IEC TS 60870-5-7:2025
Telecontrol equipment and systems - Part 5-7: Transmission protocols - Security extensions to IEC 60870-5-101 and IEC 60870-5-104 protocols (applying IEC 62351)
Telecontrol equipment and systems - Part 5-7: Transmission protocols - Security extensions to IEC 60870-5-101 and IEC 60870-5-104 protocols (applying IEC 62351)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 50
- Дата публикации:
- 18 марта 2025 г.
- Издание:
- IEC TS 60870 edition 2 version 1
- ICS:
- 33.200
IEC TS 60870-5-7:2025, which is a technical specification, describes messages and data formats for implementing IEC 62351-5:2023 for secure communication as an extension to IEC 60870-5-101 and IEC 60870-5-104. The purpose of this document is to permit the receiver of any IEC 60870-5-101/-104 Application Protocol Data Unit (APDU) to verify that the APDU was transmitted by an authorized user and that the APDU was not modified in transit. This document is also intended to be used, together with the definitions of IEC 62351-3:2023, in conjunction with the IEC 60870-5-104 companion standard. The state machines, message sequences, and procedures for exchanging these messages are defined in IEC 62351-5:2023. This document describes only the message formats, selected options, critical operations, addressing considerations and other adaptations required to implement IEC 62351 in the IEC 60870-5-101 and IEC 60870-5-104 protocols. In addition to the previous edition, this new edition of this document also addresses role-based access control, by utilizing the IEC 62351-8 RBAC approach and the already defined role to permission mapping from IEC 62351-5:2023. The scope of this document does not include security for IEC 60870-5-102 or IEC 60870-5-103. IEC 60870-5-102 is in limited use only and will therefore not be addressed. Users of IEC 60870-5-103 desiring a secure solution need to implement IEC 61850 using the security measures from in IEC 62351 referenced in IEC 61850. Management of keys, certificates or other cryptographic credentials within devices or on communication links other than IEC 60870-5-101/104 is out of the scope of this document and might be addressed by other IEC 62351 publications in the future. This second edition cancels and replaces the first edition published in 2013. This edition constitutes a technical revision. This edition includes the following significant technical changes with respect to the previous edition: a) This edition has been completely revised with respect to the previous edition; b) Alignment with updated versions of IEC 62351-3:2023 and IEC 62351-5:2023; c) Definition of specific profiles for application layer and transport layer; d) Introduction of Session Initiation Request to handle situations in which the called station reestablishes a connection; e) Inclusion of multicast security for the unbalanced mode of IEC 60870-5-101 including key management; f) Consideration of RBAC based on IEC 62351-8. This Technical Specification is to be used in conjunction with IEC 62351-5:2023 and IEC 60870-5-104:2016.
Abstract
Overview
IEC TS 60870-5-7:2025 is a Technical Specification from the IEC that provides security extensions to the telecontrol protocols IEC 60870-5-101 and IEC 60870-5-104 by applying the mechanisms defined in IEC 62351. Edition 2.0 (2025) replaces the 2013 edition and specifies message and data formats to implement IEC 62351-5:2023 and aligns with IEC 62351-3:2023. The main purpose is to enable a receiver of any IEC 60870-5-101/104 Application Protocol Data Unit (APDU) to verify that the APDU was transmitted by an authorized user and was not modified in transit.
Key topics and requirements
- Message and data formats: Defines ASDU formats and extensions required to carry integrity/MAC and authenticated/encrypted payloads for secure APDUs.
- Profiles: Defines specific application-layer (A-Profile) and transport-layer (T-Profile) security profiles for 101 and 104 implementations.
- Authentication and integrity: Support for MAC/AEAD protection to verify APDU origin and detect tampering.
- Key and session management: Session keys, update key procedures, session key change messages and broadcast session key distribution mechanisms (including multicast security for unbalanced IEC 60870-5-101).
- Session control: Introduction of a Session Initiation Request to handle re-established connections and the associated state machines and message sequences (implemented per IEC 62351-5:2023).
- Coexistence: Mechanisms for interoperating with non-secure implementations and configurable parameters for gradual deployment.
- Role-Based Access Control (RBAC): Incorporates IEC 62351-8 RBAC approach and role-to-permission mappings defined in IEC 62351-5:2023.
- Conformance: Protocol Implementation Conformance Statement (PICS) items including selectable algorithms, MAC/encryption/key-wrap choices and configurable statistic thresholds.
Applications and practical value
- Secures SCADA/telecontrol communications in electric power systems by providing integrity and authentication for telemetry and control APDUs.
- Enables vendors and integrators to implement interoperable security extensions for remote terminal units (RTUs), master stations, protocols over serial links and TCP/IP.
- Supports multicast/broadcast scenarios for telemetry distribution in unbalanced 101 networks.
- Helps utilities and operators meet cybersecurity requirements for power system management and reduce risk from message spoofing or manipulation.
Who should use this standard
- Power utilities, grid operators and system architects planning secure telecontrol deployments
- SCADA/RTU vendors and firmware developers implementing IEC 60870-5-101/104
- Security architects, network engineers and integrators implementing IEC 62351-based protections
- Compliance teams assessing protocol-level cybersecurity for power systems
Related standards
- IEC 62351-5:2023 (security for control system application layer)
- IEC 62351-3:2023 (transport/security profiles)
- IEC 62351-8 (RBAC)
- IEC 60870-5-104:2016 (companion protocol)
- Note: IEC 60870-5-102/103 are out of scope; IEC 61850 + IEC 62351 recommended for 103 users
Keywords: IEC TS 60870-5-7:2025, IEC 60870-5-101, IEC 60870-5-104, IEC 62351, telecontrol security, SCADA cybersecurity, RBAC, multicast security, APDU verification.
Технические детали
- Технический комитет
- TC 57 - Power systems management and associated information exchange
- SKU
- IEC TS 60870-5-7:2025
Похожие стандарты
Стандарты, упомянутые в описании
IEC 62351-5:2023
ДействующийPower systems management and associated information exchange - Data and communications security - Part 5: Sec…
Overview IEC 62351-5:2023 is an international standard developed by the International Electrotechnical Commission (IEC) that addresses data and communications security for power systems management. S…
IEC 62351-3:2023
ДействующийPower systems management and associated information exchange - Data and communications security - Part 3: Com…
Overview IEC 62351-3:2023 is an international standard developed by the International Electrotechnical Commission (IEC) that focuses on data and communications security for power systems management.…
IEC TS 60870-5-601:2015
ДействующийTelecontrol equipment and systems - Part 5-601: Transmission protocols - Conformance test cases for the IEC 6…
Overview IEC TS 60870-5-601:2015 is a technical specification developed by the International Electrotechnical Commission (IEC) under the reference IEC TS 60870-5-601:2015. This document defines stand…
IEC TS 61850-80-1:2016
ДействующийCommunication networks and systems for power utility automation - Part 80-1: Guideline to exchanging informat…
Overview IEC TS 61850-80-1:2016 provides guidelines for exchanging information from a CDC‑based data model (for example IEC 61850) using IEC 60870-5-101 or IEC 60870-5-104 between substations and con…
IEC 62351-11:2016
ДействующийPower systems management and associated information exchange - Data and communications security - Part 11: Se…
Overview IEC 62351-11:2016 is an international standard developed by the International Electrotechnical Commission (IEC) focusing on security for XML documents within power systems management and ass…
IEC TR 61850-90-30:2025
ДействующийCommunication networks and systems for power utility automation - Part 90-30: IEC 61850 Function Modelling in…
Overview IEC TR 61850-90-30:2025 (Communication networks and systems for power utility automation - Part 90-30) is a Technical Report that defines extensions to the SCL Substation/Process Section to…