Proxy Device Authorization for Electric Power Distribution IEDs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electric power distribution systems face challenges in securely authorizing different users to perform various actions across intelligent electronic devices (IEDs) without requiring each IED to process permissions data, which can be complex and resource-intensive.

Innovation Solution

A proxy device communicatively coupled to IEDs via a Media Access Control security (MACsec) communication link receives and processes permissions data to determine authorized actions, enabling or blocking data transmission between computing devices and IEDs based on user permissions, thereby simplifying user authorization without the need for IEDs to process permissions data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If each IED processes permissions data directly, then user authorization can be performed, but the device complexity and resource burden on IEDs increases

Engineering Contradiction:
Improveuser authorizationVSAvoidIED processing complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a gateway device as an intermediary between computing devices and IEDs. The gateway receives permissions data from computing devices, processes the authorization requests, and then communicates with IEDs through standardized commands. This mediator handles the complex permission processing logic centrally, preventing IEDs from needing to directly process complex permissions data, thus reducing IED device complexity while maintaining ease of operation for user authorization

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If IEDs process permissions data, then authorization decisions can be made locally, but the productivity and efficiency of the system decreases due to resource constraints

Engineering Contradiction:
Improvelocal authorization decisionVSAvoidsystem efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The gateway acts as an intermediary that handles all permission processing operations centrally. Instead of each IED independently processing permissions data (which would consume limited IED resources), the gateway receives authorization requests, processes permissions data using its greater computational resources, and returns authorization decisions to the appropriate parties. This approach maintains system reliability by ensuring centralized authorization control while improving productivity by offloading resource-intensive processing from constrained IEDs to the more capable gateway

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If permissions data is transmitted to each IED, then user permissions can be enforced, but the loss of information and communication overhead increases

Engineering Contradiction:
Improvepermission enforcementVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The gateway serves as an intermediary that centralizes permission enforcement. Rather than transmitting detailed permissions data to each IED (which would create communication overhead and potential information loss), the gateway receives authorization requests, enforces permissions centrally, and communicates only the necessary authorization decisions back to computing devices or IEDs. This approach maintains reliable permission enforcement while minimizing communication overhead by avoiding redundant transmission of extensive permissions data to multiple IEDs

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11777931B2Systems and methods for authorizing access to a component in an electric power distribution system
Publication Date: 2023.10.03 SCHWEITZER ENGINEERING LABORATORIES INC
  • US11777931B2 patent drawing
  • US11777931B2 patent drawing
  • US11777931B2 patent drawing

AI summary

A system includes an intelligent electronic device (IED) and a proxy device communicatively coupled to the TED via a Media Access Control (MACsec) communication link. The proxy device is configured to perform operations that include receiving permissions data, receiving a request to perform an action associated with the TED, determining whether the action is authorized based on the permissions data, and transmitting data to the TED via the MACsec communication link in response to determining that the action is authorized.