Electric Meter Security Server for Centralized Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The power industry has historically overlooked security in intelligent electronic devices (IEDs) such as electric meters, often relying on simple numeric passwords and centralized configurations, which are vulnerable to compromise, especially as networks become more interconnected.

Innovation Solution

Implementing an enterprise security system where security configurations are managed by a centralized security server, allowing for secure user authentication and authorization across multiple devices, using protocols like Modbus, HTTP POST, and LDAP, and integrating with SIEM and IDS systems for enhanced security monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If simple numeric passwords are used for security in meters, then ease of operation is improved, but security reliability deteriorates

Engineering Contradiction:
Improveease of password entryVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a security server as an intermediary between users and meters. The security server handles complex authentication and password management, allowing meters to use simple numeric passwords while the server provides strong security through centralized credential verification and management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If each meter stores its own security configuration locally, then device independence is improved, but security management complexity worsens

Engineering Contradiction:
Improvedevice independenceVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The security server acts as a centralized intermediary that manages security configurations for all meters. Meters can independently operate with simple local credentials, while the server provides centralized configuration, update, and revocation capabilities, reducing overall security management complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds a centralized management dimension by introducing the security server layer. This creates a two-level architecture where meters operate independently at the device level while the security server provides centralized control at the network level, effectively managing complexity through hierarchical organization.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Ease of operation

If the same password is configured on all meters for simplicity, then ease of operation is improved, but security vulnerability worsens

Engineering Contradiction:
Improvepassword management simplicityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The security server mediates authentication by verifying credentials centrally. Users can use the same simple password across all meters for ease of operation, but the security server ensures security by maintaining unique credential mappings and providing centralized control over authentication policies and credential revocation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240163314A1Enterprise security in meters
Publication Date: 2024.05.16 ELECTRO INDUSTRIES GAUGE TECH
  • US20240163314A1 patent drawing
  • US20240163314A1 patent drawing
  • US20240163314A1 patent drawing

AI summary

The present disclosure provides for enterprise security in intelligent electronic devices such as electric power meters. In accordance with the present disclosure, enterprise security is a security system in which each individual device, instead of configuring and storing security configurations locally, use a security server for security verifications. Such a security server of the present disclosure may be a dedicated computer on a network, that is used to manage the security configuration for all users. This makes it simpler for administrators to configure users and devices, which in turn improves security by encouraging security to be properly configured.