| 研究生: |
何宜軒 Ho, Yi-Hsuan |
|---|---|
| 論文名稱: |
適用於智慧電網之可鑑別群體導向安全廣播與命令鑑別協定 Authenticated Group-Oriented Secure Broadcasting and Command Authentication Protocols for Smart Grids |
| 指導教授: |
左瑞麟
Tso, Ray-Lin 許建隆 Hsu, Chien-Lung |
| 口試委員: |
黃正達
Huang, Cheng-Ta 高大宇 Kao, Da-Yu 許見章 Hsu, Chien-Chang |
| 學位類別: |
碩士
Master |
| 系所名稱: |
資訊學院 - 資訊安全碩士學位學程 Master Program in Information Security |
| 論文出版年: | 2026 |
| 畢業學年度: | 115 |
| 語文別: | 英文 |
| 論文頁數: | 118 |
| 中文關鍵詞: | 智慧電網 、IEC 62351-9:2023 、安全廣播 、命令鑑別 、雜湊鏈 、Merkle Tree |
| 外文關鍵詞: | Smart Grid, IEC 62351-9:2023, Secure Broadcasting, Command Authentication, Hash Chain, Merkle Tree |
| 相關次數: | 點閱:45 下載:0 |
| 分享至: |
| 查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報 |
隨著智慧電網與電力通訊系統逐漸朝向數位化、自動化及分散式控制架構發展,控制中心與終端設備之間需進行大量即時且安全之資料交換與控制命令傳遞。為強化電力系統通訊安全,IEC 62351-9:2023 針對電力系統設備之金鑰管理提出相關規範。然而,在智慧電網環境中,若僅依賴傳統逐一金鑰分發方式,或長期使用固定共享金鑰進行通訊與命令驗證,可能導致群組金鑰分發效率不足、通訊負擔增加,以及控制命令遭偽造、竄改或重送等安全問題。因此,如何提升群組金鑰分發效率,並強化控制命令之持續驗證能力,成為智慧電網通訊安全中重要的研究議題。
本研究基於 IEC 62351-9:2023 之群體金鑰管理概念與智慧電網應用需求,提出一套適用於智慧電網之可鑑別群體導向安全廣播機制與群組導向命令鑑別協定,並完成下列研究成果:(1) 設計可鑑別群體導向安全廣播機制,透過安全廣播方式進行群組金鑰分發,使合法群組成員能夠安全取得群組金鑰,以降低逐一傳送金鑰所造成之通訊負擔,並提升群組金鑰管理之效率;(2) 提出群組導向命令鑑別協定,結合雜湊鏈與 Merkle Tree 結構,針對不同控制命令建立對應之雜湊鏈,並將各命令鏈值整合至Merkle Tree 中,以根值作為接收端後續驗證依據,藉此強化控制命令之來源合法性、命令順序關聯性及資料完整性。
Driven by advances in smart grids and power communication systems, power systems are moving toward digitalization, automation, and distributed control architectures. As a result, control centers and terminal devices need to exchange real-time data and securely transmit control commands. To strengthen power system communication security, IEC 62351-9:2023 specifies key management requirements for power system equipment. However, in smart grid environments, conventional one-to-one key distribution may reduce group key distribution efficiency and increase communication overhead. The long-term use of fixed shared keys for communication and command verification may also lead to command forgery, tampering, and replay attacks. Therefore, improving group key distribution efficiency and strengthening continuous command verification have become important research issues in smart grid communication security.
Based on the group key management concept of IEC 62351-9:2023 and the application requirements of smart grids, this study proposes an authenticated group-oriented secure broadcasting mechanism and a group-oriented command authentication protocol. The main contributions are as follows: (1) an authenticated group-oriented secure broadcasting mechanism is designed to distribute group keys to legitimate members through secure broadcasting, thereby reducing one-to-one key transmission overhead and improving group key management efficiency; and (2) a group-oriented command authentication protocol is proposed by integrating hash chains and a Merkle Tree structure to support continuous command verification, thereby enhancing command source legitimacy, command sequence correlation, and data integrity.
摘要 2
Abstract 3
Chapter 1 Introduction 8
1.1 Research Background and Motivation 8
1.2 Research Problems and Objectives 11
1.3 Organization 13
Chapter 2 Related Works 14
2.1 IEC 62351 15
2.2 Trusted Data Management Scheme in Edge Computing 22
2.3 Secret-Sharing-Based Broadcasting Schemes 25
2.4 Liao et al.’s Entity Authentication Scheme in the Modbus Protocol 26
2.5 Security Analysis of Liao et al.’s Scheme 29
Chapter 3 Preliminary 31
3.1 Elliptic Curve Cryptography 31
3.2 Bilinear Pairing 33
3.3 One-Way Hash Function 33
3.4 Merkle Tree 34
Chapter 4 Authenticated Group-Oriented Secure Broadcasting Mechanism for Smart Grids 37
4.1 System Architecture Description 37
4.2 System Phase Description 38
4.3 Proposed Cryptographic Protocol 43
4.4 Discussion 54
Chapter 5 Group-Oriented Command Authentication Protocol for Smart Grids 56
5.1 System Architecture Description 56
5.2 System Phase Description 57
5.3 Proposed Cryptographic Protocol 62
5.4 Example of the Proposed Scheme 67
5.5 Discussion 82
Chapter 6 Security Analysis 85
6.1 Formal Security Verification of Method 1: Authenticated Group-Oriented Secure Broadcasting Mechanism for Smart Grids 86
6.2 Formal Security Verification of Method 2: Group-Oriented Command Authentication Protocol for Smart Grids 90
6.3 Summary of Security Feature Comparison and Discussion 93
Chapter 7 Conclusions 105
Reference 106
Appendix A. ProVerif Code for Method 1 111
Appendix B. AVISPA Code for Method 1 113
Appendix C. ProVerif Code for Method 2 115
Appendix D. AVISPA Code for Method 2 116
[A05] A.Armando et al., "The AVISPA tool for the automated validation of internet security protocols and applications", in Lecture Notes in Computer Science, 2005, vol. 3576, pp. 281-285.
[AN18] D. Abbasinezhad-Mood and M. Nikooghadam, "Design and hardware implementation of a security-enhanced elliptic curve cryptography based lightweight authentication scheme for smart grid communications", Future Generation Computer Systems, vol. 84, pp. 47-57, 2018.
[B01] B. Blanchet, "An Efficient Cryptographic Protocol Verifier Based on Prolog Rules", in Proceedings of the 14th IEEE Computer Se-curity Foundations Workshop (CSFW), pp. 82-96, 2001.
[B91] S. Berkovits, "How To Broadcast A Secret", Advances in Cryp-tology-EUROCRYPT’91, LNCS 547, pp. 535-541, 1991
[BF03] D.Boneh and M.Franklin, "Identity-based encryption from the weil pairing", SIAM Journal on Computing, vol. 32, no. 3, pp. 586-615, 2003.
[CYXLGZZHZYWH23] S. Chai, H. Yin, B. Xing, Z. Li, Y. Guo, D. Zhang, X. Zhang, D. He, J. Zhang, X. Yu, W. Wang, and X. Huang, "Provably Secure and Lightweight Authentication Key Agreement Scheme for Smart Meters", IEEE Transactions on Smart Grid, vol. 14, no. 5, 3816-3827, 2023.
[GKKRG20] S. Garg, K. Kaur, G. Kaddoum, J. J. P. C. Rodrigues, and M. Gui-zani, "Secure and lightweight authentication scheme for smart metering infrastructure in smart grid", IEEE Transactions on In-dustrial Informatics, vol. 16, no. 5, pp. 3548-3557, 2020.
[HCZXLZC23] S. Hu, Y. Chen, Y. Zheng, B. Xing, Y. Li, L. Zhang, and L. Chen, "Provably Secure ECC-Based Authentication and Key Agreement Scheme for Advanced Metering Infrastructure in the Smart Grid", IEEE Transactions on Industrial Informatics, vol. 19, no. 4, 5985-5994, 2023.
[IEC23] International Electrotechnical Commission, IEC 62351-9:2023, Power systems management and associated information exchange - Data and communications security - Part 9: Cyber security key management for power system equipment, 2023.
[IEC26] International Electrotechnical Commission, IEC 62351:2026 SER, Power systems management and associated information exchange - Data and communications security - ALL PARTS, 2026.
[IETF11] B. Weis, S. Rowles, and T. Hardjono, "The Group Domain of In-terpretation", RFC 6407, Internet Engineering Task Force (IETF), Oct. 2011.
[IETF98a] D. Harkins and D. Carrel, "The Internet Key Exchange (IKE)", RFC 2409, Internet Engineering Task Force (IETF), Nov. 1998.
[IETF98b] D. Maughan, M. Schertler, M. Schneider, and J. Turner, "Internet Security Association and Key Management Protocol (ISAKMP)", RFC 2408, Internet Engineering Task Force (IETF), Nov. 1998.
[K87] Koblitz, N., "Elliptic Curve Cryptosystems", Mathematics of Computation, Vol. 48, No.177, pp. 203-209, 1987.
[KGSMH19] P. Kumar, A. Gurtov, M. Sain, A. Martin, and H. P. Ha, "Light-weight authentication and key agreement for smart metering in smart energy networks", IEEE Transactions on Smart Grid, vol. 10, no. 4, pp. 4349-4359, 2019.
[KRYKKD24] O. Kuznetsov, A. Rusnak, A. Yezhov, K. Kuznetsova, D. Kanonik, and O. Domin, "Merkle trees in blockchain: A Study of collision probability and security implications", Internet of Things, vol. 26, 2024.
[KS24] D. Kumari and K. Singh, "Lightweight secure authentication and key agreement technique for smart grid", Peer-to-Peer Network-ing and Applications, 17, 451-478, 2024.
[LCLC08] G. Y. Liao, Y. J. Chen, W. C. Lu, & T. C. Cheng, "Toward authen-ticating the master in the modbus protocol," IEEE Transactions on Power Delivery, 23(4), 2628-2629, 2008.
[LGSWLH26] S. Li, H. Guo, H. Song, Y. Wu, J. Liu, and Y. Han, "A re-source-efficient authentication and key agreement protocol for smart grid", Cybersecurity, 9, 50, 2026.
[M79] R. C. Merkle, "Secrecy, authentication, and public key systems", Stanford University, 1979.
[M86] V. S. Miller, "Use of Elliptic Curves in Cryptography", Advances in Cryptology — CRYPTO ’85 Proceedings, Vol. 218, pp. 417-426, 1986.
[M89] R. C. Merkle, "One Way Hash Functions and DES", Advances in Cryptology — CRYPTO ’89, vol. 435, pp. 428-446, 1989.
[MCNKLS18] K. Mahmood, S. A. Chaudhry, H. Naqvi, S. Kumari, X. Li, and A. K. Sangaiah, "An elliptic curve cryptography based lightweight authentication scheme for smart grid communication", Future Generation Computer Systems, vol. 81, pp. 557-565, 2018.
[MWDHGW19] Z. Ma, X. Wang, D. K. Jain, H. Khan, H. Gao, and Z. Wang, "A Blockchain Based Trusted Data Management Scheme in Edge Computing", IEEE Transactions on Industrial Informatics, Vol. 16, No. 3, pp. 2013-2021, 2019.
[P12] Raphael C.-W. Phan, "Authenticated Modbus Protocol for Critical Infrastructure Protection", IEEE Transactions on Power Delivery, 27(3), 1687-1689, 2012.
[RBGBKMC24] S. Rostampour, N. Bagheri, B. Ghavami, Y. Bendavid, S. Kumari, H. Martin, and C. Camara, "Using a privacy-enhanced authentica-tion process to secure IoT-based smart grid infrastructures", The Journal of Supercomputing, 80, 1668-1693, 2024.
[Reuters24] L. Kearney, "US electric grid growing more vulnerable to cyberattacks, regulator says", Reuters, 2024.
[TAKAE22] M. Tanveer, M. Ahmad, H. S. Khalifa, A. Alkhayyat, and A. A. A. El-Latif, "A new anonymous authentication framework for secure smart grids applications", Journal of Information Security and Applications, 71, 103336, 2022.
[TKKNC22] M. Tanveer, A. U. Khan, N. Kumar, A. Naushad, and S. A. Chaudhry, "A Robust Access Control Protocol for the Smart Grid Systems", IEEE Internet of Things Journal, vol. 9, no. 9, 6855-6865, 2022.
[V06] L.Viganò, "Automated Security Protocol Analysis With the AVISPA Tool", Electronic Notes in Theoretical Computer Science, 2006.
全文公開日期 2031/08/03