Improvement Plan for cyber-security of DCS Control System of Nuclear Power Plants
Qiang Wang, Yuan Xiang, Daming Wang · 2024
This article proposes a cyber-security improvement plan for the DCS control system of nuclear power plants. Firstly, a brief introduction was given to the traditional architecture of DCS control systems of nuclear power plants. Secondly, the current cyber-security risks faced by DCS control systems in nuclear power plants were summarized, including identity authentication issues, access control issues, communication protocol issues, and data storage issues. Based on the cyber-security risks faced by the DCS control system in nuclear power plants, an improvement plan has been proposed for the DCS platform without increasing external cyber-security equipment. Firstly, regarding identity authentication, it is proposed that nuclear power plants have a very good physical protection that can effectively protect the operator station. However, for the engineer station, a dual factor identity authentication method needs to be added. Secondly, regarding access control, the shortcomings of role-based access control models were pointed out, and a location-based and task-based access control model was proposed. Then, in terms of security communication networks, the sensitive data range of nuclear power plants was analyzed, and communication was divided into internal communication and external communication. For internal communication, pre-stored keys can be used for encrypted communication. For external communication, certificates should be used for identity authentication, and then encrypted communication should be carried out. Finally, for data integrity, control system configurations can be saved through encryption. For passwords, they can be transmitted and saved through hash values.