IEC TS 60870-5-7:2013
Telecontrol equipment and systems - Part 5-7: Transmission protocols - Security extensions to IEC 60870-5-101 and IEC 60870-5-104 protocols (applying IEC 62351)
Telecontrol equipment and systems - Part 5-7: Transmission protocols - Security extensions to IEC 60870-5-101 and IEC 60870-5-104 protocols (applying IEC 62351)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 44
- Дата публикации:
- 15 июля 2013 г.
- Издание:
- IEC TS 60870 edition 1 version 1
- ICS:
- 33.200
IEC/TS 60870-5-7:2013(E) describes messages and data formats for implementing IEC/TS 62351-5 for secure authentication as an extension to IEC 60870-5-101 and IEC 60870-5-104. The purpose of this base standard is to permit the receiver of any IEC 60870-5-101/104 Application Protocol Data Unit (APDU) to verify that the APDU was transmitted by an authorized user and that the APDU was not modified in transit. It provides methods to authenticate not only the device which originated the APDU but also the individual human user if that capability is supported by the rest of the telecontrol system. This specification is also intended to be used, together with the definitions of IEC/TS 62351-3, in conjunction with the IEC 60870-5-104 companion standard.
Abstract
Overview
IEC/TS 60870-5-7:2013 specifies security extensions for the telecontrol protocols IEC 60870-5-101 and IEC 60870-5-104, applying concepts from IEC 62351. The technical specification defines message types, data formats and procedures so that a receiver of any IEC 60870-5 APDU (Application Protocol Data Unit) can verify the origin (authorized device or user) and integrity (not modified in transit) of telecontrol traffic. It supports device authentication and, where available, individual human-user authentication within SCADA/telecontrol systems.
Key Topics and Requirements
- Authentication messages and ASDU types: Defines new ASDU type identifiers (for example S_CH_NA_1 Authentication challenge, S_RP_NA_1 Authentication reply, S_ER_NA_1 Authentication error, S_UC_NA_1 User certificate, etc.) and their data formats for secure authentication flows.
- APDU verification: Methods to ensure APDUs are transmitted by authorized principals and protected against tampering (message authentication).
- Cryptographic elements: Specification covers MAC algorithms, encryption and key-wrap algorithms, session key handling, update key change methods and related configuration parameters (see Clause 10 Protocol Implementation Conformance Statement).
- Certificate support: Procedures for certificate exchange, comparison and multi-CA handling to support authentication based on public-key credentials.
- ASDU segmentation & timing: Rules for transmitting extended ASDUs using segmentation and the reception state machine for segmented messages.
- Operational modes: Support for normal and aggressive mode authentication, co-existence with non-secure implementations, recommended and mandatory cipher-suite usage for IEC 60870-5-104 transport (per Clause 9).
- Diagnostics & statistics: Security statistics, integrated totals and time-tagged reporting to support monitoring and thresholds.
Applications
IEC/TS 60870-5-7 is aimed at securing telemetry and telecontrol communications in electrical power systems and related infrastructure:
- Power utilities and grid operators securing master stations, substation RTUs/IEDs and SCADA links
- Manufacturers and vendors implementing secure IEC 60870-5-101/104 stacks
- System integrators and security architects designing encrypted/authenticated telecontrol channels
- Cybersecurity teams performing protocol hardening, compliance reviews and conformance testing
Who Should Use This Standard
- SCADA/telecontrol protocol implementers and firmware developers
- Substation automation and protection equipment manufacturers
- Utility engineers and system integrators deploying IEC 60870-5 systems
- Standards and compliance officers validating IEC 62351-based security features
Related Standards
- IEC 60870-5-101 / IEC 60870-5-104 (base telecontrol protocols)
- IEC 62351 family (security for power system communications), specifically IEC/TS 62351-3 for companion use with 60870-5-104
Keywords: IEC TS 60870-5-7, IEC 60870-5-104 security, IEC 60870-5-101 authentication, IEC 62351, telecontrol security, SCADA authentication, APDU integrity, session key, certificate support.
Технические детали
- Технический комитет
- TC 57 - Power systems management and associated information exchange
- SKU
- IEC TS 60870-5-7:2013
Похожие стандарты
Стандарты, упомянутые в описании
IEC TS 60870-5-601:2015
ДействующийTelecontrol equipment and systems - Part 5-601: Transmission protocols - Conformance test cases for the IEC 6…
Overview IEC TS 60870-5-601:2015 is a technical specification developed by the International Electrotechnical Commission (IEC) under the reference IEC TS 60870-5-601:2015. This document defines stand…
IEC TS 61850-80-1:2016
ДействующийCommunication networks and systems for power utility automation - Part 80-1: Guideline to exchanging informat…
Overview IEC TS 61850-80-1:2016 provides guidelines for exchanging information from a CDC‑based data model (for example IEC 61850) using IEC 60870-5-101 or IEC 60870-5-104 between substations and con…
IEC 62351-11:2016
ДействующийPower systems management and associated information exchange - Data and communications security - Part 11: Se…
Overview IEC 62351-11:2016 is an international standard developed by the International Electrotechnical Commission (IEC) focusing on security for XML documents within power systems management and ass…