Caching-based Multicast Message Authentication in Time-critical Industrial Control Systems

被引:7
|
作者
Tefek, Utku [1 ]
Esiner, Ertem [1 ]
Mashima, Daisuke [1 ]
Chen, Binbin [2 ]
Hu, Yih-Chun [3 ]
机构
[1] Adv Digital Sci Ctr, Singapore, Singapore
[2] Singapore Univ Technol & Design, Singapore, Singapore
[3] Univ Illinois, Urbana, IL USA
基金
新加坡国家研究基金会;
关键词
industrial control system; IEC; 61850; message authentication; multicast; SIGNATURES; SCHEME;
D O I
10.1109/INFOCOM48880.2022.9796767
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Attacks against industrial control systems (ICSs) often exploit the insufficiency of authentication mechanisms. Verifying whether the received messages are intact and issued by legitimate sources can prevent malicious data/command injection by illegitimate or compromised devices. However, the key challenge is to introduce message authentication for various ICS communication models, including multicast or broadcast, with a messaging rate that can be as high as thousands of messages per second, within very stringent latency constraints. For example, certain commands for protection in smart grids must be delivered within 2 milliseconds, ruling out public-key cryptography. This paper proposes two lightweight message authentication schemes, named CMA and its multicast variant CMMA, that perform precomputation and caching to authenticate future messages. With minimal precomputation and communication overhead, C(M)MA eliminates all cryptographic operations for the source after the message is given, and all expensive cryptographic operations for the destinations after the message is received. C(M)MA considers the urgency profile (or likelihood) of a set of future messages for even faster verification of the most time-critical (or likely) messages. We demonstrate the feasibility of C(M)MA in an ICS setting based on a substation automation system in smart grids.
引用
收藏
页码:1039 / 1048
页数:10
相关论文
共 50 条
  • [1] Message-Based MAC Accelerator for Time-Critical Industrial Communication
    Wulf, Armin
    Naumann, Tobias
    Endemann, Wolfgang
    Kays, Ruediger
    [J]. 2017 XXVI INTERNATIONAL CONFERENCE ON INFORMATION, COMMUNICATION AND AUTOMATION TECHNOLOGIES (ICAT), 2017,
  • [2] Time Valid One-Time Signature for Time-Critical Multicast Data Authentication
    Wang, Qiyan
    Khurana, Himanshu
    Huang, Ying
    Nahrstedt, Klara
    [J]. IEEE INFOCOM 2009 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS, VOLS 1-5, 2009, : 1233 - 1241
  • [3] Efficiency optimisation signature scheme for time-critical multicast data origin authentication
    Wang, Yichuan
    Ma, Jianfeng
    Lu, Xiang
    Lu, Di
    Zhang, Liumei
    [J]. INTERNATIONAL JOURNAL OF GRID AND UTILITY COMPUTING, 2016, 7 (01) : 1 - 11
  • [4] Towards the control of time-critical systems
    Bonhomme, P
    Aygalinc, P
    Calvez, S
    [J]. PROCEEDINGS OF THE 2001 IEEE INTERNATIONAL CONFERENCE ON CONTROL APPLICATIONS (CCA'01), 2001, : 1184 - 1189
  • [5] Robust control for time-critical systems
    Bonhomme, P
    Aygalinc, P
    Calvez, S
    [J]. ETFA 2001: 8TH IEEE INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION, VOL 1, PROCEEDINGS, 2001, : 537 - 546
  • [6] Message Authentication and Provenance Verification for Industrial Control Systems
    Esiner, Ertem
    Tefek, Utku
    Mashima, Daisuke
    Chen, Binbin
    Kalbarczyk, Zbigniew
    Nicol, David M.
    [J]. ACM TRANSACTIONS ON CYBER-PHYSICAL SYSTEMS, 2023, 7 (04)
  • [7] Slingshot: Time-critical multicast for clustered applications
    Balakrishnan, M
    Pleisch, S
    Birman, K
    [J]. FOURTH IEEE INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS, PROCEEDINGS, 2005, : 205 - 212
  • [8] SPECIFYING MESSAGE-PASSING AND TIME-CRITICAL SYSTEMS WITH TEMPORAL LOGIC
    KOYMANS, R
    [J]. LECTURE NOTES IN COMPUTER SCIENCE, 1992, 651 : R3 - +
  • [9] Time-Critical Systems Design
    Henkel, Jorg
    [J]. IEEE DESIGN & TEST, 2018, 35 (02) : 4 - 4
  • [10] Reliable Communication Framework for Time-Critical Wireless Industrial Control Networks
    Karimireddy, Thanmayee
    Zhang, Sijing
    [J]. 2017 NINTH INTERNATIONAL CONFERENCE ON UBIQUITOUS AND FUTURE NETWORKS (ICUFN 2017), 2017, : 367 - 372