Microgrid Cyber-Security Architecture Segregating Control and SCADA Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Microgrid control networks face challenges in securing real-time communication due to external threats, as existing cryptographic protections introduce latency and complex network interconnections complicate security certifications, making them vulnerable to cyber attacks, especially in sensitive sites like military bases.

Innovation Solution

A cyber-security architecture that segregates communication networks for fast, real-time control from those for external monitoring, using lightweight cryptography and standards-based security protocols like OPC UA to reduce latency and minimize the attack surface, thereby simplifying security certifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic protection is used to secure microgrid control networks, then security is improved, but latency increases making real-time control unacceptable

Engineering Contradiction:
ImprovesecurityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The network is segmented into two distinct parts: a control network for real-time control signals and a SCADA network for monitoring and external communications. This segmentation allows the control network to operate without heavy cryptographic overhead while the SCADA network handles security functions, thereby resolving the contradiction between security and latency requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Security functions are extracted from the real-time control network and placed in a separate SCADA network. This extraction allows the control network to maintain low latency by eliminating cryptographic processing from the critical control path, while security is still provided through the isolated SCADA infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If control networks are interconnected with SCADA and external networks for monitoring and control, then functionality is improved, but attack surface increases making security certification harder

Engineering Contradiction:
ImprovefunctionalityVSAvoidnetwork complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The interconnected network is segmented into isolated zones: the control network remains isolated for real-time operations, while the SCADA network handles external communications and monitoring functions. This segmentation maintains the versatility of having both control and monitoring capabilities while reducing the attack surface by preventing direct paths between control and external networks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The SCADA network acts as an intermediary between external networks and the control network. It provides the necessary functionality for remote monitoring and control while isolating the critical control network from direct exposure to external threats, thereby simplifying security certification by creating clear security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10623436B2System and method of architectural security and resilience for microgrid systems
Publication Date: 2020.04.14 HONEYWELL INTERNATIONAL INC
  • US10623436B2 patent drawing
  • US10623436B2 patent drawing
  • US10623436B2 patent drawing

AI summary

Devices, methods, systems, and computer-readable for providing a cyber-security architecture for microgrid systems are described herein. One or more embodiments include a system for providing a cyber-security architecture for a microgrid, comprising a supervisory control and data acquisition network device having at least one remote network connection to a non-local network device and allowing communication of data and control instructions between the non-local network device and at least one local device in a microgrid network and a control network for providing control instructions to the local device based on data from the microgrid and a power generation network device, the control network allowing communication of data and control instructions between the power generation network device and the local device in the microgrid network.