IEC 62351-5:2023
Power systems management and associated information exchange - Data and communications security - Part 5: Security for IEC 60870-5 and derivatives
Power systems management and associated information exchange - Data and communications security - Part 5: Security for IEC 60870-5 and derivatives
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 263
- Дата публикации:
- 13 января 2023 г.
- Издание:
- IEC IS 62351 edition 1 version 1
- ICS:
- 33.200
IEC 62351-5:2023 defines the application profile (A-profile) secure communication mechanism specifying messages, procedures and algorithms for securing the operation of all protocols based on or derived from IEC 60870-5, Telecontrol Equipment and Systems – Transmission Protocols. For the measures described in this document to take effect, they must be accepted and referenced by the specifications for the protocols themselves. This document is written to enable that process. The subsequent audience for this document is intended to be the developers of products that implement these protocols. Portions of this document may also be of use to managers and executives in order to understand the purpose and requirements of the work. This document is organized working from the general to the specific, as follows: • Clauses 2 through 4 provide background terms, definitions, and references. • Clause 5 describes the problems this specification is intended to address. • Clause 6 describes the mechanism generically without reference to a specific protocol. • Clauses 7 and 8 describe the mechanism more precisely and are the primary normative part of this specification. • Clause 9 define the interoperability requirements for this secure communication mechanism. • Clause 10 describes the requirements for other standards referencing this document. The actions of an organization in response to events and error conditions described in this document are expected to be defined by the organization’s security policy and they are beyond the scope of this document. This International Standard cancels and replaces IEC TS 62351-5 published in 2013. It constitutes a technical revision. The primary changes in this International Standard are: a) The secure communication mechanism is performed on per controlling station/controlled station association. b) User management to add, change or delete a User, was removed. c) Symmetric method to change the Update Key was removed. d) Asymmetric method to the change Update Key was reviewed. e) Challenge/Reply procedure and concepts were removed. f) Aggressive Mode concept was replaced with the Secure Data message exchange mechanism. g) Authenticated encryption of application data was added. h) The list of permitted security algorithms has been updated. i) The rules for calculating messages sequence numbers have been updated j) Events monitoring and logging was added
Abstract
Overview
IEC 62351-5:2023 is an international standard developed by the International Electrotechnical Commission (IEC) that addresses data and communications security for power systems management. Specifically, it focuses on securing protocols based on or derived from IEC 60870-5, which are widely used in telecontrol equipment and systems for transmission protocols. The standard defines a secure communication mechanism, known as the application profile (A-profile), detailing messages, procedures, and cryptographic algorithms to protect these control systems against cybersecurity threats.
This technical revision (replacing IEC TS 62351-5 from 2013) enhances security features by introducing advanced encryption methods, refined key management, and updated message sequencing rules, ensuring secure and reliable communications in power system operations.
Key Topics
- Scope and Purpose: Establishes secure communication mechanisms for protocols derived from IEC 60870-5, supporting product developers and informing management on cybersecurity requirements.
- Security Challenges Addressed:
- Limited bandwidth and processing power in remote and legacy systems
- Asymmetric communication issues
- Unreliable media and network infrastructures, including radio and dial-up systems
- Compatibility with varied data link layers and long upgrade intervals
- Mechanisms Defined:
- Per controlling station/controlled station association security
- Removal of outdated concepts like aggressive mode and challenge/reply procedures
- Incorporation of authenticated encryption for application data
- Updated lists of permitted cryptographic algorithms and procedures
- Key Management:
- Reviewed asymmetric key update procedures
- Elimination of symmetric methods for updating keys
- Role-Based Access Control (RBAC) integration for secure access
- Message Sequencing and Interoperability:
- Revised rules for calculating message sequence numbers to improve integrity and order
- Defined interoperability requirements for consistent implementation by various vendors
- Event Monitoring and Logging:
- Added mechanisms for security event detection, monitoring, and audit logging to support incident response aligned with organizational security policies
Applications
IEC 62351-5:2023 plays a critical role in enhancing cybersecurity for electric power utilities, grid operators, and manufacturers of telecontrol equipment. Key application areas include:
- Power System Telecontrol: Securing data exchange in control and monitoring protocols used for dispatch and operation of power transmission grids.
- Smart Grid Communications: Protecting communication links within modern power management systems integrating renewable energy sources and distributed automation.
- SCADA Systems: Improving the resilience of supervisory control and data acquisition systems against cyberattacks by ensuring message authentication and integrity.
- Legacy System Security Upgrades: Enabling secure communication over existing IEC 60870-5 based infrastructures without significant hardware changes, facilitating gradual cybersecurity improvements.
- Vendor Product Development: Guiding manufacturers in implementing robust cryptographic procedures and interoperability compliance within their IEC 60870-5 protocol-based products.
- Security Policy Implementation: Assisting managers and executives in understanding operational security measures and compliance requirements relevant to critical infrastructure protection.
Related Standards
IEC 62351-5:2023 is part of the broader IEC 62351 series, which focuses on cybersecurity for power system management and information exchange:
- IEC 62351-3: Specifies security for profiles including MMS, handling authentication and authorization.
- IEC 62351-4: Addresses security for network and system management in power systems.
- IEC 62351-6: Covers security for IEC 61850 communications.
- IEC 62351-7: Defines network and system management data models for secure communications.
- IEC 60870-5 series: The foundational telecontrol protocol that IEC 62351-5 secures.
Together, these standards provide a comprehensive framework safeguarding critical power infrastructure communication against cyber threats with interoperable and scalable security solutions.
Keywords: IEC 62351-5:2023, data and communications security, IEC 60870-5 security, power system telecontrol, cryptographic key management, secure communication protocols, power grid cybersecurity, IEC standards, SCADA security, telecontrol equipment security.
Технические детали
- Технический комитет
- TC 57 - Power systems management and associated information exchange
- SKU
- IEC 62351-5:2023
Похожие стандарты
Стандарты, упомянутые в описании
IEC TS 60870-5-601:2015
ДействующийTelecontrol equipment and systems - Part 5-601: Transmission protocols - Conformance test cases for the IEC 6…
Overview IEC TS 60870-5-601:2015 is a technical specification developed by the International Electrotechnical Commission (IEC) under the reference IEC TS 60870-5-601:2015. This document defines stand…
IEC 62351-11:2016
ДействующийPower systems management and associated information exchange - Data and communications security - Part 11: Se…
Overview IEC 62351-11:2016 is an international standard developed by the International Electrotechnical Commission (IEC) focusing on security for XML documents within power systems management and ass…
IEC TS 62351-100-3:2020
ДействующийPower systems management and associated information exchange - Data and communications security - Part 100-3:…
Overview IEC TS 62351-100-3:2020 is a technical specification developed by the International Electrotechnical Commission (IEC) focused on ensuring data and communications security in power systems ma…
IEC TS 62351-100-4:2023
ДействующийPower systems management and associated information exchange - Data and communication security - Part 100-4:…
Overview IEC TS 62351-100-4:2023 is a technical specification published by the International Electrotechnical Commission (IEC). The document details standardized procedures for cybersecurity conforma…
IEC 62351-6:2020
ДействующийPower systems management and associated information exchange - Data and communications security - Part 6: Sec…
Overview IEC 62351-6:2020 - "Power systems management and associated information exchange - Data and communications security - Part 6: Security for IEC 61850" specifies the messages, procedures and a…
IEC TR 61850-90-30:2025
ДействующийCommunication networks and systems for power utility automation - Part 90-30: IEC 61850 Function Modelling in…
Overview IEC TR 61850-90-30:2025 (Communication networks and systems for power utility automation - Part 90-30) is a Technical Report that defines extensions to the SCL Substation/Process Section to…
IEC 62351-7:2025
ДействующийPower systems management and associated information exchange - Data and communications security - Part 7: Net…
Overview IEC 62351-7:2025 is part of the IEC 62351 series focused on power systems management and associated information exchange. This standard, published by the International Electrotechnical Commi…