Secure Wireless IED Communication for Remote Power Equipment Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing protection and control systems, such as those in industrial plants and power distribution systems, face challenges in securely communicating with intelligent electronic devices (IEDs) at a distance, particularly due to the presence of high voltage equipment, which complicates the setup and increases the time required for establishing connections.
Innovation Solution
A system utilizing a secure communication protocol, including a wireless local area network (WLAN) based on the IEEE 802.11n standard, enables IEDs to securely communicate with management devices, reducing the complexity of wiring and enhancing cybersecurity by using authentication processes and encryption methods, such as EAP and VPN, to facilitate secure data transmission and configuration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If wireless communication is used to communicate with IEDs at a distance, then operator safety is improved and wiring complexity is reduced, but security risks increase due to potential unauthorized access
Solution Approach 1:
An authentication server is introduced as an intermediary between the wireless communication system and IEDs. The authentication server verifies device credentials and manages authentication credentials, acting as a security mediator that enables remote wireless access while maintaining security through centralized credential verification
Solution Approach 2:
Authentication credentials are pre-configured in IEDs and the authentication server before wireless communication begins. This preliminary setup of security credentials ensures that when wireless communication is established, security verification is already in place, preventing unauthorized access from the outset
2Reliability
If traditional wired communication is used to connect to IEDs, then security is maintained through physical connection control, but the time and complexity to establish connections increases
Solution Approach 1:
The patent replaces the mechanical wired connection system with a wireless communication system. Instead of requiring physical cable connections, the system uses wireless protocols for communication, eliminating the time and complexity associated with physical connection establishment while maintaining security through digital authentication mechanisms
3Adaptability or versatility
If wireless communication infrastructure is deployed, then geographic flexibility is improved, but device complexity and setup requirements increase
Solution Approach 1:
The authentication server is designed as a universal platform that can authenticate multiple IEDs across different geographic locations through a single centralized system. This multi-functional approach allows the same authentication infrastructure to serve various locations and devices, reducing overall system complexity despite geographic distribution
Solution Approach 2:
The authentication server acts as a mediating infrastructure that simplifies wireless deployment by handling authentication centrally. Instead of requiring complex local authentication setups at each geographic location, the intermediary server provides centralized credential verification, reducing the complexity of deploying wireless communication across multiple locations
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The embodiments described herein provide a system including an intelligent electronic device (IED) (42) comprising a first processor (48) configured to communicate control commands to power equipment (44), receive measurements from the power equipment (44), use a secure wireless system (60) to send data to an access point (40), wherein the data includes the measurements, and use the secure system (60) to communicate with a management device (38), via the access point (40), to receive configuration information, command information, or any combination thereof.