...
首页> 外文期刊>International Journal of Distributed Sensor Networks >Authentication and Integrity in the Smart Grid: An Empirical Study in Substation Automation Systems
【24h】

Authentication and Integrity in the Smart Grid: An Empirical Study in Substation Automation Systems

机译:智能电网中的身份验证和完整性:变电站自动化系统中的一项经验研究

获取原文
           

摘要

The smart grid is an emerging technology that integrates power infrastructures with information technologies to enable intelligent energy managements. As one of the most important facilities of power infrastructures, electrical substations undertake responsibilities of energy transmissions and distributions by operating interconnected electrical devices in a coordinated manner. Accordingly, it imposes a great challenge on information security, since any falsifications may trigger mal-operations, and result in damages to power usage. In this paper, we aim at authentication and integrity protections in substation automation systems (SAS), by an experimental approach on a small scale SAS prototype, in which messages are transmitted with commonly-used data origin authentication schemes, such as RSA, Message Authentication Code, and One-Time Signature. Through experimental results, we find that, current security solutions cannot be applied directly into the SAS due to insufficient performance considerations in response to application constraints, including limited device computation capabilities, stringent timing requirements and high data sampling rates. Moreover, intrinsic limitations of security schemes, such as complicated computations, shorter key valid time and limited key supplies, can easily be hijacked by malicious attackers, to undermine message deliveries, thus becoming security vulnerabilities. Our experimental results demonstrate guidelines in design of novel security schemes for the smart grid.
机译:智能电网是将电力基础设施与信息技术集成在一起以实现智能能源管理的新兴技术。作为电力基础设施的最重要设施之一,变电站通过以协调的方式操作互连的电气设备来承担能量传输和分配的责任。因此,由于任何篡改都可能引发误操作,并导致对功率使用的损害,这对信息安全提出了巨大的挑战。在本文中,我们通过在小型SAS原型上的实验方法,针对变电站自动化系统(SAS)中的身份验证和完整性保护,在该原型中,使用通用数据源身份验证方案(例如RSA,消息身份验证)传输消息代码和一次性签名。通过实验结果,我们发现,由于对应用程序约束(包括有限的设备计算能力,严格的时序要求和高数据采样率)的性能考虑不足,因此当前的安全解决方案无法直接应用于SAS。此外,安全方案的固有局限性,例如复杂的计算,更短的密钥有效时间和有限的密钥供应,很容易被恶意攻击者劫持,破坏消息传递,从而成为安全漏洞。我们的实验结果证明了智能电网新型安全方案设计的指导原则。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号