DNPSec: Distributed Network Protocol Version 3 (DNP3) security framework

被引:39
作者
Majdalawieh, Munir [1 ,2 ]
Parisi-Presicce, Francesco [2 ]
Wijesekera, Duminda [2 ]
机构
[1] Amer Univ Sharjah, Sharjah, U Arab Emirates
[2] George Mason Univ, Fairfax, VA 22030 USA
来源
ADVANCES IN COMPUTER, INFORMATION, AND SYSTEMS SCIENCES AND ENGINEERING | 2006年
关键词
SCADA; DNP3; DNPSec;
D O I
10.1007/1-4020-5261-8_36
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed Network Protocol Version 3 (DNP3) is an open and optimized protocol developed for the Supervisory Control and Data Acquisition (SCADA) Systems supporting the utilities industries. The DNP3 enables the Master Station to request data from Substations using pre-defined control function commands and Substations to respond by transmitting the requested data. DNP3 was never designed with security mechanisms in mind and therefore the protocol itself lacks any form of authentication or encryption. Discussion so far has been centered on two solutions to provide security for SCADA: cryptographic technologies placed at each end of the communication medium, or security enhancements placed directly in the protocol. This paper recommends a new Distributed Network Protocol Version 3 Security (DNPSec) framework to enable confidentiality, integrity, and authenticity placed directly in the DNP3. Such framework requires some modifications in the data structure of the DNP3 Data Link layer. Our main goal is to address the threats related to confidentiality, integrity, and authenticity in the DNP3 as part of SCADA architecture, with a minimum performance impact on the communication link; and without requiring modification to the much more expensive Master Station and Substation devices and the applications supporting them.
引用
收藏
页码:227 / +
页数:2
相关论文
共 17 条
[1]  
[Anonymous], 2401 IETF RFC
[2]  
[Anonymous], 1981, RFC0791 INTERNET PRO
[3]  
[Anonymous], 2004, 12 AGA
[4]  
COATS J, 2002, DNP3 PROT AGA GTI SC
[5]  
IEC, IEC 61850-Based Smart Substations, V1st
[6]  
*INF ASS TASK FORC, 2004, EL POW RISK ASS
[7]  
KENT S, 1998, 2403 IETF RFC
[8]  
Kent S. T., 1998, RFC 2402
[9]  
KIM, 2003, P IASTED INT C COMM, P231
[10]  
*NEWT EV RES CO, 2002, WORLD MARK SUBST AUT