Secured Power Distribution Network Device Onboarding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing power distribution communication networks face challenges in flexibility and security during the installation of new devices, as re-programming them is cumbersome and makes the network inflexible, leading to potential unauthorized access and fraudulent messages.
Innovation Solution
A method that updates the network topology to define device relations and rules, downloads relation tables and processing rules to new devices, and performs automatic evaluations of device-specific information to ensure secure communication, rejecting unauthorized devices and generating logs or alarms as needed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If new devices are programmed with communication parameters before installation, then security is improved, but installation flexibility deteriorates and the network becomes less adaptable
Solution Approach 1:
The system pre-generates device-specific information and communication parameters for new devices before they are actually installed in the network. This preliminary preparation allows devices to be pre-configured with security credentials without requiring manual programming during installation, thus maintaining both security and flexibility. The server automatically creates the necessary communication parameters based on device identifiers before the device joins the network.
Solution Approach 2:
The new device automatically receives and configures its communication parameters through self-service mechanisms. When a device joins the network, it autonomously retrieves its pre-generated device-specific information from the server and configures its communication settings without requiring manual intervention or re-programming. This self-configuration process maintains security while enabling flexible installation.
2Reliability
If manual re-programming of devices is performed during installation, then security parameters can be updated, but the installation process becomes cumbersome and time-consuming
Solution Approach 1:
Communication parameters and device-specific information are generated and prepared in advance by the server before the device is installed. This preliminary action eliminates the need for time-consuming manual re-programming during installation, as devices can be quickly configured using pre-prepared parameters that are automatically transmitted upon device joining.
Solution Approach 2:
The manual mechanical process of re-programming devices is replaced with an automated electronic system. The server automatically generates, transmits, and configures communication parameters through digital communication channels, eliminating the need for physical access to device programming interfaces and manual configuration steps.
3Reliability
If automatic device evaluation and rejection mechanisms are implemented, then network security is improved, but system complexity increases
Solution Approach 1:
The server acts as an intermediary that centralizes the automatic evaluation and device management functions. Instead of distributing complex evaluation logic across multiple network components, the server consolidates the device-specific information generation, transmission, and validation processes in a single centralized location, simplifying the overall system architecture while maintaining security.
Solution Approach 2:
The server performs multiple functions including device-specific information generation, secure parameter transmission, device evaluation, and network configuration management. By consolidating these diverse functions into a single multi-functional system, the patent reduces the number of separate components needed and simplifies the overall system complexity while maintaining comprehensive security controls.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention concerns a method for providing secured communication in a power distribution communication network (100) comprising - upon receipt of a request for the insertion of a new device to the power distribution communication network (100), - checking (301) unique ID of the new device received in the request against a list of stored new devices or suppliers stored in a data storage (126), - upon finding a matching entry, evaluating (302) predetermined device or supplier certificate against a certificate received in the request, - upon validation of the received certificate, checking (303) to determine if the new device will fit into a predetermined network topology or relation table, - configuring (304) the power distribution communication network (100) to include the new device in case the new device fits into the network topology or relation table. The invention also concerns a corresponding server and client.