IP Library › Granted Patent US 12,244,143
Granted Patent B2
US 12,244,143 · App. 17/583,384 · Granted Mar 4, 2025

Methods of securely controlling utility grid edge devices

Inventors: David Crawford Lawrence (Charlotte, NC); Marshal Dwayne Bradley (Gastonia, NC); Thomas E. Burdick (Chicago, IL); Jessica C. Modeen (Charlotte, NC); Nicholas J. Kennedy (Jasper, AL); Matthew A. DeVenny (Phoenix, AZ); Caleb J. Lloyd (Raleigh, NC); C. Wilson Kinard (Greenville, SC)
Assignees: DUKE ENERGY CORPORATION; OPEN ENERGY SOLUTIONS INC.
H02J13/00016G06F21/72H02J13/00022
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,244,143
App. No.
17/583,384
Granted
Mar 4, 2025
Kind
B2
Abstract

Methods of securely controlling a utility grid edge device are provided. A method of securely controlling a utility grid edge device includes receiving renewed security information at a node that includes cryptographic circuitry. Moreover, the method includes controlling an operation of the utility grid edge device via the node, after receiving the renewed security information. Related nodes and utility grid edge devices are also provided.

Claims (37)

1. A method of securely controlling a utility grid edge device, the method comprising:

receiving renewed security information, from a distributed certification authority (CA) server on a first node in a cluster of nodes, at a second node within the cluster of nodes and that is adjacent the utility grid edge device and that includes cryptographic circuitry comprising a Trusted Platform Module (TPM), wherein the first node, the second node receiving the renewed security information, and the utility grid edge device are each outside of a data center, wherein the second node comprises a memory comprising an agent and a workload, wherein the workload comprises an application that controls an operation of the utility grid edge device, and wherein receiving the renewed security information at the second node comprises:

receiving the renewed security information at the agent from the distributed CA server on the first node,

providing the renewed security information from the agent to the workload, wherein the renewed security information comprises a private digital security key and a public digital security key and automatically expires in no more than one hour, and

patching or updating the workload using a Public Key Infrastructure (PKI); then controlling the operation of the utility grid edge device via the second node.

2. The method of claim 1 , wherein the method further comprises using the renewed security information to provide identity-based encrypted communications between the workload and another workload that is on the second node or on another node within the cluster of nodes that is different from the first and second nodes.

3. The method of claim 2 , wherein the encrypted communications are provided via a data broker that is on the second node or on the another node in the cluster of nodes.

4. The method of claim 1 ,

wherein the utility grid edge device comprises a first utility grid edge device, and

wherein the method further comprises controlling, via the second node, an operation of a second utility grid edge device that is adjacent the second node.

5. The method of claim 4 , wherein adjacent the second node comprises no more than thirty meters from the second node.

6. The method of claim 4 , wherein controlling the operation of the first utility grid edge device and controlling the operation of the second utility grid edge device are performed via first and second workloads, respectively, on the first and second nodes.

7. The method of claim 1 , wherein controlling the operation of the utility grid edge device is performed via a direct, wired communications link that is between the second node and the utility grid edge device.

8. The method of claim 1 , wherein controlling the operation of the utility grid edge device is performed via a wireless communications link that is between the second node and the utility grid edge device.

9. The method of claim 1 ,

wherein the method further comprises providing trust bundles from a certificate authority (CA) to a distributed CA node orchestrator that communicates with the second node and a third node within the cluster of nodes, and

wherein the trust bundles comprise digital certificates and/or digital keys and enable communications, or other operations, with respect to utility grid edge devices.

10. The method of claim 1 , wherein the utility grid edge device is at a customer premise.

11. The method of claim 1 , wherein the utility grid edge device is a first utility grid edge device of a feeder and is adjacent a recloser of the feeder.

12. The method of claim 11 ,

wherein the feeder further comprises a second utility grid edge device and a third node within the cluster of nodes and that is adjacent to the second utility grid edge device, and

wherein the method further comprises using the renewed security information to provide encrypted communications between the second node and the third node.

13. The method of claim 1 ,

wherein the utility grid edge device is a first utility grid edge device of a microgrid,

wherein the microgrid further comprises a second utility grid edge device that is adjacent a third node, and

wherein the method further comprises using the renewed security information to provide encrypted communications between the second node and the third node.

14. The method of claim 1 , wherein controlling the operation of the utility grid edge device via the second node comprises:

removing a first workload from the second node and/or adding a second workload to the second node.

15. The method of claim 1 , further comprising, before

receiving the renewed security information:

powering-on the second node;

accessing a digital security key at the second node by using the cryptographic circuitry;

sending the digital security key from the second node to the distributed CA server on the first node;

receiving encrypted data at the second node from the distributed CA server on the first node;

decrypting the data at the second node;

transmitting the decrypted data from the second node to the distributed CA server on the first node; and

receiving a digital certificate at the second node from the distributed CA server on the first node, in response to transmitting the decrypted data from the second node to the distributed CA server on the first node.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2022
From: LAWRENCE, DAVID CRAWFORD; BRADLEY, MARSHAL DWAYNE
To: DUKE ENERGY CORPORATION
Reel/Frame 058756/0151 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2022
From: BURDICK, THOMAS E.; MODEEN, JESSICA C.
To: OPEN ENERGY SOLUTIONS INC.
Reel/Frame 058756/0238 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2022
From: KENNEDY, NICHOLAS J.; DEVENNY, MATTHEW A.; LLOYD, CALEB J.; KINARD, C. WILSON
To: BOXBOAT TECHNOLOGIES
Reel/Frame 058756/0350 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2022
From: BOXBOAT TECHNOLOGIES
To: OPEN ENERGY SOLUTIONS INC.
Reel/Frame 058756/0371 →
Continuity (2)
Provisional Application 63174704 · Apr 14, 2021
Related Publication 20220337082A1 · Oct 20, 2022
References Cited (13)
US 5689565A · Spies · 1997 [cited by examiner]
US 9722665B2 · Smith et al. · 2017 [cited by applicant]
US 10523597B2 · Giorgi · 2019 [cited by examiner]
US 11115224B1 · Scofield · 2021 [cited by examiner]
US 20050111560A1 · Haines · 2005 [cited by examiner]
US 20080059799A1 · Scarlata · 2008 [cited by examiner]
US 20110126002A1 · Fu · 2011 [cited by examiner]
US 20120266209A1 · Gooding · 2012 [cited by examiner]
US 20150088325A1 · Forbes, Jr. · 2015 [cited by examiner]
US 20150097694A1 · Laval · 2015 [cited by examiner]
US 20150378382A1 · Phatak · 2015 [cited by examiner]
US 20170229868A1 · Laval · 2017 [cited by examiner]
US 20200322353A1 · Bhandari · 2020 [cited by examiner]
Cited By (1)
US 12,489,641