IEC 62351-3:2023
Power systems management and associated information exchange - Data and communications security - Part 3: Communication network and system security - Profiles including TCP/IP
Power systems management and associated information exchange - Data and communications security - Part 3: Communication network and system security - Profiles including TCP/IP
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 103
- Дата публикации:
- 6 июня 2023 г.
- Издание:
- IEC IS 62351 edition 2 version 1
- ICS:
- 33.200
IEC 62351-3:2023 specifies how to provide confidentiality, integrity protection, and message level authentication for protocols that make use of TCP/IP as a message transport layer and utilize Transport Layer Security when cyber-security is required. This may relate to SCADA and telecontrol protocols, but also to additional protocols if they meet the requirements in this document. IEC 62351-3 specifies how to secure TCP/IP-based protocols through constraints on the specification of the messages, procedures, and algorithms of Transport Layer Security (TLS) (TLSv1.2 defined in RFC 5246, TLSv1.3 defined in RFC 8446). In the specific clauses, there will be subclauses to note the differences and commonalities in the application depending on the target TLS version. The use and specification of intervening external security devices (e.g., "bump-in-the-wire") are considered out-of-scope. In contrast to previous editions of this document, this edition is self-contained in terms of completely defining a profile of TLS. Hence, it can be applied directly, without the need to specify further TLS parameters, except the port number, over which the communication will be performed. Therefore, this part can be directly utilized from a referencing standard and can be combined with further security measures on other layers. Providing the profiling of TLS without the need for further specifying TLS parameters allows declaring conformity to the described functionality without the need to involve further IEC 62351 documents. This document is intended to be referenced as a normative part of other IEC standards that have the need for providing security for their TCP/IP-based protocol exchanges under similar boundary conditions. However, it is up to the individual protocol security initiatives to decide if this document is to be referenced. The document also defines security events for specific conditions, which support error handling, security audit trails, intrusion detection, and conformance testing. Any action of an organization in response to events to an error condition described in this document are beyond the scope of this document and are expected to be defined by the organization’s security policy. This document reflects the security requirements of the IEC power systems management protocols. Should other standards bring forward new requirements, this document may need to be revised. This second edition cancels and replaces the first edition published in 2014, Amendment 1:2018 and Amendment 2:2020. This edition constitutes a technical revision. This edition includes the following significant technical changes with respect to the previous edition: a) Inclusion of the TLSv1.2 related parameter required in IEC 62351-3 Ed.1.2 to be specified by the referencing standard. This comprises the following parameter: • Mandatory TLSv1.2 cipher suites to be supported. • Specification of session resumption parameters. • Specification of session renegotiation parameters. • Revocation handling using CRL and OCSP. • Handling of security events. b) Inclusion of a TLSv1.3 profile to be applicable for the power system domain in a similar way as for TLSv1.2 session.
Abstract
Overview
IEC 62351-3:2023 is an international standard developed by the International Electrotechnical Commission (IEC) that focuses on data and communications security for power systems management. This document specifically addresses communication network and system security profiles, with a strong emphasis on protocols utilizing TCP/IP as the transport layer. It provides security guidelines incorporating Transport Layer Security (TLS) versions 1.2 and 1.3 to ensure confidentiality, integrity, and message-level authentication, crucial for securing power system control and monitoring networks such as SCADA and telecontrol.
This edition, published in 2023, is a significant technical revision that profiles TLS protocols with clearly defined cipher suites, session management, and certificate validation processes. Unlike previous versions, IEC 62351-3:2023 is self-contained and can be directly referenced by other IEC standards to enforce TCP/IP-based protocol security without additional parameter specifications.
Key Topics
-
TLS Profiles for Power Systems
Defines constraints and profiles for TLS 1.2 and TLS 1.3 tailored to power system communication, including mandatory cipher suites and secure handshake mechanisms. -
Security Requirements
Addresses confidentiality, integrity protection, and message authentication for TCP/IP-transported data to mitigate cyber threats in critical infrastructure systems. -
Certificate Handling
Describes certificate support including trust anchor management, size constraints, exchange procedures, and validation techniques such as Certificate Revocation List (CRL) and Online Certificate Status Protocol (OCSP). -
Session Management
Covers session resumption, renegotiation, and updates, ensuring secure and efficient reuse of TLS sessions. -
Security Event Logging
Specifies security events related to TLS handshakes and certificate handling to support auditing, intrusion detection, and conformance verification. -
Scope & Integration
IEC 62351-3:2023 targets TCP/IP-based protocols in power systems environments but remains extensible to other protocols under similar boundary conditions. It excludes external security devices, focusing purely on protocol-level security.
Applications
-
SCADA Systems Security
Ensures secure communication for Supervisory Control and Data Acquisition systems by implementing TLS profiles that provide necessary data protection over IP networks. -
Telecontrol Protocols
Safeguards data exchanges in telecontrol applications used in power grid operations to prevent tampering and unauthorized access. -
Power System Management Tools
Enables secure remote management and monitoring of electrical substations and control centers through standardized and interoperable TLS security profiles. -
Conformance for IEC Standards
Acts as a normative reference for other IEC standards requiring TCP/IP transport security, allowing organizations to uniformly implement and attest compliance with TLS-based cybersecurity requirements. -
Cybersecurity Compliance
Provides a basis for ensuring communication security aligns with organizational policies, supports audit trails, and aids in resilience against cyber attacks in power grids.
Related Standards
-
IEC 62351 Series
The broader IEC 62351 family addresses various aspects of cybersecurity for power system management and associated information exchanges beyond just communication security. -
RFC 5246 (TLS 1.2) and RFC 8446 (TLS 1.3)
Fundamental IETF RFCs defining the technical specifications of TLS protocols which IEC 62351-3 profiles and adapts for power systems. -
IEC 60870 and IEC 61850
Standards for power system telecontrol and communication, which may incorporate IEC 62351-3 profiles to secure their TCP/IP-based communications. -
ISO/IEC 27000 Series
While broader in scope, these standards for information security management systems (ISMS) complement IEC 62351-3 by defining organizational security policies that govern responses to security events and incidents.
Keywords: IEC 62351-3 2023, power systems security, TCP/IP security, Transport Layer Security, TLS profiling, SCADA security, telecontrol cybersecurity, certificate validation, security event logging, IEC standards cybersecurity, cyber protection power grids, communication network security.
Технические детали
- Технический комитет
- TC 57 - Power systems management and associated information exchange
- SKU
- IEC 62351-3:2023
Похожие стандарты
Стандарты, упомянутые в описании
IEC 62351-11:2016
ДействующийPower systems management and associated information exchange - Data and communications security - Part 11: Se…
Overview IEC 62351-11:2016 is an international standard developed by the International Electrotechnical Commission (IEC) focusing on security for XML documents within power systems management and ass…
IEC TS 62351-100-3:2020
ДействующийPower systems management and associated information exchange - Data and communications security - Part 100-3:…
Overview IEC TS 62351-100-3:2020 is a technical specification developed by the International Electrotechnical Commission (IEC) focused on ensuring data and communications security in power systems ma…
IEC 60870-6-503:2014
ДействующийTelecontrol equipment and systems - Part 6-503: Telecontrol protocols compatible with ISO standards and ITU-T…
Overview IEC 60870-6-503:2014 is an international standard published by the International Electrotechnical Commission (IEC) that specifies telecontrol protocols known as TASE.2. These protocols are f…
IEC TR 61850-90-30:2025
ДействующийCommunication networks and systems for power utility automation - Part 90-30: IEC 61850 Function Modelling in…
Overview IEC TR 61850-90-30:2025 (Communication networks and systems for power utility automation - Part 90-30) is a Technical Report that defines extensions to the SCL Substation/Process Section to…