Systems and methods for managing secure communication sessions with remote devices
Abstract
According to various embodiments, a session manager generates, stores, and periodically updates the login credentials of each of a plurality of connected IEDs. An operator, possibly through an access device, can provide unique login credentials to the session manager. The session manager can determine the operator's authorization level based on the operator's login credentials, which define which IEDs the operator can communicate with. According to various embodiments, the session manager does not facilitate a communication session between the operator and a target IED. Instead, the session manager maintains a first communication session with the operator and initiates a second communication session with the target IED. Therefore, the session manager can forward commands transmitted by the operator to the target IED. Depending on the authorization level of the operator, a session filter can restrict what can be communicated between an operator and an IED.

Term
5.7 yearsleft in the term
Expires 21 June 2032.
- Priority
- Filed
- Granted
- Today
- Expires
25 claims: 1 independent, 24 dependent
- 1ES 2 464 665 B2 REIVINDICACIONES 1. - Un procedimiento de gestión de credenciales de inicio de sesión y sesiones de comunicación de una pluralidad de dispositivos electrónicos inteligentes (IED), que comprende:conectar cada uno de una pluralidad de IED a un gestor de sesiones, comprendiendo la pluralidad de IED un primer subgrupo y un segundo subgrupo, donde el primer subgrupo de IED son los únicos IED de la pluralidad de IED que soportan una característica de seguridad avanzada;generar una pluralidad de credenciales de inicio de sesión para cada uno de la pluralidad de IED usando el gestor de sesiones;almacenar la pluralidad de credenciales de inicio de sesión en una base de datos accesible mediante el gestor de sesiones;crear una primera sesión de comunicación entre el gestor de sesiones y un dispositivo de acceso de operador, solicitando el dispositivo de acceso de operador acceso a un IED del segundo subgrupo;crear una segunda sesión de comunicación entre el gestor de sesiones y el IED solicitado mediante el gestor de sesiones proporcionando credenciales de inicio de sesión del IED solicitado;y simular la característica de seguridad avanzada usando el gestor de sesiones como un proxy para comunicaciones entre la primera sesión de comunicación y la segunda sesión de comunicación, el gestor de sesiones imponiendo la característica de seguridad avanzada en la segunda sesión de comunicación .
- 2- El procedimiento según la reivindicación 1, en el que cada una de la pluralidad de credenciales de inicio de sesión comprende un nombre de usuario y una contraseña.
- 3- El procedimiento según la reivindicación 1, en el que generar la pluralidad de credenciales de inicio de sesión para cada uno de la pluralidad de IED comprende generar ES 2 464 665 B2 credenciales de inicio de sesión únicas para una pluralidad de niveles de acceso de al menos uno de la pluralidad de IED.
- 4- El procedimiento según la reivindicación 1, en el que conectar cada uno de la pluralidad de IED comprende conectar cada IED al gestor de sesiones usando al menos uno de entre un cable de Ethernet, un cable serie, un cable coaxial, un cable óptico y una conexión inalámbrica.
- 5- El procedimiento según la reivindicación 1, que comprende además:asociar una pluralidad de credenciales de inicio de sesión de operador a una pluralidad de operadores, teniendo cada una de la pluralidad de credenciales de inicio de sesión de operador un nivel de autorización que especifica el nivel de acceso del operador asociado.
- 6- Un procedimiento según la reivindicación 5, que comprende además:recibir una de la pluralidad de credenciales de inicio de sesión de operador mediante el gestor de sesiones;determinar el nivel de autorización de las credenciales de inicio de sesión de operador recibidas usando el gestor de sesiones.
- 7- El procedimiento según la reivindicación 6, que comprende además:recibir una solicitud desde el dispositivo de acceso de operador para comunicarse con un IED conectado que pertenece al nivel de autorización de las credenciales de inicio de sesión de operador recibidas;y retransmitir de manera selectiva por medio del gestor de sesiones, las comunicaciones recibidas desde el dispositivo de acceso de operador en la primera sesión de comunicación al IED solicitado en la segunda sesión de comunicación.
- 8- El procedimiento según la reivindicación 6, que comprende además:suprimir las comunicaciones entre el operador y el IED que superen el nivel de autorización 24 ES 2 464 665 B2 del operador.
- 9- El procedimiento según la reivindicación 6, que comprende además registrar eventos de acceso asociados a las credenciales de inicio de sesión del operador usando el gestor de sesiones.
- 10- El procedimiento según la reivindicación 6, que comprende además que el gestor de sesiones:proporcione al dispositivo de acceso de operador una lista de IED conectados;reciba una solicitud desde el dispositivo de acceso de operador para comunicarse con uno de los IED listados que pertenecen al nivel de autorización de las credenciales de inicio de sesión de operador recibidas;inicie una segunda sesión de comunicación entre el gestor de sesiones y el IED solicitado mediante el gestor de sesiones proporcionando credenciales de inicio de sesión del IED solicitado;y retransmita de manera selectiva las comunicaciones recibidas desde el dispositivo de acceso de operador en la primera sesión de comunicación al IED solicitado en la segunda sesión de comunicación.
- 11- El procedimiento según la reivindicación 10, en el que la lista comprende solamente los IED que pertenecen al nivel de autorización de las credenciales de inicio de sesión de operador recibidas.
- 12- El procedimiento según la reivindicación 1, que comprende además traducir un primer protocolo de datos en un segundo protocolo de datos.
- 13- El procedimiento según la reivindicación 1, donde la característica de seguridad avanzada comprende usar un carácter ampliado, en conexión con la pluralidad de credenciales lógicas.
- 14- El procedimiento según la reivindicación 1, donde la característica de seguridad ES 2 464 665 B2 avanzada comprende requerir a un usuario que actualice una credencial de inicio de sesión asociada en un intervalo de tiempo especificado. 15.- Un gestor de sesiones para gestionar credenciales de inicio de sesión y sesiones de comunicación de una pluralidad de dispositivos electrónicos inteligentes (IED), que comprende:un bus;un procesador en comunicación con el bus;una pluralidad de puertos en comunicación con el bus y configurados para permitir la conexión de una pluralidad de IED con el gestor de sesiones, comprendiendo la pluralidad de IED un primer subgrupo y un segundo subgrupo, donde el primer subgrupo de IED son los únicos IED de la pluralidad de IED que soportan una característica de seguridad avanzada;y un medio de almacenamiento legible por ordenador en comunicación con el bus, comprendiendo el medio de almacenamiento legible por ordenador: un módulo de gestión de credenciales de IED que puede ejecutarse en el procesador y que está configurado para: generar credenciales de inicio de sesión para cada IED conectado;almacenar las credenciales de inicio de sesión de los IED conectados en una base de datos accesible al gestor de sesiones;iniciar una primera sesión de comunicación entre el gestor de sesiones y un dispositivo de acceso de operador, el dispositivo de acceso de operador solicitando acceso a un IED del segundo subgrupo;iniciar una segunda sesión de comunicación entre el gestor de sesiones y el IED solicitado mediante el gestor de sesiones proporcionando credenciales de inicio de sesión del IED solicitado;ES 2 464 665 B2 simular la característica de seguridad avanzada actuando el gestor de sesiones como un proxy para comunicaciones entre un IED del segundo subgrupo de IED el dispositivo de acceso de operador, el gestor de sesiones estando configurado para imponer la característica de seguridad avanzada en comunicación con el dispositivo de acceso de operador y acceder el gestor de sesiones al IED del segundo subgrupo de IED usando las credenciales de inicio de sesión generadas.
- 1516. - El gestor de sesiones según la reivindicación 15, en el que cada una de la pluralidad de credenciales de inicio de sesión comprende un nombre de usuario y una contraseña.
- 1617. - El gestor de sesiones según la reivindicación 15, en el que el módulo de gestión de credenciales de IED está configurado para generar credenciales de inicio de sesión para una pluralidad de niveles de acceso de al menos uno de la pluralidad de IEDs.
- 1718. - El gestor de sesiones según la reivindicación 15, en el que la pluralidad de puertos comprende al menos uno de entre un puerto de Ethernet, un puerto serie, un puerto coaxial, un puerto óptico y un puerto inalámbrico.
- 1819. - El gestor de sesiones según la reivindicación 15, en el que el medio de almacenamiento legible por ordenador comprende además:un módulo de gestión de credenciales de dispositivo de acceso que puede ejecutarse en el procesador y que está configurado para asociar una pluralidad de credenciales de inicio de sesión de operador a una pluralidad de operadores, teniendo cada una de la pluralidad de credenciales de inicio de sesión de operador un nivel de autorización que especifica el nivel de acceso de al menos uno de la pluralidad de IED.
- 1920. - El gestor de sesiones según la reivindicación 19, en el que el medio de almacenamiento legible por ordenador comprende además:un módulo de gestión de control de acceso que puede ejecutarse en el procesador y que está configurado para: ES 2 464 665 B2 recibir una de la pluralidad de credenciales de inicio de sesión de operador desde un dispositivo de acceso de operador;determinar el nivel de autorización de las credenciales de inicio de sesión de operador.
- 2021. - El gestor de sesiones según la reivindicación 20, en el que el módulo de gestión de control de acceso está configurado además para:recibir una solicitud desde el dispositivo de acceso de operador para comunicarse con un IED que pertenece al nivel de autorización de las credenciales de inicio de sesión de operador recibidas;y retransmitir las comunicaciones recibidas desde el dispositivo de acceso de operador en la primera sesión de comunicación al IED solicitado en la segunda sesión de comunicación.
- 2122. - El gestor de sesiones según la reivindicación 20, en el que el medio de almacenamiento legible por ordenador comprende además:un módulo de filtrado de sesiones que puede ejecutarse en el procesador y que está configurado para suprimir las comunicaciones que superen el nivel de autorización determinado de las credenciales de inicio de sesión de operador proporcionadas.
- 2223. - El gestor de sesiones según la reivindicación 19, en el que el medio de almacenamiento legible por ordenador comprende además:un módulo de registro de eventos de acceso que puede ejecutarse en el procesador y que está configurado para registrar eventos de acceso asociados a las credenciales de inicio de sesión de operador proporcionadas.
- 2324. - El gestor de sesiones según la reivindicación 20, en el que el módulo de gestión de control de acceso está configurado además para:proporcionar al dispositivo de acceso de operador una lista de IED;ES 2 464 665 B2 recibir una solicitud desde el dispositivo de acceso de operador para comunicarse con uno de los IED listados que pertenecen al nivel de autorización de las credenciales de inicio de sesión de operador recibidas;5 retransmitir las comunicaciones recibidas desde el dispositivo de acceso de operador en la primera sesión de comunicación al IED solicitado en la segunda sesión de comunicación.
- 2425. - El gestor de sesiones según la reivindicación 24, en el que la lista comprende 10 solamente los IED que pertenecen al nivel de autorización de las credenciales de inicio de sesión de operador recibidas.
- 2526. - El gestor de sesiones según la reivindicación 15, en el que el medio de almacenamiento legible por ordenador comprende además:un módulo de traducción de protocolos que puede ejecutarse en el procesador y que está configurado para traducir un primer protocolo de datos en un segundo protocolo de datos.
Independent claims25
96 paragraphs in 11 sections, as filed
ES 2 464 665 B2
Systems and procedures for managing secure communication sessions with remote devices
DESCRIPTION
TECHNICAL FIELD
The present invention relates generally to secure communication session management systems and procedures. More particularly, the systems and procedures disclosed in this document can be implemented in gateways, firewalls and other network devices and can be configured to implement modern access control paradigms across various networked devices.
BRIEF DESCRIPTION OF THE DRAWINGS
Non-limiting and non-exhaustive embodiments of the disclosure, including various embodiments of the disclosure, are described below with reference to the figures, in which:
FIG.1 illustrates an embodiment of a gateway session management system that includes a session manager, multiple intelligent electronic devices (IEDs), and an operator access device.
FIG. 2 illustrates an embodiment of a functional block diagram of a computer system configured to manage login credentials and communication sessions between an access device and one or more IEDs.
FIG. 3 illustrates one embodiment of a method for establishing and maintaining secure login credentials for each of a plurality of IEDs.
FIG. 4 illustrates one embodiment of a method for initiating a communication session between an access device and a session manager.
FIG. 5 illustrates an embodiment of a method for initiating a first communication session between an access device and a session manager and a second access-controlled communication session between an IED and the session manager.
ES 2 464 665 B2
FIG. 6A and 6B illustrate representative table embodiments of the credential management of a legacy IED and a more secure modern IED, respectively.
FIG. 7 illustrates a representative table for managing the login credentials and connections of a plurality of IEDs in one embodiment of a session manager.
FIG. 8 illustrates a representative table for managing login credentials and the associated authorization level granted to each of a plurality of access devices through a session manager.
FIG. 9 illustrates a representative table for managing the login credentials and associated authorization levels granted to each of a plurality of access devices via a session manager that includes a session filter.
Numerous specific details are provided in the following description for a thorough understanding of the various embodiments disclosed herein. The systems and procedures disclosed in this document can be practiced without one or more of the specific details, or with other procedures, components, materials, etc. Furthermore, in some cases, widely known structures, materials or operations may not be shown or described in detail so as not to obscure aspects of the invention. Furthermore, the properties, structures or characteristics can be combined in any suitable way in one or more alternative embodiments.
DETAILED DESCRIPTION
The present disclosure provides systems and procedures for managing access to a plurality of intelligent electronic devices (IEDs). According to various embodiments, the built-in security measures of existing IEDs vary considerably. For example, legacy IEDs cannot distinguish unique users and can include username / password combinations with a limited length and / or character set. Even using modern IEDs, which can allow the creation of many complex username / password combinations, it can be difficult to manage and update a large number of login credentials via
ES 2 464 665 B2 an IED network.
According to various embodiments disclosed herein, a session manager can be configured to manage and update the login credentials of a plurality of networked IEDs. Furthermore, a session manager can manage a plurality of access device login credentials. According to various embodiments, a session manager can be configured with a variety of network ports and can communicate using a wide variety of communication protocols. For example, a session manager can be configured with serial ports and Ethernet ports and can communicate with and / or translate various protocols associated with various types of physical network connections.
According to various embodiments, the session manager is configured to set the login credentials for each access level of each connected IED. In addition, the session manager can be configured to reset and update the login credentials in a specific time interval. For example, the login credentials of each connected IED can be reset and updated annually to comply with an applicable regulation.
The session manager can be configured to assign login credentials to each associated IED that are as robust as each IED allows. For example, a legacy IED may allow only a single username and password combination with a limited length and character set, while a more modern IED may allow multiple usernames and / or passwords that have lengths and / or broader character sets.
According to various embodiments, an operator can access a remote IED through the session manager. It may be necessary for the operator to provide a username and password to the session manager to gain access to a particular IED. According to various embodiments, the operator can communicate with a session manager using an access device connected to the session manager. The session manager can be configured to maintain and manage a plurality of login credentials associated with a plurality of operators, access devices, and / or combinations thereof. According to various embodiments, a session manager may require an access device, or the operator thereof, to provide login credentials
ES 2 464 665 B2 to gain access to networked IEDs. An authorization level can be associated with each operator, which specifies the IEDs with which the operator can communicate. Furthermore, some operators may have limited access to some IEDs, while others may have full access.
A session manager may include a session filter configured to suppress communication between an operator and a networked IED that does not belong to the operator's authorization level. For example, a session filter can prevent all operators and / or access devices from changing the login credentials of a networked IED. Furthermore, a session filter can be configured to suppress commands sent by an operator and / or access device to a particular IED that are on a command blacklist.
An operator who wishes to initiate a communication session with a particular IED may initially contact the session manager. Thereafter, the operator and / or access device may be required to provide login credentials, such as a username and one / more password (s). The session manager can analyze the login credentials provided to determine the authorization level of the operator and / or access device. The operator can then specify an IED to communicate with. If the specified IED belongs to the authorization level of the provided login credentials, the session manager can provide appropriate login credentials to the specified IED to initiate a communication session between the IED and the session manager. The operator and / or the access device can then transmit to the session manager a command destined for the IED. The command can be parsed by the session filter and, if the command sent by the operator satisfies the criteria imposed by the session filter, the command can be forwarded to the target IED. Also, the session manager can forward information sent by the target IED to the access device.
According to certain embodiments, a session manager can maintain access event logs, including commands and information sent between access devices and IEDs and the associated login credentials of the access operators and / or devices. As described in this document, a session manager enables the application of modern and consistent security standards and practices across a plurality of networked IEDs and access devices, even when some
ES 2 464 665 B2
Legacy IEDs and / or access devices cannot conform to or provide modern security practices.
Operators and / or access devices can provide login credentials to a session manager to gain access to each of the IEDs with which the operator is authorized to communicate. This can eliminate the need for an operator to have to remember (or possibly write down, which creates further security concerns) the login credentials of each of a plurality of IEDs. In addition, in some industries, such as power generation and supervision, the regulation imposes minimum security requirements and periodic password changes. The session manager described in this document can automate the task of updating hundreds or even thousands of username / password combinations.
Reference throughout this specification to "an embodiment" means that a particular property, structure, or characteristic described in connection with the embodiment is included in at least one embodiment. Therefore, the appearance of the phrase "in one embodiment" at various points in this specification does not necessarily refer to the same embodiment. In particular, "an embodiment" can be a system, an article of manufacture (such as a computer-readable storage medium), a method, and / or a product of a process.
The terms "connected to" and "in communication with" refer to any form of interaction between two or more components, including mechanical, electrical, magnetic and electromagnetic interactions. Two components can be connected to each other, even though they are not in direct contact with each other, and even though there may be intermediate devices between the two components. For example, an IED may be connected to a gateway session manager through one or more IEDs or intermediate networking devices. Such networks can be modeled as tree structures, as is common in the art.
As used in this document, the term IED can refer to any microprocessor-based device that monitors, controls, automates and / or protects the monitored equipment of a system. Such devices may include, for example, remote terminal units, differential relays, distance relays, directional relays, power relays, overcurrent relays, voltage regulation controls, voltage relays,
ES 2 464 665 B2 Circuit breaker fault relays, generator relays, motor relays, automation controllers, module controllers, meters, recloser controls, communication processors, computer platforms, programmable logic controllers (PLC), controllers of programmable automation, input and output modules, motor controllers and the like. The IEDs can be connected to a network, and communication in the network can be facilitated by interconnection devices including, but not limited to, multiplexers, routers, hubs, gateways, firewalls, and switches. Furthermore, the networking and communication devices can be embedded in an IED or be in communication with an IED. The term IED can be used interchangeably to describe a single IED or a system comprising multiple IEDs.
As used herein, the term "login credentials" can refer to any type of authentication procedure known in the art for its usefulness. For example, login credentials can typically refer to an ASCII-encoded username and password combination; therefore, the terms "login credentials" and "username and password (s)" may be interchangeable in this document. However, the username and password (s) can be substituted for any of a wide variety of authentication protocols and / or techniques including cryptographic authentication machine protocols, challenge response procedures, tests of knowledge. zero, time-synchronized one-time passwords, security tokens, biometric authentication, graphical or other non-text-based passwords, voice authentication, and the like.
Some of the infrastructures that can be used with the embodiments disclosed in this document are already available, such as: general purpose computers, computer programming tools and techniques, digital storage media and communication networks. A computer may include a processor, such as a microprocessor, microcontroller, logic circuitry, or the like. The processor may include a special purpose processing device, such as an ASIC, PAL, PLA, PLD, field programmable gate array, or other custom or programmable device. The computer may also include a computer-readable storage device, such as non-volatile memory, static RAM, dynamic RAM, ROM, CD-ROM, disk, tape, magnetic, optical, flash memory, or other media.
ES 2 464 665 B2 computer-readable storage.
Networks suitable for configuration and / or use, as described in this document, include one or more local area networks, wide area networks, metropolitan area networks, and / or Internet or Internet Protocol (IP) networks, such as the World Wide Web, a private Internet, a secure Internet, a value-added network, a virtual private network, an extranet, an intranet, or even autonomous machines that communicate with other machines through the physical transport of media. In particular, a suitable network may be made up of parts or all of two or more networks, including networks that use different network communication technologies and hardware. A network can include land lines, wireless communication, and combinations thereof.
The network may include communications or networking software, such as software available from Novell, Microsoft, Artisoft, and other vendors, and may operate using TCP / IP, SPX, IPX, and other protocols over twisted-pair, coaxial cables. or fiber optic, telephone lines, satellites, microwave relays, modulated AC power lines, physical media transfer and / or other data transmission lines. The network can span smaller networks and / or can be connected to other networks through a gateway or similar mechanism.
Aspects of certain embodiments described in this document may be implemented as software modules or components. As used herein, a software module or component can include any type of computer instruction or computer executable code located on a computer-readable storage medium. A software module can comprise, for example, one or more physical or logical blocks of computer instructions that can be organized as a routine, a program, an object, a component, a data structure, etc., that performs one or more tasks or that implements particular abstract data types.
In certain embodiments, a particular software module may comprise different instructions stored in different locations on a computer-readable storage medium that together implement the described functionality of the module. In fact, a module can comprise a single instruction or many instructions, and it can be distributed across several different code segments, between different programs and across several storage media.
ES 2 464 665 B2 machine readable. Some embodiments can be implemented in a distributed computing environment, where tasks are carried out by a remote processing device connected through a communication network. In a distributed computing environment, software modules can be located on local and / or remote computer-readable storage media. In addition, data linked to or stored together in a database record may reside on the same computer-readable storage medium or on several computer-readable storage media, and may be related to each other in fields of a database record. database over a network.
The software modules described in this document tangibly represent programs, functions and / or instructions that can be executed by one or more computers to carry out the tasks described in this document. Suitable software can be provided, if applicable, using the teachings presented in this document and programming languages and tools, such as XML, Java, Pascal, C ++, C, database languages, API, SDK, assembler, firmware, microcode, and / or other languages and tools. Furthermore, software, firmware and hardware can be used interchangeably to implement a given function.
In some cases, widely known features, structures, or operations are not shown or described in detail. Furthermore, the described features, structures, or operations can be combined in any suitable way in one or more embodiments. It will also be readily understood that the components of the embodiments, generically described and illustrated in the figures herein, can be arranged and designed in a wide variety of different configurations.
Embodiments of the disclosure will be better understood with reference to the drawings, in which like parts are designated by like reference numerals throughout the drawings. The components of the disclosed embodiments, described and illustrated generically in the figures herein, can be arranged and designed in a wide variety of different configurations. Therefore, the following detailed description of the embodiments of the systems and methods of the invention does not limit the scope of the claimed invention, but only represents possible embodiments. In other cases, widely known structures, materials, or operations are not shown or described in detail so as not to obscure aspects of this invention.
ES 2 464 665 B2
In addition, the steps of a procedure do not need to be executed in a specific order, or even sequentially, nor do the steps need to be executed only once, unless otherwise indicated.
FIG. 1 illustrates an embodiment of a system 100 that includes a session manager 110, a plurality of intelligent electronic devices (IEDs) 161, 162, 163, 164, 165, and 166, and an operator access device 150. As illustrated, session manager 110 may include multiple ports 120, 130, and 140. According to various embodiments, the ports may include serial ports 120 and Ethernet ports 130 and 140. According to other embodiments, a session manager 110 may include optical ports, USB ports, SATA ports, and / or alternate ports. As illustrated, IEDs 161 and 162 are connected to session manager 110 via Ethernet cables 131 and 132. IEDs 165 and 166 are connected via Ethernet cables and / or serial cables 135 and 136 to IED 162 and ultimately to session manager 110 via Ethernet cable 132. IEDs 163 and 164 are IEDs connected to session manager 110 via serial cables 123 and 124. According to various embodiments, session manager 110 can maintain a tree-shaped model of all networked devices, of their types , communication protocols and interconnections.
One or more ports of session manager 110 may be designated as a master port 140 for communication with an operator access device 150, while other ports, such as serial ports 120 and / or Ethernet ports 130, may be reserved as slave ports for IED connection towards the user. Alternatively, any of ports 120, 130, and 140 can be configured as master ports or slave ports. According to another alternative embodiment, each of ports 120, 130 and 140 can be used interchangeably as master and slave ports by a connected device, as appropriate during various communication sessions. That is, any one of the IEDs 161 to 166 can be considered a slave device during a communication session in which the access device 150 is sending commands. However, the same IED can be considered a master device during a communication session where an operator uses that same IED to access another IED on the network.
An operator of access device 150 can initiate a communication session with session manager 110 by providing unique login credentials. The manager
ES 2 464 665 B2 sessions 110 can analyze the login credentials to determine what level of authorization should be assigned to the operator. The authorization level can be used to determine the IEDs 161 to 166 that the operator can access and / or the access level the operator has on each IED.
During the communication session, the operator can send a request to communicate with, for example, the IED 161. The session manager 110 can then initiate a communication session between the IED 161 and the session manager 110. Thereafter, the operator it can transmit to session manager 110 commands destined for IED 161. Then, session manager 110 can forward the commands to IED 161.
According to various embodiments, the session manager 110 can be configured to act as a proxy for communications with any of the IEDs 161 to 166. Accordingly, the session manager 110 can maintain two independent communication sessions: a first communication session with the access device 150 and a second communication session with one of the IEDs 161 to 166. Additionally, session manager 110 may include a session filter configured to suppress commands passed by access device 150 to a target IED that do not belong to the operator authorization level of access device 150. For example, since a session manager 110 independently manages the login credentials of each of the IEDs 161 to 166, the session filter can automatically suppress any command that tries to modify the login credentials of any of IEDs 161 to 166.
According to one embodiment, the session manager 110 may provide an operator of the access device 150 with a list of IEDs that belong to the authorization level of the received login credentials. IEDs that do not belong to the authorization level of the received login credentials can effectively remain hidden from the operator of the access device 150. Furthermore, the operator of the access device 150 may be unaware of the number of other IEDs that are connected. Consequently, the operator of the access device 150 can only be aware of the IEDs from the list provided by the session manager 110. A session filter can suppress the commands transmitted to the listed IEDs that do not belong to the access level associated with the access device operator authorization level 150. In addition, the session filter may suppress any attempt by the operator of the access device 150 to communicate with an IED that is not on the list of IEDs provided by the
ES 2 464 665 B2 session manager 110.
According to various embodiments, the session manager 110 may include a protocol translator configured to translate various communication protocols and physical communication media. For example, session manager 110 may allow communication between a first device connected to session manager 110 via Ethernet and a second device connected to session manager 110 via serial connection. For example, the access device 150 can communicate using IP packets over an Ethernet cable 145, while the IED 164 can use RS-232 over a serial cable 124. The session manager 110 can perform all the conversions involved in the communication, so that the conversions and / or translations are transparent to the operator using the access device 150.
The gateway session management system 100 includes a single access device 150; however, according to alternative embodiments, any number of access devices may be in communication with the session manager 110. Furthermore, according to various embodiments, an access device may be an IED. Therefore, anyone of the IEDs 161 to 166 can be configured to further perform the functions of an access device. In addition, session manager 110 can include any number of wired and / or wireless ports, can use any number of protocols, and / or can include a built-in access device. A computer, server, or other electronic device, including an IED, can be modified using hardware, firmware, and / or software to perform the functions of session manager 110, as described in this document.
FIG. 2 illustrates an embodiment of a functional block diagram of a computer system 200 configured to function as a session manager. Computer system 200 can be configured to manage communication sessions between one or more access devices and one or more IEDs. As illustrated, the computer system 200 may include a processor 230, a memory (RAM) 240, a network interface 250, and a computer-readable storage medium 270, all connected via a system bus 220.
Processor 230 can be configured to process communications received through network interface 250 and input / output ports 290. Processor 230 can operate using any number of speeds and processing architectures. Processor
ES 2 464 665 B2
230 it can be configured to perform various algorithms and calculations described in this document. Processor 230 can be realized as a general purpose integrated circuit, an application specific integrated circuit, a programmable field gate array, and other programmable logic devices.
Network interface 250 and input / output ports 290 may allow communication between computer system 200 and a plurality of connected IEDs and operator access devices. Network interface 250 can be realized using various interfaces for various types of physical media (eg, fiber optic, twisted pair, or coaxial cable). In addition, the network interface 250 can be configured to allow communications according to various communication protocols and speeds. According to various embodiments, multiple network interfaces can be used to allow communication with multiple IEDs or other network components.
The input / output ports 290 can be configured to allow communication between the computer system 200 and a plurality of other devices, such as IEDs. The input / output ports 290 can be realized, for example, as RS-232 connections, USB connections, IEEE 1394 and the like. A plurality of input / output ports 290 may be provided to facilitate communication with a plurality of devices.
According to various embodiments, the computer-readable storage medium 270 may include modules 280 to 292. According to various embodiments, each of the modules 280 to 292 may alternatively be implemented using hardware, firmware, software, or a combination thereof.
A topology module 280 can be configured to identify and maintain a record of the interconnections between each networked device, including IEDs, access device (s), and / or other network elements. According to various embodiments, when an access device makes a connection request, the topology module 280 can be configured to determine a communication path that can include one or more IEDs or other intermediate network devices, and create a communication path that can used for communications with the requested IED. If multiple network devices are included in the communication path, the computer system 200 can connect to each intermediate device in succession to initiate a communication session with the requested IED.
ES 2 464 665 B2
An IED credential management module 282 can be configured to generate and establish secure credentials for one or more IEDs connected to the computer system 200. According to various embodiments, the IED credential management module 282 can be configured to establish login credentials. random for each IED and store them in an internal table. According to some embodiments, if an IED supports more than one access level, the IED credential management module 282 can establish login credentials for each access level. In addition, the IED credential management module 282 can be configured to monitor the age of the login credentials associated with each IED and update them in a specified time interval. For example, login credentials can be updated weekly, monthly, or annually.
An access device credential management module 284 may be configured to manage the login credentials of one or more access devices and / or operators. Each access device and / or operator can have unique login credentials. According to one embodiment, the login credentials comprise a username and at least one password. Alternatively, each login credential can include any of a variety of authentication mechanisms. Access device credential management module 284 may be configured to prompt an operator and / or access device to reset and / or update unique login credentials at specified time intervals. Alternatively, the access device credential management module 284 can be configured to automatically select and update the login credentials of access devices and / or operators.
An access control management module 286 can be configured to determine the authorization level of an access device and / or operator based on the login credentials provided. For example, when an operator attempts to initiate a communication session with the computer system 200 through an access device, the operator may be required to provide unique login credentials. Access control management module 286 can determine which networked IEDs the operator can communicate with. In addition, the access control management module 286 can be configured to generate a black list of commands that the operator must not be able to transmit to specific IEDs and / or with what access level a
ES 2 464 665 B2 operator should be able to communicate with an IED. Also, the access control management module 286 can be configured to generate a whitelist of commands that the operator can transmit to specific IEDs.
In addition, the access control management module 286 can support user-defined virtual commands. According to various embodiments, a virtual command can include a set of custom commands configured to request data from an IED and then return the requested data in a user-specified format. For example, an IED can only support a specific set of basic commands. The access control management module 286 may allow an operator to define a custom virtual command as a set of basic commands that must be carried out in a predefined sequence. An operator can enter a virtual command and the access control management module 286 can then transmit to an IED the predefined set of basic commands in the predefined sequence. Additionally, the data can be returned to the operator or access device in a user-specified format.
Commands transmitted by an operator to a target IED can be suppressed by a session filtering module 288 if the commands exceed the operator's authorization level. For example, commands transmitted by an operator destined for an IED that are on a black list generated by the access control management module 286 can be suppressed. Alternatively, the commands transmitted by an operator can be suppressed if they are not on a whitelist generated by the access control management module 286. According to one embodiment, the commands that attempt to modify the login credentials of the connected IEDs in network they are suppressed by a filter of sessions. The access control management module 286 can also be configured to suppress commands that may result in the interruption of electrical service or damage to an electrical supply system.
According to various embodiments, the IEDs, network equipment, and / or access devices can communicate with computer system 200 using a wide variety of physical hardware and protocols. A protocol translation module 291 can be configured to translate commands received in one protocol in order to forward them to an IED in another protocol, and vice versa. For example, the protocol translation module 291 can translate TCP / IP data transmitted over Ethernet or fiber optics to RS-232 over a serial cable.
ES 2 464 665 B2
Additionally, an access event logging module 292 can be configured to log access events and associated login credentials. According to various embodiments, the access events can include successful or unsuccessful session start or end, transmitted commands, received commands, suppressed commands, received information, requested information, transmitted information and / or other data transmissions between an access device, a session manager and / or an IED. According to various embodiments, the type and amount of information recorded can be configured by an operator to suit a particular need.
FIG. 3 illustrates one embodiment of a method 300 for establishing and maintaining secure login credentials for each of a plurality of IEDs. Each of the plurality of IEDs connects to a session manager, at 310. According to various embodiments, the IEDs can connect to a session manager using any of a wide variety of physical connections or using a wireless connection. The session manager may include a connection manager that determines the model and protocol for communication with each of the connected IEDs, at 320. For example, a tree model may be maintained representing the topology of a plurality of connected IEDs. in network.
According to various embodiments, the session manager may be capable of using and translating a wide variety of communication protocols, including the RS-232 protocol and packet-based data protocols. The connection manager can also determine a communication path to each connected IED, at 330.
A credential manager can establish secure login credentials for various authorization levels of each connected IED, at 340. According to various embodiments, each IED may require that login credentials be provided, such as a username and a password. password, to access the IED. For example, an IED can be configured to monitor parts of a power distribution system and automatically control a circuit breaker. The IED may require an operator to provide a username and password to prevent unauthorized access.
The credential manager can also monitor the age of the login credentials of each of the plurality of IEDs and modify the login credentials of
ES 2 464 665 B2 session in a specified time interval, at 350. For example, federal regulations may require that the IED login credentials be reset annually. By automatically resetting the login credentials of all networked IEDs within a specified time interval, the session manager can automate what would otherwise be a complex and time-consuming manual process.
According to various embodiments, the credential manager can generate random login credentials for each connected IED and store the credentials in an internal database. Legacy IEDs cannot offer the same security controls as modern IEDs. For example, a legacy IED can only allow a single login credential, such as a single username / password combination that grants unrestricted access to the IED. In contrast, more modern IEDs can allow multiple username / password combinations that have configurable access levels. Also, the length and character set available to create login credentials can vary considerably from one IED to another. The credential manager can be configured to interact appropriately with each type of IED, regardless of the security standards used by the particular IED.
FIG. 4 illustrates one embodiment of a method 400 for initiating a communication session between an access device and a session manager. At 410, an access device initiates a communication session with a session manager. An access control manager built into the session manager requests that the access device provide login credentials, at 420. Login credentials are provided by the access device and / or an operator thereof, at 430. According to various embodiments, the access control manager may request the login credentials for the machine being used as the access device. , the login credentials of the access device operator, or both. Thus, according to some embodiments, a session manager may only be accessible to access devices known to the session manager. Alternatively, the session manager can allow access as long as the access device operator can provide authorized login credentials.
The access control manager can then determine the access device authorization level for the initiated communication session based on the received login credentials, at 440. That is, the session manager can
ES 2 464 665 B2 provide access to networked IEDs, based on the login credentials of the access device and / or the operator. For example, a given operator may have several levels of access to each of the networked IEDs. The operator may have full access to some IEDs and limited access to some IEDs, and may be completely prevented from interacting with other IEDs.
The session manager can forward communications between the access device and a target IED belonging to the given authorization level, at 450. According to various embodiments, the session manager does not facilitate a communication session between the access device and an IED. Instead, the session manager can hold a first communication session with the access device and initiate a second communication session with a target IED. Consequently, the session manager forwards commands transmitted by the access device in the first communication session to a target IED in the second communication session, as long as the target IED belongs to the given authorization level.
According to various embodiments, a session manager can maintain a first communication session with an access device and multiple communication sessions with several target IEDs. Furthermore, a session manager can facilitate communications between multiple access devices and multiple IEDs simultaneously. That is, multiple access devices can use the session manager functionality without necessarily being aware of each other. For example, two access devices can communicate simultaneously with a single IED or with two different IEDs. According to various embodiments, a concurrent or simultaneous access is provided through a single communication port. For example, a single Ethernet port can support communications between multiple access devices and the session manager and / or an IED.
FIG. 5 illustrates an embodiment of a method 500 for initiating a first communication session between an access device and a session manager, and a second access-controlled communication session between an IED and the session manager. At 510, an access device provides login credentials to a session manager to initiate a communication session. The session manager's access control manager determines the access device authorization level based on the received credentials, at 520. The granted authorization level may depend on the login credentials of the physical machine used as the access device. access, of
ES 2 464 665 B2 the login credentials of an access device operator, or a combination thereof.
According to various embodiments, a session manager provides various levels of access to each connected IED, depending on the authorization level of the access device and / or the operator. According to some embodiments, a session manager can use the differentiated and embedded access levels of modern IEDs to provide limited access per access device to some IEDs. Furthermore, a session manager can include a session filter configured to suppress commands and communications between an access device and an IED that do not belong to the authorization level of the access device and / or the operator thereof.
For example, it may be desirable to grant a particular operator administrative privileges for some IEDs, high-level operator privileges for other IEDs, and low-level operator privileges for other IEDs. If the operator wishes to communicate with a particular IED, the session manager can initiate a communication session with the IED that corresponds to the authorization level of the operator. Such a model works as long as the IED supports different levels of access. In legacy IEDs that do not support different levels of access, a session filter built into the session manager can suppress communications that do not belong to the authorization level of the access device. Consequently, a session manager can efficiently provide legacy IEDs with different levels of access by using a session filter.
At 520 the authorization level can be determined and at 530 the access device can request the session manager to forward commands to a connected IED. At 540, a session filter can determine if the commands belong to the authorization level of the access device for the target IED. If the request belongs to the authorization level of the access device, at 550, the session manager can forward the command to the target IED, at 570. However, if the request does not belong to the authorization level of the access device, at 550, the session manager can reject the request to forward the command, at 560.
According to various embodiments, a session manager can include a registration subsystem. Accordingly, the logging subsystem can log access events and associated logon credentials, at 580. According to various embodiments, the events
ES 2 464 665 B2 registered accesses can include any successful or unsuccessful session start or end, transmitted commands, received commands, suppressed commands, received information, requested information, transmitted information and / or other data transmissions between an access device , a session manager and / or an IED. According to various embodiments, the type and amount of information recorded can be tailored to suit a particular need.
FIG. 6A and 6B illustrate representative table embodiments of credential management of a legacy IED 600 and a more secure modern IED 650. As described above, a modern IED 650 can allow different levels of access based on login credentials, while a legacy IED 600 cannot provide any access or can provide unlimited access. As illustrated in FIG. 6A, a legacy IED can provide full access to all systems and files after authentication using a username and password. Also, the length and character set used to create the username and password can be limited.
In contrast, an enhanced IED 650 can allow multiple username and password combinations, each with different levels of access. As illustrated in FIG. 6B, possible access levels may include variations in the operator's ability to read and write to the systems and files present in the IED. FIG. 6A and 6B are simply examples of possible username, password, and access level combinations. According to various embodiments, the IEDs may use alternative login credential paradigms and may include more defined access levels.
FIG. 7 illustrates a representative table 700 for managing the passwords and connections of a plurality of IEDs in one embodiment of a session manager. As described above, a session manager can manage the login credentials, type, connection, and available levels of access for each of a plurality of connected IEDs. The session manager can automatically generate and update the login credentials for multiple access levels (where possible) of each connected IED. As illustrated in the first column of table 700, IEDs 1 to N can connect to the session manager. IEDs 1 and N can be legacy devices (second column) connected via serial cables (third column). These legacy IEDs can only support a single equivalent access level
ES 2 464 665 B2 that of an administrator (fourth column). Consequently, a username (fifth column) and password (sixth column) can be generated, stored and periodically updated for each IED.
IEDs 2 and 3 (first column) can be upgraded or modern IEDs (second column) connected to the session manager via Ethernet (third column). As illustrated, IED 2 can support five predefined access levels (fourth column) such as administrator, high level, medium level, low level and custom. IED 3 can also support numerous access levels (fourth column), each of which can be customized. The session manager can generate, store and periodically update user names and passwords for each access level of IED 2 and for any number of access levels of IED 3.
FIG. 8 illustrates a representative table 800 for managing login credentials and the associated authorization level granted to each of a plurality of operators through a session manager. The first and second columns of table 800 represent the access device and / or the operator login credentials. According to various embodiments, each operator can have a unique username, displayed in the first column of table 800 as Operator 1 to Operator N, and a unique password, displayed in the second column of table 800. The login credentials of An access device and / or operator session may comprise any number of possible authentication schemes, and are not limited to username / password combinations.
An authorization level for each connected IED is associated with each operator login credential. Using the first row as an example, the authorization level associated with the login credentials “Operator 1” and “Password 1” provides administrator access to IED 1, medium level access to IED 2, low level access to IED 3 and administrative access to IED No. As another example, the operator associated with the username “Operator 3” and the password “Password 3” only has low-level access to both IED 2 and IED 3.
As described above, legacy IEDs cannot provide different levels of access. Accordingly, to all the operators of FIG. 8 administrator access is granted to both IED 1 and IED 2 as the other possible alternative is no
ES 2 464 665 B2 grant them access.
FIG. 9 illustrates a representative table 900 for managing login credentials and associated authorization levels granted to each of a plurality of access devices via a session manager that includes a session filter. According to various embodiments and as described above, a session filter can efficiently provide legacy IEDs with different levels of access. For example, IED 1 and IED N are shown as legacy devices (third column). Consequently, the only access level available for IED 1 and IED N is either manager or neither (see fourth column of FIGS. 7 and 9). Again, using a session filter to suppress specific commands, it may appear that a legacy IED supports different levels of access.
For example, the operator in the second row associated with the user name “Operator 2” (first column) and the password “Password 2” (second column) has administrator access to IED 1 and IED 2 (fourth column). However, the session filter suppresses commands so that the operator is in practical terms a high-level operator of IED 1 and a mid-level operator of IED N. According to various embodiments, a session filter can be configured to suppress all commands related to modifications of the login credentials of the IEDs themselves.
The above description provides numerous specific details to offer a thorough understanding of the embodiments described in this document. However, those skilled in the art will recognize that one or more of the specific details may be omitted, modified and / or substituted by a similar process or system.
Contents11
9 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9
12 members in 8 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 13166648 | United States of America | – | |
| 201113166648 | United States of America | A | |
| 201113166648 | United States of America | A | |
| 2012043593 | United States of America | W | |
| 2012043593 | United States of America | W | |
| 13166648 | – | – | – |
| PCTUS2012043593 | – | – | – |
| US201113166648 | – | – | – |
| WO2012US43593 | – | – | – |
Members12
| Document | Office | Kind | |
|---|---|---|---|
| CA2836806A1 | Canada | A1 | |
| US2012331534A1 | United States of America | A1 | |
| WO2012177912A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2012272909A1 | Australia | A1 | |
| MX2013013856A | Mexico | A | |
| US8677464B2 | United States of America | B2 | |
| ES2464665A2 | Spain | A2 | |
| ZA201308548B | South Africa | B | |
| ES2464665R1 | Spain | R1 | |
| AU2012272909B2 | Australia | B2 | |
| ES2464665B2This record | Spain | B2 | |
| BR112013032879A2 | Brazil | A2 |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Announcement of lapse in spainLapsedFD2A | FD2A | |
| Definitive protectionFG2A | FG2A |
Numbers
- Publication
- 2464665
- Publication, DOCDB
- 2464665
- Publication, EPODOC
- ES2464665
- Application
- 201390095
- Application, DOCDB
- 201390095
- Application, EPODOC
- ES20130090095
Titles2
- Spanish
- Sistemas y procedimientos de gestión de sesiones de comunicación seguras con dispositivos remotos
- English
- Systems and procedures for managing secure communication sessions with remote devices
Classification
- CPC, 6
- G06F21/41
- H04L9/088
- H04L9/0891
- H04L63/0846
- Y04S40/20
- H04L9/32
- IPC, 2
- G06F21 41
- H04L9 32