首页> 外文会议>IEEE International Conference on Smart Grid Communications >Resilient end-to-end message protection for large-scale cyber-physical system communications
【24h】

Resilient end-to-end message protection for large-scale cyber-physical system communications

机译:适用于大型网络物理系统通信的弹性端到端消息保护

获取原文

摘要

Essential features of cyber-physical systems such as Smart Grid are real-time analysis of high-resolution data, which a massive number of embedded devices periodically generate, and the effective and timely response to specific analytic results obtained from the data. Therefore, mission-critical data and control messages exchanged among machines in the cyber-physical systems must be strongly protected to prevent the infrastructures from becoming vulnerable. Specifically, the protection mechanism used must be scalable, secured from an end-to-end perspective, and key exposure resilient. Moreover, there may be privacy protection required among devices that generate data, e.g., smart metering. In this paper, we show that, for large-scale cyber-physical system communications, most well-known point-to-point security schemes such as IPsec [1], TLS [2], or SRTP [3] cannot meet the scalability, extensibility, and thinness requirements. By contrast conventional group security schemes which address the limitations of the point-to-point schemes have other limitations on aspects of privacy, key exposure resiliency, and key refreshment. To address the security requirements for cyber-physical systems, we design a resilient end-to-end message protection framework, REMP, exploiting the notion of the long-term key that is given on per node basis. This long term key is assigned during the node authentication phase and is subsequently used to derive encryption keys from a random number per-message sent. Compared with conventional schemes, REMP improves privacy, message authentication, and key exposure, and without compromising scalability and end-to-end security. The tradeoff is a slight increase in computation time for message decryption and message authentication.
机译:诸如智能电网的网络物理系统的基本特征是对高分辨率数据的实时分析,该高分辨率数据是周期性地生成的大量嵌入式设备,以及对从数据获得的特定分析结果的有效和及时响应。因此,必须强烈地保护在网络物理系统中的机器中交换的任务关键数据和控制消息,以防止基础设施变得脆弱。具体地,所使用的保护机制必须可扩展,从端到端的透视图中固定,并且键暴露弹性。此外,在生成数据的设备中可能需要隐私保护,例如智能计量。在本文中,我们表明,对于大型网络物理系统通信,最着名的点对点安全方案(如IPSec [1],TLS [2]或SRTP [3])不能满足可伸缩性,可扩展性和薄度要求。通过对比传统的群组安全方案,解决了点对点方案的限制对隐私,关键曝光弹性和密钥刷新方面的其他限制。为满足网络物理系统的安全要求,我们设计了一个弹性端到端消息保护框架,REMP,利用每个节点给出的长期键的概念。在节点认证阶段期间分配了该长期键,随后用于从发送的每条消息的随机数派生加密密钥。与传统方案相比,REMP改善了隐私,消息认证和键曝光,而不会影响可扩展性和最终安全性。权衡是消息解密和消息认证的计算时间略有增加。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号