Secure Communication Link Configuration in Power Distribution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electric power distribution systems face difficulties in adjusting the configuration of secure communication links between intelligent electronic devices (IEDs) and gateways, making it time-consuming and complex to establish new secure communication links with desired properties without replacing devices.
Innovation Solution
The system generates and distributes connectivity association keys (CAKs) based on predefined profiles, allowing IEDs to automatically adjust settings and establish secure MACsec communication links according to specific configurations, enabling easy switching between different profiles for varying security and communication properties.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual configuration methods are used to establish secure communication links, then security can be maintained, but the process becomes time-consuming and complex
Solution Approach 1:
The patent applies preliminary action by pre-configuring security parameters, encryption algorithms, and communication protocols into profiles before deployment. When a secure communication link needs to be established, the system simply selects and applies a pre-configured profile, eliminating the need for time-consuming manual configuration during operation.
Solution Approach 2:
The patent uses copying by creating template profiles that can be replicated and distributed across multiple devices. Once a secure communication profile is configured and validated, it can be copied to numerous devices, ensuring consistent security configurations without repeating the configuration process for each device individually.
2Adaptability or versatility
If device replacement is used to achieve desired communication properties, then security requirements can be met, but system complexity and cost increase
Solution Approach 1:
The patent applies dynamics by making communication properties dynamically adjustable through profile selection rather than being fixed at the device hardware level. Devices can switch between different communication profiles to adapt to varying security requirements, eliminating the need for physical device replacement when communication properties need to change.
Solution Approach 2:
The patent uses parameter changes by modifying communication parameters (encryption strength, protocol type, key management settings) through software-based profile configurations rather than hardware changes. This allows the system to adapt communication properties by changing parameters in existing devices rather than replacing devices.
3Manufacturing precision
If detailed manual configuration is performed, then precise control over security settings is achieved, but the process becomes complex and error-prone
Solution Approach 1:
The patent applies segmentation by dividing the complex security configuration into distinct, manageable profiles. Each profile encapsulates a specific set of security parameters, encryption settings, and communication protocols as a unified configuration unit. This segmentation allows precise control over security settings while simplifying the configuration process through modular profile selection.
Data Source
AI summary
A control system of an electric power distribution system includes processing circuitry and a memory having instructions that, when executed by the processing circuitry, cause the processing circuitry to perform operations that include receiving an indication of a profile, generating a connectivity association key (CAK) based on the profile, distributing a copy of the CAK to a device of the electric power distribution system, and establishing a connectivity association with the device in accordance with the profile based on a verification that the device possesses the copy of the CAK.


