MACsec Key Server Isolating Suspect Devices in Power Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Intruders can compromise the security of power system communication networks by accessing or modifying data through intelligent electronic devices (IEDs), necessitating improved security measures to isolate suspect devices and prevent unauthorized access.
Innovation Solution
A key server is used to detect and isolate suspect devices on a Media Access Control Security (MACsec) network by changing their connectivity association, either by sending a unicast message to the suspect device to transition to an isolated CA or by sending new CA keys to non-suspect devices to join a separate CA, thereby isolating the suspect device from the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MACsec security measures are implemented to protect power system communication networks, then security against intruders is improved, but device complexity increases due to the need for key management and connectivity association handling
Solution Approach 1:
The patent introduces a key server as an intermediary component that centralizes MACsec key management and connectivity association handling. The key server receives MKA messages from IEDs, processes key exchange operations, and manages connectivity associations, thereby reducing the complexity burden on individual IEDs while maintaining robust security.
Solution Approach 2:
The patent segments the security management function by separating key management operations from data communication operations. The key server handles all MACsec key exchange and connectivity association tasks independently, allowing IEDs to focus on data communication while security is managed centrally.
2Reliability
If suspect devices are isolated by changing connectivity associations, then security against unauthorized access is improved, but loss of time occurs during the isolation process as devices must re-establish connections
Solution Approach 1:
The patent implements preliminary action by pre-establishing multiple connectivity associations with different keys before a security breach occurs. When a suspect device is detected, the system can quickly switch to an alternative pre-configured connectivity association, minimizing the time required for re-establishment and reducing security disruption.
Data Source
AI summary
A key server may establish an initial media access security (MACsec) connectivity association (CA) between a set of devices on a communication network of a power system. The key server may identify a device in the set of devices on the initial CA as a suspect device. The key server may communicate a new connectivity association key (CAK) of an independent CA to one or more other devices in the set of devices to cause the one or more other devices to join an independent CA without the suspect device.


