Wind Turbine Control Integrity Check Using Runtime Master Key Derivation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wind turbines, the storage of the master key within modules poses security risks as it can be compromised or stolen, allowing unauthorized access and analysis, leading to potential tampering and operational disruptions.

Innovation Solution

The master key is derived at runtime from the environmental features of multiple sets of controls, ensuring it is not stored within any single module, thus preventing unauthorized access and enabling secure startup only when all controls confirm integrity and origin of tokens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the master key is stored within a module, then the module can be easily started up and operated, but the security is compromised as the key can be read out, stolen, or accessed by unauthorized interventions

Engineering Contradiction:
Improvemodule startupVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The master key is extracted from the individual module and relocated to an external secure storage location. The key is no longer stored within the module itself but is kept in a secure environment outside the module, preventing unauthorized access while maintaining operational capability through controlled key provision.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

A key provision device acts as an intermediary between the secure key storage and the module. This mediator controls the provision of the master key to the module, ensuring that the key is only made available when proper authentication and integrity verification are performed, thus balancing security with operational ease.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the master key is derived from hardware features of internal devices, then the key is not stored externally, but replacement of the controller is not possible without generating a new master key and re-encrypting all data

Engineering Contradiction:
Improvekey securityVSAvoidcontroller replacement
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The key management system is segmented into separate components: the master key is stored externally in a secure location, while the module contains only the capability to request and use the key temporarily. This segmentation allows the controller to be replaced without affecting the master key storage, as the key remains in the external secure storage and can be provisioned to new controllers as needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The external key provision device serves multiple functions: it securely stores the master key, authenticates modules, verifies integrity, and provisions keys to multiple different controllers. This universal approach allows any controller to be replaced without generating new keys, as the external device manages key distribution to all controllers uniformly.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If the master key is entered by the user, then the key can be changed and controllers replaced, but it is known to employees of the machine manufacturer creating a security risk

Engineering Contradiction:
Improvecontroller replacementVSAvoidkey confidentiality
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The master key is extracted from human knowledge and stored in a secure automated system. Instead of employees knowing the key, the key is stored in a protected environment with access controlled by automated authentication mechanisms, eliminating the security risk associated with human knowledge of the key while maintaining the ability to provision keys to authorized controllers.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The key provision device operates autonomously to manage master key security. It automatically authenticates modules, verifies integrity through cryptographic checks, and provisions keys without requiring human employees to know or handle the master key. The system serves itself in managing key security, eliminating the need for human key custodians.

Inventive Principle:
Principle #25Self-service

4Reliability

If the controller and device are stolen, then the controller boots normally allowing analysis, but with the invention the stolen controller cannot be started up without the surrounding sets of controls

Engineering Contradiction:
Improvetheft protectionVSAvoidstartup procedure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security verification process merges multiple functions into a unified startup procedure: the external key provision device simultaneously performs authentication, integrity verification, and key provisioning in a single coordinated process. This merged approach prevents stolen controllers from booting normally while maintaining a streamlined startup procedure that appears simple despite the complex security checks performed.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11650558B2Method and device for checking the integrity of modules of a wind turbine
Publication Date: 2023.05.16 BACHMANN GMBH
  • US11650558B2 patent drawing
  • US11650558B2 patent drawing
  • US11650558B2 patent drawing

AI summary

A method and a device for checking the integrity of modules of a technical facility. The technical facility has multiple modules and sets of controls for controlling the technical facility. For starting up each set of controls and the overall technical facility, a master key is used which is utilized for decrypting an encrypted region of the set of controls. The master key for starting up a set of controls of the technical facility is derived from features of all sets of controls installed in the technical facility, and a start or a start-up of the technical facility can take place only when the master key is found to be satisfactory.