MACsec Secure Channel Identifier for Power System Protocol Differentiation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In electric power delivery systems, there is a need to efficiently communicate frames of different application protocols over wired Ethernet networks while ensuring security, particularly in scenarios where various application protocols manage messages differently, and there is a requirement to facilitate better communication of power system data between intelligent electronic devices (IEDs) using Media Access Control Security (MACsec) and MACsec Key Agreement (MKA).
Innovation Solution
The implementation of MACsec frames with a secure channel identifier (SCI) and port identifier (PI) within the data link layer, along with the MACsec Key Agreement (MKA) process, allows for secure and differentiated communication of power system data between IEDs, enabling secure channel management and protocol identification without decrypting the payload, using a key server to manage MACsec keys and application protocol-specific secure associations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MACsec encryption is applied to all frames, then security is improved, but processing complexity and overhead increase
Solution Approach 1:
The patent segments the communication channels by introducing secure channel identifiers (SCIDs) that differentiate between various application protocols. Each protocol gets its own secure channel with appropriate encryption parameters, allowing selective encryption application rather than blanket encryption of all frames, thus reducing unnecessary processing overhead while maintaining security where needed.
Solution Approach 2:
The patent applies different security parameters and encryption settings to different secure channels based on their specific requirements. Each application protocol can have customized security associations with appropriate encryption strength, ensuring that security resources are allocated efficiently according to local needs rather than applying uniform encryption to all traffic.
2Adaptability or versatility
If multiple application protocols are supported with different message management, then adaptability is improved, but device complexity increases
Solution Approach 1:
The patent introduces secure channel identifiers (SCIDs) as intermediaries between the MACsec layer and application protocols. The SCID acts as a mediator that maps different application protocols to appropriate security associations without requiring the MACsec layer to understand the specifics of each protocol, thus supporting multiple protocols while maintaining manageable device complexity.
Solution Approach 2:
The patent creates a universal secure channel framework that can accommodate multiple application protocols through a common MACsec structure. The secure channel mechanism provides a multi-functional interface that handles different protocols uniformly at the data link layer, allowing the system to support various protocols without proportionally increasing complexity.
3Speed
If protocol identification is done without decryption, then processing speed is improved, but measurement precision of protocol type decreases
Solution Approach 1:
The patent performs preliminary protocol identification by examining unencrypted header fields and secure channel identifiers before decryption occurs. This preliminary action allows the system to quickly route frames to appropriate processing queues and prepare decryption parameters in advance, maintaining high processing speed while ensuring accurate protocol identification through multiple indicator fields.
Data Source
AI summary
An intelligent electronic device (IED) includes memory and a processor operatively coupled to the memory. The IED establishes, over a communication network of a power system, a connection association (CA) with a receiving device using a media access control security (MACsec) Key Agreement (MKA) protocol. The IED automatically sends an announce message indicating a set of enabled application protocols on the IED to the receiving device.


