IEC 62351-4:2018
Power systems management and associated information exchange - Data and communications security - Part 4: Profiles including MMS and derivatives
Power systems management and associated information exchange - Data and communications security - Part 4: Profiles including MMS and derivatives
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 109
- Дата публикации:
- 17 июля 2020 г.
- Издание:
- IEC IS 62351 edition 1 version 1
- ICS:
- 33.200
IEC 62351:2018 specifies security requirements both at the transport layer and at the application layer. While IEC TS 62351-4:2007 primarily provided some limited support at the application layer for authentication during handshake for the Manufacturing Message Specification (MMS) based applications, this document provides support for extended integrity and authentication both for the handshake phase and for the data transfer phase. It provides for shared key management and data transfer encryption at the application layer and it provides security end-to-end (E2E) with zero or more intermediate entities. While IEC TS 62351-4:2007 only provides support for systems based on the MMS, i.e. systems using an Open Systems Interworking (OSI) protocol stack, this document provides support for application protocols using other protocol stacks, e.g. an Internet protocol suite. This support is extended to protect application protocols using XML encoding. This extended security at the application layer is referred to as E2E-security. In addition to E2E security, this part of IEC 62351 also provides mapping to environmental protocols carrying the security related information. Only OSI and XMPP environments are currently considered.
Abstract
Overview
IEC 62351-4:2018 is an international standard developed by the International Electrotechnical Commission (IEC) focusing on data and communications security for power systems management and associated information exchange. As part of the IEC 62351 series, this standard builds on and extends the earlier IEC TS 62351-4:2007 by introducing robust security requirements at both the transport layer and application layer for protocols including the Manufacturing Message Specification (MMS) and its derivatives.
A primary feature of IEC 62351-4:2018 is its support for end-to-end (E2E) security, incorporating mechanisms for data integrity, authentication, data transfer encryption, and shared key management. The standard broadens its scope by not only securing systems based on the traditional Open Systems Interconnection (OSI) protocol stack but also enabling security adaptations for application protocols over other protocol stacks, such as the Internet protocol suite, including those using XML encoding and environments like XMPP.
With its focus on power systems communication security, IEC 62351-4:2018 is an essential reference for utility operators, system integrators, vendors, and organizations responsible for the cybersecurity of critical infrastructures.
Key Topics
-
Application and Transport Layer Security
Specifies requirements at both the transport and application layers, supporting stronger authentication and integrity throughout data communication processes. -
End-to-End (E2E) Security
Provides comprehensive protections from source to destination, even when intermediate network entities are present. E2E security ensures that authenticity and confidentiality are retained across the entire communication path. -
Protocol Compatibility and Interoperability
Defines a compatibility mode for interoperability with systems based on IEC TS 62351-4:2007, and a native mode with advanced security for new deployments. -
Extended Environment Support
Expands application security coverage to protocols operating over the Internet protocol suite and secures application protocols using XML encoding. Addresses security mapping in OSI and XMPP (Extensible Messaging and Presence Protocol) environments. -
Threat Mitigation
Details the types of security threats and attack vectors countered, including unauthorized access, message tampering, and eavesdropping. -
Cryptographic Techniques
References the application of cryptographic algorithms for secure authentication, integrity validation, and encryption.
Applications
The implementations of IEC 62351-4:2018 are vital in contexts where secure data exchange is critical for the reliable operation of modern energy and utility systems. Examples include:
-
Electric Power Utilities
Safeguarding SCADA system communications, substation automation, and real-time monitoring processes. -
Grid Communications
Securing inter-control center protocol exchanges, including those relying on MMS and derivatives, across public and private network infrastructures. -
Smart Grid and Renewable Integration
Ensuring secure integration of distributed generation sources and smart devices through protected communication protocols. -
Interoperable Systems
Facilitating secure data exchange between equipment from different vendors by adhering to standardized security measures at both protocol stack and application levels. -
Critical Infrastructure Cybersecurity
Meeting compliance requirements for the protection of essential systems against evolving cybersecurity threats.
Related Standards
-
IEC 62351 Series
A multi-part series addressing security for communication protocols in power system operations, including standards on network and data object security. -
IEC TS 62351-4:2007
The technical specification preceding this standard, focusing on initial application layer security for MMS-based operations. -
IEC 61850
Communications networks and systems for power utility automation - can rely on IEC 62351-4 for securing information exchange. -
IEC 60870-6
Telecontrol equipment and systems - compatibility with security profiles defined by IEC 62351-4. -
IETF Standards
Such as those relating to Transport Layer Security (TLS) and XMPP, referenced for implementing secured communication channels within the scope of the standard.
By adopting IEC 62351-4:2018, organizations can ensure the confidentiality, integrity, and reliability of communications across power system management networks, enabling secure integration, interoperability, and compliance with global cybersecurity best practices.
Технические детали
- Технический комитет
- TC 57 - Power systems management and associated information exchange
- SKU
- IEC 62351-4:2018
Похожие стандарты
Стандарты, упомянутые в описании
IEC 62351-11:2016
ДействующийPower systems management and associated information exchange - Data and communications security - Part 11: Se…
Overview IEC 62351-11:2016 is an international standard developed by the International Electrotechnical Commission (IEC) focusing on security for XML documents within power systems management and ass…
IEC TR 61850-90-30:2025
ДействующийCommunication networks and systems for power utility automation - Part 90-30: IEC 61850 Function Modelling in…
Overview IEC TR 61850-90-30:2025 (Communication networks and systems for power utility automation - Part 90-30) is a Technical Report that defines extensions to the SCL Substation/Process Section to…
IEC TS 62351-100-4:2023
ДействующийPower systems management and associated information exchange - Data and communication security - Part 100-4:…
Overview IEC TS 62351-100-4:2023 is a technical specification published by the International Electrotechnical Commission (IEC). The document details standardized procedures for cybersecurity conforma…
IEC 60870-6-503:2014
ДействующийTelecontrol equipment and systems - Part 6-503: Telecontrol protocols compatible with ISO standards and ITU-T…
Overview IEC 60870-6-503:2014 is an international standard published by the International Electrotechnical Commission (IEC) that specifies telecontrol protocols known as TASE.2. These protocols are f…