Conference item
Secure Authentication in the Grid: A Formal Analysis of DNP3: SAv5
- Abstract:
- Most of the world's power grids are controlled remotely. Their control messages are sent over potentially insecure channels, driving the need for an authentication mechanism. The main communication mechanism for power grids and other utilities is defined by an IEEE standard, referred to as DNP3; this includes the Secure Authentication v5 (SAv5) protocol, which aims to ensure that messages are authenticated. We provide the first security analysis of the complete DNP3: SAv5 protocol. Previous work has considered the message-passing sub-protocol of SAv5 in isolation, and considered some aspects of the intended security properties. In contrast, we formally model and analyse the complex composition of the protocol's three sub-protocols. In doing so, we consider the full state machine, and the possibility of cross-protocol attacks. Furthermore, we model fine-grained security properties that closely match the standard's intended security properties. For our analysis, we leverage the TAMARIN prover for the symbolic analysis of security protocols. Our analysis shows that the core DNP3: SAv5 design meets its intended security properties. Notably, we show that a previously reported attack does not apply to the standard. However, our analysis also leads to several concrete recommendations for improving future versions of the standard.
- Publication status:
- Published
- Peer review status:
- Peer reviewed
Actions
Access Document
- Files:
-
-
(Preview, Accepted manuscript, pdf, 346.8KB, Terms of use)
-
- Publisher copy:
- 10.1007/978-3-319-66402-6_23
Authors
- Publisher:
- Springer Verlag
- Host title:
- ESORICS'17: 22nd European Symposium on Research in Computer Security
- Journal:
- ESORICS More from this journal
- Volume:
- 10492
- Pages:
- 389-407
- Series:
- Lecture Notes in Computer Science
- Publication date:
- 2017-08-12
- Acceptance date:
- 2017-06-17
- Event start date:
- 2017-09-11
- Event end date:
- 2017-09-13
- DOI:
- ISBN:
- 9783319664019
- Pubs id:
-
pubs:701963
- UUID:
-
uuid:fcc89abf-4451-47ea-babe-565edfc34f13
- Local pid:
-
pubs:701963
- Source identifiers:
-
701963
- Deposit date:
-
2017-06-26
Terms of use
- Copyright holder:
- Springer
- Copyright date:
- 2017
- Notes:
- © Springer International Publishing AG 2017. This article was presented at ESORICS'17: 22nd European Symposium on Research in Computer Security (11-15 September 2017: Oslo, Norway). This is the accepted manuscript version of the article. The final version is available online from Springer at: [10.1007/978-3-319-66402-6_23]
If you are the owner of this record, you can report an update to it here: Report update to this record