MACsec Key Agreement for IED Authorization Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In electric power delivery systems, intelligent electronic devices (IEDs) face challenges in securely accessing and managing authorization information, particularly in networks lacking firewalls or routers, and devices that are inaccessible due to location or lack of network enablement, leading to security vulnerabilities.
Innovation Solution
The implementation of Media Access Control Security (MACsec) and MACsec Key Agreement (MKA) protocols to secure the transfer of authorization information through encrypted MACsec frames and key management, ensuring secure communication and authentication of commands between IEDs, even for devices not directly connected to the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network access methods are used for IEDs, then network connectivity is achieved, but security vulnerabilities arise due to lack of firewalls or routers and unauthorized access risks
Solution Approach 1:
The patent introduces MACsec and MKA protocols as intermediary security mechanisms between IEDs and the network. These protocols act as a mediator that provides encryption and key management, protecting communication without requiring traditional network infrastructure like firewalls or routers. The MACsec protocol encrypts data frames at the data link layer, while MKA manages the security associations and key distribution, creating a secure communication channel that protects against unauthorized access.
2Reliability
If MACsec and MKA protocols are implemented, then secure transfer of authorization information is achieved, but device complexity increases due to encryption and key management requirements
Solution Approach 1:
The MKA protocol implements self-service mechanisms for key management and security association establishment. Devices automatically perform key derivation, security parameter negotiation, and association setup without requiring manual configuration or external key management infrastructure. The protocol enables devices to autonomously establish secure MACsec connections by exchanging capability announcements, negotiating security parameters, and deriving encryption keys through a standardized automated process, thereby reducing operational complexity despite the cryptographic operations involved.
Data Source
AI summary
A key server device obtains authorization information of a user associated with an intelligent electronic device (IED). The key server communicates the authorization information to the IED, via a Media Access Control Security (MACsec) Key Agreement (MKA) protocol to allow the IED to authenticate the user. The key server receives one or more commands from the user. The key server communicates the one or more commands to the IED to allow the IED to perform operations based on the one or more commands.


