首页> 外文会议>MILITARY COMMUNICATIONS CONFERENCE, 2011 - MILCOM 2011 >From security to vulnerability: Data authentication undermines message delivery in smart grid
【24h】

From security to vulnerability: Data authentication undermines message delivery in smart grid

机译:从安全到漏洞:数据身份验证破坏了智能电网中的消息传递

获取原文
获取原文并翻译 | 示例

摘要

The smart grid is an emerging technology that integrates the power infrastructure with information technologies to enable real-time monitoring and control of various power equipments. As the most important component in power systems, power substations merge not only many critical equipments, such as transformers and transmission lines, but a large amount of system information to manipulate miscellaneous system events for well-maintained system states. In this paper, we aim at security issues within a substation and try to address the open question, whether existing security mechanisms satisfy both security and performance requirements of applications in Substation Automation Systems (SAS). To this end, we establish a small-scale SAS prototype with commonly-used security mechanisms for message integrity protection, such as RSA and one-time signature (OTS) based schemes, to measure delivery performances of secure SAS messages. Our results reveal that neither of them can be readily adopted by the SAS. Adversely, the limitation of security mechanisms, such as complicated computation, short key valid time and limited key supply, can be easily hijacked by attackers to undermine the SAS message delivery, thereby becoming security vulnerabilities. Our work indicates that message integrity protection in the SAS needs to be addressed urgently before a large-scale deployment of the smart grid.
机译:智能电网是将电力基础设施与信息技术集成在一起的新兴技术,可以对各种电力设备进行实时监视和控制。作为电力系统中最重要的组件,变电站不仅合并了许多关键设备,例如变压器和输电线路,而且还合并了大量的系统信息,以操纵各种系统事件以维护良好的系统状态。在本文中,我们针对变电站内的安全问题,并尝试解决一个开放性问题,即现有的安全机制是否满足变电站自动化系统(SAS)中应用程序的安全性和性能要求。为此,我们建立了一个小规模的SAS原型,该原型具有用于消息完整性保护的常用安全机制,例如RSA和基于一次性签名(OTS)的方案,以测量安全SAS消息的传递性能。我们的结果表明,SAS都不容易采用它们。相反,攻击者很容易劫持安全机制的局限性,例如复杂的计算,较短的密钥有效时间和有限的密钥供应,以破坏SAS消息的传递,从而成为安全漏洞。我们的工作表明,在大规模部署智能电网之前,迫切需要解决SAS中的消息完整性保护问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号