MACsec Key Agreement Cryptographic Fingerprinting for Power Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In electric power delivery systems, there is a need to effectively communicate frames of different application protocols over communication networks while ensuring security, as existing solutions struggle to efficiently manage and secure data transmission using Media Access Control Security (MACsec) and MACsec Key Agreement (MKA) protocols.

Innovation Solution

Implementing a system where intelligent electronic devices (IEDs) communicate using MACsec frames with secure channel identifiers and port identifiers, and employing MACsec Key Agreement (MKA) processes to establish secure associations between devices, allowing for secure and protocol-specific data transmission, and utilizing Software Defined Networking (SDN) to manage and control communication flows based on application protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MACsec is used to secure data transmission, then security is improved, but device complexity increases due to key management and cryptographic processing requirements

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a key server as an intermediary component that centralizes MACsec key management functions. The key server generates, distributes, and manages cryptographic keys for multiple IEDs, eliminating the need for each device to independently manage complex key relationships. This mediator approach resolves the technical contradiction by maintaining high security through centralized key control while reducing individual device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If multiple application protocols are communicated over the same MACsec connectivity association, then productivity is improved, but measurement precision deteriorates because protocol identification becomes difficult with encrypted payloads

Engineering Contradiction:
ImproveproductivityVSAvoidmeasurement precision
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent segments the MACsec frame structure by introducing a Confidentiality Offset field that divides the frame into an unencrypted header portion and an encrypted payload portion. The header contains protocol identification information that remains accessible for measurement and routing purposes, while the payload is encrypted for security. This segmentation allows multiple protocols to share the same connectivity association (improving productivity) while maintaining the ability to precisely identify and measure protocol types (maintaining measurement precision).

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11677268B2Media access control security (MACsec) application cryptographic fingerprinting
Publication Date: 2023.06.13 SCHWEITZER ENGINEERING LABORATORIES INC
  • US11677268B2 patent drawing
  • US11677268B2 patent drawing
  • US11677268B2 patent drawing

AI summary

An intelligent electronic device (IED) includes memory and a processor operatively coupled to the memory. The processor is configured to establish, over a communication network of a power system, a connection association (CA) with a receiving device using a MACsec Key Agreement (MKA). The processor is configured to automatically send an announce message indicating a set of enabled application protocols on the IED to the receiving device.