{"title":"Secure Communication of Intelligent Electronic Devices in Digital Substations","authors":"D. Ishchenko, R. Nuqui","doi":"10.1109/TDC.2018.8440438","DOIUrl":null,"url":null,"abstract":"This paper presents a communication “bump-in-the-wire” Security Filter device connected between the digital relays and the IEC 61850 communication buses to secure digital substation communications. Security Filter authenticates and verifies the designated Ethernet packets transmitted between protection and control devices by appending a message authentication code based on symmetric cryptography, which is compliant with the new mechanisms described in IEC 61850 and suitable for embedded system implementation. A prototype development and testing on a low cost commodity embedded system has proved that Security Filter can fully protect digital substation communication against replay attacks with time delays within the range of the most stringent IEC 61580 performance class requirements. The paper also presents multimode Security Filter operation design, which provides a practical interoperable way to upgrade and secure legacy substations with minimal modification or interruption to the existing systems.","PeriodicalId":6568,"journal":{"name":"2018 IEEE/PES Transmission and Distribution Conference and Exposition (T&D)","volume":"19 1 1","pages":"1-5"},"PeriodicalIF":0.0000,"publicationDate":"2018-04-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"19","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 IEEE/PES Transmission and Distribution Conference and Exposition (T&D)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/TDC.2018.8440438","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 19
Abstract
This paper presents a communication “bump-in-the-wire” Security Filter device connected between the digital relays and the IEC 61850 communication buses to secure digital substation communications. Security Filter authenticates and verifies the designated Ethernet packets transmitted between protection and control devices by appending a message authentication code based on symmetric cryptography, which is compliant with the new mechanisms described in IEC 61850 and suitable for embedded system implementation. A prototype development and testing on a low cost commodity embedded system has proved that Security Filter can fully protect digital substation communication against replay attacks with time delays within the range of the most stringent IEC 61580 performance class requirements. The paper also presents multimode Security Filter operation design, which provides a practical interoperable way to upgrade and secure legacy substations with minimal modification or interruption to the existing systems.