Security through layers in an intelligent electronic device

US10303860B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10303860-B2
Application numberUS-201514742061-A
CountryUS
Kind codeB2
Filing dateJun 17, 2015
Priority dateOct 4, 2011
Publication dateMay 28, 2019
Grant dateMay 28, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The present disclosure provides for improving security in a meter or an intelligent electronic device (IED) through the use of a security key which is unique to each meter or IED. Such a key may be used to prevent password reuse among multiple meters. Such a key may also be used to encrypt critical components of the software, such that only when running on the correct meter can the components of the software be decrypted. Such a key may also be used to uniquely identify the device in a larger data collection and management system. The security key can also be used to prevent the direct copying of meters. The present disclosure also provides for a meter or IED that stores functional software separately from core software.

First claim

Opening claim text (preview).

What is claimed is: 1. An intelligent electronic device (IED) comprising: at least one sensor coupled to at least one power line of an electrical power distribution system and configured for measuring at least one power parameter of the at least one power line and generating at least one analog signal indicative of the at least one power parameter; at least one analog to digital converter coupled to the at least one sensor configured for receiving the at least one analog signal and converting the at least one analog signal to at least one digital signal; at least one first processor configured for executing at least one application, the at least one application requiring a security key, the security key including at least one component with each of the at least one component being stored in a different location, the security key being generated by iteratively encrypting a key with the at least one component, wherein at least one of the at least one component is changed after a predetermined period of time; at least one second processor in communication with the at least one first processor, the at least one second processor configured to receive a message from the at least one first processor, retrieve the security key from at least one location, decrypt the message and return the decrypted message to the at least one first processor, and a storage device that stores measured and calculated data, wherein the message is a request for access to data stored in the storage device, wherein the message includes a payload key to be decrypted by the security key and the returned decrypted message includes a decrypted payload key to decrypt the at least one application in the at least one first processor. 2. The IED of claim 1 , wherein the message is the at least one application. 3. The IED of claim 1 , wherein the at least one second processor generates the security key. 4. The IED of claim 1 , wherein the at least one second processor decrypts at least one software application. 5. The IED of claim 1 , further comprising a private key for encryption and password generation and a public key for identifying the IED. 6. The IED of claim 5 , wherein the public key is a transport security layer (TSL) certificate. 7. The IED of claim 5 , wherein the at least one second processor generates a unique signature based on the private key and public key. 8. The IED of claim 1 , wherein the IED is one of a Programmable Logic Controller (PLC), a Remote Terminal Unit (RTU), an electric power meter, a revenue meter, a protective relay, a fault recorder, a phase measurement unit, a serial switch and a smart input/output device. 9. The IED of claim 1 , wherein the at least one sensor, at least one analog to digital converter, at least one first processor and at least one second processor are disposed in a housing. 10. The IED of claim 9 , wherein the housing is at least one of a socket/S-base housing, a panel meter housing, a switchboard/draw-out housing and a A-base housing. 11. An intelligent electronic device (IED) comprising: at least one sensor coupled to at least one power line of an electrical power distribution system and configured for measuring at least one power parameter of the at least one power line and generating at least one analog signal indicative of the at least one power parameter; at least one analog to digital converter coupled to the at least one sensor configured for receiving the at least one analog signal and converting the at least one analog signal to at least one digital signal; at least one first processor configured for executing at least one software application, the at least one application requiring a security key, the security key including at least one component with each of the at least one component being stored in a different location, the security key being generated by iteratively encrypting a key with the at least one component, wherein at least one of the at least one component is changed after a predetermined period of time; and at least one second processor in communication with the at least one first processor, the at least one second processor configured to receive a message from the at least one first processor, retrieve the security key from at least one location, decrypt the message and return the decrypted message to the at least one first processor, wherein the message is the at least one software application, wherein the message includes a payload key to be decrypted by the security key and the returned decrypted message includes a decrypted payload key to decrypt the at least one software application in the at least one first processor. 12. The IED of claim 11 , wherein the at least one second processor generates the security key. 13. The IED of claim 11 , wherein the at least one second processor decrypts the at least one software application. 14. The IED of claim 11 , further comprising a private key for encryption and password generation and a public key for identifying the IED. 15. The IED of claim 14 , wherein the public key is a transport security layer (TSL) certificate. 16. The IED of claim 14 , wherein the at least one second processor generates a unique signature based on the private key and public key. 17. The IED of claim 11 , wherein the IED is one of a Programmable Logic Controller (PLC), a Remote Terminal Unit (RTU), an electric power meter, a revenue meter, a protective relay, a fault recorder, a phase measurement unit, a serial switch and a smart input/output device. 18. The IED of claim 11 , wherein the at least one sensor, at least one analog to digital converter, at least one first processor and at least one second processor are disposed in a housing. 19. The IED of claim 18 , wherein the housing is at least one of a socket/S-base housing, a panel meter housing, a switchboard/draw-out housing and a A-base housing. 20. An intelligent electronic device (IED) comprising: at least one sensor coupled to at least one power line of an electrical power distribution system and configured for measuring at least one power parameter of the at least one power line and generating at least one analog signal indicative of the at least one power parameter; at least one analog to digital converter coupled to the at least one sensor configured for receiving the at least one analog signal and converting the at least one analog signal to digital data; and at least one processor configured for executing at least one application, the at least one application requiring a security key, the security key including at least one component with each of the at least one component being stored in a different location, the security key being generated by iteratively encrypting a key with the at least one component, wherein at least one of the at least one component is changed after a predetermined period of time; wherein the at least one processor is configured to receive a message, retrieve the security key from at least one location, decrypt the message based on the retrieved key, and wherein the message includes a payload key to be decrypted by the security key and the decrypted message includes a decrypted payload key to decrypt the at least one application. 21. The IED of claim 20 , further comprising a storage device that stores the measured digital data and calculated data, wherein the message includes a request for access to data stored in the storage device. 22. The IED of claim 20 , wherein the IED is one of a Programmable Logic Controller (PLC)

Assignees

Inventors

Classifications

  • related to remote communication · CPC title

  • Network protocols supporting networked applications, e.g. including control of end-device applications over a network · CPC title

  • against software analysis or reverse engineering, e.g. by obfuscation · CPC title

  • Cross-Sectional Technologies · mapped topic

  • specially adapted for file transfer, e.g. file transfer protocol [FTP] · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10303860B2 cover?
The present disclosure provides for improving security in a meter or an intelligent electronic device (IED) through the use of a security key which is unique to each meter or IED. Such a key may be used to prevent password reuse among multiple meters. Such a key may also be used to encrypt critical components of the software, such that only when running on the correct meter can the components o…
Who is the assignee on this patent?
Electro Industries/Gauge Tech
What technology area does this patent fall under?
Primary CPC classification G01D4/004. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue May 28 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 5 related publications on this page (citations in our corpus or others sharing the same primary CPC).