Session Manager for Secure IED Credential Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing intelligent electronic devices (IEDs) face challenges in managing and updating large numbers of login credentials across a network, with legacy IEDs lacking modern security standards and modern IEDs requiring complex credential management, leading to difficulties in ensuring secure and compliant access control.

Innovation Solution

A session manager system is implemented to manage and update login credentials for multiple IEDs, supporting various communication protocols and ports, setting credentials based on access levels, and resetting them periodically to enforce strong security practices, while also providing authorization levels and filtering unauthorized commands.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual credential management is used for each IED, then legacy IEDs can maintain basic access control, but the complexity and time required to manage and update credentials increases significantly

Engineering Contradiction:
Improveaccess control securityVSAvoidcredential management time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces a session manager as an intermediary device that centralizes credential management for multiple IEDs. The session manager stores credentials locally and manages communication sessions, eliminating the need for manual credential updates on each IED. This mediator handles authentication and credential distribution automatically, resolving the contradiction between maintaining security reliability and reducing management time.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If modern security standards are implemented across all IEDs, then security compliance is improved, but legacy IEDs without modern security capabilities cannot be updated

Engineering Contradiction:
Improvesecurity complianceVSAvoidcompatibility with legacy devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The session manager acts as a security intermediary that implements modern security standards while supporting legacy IEDs. It enforces security policies, manages credentials with modern protection mechanisms, and adapts communication protocols to work with both modern and legacy devices. This allows the system to achieve security compliance through the session manager while maintaining compatibility with IEDs that lack native modern security capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments security functions by separating credential management and security enforcement into the session manager, distinct from the IEDs themselves. This segmentation allows modern security standards to be implemented in the session manager layer while leaving legacy IEDs unchanged, thereby achieving both security compliance and legacy compatibility simultaneously.

Inventive Principle:
Principle #1Segmentation

3Reliability

If a centralized system manages credentials for hundreds or thousands of IEDs, then uniform security standards are enforced, but the device complexity and infrastructure requirements increase

Engineering Contradiction:
Improveuniform security enforcementVSAvoidsession manager complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The session manager is designed as a universal device that can manage credentials and sessions for a large number of diverse IED types simultaneously. It supports multiple communication protocols and adapts to different IED capabilities, providing uniform security enforcement across heterogeneous networks. This multi-functionality reduces the need for multiple specialized systems, managing complexity through consolidation rather than proliferation of devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8677464B2Systems and methods for managing secure communication sessions with remote devices
Publication Date: 2014.03.18 SCHWEITZER ENGINEERING LABORATORIES INC
  • US8677464B2 patent drawing
  • US8677464B2 patent drawing
  • US8677464B2 patent drawing

AI summary

According to various embodiments, a session manager generates, stores, and periodically updates the login credentials for each of a plurality of connected IEDs. An operator, possibly via an access device, may provide unique login credentials to the session manager. The session manager may determine the authorization level of the operator based on the operator's login credentials, defining with which IEDs the operator may communicate. According to various embodiments, the session manager does not facilitate a communication session between the operator and a target IED. Rather, the session manager maintains a first communication session with the operator and initiates a second communication session with the target IED. Accordingly, the session manager may forward commands transmitted by the operator to the target IED. Based on the authorization level of the operator, a session filter may restrict what may be communicated between an operator and an IED.