IED Authentication via MACsec Secure Association Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In electric power delivery systems, existing access control methods using passcodes are inadequate in ensuring that only authorized operators can access intelligent electronic devices (IEDs), leading to potential unauthorized access and security risks.

Innovation Solution

The implementation of Media Access Control Security (MACsec) using secure association keys (SAKs) generated through the MACsec Key Agreement (MKA) process, which secures communication sessions between key servers and IEDs, and distributes access control SAKs with metadata restrictions, ensuring authorized access by operators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If passcode-based access control is used for IEDs, then ease of operation is improved, but security is worsened due to inadequate authorization verification

Engineering Contradiction:
Improveaccess control operationVSAvoidsecurity authorization
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces MACsec protocol and key server as intermediary mechanisms between operators and IEDs. Instead of direct passcode verification, access requests are mediated through cryptographic authentication using pre-shared keys (PSK) and secure association keys (SAK), providing robust security while maintaining operational ease through automated key management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/passcode-based access control system with an electronic cryptographic authentication system. The manual verification of passcodes is substituted by automated MACsec protocol execution, MKA key agreement process, and cryptographic key verification, significantly enhancing security reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If MACsec with MKA process is implemented, then security is improved, but device complexity is worsened

Engineering Contradiction:
Improvesecurity authorizationVSAvoidaccess control system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the key server perform multiple functions: it acts as a certificate authority, manages key distribution, verifies operator credentials, and coordinates MKA processes. This consolidation of security functions into a single multi-functional component reduces overall system complexity despite the advanced cryptographic mechanisms employed.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The MACsec and MKA protocols implement automated key generation, distribution, and verification processes that operate without manual intervention. The system self-manages cryptographic credentials, automatically establishes secure associations, and verifies authentication credentials, reducing operational complexity despite the sophisticated security mechanisms.

Inventive Principle:
Principle #25Self-service

3Reliability

If access control SAKs with metadata restrictions are distributed, then security is improved by limiting access, but loss of information is worsened due to restricted access periods

Engineering Contradiction:
Improveauthorized access controlVSAvoidaccess availability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements dynamic access control where SAK validity periods and metadata restrictions are not fixed but can be adjusted based on operational requirements. The key server can issue, revoke, and renew SAKs with flexible time constraints and privilege levels, allowing the system to adapt access availability to changing security requirements while maintaining authorized access control.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11601278B2Authentication of intelligent electronic devices (IEDs) using secure association keys (SAKs)
Publication Date: 2023.03.07 SCHWEITZER ENGINEERING LABORATORIES INC
  • US11601278B2 patent drawing
  • US11601278B2 patent drawing
  • US11601278B2 patent drawing

AI summary

An intelligent electronic device (IED) includes memory and a processor operatively coupled to the memory. The processor is configured to establish, over a communication network of a power system, a communication link according to a media access control security (MACsec) Key Agreement (MKA). The TED receives a plurality of access control secure association keys (SAKs) via the communication link. The TED receives one or more checked-out SAKs indicating a request to access the TED The TED allows access based on the one or more checked-out access control SAKs matching at least one of the plurality of access control SAKs.