MACsec IED Management via Encrypted Network Frames

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In electric power delivery systems, managing and monitoring intelligent electronic devices (IEDs) remotely is challenging due to the need for physical access, which compromises security and is time-consuming, especially when dealing with devices located remotely or in hard-to-reach places.

Innovation Solution

Implementing Media Access Control Security (MACsec) and MACsec key agreement (MKA) protocols to facilitate secure, remote communication of device management information, including device identification and password management, through encrypted MACsec frames and key management within the communication network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If physical access is required to manage and monitor IEDs, then device management can be performed, but security is compromised and it becomes time-consuming

Engineering Contradiction:
Improvedevice management accessibilityVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a communication network as an intermediary between operators and IEDs, enabling remote management without physical access. The network transmits device management information, events, and alerts between IEDs and external systems, eliminating the need for operators to physically visit remote devices while maintaining secure access through controlled communication protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical approach of physical device access with electronic/communication-based management. Instead of manually accessing IEDs through physical presence, the system uses digital communication networks to transmit management information, substitute physical inspection and configuration with remote digital interactions

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If physical access is required to manage IEDs, then direct device control is possible, but it becomes time-consuming especially for remote devices

Engineering Contradiction:
Improvedevice management efficiencyVSAvoidtime for physical access
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The communication network serves as a mediator that enables simultaneous remote management of multiple IEDs across different locations. Operators can access and manage numerous devices through the network without traveling to each physical location, dramatically reducing the time required for device management activities

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The communication network provides universal access to all IEDs within the system, enabling a single management interface to control and monitor multiple devices regardless of their physical locations. This multi-functional approach allows operators to perform various management tasks across the entire system through one centralized access point

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If device management information is transmitted over the communication network, then remote management is enabled, but security risks increase without encryption

Engineering Contradiction:
Improveremote management capabilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent creates a secure communication environment by encrypting device management information transmitted over the network. This encrypted channel acts as an 'inert atmosphere' that protects sensitive data from external threats and unauthorized access, allowing remote management while neutralizing security vulnerabilities associated with network transmission

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

Data Source

PatentUS11722501B2Device management in power systems using media access control security (MACsec)
Publication Date: 2023.08.08 SCHWEITZER ENGINEERING LABORATORIES INC
  • US11722501B2 patent drawing
  • US11722501B2 patent drawing
  • US11722501B2 patent drawing

AI summary

An intelligent electronic device (IED) includes memory and a processor operatively coupled to the memory. The processor is configured to establish, over a communication network of a power system, a connection association (CA) with a receiving device using a MACsec Key Agreement (MKA). The processor is configured to automatically send device management information via the MKA process.