System and method for enabling a scalable public-key infrastructure on a smart grid network

    公开(公告)号:US10764261B2

    公开(公告)日:2020-09-01

    申请号:US14588042

    申请日:2014-12-31

    Abstract: A method for enabling a scalable public-key infrastructure (PKI) comprises invoking a process of receiving a message for a device, identifying an association ID for the device, retrieving encrypted association keys stored on the server for communicating with the device, the encrypted association keys encrypted using a wrapping key stored on a Hardware Security Module (HSM). The method further comprises sending the message and the encrypted association keys to the HSM, unwrapping, by the HSM, the encrypted association keys to create unwrapped association keys, cryptographically processing the message to generate a processed message, deleting the unwrapped association keys, sending the processed message to the device, and invoking, concurrently and by a second application, the process.

    HANDHELD VIDEO VISITATION
    3.
    发明申请
    HANDHELD VIDEO VISITATION 审中-公开
    手持视频访问

    公开(公告)号:US20150156180A1

    公开(公告)日:2015-06-04

    申请号:US14588042

    申请日:2014-12-31

    CPC classification number: H04L63/0471 H04B2203/5433 H04L63/0281 Y04S40/24

    Abstract: A method for enabling a scalable public-key infrastructure (PKI) comprises invoking a process of receiving a message for a device, identifying an association ID for the device, retrieving encrypted association keys stored on the server for communicating with the device, the encrypted association keys encrypted using a wrapping key stored on a Hardware Security Module (HSM). The method further comprises sending the message and the encrypted association keys to the HSM, unwrapping, by the HSM, the encrypted association keys to create unwrapped association keys, cryptographically processing the message to generate a processed message, deleting the unwrapped association keys, sending the processed message to the device, and invoking, concurrently and by a second application, the process.

    Abstract translation: 一种用于启用可扩展公钥基础结构(PKI)的方法包括:调用接收设备的消息的过程,识别该设备的关联ID,检索存储在该服务器上用于与该设备通信的加密关联密钥,该加密关联 使用存储在硬件安全模块(HSM)上的包装密钥加密的密钥。 该方法还包括将消息和加密的关联密钥发送到HSM,由HSM解包加密的关联密钥以创建未包裹的关联密钥,密码处理消息以生成经处理的消息,删除未包装关联密钥,发送 处理的消息到设备,并且同时和第二应用调用该过程。

    Secure management of radio transmissions in an endpoint device of a network
    4.
    发明授权
    Secure management of radio transmissions in an endpoint device of a network 有权
    安全管理网络端点设备中的无线电传输

    公开(公告)号:US09363836B2

    公开(公告)日:2016-06-07

    申请号:US14242368

    申请日:2014-04-01

    Abstract: A method for managing radio transmission in an endpoint device in a network includes: receiving, at a first endpoint device, a message requesting wake up of the first endpoint device; establishing a connection between the first endpoint device to a second endpoint device connected to the network; determining, at the first endpoint device, whether a secure command is received from the second endpoint device via the established connection within a predetermined period of time; and based on the received secure command, establishing a connection between the first endpoint device and the network via radio transmission, wherein the first endpoint device is configured to turn off radio transmission if the secure command is not received within the predetermined period of time.

    Abstract translation: 一种用于管理网络中的端点设备中的无线电传输的方法包括:在第一端点设备处接收请求唤醒所述第一端点设备的消息; 建立所述第一端点设备与连接到所述网络的第二端点设备之间的连接; 在所述第一端点设备处确定在预定时间段内是否经由建立​​的连接从所述第二端点设备接收到安全命令; 并且基于所接收的安全命令,经由无线电传输建立所述第一端点设备和所述网络之间的连接,其中,如果在所述预定时间段内没有接收到所述安全命令,则所述第一端点设备被配置为关闭无线电传输。

    Method and system for cryptographically enabling and disabling lockouts for critical operations in a smart grid network

    公开(公告)号:US10229291B2

    公开(公告)日:2019-03-12

    申请号:US15620081

    申请日:2017-06-12

    Abstract: A method for locking out a remote terminal unit includes: receiving a lockout request, wherein the lockout request includes at least a public key associated with a user, a user identifier, and a terminal identifier; identifying a user profile associated with the user based on the user identifier included in the received lockout request; verifying the public key included in the received lockout request and permission for the user to lockout a remote terminal unit associated with the terminal identifier included in the received lockout request based on data included in the identified user profile; generating a lockout permit, wherein the lockout permit includes at least the public key included in the received lockout request; and transmitting at least a lockout request and the generated lockout permit, wherein the lockout request includes an instruction to place a lockout on the remote terminal unit.

    SECURE MANAGEMENT OF RADIO TRANSMISSIONS IN AN ENDPOINT DEVICE OF A NETWORK
    7.
    发明申请
    SECURE MANAGEMENT OF RADIO TRANSMISSIONS IN AN ENDPOINT DEVICE OF A NETWORK 有权
    网络终端设备中无线传输的安全管理

    公开(公告)号:US20140295772A1

    公开(公告)日:2014-10-02

    申请号:US14242368

    申请日:2014-04-01

    Abstract: A method for managing radio transmission in an endpoint device in a network includes: receiving, at a first endpoint device, a message requesting wake up of the first endpoint device; establishing a connection between the first endpoint device to a second endpoint device connected to the network; determining, at the first endpoint device, whether a secure command is received from the second endpoint device via the established connection within a predetermined period of time; and based on the received secure command, establishing a connection between the first endpoint device and the network via radio transmission, wherein the first endpoint device is configured to turn off radio transmission if the secure command is not received within the predetermined period of time.

    Abstract translation: 一种用于管理网络中的端点设备中的无线电传输的方法包括:在第一端点设备处接收请求唤醒所述第一端点设备的消息; 建立所述第一端点设备与连接到所述网络的第二端点设备之间的连接; 在所述第一端点设备处确定在预定时间段内是否经由建立​​的连接从所述第二端点设备接收到安全命令; 并且基于所接收的安全命令,经由无线电传输建立所述第一端点设备和所述网络之间的连接,其中,如果在所述预定时间段内没有接收到所述安全命令,则所述第一端点设备被配置为关闭无线电传输。

Patent Agency Ranking