Critical energy infrastructures increasingly rely on information and communication technology for monitoring and control, which leads to new challenges with regard to cybersecurity. Recent advancements in this domain, including attribute-based access control (ABAC), have not been sufficiently addressed by established standards such as IEC 61850 and IEC 62351. To address this issue, we propose a novel real-time server-aided attribute-based authorization and access control for time-critical applications called RTS-ABAC. We tailor RTS-ABAC to the strict timing constraints inherent to the protocols employed in substation automation systems (SAS). We extend the concept of conventional ABAC by introducing real-time attributes and time-dependent policy evaluation and enforcement. To safeguard the authenticity, integrity, and non-repudiation of SAS communication and protect an SAS against domain-typical adversarial attacks, RTS-ABAC employs mandatory authentication, authorization, and access control for any type of SAS communication using a bump-in-the-wire (BITW) approach. To evaluate RTS-ABAC, we conduct a testbed-based performance analysis and a laboratory-based demonstration of applicability. We demonstrate the applicability using intelligent electronic devices, merging units, and I/O boxes communicating via the GOOSE and SV protocol. The results show that RTS-ABAC is able to secure low-latency communication between SAS devices, as up to 99.82 % of exchanged packets achieve a round-trip time below 6 ms. Moreover, the results of the evaluation indicate that RTS-ABAC is a viable solution to enhance the cybersecurity not only in a newly constructed SAS but also via retrofitting of existing substations.
翻译:关键能源基础设施日益依赖信息与通信技术进行监控和控制,这带来了新的网络安全挑战。尽管该领域近期取得了进展(包括基于属性的访问控制),但IEC 61850和IEC 62351等现有标准尚未充分解决这些问题。针对这一不足,我们提出了一种新颖的实时服务器辅助属性基授权与访问控制方案RTS-ABAC,适用于时间关键型应用。我们针对变电站自动化系统(SAS)所用协议中固有的严格时序约束,对RTS-ABAC进行了定制化设计。通过引入实时属性和时间相关策略评估与执行,我们扩展了传统ABAC的概念。为保障SAS通信的真实性、完整性和不可否认性,并保护SAS免受领域典型对抗攻击,RTS-ABAC采用线缆中继(BITW)方法,对任何类型的SAS通信实施强制认证、授权和访问控制。为评估RTS-ABAC,我们开展了基于测试台的性能分析和基于实验室的适用性演示。我们使用智能电子设备、合并单元和输入/输出盒,通过GOOSE和SV协议进行通信,演示了其适用性。结果表明,RTS-ABAC能够保障SAS设备间的低延迟通信,高达99.82%的交换数据包往返时间低于6毫秒。此外,评估结果指出,RTS-ABAC不仅适用于新建SAS,还可通过改造现有变电站来增强其网络安全。