首页> 外文会议>Advanced machinery technology symposium >Control System Data Integrity using a Variable-round Message Authentication Code with an Elliptic Curve Key Exchange Protocol
【24h】

Control System Data Integrity using a Variable-round Message Authentication Code with an Elliptic Curve Key Exchange Protocol

机译:使用带有椭圆曲线密钥交换协议的可变回合消息验证码控制系统数据完整性

获取原文

摘要

The challenge of securing industrial control systems is significant and previous work provided solutions to a number of these challenges including performing mathematical operations on BigIntegers; generating and distributing keys; generating cryptographically secure hash values; implementing random number generation; and ensuring that the operations can be performed without impacting normal operation / scan times. In previous works the Variable-round Message Authentication Code (VMAC) algorithm was introduced for per-message data authentication, and a scheme was presented for two nodes to exchange a symmetric key for VMAC. This work expands upon previous work by introducing the Key Exchange Protocol (KEP), which allows for generation and distribution of symmetric keys for use in multicast implementations of VMAC. KEP is capable of being configured into multiple tree configurations to increase the efficiency of key distribution, but also provides for redundancy in case the root node is taken offline. This work also provides additional VMAC proof of security and VMAC implementation details. A proof of concept for VMA C and KEP was then created and tested using four 1756-L83 Rockwell Automation processors. KEP was show to have an average scan time impact of 10ms during a key exchange with a minimum impact of less than 1ms when IDLE and a maximum impact of 20 ms if verifying and creating digital signed messages at the same time.
机译:保护工业控制系统的挑战是巨大的,以前的工作为许多挑战提供了解决方案,包括在BigIntegers上执行数学运算;生成和分发密钥;生成加密安全的哈希值;实现随机数生成;并确保可以在不影响正常操作/扫描时间的情况下执行操作。在以前的工作中,引入了可变消息验证码(VMAC)算法用于按消息的数据验证,并提出了两个节点交换VMAC对称密钥的方案。这项工作通过引入密钥交换协议(KEP)扩展了以前的工作,该协议允许生成和分发用于VMAC的多播实现的对称密钥。 KEP可以配置为多个树配置以提高密钥分发的效率,但是还可以在根节点脱机的情况下提供冗余。这项工作还提供了其他VMAC安全性证明和VMAC实现细节。然后使用四个1756-L83罗克韦尔自动化处理器创建并测试了VMA C和KEP的概念证明。事实证明,KEP在密钥交换过程中平均扫描时间影响为10毫秒,而在IDLE时,最小影响小于1毫秒,如果同时验证和创建数字签名消息,则最大影响为20毫秒。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号