• DocumentCode
    825691
  • Title

    Security for Industrial Communication Systems

  • Author

    Dzung, Dacfey ; Naedele, Martin ; Von Hoff, Thomas P. ; Crevatin, Mario

  • Author_Institution
    ABB Corp. Res., Baden, Switzerland
  • Volume
    93
  • Issue
    6
  • fYear
    2005
  • fDate
    6/1/2005 12:00:00 AM
  • Firstpage
    1152
  • Lastpage
    1177
  • Abstract
    Modern industrial communication networks are increasingly based on open protocols and platforms that are also used in the office IT and Internet environment. This reuse facilitates development and deployment of highly connected systems, but also makes the communication system vulnerable to electronic attacks. This paper gives an overview of IT security issues in industrial automation systems which are based on open communication systems. First, security objectives, electronic attack methods, and the available countermeasures for general IT systems are described. General security objectives and best practices are listed. Particularly for the TCP/IP protocol suite, a wide range of cryptography-based secure communication protocols is available. The paper describes their principles and scope of application. Next, we focus on industrial communication systems, which have a number of security-relevant characteristics distinct from the office IT systems. Confidentiality of transmitted data may not be required; however, data and user authentication, as well as access control are crucial for the mission critical and safety critical operation of the automation system. As a result, modern industrial automation systems, if they include security measures at all, emphasize various forms of access control. The paper describes the status of relevant specifications and implementations for a number of standardized automation protocols. Finally, we illustrate the application of security concepts and tools by brief case studies describing security issues in the configuration and operation of substations, plants, or for remote access.
  • Keywords
    Internet; cryptography; message authentication; telecommunication security; transport protocols; IT security; Internet; TCP-IP protocol; access control; cryptography; data authentication; electronic attacks; embedded system; industrial automation system; industrial communication network; industrial communication system; mission critical operation; open communication system; open protocols; remote access; safety critical operation; secure communication protocols; security protocol; security standard; standardized automation protocol; user authentication; Access control; Access protocols; Automation; Communication industry; Communication networks; Communication system security; Cryptographic protocols; Electrical equipment industry; Electronic countermeasures; IP networks; Cryptography; embedded systems; industrial automation; industrial communication systems; remote access; security objectives; security protocols; security standards;
  • fLanguage
    English
  • Journal_Title
    Proceedings of the IEEE
  • Publisher
    ieee
  • ISSN
    0018-9219
  • Type

    jour

  • DOI
    10.1109/JPROC.2005.849714
  • Filename
    1435744