Overview
IEC/TS 60870-5-7:2013 specifies security extensions for the telecontrol protocols IEC 60870-5-101 and IEC 60870-5-104, applying concepts from IEC 62351. The technical specification defines message types, data formats and procedures so that a receiver of any IEC 60870-5 APDU (Application Protocol Data Unit) can verify the origin (authorized device or user) and integrity (not modified in transit) of telecontrol traffic. It supports device authentication and, where available, individual human-user authentication within SCADA/telecontrol systems.
Key Topics and Requirements
- Authentication messages and ASDU types: Defines new ASDU type identifiers (for example S_CH_NA_1 Authentication challenge, S_RP_NA_1 Authentication reply, S_ER_NA_1 Authentication error, S_UC_NA_1 User certificate, etc.) and their data formats for secure authentication flows.
- APDU verification: Methods to ensure APDUs are transmitted by authorized principals and protected against tampering (message authentication).
- Cryptographic elements: Specification covers MAC algorithms, encryption and key-wrap algorithms, session key handling, update key change methods and related configuration parameters (see Clause 10 Protocol Implementation Conformance Statement).
- Certificate support: Procedures for certificate exchange, comparison and multi-CA handling to support authentication based on public-key credentials.
- ASDU segmentation & timing: Rules for transmitting extended ASDUs using segmentation and the reception state machine for segmented messages.
- Operational modes: Support for normal and aggressive mode authentication, co-existence with non-secure implementations, recommended and mandatory cipher-suite usage for IEC 60870-5-104 transport (per Clause 9).
- Diagnostics & statistics: Security statistics, integrated totals and time-tagged reporting to support monitoring and thresholds.
Applications
IEC/TS 60870-5-7 is aimed at securing telemetry and telecontrol communications in electrical power systems and related infrastructure:
- Power utilities and grid operators securing master stations, substation RTUs/IEDs and SCADA links
- Manufacturers and vendors implementing secure IEC 60870-5-101/104 stacks
- System integrators and security architects designing encrypted/authenticated telecontrol channels
- Cybersecurity teams performing protocol hardening, compliance reviews and conformance testing
Who Should Use This Standard
- SCADA/telecontrol protocol implementers and firmware developers
- Substation automation and protection equipment manufacturers
- Utility engineers and system integrators deploying IEC 60870-5 systems
- Standards and compliance officers validating IEC 62351-based security features
Related Standards
Keywords: IEC TS 60870-5-7, IEC 60870-5-104 security, IEC 60870-5-101 authentication, IEC 62351, telecontrol security, SCADA authentication, APDU integrity, session key, certificate support.