• DocumentCode
    1670106
  • Title

    Resilient end-to-end message protection for large-scale cyber-physical system communications

  • Author

    Young-Jin Kim ; Kolesnikov, Vladimir ; Thottan, Marina

  • Author_Institution
    Bell Labs., Alcatel-Lucent, Murray Hill, NJ, USA
  • fYear
    2012
  • Firstpage
    193
  • Lastpage
    198
  • Abstract
    Essential features of cyber-physical systems such as Smart Grid are real-time analysis of high-resolution data, which a massive number of embedded devices periodically generate, and the effective and timely response to specific analytic results obtained from the data. Therefore, mission-critical data and control messages exchanged among machines in the cyber-physical systems must be strongly protected to prevent the infrastructures from becoming vulnerable. Specifically, the protection mechanism used must be scalable, secured from an end-to-end perspective, and key exposure resilient. Moreover, there may be privacy protection required among devices that generate data, e.g., smart metering. In this paper, we show that, for large-scale cyber-physical system communications, most well-known point-to-point security schemes such as IPsec [1], TLS [2], or SRTP [3] cannot meet the scalability, extensibility, and thinness requirements. By contrast conventional group security schemes which address the limitations of the point-to-point schemes have other limitations on aspects of privacy, key exposure resiliency, and key refreshment. To address the security requirements for cyber-physical systems, we design a resilient end-to-end message protection framework, REMP, exploiting the notion of the long-term key that is given on per node basis. This long term key is assigned during the node authentication phase and is subsequently used to derive encryption keys from a random number per-message sent. Compared with conventional schemes, REMP improves privacy, message authentication, and key exposure, and without compromising scalability and end-to-end security. The tradeoff is a slight increase in computation time for message decryption and message authentication.
  • Keywords
    data privacy; message authentication; public key cryptography; telecommunication security; IPsec; SRTP; control messages; embedded devices; encryption keys; group security schemes; high-resolution data real-time analysis; key exposure resiliency; key refreshment; large-scale cyber-physical system communications; message authentication; message decryption; mission-critical data; node authentication phase; point-to-point security schemes; privacy protection; resilient end-to-end message protection; smart grid; smart metering; Abstracts; Cryptography; Logic gates; Publishing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Smart Grid Communications (SmartGridComm), 2012 IEEE Third International Conference on
  • Conference_Location
    Tainan
  • Print_ISBN
    978-1-4673-0910-3
  • Electronic_ISBN
    978-1-4673-0909-7
  • Type

    conf

  • DOI
    10.1109/SmartGridComm.2012.6485982
  • Filename
    6485982