IP Library Granted Patent US 8,793,767
Granted Patent B2
US 8,793,767 · App. 13/599,927 · Granted Jul 29, 2014

Network access management via a secondary communication channel

Inventors: Edmund O. Schweitzer, III (Pullman, WA); David E. Whitehead (Pullman, WA); Rhett Smith (Kuna, ID); Mark Weber (Pullman, WA)
Assignee: Schweitzer Engineering Laboratories Inc
G06F21/606G06F21/82
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,793,767
App. No.
13/599,927
Granted
Jul 29, 2014
Kind
B2
Abstract

The present disclosure provides for selectively enabling a primary communication channel upon receipt of enablement instructions received via a secondary communication channel. In some embodiments, a first intelligent electronic device (IED) may be connected to a second IED via a primary communication channel. In various embodiments, the primary communication channel may be selectively and/or temporarily enabled by transmitting an enablement instruction via a secondary communication channel. The secondary communication channel may be relatively more secure than the primary communication channel. In some embodiments, the secondary communication channel may also connect the first and second IEDs. Accordingly, the first IED may transmit an enablement instruction to the second IED in order to temporarily enable communication via the primary communication channel between the first and second IEDs.

Claims (51)

1. A method for enabling network communication with an intelligent electronic device (IED), comprising:

disabling communication via a first communication channel with the IED to prevent communication via the first communication channel;

enabling communication via a second communication channel with the IED, wherein the first communication channel and the second communication channel are physically distinct communication channels,

wherein the second communication channel is a private communication channel that is physically secure;

receiving an enablement instruction via the private and physically secure second communication channel, the enablement instruction providing an instruction to activate the first communication channel;

enabling communication via the first communication channel with the IED in response to the enablement instruction; and

receiving communication via the first communication channel.

2. The method of claim 1 , further comprising the intelligent electronic device disabling communication via the first communication channel in response to a disabling event.

3. The method of claim 1 , wherein the first communication channel utilizes a first communication protocol and the second communication channel utilizes a second communication protocol.

4. The method of claim 1 , wherein the first communication channel utilizes a first type of physical network link and the second communication channel utilizes a second type of physical network link.

5. The method of claim 1 , wherein the first communication channel communicates via a first communication network and the second communication channel communicates via a second, independent communication network.

6. The method of claim 1 , wherein the second communication channel comprises a contact input.

7. The method of claim 1 , wherein the second communication channel comprises an Ethernet link.

8. The method of claim 1 , wherein the second communication channel comprises a serial port.

9. The method of claim 1 , wherein the first communication channel comprises a wireless network.

10. The method of claim 9 , wherein the wireless network comprises a cellular network.

11. The method of claim 1 , wherein the enablement instruction comprises a supervisory control and data acquisition tag.

12. The method of claim 1 , wherein the enablement instruction comprises a toggle of a contact input.

13. The method of claim 1 , wherein the first communication channel comprises a network communication channel accessible via a wide area network (WAN) and the second communication channel comprises a network communication channel accessible via a secure network.

14. The method of claim 2 , wherein the disabling event comprises a disablement instruction received via one of the second communication channel and the first communication channel.

15. The method of claim 2 , wherein the disabling event comprises an expiration of a time limit.

16. The method of claim 1 , wherein the step of enabling communication via the first communication channel further comprises encryption of communication via the first communication channel.

17. A system for managing network communication with an intelligent electronic device (IED), comprising:

a first communication channel configured to facilitate network communication with the IED, the first communication channel configured to be selectively enabled and disabled, wherein the first communication channel is prevented from communicating when disabled;

a second communication channel for receiving an enablement instruction, the enablement instruction providing an instruction to activate network communication via the first communication channel,

wherein the second communication channel is a private communication channel that is physically secure; and

an access module configured to enable network communication via the first communication channel in response to receiving the enablement instruction via the private and physically secure second communication channel,

wherein the first communication channel and the second communication channel are physically distinct communication channels.

18. The system of claim 17 , wherein the first communication channel utilizes a first communication protocol and the second communication channel utilizes a second communication protocol.

19. The system of claim 17 , wherein the first communication channel utilizes a first type of physical network link and the second communication channel utilizes a second type of physical network link.

20. The system of claim 17 , wherein the first communication channel communicates via a first communication network and the second communication channel communicates via a second, independent communication network.

21. The system of claim 17 , wherein the second communication channel comprises a contact input.

22. The system of claim 17 , wherein the second communication channel comprises an Ethernet link.

23. The system of claim 17 , wherein the second communication channel comprises a serial port.

24. The system of claim 17 , wherein the first communication channel comprises a wireless network.

25. The system of claim 24 , wherein the wireless network comprises a cellular network.

26. The system of claim 17 , wherein the enablement instruction comprises a supervisory control and data acquisition tag.

27. The system of claim 17 , wherein the enablement instruction comprises a toggle of a contact input.

28. The system of claim 17 , wherein the first communication channel comprises a network communication channel accessible via a wide area network (WAN) and the second communication channel comprises a network communication channel accessible via a secure network.

29. The system of claim 17 , wherein the access module is configured to disable network communication via the first communication channel in response to a disablement event.

30. The system of claim 29 , wherein the disabling event comprises a disablement instruction received via one of the second communication channel and the first communication channel.

31. The system of claim 29 , wherein the disabling event comprises an expiration of a time limit.

32. The system of claim 17 , wherein the first communication channel is further configured to provide encrypted communications with the IED.

33. A non-transitory computer-readable medium having instructions encoded thereon that, when executed by a processor, are configured to cause the processor to perform operations, the operations comprising:

disabling communication via a first communication channel with an IED to prevent communication via the first communication channel;

enabling communication via a second communication channel with the IED, wherein the first communication channel and the second communication channel are physically distinct communication channels,

wherein the second communication channel is a private communication channel that is physically secure;

receiving an enablement instruction via the private and physically secure second communication channel, the enablement instruction providing an instruction to activate communication via the first communication channel;

enabling communication via the first communication channel with the IED in response to the enablement instruction;

receiving communication via the first communication channel; and

disabling communication via the first communication channel in response to a pre-defined event.

Assignments (2)
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Jun 4, 2018
From: SCHWEITZER ENGINEERING LABORATORIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 047231/0253 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2012
From: SCHWEITZER, III, EDMUND O.; WHITEHEAD, DAVID E.; SMITH, RHETT; WEBER, MARK
To: SCHWEITZER ENGINEERING LABORATORIES, INC.
Reel/Frame 028878/0865 →
Continuity (1)
Related Publication 20140068711A1 · Mar 6, 2014