MACsec Secure Channel Identifier for Power System Protocol Differentiation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In electric power delivery systems, there is a need to efficiently communicate frames of different application protocols over wired Ethernet networks while ensuring security, particularly in scenarios where various application protocols manage messages differently, and there is a requirement to facilitate better communication of power system data between intelligent electronic devices (IEDs) using Media Access Control Security (MACsec) and MACsec Key Agreement (MKA).

Innovation Solution

The implementation of MACsec frames with a secure channel identifier (SCI) and port identifier (PI) within the data link layer, along with the MACsec Key Agreement (MKA) process, allows for secure and differentiated communication of power system data between IEDs, enabling secure channel management and protocol identification without decrypting the payload, using a key server to manage MACsec keys and application protocol-specific secure associations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MACsec encryption is applied to all frames, then security is improved, but processing complexity and overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the communication channels by introducing secure channel identifiers (SCIDs) that differentiate between various application protocols. Each protocol gets its own secure channel with appropriate encryption parameters, allowing selective encryption application rather than blanket encryption of all frames, thus reducing unnecessary processing overhead while maintaining security where needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security parameters and encryption settings to different secure channels based on their specific requirements. Each application protocol can have customized security associations with appropriate encryption strength, ensuring that security resources are allocated efficiently according to local needs rather than applying uniform encryption to all traffic.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If multiple application protocols are supported with different message management, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improveprotocol supportVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces secure channel identifiers (SCIDs) as intermediaries between the MACsec layer and application protocols. The SCID acts as a mediator that maps different application protocols to appropriate security associations without requiring the MACsec layer to understand the specifics of each protocol, thus supporting multiple protocols while maintaining manageable device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal secure channel framework that can accommodate multiple application protocols through a common MACsec structure. The secure channel mechanism provides a multi-functional interface that handles different protocols uniformly at the data link layer, allowing the system to support various protocols without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Speed

If protocol identification is done without decryption, then processing speed is improved, but measurement precision of protocol type decreases

Engineering Contradiction:
Improveprocessing speedVSAvoidprotocol identification accuracy
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The patent performs preliminary protocol identification by examining unencrypted header fields and secure channel identifiers before decryption occurs. This preliminary action allows the system to quickly route frames to appropriate processing queues and prepare decryption parameters in advance, maintaining high processing speed while ensuring accurate protocol identification through multiple indicator fields.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11233635B1Media access control security (MACSEC) application cryptographic fingerprinting
Publication Date: 2022.01.25 SCHWEITZER ENGINEERING LABORATORIES INC
  • US11233635B1 patent drawing
  • US11233635B1 patent drawing
  • US11233635B1 patent drawing

AI summary

An intelligent electronic device (IED) includes memory and a processor operatively coupled to the memory. The IED establishes, over a communication network of a power system, a connection association (CA) with a receiving device using a media access control security (MACsec) Key Agreement (MKA) protocol. The IED automatically sends an announce message indicating a set of enabled application protocols on the IED to the receiving device.