IEC 62351-9:2023
Power systems management and associated information exchange - Data and communications security - Part 9: Cyber security key management for power system equipment
Power systems management and associated information exchange - Data and communications security - Part 9: Cyber security key management for power system equipment
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 296
- Дата публикации:
- 6 июня 2023 г.
- Издание:
- IEC IS 62351 edition 2 version 1
- ICS:
- 33.200
IEC 62351-9:2023 specifies cryptographic key management, primarily focused on the management of long-term keys, which are most often asymmetric key pairs, such as public-key certificates and corresponding private keys. As certificates build the base this document builds a foundation for many IEC 62351 services (see also Annex A). Symmetric key management is also considered but only with respect to session keys for group-based communication as applied in IEC 62351-6. The objective of this document is to define requirements and technologies to achieve interoperability of key management by specifying or limiting key management options to be used. This document assumes that an organization (or group of organizations) has defined a security policy to select the type of keys and cryptographic algorithms that will be utilized, which may have to align with other standards or regulatory requirements. This document therefore specifies only the management techniques for these selected key and cryptography infrastructures. This document assumes that the reader has a basic understanding of cryptography and key management principles. The requirements for the management of pairwise symmetric (session) keys in the context of communication protocols is specified in the parts of IEC 62351 utilizing or specifying pairwise communication such as: • IEC 62351-3 for TLS by profiling the TLS options • IEC 62351-4 for the application layer end-to-end security • IEC TS 62351-5 for the application layer security mechanism for IEC 60870-5-101/104 and IEEE 1815 (DNP3) The requirements for the management of symmetric group keys in the context of power system communication protocols is specified in IEC 62351-6 for utilizing group security to protect GOOSE and SV communication. IEC 62351-9 utilizes GDOI as already IETF specified group-based key management protocol to manage the group security parameter and enhances this protocol to carry the security parameter for GOOSE, SV, and PTP. This document also defines security events for specific conditions which could identify issues which might require error handling. However, the actions of the organisation in response to these error conditions are beyond the scope of this document and are expected to be defined by the organizations security policy. In the future, as public-key cryptography becomes endangered by the evolution of quantum computers, this document will also consider post-quantum cryptography to a certain extent. Note that at this time being no specific measures are provided. This second edition cancels and replaces the first edition published in 2017. This edition constitutes a technical revision. This edition includes the following significant technical changes with respect to the previous edition: a) Certificate components and verification of the certificate components have been added; b) GDOI has been updated to include findings from interop tests; c) GDOI operation considerations have been added; d) GDOI support for PTP (IEEE 1588) support has been added as specified by IEC/IEEE 61850-9-3 Power Profile; e) Cyber security event logging has been added as well as the mapping to IEC 62351-14; f) Annex B with background on utilized cryptographic algorithms and mechanisms has been added.
Abstract
Overview
IEC 62351-9:2023 is a critical international standard published by the IEC that addresses cyber security key management specifically for power system equipment. This standard focuses on cryptographic key management practices essential for securing data and communications within power systems. It primarily covers the management of long-term asymmetric keys such as public-key certificates and corresponding private keys, forming a foundation for many IEC 62351 services. The scope also extends to symmetric key management for session keys used in group-based communication as applied in IEC 62351-6.
Designed to ensure interoperability across power system equipment and security infrastructures, IEC 62351-9 provides requirements and best practices for managing cryptographic keys in line with organizational policies and regulatory standards. The 2023 revision includes significant technical updates such as enhanced certificate verification, updates to the Group Domain of Interpretation (GDOI), support for Precision Time Protocol (PTP), and new guidelines for cyber security event logging.
Key Topics
-
Cryptographic Key Lifecycle Management
Covers the entire lifecycle of cryptographic keys including generation, distribution, storage, usage, renewal, and revocation, ensuring secure key handling throughout power system operations. -
Public-Key Infrastructure (PKI) and Privilege Management Infrastructure (PMI)
Details the use of certification authorities (CAs), registration authorities (RAs), and public-key certificates essential for establishing trust and authentication within power equipment communication. -
Symmetric and Asymmetric Key Management
Addresses both asymmetric key pairs (e.g., public/private keys) and symmetric session keys for securing group communications such as GOOSE and Sampled Values (SV) messages. -
Group Key Management Using GDOI
Utilizes the IETF-standardized Group Domain of Interpretation (GDOI) protocol for managing group keys, with enhancements supporting power system-specific protocols including IEC 61850 and IEEE 1588 PTP. -
Security Events and Logging
Defines specific security events relevant to key management and cyber security with recommendations for event logging, supporting integration with IEC 62351-14 for comprehensive security monitoring. -
Future-Proofing for Post-Quantum Cryptography
While no specific post-quantum measures are mandated yet, the document lays groundwork for potential adoption as quantum computing evolves. -
Integration with Related IEC 62351 Parts
Focuses on interoperability by aligning key management practices with other parts in the IEC 62351 series governing secure communication protocols such as TLS, DNP3, and more.
Applications
IEC 62351-9:2023 is highly applicable in the following contexts:
-
Power Utility Cyber Security
Ensures secure management of cryptographic credentials protecting control and monitoring systems in electric power utilities. -
Smart Grid Security
Supports the secure exchange of information across smart grid components including substations, intelligent electronic devices (IEDs), and control centers. -
Industrial Control Systems (ICS)
Enhances security protocols for critical infrastructure systems that rely on robust key management to prevent cyber intrusions and unauthorized access. -
Interoperability Across Vendors and Systems
Facilitates consistent key management standards allowing different vendors’ equipment to securely interoperate within a power system environment. -
Regulatory Compliance
Helps organizations meet compliance requirements relating to cryptographic security and key management defined by international, national, or sector-specific regulations.
Related Standards
For comprehensive security in power system management, IEC 62351-9 complements other IEC 62351 parts and relevant protocols:
- IEC 62351-3: Secure communication using TLS – Profiles TLS options for pairwise symmetric key management.
- IEC 62351-4: Application layer end-to-end security – Specifies security mechanisms for application layer protocols.
- IEC 62351-6: Group communication security – Defines symmetric group key management protocols for GOOSE and SV messages.
- IEC TS 62351-5: Security for IEC 60870-5 and DNP3 protocols – Addresses pairwise communication security.
- IEC 62351-14: Security event logging – Defines requirements and mappings for cyber security event logging.
- IEC/IEEE 61850-9-3: Power Profile for IEEE 1588 (PTP) – Provides precision timing profile, supported in key management by IEC 62351-9.
Adhering to IEC 62351-9:2023 ensures that power system operators and manufacturers implement state-of-the-art cryptographic key management practices, enhancing the overall security posture and trustworthiness of critical power infrastructure communications.
Технические детали
- Технический комитет
- TC 57 - Power systems management and associated information exchange
- SKU
- IEC 62351-9:2023
Похожие стандарты
Стандарты, упомянутые в описании
IEC 62351-11:2016
ДействующийPower systems management and associated information exchange - Data and communications security - Part 11: Se…
Overview IEC 62351-11:2016 is an international standard developed by the International Electrotechnical Commission (IEC) focusing on security for XML documents within power systems management and ass…
IEC 62351-6:2020
ДействующийPower systems management and associated information exchange - Data and communications security - Part 6: Sec…
Overview IEC 62351-6:2020 - "Power systems management and associated information exchange - Data and communications security - Part 6: Security for IEC 61850" specifies the messages, procedures and a…
IEC 62351-9:2017
ДействующийPower systems management and associated information exchange - Data and communications security - Part 9: Cyb…
Overview IEC 62351-9:2017 specifies cryptographic key management practices for power system equipment. It defines how to generate, distribute, renew and revoke asymmetric (private/public-key certific…
IEC TR 61850-90-30:2025
ДействующийCommunication networks and systems for power utility automation - Part 90-30: IEC 61850 Function Modelling in…
Overview IEC TR 61850-90-30:2025 (Communication networks and systems for power utility automation - Part 90-30) is a Technical Report that defines extensions to the SCL Substation/Process Section to…
IEC TS 62351-100-3:2020
ДействующийPower systems management and associated information exchange - Data and communications security - Part 100-3:…
Overview IEC TS 62351-100-3:2020 is a technical specification developed by the International Electrotechnical Commission (IEC) focused on ensuring data and communications security in power systems ma…
IEC TS 62351-100-4:2023
ДействующийPower systems management and associated information exchange - Data and communication security - Part 100-4:…
Overview IEC TS 62351-100-4:2023 is a technical specification published by the International Electrotechnical Commission (IEC). The document details standardized procedures for cybersecurity conforma…
IEC TS 60870-5-601:2015
ДействующийTelecontrol equipment and systems - Part 5-601: Transmission protocols - Conformance test cases for the IEC 6…
Overview IEC TS 60870-5-601:2015 is a technical specification developed by the International Electrotechnical Commission (IEC) under the reference IEC TS 60870-5-601:2015. This document defines stand…