Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Science and Engineering, Wuhan University, Wuhan, China.
State Grid Electric Power Research Institute, Nanjing, China.
PLoS One. 2022 Mar 24;17(3):e0265937. doi: 10.1371/journal.pone.0265937. eCollection 2022.
As an important part of the second defense line of the power system, the Security and Stability Control System (SSCS) is of great significance to ensure the reliable operation of the power system. However, SSCS still lacks an effective security mechanism and is easily accessed by attackers, thus posing a threat to the stable and reliable operation of the power system. To tackle this issue, we propose a blockchain-based identity authentication scheme for Intelligent Electronic Devices (IEDs) of SSCS. We first propose an identity authentication system model for IEDs and design the deployment of consortium chain nodes on IEDs, with architectural characteristics of SSCS and the working scenario of IEDs taken into consideration. The consortium chain is used to store credentials required for authentication, ensuring that they are tamper-proof. We combine IP address, port number and physical ID, and propose the unique identification of IEDs, with a data structure designed for the identification. We also propose a lightweight identity authentication method based on renewable hash chains, with hash chains used as one-time authentication passwords, and introduce a renewal mechanism of hash chains. Further, the detailed processes of registration and authentication phase are designed. Finally, the security analysis shows that our identity authentication scheme can resist various attacks, and the feasibility of our scheme is verified by experiments.
作为电力系统第二道防线的重要组成部分,安全稳定控制系统(SSCS)对于确保电力系统的可靠运行具有重要意义。然而,SSCS 仍然缺乏有效的安全机制,容易被攻击者访问,从而对电力系统的稳定可靠运行构成威胁。针对这一问题,我们提出了一种基于区块链的 SSCS 智能电子设备(IED)身份认证方案。我们首先为 IED 提出了一个身份认证系统模型,并设计了联盟链节点在 IED 上的部署,考虑了 SSCS 的体系结构特点和 IED 的工作场景。联盟链用于存储身份验证所需的凭据,以确保其防篡改。我们结合 IP 地址、端口号和物理 ID,并提出了 IED 的唯一标识,设计了标识的数据结构。我们还提出了一种基于可再生哈希链的轻量级身份认证方法,使用哈希链作为一次性认证密码,并引入了哈希链的更新机制。进一步设计了注册和认证阶段的详细流程。最后,安全性分析表明,我们的身份认证方案可以抵御各种攻击,实验验证了我们方案的可行性。