IED Configuration Authentication Using Time-Limited Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Electric power delivery systems face challenges in protecting against physical and electronic intrusions as well as errors introduced by well-meaning engineers and technicians due to the lack of robust authentication and authorization processes during the configuration and programming of intelligent electronic devices (IEDs).
Innovation Solution
Implementing a token-based authentication and authorization scheme that involves a token generating server to provide tokens for engineers, technicians, and IEDs, ensuring that only authorized individuals and devices can access and install configuration packages, with digital signatures and time windows for validation to prevent unauthorized changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional configuration methods are used without authentication, then the configuration process is simple and fast, but the system is vulnerable to unauthorized intrusions and errors
Solution Approach 1:
The system performs authentication and validation actions before allowing configuration installation. Tokens are generated in advance with embedded validation criteria, and the IED verifies these tokens before accepting any configuration changes, preventing unauthorized intrusions before they can cause harm
Solution Approach 2:
A token-based intermediary system is introduced between the configuration source and the IED. The token serves as a mediator that carries authentication and authorization information, enabling secure configuration deployment without requiring complex direct authentication mechanisms between all system components
2Reliability
If authentication and authorization tokens are implemented, then unauthorized intrusions and errors are prevented, but the configuration process becomes more complex
Solution Approach 1:
The IED automatically verifies tokens and validates configuration packages without requiring manual authentication interventions. The system self-services the authentication process by checking token validity, timestamps, and digital signatures automatically, reducing operational complexity despite enhanced security
Solution Approach 2:
The token system uses parameter changes such as time windows and device-specific identifiers to simplify authentication. Instead of complex continuous authentication, the system changes parameters by using time-limited tokens valid only within specific windows and for specific devices, making the process more manageable
3Reliability
If configuration packages are allowed to be installed without validation, then the installation process is fast, but unauthorized or modified configurations can be deployed
Solution Approach 1:
Digital signatures and validation criteria are embedded in the configuration packages during creation. The IED performs rapid verification of these pre-established validation markers, allowing fast deployment while ensuring integrity through preliminary embedding of security measures
Solution Approach 2:
The system skips detailed manual validation steps by using automated token verification and digital signature checking. This allows the configuration deployment process to rush through the validation phase quickly while still maintaining security, avoiding slow manual verification processes
Data Source
AI summary
Systems and methods are disclosed herein relating to the secure configuration of intelligent electronic devices. Intelligent electronic devices are used in electric power generation and transmission systems for protection, control, automation, and/or monitoring of equipment. The use of tokens and token-based digital signatures in the configuration process of intelligent electronic devices reduces the likelihood of malicious acts or unintended errors. Tokens distributed to engineers, technicians, intelligent electronic devices, computing devices, and/or software decrease the likelihood of errors being introduced in the configuration process.


