IED Configuration Authentication Using Time-Limited Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Electric power delivery systems face challenges in protecting against physical and electronic intrusions as well as errors introduced by well-meaning engineers and technicians due to the lack of robust authentication and authorization processes during the configuration and programming of intelligent electronic devices (IEDs).

Innovation Solution

Implementing a token-based authentication and authorization scheme that involves a token generating server to provide tokens for engineers, technicians, and IEDs, ensuring that only authorized individuals and devices can access and install configuration packages, with digital signatures and time windows for validation to prevent unauthorized changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional configuration methods are used without authentication, then the configuration process is simple and fast, but the system is vulnerable to unauthorized intrusions and errors

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs authentication and validation actions before allowing configuration installation. Tokens are generated in advance with embedded validation criteria, and the IED verifies these tokens before accepting any configuration changes, preventing unauthorized intrusions before they can cause harm

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A token-based intermediary system is introduced between the configuration source and the IED. The token serves as a mediator that carries authentication and authorization information, enabling secure configuration deployment without requiring complex direct authentication mechanisms between all system components

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication and authorization tokens are implemented, then unauthorized intrusions and errors are prevented, but the configuration process becomes more complex

Engineering Contradiction:
Improveconfiguration securityVSAvoidconfiguration process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The IED automatically verifies tokens and validates configuration packages without requiring manual authentication interventions. The system self-services the authentication process by checking token validity, timestamps, and digital signatures automatically, reducing operational complexity despite enhanced security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The token system uses parameter changes such as time windows and device-specific identifiers to simplify authentication. Instead of complex continuous authentication, the system changes parameters by using time-limited tokens valid only within specific windows and for specific devices, making the process more manageable

Inventive Principle:
Principle #35Parameter changes

3Reliability

If configuration packages are allowed to be installed without validation, then the installation process is fast, but unauthorized or modified configurations can be deployed

Engineering Contradiction:
Improveconfiguration integrityVSAvoidconfiguration deployment speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Digital signatures and validation criteria are embedded in the configuration packages during creation. The IED performs rapid verification of these pre-established validation markers, allowing fast deployment while ensuring integrity through preliminary embedding of security measures

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system skips detailed manual validation steps by using automated token verification and digital signature checking. This allows the configuration deployment process to rush through the validation phase quickly while still maintaining security, avoiding slow manual verification processes

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS11283613B2Secure control of intelligent electronic devices in power delivery systems
Publication Date: 2022.03.22 SCHWEITZER ENGINEERING LABORATORIES INC
  • US11283613B2 patent drawing
  • US11283613B2 patent drawing
  • US11283613B2 patent drawing

AI summary

Systems and methods are disclosed herein relating to the secure configuration of intelligent electronic devices. Intelligent electronic devices are used in electric power generation and transmission systems for protection, control, automation, and/or monitoring of equipment. The use of tokens and token-based digital signatures in the configuration process of intelligent electronic devices reduces the likelihood of malicious acts or unintended errors. Tokens distributed to engineers, technicians, intelligent electronic devices, computing devices, and/or software decrease the likelihood of errors being introduced in the configuration process.