MACsec Key Server Isolating Suspect Devices in Power Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Intruders can compromise the security of power system communication networks by accessing or modifying data through intelligent electronic devices (IEDs), necessitating improved security measures to isolate suspect devices and prevent unauthorized access.

Innovation Solution

A key server is used to detect and isolate suspect devices on a Media Access Control Security (MACsec) network by changing their connectivity association, either by sending a unicast message to the suspect device to transition to an isolated CA or by sending new CA keys to non-suspect devices to join a separate CA, thereby isolating the suspect device from the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MACsec security measures are implemented to protect power system communication networks, then security against intruders is improved, but device complexity increases due to the need for key management and connectivity association handling

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a key server as an intermediary component that centralizes MACsec key management and connectivity association handling. The key server receives MKA messages from IEDs, processes key exchange operations, and manages connectivity associations, thereby reducing the complexity burden on individual IEDs while maintaining robust security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security management function by separating key management operations from data communication operations. The key server handles all MACsec key exchange and connectivity association tasks independently, allowing IEDs to focus on data communication while security is managed centrally.

Inventive Principle:
Principle #1Segmentation

2Reliability

If suspect devices are isolated by changing connectivity associations, then security against unauthorized access is improved, but loss of time occurs during the isolation process as devices must re-establish connections

Engineering Contradiction:
ImprovesecurityVSAvoidconnection re-establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-establishing multiple connectivity associations with different keys before a security breach occurs. When a suspect device is detected, the system can quickly switch to an alternative pre-configured connectivity association, minimizing the time required for re-establishment and reducing security disruption.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11764969B2Media access control security (MACsec) sandboxing for suspect devices
Publication Date: 2023.09.19 SCHWEITZER ENGINEERING LABORATORIES INC
  • US11764969B2 patent drawing
  • US11764969B2 patent drawing
  • US11764969B2 patent drawing

AI summary

A key server may establish an initial media access security (MACsec) connectivity association (CA) between a set of devices on a communication network of a power system. The key server may identify a device in the set of devices on the initial CA as a suspect device. The key server may communicate a new connectivity association key (CAK) of an independent CA to one or more other devices in the set of devices to cause the one or more other devices to join an independent CA without the suspect device.