Role-Based Access Control for Intelligent Electronic Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Power substation control systems face challenges with redundant and costly maintenance of multiple intelligent electronic devices (IEDs), as well as difficulties in implementing and managing role-based access control, which affects security and efficiency.
Innovation Solution
A new IED with a role-based access control (RBAC) system that uses a microprocessor, network-connected computer, and software to assign permissions and create unique security keys for users, allowing access to only authorized functions and logging access attempts, conforming to the ANSI INCITS 359-2004 standard.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple IEDs are maintained for a single piece of power equipment to prevent interference, then security and reliability are improved, but device complexity and cost increase
Solution Approach 1:
The patent consolidates multiple IED functions into a single IED while implementing role-based access control to manage security. Instead of maintaining separate IEDs for different functions, the system combines protection, configuration, and monitoring functions in one device with differentiated access levels for various users.
Solution Approach 2:
The IED is designed to perform multiple functions including protection, configuration, monitoring, and control operations. A single IED device provides universal access to various functions through software-based role management, eliminating the need for multiple specialized devices.
2Reliability
If multiple IEDs are maintained for a single piece of power equipment, then security is improved, but cost increases
Solution Approach 1:
The patent consolidates multiple IED functions into a single IED while implementing role-based access control to manage security. Instead of maintaining separate IEDs for different functions, the system combines protection, configuration, and monitoring functions in one device with differentiated access levels for various users.
3Quantity of substance
If a single IED consolidates multiple functions, then cost is reduced, but access control complexity increases
Solution Approach 1:
The IED is designed to perform multiple functions including protection, configuration, monitoring, and control operations. A single IED device provides universal access to various functions through software-based role management, eliminating the need for multiple specialized devices.
Solution Approach 2:
The access control system segments user permissions into distinct roles (e.g., operator, engineer, administrator) with specific authorization levels. This segmentation allows complex access control requirements to be managed through standardized role templates rather than individual user configurations.
4Quantity of substance
If role-based access control is implemented in a single IED, then cost is reduced, but difficulty of managing user permissions increases
Solution Approach 1:
The access control system segments user permissions into distinct roles (e.g., operator, engineer, administrator) with specific authorization levels. This segmentation allows complex access control requirements to be managed through standardized role templates rather than individual user configurations.
Data Source
AI summary
The present disclosure describes apparatus, methods, and system for secure access control of an intelligent electronic device (“IED”) by multiple personnel. Within the IED a set of basic permissions is defined. A software program allows a security administrator create specific roles from the basic permissions. The software program can then be used to assign to a user a specific role for one or more specific IEDs. This action creates a set of unique security keys for the user and a unique security file for each IED. When a user accesses an IED the system identifies the user from the security key and determines his/her permissions using the security file. The security key may take the form of a password inputted into the IED, an access device incorporated within the IED, and/or a remote access device positioned proximate the IED or removably positioned in the IED.


