Power Grid Access Security System for Intermittent Ports

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of Internet of Things (IoT) devices in industrial fields has increased the risk of cyber threats due to the simultaneous management of OT and IT protocols in public or open networks, leading to potential physical and logical threats.

Innovation Solution

A power grid access security system for intermittent communication ports, which includes a link manager to monitor and manage communication port links, a power source to ensure operational functionality, and a multi-interface to integrate network links and security services. This system checks link settings and removes unauthorized data, allowing secure network access based on predefined criteria.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a closed-network configuration is used to limit external links, then network security is improved, but the ability to perform maintenance and upgrades of industrial equipment is worsened

Engineering Contradiction:
Improvenetwork securityVSAvoidmaintenance access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by establishing predetermined link settings and access control policies before external devices attempt to connect. The link manager pre-configures acceptable link parameters, authentication credentials, and security policies, so that when maintenance personnel need to access the network, the connection can be quickly established within pre-approved parameters without requiring security policy changes or manual approvals during the maintenance window.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If physical access is allowed for engineering PCs and storage devices, then equipment management capability is improved, but cyber threat risk is worsened

Engineering Contradiction:
Improveequipment managementVSAvoidcyber threat risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The link manager acts as an intermediary between external devices and the industrial network. It intercepts and monitors all connection attempts, comparing actual link parameters against predetermined settings. The link manager mediates by allowing only those connections that match approved configurations, blocking unauthorized access attempts, and logging all connection events. This intermediary layer enables equipment management access while filtering out cyber threats before they can reach the internal network.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If network protocols are made accessible for IT and OT devices, then communication versatility is improved, but vulnerability to malicious code is worsened

Engineering Contradiction:
Improvecommunication capabilityVSAvoidmalicious code vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system applies local quality by implementing different link management approaches for different communication needs. For standard maintenance connections, the system uses predetermined link settings with strict parameter matching. For authorized IT-OT communication, the system allows protocol accessibility but applies continuous monitoring and parameter verification. This localized approach to link management enables versatile communication while applying appropriate security controls to each specific connection type and location in the network.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250141786A1Power grid access security system and method for intermittent communication ports
Publication Date: 2025.05.01 ELECTRONICS & TELECOMM RES INST
  • US20250141786A1 patent drawing
  • US20250141786A1 patent drawing
  • US20250141786A1 patent drawing

AI summary

A power grid access security system for intermittent communication ports includes a link manager configured to manage and monitor a link of a communication port, a power source configured to supply needed for a function operation of the communication port, and a multi-interface configured to integrate and provide an interface for a network link and a security service, wherein the link manager checks whether a network link of an external device is established, based on link setting information, and when a condition for the network link is not satisfied, removes data received from the external device, based on the link setting information.