US 12,244,143 B2
Methods of securely controlling utility grid edge devices
David Crawford Lawrence, Charlotte, NC (US); Marshal Dwayne Bradley, Gastonia, NC (US); Thomas E. Burdick, Chicago, IL (US); Jessica C. Modeen, Charlotte, NC (US); Nicholas J. Kennedy, Jasper, AL (US); Matthew A. DeVenny, Phoenix, AZ (US); Caleb J. Lloyd, Raleigh, NC (US); and C. Wilson Kinard, Greenville, SC (US)
Assigned to DUKE ENERGY CORPORATION, Charlotte, NC (US); and OPEN ENERGY SOLUTIONS INC., Santa Clara, CA (US)
Filed by DUKE ENERGY CORPORATION, Charlotte, NC (US); and OPEN ENERGY SOLUTIONS INC., Santa Clara, CA (US)
Filed on Jan. 25, 2022, as Appl. No. 17/583,384.
Claims priority of provisional application 63/174,704, filed on Apr. 14, 2021.
Prior Publication US 2022/0337082 A1, Oct. 20, 2022
Int. Cl. H02J 13/00 (2006.01); G06F 21/72 (2013.01)
CPC H02J 13/00016 (2020.01) [G06F 21/72 (2013.01); H02J 13/00022 (2020.01)] 15 Claims
OG exemplary drawing
 
1. A method of securely controlling a utility grid edge device, the method comprising:
receiving renewed security information, from a distributed certification authority (CA) server on a first node in a cluster of nodes, at a second node within the cluster of nodes and that is adjacent the utility grid edge device and that includes cryptographic circuitry comprising a Trusted Platform Module (TPM), wherein the first node, the second node receiving the renewed security information, and the utility grid edge device are each outside of a data center, wherein the second node comprises a memory comprising an agent and a workload, wherein the workload comprises an application that controls an operation of the utility grid edge device, and wherein receiving the renewed security information at the second node comprises:
receiving the renewed security information at the agent from the distributed CA server on the first node,
providing the renewed security information from the agent to the workload, wherein the renewed security information comprises a private digital security key and a public digital security key and automatically expires in no more than one hour, and
patching or updating the workload using a Public Key Infrastructure (PKI); then controlling the operation of the utility grid edge device via the second node.