密钥管理是智能变电站信息安全防护措施成功实施的关键,密钥管理方案设计的难点在于结合智能变电站通信特点与安全需求,平衡安全性和效率。文中在分析智能变电站通信特点及其报文安全需求、Needham-Schroeder密钥管理方案应用于智能变电站可行性的基础上,提出一种基于改进NSSK协议的智能变电站密钥管理方案,给出该方案中密钥生成、分发、更新、销毁的详细流程及其产生问题的解决办法,分析该方案的密钥安全性、抗伪造攻击性、抗中间人攻击性、抗重放攻击性、前向和后向安全性、运算和传输时间开销,采用BAN逻辑判断该方案的有效性。分析结果表明,所提密钥管理方案对常见的攻击有较好的抵抗性,具有较少的运算和传输时间开销,能满足智能变电站信息安全需求。
Key management is the crucial part of cyber security defense in the smart substation.Difficulties in designing the key management scheme are balancing security and efficiency,combing with communication characteristics and security requirements of the smart substation.After analyzing the message security requirements and feasibility of Needham-Schroeder key management scheme applied in the smart substation,a key management scheme of smart substation based on the improved NSSK protocol is proposed.The detailed flow and solutions to the issues of generation,distribution,update,and destructionoy of the key are provided.And the key security,anti-forgery attacks,anti-middle attacks,anti-replay attacks,forward and backward security,operation and transmission time costs of the scheme are analyzed.The validity of the key management scheme is judged by the BAN logic.The analyzing results show that the key management scheme proposed has good resistance to the attacks above and lower computation and transmission time cost,satisfying the requirements of cyber security in the smart substation.