Secure Wireless IED Communication for Remote Power Equipment Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing protection and control systems, such as those in industrial plants and power distribution systems, face challenges in securely communicating with intelligent electronic devices (IEDs) at a distance, particularly due to the presence of high voltage equipment, which complicates the setup and increases the time required for establishing connections.

Innovation Solution

A system utilizing a secure communication protocol, including a wireless local area network (WLAN) based on the IEEE 802.11n standard, enables IEDs to securely communicate with management devices, reducing the complexity of wiring and enhancing cybersecurity by using authentication processes and encryption methods, such as EAP and VPN, to facilitate secure data transmission and configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless communication is used to communicate with IEDs at a distance, then operator safety is improved and wiring complexity is reduced, but security risks increase due to potential unauthorized access

Engineering Contradiction:
Improveoperator safetyVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

An authentication server is introduced as an intermediary between the wireless communication system and IEDs. The authentication server verifies device credentials and manages authentication credentials, acting as a security mediator that enables remote wireless access while maintaining security through centralized credential verification

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Authentication credentials are pre-configured in IEDs and the authentication server before wireless communication begins. This preliminary setup of security credentials ensures that when wireless communication is established, security verification is already in place, preventing unauthorized access from the outset

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional wired communication is used to connect to IEDs, then security is maintained through physical connection control, but the time and complexity to establish connections increases

Engineering Contradiction:
ImprovesecurityVSAvoidconnection establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces the mechanical wired connection system with a wireless communication system. Instead of requiring physical cable connections, the system uses wireless protocols for communication, eliminating the time and complexity associated with physical connection establishment while maintaining security through digital authentication mechanisms

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If wireless communication infrastructure is deployed, then geographic flexibility is improved, but device complexity and setup requirements increase

Engineering Contradiction:
Improvegeographic flexibilityVSAvoidinfrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication server is designed as a universal platform that can authenticate multiple IEDs across different geographic locations through a single centralized system. This multi-functional approach allows the same authentication infrastructure to serve various locations and devices, reducing overall system complexity despite geographic distribution

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication server acts as a mediating infrastructure that simplifies wireless deployment by handling authentication centrally. Instead of requiring complex local authentication setups at each geographic location, the intermediary server provides centralized credential verification, reducing the complexity of deploying wireless communication across multiple locations

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2779587B1Wireless communication systems and methods for intelligent electronic devices
Publication Date: 2021.04.28 GENERAL ELECTRIC CO
  • EP2779587B1 patent drawingFigure 1
  • EP2779587B1 patent drawingFigure 2
  • EP2779587B1 patent drawingFigure 3

AI summary

The embodiments described herein provide a system including an intelligent electronic device (IED) (42) comprising a first processor (48) configured to communicate control commands to power equipment (44), receive measurements from the power equipment (44), use a secure wireless system (60) to send data to an access point (40), wherein the data includes the measurements, and use the secure system (60) to communicate with a management device (38), via the access point (40), to receive configuration information, command information, or any combination thereof.