PRP MACsec Mode Switching for Secure Power Grid Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Electric power delivery systems face challenges in securely communicating data between intelligent electronic devices (IEDs) due to differences in data encryption methods, making it difficult to implement and operate these systems efficiently.
Innovation Solution
The implementation of Media Access Control Security (MACsec) communication links and Parallel Redundancy Protocol (PRP) to ensure secure data transmission, with adaptive operation in different PRP MACsec modes to accommodate varying encryption practices among IEDs, allowing for flexible and secure data communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If different IEDs apply different data encryption methods, then each IED can maintain its own security preferences and operational characteristics, but it becomes difficult to incorporate these IEDs into a unified electric power delivery system
Solution Approach 1:
The patent introduces a network device as an intermediary between IEDs with different encryption methods. This intermediary translates or adapts data packets between different encryption schemes, allowing IEDs to maintain their preferred encryption methods while still communicating within the unified system. The intermediary handles the complexity of multiple encryption methods centrally rather than requiring each IED to support all methods.
2Device complexity
If all IEDs are standardized to a single PRP MACsec mode, then system integration becomes easier and complexity is reduced, but the cost of standardization and loss of flexibility increase
Solution Approach 1:
The patent implements a dynamic system where the network device can adaptively select and switch between different PRP MACsec modes based on the capabilities and requirements of communicating IEDs. Rather than fixing the system to a single mode, the encryption mode becomes a dynamic parameter that adjusts to match the operational needs of different devices while maintaining unified system management.
3Adaptability or versatility
If adaptive operation in different PRP MACsec modes is implemented, then flexibility and accommodation of varying encryption practices are maintained, but the complexity of managing multiple modes increases
Solution Approach 1:
The network device implements self-service mechanisms by automatically detecting the encryption mode requirements of communicating IEDs and configuring itself to use the appropriate PRP MACsec mode. This automation reduces the manual configuration burden and operational complexity, allowing the system to maintain high adaptability without proportionally increasing operational difficulty. The device serves itself by making intelligent decisions about mode selection based on observed communication patterns.
Data Source
AI summary
A system includes a parallel redundancy protocol (PRP) link redundancy entity (LRE) configured to receive data and copy the data to create a first copy of the data and a second copy of the data for transmission and a switch configured to cause operation between a first PRP media access control security (MACsec) mode and a second PRP MACsec mode to encrypt the data. The first PRP MACsec mode includes performing MACsec encryption on the data received by the PRP LRE prior to the data being copied by the PRP LRE, and the second PRP MACsec mode includes performing the MACsec encryption on the first copy of the data and the second copy of the data after the data has been copied by the PRP LRE.


