Wind Turbine SCADA Access via Signed Metadata and Broker Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for accessing SCADA data from wind turbines lack secure and authorized access, risking data manipulation and unauthorized use.

Innovation Solution

A method involving digital signing and transmission of SCADA and master data through a broker server, creating metadata records, and using a distributed ledger database like blockchain for secure storage and access, ensuring data integrity and authorized usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If SCADA data are transmitted to a superordinate control unit for assessment and further processing, then the data become available for detecting malfunctions and developing optimizations, but the data may be manipulated or accessed by unauthorized users

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by digitally signing the SCADA data at the source (wind turbine) before transmission, and by requiring users to digitally sign their requests before data release. This pre-established cryptographic authentication ensures data integrity and authorized access without hindering operational accessibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The broker server acts as an intermediary between the wind turbine and user clients. It receives signed data from the turbine, creates metadata records, verifies user authorization through digital signatures, and controls data distribution. This intermediary layer protects data integrity while enabling controlled accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If digital signing and metadata records are implemented to protect SCADA data, then data integrity and authorized access are ensured, but the system complexity increases

Engineering Contradiction:
Improvedata protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the data protection system into distinct functional components: the wind turbine generates and signs data, the broker server creates metadata records and manages authorization, and user clients request and receive data. This segmentation distributes complexity across multiple independent modules, making the overall system more manageable despite the added security requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the state of data by adding digital signatures and metadata parameters. These parameter changes (cryptographic signatures, metadata records) provide protection and tracking without fundamentally altering the underlying SCADA data structure, thus adding security while maintaining data usability.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If metadata records are created and transmitted to user clients, then authorized users can identify and access relevant SCADA data, but the transmission and processing overhead increases

Engineering Contradiction:
Improvedata retrieval efficiencyVSAvoiddata transmission time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The broker server creates metadata records in advance, organizing and indexing SCADA data before user requests arrive. This preliminary organization allows users to quickly identify and retrieve relevant data without searching through raw data streams, improving retrieval efficiency while the metadata structure manages the transmission overhead.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11976634B2Method and assembly for accessing SCADA data of wind turbines
Publication Date: 2024.05.07 SIEMENS GAMESA RENEWABLE ENERGY SERVICE GMBH
  • US11976634B2 patent drawing

AI summary

The invention relates to a method for accessing SCADA data of a wind turbine in a protected manner and to an assembly designed to carry out said method. The SCADA data together with master data of the wind turbine is transmitted to a broker server in a digitally signed form, said broker server generating a metadata set on the basis of said data and transmitting the metadata set to user clients. If the user client is interested in the SCADA data, the user client transmits the metadata set back to the broker server in a digitally signed form. The broker server responds with a likewise digitally signed delivery data set comprising the metadata set signed by the user client and the SCADA and master data belonging to the metadata set.