基于商用密码算法的水利工控协议安全加固技术

    Security reinforcement technology for water conservancy industrial control protocol based on commercial cryptographic algorithm

    • 摘要: 针对水利工控系统面临的数据监听、数据篡改、数据伪造等安全风险,基于商用密码算法,开展数据安全传输技术研究,确保水利系统中工业以太网数据和现场总线数据传输的机密性、完整性和真实性。在分析当前水利工控系统面临的数据传输风险的基础上,针对工业以太网和现场总线2类通信协议进行安全加固设计,完成了密码模块设计,开展了多场景安全性测试与分析。经某水务基地水利一体化闸门现场测试,2类协议下各通讯主体间分别收发数据10 000次,其中工业以太网层共计成功收发数据10 000次,失败0次,加密前后平均延时0.25 ms;现场总线层共计成功收发数据9 977次,失败23次,加密前后平均延时269.28 ms。另外,开展了身份仿冒、数据窃取、数据篡改攻击测试。结果表明:该方法加解密成功率高,时延低,运行稳定,能够抵御外部攻击,在不影响业务运转前提下,可有效保障水利工控场景下的数据通信安全。

       

      Abstract: Given the security risks such as data monitoring, data tampering, and data forgery in water conservancy industrial control systems, research on data security transmission technology based on commercial cryptographic algorithms is carried out to ensure the confidentiality, integrity, and authenticity of industrial Ethernet data and fieldbus data transmission in water conservancy systems. We analyzed the data transmission risks faced by the current water conservancy industrial control system. Then we designed the security reinforcement for the 2 major types of communication protocols for industrial control, completed the design of the cryptographic module, and carried out multi-scenario security testing and analysis. Field tests were carried out at an integrated gate of a water conservancy base. Each communication device sent and received data 10 000 times in the two modes, of which the industrial Ethernet layer successfully sent and received data 10 000 times, with 0 failures. The average delay before and after encryption was 0.25 ms. And the fieldbus layer successfully sent and received data 9 977 times, with 23 failures. The average delay before and after encryption was 269.28 ms. In addition, identity impersonation, data theft, and data tampering attacks were tested. The experimental results show that the method has a high success rate of encryption and decryption, a low delay, a very stable operation, and can resist external attacks. It can effectively guarantee the data communication process security in the water conservancy industrial control scenario without affecting the business operation.

       

    /

    返回文章
    返回