IP Library › Granted Patent US 12,225,133
Granted Patent B2
US 12,225,133 · App. 18/412,353 · Granted Feb 11, 2025

Configurable network security for networked energy resources, and associated systems and methods

Inventors: Randall King (Santa Rosa, CA); Roger L. Jungerman (Petaluma, CA); Mayank Saxena (Pleasanton, CA)
Assignee: OPERANT NETWORKS
H04L9/321H04L9/003H04L9/0819H04L9/30H04L9/3265H04L63/0263H04L63/0823H04L63/101H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,225,133
App. No.
18/412,353
Granted
Feb 11, 2025
Kind
B2
Abstract

Secure communication between users and resources of an electrical infrastructure and associated systems and methods. A representative secure distributed energy resource (DER) communication system provides for the creation of trust rules that govern the permitted communications between users and resources of an electrical infrastructure system, and the enforcement of the trust rules.

Claims (42)

1. A method, performed by a computing system, to secure access to utility infrastructure, the method comprising:

maintaining, at the computing system, a trust policy comprised of a plurality of trust rules, wherein each trust rule comprises an origin identifier, a target identifier, and an action identifier;

generating an Information Centric Networking (ICN) command message based on a trust rule selected from the plurality of trust rules, wherein the origin identifier of the selected trust rule corresponds to a utility infrastructure user, the action identifier of the selected trust rule corresponds to a command in the ICN command message, and the target identifier of the selected trust rule corresponds to a utility infrastructure resource;

publishing, on a communication channel, the ICN command message, wherein publishing the ICN command message causes an enforcement computing system, on the communication channel and associated with the utility infrastructure resource, to maintain authorization information characterized by the origin identifier, target identifier, and action identifier of the selected trust rule; and

cryptographically signing a certificate associated with the utility infrastructure user, wherein the certificate includes a utility infrastructure user name defined in an ICN hierarchical namespace and a utility infrastructure user public key;

wherein the enforcement computing system associated with the utility infrastructure resource, in response to subscribing to the ICN command message:

determines, from the ICN command message, the target identifier and the action identifier of the ICN command message, wherein the target identifier of the ICN command message corresponds to the utility infrastructure resource; and

determines whether the utility infrastructure user of the ICN command message, associated with the utility infrastructure user name of the certificate, is authorized to perform an action, corresponding to the action identifier of the ICN command message, on the utility infrastructure resource, based on the maintained authorization information.

2. The method of claim 1 , wherein the ICN command message is cryptographically signed based on a private key associated with the utility infrastructure user, and wherein in response to subscribing to the ICN command message the enforcement computing system further:

validates, based on the cryptographically signed ICN command message and the utility infrastructure user public key, that the ICN command message was published by the utility infrastructure user and that the message was not altered after the message was cryptographically signed.

3. The method of claim 1 , wherein a second enforcement computing system, associated with the utility infrastructure user:

determines, from the ICN command message, a target identifier and an action identifier of the ICN command message; and

determines whether the utility infrastructure user, associated with the utility infrastructure user name, is authorized to publish the ICN command message based on the selected trust rule;

wherein the publishing of the ICN command message is based on the determination of whether the utility infrastructure user is authorized.

4. The method of claim 1 , wherein the utility infrastructure resource is a telecommunications infrastructure resource.

5. The method of claim 4 , wherein the command of the ICN command message corresponds to at least one of enabling a gated general purpose internet connection to the telecommunications infrastructure resource, configuring a firewall on the telecommunications infrastructure resource, configuring a virtual private network (VPN) on the telecommunications infrastructure resource, or performing a software upgrade on the telecommunications infrastructure resource.

6. The method of claim 4 wherein the telecommunications infrastructure resource is at least one of a cellular resource, a long range (LoRa) resource, a LoRa mesh resource, a wireless resource, a wired resource, or a fifth generation (5G) resource.

7. The method of claim 1 , wherein the utility infrastructure resource is at least one of a water purification resource, a water distribution resource, a wastewater resource, a gas infrastructure resource, a pipeline and distribution system resource, an industrial control system resource, a food processing system resource, a chemical processing resource, a mining resource, a gas pipeline resource, a hydrogen pipeline resource, or a sewage treatment facility resource.

8. The method of claim 1 , wherein the utility infrastructure user is an industrial control system owner, the utility infrastructure resource is an industrial control system resource, and the ICN command message corresponds to a supervisory control and data acquisition system (SCADA) command on the industrial control system resource.

9. The method of claim 1 , the method further comprising revoking the certificate.

10. The method of claim 9 , wherein the certificate is revoked based on at least one of a Certificate Revocation List (CRL) or Online Certificate Status Protocol (OCSP).

11. The method of claim 1 , wherein the certificate is an X.509 certificate.

12. A method, performed by a computing system, to secure access to utility infrastructure, the method comprising:

maintaining, at the computing system, a trust policy comprised of a plurality of trust rules, wherein each trust rule comprises an origin identifier, a target identifier, and an action identifier;

generating an Information Centric Networking (ICN) response message based on a trust rule selected from the plurality of trust rules, wherein the origin identifier of the selected trust rule corresponds to a utility infrastructure resource, the action identifier of the selected trust rule corresponds to a response in the ICN response message, and the target identifier of the selected trust rule corresponds to a utility infrastructure user;

publishing, on a communication channel, the ICN response message, wherein publishing the ICN response message causes an enforcement computing system, on the communication channel and associated with the utility infrastructure user, to maintain authorization information characterized by the origin identifier, target identifier, and action identifier of the selected trust rule; and

cryptographically signing a certificate associated with the utility infrastructure resource, wherein the certificate includes a utility infrastructure resource name defined in an ICN hierarchical namespace and a utility infrastructure resource public key;

wherein the enforcement computing system associated with the utility infrastructure user, in response to subscribing to the ICN response message:

determines, from the ICN response message, the target identifier and the action identifier of the ICN response message, wherein the target identifier of the ICN response message corresponds to the utility infrastructure user; and

determines whether the utility infrastructure resource of the ICN response message, associated with the utility infrastructure resource name of the certificate, is authorized to respond, corresponding to the action identifier of the ICN response message, to the utility infrastructure user, based on the maintained authorization information.

13. The method of claim 12 , wherein the ICN response message is cryptographically signed based on a private key associated with the utility infrastructure resource, and wherein in response to subscribing to the ICN response message the enforcement computing system further:

validates, based on the cryptographically signed ICN response message and the utility infrastructure resource public key, that the ICN response message was published by the utility infrastructure resource and that the message was not altered after the message was cryptographically signed.

14. The method of claim 13 , wherein the private key is stored in a Trusted Platform Module (TPM).

15. The method of claim 12 , wherein the utility infrastructure resource is a telecommunications infrastructure resource.

16. The method of claim 15 , wherein the response of the ICN response message corresponds to at least one of responding to a gated general purpose internet connection command of an ICN command message from a telecommunications infrastructure user, responding to a firewall configuration command of an ICN command message from a telecommunications infrastructure user, responding to a VPN configuration command of an ICN command message from a telecommunications infrastructure user, or responding to a software upgrade command of an ICN command message from a telecommunications infrastructure user.

17. The method of claim 15 wherein the telecommunications infrastructure resource is at least one of a cellular resource, a LoRa resource, a LoRa mesh resource, a mobile edge computing resource, a wireless resource, a wired resource, or a 5G resource.

18. The method of claim 12 , wherein the utility infrastructure resource is at least one of a water purification resource, a water distribution resource, a wastewater resource, a gas infrastructure resource, a pipeline and distribution system resource, an industrial control system resource, a food processing system resource, a chemical processing resource, a mining resource, a gas pipeline resource, a hydrogen pipeline resource, or a sewage treatment facility resource.

19. The method of claim 12 , wherein the utility infrastructure resource is an industrial control system resource, the utility infrastructure user is an industrial control system user, and the ICN response message corresponds to a supervisory control and data acquisition system (SCADA) response to a command, wherein the command is associated to an industrial control system user.

20. The method of claim 12 , wherein a second enforcement computing system, associated with the utility infrastructure resource:

determines, from the ICN response message, the target identifier and the action identifier of the ICN response message; and

determines whether the utility infrastructure resource, associated with the utility infrastructure resource name, is authorized to publish the Information Centric Networking (ICN) response message based on the selected trust rule;

wherein the publishing of the ICN response message is based on the determination.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2024
From: KING, RANDALL; JUNGERMAN, ROGER L.; SAXENA, MAYANK
To: OPERANT NETWORKS
Reel/Frame 066171/0992 →
Continuity (4)
Continuation 18106402 · Feb 6, 2023
Continuation 17390726 · Jul 30, 2021
Provisional Application 63059876 · Jul 31, 2020
Related Publication 20240243915A1 · Jul 18, 2024
References Cited (49)
US 7904642B1 · Gupta et al. · 2011 [cited by applicant]
US 8023504B2 · Shah · 2011 [cited by examiner]
US 9270701B1 · Lamb et al. · 2016 [cited by applicant]
US 9426124B2 · Pope et al. · 2016 [cited by applicant]
US 9680875B2 · Knjazihhin et al. · 2017 [cited by applicant]
US 10305864B2 · Wood · 2019 [cited by applicant]
US 10389757B2 · Kumar et al. · 2019 [cited by applicant]
US 20120159176A1 · Ravindran et al. · 2012 [cited by applicant]
US 20130124546A1 · Wormley et al. · 2013 [cited by applicant]
US 20130227166A1 · Ravindran et al. · 2013 [cited by applicant]
US 20140053228A1 · Mahadevan et al. · 2014 [cited by applicant]
US 20140173076A1 · Ravindran · 2014 [cited by examiner]
US 20160119234A1 · Valencia Lopez et al. · 2016 [cited by applicant]
US 20160143075A1 · Tucker et al. · 2016 [cited by applicant]
US 20160373390A1 · Wood · 2016 [cited by examiner]
US 20160380945A1 · Wood · 2016 [cited by examiner]
US 20170041420A1 · Solis · 2017 [cited by examiner]
US 20170257314A1 · Wood · 2017 [cited by examiner]
US 20170257904A1 · Mildh · 2017 [cited by examiner]
US 20170371718A1 · Ko et al. · 2017 [cited by applicant]
US 20180083921A1 · Talamo et al. · 2018 [cited by applicant]
US 20180145907A1 · Vannithamby et al. · 2018 [cited by applicant]
US 20180191514A1 · Erdmann et al. · 2018 [cited by applicant]
US 20190319964A1 · Smith · 2019 [cited by examiner]
US 20200027022A1 · Jha et al. · 2020 [cited by applicant]
US 20200162270A1 · Du et al. · 2020 [cited by applicant]
US 20210021609A1 · Smith et al. · 2021 [cited by applicant]
US 20210029174A1 · Kunduru et al. · 2021 [cited by applicant]
US 20230156826A1 · Palermo et al. · 2023 [cited by applicant]
IEEE Standard for Interconnection and Interoperability of Distributed Energy Resources with Associated Electric Power Systems Interfaces [Online], Apr. 6, 2018 [Retrieved on: Aug. 23, 2023]. [cited by applicant]
SANS Industrial Control Systems and E-ISAC, “Analysis of the Cyber Attack on the Ukrainian Power Grid—Defense Use Case,” Mar. 18, 2016, 29 pages. [cited by applicant]
Wikipedia, 2019 California power shutoffs, https://en.wikipedia.org/wiki/2019_California_power_shutoffs, retrieved on Jul. 24, 2022. [cited by applicant]
“4 Major IoT Protocols—MQTT, CoAP, AMPQ, DDS”, Dec. 5, 2018, 5 pages. [cited by applicant]
“ITRON, Advanced Meter Infrastructure”, Transforming Meter Systems Today . . . and Tomorrow9 pages. [cited by applicant]
“MODBUS and DNP3 Communication Protocols”, Triangle Micro Works, Inc. 4 pages. [cited by applicant]
“Publisher-Subscriber pattern, retrieved from https://docs.microsoft.com/en-us/azure/architecture/patterns/publisher-subscriber; Jul. 26, 2022”. [cited by applicant]
“Wikipedia”, Information-centric networking, Jun. 25, 2021, 1 page. [cited by applicant]
Boneh, Dan, et al., “BLS Multi-Signatures With Public-Key Aggregation”, Stanford University, Mar. 24, 2018, 6 pages. [cited by applicant]
Boneh, Dan, et al., “Short Group Signatures”, Advances in Cryptology-CRYPTO 2004, Springer-Verlag, 19 pages. [cited by applicant]
Conran, Matt, “Named data networking: Stateful forwarding plane for datagram delivery”, networkworld.com/article/3342212/named-data-networking-stateful-forwarding-plane-for-datagram-delivery.htmlIDG Communications, Inc.… [cited by applicant]
Conti, Mauro, et al., “The Road Ahead for Networking: A Survey on ICN-IP Coexistence Solutions”, University of Padua, Oct. 15, 2019, https://named-data.net/ndn-testbed/. [cited by applicant]
Horowitz,“An Overview of Distributed Energy Resource (DER) Interconnection: Current Practices and Emerging Solutions” [Online], Apr. 2019, [Retrieved on: Sep. 14, 2022], NREL, Retrieved from: <https://www.nrel.gov/docs/… [cited by applicant]
Lai, Christine, et al., “Cyber Security Primer for Der Ventors, Aggregators, and Grid Operators”, Sandia Report, Sandia National Laboratories, Dec. 2017, 63 pages. [cited by applicant]
Nichols, Kathleen, “Lessons Learned Building a Secure Network Measurement Framework using Basic NDN”, Pollere, Inc., Sep. 24-26, 2019, 11 pages. [cited by applicant]
Pollere, DCT, “Definted-trust Communications Toolkit (DCT)”, Pollere LLC, 2021-2022, 3 pages. [cited by applicant]
Shang, Wentao, et al., “Publish-Subscribe Communication in Building Management Systems over Named Data Networking”, NDN, Technical Report NDN-0066, 2018. http://named-data.net/techreports.html, 11 pages. [cited by applicant]
Yu, Yingdi, “Public Key Management in Named Data Networking”, NDN, Technical Report NDN-0029, 2015. http://named-data.net/techreports.html, Apr. 20, 2015, 8 pages. [cited by applicant]
Yu, Yingdi, et al., “Schematizing Trust in Named Data Networking”, Oct. 30-Oct. 2, 2015, pp. 177-186, http://dx.doi.org/10.1145/2810156.2810170. [cited by applicant]
Zhang, Zhiyi, et al., “An Overview of Security Support in Named Data Networking”, Information-Centric Networking Security, IEEE, Nov. 2018, pp. 62-68. [cited by applicant]