Shin SooHyun, Park MyungJoo, Kim TaeWan, Yang HyoSik
Department of Computer Science and Engineering, Sejong University, 209, Neungdong-ro, Gwangjin-gu, Seoul 05006, Republic of Korea.
Department of Electrical Engineering, Myongji University, Yongin 17058, Republic of Korea.
Sensors (Basel). 2024 Sep 16;24(18):6000. doi: 10.3390/s24186000.
In traditional power grids, the unidirectional flow of energy and information has led to a decrease in efficiency. To address this issue, the concept of microgrids with bidirectional flow and independent power sources has been introduced. The components of a microgrid utilize various IoT protocols such as OPC-UA, MQTT, and DDS to implement bidirectional communication, enabling seamless network communication among different elements within the microgrid. Technological innovation, however, has simultaneously given rise to security issues in the communication system of microgrids. The use of IoT protocols creates vulnerabilities that malicious hackers may exploit to eavesdrop on data or attempt unauthorized control of microgrid devices. Therefore, monitoring and controlling security vulnerabilities is essential to prevent intrusion threats and enhance cyber resilience in the stable and efficient operation of microgrid systems. In this study, we propose an RBAC-based security approach on top of DDS protocols in microgrid systems. The proposed approach allocates roles to users or devices and grants various permissions for access control. DDS subscribers request access to topics and publishers request access to evaluations from the role repository using XACML. The overall implementation model is designed for the publisher to receive XACML transmitted from the repository and perform policy decision making and enforcement. By applying these methods, security vulnerabilities in communication between IoT devices can be reduced, and cyber resilience can be enhanced.
在传统电网中,能量和信息的单向流动导致了效率的降低。为了解决这个问题,引入了具有双向流动和独立电源的微电网概念。微电网的组件利用各种物联网协议,如OPC-UA、MQTT和DDS来实现双向通信,从而使微电网内不同元件之间能够进行无缝网络通信。然而,技术创新同时也给微电网通信系统带来了安全问题。物联网协议的使用产生了漏洞,恶意黑客可能利用这些漏洞来窃听数据或试图对微电网设备进行未经授权的控制。因此,监测和控制安全漏洞对于防止入侵威胁以及在微电网系统的稳定高效运行中增强网络弹性至关重要。在本研究中,我们在微电网系统的DDS协议之上提出了一种基于角色的访问控制(RBAC)安全方法。所提出的方法为用户或设备分配角色,并授予各种访问控制权限。DDS订阅者请求访问主题,发布者使用可扩展访问控制标记语言(XACML)从角色存储库请求访问评估。总体实现模型设计为发布者接收从存储库传输的XACML并执行策略决策和实施。通过应用这些方法,可以减少物联网设备之间通信中的安全漏洞,并增强网络弹性。