...
首页> 外文期刊>Renewable & Sustainable Energy Reviews >Cyber-security in substation automation systems
【24h】

Cyber-security in substation automation systems

机译:变电站自动化系统中的网络安全

获取原文
获取原文并翻译 | 示例
           

摘要

The cyber-security of several industrial plants has been compromised for last years by some worms and viruses, such as Stuxnet, which was able to take control of the Supervisory Control And Data Acquisition (SCADA) system of a nuclear plant in Iran. The research community and the international standardization committees raised their awareness about protecting information in Substation Automation Systems (SAS). IEC 61850-5 and IEC 62351-6 standards respectively describe communication models and the security mechanisms to be deployed in current substations, but they present some inconsistencies. On the one hand, this standard mandates that RSA cryptosystem must be used to provide source authenticity of GOOSE and SV messages. However, despite expensive processors with crypto accelerators were utilized, execution times would exceed the maximum transfer times stated in the standard for most time critical applications. On the other hand, the recommended synchronization solution is the Precision Time Protocol (PTP), as defined in IEEE 1588-2008, which introduced an optional security extension based on old keyed hash algorithms that has also been demonstrated to be suboptimal due to latency times and required resources. The aim of this paper is to explore current available security solutions and study their applicability to the substation environment. Furthermore, as part of the future security framework, a MACsec-based security approach that allows different communication services with diverse performance and security requirements to live together within the substation network is proposed. (C) 2015 Elsevier Ltd. All rights reserved.
机译:近年来,一些蠕虫和病毒破坏了几家工厂的网络安全,例如Stuxnet,它能够控制伊朗核工厂的监督控制和数据采集(SCADA)系统。研究界和国际标准化委员会提高了他们对变电站自动化系统(SAS)中信息保护的认识。 IEC 61850-5和IEC 62351-6标准分别描述了要在当前变电站中部署的通信模型和安全机制,但它们存在一些不一致之处。一方面,该标准要求必须使用RSA密码系统来提供GOOSE和SV消息的源真实性。但是,尽管使用了带有加密加速器的昂贵处理器,但是执行时间将超过大多数时间紧迫应用中标准规定的最大传输时间。另一方面,推荐的同步解决方案是IEEE 1588-2008中定义的精确时间协议(PTP),该协议引入了基于旧密钥哈希算法的可选安全扩展,由于延迟时间,该扩展也被证明不是最佳的和所需的资源。本文的目的是探索当前可用的安全解决方案,并研究其在变电站环境中的适用性。此外,作为未来安全框架的一部分,提出了一种基于MACsec的安全方法,该方法允许具有不同性能和安全要求的不同通信服务一起生活在变电站网络中。 (C)2015 Elsevier Ltd.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号