MACsec Key Agreement for IED Authorization Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In electric power delivery systems, intelligent electronic devices (IEDs) face challenges in securely accessing and managing authorization information, particularly in networks lacking firewalls or routers, and devices that are inaccessible due to location or lack of network enablement, leading to security vulnerabilities.

Innovation Solution

The implementation of Media Access Control Security (MACsec) and MACsec Key Agreement (MKA) protocols to secure the transfer of authorization information through encrypted MACsec frames and key management, ensuring secure communication and authentication of commands between IEDs, even for devices not directly connected to the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network access methods are used for IEDs, then network connectivity is achieved, but security vulnerabilities arise due to lack of firewalls or routers and unauthorized access risks

Engineering Contradiction:
Improvenetwork securityVSAvoidunauthorized access vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces MACsec and MKA protocols as intermediary security mechanisms between IEDs and the network. These protocols act as a mediator that provides encryption and key management, protecting communication without requiring traditional network infrastructure like firewalls or routers. The MACsec protocol encrypts data frames at the data link layer, while MKA manages the security associations and key distribution, creating a secure communication channel that protects against unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If MACsec and MKA protocols are implemented, then secure transfer of authorization information is achieved, but device complexity increases due to encryption and key management requirements

Engineering Contradiction:
Improveauthorization information securityVSAvoidencryption and key management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The MKA protocol implements self-service mechanisms for key management and security association establishment. Devices automatically perform key derivation, security parameter negotiation, and association setup without requiring manual configuration or external key management infrastructure. The protocol enables devices to autonomously establish secure MACsec connections by exchanging capability announcements, negotiating security parameters, and deriving encryption keys through a standardized automated process, thereby reducing operational complexity despite the cryptographic operations involved.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11570179B2Secure transfer using media access control security (MACsec) key agreement (MKA)
Publication Date: 2023.01.31 SCHWEITZER ENGINEERING LABORATORIES INC
  • US11570179B2 patent drawing
  • US11570179B2 patent drawing
  • US11570179B2 patent drawing

AI summary

A key server device obtains authorization information of a user associated with an intelligent electronic device (IED). The key server communicates the authorization information to the IED, via a Media Access Control Security (MACsec) Key Agreement (MKA) protocol to allow the IED to authenticate the user. The key server receives one or more commands from the user. The key server communicates the one or more commands to the IED to allow the IED to perform operations based on the one or more commands.