MKA Key Agreement for IED Security in Power Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Establishing a secure communication link between intelligent electronic devices (IEDs) and other components in electric power distribution systems is complex and time-consuming, requiring users to perform multiple procedures such as configuring settings and verifying protocols.

Innovation Solution

The implementation of a Media Access Control security (MACsec) key agreement (MKA) protocol that automatically establishes a secure communication link between IEDs and gateways using connectivity association keys (CAKs) and secure association keys (SAKs), simplifying the process by eliminating the need for user intervention in configuring settings and verifying protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration and verification procedures are used to establish secure communication links, then security can be ensured, but the process becomes complex and time-consuming

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs self-configuration and self-verification of secure communication links. The IED and gateway automatically exchange CAKs, establish adoption links, generate SAKs, and verify security parameters without requiring manual user intervention for each step, thereby maintaining security while reducing operational complexity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security parameters and CAKs are pre-configured in the IED and gateway before operation. The system has pre-established security policies, cryptographic algorithms, and key management structures ready for automatic execution during link establishment, eliminating the need for manual configuration during operation

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual configuration and verification procedures are used to establish secure communication links, then security can be ensured, but the process becomes time-consuming

Engineering Contradiction:
ImprovesecurityVSAvoidlink establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The automatic key exchange and verification process eliminates manual configuration steps, reducing link establishment time from potentially hours of manual work to seconds of automated exchange between IED and gateway

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

By pre-configuring security parameters, cryptographic algorithms, and key management structures before operation, the system eliminates time-consuming manual setup during link establishment, allowing rapid automated security verification

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If automatic key agreement protocol is implemented, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improveoperation simplicityVSAvoidprotocol complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The MKA protocol implementation automates the entire key agreement process, allowing users to simply initiate connection while the system automatically performs CAK exchange, adoption link establishment, SAK generation, and security verification without requiring users to understand or configure the underlying protocol complexity

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11997076B2Systems and methods for establishing secure communication in an electric power distribution system
Publication Date: 2024.05.28 SCHWEITZER ENGINEERING LABORATORIES INC
  • US11997076B2 patent drawing
  • US11997076B2 patent drawing
  • US11997076B2 patent drawing

AI summary

A system includes an intelligent electronic device (IED) configured to perform operations that include receiving a first user input and deriving a first connectivity association key (CAK) based on the first user input. The system also includes a gateway configured to perform operations that include receiving a second user input, deriving a second CAK based on the second user input, identifying the first CAK of the IED, establishing an adoption link with the IED based on a match between the first CAK and the second CAK, generating a third CAK, and distributing a copy of the third CAK to the IED via the adoption link to establish a MKA connectivity association with the IED.