Wind Turbine Control Integrity Check Using Runtime Master Key Derivation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In wind turbines, the storage of the master key within modules poses security risks as it can be compromised or stolen, allowing unauthorized access and analysis, leading to potential tampering and operational disruptions.
Innovation Solution
The master key is derived at runtime from the environmental features of multiple sets of controls, ensuring it is not stored within any single module, thus preventing unauthorized access and enabling secure startup only when all controls confirm integrity and origin of tokens.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the master key is stored within a module, then the module can be easily started up and operated, but the security is compromised as the key can be read out, stolen, or accessed by unauthorized interventions
Solution Approach 1:
The master key is extracted from the individual module and relocated to an external secure storage location. The key is no longer stored within the module itself but is kept in a secure environment outside the module, preventing unauthorized access while maintaining operational capability through controlled key provision.
Solution Approach 2:
A key provision device acts as an intermediary between the secure key storage and the module. This mediator controls the provision of the master key to the module, ensuring that the key is only made available when proper authentication and integrity verification are performed, thus balancing security with operational ease.
2Reliability
If the master key is derived from hardware features of internal devices, then the key is not stored externally, but replacement of the controller is not possible without generating a new master key and re-encrypting all data
Solution Approach 1:
The key management system is segmented into separate components: the master key is stored externally in a secure location, while the module contains only the capability to request and use the key temporarily. This segmentation allows the controller to be replaced without affecting the master key storage, as the key remains in the external secure storage and can be provisioned to new controllers as needed.
Solution Approach 2:
The external key provision device serves multiple functions: it securely stores the master key, authenticates modules, verifies integrity, and provisions keys to multiple different controllers. This universal approach allows any controller to be replaced without generating new keys, as the external device manages key distribution to all controllers uniformly.
3Adaptability or versatility
If the master key is entered by the user, then the key can be changed and controllers replaced, but it is known to employees of the machine manufacturer creating a security risk
Solution Approach 1:
The master key is extracted from human knowledge and stored in a secure automated system. Instead of employees knowing the key, the key is stored in a protected environment with access controlled by automated authentication mechanisms, eliminating the security risk associated with human knowledge of the key while maintaining the ability to provision keys to authorized controllers.
Solution Approach 2:
The key provision device operates autonomously to manage master key security. It automatically authenticates modules, verifies integrity through cryptographic checks, and provisions keys without requiring human employees to know or handle the master key. The system serves itself in managing key security, eliminating the need for human key custodians.
4Reliability
If the controller and device are stolen, then the controller boots normally allowing analysis, but with the invention the stolen controller cannot be started up without the surrounding sets of controls
Solution Approach 1:
The security verification process merges multiple functions into a unified startup procedure: the external key provision device simultaneously performs authentication, integrity verification, and key provisioning in a single coordinated process. This merged approach prevents stolen controllers from booting normally while maintaining a streamlined startup procedure that appears simple despite the complex security checks performed.
Data Source
AI summary
A method and a device for checking the integrity of modules of a technical facility. The technical facility has multiple modules and sets of controls for controlling the technical facility. For starting up each set of controls and the overall technical facility, a master key is used which is utilized for decrypting an encrypted region of the set of controls. The master key for starting up a set of controls of the technical facility is derived from features of all sets of controls installed in the technical facility, and a start or a start-up of the technical facility can take place only when the master key is found to be satisfactory.


