Secured Power Distribution Network Device Onboarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing power distribution communication networks face challenges in flexibility and security during the installation of new devices, as re-programming them is cumbersome and makes the network inflexible, leading to potential unauthorized access and fraudulent messages.

Innovation Solution

A method that updates the network topology to define device relations and rules, downloads relation tables and processing rules to new devices, and performs automatic evaluations of device-specific information to ensure secure communication, rejecting unauthorized devices and generating logs or alarms as needed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If new devices are programmed with communication parameters before installation, then security is improved, but installation flexibility deteriorates and the network becomes less adaptable

Engineering Contradiction:
ImprovesecurityVSAvoidinstallation flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system pre-generates device-specific information and communication parameters for new devices before they are actually installed in the network. This preliminary preparation allows devices to be pre-configured with security credentials without requiring manual programming during installation, thus maintaining both security and flexibility. The server automatically creates the necessary communication parameters based on device identifiers before the device joins the network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The new device automatically receives and configures its communication parameters through self-service mechanisms. When a device joins the network, it autonomously retrieves its pre-generated device-specific information from the server and configures its communication settings without requiring manual intervention or re-programming. This self-configuration process maintains security while enabling flexible installation.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual re-programming of devices is performed during installation, then security parameters can be updated, but the installation process becomes cumbersome and time-consuming

Engineering Contradiction:
Improvesecurity parameter accuracyVSAvoidinstallation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Communication parameters and device-specific information are generated and prepared in advance by the server before the device is installed. This preliminary action eliminates the need for time-consuming manual re-programming during installation, as devices can be quickly configured using pre-prepared parameters that are automatically transmitted upon device joining.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The manual mechanical process of re-programming devices is replaced with an automated electronic system. The server automatically generates, transmits, and configures communication parameters through digital communication channels, eliminating the need for physical access to device programming interfaces and manual configuration steps.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If automatic device evaluation and rejection mechanisms are implemented, then network security is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The server acts as an intermediary that centralizes the automatic evaluation and device management functions. Instead of distributing complex evaluation logic across multiple network components, the server consolidates the device-specific information generation, transmission, and validation processes in a single centralized location, simplifying the overall system architecture while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The server performs multiple functions including device-specific information generation, secure parameter transmission, device evaluation, and network configuration management. By consolidating these diverse functions into a single multi-functional system, the patent reduces the number of separate components needed and simplifies the overall system complexity while maintaining comprehensive security controls.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2816760B1A method, a server and a client providing secured communication in a power distribution communication network
Publication Date: 2019.07.31 ALCATEL LUCENT SA
  • EP2816760B1 patent drawingFigure 1
  • EP2816760B1 patent drawingFigure 2
  • EP2816760B1 patent drawingFigure 3

AI summary

The invention concerns a method for providing secured communication in a power distribution communication network (100) comprising - upon receipt of a request for the insertion of a new device to the power distribution communication network (100), - checking (301) unique ID of the new device received in the request against a list of stored new devices or suppliers stored in a data storage (126), - upon finding a matching entry, evaluating (302) predetermined device or supplier certificate against a certificate received in the request, - upon validation of the received certificate, checking (303) to determine if the new device will fit into a predetermined network topology or relation table, - configuring (304) the power distribution communication network (100) to include the new device in case the new device fits into the network topology or relation table. The invention also concerns a corresponding server and client.