Automated IED Enrollment via Configuration Tool

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for registering intelligent electronic devices with a certification authority are labor-intensive and error-prone, particularly in securely distributing one-time passwords for certificate enrollment, which is crucial for ensuring only valid devices receive certificates in secure communication networks like Smart Grid systems.

Innovation Solution

A method involving a configuration tool that enrolls with a certification authority, generates and securely distributes one-time passwords to intelligent electronic devices, establishing a trusted connection for secure enrollment and certificate issuance, compliant with standards like IEC 62351-9, using protocols like SCEP and EST for scalable and secure certificate management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If one-time passwords are manually distributed to each intelligent electronic device via configuration tools and storage media, then security is maintained, but labor intensity and error rate increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidlabor efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service by allowing intelligent electronic devices to automatically obtain one-time passwords through standardized protocols (SCEP, EST) without requiring manual configuration. The devices can autonomously enroll with certification authorities and receive cryptographic credentials, eliminating the need for manual password distribution while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements universal enrollment mechanisms that work across multiple device types and certification authority systems through standardized protocols. A single configuration approach can enroll diverse intelligent electronic devices (IEDs) with different manufacturers and models, replacing the need for device-specific manual configuration procedures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If manual configuration methods are used to distribute registration data, then security control is maintained, but time consumption and operational complexity increase

Engineering Contradiction:
Improvesecurity controlVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring certification authorities with enrollment protocols and pre-establishing trusted communication channels. Intelligent electronic devices come pre-loaded with enrollment capabilities and can immediately begin the automated enrollment process upon activation, eliminating time-consuming manual configuration steps.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces mechanical manual operations (physically connecting storage media, manually typing passwords) with automated electronic processes. Configuration tools communicate electronically with certification authorities through standardized protocols, automatically transmitting registration data and one-time passwords without human intervention.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If automated enrollment protocols like SCEP and EST are implemented, then productivity increases, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improveenrollment efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces configuration tools as intermediaries that simplify the enrollment process. These tools handle the complexity of implementing standardized protocols (SCEP, EST) by providing pre-configured software solutions that automatically manage certificate enrollment, key generation, and credential distribution, shielding end users from protocol complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes implementation parameters by adopting industry-standard protocols with well-defined parameters and procedures. By following established standards for enrollment messages, cryptographic key lengths, and communication formats, the system achieves automated enrollment without requiring custom complex implementations, reducing overall system complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3258662B1Secure efficient registration of industrial intelligent electronic devices
Publication Date: 2019.10.30 ABB (SCHWEIZ) AG
  • EP3258662B1 patent drawingFigure 1~2

AI summary

A method for registering an intelligent electronic device (14) with a certification authority (16) comprises: enrolling a configuration tool (12) at the certification authority (16); generating a one-time password (28) for the intelligent electronic device (14) and storing the one-time password (28) in the certification authority (16) and in the configuration tool (20); connecting to the intelligent electronic device (14) with the configuration tool (20), wherein the configuration tool (20) authenticates at the intelligent electronic device (14); sending the one-time password (28) from the configuration tool (20) to the intelligent electronic device (14); enrolling the intelligent electronic device (14) at the certification authority (16) with the one-time password (28) and registering the intelligent electronic device (14) with the certification authority (16); and receiving a device certificate (34) from the certification authority (16) in the intelligent electronic device (14).