IED Authentication via MACsec Secure Association Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In electric power delivery systems, existing access control methods using passcodes are inadequate in ensuring that only authorized operators can access intelligent electronic devices (IEDs), leading to potential unauthorized access and security risks.
Innovation Solution
The implementation of Media Access Control Security (MACsec) using secure association keys (SAKs) generated through the MACsec Key Agreement (MKA) process, which secures communication sessions between key servers and IEDs, and distributes access control SAKs with metadata restrictions, ensuring authorized access by operators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If passcode-based access control is used for IEDs, then ease of operation is improved, but security is worsened due to inadequate authorization verification
Solution Approach 1:
The patent introduces MACsec protocol and key server as intermediary mechanisms between operators and IEDs. Instead of direct passcode verification, access requests are mediated through cryptographic authentication using pre-shared keys (PSK) and secure association keys (SAK), providing robust security while maintaining operational ease through automated key management.
Solution Approach 2:
The patent replaces the mechanical/passcode-based access control system with an electronic cryptographic authentication system. The manual verification of passcodes is substituted by automated MACsec protocol execution, MKA key agreement process, and cryptographic key verification, significantly enhancing security reliability.
2Reliability
If MACsec with MKA process is implemented, then security is improved, but device complexity is worsened
Solution Approach 1:
The patent makes the key server perform multiple functions: it acts as a certificate authority, manages key distribution, verifies operator credentials, and coordinates MKA processes. This consolidation of security functions into a single multi-functional component reduces overall system complexity despite the advanced cryptographic mechanisms employed.
Solution Approach 2:
The MACsec and MKA protocols implement automated key generation, distribution, and verification processes that operate without manual intervention. The system self-manages cryptographic credentials, automatically establishes secure associations, and verifies authentication credentials, reducing operational complexity despite the sophisticated security mechanisms.
3Reliability
If access control SAKs with metadata restrictions are distributed, then security is improved by limiting access, but loss of information is worsened due to restricted access periods
Solution Approach 1:
The patent implements dynamic access control where SAK validity periods and metadata restrictions are not fixed but can be adjusted based on operational requirements. The key server can issue, revoke, and renew SAKs with flexible time constraints and privilege levels, allowing the system to adapt access availability to changing security requirements while maintaining authorized access control.
Data Source
AI summary
An intelligent electronic device (IED) includes memory and a processor operatively coupled to the memory. The processor is configured to establish, over a communication network of a power system, a communication link according to a media access control security (MACsec) Key Agreement (MKA). The TED receives a plurality of access control secure association keys (SAKs) via the communication link. The TED receives one or more checked-out SAKs indicating a request to access the TED The TED allows access based on the one or more checked-out access control SAKs matching at least one of the plurality of access control SAKs.


