operational complexity while maintaining security controls.
3Reliability
If IEDs are granted high trust level upon enrollment, then communication security is improved, but risk of unauthorized access increases if enrollment is compromised
Solution Approach 1:
The patent implements parameter changes by dynamically adjusting trust levels and security parameters based on the enrollment status and verification results. Instead of granting maximum trust immediately, the system adjusts trust parameters progressively as the IED successfully completes enrollment steps and verifies its identity. This reduces the risk of unauthorized access while maintaining communication security for authenticated devices.
4Reliability
If cryptographic keys are generated by external servers and transmitted to IEDs, then key robustness is improved, but transmission security requirements and complexity increase
Solution Approach 1:
The patent merges the key generation and transmission functions into the secure gateway, which combines the capabilities of both the IED and the external enrollment server. The gateway generates robust cryptographic keys using secure local processes and transmits them to IEDs through established secure channels. This consolidation reduces overall system complexity by eliminating the need for direct secure communication between external servers and numerous IEDs.
Data Source
Figure 1~2
Figure 3
Figure 4~5
AI summary
The invention concerns a method for enrolling a piece of equipment (IED) in a secure network to which an information system (SI) is connected, the method comprising the following steps, implemented by a trusted piece of equipment (HSACD), connected to the secure network: a) receiving (S22), from a user terminal separate from the piece of equipment to be enrolled (IED), an authorisation to connect to the piece of equipment to be enrolled (IED), b) generating (S23) cryptographic keys intended for the piece of equipment to be enrolled (IED) for accessing the secure network, and c) transmitting (S26) the cryptographic keys to the piece of equipment to be enrolled (IED).