MACsec Key Agreement Cryptographic Fingerprinting for Power Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In electric power delivery systems, there is a need to effectively communicate frames of different application protocols over communication networks while ensuring security, as existing solutions struggle to efficiently manage and secure data transmission using Media Access Control Security (MACsec) and MACsec Key Agreement (MKA) protocols.
Innovation Solution
Implementing a system where intelligent electronic devices (IEDs) communicate using MACsec frames with secure channel identifiers and port identifiers, and employing MACsec Key Agreement (MKA) processes to establish secure associations between devices, allowing for secure and protocol-specific data transmission, and utilizing Software Defined Networking (SDN) to manage and control communication flows based on application protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MACsec is used to secure data transmission, then security is improved, but device complexity increases due to key management and cryptographic processing requirements
Solution Approach 1:
The patent introduces a key server as an intermediary component that centralizes MACsec key management functions. The key server generates, distributes, and manages cryptographic keys for multiple IEDs, eliminating the need for each device to independently manage complex key relationships. This mediator approach resolves the technical contradiction by maintaining high security through centralized key control while reducing individual device complexity.
2Productivity
If multiple application protocols are communicated over the same MACsec connectivity association, then productivity is improved, but measurement precision deteriorates because protocol identification becomes difficult with encrypted payloads
Solution Approach 1:
The patent segments the MACsec frame structure by introducing a Confidentiality Offset field that divides the frame into an unencrypted header portion and an encrypted payload portion. The header contains protocol identification information that remains accessible for measurement and routing purposes, while the payload is encrypted for security. This segmentation allows multiple protocols to share the same connectivity association (improving productivity) while maintaining the ability to precisely identify and measure protocol types (maintaining measurement precision).
Data Source
AI summary
An intelligent electronic device (IED) includes memory and a processor operatively coupled to the memory. The processor is configured to establish, over a communication network of a power system, a connection association (CA) with a receiving device using a MACsec Key Agreement (MKA). The processor is configured to automatically send an announce message indicating a set of enabled application protocols on the IED to the receiving device.


