SDN Controller Key Distribution for Power Grid MACsec Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing a secure communication link between intelligent electronic devices (IEDs) in electric power distribution systems is challenging due to the difficulty in ensuring secure data transmission and encryption, which is crucial for controlling and monitoring electrical power distribution effectively.
Innovation Solution
A system that uses a controller to generate and distribute cryptographic keys for establishing a Media Access Security (MACsec) communication link, enabling secure data transmission between IEDs through a software-defined network (SDN), allowing switches to communicate securely without continuous controller supervision.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic keys are manually configured for each device, then secure communication can be established, but the system complexity and time required for key distribution increase significantly
Solution Approach 1:
An SDN controller is introduced as an intermediary to automatically generate and distribute cryptographic keys to network devices. The controller receives key material, generates session keys, and distributes them to switches and IEDs, eliminating the need for manual key configuration while maintaining security. This mediator approach resolves the contradiction by centralizing key management functionality.
Solution Approach 2:
Cryptographic key material is pre-configured in the SDN controller before actual communication begins. The controller performs preliminary key generation and distribution operations, so that when communication is needed, secure keys are already in place. This preliminary action reduces the complexity of real-time key establishment.
2Reliability
If continuous controller supervision is used to maintain secure connections, then communication security is maintained, but the system requires constant controller intervention increasing operational complexity
Solution Approach 1:
Network devices (switches and IEDs) are configured to autonomously establish and maintain secure MACsec communication links using keys previously distributed by the SDN controller. Once keys are distributed, devices perform self-service by automatically establishing connectivity associations and maintaining secure connections without requiring continuous controller intervention. This resolves the contradiction by enabling devices to manage their own security connections.
Solution Approach 2:
The continuous supervision function is extracted from the SDN controller and transferred to the network devices themselves. Devices take over the maintenance of secure connections, allowing the controller to step back from continuous intervention while security is maintained through the autonomous operation of distributed devices.
3Reliability
If manual key configuration is performed for each device pair, then secure communication links can be established, but the time and resources required for key distribution increase
Solution Approach 1:
The SDN controller performs preliminary key generation and distribution to all network devices before secure communication is needed. Base key material is pre-configured in the controller, and devices receive their cryptographic keys in advance through automated distribution protocols. This preliminary action eliminates time-consuming manual key configuration for each device pair.
Solution Approach 2:
The key distribution process is segmented into automated phases: base key material storage in the controller, automated key generation for each device, and systematic distribution to network devices. This segmentation allows parallel processing of key distribution to multiple devices simultaneously, reducing total distribution time compared to sequential manual configuration.
Data Source
AI summary
A system includes a switch of an electric power distribution system, the switch being configured to receive data and to transmit data, and the system includes a controller configured to communicatively couple to the switch. The controller is configured to create a software defined network by instructing the switch to transmit data to a location, and the controller is configured to generate a set of keys and to provide the set of keys to the switch to enable the switch to communicate data via a Media Access Security (MACsec) communication link, a MACsec key agreement (MKA) connectivity association, or both.


