{"title":"Communication Security Architecture for Smart Distribution System Operations","authors":"T. Mander, H. Cheung, A. Hamlyn, R. Cheung","doi":"10.1109/EPC.2007.4520367","DOIUrl":null,"url":null,"abstract":"This paper proposes a communication cybersecurity architecture for smart distribution system operations using distributed network protocol (DNP3). The focus is on providing cybersecurity for residential load-management devices that are networked for access by the utility and their consumers. The proposed architecture utilizes DNP3 to produce a disjoint protocol between strictly-regulated utility devices and devices accessible by the utility and consumers. The disjoint protocol limits the effectiveness of attacks originated from the consumer TCP/IP access to a device into the utility network. Since DNP3 does not provide sufficient security, security enhancements to DNP3 are proposed using data object security and a security layer. The data object security provides data access rules to a device, preventing unauthorized manipulation of device operations and data. The security layer provides confidentiality through encryption between devices for consumer personal privacy and to prevent cyber-attackers from identifying potential utility targets.","PeriodicalId":196861,"journal":{"name":"2007 IEEE Canada Electrical Power Conference","volume":"73 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2007-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2007 IEEE Canada Electrical Power Conference","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/EPC.2007.4520367","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4
Abstract
This paper proposes a communication cybersecurity architecture for smart distribution system operations using distributed network protocol (DNP3). The focus is on providing cybersecurity for residential load-management devices that are networked for access by the utility and their consumers. The proposed architecture utilizes DNP3 to produce a disjoint protocol between strictly-regulated utility devices and devices accessible by the utility and consumers. The disjoint protocol limits the effectiveness of attacks originated from the consumer TCP/IP access to a device into the utility network. Since DNP3 does not provide sufficient security, security enhancements to DNP3 are proposed using data object security and a security layer. The data object security provides data access rules to a device, preventing unauthorized manipulation of device operations and data. The security layer provides confidentiality through encryption between devices for consumer personal privacy and to prevent cyber-attackers from identifying potential utility targets.