IEC 62351-9:2017
Power systems management and associated information exchange - Data and communications security - Part 9: Cyber security key management for power system equipment
Power systems management and associated information exchange - Data and communications security - Part 9: Cyber security key management for power system equipment
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 85
- Дата публикации:
- 18 мая 2017 г.
- Издание:
- IEC IS 62351 edition 1 version 1
- ICS:
- 33.200
IEC 62351-9:2017 specifies cryptographic key management, namely how to generate, distribute, revoke, and handle public-key certificates and cryptographic keys to protect digital data and its communication. Included in the scope is the handling of asymmetric keys (e.g. private keys and public-key certificates), as well as symmetric keys for groups (GDOI). This document assumes that other standards have already chosen the type of keys and cryptography that will be utilized, since the cryptography algorithms and key materials chosen will be typically mandated by an organization’s own local security policies and by the need to be compliant with other international standards. This document therefore specifies only the management techniques for these selected key and cryptography infrastructures. The objective is to define requirements and technologies to achieve interoperability of key management. The purpose of this document is to guarantee interoperability among different vendors by specifying or limiting key management options to be used. This document assumes that the reader understands cryptography and PKI principles.
Abstract
Overview
IEC 62351-9:2017 specifies cryptographic key management practices for power system equipment. It defines how to generate, distribute, renew and revoke asymmetric (private/public-key certificates) and symmetric (group) keys to protect digital data and communications in power systems. The standard focuses on management techniques (not on selecting cryptographic algorithms) and aims to ensure interoperability among vendors by constraining key-management options. It assumes readers understand cryptography and PKI principles.
Key topics and requirements
- Scope: Management of asymmetric keys, public‑key certificates and symmetric group keys (GDOI).
- Lifecycle management: Requirements for key/certificate generation, enrolment, renewal, revocation and expiry; certificate profiles and lifecycle diagrams.
- Trust models: Use of PKI (CAs, RAs, trust anchors), non‑PKI self‑signed certificates, Authorization and Validation Lists (AVLs), and pre‑shared keys.
- Certificate processes: Certificate Signing Requests (CSRs), initial enrolment, CRLs, OCSP, SCVP and options for short‑lived certificates.
- Protocols & mechanisms: Support and guidance for enrolment and management protocols such as SCEP, CMP, CMC, EST, and Trust Anchor Management Protocol (TAMP).
- Group key management: Group Domain of Interpretation (GDOI) and IKEv1 exchanges for secure group key distribution (useful for multicast/real‑time data).
- Transport and session keys: Use of TLS and session-key handling for secure channels.
- Security controls: Cryptographic key protection, random number generation guidance (informative annex), and Protocol Implementation Conformance Statement (PICS).
- Interoperability focus: Limits and options defined to guarantee cross‑vendor interoperability in power system operations.
Practical applications
IEC 62351-9 is applied where robust key management is required to secure:
- Substation automation and protection communications (including multicast messaging and IEC 61850 data).
- Control center to field device communications and SCADA telemetry.
- Secure firmware provisioning, device enrolment and remote key lifecycle operations.
- Group communications (e.g., GOOSE/SV multicast) where synchronized group keys are needed. The standard helps utilities, vendors and integrators implement repeatable, auditable key management capable of meeting operational and compliance needs.
Who should use this standard
- Utility cybersecurity architects and engineers
- Device and system vendors (IEDs, RTUs, gateways)
- PKI and Certificate Authority administrators
- System integrators and implementers of IEC 61850 / SCADA security
- Compliance and security auditors in the energy sector
Related standards and keywords
- Related IEC 62351 parts (data/communications security) and IEC 61850 (substation automation)
- Keywords: IEC 62351-9, key management, PKI, GDOI, certificate management, OCSP, CRL, SCEP, EST, IKEv1, TLS, power system cybersecurity, cryptographic key lifecycle.
Технические детали
- Технический комитет
- TC 57 - Power systems management and associated information exchange
- SKU
- IEC 62351-9:2017
Похожие стандарты
Упомянутые в описании и другие стандарты IEC
IEC TR 61850-90-30:2025
ДействующийCommunication networks and systems for power utility automation - Part 90-30: IEC 61850 Function Modelling in…
Overview IEC TR 61850-90-30:2025 (Communication networks and systems for power utility automation - Part 90-30) is a Technical Report that defines extensions to the SCL Substation/Process Section to…
IEC 62351-11:2016
ДействующийPower systems management and associated information exchange - Data and communications security - Part 11: Se…
Overview IEC 62351-11:2016 is an international standard developed by the International Electrotechnical Commission (IEC) focusing on security for XML documents within power systems management and ass…
IEC 62590-2-2:2026
ДействующийRailway applications - Electronic power converters for fixed installations - Part 2-2: DC Traction applicatio…
Overview IEC 62590-2-2:2026 is an international standard developed by the International Electrotechnical Commission (IEC) focusing on railway applications, specifically the electronic power converter…
IEC 61753-042-02:2026
ДействующийFibre optic interconnecting devices and passive components - Performance standard - Part 042-02: Plug-pigtail…
Overview IEC 61753-042-02:2026 establishes the minimum performance, test, and measurement requirements for plug-pigtail and plug-receptacle style OTDR (Optical Time-Domain Reflectometer) reflecting d…
IEC 61837-2:2018
ДействующийSurface mounted piezoelectric devices for frequency control and selection - Standard outlines and terminal le…
Overview IEC 61837-2:2018 - Surface mounted piezoelectric devices for frequency control and selection - Standard outlines and terminal lead connections - Part 2: Ceramic enclosures (Edition 3.0, 2018…
IEC 61851-23-1:2026
ДействующийElectric vehicle conductive charging system - Part 23-1: DC electric vehicle supply equipment - Automated con…
Overview IEC 61851-23-1:2026 is an international standard published by the International Electrotechnical Commission (IEC) that specifies requirements for DC electric vehicle supply equipment (EVSE)…
IEC 63506:2026
ДействующийCalibration of the prompt fission neutron logging tools
Overview IEC 63506:2026 - Calibration of the Prompt Fission Neutron Logging Tools is the international standard that specifies the calibration methods for prompt fission neutron (PFN) logging tools,…
IEC 63589-1:2026
ДействующийLinear accelerator - Electron linear accelerator for radiation processing - Part 1: General requirements and…
Overview IEC 63589-1:2026 specifies the general requirements and test methods for electron linear accelerator devices used in radiation processing. Developed by the International Electrotechnical Com…