首页 | 本学科首页   官方微博 | 高级检索  
     

一种高效的GOOSE报文完整性认证方法
引用本文:王智东,王钢,童晋方,许志恒,朱革兰,罗致远. 一种高效的GOOSE报文完整性认证方法[J]. 电力系统自动化, 2017, 41(2): 173-177
作者姓名:王智东  王钢  童晋方  许志恒  朱革兰  罗致远
作者单位:华南理工大学电力学院, 广东省广州市 510640,华南理工大学电力学院, 广东省广州市 510640,华南理工大学电力学院, 广东省广州市 510640,华南理工大学电力学院, 广东省广州市 510640,华南理工大学电力学院, 广东省广州市 510640,深圳供电局有限公司, 深圳市 518001
基金项目:国家自然科学基金资助项目(51477057)
摘    要:当前主流研究采用HASH信息验证码(HMAC)认证方法保障面向通用对象的变电站事件(GOOSE)报文的完整性,但分析发现HMAC对经典的GOOSE这类短报文来说效率并不高。设计一种直接采用密钥和顺序调整后的报文作为HASH函数输入的GOOSE报文认证方法,利用GOOSE报文显性长度域、统一报文格式和时序性等属性,降低碰撞攻击和避免长度扩展攻击、重放攻击等风险;将GOOSE心跳报文的时变内容置于待认证报文末端,可重复利用同系列心跳报文中相同内容的HASH压缩运算的中间结果。嵌入式平台验证结果表明算法的高效性。

关 键 词:实时报文  完整性  认证  算法效率
收稿时间:2016-05-18
修稿时间:2016-09-14

Efficient Integrity Authentication Method for GOOSE Packet
WANG Zhidong,WANG Gang,TONG Jinfang,XU Zhiheng,ZHU Gelan and LUO Zhiyuan. Efficient Integrity Authentication Method for GOOSE Packet[J]. Automation of Electric Power Systems, 2017, 41(2): 173-177
Authors:WANG Zhidong  WANG Gang  TONG Jinfang  XU Zhiheng  ZHU Gelan  LUO Zhiyuan
Affiliation:College of Electric Power, South China University of Technology, Guangzhou 510640, China,College of Electric Power, South China University of Technology, Guangzhou 510640, China,College of Electric Power, South China University of Technology, Guangzhou 510640, China,College of Electric Power, South China University of Technology, Guangzhou 510640, China,College of Electric Power, South China University of Technology, Guangzhou 510640, China and Shenzhen Power Supply Bureau Co. Ltd., Shenzhen 518001, China
Abstract:Today''s popular study suggests HASH message authentication code(HMAC)method for generic object oriented substation event(GOOSE)to insure message integrity. However, elaborate study finds that HMAC method is not efficient to classic message whose length is short. An authentication method of getting the encrypted key and sequence adjusted information as direct inputs of the HASH function is proposed. GOOSE attributes of explicit length, unified message format and time factor are used in the method to resist length-expanded attacks and replay attacks. The time-varying content of heartbeat GOOSE is reorganized at the end of the message so that the intermediate result of HASH compressive computation to the unvaried content of the same series of heartbeats GOOSE can be efficiently used. Testing results in the embedded platform have proved the high efficiency of the proposed method. This work is supported by National Natural Science Foundation of China(No. 51477057).
Keywords:real-time packet   integrity   authentication   algorithm efficiency
本文献已被 CNKI 等数据库收录!
点击此处可从《电力系统自动化》浏览原始摘要信息
点击此处可从《电力系统自动化》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号