Automated IED Enrollment via Configuration Tool
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for registering intelligent electronic devices with a certification authority are labor-intensive and error-prone, particularly in securely distributing one-time passwords for certificate enrollment, which is crucial for ensuring only valid devices receive certificates in secure communication networks like Smart Grid systems.
Innovation Solution
A method involving a configuration tool that enrolls with a certification authority, generates and securely distributes one-time passwords to intelligent electronic devices, establishing a trusted connection for secure enrollment and certificate issuance, compliant with standards like IEC 62351-9, using protocols like SCEP and EST for scalable and secure certificate management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If one-time passwords are manually distributed to each intelligent electronic device via configuration tools and storage media, then security is maintained, but labor intensity and error rate increase significantly
Solution Approach 1:
The system enables self-service by allowing intelligent electronic devices to automatically obtain one-time passwords through standardized protocols (SCEP, EST) without requiring manual configuration. The devices can autonomously enroll with certification authorities and receive cryptographic credentials, eliminating the need for manual password distribution while maintaining security.
Solution Approach 2:
The patent implements universal enrollment mechanisms that work across multiple device types and certification authority systems through standardized protocols. A single configuration approach can enroll diverse intelligent electronic devices (IEDs) with different manufacturers and models, replacing the need for device-specific manual configuration procedures.
2Reliability
If manual configuration methods are used to distribute registration data, then security control is maintained, but time consumption and operational complexity increase
Solution Approach 1:
The system performs preliminary actions by pre-configuring certification authorities with enrollment protocols and pre-establishing trusted communication channels. Intelligent electronic devices come pre-loaded with enrollment capabilities and can immediately begin the automated enrollment process upon activation, eliminating time-consuming manual configuration steps.
Solution Approach 2:
The patent replaces mechanical manual operations (physically connecting storage media, manually typing passwords) with automated electronic processes. Configuration tools communicate electronically with certification authorities through standardized protocols, automatically transmitting registration data and one-time passwords without human intervention.
3Productivity
If automated enrollment protocols like SCEP and EST are implemented, then productivity increases, but system complexity and implementation difficulty increase
Solution Approach 1:
The patent introduces configuration tools as intermediaries that simplify the enrollment process. These tools handle the complexity of implementing standardized protocols (SCEP, EST) by providing pre-configured software solutions that automatically manage certificate enrollment, key generation, and credential distribution, shielding end users from protocol complexity.
Solution Approach 2:
The system changes implementation parameters by adopting industry-standard protocols with well-defined parameters and procedures. By following established standards for enrollment messages, cryptographic key lengths, and communication formats, the system achieves automated enrollment without requiring custom complex implementations, reducing overall system complexity.
Data Source
Figure 1~2
AI summary
A method for registering an intelligent electronic device (14) with a certification authority (16) comprises: enrolling a configuration tool (12) at the certification authority (16); generating a one-time password (28) for the intelligent electronic device (14) and storing the one-time password (28) in the certification authority (16) and in the configuration tool (20); connecting to the intelligent electronic device (14) with the configuration tool (20), wherein the configuration tool (20) authenticates at the intelligent electronic device (14); sending the one-time password (28) from the configuration tool (20) to the intelligent electronic device (14); enrolling the intelligent electronic device (14) at the certification authority (16) with the one-time password (28) and registering the intelligent electronic device (14) with the certification authority (16); and receiving a device certificate (34) from the certification authority (16) in the intelligent electronic device (14).