Centralized Access Rights Distribution for Intelligent Electronic Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The administration of access rights in distributed network control systems is complex and time-consuming due to the need for individual configuration of user accounts on each intelligent device, making it difficult to manage and distribute access rights across multiple devices.
Innovation Solution
A method and device that utilize a shared common key and device-internal key to encrypt and decrypt user accounts, allowing for simultaneous distribution of access rights across multiple intelligent devices within a distributed system, minimizing the effort required for managing user accounts and preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If password protection is configured individually for each device, then security is maintained, but the administration of access rights becomes time-consuming and complex
Solution Approach 1:
The patent combines multiple individual device configurations into a single centralized user account that can be distributed to multiple devices simultaneously. The control center consolidates the management of access rights across the entire distributed system, allowing one configuration action to affect multiple devices at once, thereby reducing administration time while maintaining security through centralized control
Solution Approach 2:
The user account is designed to be universal across multiple device types and functions within the distributed system. A single user account can be configured once and then distributed to various intelligent electronic devices (IEDs), RTUs, and other components, enabling the same access rights management mechanism to serve multiple purposes and devices simultaneously
2Reliability
If user accounts are stored in encrypted format in each device, then unauthorized access is prevented, but the configuration changes become very complex
Solution Approach 1:
The patent extracts the encryption and decryption operations from individual device configurations and centralizes them in the control center. The control center handles the secure generation, distribution, and updating of encrypted user accounts, while individual devices simply receive and store the pre-encrypted credentials, significantly simplifying device-level configuration while maintaining strong security
Solution Approach 2:
The control center acts as an intermediary between the administrator and individual devices in the distributed system. It manages the complex encryption, decryption, and distribution of user accounts, shielding individual devices from the complexity of security management while ensuring that encrypted credentials are properly handled and distributed throughout the system
3Ease of operation
If access rights are changed on each device separately, then precise control is achieved, but the process becomes extremely time-consuming
Solution Approach 1:
The patent merges multiple individual configuration operations into a single centralized action. When access rights need to be changed, the administrator makes one modification in the control center that automatically propagates to all affected devices simultaneously, maintaining precise control over access rights while dramatically increasing configuration speed and productivity
Solution Approach 2:
The control center performs preliminary configuration and validation of user accounts before distribution to individual devices. By pre-configuring access rights centrally and then distributing them automatically, the system eliminates the need for repetitive manual configuration on each device, thereby speeding up the overall process while maintaining control precision
Data Source
Figure 1
Figure 2
AI summary
The method involves encrypting a password file of an intelligent electronic device using a shared key (A) into a web client (40) before reading the file, and providing the encrypted file to the client for transmitting to other intelligent electronic devices (21-23). The encrypted file is distributed by the client to the other intelligent devices over a network connection (30), and data stored in the encrypted file is decrypted in the other intelligent devices using the key. The password file is encrypted and stored with the data in the other devices by device-internal keys (B1-B3). An independent claim is also included for a system for configuring and distributing access rights, comprising an intelligent electronic device connected with other intelligent electronic devices by a web client over a network connection.