Session Manager for Secure IED Credential Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing intelligent electronic devices (IEDs) face challenges in managing and updating large numbers of login credentials across a network, with legacy IEDs lacking modern security standards and modern IEDs requiring complex credential management, leading to difficulties in ensuring secure and compliant access control.
Innovation Solution
A session manager system is implemented to manage and update login credentials for multiple IEDs, supporting various communication protocols and ports, setting credentials based on access levels, and resetting them periodically to enforce strong security practices, while also providing authorization levels and filtering unauthorized commands.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual credential management is used for each IED, then legacy IEDs can maintain basic access control, but the complexity and time required to manage and update credentials increases significantly
Solution Approach 1:
The patent introduces a session manager as an intermediary device that centralizes credential management for multiple IEDs. The session manager stores credentials locally and manages communication sessions, eliminating the need for manual credential updates on each IED. This mediator handles authentication and credential distribution automatically, resolving the contradiction between maintaining security reliability and reducing management time.
2Reliability
If modern security standards are implemented across all IEDs, then security compliance is improved, but legacy IEDs without modern security capabilities cannot be updated
Solution Approach 1:
The session manager acts as a security intermediary that implements modern security standards while supporting legacy IEDs. It enforces security policies, manages credentials with modern protection mechanisms, and adapts communication protocols to work with both modern and legacy devices. This allows the system to achieve security compliance through the session manager while maintaining compatibility with IEDs that lack native modern security capabilities.
Solution Approach 2:
The system segments security functions by separating credential management and security enforcement into the session manager, distinct from the IEDs themselves. This segmentation allows modern security standards to be implemented in the session manager layer while leaving legacy IEDs unchanged, thereby achieving both security compliance and legacy compatibility simultaneously.
3Reliability
If a centralized system manages credentials for hundreds or thousands of IEDs, then uniform security standards are enforced, but the device complexity and infrastructure requirements increase
Solution Approach 1:
The session manager is designed as a universal device that can manage credentials and sessions for a large number of diverse IED types simultaneously. It supports multiple communication protocols and adapts to different IED capabilities, providing uniform security enforcement across heterogeneous networks. This multi-functionality reduces the need for multiple specialized systems, managing complexity through consolidation rather than proliferation of devices.
Data Source
AI summary
According to various embodiments, a session manager generates, stores, and periodically updates the login credentials for each of a plurality of connected IEDs. An operator, possibly via an access device, may provide unique login credentials to the session manager. The session manager may determine the authorization level of the operator based on the operator's login credentials, defining with which IEDs the operator may communicate. According to various embodiments, the session manager does not facilitate a communication session between the operator and a target IED. Rather, the session manager maintains a first communication session with the operator and initiates a second communication session with the target IED. Accordingly, the session manager may forward commands transmitted by the operator to the target IED. Based on the authorization level of the operator, a session filter may restrict what may be communicated between an operator and an IED.


