Virtual Security Perimeter for Deterministic Power Substation Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity measures for critical infrastructure, such as the NERC CIP initiatives, lack specific implementation details for ensuring secure communication perimeters, particularly in deterministic networking environments where precise timing and zero packet loss are critical.

Innovation Solution

Implementing a Security Perimeter Manager (SPM) that computes paths and schedules communications within a virtual electronic security perimeter using deterministic networking, ensuring all mission-critical communications are contained and authenticated through strict authorization and encryption mechanisms, leveraging Deterministic Ethernet protocols and security certificates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If NERC CIP security perimeter requirements are implemented, then cybersecurity protection is improved, but implementation complexity increases due to lack of specific implementation details

Engineering Contradiction:
Improvecybersecurity protectionVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Security Perimeter Manager (SPM) as an intermediary component that mediates between the NERC CIP security requirements and the deterministic networking infrastructure. The SPM computes security paths, manages security certificates, and enforces perimeter policies without requiring end users to implement complex security logic themselves, thus improving cybersecurity protection while reducing implementation complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network into distinct security perimeters with clearly defined boundaries and access points. By dividing the network infrastructure into segmented zones with controlled communication paths, the system provides structured cybersecurity protection that simplifies compliance implementation while maintaining robust security boundaries

Inventive Principle:
Principle #1Segmentation

2Reliability

If strict authorization and encryption mechanisms are enforced at access points, then security is improved, but communication timing precision deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication timing precision
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs security authentication and authorization actions in advance before actual data transmission occurs. Security certificates are validated and access permissions are established beforehand, allowing subsequent communications to proceed with minimal security processing delay. This preliminary security setup preserves deterministic timing requirements while maintaining strict security enforcement

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes continuous security session states where authenticated communication paths maintain their security context across multiple transactions. Once a communication path is authorized within the security perimeter, the security validation continues seamlessly without repeated authentication overhead, ensuring both continuous security protection and precise communication timing

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If all communications are contained within security perimeter, then cybersecurity is improved, but network adaptability deteriorates

Engineering Contradiction:
ImprovecybersecurityVSAvoidnetwork adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security path computation that can adapt communication routes within the security perimeter based on changing network conditions, device availability, and traffic requirements. The Security Perimeter Manager dynamically recalculates secure paths while maintaining perimeter boundaries, providing both cybersecurity protection and network adaptability through flexible, real-time path optimization

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10516661B2Virtual electronic security perimeter using deterministic networking
Publication Date: 2019.12.24 CISCO TECHNOLOGY INC
  • US10516661B2 patent drawing
  • US10516661B2 patent drawing
  • US10516661B2 patent drawing

AI summary

In one embodiment, a supervisory device for a network of a power substation identifies a plurality of nodes in the network of the power substation. The supervisory device associates each of the nodes with one or more security certificates. A particular security certificate authenticates a particular node to the supervisory device and authorizes the particular node to communicate in the network of the power substation. The supervisory device determines a security perimeter for the nodes in the network. The supervisory device schedules communications among the nodes using the one or more security certificates and based on the determined security perimeter.