首页> 外文会议>International conference on security standardisation research >Non-repudiation Services for the MMS Protocol of IEC 61850
【24h】

Non-repudiation Services for the MMS Protocol of IEC 61850

机译:IEC 61850的MMS协议的不可否认服务

获取原文

摘要

In Smart Grids various processes can be automated using communication between the components of the grid. The standard IEC 61850 defines, among other requirements and parts of the system, different communication protocols, that shall be used for different purposes. Although the scope of IEC 61850 is the automation of substations, there are also use cases beyond that can be addressed by IEC 61850. The standard IEC 62351 sets the focus on security in Smart Grids and lists various security requirements, that should be met, and further a series of measures to accomplish the required level of security. However, there are additional security requirements, such as non-repudiation and traceabil-ity of transactions, which cannot be sufficed using only the mechanisms provided by IEC 62351. In this paper a security solution will be presented that meets these additional requirements. Basically, it uses certificates for the proof of identity of the system participants and provides the two non-repudiation services Non-repudiation of Origin and Non-repudiation of Delivery using mechanisms described by the standard ISO 13888-3. The focus is set on the MMS protocol that is used for end-to-end communication between client and server. However, due to the flexibility of the mechanisms used, the security solution can also be transferred to different protocols. Finally, this paper describes a way to implement the solution using XML signatures and X.509 certificates.
机译:在智能电网中,可以使用电网组件之间的通信来自动化各种过程。 IEC 61850标准除其他要求和系统组成部分之外,还定义了不同的通信协议,这些协议应用于不同的目的。尽管IEC 61850的范围是变电站的自动化,但是还有一些用例超出了IEC 61850可以解决的情况。标准IEC 62351将重点放在智能电网的安全性上,并列出了应满足的各种安全要求,以及进一步采取了一系列措施来达到所需的安全级别。但是,还有其他安全要求,例如不可否认性和交易的可追溯性,仅使用IEC 62351提供的机制无法满足这些要求。在本文中,将提出一种满足这些附加要求的安全解决方案。基本上,它使用证书来证明系统参与者的身份,并使用标准ISO 13888-3所描述的机制提供两种不可否认性服务:不可否认来源和不可否认交付。重点放在用于客户端和服务器之间的端到端通信的MMS协议上。但是,由于所使用机制的灵活性,安全解决方案也可以转移到不同的协议。最后,本文描述了一种使用XML签名和X.509证书来实现该解决方案的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号