Secure DER Communication via NDN Trust Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing decentralization of electrical infrastructure with distributed energy resources (DERs) poses challenges in securing communication between various entities and resources, making them susceptible to cyber-attacks and data breaches.

Innovation Solution

A secure DER communication system utilizing Information Centric Networking (ICN), specifically Named Data Networking (NDN), to manage trust rules and secure communication between entities and resources, ensuring secure access and communication without exposing the network to unauthorized entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional communication technologies are used to enable communication between entities and DERs, then communication demand is satisfied, but the system becomes susceptible to cyber-attacks and data breaches

Engineering Contradiction:
Improvecommunication capabilityVSAvoidcyber-attack susceptibility
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a Named Data Networking (NDN) layer as an intermediary between conventional communication technologies and DER resources. This NDN layer implements granular trust rules and security policies that mediate all communications, preventing direct exposure of resources to untrusted network entities while still allowing legitimate access. The NDN architecture acts as a security gateway that filters and controls data flows based on predefined trust criteria.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network architecture into distinct trust zones with different security requirements. Each DER resource is protected by individual trust rules that define specific access permissions. The system divides communication paths into authorized and unauthorized segments, applying security policies at each segment boundary. This segmentation allows the system to maintain communication versatility while limiting attack surfaces by isolating resources from untrusted entities.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If control of system components is granted to multiple parties in different organizations, then business relationships are enabled, but the number of cyber-attack points increases

Engineering Contradiction:
Improvemulti-party collaboration capabilityVSAvoidnumber of access points
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal NDN-based security framework that serves multiple entities and resources through a single standardized interface. Instead of creating separate access mechanisms for each organization or resource, the system uses a unified trust rule engine that handles authentication and authorization for all parties. This universal approach enables multi-party collaboration while reducing the effective number of attack points by consolidating security management into a single robust layer.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The NDN security layer acts as an intermediary that manages all multi-party interactions through centralized trust rules. Rather than allowing direct peer-to-peer access between multiple organizations (which would create multiple attack vectors), the system routes all communications through the NDN mediator that enforces security policies. This intermediary approach maintains collaborative versatility while minimizing exposed attack surfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If granular trust rules are enforced to secure communication, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidtrust rule management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the NDN system automatically manages trust rule enforcement without requiring manual intervention for each communication event. The system includes automated trust rule validation, dynamic policy application, and self-configuring security parameters. This self-service capability maintains high security through granular trust rules while reducing operational complexity by eliminating manual security management tasks.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary configuration of trust rules and security policies before actual communications occur. Trust relationships are established and validated in advance through predefined policies, so that during runtime, security decisions are made automatically based on pre-evaluated rules. This preliminary action approach maintains granular security control while reducing real-time complexity by shifting security management work to the configuration phase.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12225133B2Configurable network security for networked energy resources, and associated systems and methods
Publication Date: 2025.02.11 OPERANT NETWORKS
  • US12225133B2 patent drawing
  • US12225133B2 patent drawing
  • US12225133B2 patent drawing

AI summary

Secure communication between users and resources of an electrical infrastructure and associated systems and methods. A representative secure distributed energy resource (DER) communication system provides for the creation of trust rules that govern the permitted communications between users and resources of an electrical infrastructure system, and the enforcement of the trust rules.