Multiplexer Lockdown Control for Secure Remote Grid Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems face significant security risks due to remote access vulnerabilities, allowing malicious individuals to disrupt critical infrastructure by gaining unauthorized access through weak authentication methods and cyberattacks, which are difficult to detect and prevent with current firewalls and device login credentials.

Innovation Solution

Implementing a network of multiplexers connected via a firewall with a physical authentication device that requires a trusted individual to confirm the identity of remote users via telephone or video conference, using biometric sensors or USB key fobs, and generating encrypted tokens to temporarily exit secure lockdown mode for authorized access, ensuring physical presence and secure access management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If remote access is allowed via electronic communication network, then system maintenance and upgrades can be performed remotely, but security risk increases allowing malicious individuals to gain unauthorized access

Engineering Contradiction:
Improveremote access capabilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a multiplexer as an intermediary device between the remote user and the industrial control system. The multiplexer acts as a secure gateway that requires authentication before allowing remote access, thus maintaining ease of remote operation while mitigating security risks through controlled access procedures

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If default secure lockdown mode is maintained, then unauthorized access is prevented, but authorized remote access for maintenance becomes difficult

Engineering Contradiction:
Improvesecurity protectionVSAvoidauthorized access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic access control where the multiplexer can transition between secure lockdown mode and accessible mode. Authorized users can temporarily exit lockdown mode through authentication procedures, allowing maintenance operations while maintaining security protection. The system dynamically adjusts its security state based on authentication outcomes

Inventive Principle:
Principle #15Dynamics

3Reliability

If authentication device is physically connected to multiplexer, then identity verification is enhanced, but system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces complex mechanical authentication systems with electronic and optical verification methods. The multiplexer uses LED indicators and electronic signal processing to verify authentication tokens, substituting physical mechanical verification with more sophisticated but integrated electronic systems that enhance security without proportionally increasing physical complexity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12088573B2System and method for securely changing network configuration settings to multiplexers in an industrial control system
Publication Date: 2024.09.10 HUBBELL INC
  • US12088573B2 patent drawing
  • US12088573B2 patent drawing
  • US12088573B2 patent drawing

AI summary

A secure control system includes a network of multiplexers that control end/field devices of an infrastructure system, such as an electric power grid. The multiplexers have a default secure lockdown state that prevents remote access to data on the multiplexers and prevents modification of software or firmware of the multiplexer. One or more of the multiplexers include a physical authentication device that confirms the physical proximity of a trusted individual when remote access is requested. A user accesses the network and one of the multiplexers remotely by way of login credentials. The trusted individual confirms the identity of the remote user and operates the physical authentication device connected with and in proximity to that multiplexer, thereby confirming that the remote user can be trusted to access data and reconfigure the multiplexers. The multiplexer connected with the physical authentication device generates a token that is passed to each of the multiplexers that the remote user needs access to. The token may specify a time period, after which, the multiplexers will reenter secure lockdown mode.