{"title":"面向智能配电系统运行的通信安全架构","authors":"T. Mander, H. Cheung, A. Hamlyn, R. Cheung","doi":"10.1109/EPC.2007.4520367","DOIUrl":null,"url":null,"abstract":"This paper proposes a communication cybersecurity architecture for smart distribution system operations using distributed network protocol (DNP3). The focus is on providing cybersecurity for residential load-management devices that are networked for access by the utility and their consumers. The proposed architecture utilizes DNP3 to produce a disjoint protocol between strictly-regulated utility devices and devices accessible by the utility and consumers. The disjoint protocol limits the effectiveness of attacks originated from the consumer TCP/IP access to a device into the utility network. Since DNP3 does not provide sufficient security, security enhancements to DNP3 are proposed using data object security and a security layer. The data object security provides data access rules to a device, preventing unauthorized manipulation of device operations and data. The security layer provides confidentiality through encryption between devices for consumer personal privacy and to prevent cyber-attackers from identifying potential utility targets.","PeriodicalId":196861,"journal":{"name":"2007 IEEE Canada Electrical Power Conference","volume":"73 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2007-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":"{\"title\":\"Communication Security Architecture for Smart Distribution System Operations\",\"authors\":\"T. Mander, H. Cheung, A. Hamlyn, R. Cheung\",\"doi\":\"10.1109/EPC.2007.4520367\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"This paper proposes a communication cybersecurity architecture for smart distribution system operations using distributed network protocol (DNP3). The focus is on providing cybersecurity for residential load-management devices that are networked for access by the utility and their consumers. The proposed architecture utilizes DNP3 to produce a disjoint protocol between strictly-regulated utility devices and devices accessible by the utility and consumers. The disjoint protocol limits the effectiveness of attacks originated from the consumer TCP/IP access to a device into the utility network. Since DNP3 does not provide sufficient security, security enhancements to DNP3 are proposed using data object security and a security layer. The data object security provides data access rules to a device, preventing unauthorized manipulation of device operations and data. The security layer provides confidentiality through encryption between devices for consumer personal privacy and to prevent cyber-attackers from identifying potential utility targets.\",\"PeriodicalId\":196861,\"journal\":{\"name\":\"2007 IEEE Canada Electrical Power Conference\",\"volume\":\"73 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2007-10-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"4\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2007 IEEE Canada Electrical Power Conference\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/EPC.2007.4520367\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2007 IEEE Canada Electrical Power Conference","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/EPC.2007.4520367","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Communication Security Architecture for Smart Distribution System Operations
This paper proposes a communication cybersecurity architecture for smart distribution system operations using distributed network protocol (DNP3). The focus is on providing cybersecurity for residential load-management devices that are networked for access by the utility and their consumers. The proposed architecture utilizes DNP3 to produce a disjoint protocol between strictly-regulated utility devices and devices accessible by the utility and consumers. The disjoint protocol limits the effectiveness of attacks originated from the consumer TCP/IP access to a device into the utility network. Since DNP3 does not provide sufficient security, security enhancements to DNP3 are proposed using data object security and a security layer. The data object security provides data access rules to a device, preventing unauthorized manipulation of device operations and data. The security layer provides confidentiality through encryption between devices for consumer personal privacy and to prevent cyber-attackers from identifying potential utility targets.