IED Security Key Segmentation for Software Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Intelligent electronic devices (IEDs) face security challenges due to minimal security measures, especially as they become more network-accessible, with issues like default password reuse, reverse engineering, and software copying, which traditional methods like locking software in chips cannot effectively address without limiting functionality.
Innovation Solution
Implementing a unique security key for each IED to prevent password reuse and encrypt critical software components, along with functional isolation of external and internal interfaces, and encrypting software to ensure only authorized devices can run the software, using a separate processor for decryption and storing the security key externally to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security methods like locking software inside chips are used, then software copying is prevented, but device functionality and flexibility are limited
Solution Approach 1:
The patent segments the IED into multiple processing units with distinct security roles. A secure processing unit stores and manages security keys separately from the main processing unit, which executes software. This segmentation allows the main processor to run flexible, updatable software while the secure unit protects against copying through cryptographic verification, resolving the contradiction between security and functionality.
Solution Approach 2:
The patent introduces a secure processing unit as an intermediary between the external environment and the main processing unit. This intermediary verifies software authenticity using stored security keys before allowing execution, enabling the main processor to maintain full functionality while the intermediary enforces security policies without limiting software capabilities.
2Productivity
If network accessibility is increased for smart grid communication, then data collection and remote monitoring are improved, but security vulnerabilities and unauthorized access risks increase
Solution Approach 1:
The patent implements preliminary anti-action by pre-configuring the IED with unique security keys and cryptographic authentication mechanisms before network connection. The secure processing unit verifies incoming communication requests and software updates using these pre-established security credentials, blocking unauthorized access attempts before they can compromise the system, thus enabling safe network connectivity for improved productivity.
3Adaptability or versatility
If software is made more complex with additional features, then device capability is enhanced, but susceptibility to reverse engineering and copying increases
Solution Approach 1:
The patent extracts the security verification function from the main software and places it in a separate secure processing unit with stored security keys. This allows the main software to become more complex and feature-rich without increasing reverse engineering risk, as the critical security logic and keys are isolated in a protected unit that verifies software authenticity before execution.
Data Source
AI summary
The present disclosure provides for improving security in a meter or an intelligent electronic device (IED) through the use of a security key which is unique to each meter or IED. Such a key may be used to prevent password reuse among multiple meters. Such a key may also be used to encrypt critical components of the software, such that only when running on the correct meter can the components of the software be decrypted. Such a key may also be used to uniquely identify the device in a larger data collection and management system. The security key can also be used to prevent the direct copying of meters. The present disclosure also provides for a meter or IED that stores functional software separately from core software.


