MACsec IED Management via Encrypted Network Frames
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In electric power delivery systems, managing and monitoring intelligent electronic devices (IEDs) remotely is challenging due to the need for physical access, which compromises security and is time-consuming, especially when dealing with devices located remotely or in hard-to-reach places.
Innovation Solution
Implementing Media Access Control Security (MACsec) and MACsec key agreement (MKA) protocols to facilitate secure, remote communication of device management information, including device identification and password management, through encrypted MACsec frames and key management within the communication network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If physical access is required to manage and monitor IEDs, then device management can be performed, but security is compromised and it becomes time-consuming
Solution Approach 1:
The patent introduces a communication network as an intermediary between operators and IEDs, enabling remote management without physical access. The network transmits device management information, events, and alerts between IEDs and external systems, eliminating the need for operators to physically visit remote devices while maintaining secure access through controlled communication protocols
Solution Approach 2:
The patent replaces the mechanical approach of physical device access with electronic/communication-based management. Instead of manually accessing IEDs through physical presence, the system uses digital communication networks to transmit management information, substitute physical inspection and configuration with remote digital interactions
2Productivity
If physical access is required to manage IEDs, then direct device control is possible, but it becomes time-consuming especially for remote devices
Solution Approach 1:
The communication network serves as a mediator that enables simultaneous remote management of multiple IEDs across different locations. Operators can access and manage numerous devices through the network without traveling to each physical location, dramatically reducing the time required for device management activities
Solution Approach 2:
The communication network provides universal access to all IEDs within the system, enabling a single management interface to control and monitor multiple devices regardless of their physical locations. This multi-functional approach allows operators to perform various management tasks across the entire system through one centralized access point
3Ease of operation
If device management information is transmitted over the communication network, then remote management is enabled, but security risks increase without encryption
Solution Approach 1:
The patent creates a secure communication environment by encrypting device management information transmitted over the network. This encrypted channel acts as an 'inert atmosphere' that protects sensitive data from external threats and unauthorized access, allowing remote management while neutralizing security vulnerabilities associated with network transmission
Data Source
AI summary
An intelligent electronic device (IED) includes memory and a processor operatively coupled to the memory. The processor is configured to establish, over a communication network of a power system, a connection association (CA) with a receiving device using a MACsec Key Agreement (MKA). The processor is configured to automatically send device management information via the MKA process.


