Yang Yu-Sheng, Lee Shih-Hsiung, Chen Wei-Che, Yang Chu-Sing, Huang Yuen-Min, Hou Ting-Wei
Department of Engineering Science, National Cheng Kung University, Tainan City 701, Taiwan.
Department of Intelligent Commerce, National Kaohsiung University of Science and Technology, Kaohsiung City 824, Taiwan.
Sensors (Basel). 2021 Apr 11;21(8):2685. doi: 10.3390/s21082685.
The vigorous development of the Industrial Internet of Things brings the advanced connection function of the new generation of industrial automation and control systems. The Supervisory Control and Data Acquisition (SCADA) network is converted into an open and highly interconnected network, where the equipment connections between industrial electronic devices are integrated with a SCADA system through a Modbus protocol. As SCADA and Modbus are easily used for control and monitoring, the interconnection and operational efficiency between systems are highly improved; however, such connectivity inevitably exposes the system to the open network environment. There are many network security threats and vulnerabilities in a SCADA network system. Especially in the era of the Industrial Internet of Things, any security vulnerability of an industrial system may cause serious property losses. Therefore, this paper proposes an encryption and verification mechanism based on the trusted token authentication service and Transport Layer Security (TLS) protocol to prevent attackers from physical attacks. Experimentally, this paper deployed and verified the system in an actual field of energy management system. According to the experimental results, the security defense architecture proposed in this paper can effectively improve security and is compatible with the actual field system.
工业物联网的蓬勃发展带来了新一代工业自动化与控制系统的先进连接功能。监控与数据采集(SCADA)网络转变为一个开放且高度互联的网络,其中工业电子设备之间的设备连接通过Modbus协议与SCADA系统集成。由于SCADA和Modbus易于用于控制和监测,系统之间的互联性和运行效率得到了极大提高;然而,这种连接性不可避免地使系统暴露于开放的网络环境中。SCADA网络系统存在许多网络安全威胁和漏洞。特别是在工业物联网时代,工业系统的任何安全漏洞都可能导致严重的财产损失。因此,本文提出了一种基于可信令牌认证服务和传输层安全(TLS)协议的加密与验证机制,以防止攻击者进行物理攻击。通过实验,本文在能源管理系统的实际领域中部署并验证了该系统。根据实验结果,本文提出的安全防御架构能够有效提高安全性,并且与实际领域系统兼容。