Authentication of GOOSE Messages under Timing Constraints in IEC 61850 Substations

Ghada Elbez, Hubert B. Keller, Veit Hagenmeyer · Electronic workshops in computing · 2019

For the future generation of energy systems, secure communication is a key component in ensuring a reliable and stable operation. The actual respective standard to define the communication network architectures for substation automation is the IEC 61850. In order to address the shortcomings of IEC 61850 w.r.t. communication security, IEC 62351-6 introduces respective recommendations. However, a thorough analysis of these recommendations shows that the authenticity and integrity of time-critical protocols such as Generic Object Oriented Substation Event (GOOSE) messages are not entirely covered by the proposed security measures. Therefore, in the present contribution, implementation of the RSASSA-PSS and HMAC-SHA256 authentication are investigated for the given context. Comparison with previous works is provided and obtained results show that the HMAC scheme has a better computational time than the recommended RSASSA-PSS. Thus, adjustment of the IEC 62351-6 considering the authentication of GOOSE messages shall be considered in the next edition of the standard.

Read the paper · More papers on PaperTik