Role-based access control for substation automation systems using XACML

被引:9
作者
Lee, Byunghun [1 ]
Kim, Dae-Kyoo [1 ]
Yang, Hyosik [2 ]
Jang, Hyuksoo [3 ]
机构
[1] Oakland Univ, Dept Comp Sci & Engn, Rochester, MI 48309 USA
[2] Sejong Univ, Dept Comp Engn, Seoul, South Korea
[3] Myongji Univ, Dept Comp Engn, Yongin, South Korea
关键词
RBAC; Smart grid; Substation automation; XACML;
D O I
10.1016/j.is.2015.01.007
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
There has been an increasing need for accessing data of internal equipment and devices of a substation system from external systems as power grids evolve. This has also introduced growing concerns on data security. In response to the concerns, IEC 62351 has proposed role-based access control (RBAC) for substation automation. In this work, we present a novel approach for implementing RBAC based on IEC 62351 for substation automation using eXtensible Access Control Markup Language (XACML). We integrate the approach with IEC 61850 by extending Abstract Communication Service Interface (ACSI), Manufacturing Message Specification (MMS), and System Configuration Language (SCL). A major advantage of the approach is that it fully conforms to both IEC 61850 and IEC 62351 and highly compatible with SCL as both XACML and SCL are XML-based. We implement the approach using OpenIEC61850 which is an open source library for ACSI services and demonstrate the implementation. (C) 2015 Elsevier Ltd. All rights reserved.
引用
收藏
页码:237 / 249
页数:13
相关论文
共 17 条
[1]  
[Anonymous], 2005, EXT ACC CONTR MARK L
[2]  
[Anonymous], 2013, Openiec61850
[3]  
[Anonymous], 61850 IEC
[4]  
[Anonymous], 2012, SPECIFIC COMMUNICATI
[5]  
[Anonymous], 2006, 6140025 IEC
[6]  
[Anonymous], 2006, SUNS XACML IMPL
[7]  
Baoyi W., 2008, P IEEE INT C IND TEC, P1
[8]  
Dong W., 2013, P 7 IEEE VEH TECHN C, P1
[9]  
Ferraiolo D. F., 2001, ACM Transactions on Information and Systems Security, V4, P224, DOI 10.1145/501978.501980
[10]  
*IEC, 2007, 62351 IEC