Token-Based Access Control Using Device Uptime for IED Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing token-based access systems in electric power distribution and transmission systems are vulnerable to unauthorized access due to manual modifications of the system clock or spoofing of network-provided time, allowing users to gain extended or unauthorized access to intelligent electronic devices (IEDs).
Innovation Solution
Implementing a token-based access system that uses the device uptime of IEDs to limit access duration and initial access windows, rather than relying on the system clock or network-provided time, ensuring that access privileges are revoked based on the device's uptime counter, which is not user-changeable and not dependent on external time signals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the system clock or network-provided time is used to measure access duration, then the access control system can provide flexible time-based access management, but the system becomes vulnerable to unauthorized access through manual clock modification or time spoofing
Solution Approach 1:
The patent introduces an uptime counter as an intermediary time measurement mechanism that sits between the access control system and the time source. This counter increments monotonically based on system operation duration and cannot be manually altered, serving as a trusted mediator that provides time-based access control without the security vulnerabilities of direct clock manipulation
Solution Approach 2:
The system uses its own internal uptime counter to measure access duration, eliminating dependence on external time sources or manual clock settings. The device serves itself by generating and tracking its own operational time, making the access control mechanism independent of external time synchronization or user-modifiable time settings
2Ease of operation
If the system allows manual clock modification for maintenance purposes, then device maintenance becomes more convenient, but security is compromised allowing extended unauthorized access
Solution Approach 1:
The patent separates the time measurement function into two independent components: a user-modifiable system clock for scheduling and display purposes, and a protected uptime counter for security-critical access duration measurement. This segmentation allows maintenance operations to modify the clock without affecting the security mechanism
Solution Approach 2:
Instead of using the system clock to measure access duration (which can be modified), the patent inverts the approach by using a dedicated uptime counter that counts upward from system initialization. This inversion makes the time measurement immune to clock adjustments while still providing the necessary time-based access control
3Stability of the object's composition
If network-provided time is used for synchronization, then multiple devices can maintain consistent time, but the system becomes dependent on external time sources that can be spoofed
Solution Approach 1:
The uptime counter serves as an intermediary that provides time measurement without requiring external time synchronization. Each device generates its own monotonic time based on operational duration, eliminating the need to trust external time sources while maintaining consistent access control across the network
Solution Approach 2:
Each device in the network independently generates and tracks its own uptime counter without relying on network time synchronization protocols. This self-service approach to time measurement makes the system independent of external time sources and immune to network time spoofing attacks
Data Source
AI summary
Systems and methods are described herein for token-based access to an intelligent electronic device (IED) resource in a power delivery system. A token server and an IED resource may be communicatively connected via a communication network. The token server may generate a token associated with access privileges to one or more IED resources. The token server associates an access duration time with the generated token. The user presents the IED resource with the token as part of an access attempt. The IED resource grants access at a first time defined with reference to the device uptime of the IED resource until a second time defined with reference to the device up time. The difference between the first time and the second time corresponds to the access duration time of the token.


