首页> 外文会议>IFIP 11.10 international conference on critical infrastructure protection >ENFORCING END-TO-END SECURITY IN SCADA SYSTEMS VIA APPLICATION-LEVEL CRYPTOGRAPHY
【24h】

ENFORCING END-TO-END SECURITY IN SCADA SYSTEMS VIA APPLICATION-LEVEL CRYPTOGRAPHY

机译:通过应用级密码技术在SCADA系统中增强端到端安全性

获取原文

摘要

Recent technological advances have had a strong impact on performance optimization and the provisioning of flexible supervisory control and data acquisition (SCADA) systems. However, most SCADA communications protocols, as currently implemented, are extremely vulnerable to cyber attacks. Several international organizations have been developing security standards to alleviate these threats. Nevertheless, investigations reveal that the vast majority of high-end control hardware devices do not incorporate security features (i.e., security protocols). Therefore, the enforcement of data security in end-to-end communications flows must be addressed at the application layer. This chapter evaluates the feasibility of performing cryptographic computations at the application layer of a programmable logic controller. It shows that, despite the modest computational resources of modern programmable logic controllers, it is possible to develop efficient cryptographic applications that enforce several data security properties in the application layer. The experimental evaluations compare the performance of AES, SHA1 and HMAC-SHA1 against the performance of the new Speck and Simon lightweight block cipher algorithms executing on a Phoenix Contact ILC 350 PN controller with the control logic of a real SCADA system used in the Romanian gas transportation network.
机译:最近的技术进步对性能优化以及提供灵活的监督控制和数据采集(SCADA)系统产生了重大影响。但是,目前实施的大多数SCADA通信协议都极易受到网络攻击。几个国际组织一直在开发安全标准以减轻这些威胁。然而,调查显示,绝大多数高端控制硬件设备未包含安全功能(即安全协议)。因此,必须在应用程序层解决端到端通信流中数据安全性的强制措施。本章评估了在可编程逻辑控制器的应用层执行密码计算的可行性。它表明,尽管现代可编程逻辑控制器的计算资源有限,但仍有可能开发出有效的密码应用程序,该应用程序在应用程序层中强制实施几种数据安全性属性。实验评估将AES,SHA1和HMAC-SHA1的性能与在Phoenix Contact ILC 350 PN控制器上执行的新型Speck和Simon轻量级分组密码算法的性能以及罗马尼亚天然气中使用的实际SCADA系统的控制逻辑进行了比较交通网络。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号