Security Management Unit Location Verification for Smart Grid IEDs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The deployment of 5G networks in smart electrical grids poses security risks due to equipment remaining in standby mode for extended periods, making it vulnerable to security attacks during inactive periods.

Innovation Solution

A security management method that involves obtaining and comparing first and second location information of intelligent electronic devices (IEDs) to verify their authenticity, generating a refusal of access if the information does not match, thereby preventing unauthorized access and potential security attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Use of energy by moving object

If equipment remains in standby mode for extended periods to conserve energy, then energy consumption is reduced, but security vulnerability increases

Engineering Contradiction:
Improveenergy consumptionVSAvoidsecurity vulnerability
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The system performs preliminary actions by obtaining and storing location information of the equipment before it enters standby mode. When the equipment becomes active again, the system compares the current location with the stored location to verify authenticity, preventing security attacks that might occur during the standby period.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements a feedback mechanism by continuously monitoring equipment location and comparing it with previously stored location data. This feedback loop ensures that even when equipment is inactive, the system can detect unauthorized movements or counterfeit equipment attempting to access the network.

Inventive Principle:
Principle #23Feedback

2Reliability

If location verification is performed for every equipment activation, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system creates a copy of the equipment's location information and stores it in the network infrastructure. This copied location data serves as a reference for future verification, eliminating the need for complex real-time monitoring while maintaining security. The verification process simply compares current location against the stored copy.

Inventive Principle:
Principle #26Copying

3Reliability

If equipment authentication is strengthened with location checks, then unauthorized access is prevented, but processing time increases

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Location information is obtained and stored in advance when equipment first connects or during previous active periods. This preliminary action ensures that when equipment activates from standby, the verification process is rapid since the reference data is already available in the network, minimizing processing time while maintaining strong authentication.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4068818A1Management method for security in a data communication system, and system for implementing the method
Publication Date: 2022.10.05 ELECTRICITE DE FRANCE
  • EP4068818A1 patent drawingFigure 1
  • EP4068818A1 patent drawingFigure 2a
  • EP4068818A1 patent drawingFigure 2b

AI summary

A security management method in a data communication system for the exchange of data between a device and an application server of the system, the system comprising a first data communication network, operationally coupled to a second data communication network, is proposed, which includes, in a system security management unit implemented in a node of the second communication network: obtaining a first location information of the device; upon determination of a presumed change in device activity, obtaining a second location information of the device; performing a concordance check between the first location information of the device and the second location information of the device;and when the first equipment location information and the second equipment location information do not match, generate a refusal of access to the application server for the equipment.