首页> 外文期刊>Journal of computer security >Secure authentication in the grid: A formal analysis of DNP3 SAv5
【24h】

Secure authentication in the grid: A formal analysis of DNP3 SAv5

机译:网格中的安全身份验证:DNP3 SAv5的形式分析

获取原文
获取原文并翻译 | 示例
           

摘要

Most of the world’s power grids are controlled remotely. Their control messages are sent over potentially insecure channels, driving the need for an authentication mechanism. The main communication mechanism for power grids and other utilities is defined by an IEEE standard, referred to as DNP3; this includes the Secure Authentication v5 (SAv5) protocol, which aims to ensure that messages are authenticated. We provide the first security analysis of the complete DNP3: SAv5 protocol. Previous work has considered the message-passing sub-protocol of SAv5 in isolation, and considered some aspects of the intended security properties. In contrast, we formally model and analyse the complex composition of the protocol’s sub-protocols. In doing so, we consider the full state machine, the protocol’s asymmetric mode, and the possibility of cross-protocol attacks. Furthermore, we model fine-grained security properties that closely match the standard’s intended security properties. For our analysis, we leverage the Tamarin  prover for the symbolic analysis of security protocols. Our analysis shows that the core DNP3: SAv5 design meets its intended security properties. Notably, we show that a previously reported attack does not apply to the standard. However, our analysis also leads to several concrete recommendations for improving future versions of the standard.
机译:世界上大多数电网都是远程控制的。它们的控制消息是通过可能不安全的通道发送的,从而推动了对身份验证机制的需求。电网和其他公用事业的主要通信机制由称为DNP3的IEEE标准定义。这包括安全身份验证v5(SAv5)协议,该协议旨在确保对消息进行身份验证。我们提供完整DNP3:SAv5协议的首次安全分析。先前的工作单独考虑了SAv5的消息传递子协议,并考虑了预期安全性的某些方面。相反,我们正式对协议子协议的复杂组成进行建模和分析。在此过程中,我们考虑了完整状态机,协议的非对称模式以及跨协议攻击的可能性。此外,我们对与标准预期的安全属性非常匹配的细粒度安全属性进行建模。对于我们的分析,我们利用Tamarin证明程序对安全协议进行符号分析。我们的分析表明,核心DNP3:SAv5设计符合其预期的安全性。值得注意的是,我们表明先前报告的攻击不适用于该标准。但是,我们的分析还提出了一些具体建议,以改进标准的未来版本。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号