0% found this document useful (0 votes)
7 views13 pages

Cyber Security in Smart Grid Communications

The document surveys the cyber security requirements and vulnerabilities associated with smart grid communications, highlighting the need for secure communication infrastructures as the smart grid integrates power systems with digital technologies. It discusses the challenges posed by cyber threats and the inadequacy of traditional security measures in addressing these risks. The paper also reviews existing solutions and frameworks aimed at enhancing the security of smart grid communications to ensure reliable and efficient operations.

Uploaded by

syeda amira
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
7 views13 pages

Cyber Security in Smart Grid Communications

The document surveys the cyber security requirements and vulnerabilities associated with smart grid communications, highlighting the need for secure communication infrastructures as the smart grid integrates power systems with digital technologies. It discusses the challenges posed by cyber threats and the inadequacy of traditional security measures in addressing these risks. The paper also reviews existing solutions and frameworks aimed at enhancing the security of smart grid communications to ensure reliable and efficient operations.

Uploaded by

syeda amira
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

998 IEEE COMMUNICATIONS SURVEYS & TUTORIALS, VOL. 14, NO.

4, FOURTH QUARTER 2012

A Survey on Cyber Security for Smart Grid


Communications
Ye Yan, Yi Qian, Hamid Sharif and David Tipper

Abstract—A smart grid is a new form of electricity network


with high fidelity power-flow control, self-healing, and energy
reliability and energy security using digital communications and
control technology. To upgrade an existing power grid into a
smart grid, it requires significant dependence on intelligent and
secure communication infrastructures. It requires security frame-
works for distributed communications, pervasive computing and
sensing technologies in smart grid. However, as many of the
communication technologies currently recommended to use by
a smart grid is vulnerable in cyber security, it could lead to
unreliable system operations, causing unnecessary expenditure,
even consequential disaster to both utilities and consumers. In
this paper, we summarize the cyber security requirements and
the possible vulnerabilities in smart grid communications and
survey the current solutions on cyber security for smart grid
communications.
Index Terms—Smart grid communication, cyber security, vul-
nerability, reliability.

I. I NTRODUCTION
OWER industry is integrating the electrical distribution
P system with communication networks to form a two-
directional power and information flow infrastructure, which is
called a smart grid [1]. The integration not only moves power
automation systems from outdated, proprietary technology to
the advanced communication technologies, but also changes
the closed power control systems to the public data net-
works [2]. By adding significant new functionality, distributed
intelligence, and state-of-the-art communication capabilities
Fig. 1. A Smart Grid Communication System [7]
to the power grid, the smart grid infrastructure can be more
efficient, more resilient, and more affordable to manage and
operate [3], [4].
However, it brings not only great performance benefit to the causing substantial damage to distribution, transmission, and
power industry, but also tremendous risks as well as arduous even generation facilities [6].
challenges in protecting the smart grid systems from cyber A typical smart grid communication system, as illustrated
security threats [5]. Considering the vast scale of a smart in Fig. 1, is a horizontal integration of one or more regional
grid, it is reasonable to expect that the cumulative vulnerability control centers, with each center supervising the operation
of the smart grid communication system might also be vast. of multiple power plants and substations. A smart grid
Virtually all parties agree that the consequences of a smart communication system has a layered structure and performs
grid cyber security breach can be enormous. New functions data collection and control of electricity delivery. A regional
such as demand response introduce significant new cyber control center typically support metering system, operation
attack vectors such as a malware that initiates a massive data management, power market operations, power system
coordinated and instantaneous drop in demand, potentially operation and data acquisition control. Substations contain
Remote Terminal Units (RTUs), circuit breaker. Human Ma-
Manuscript received 25 February 2011; revised 5 September 2011 and 22 chine Interfaces (HMIs), communication devices (switches,
November 2011.
Y. Yan, Y. Qian, and H. Sharif are with the Department of Com- hubs, and routers), log servers, data concentrators, and a
puter and Electronics Engineering, University of Nebraska-Lincoln (e-mail: protocol gateway. Intelligent Electronic Device (IEDs) are
yqian@[Link]). field devices, including an array of instrument transducers, tap
D. Tipper is with the Graduate Telecommunications and Networking
Program, University of Pittsburgh. changers, circuit re-closers, phase measuring units (PMUs),
Digital Object Identifier 10.1109/SURV.2012.010912.00035. and protection relays [7].
1553-877X/12/$31.00 
c 2012 IEEE
Authorized licensed use limited to: Maharaja Institute of Tech. Downloaded on June 20,2025 at 04:21:42 UTC from IEEE Xplore. Restrictions apply.
YAN et al.: A SURVEY ON CYBER SECURITY FOR SMART GRID COMMUNICATIONS 999

The legacy cyber security techniques for enterprise net- to achieve higher reliability of supply and reduce operating
works can hardly fit well for the requirements of a smart and maintenance costs. In the past, Sectionalizer Switchgears,
grid communication system to operate securely in the public Ring Main Units, Reclosers and Capacitor Banks were de-
data communication networks such as internet. Compared with signed for local operations with limited remote control. Today,
regular enterprise network systems, smart grid communica- using SCADA over reliable wireless communication links,
tion systems have different goals, objectives and assumptions RTUs provide powerful integrated solutions when upgrad-
concerning what need to be protected in cyber security. It ing remotely installed electric equipment. In a Distribution
is important to guarantee the real time performance and Management System (DMS), RTUs seamlessly interface via
continuous operation features in a smart grid communication SCADA with a wide range of high performance control
system. Those applications are not originally designed for centers supplied by leading vendors worldwide. Connection to
the general enterprise network environment. Therefore, it is these Enterprise Management Systems (EMS) and DA/DMS
necessary to embrace the existing security solutions where control centers is typically provided via a high performance
they fit, such as communication networks within a control IP Gateway or a similar node [11].
center and/or a substation, and develop unique solutions to fill
the gaps where traditional enterprise network cyber security B. Communication Networks
solutions do not work or apply [8].
The operational and commercial demands of electric utili-
Updating a system as complex as the smart grid commu-
ties require a high-performance data communication network
nication infrastructure has the potential of introducing new
that supports both existing functionalities and future opera-
security vulnerabilities into the system. In [9] the author
tional requirements. Such a communication network consti-
presented a review of the work related to smart grid cyber
tutes the core of the electric system automation applications.
security. The work reviewed is separated into five categories
The design of a cost-effective and reliable network architecture
that make up different components of the smart grid: Process
is crucial. In [12], the opportunities and challenges of a
Control System (PCS) Security, Smart Meter Security, Power
hybrid network architecture are discussed for electric system
System State Estimation Security, Smart Grid Communication
automation. Internet based Virtual Private Networks (VPNs),
Protocol Security, and Smart Grid Simulation for Security
power line communications, satellite communications and
Analysis. A smart grid is a large complex system, and it still
wireless communications (wireless sensor networks, WiMAX
requires a lot of cyber security design work.
and wireless mesh networks) are discussed. It provides a brief
In this paper we present a summary of vulnerabilities and
survey on the hybrid network architecture that can support the
potential cyber attacks on smart grid communication systems,
heterogeneous electric system automation application require-
and the major challenges of cyber security in smart grid
ments. A smart grid communication network as a structured
communication systems. It also surveys the existing solutions
framework for electric utilities is planned to utilize new
for cyber security in smart grid communications.
communication technologies for automation, and hence, to
The rest of this paper is organized as follows. In Section II,
make the decision-making process more effective and direct.
the background of smart grid communication security is de-
Different scale and structure of the smart grid systems adopt
scribed. Section III discusses the cyber security requirements
different communication networking solutions. Advanced me-
for smart grid systems. Challenges and current solutions are
tering infrastructure (AMI) solutions can be meshed or point-
discussed in Section IV and V respectively. Finally, Section
to-point, with short local coverage or long range communi-
VI draws the conclusion.
cations [13], [14]. Options for backhaul solutions might be
fiber, wireless broadband, or broadband over power-line. The
II. BACKGROUND possible solutions include WiMax, WLAN, WSN, cellular and
A smart grid communication system is comprised of several LMR, depending on the reliability, throughput, and coverage
subsystems. It is eventually a network of networks. SCADA desired by the utility. The wireless communication solutions
is not only a controlling system but also a communication can be either licensed or unlicensed, again depending on the
network in smart grid. The communication networks in smart needs of the utility. For the highest reliability, licensed should
grid systems could include dedicated or overlayed land mobile be chosen. Each of the above options has their advantages
radios (LMR), cellular, microwaves, fiber optics, wirelines and disadvantages, but what is consistently true of any and
such as power line communications (PLC), RS-232/RS-485 all of the solutions is the need to have a scalable security
serial links, wireless local area networks (WLANs) or a versa- solution [15].
tile data network combining these media [10]. In this section,
we briefly discuss the background of a smart grid system in C. Deployments
several aspects: SCADA system, communication networks and
deployments of secure smart grid communications. Smart grid deployments must meet stringent security re-
quirements. Strong authentication will be required for all
users and devices which may affect the operation of the
A. SCADA grid. With the large number of users and devices affected,
Core to the monitoring and control of a substation is the scalable key and trust management systems, customized to
SCADA system. It is utilized for Distribution Automation the specific needs of the Energy Service Provider, will be
(DA) and computerized remote control of Medium Voltage essential. What has been learned from years of deploying and
(MV) substations and power grids, and it helps electric utilities operating large secure network communication systems is that
Authorized licensed use limited to: Maharaja Institute of Tech. Downloaded on June 20,2025 at 04:21:42 UTC from IEEE Xplore. Restrictions apply.
1000 IEEE COMMUNICATIONS SURVEYS & TUTORIALS, VOL. 14, NO. 4, FOURTH QUARTER 2012

the effort required to provision symmetric keys into thousands a network, gain access to control software, and alter load
of devices can be too expensive or insecure. The development conditions to destabilize the grid in unpredictable ways. The
of key and trust management systems for large networks is high level requirements for smart grid communication security
required; these systems can be leveraged from other indus- are conducted in various organizations and the corresponding
tries, such as land mobile radio systems and Association of standards in details.
Public-Safety Communications Officials (APCO) radio sys- There are many organizations working on the development
tems. Several APCO deployed systems provide state-wide of smart grid security requirements including North American
wireless coverage, with tens of thousands of secure devices. Electrical Reliability Corporation-Critical Infrastructure Pro-
Trust management systems, based on public key infrastructure tection (NERC-CIP [20]), International Society of Automation
(PKI) technology, could be customized specifically for smart (ISA [21]), IEEE 1402 [22], National Infrastructure Protection
grid operators, easing the burden of providing security which Plan (NIPP [23]), and National Institute of Standards and
adheres to the standards and guidelines that are known to be Technology (NIST), which has a number of smart grid cyber
secure [16]. Within three years there are expected to be over security programs on proceeding.
1000 PMUs installed. There will be many more installed in One prominent source of requirements is the Smart Grid
distribution networks to help accommodate intermittent power Interoperability Panel (SGiP) Cyber Security Working Group,
from rooftop solar and electric vehicles. Additionally, PMUs previously the NIST Cyber Security Coordination Task Group
will begin appearing at the terminals of generation equipment, (CSCTG) [24]. The NIST CSCTG was established to ensure
transformers, and large motors. They will be used in large consistency in the cyber security requirements across all the
commercial and residential facilities. One of the key reasons smart grid domains and components. The latest draft document
for redundancy in PMU systems in smart grid is to support from the Cyber Security Working Group, NIST Interagency
the requirements to be able to make security patches to the Report (NIST-IR7628) [25], entitled Smart Grid Cyber Se-
software without lost data. These software patches must be curity Strategy and Requirements, continues to evolve at the
made with no loss of data. The energy company experience time of this writing. NIST and the DoE GridWise Architec-
during the Hurricane Gustav power island event is a clear ture Council (GWAC) [26] have established Domain Expert
example of the value of PMUs for real time operations of the Working Groups (DEWGs): Home-to-Grid (H2G), Building-
grid [17]. to-Grid (B2G), Industrial-to-Grid (I2G), Transmission and
Distribution (T&D) and Business and Policy (B&P).
III. R EQUIREMENTS Working with standards bodies, such as NIST and others,
The reliability of a smart grid depends on the reliability will be extremely important to ensure a highly secure, scalable,
of the control and communication systems. In the develop- consistently deployed smart grid system, as these standards
ment of smart grids, communication systems are becoming bodies will drive the security requirements of the system [27].
more and more sophisticated, allowing for better control and One thing is consistent among the various standards bodies,
higher reliability. Smart grid will require higher degrees of the security of the grid will strongly depend on authentication,
network connectivity to support the new features. Meanwhile, authorization, and privacy technologies. Privacy technologies
the higher degree of connectivity should have corresponding are well matured. Federal Information Processing Standard
sophisticated security protocols to deal with the cyber secu- (FIPS) approved Advanced Encryption Standard (AES) [28]
rity vulnerabilities and breaches. Table I lists some security and Triple Data Encryption Standard (3DES) [29] solutions,
protocols adopted by different layers in communication net- offering strong security and high performance, are readily
works with the specific security requirements, more details available. The specific privacy solution required will depend
are summarized in [18]. In this section, we discuss the high on the type of communication resource being protected. As
level security requirements in general and the major secu- a specific example, NIST has determined that 3DES solution
rity requirements and vulnerabilities in privacy, availability, will likely become insecure by the year 2030. Considering that
integrity, authentication, authorization, auditability, nonrepudi- utility components are expected to have long lifetimes, AES
ability, third-party protection, and trust components for smart would be the preferred solution for new components. However,
grid communications. it is reasonable to expect that under certain circumstances
where legacy functionality must be supported and the risk of
compromise is acceptable, 3DES could be used.
A. High Level Security Requirements Wireless links will be secured with technologies from
According to the Electric Power Research Institute (EPRI), well-known standards such as IEEE 802.11i [30] and IEEE
one of the biggest challenges facing the smart grid deployment 802.16e [31]. Different wireless protocols have varying de-
is related to cyber security of the systems [19]. According to grees of security mechanisms. Wired links will be secured with
the EPRI Report, cyber security is a critical issue due to the firewalls, virtual private networks (VPNs) and IPSec technolo-
increasing potential of cyber attacks and incidents against this gies. Higher layer security mechanisms such as Secure Shell
critical sector as it becomes more and more interconnected. (SSH) and SSL/TLS should also be used [32].
Cyber security must address not only deliberate attacks, such System architects and designers often identify the need for
as from disgruntled employees, industrial espionage, or ter- and specify the use of secure protocols, such as SSH and
rorists, but inadvertent compromises of the information in- IPSec, but then skip the implementation details associated
frastructure due to user errors, equipment failures, and natural with establishing security associations between end points
disasters. Vulnerabilities might allow an attacker to penetrate of communications. Such an approach is likely to result
Authorized licensed use limited to: Maharaja Institute of Tech. Downloaded on June 20,2025 at 04:21:42 UTC from IEEE Xplore. Restrictions apply.
YAN et al.: A SURVEY ON CYBER SECURITY FOR SMART GRID COMMUNICATIONS 1001

TABLE I
L AYERED S ECURITY P ROTOCOLS

Layer Security Protocol Application Confidentiality Integrity Authentication


WS-Security Document Yes Yes Data
PGP/GnuPG Yes Yes
S/MIME Email Yes Yes Message
Application
HTTP Digest Authentication No No User
SSH Yes Yes
Transport SSL/TLS Client-to-Server Yes Yes Server
Network IPSec Host-to-Host Yes Yes Host
CHAP/PAP Point-to-Point No No Client
Link WEP/WAP/802.1X Wireless Access Yes Yes Device

in a smart grid communication system where the necessary systems, as well as the communication systems between these
procedures for secure key management can quickly become elements and to the outside world.
extremely huge and complicated an operational nightmare. Malicious attacks targeting availability can be considered
This is due to the fact that, when system architects do not as denial-of-service (DoS) attacks, which attempt to delay,
develop an integrated and comprehensive key management block or even corrupt information transmission in order to
scheme, customers may be provided with few key management make network resources unavailable to communicating nodes
options, and often resort to manually pre-configuring symmet- that need information exchange in the smart grid. Since it is
ric keys. This approach is simple for the system designers, but widely expected that at least, if not all, part of the smart grid
it can be very expensive for the system owners/operators. will use IP-based protocols (e.g., IEC 61580 [35] has already
adopted TCP/IP as a part of its protocol stacks) and TCP/IP is
B. Privacy vulnerable to DoS attacks. DoS attacks against TCP/IP have
been well studied in the literature regarding attacking types,
Privacy issues have to be covered with the derived customer prevention and response [36]–[38].
consumption data as they are created in metering devices. However, a major difference between a smart grid commu-
Consumption data contains detailed information that can be nication network and the Internet is that the smart grid is more
used to gain insights on a customer’s behavior. concerned with the message delay than the data throughput
Smart grid communications have unintended consequences due to the timing constraint of messages transmitted over the
for customer privacy. Electricity usage information stored power networks. Indeed, network traffic in smart grid commu-
at the smart meter and distributed thereafter acts as an nication networks is in general time-critical. For instance, the
information-rich side channel, exposing customers’ habits and delay constraint of generic object oriented substation events
behaviors. Certain activities, such as watching television, have (GOOSE) messages is 4 ms in IEC 61850.
detectable power consumption signatures. History has shown
Intruders only need to connect to communication channels
that where financial or political incentives align, the techniques
rather than authenticated networks in the smart grid, it is very
for mining behavioral data will evolve quickly to match the
easy for them to launch DoS attacks against the smart grid
desires of those who would exploit that information [33].
communication networks, especially for the wireless-based
Utility companies are not the only sources of potential
communication networks that are susceptible to jamming
privacy abuse. The recently announced Google PowerMeter
attacks [39]–[41]. Hence, it is of critical importance to evaluate
service [34], for instance, receives real-time usage statistics
the impact of DoS attacks on the smart grid and to design
from installed smart meters. Customers subscribing to the
effective countermeasures to such attacks.
service receive a customized web page that visualizes local
usage. Although Google has yet to announce the final privacy
policy for this service, early versions leave the door open to the D. Integrity
company using this information for commercial purposes, such
as marketing individual or aggregate usage statistics to third Integrity refers to preventing undetected modification of
parties. Although services such as Google PowerMeter are information by unauthorized persons or systems. For smart
optional, the customers have less control over the use of power grid communication systems, this applies to information such
information delivered to utility companies. Existing privacy as product recipes, sensor values, or control commands. This
laws in the US are in general a patchwork of regulations objective includes defense against information modification
and guidelines. It is unclear how these or any laws apply to via message injection, message replay, and message delay on
customer energy usage yet. the network. Violation of integrity may cause safety issues,
that is, equipment or people may be harmed.
Different from attacks targeting availability, attacks target-
C. Availability ing data integrity can be regarded as less brute-force yet more
Availability refers to ensuring that unauthorized persons or sophisticated attacks. The target of the integrity attacks is
systems cannot deny access or use to authorized users. For either customer’s information (e.g., pricing information and
smart grid systems, this refers to all the IT elements of the customer account balance) or network operation information
plant, like control systems, safety systems, operator work- (e.g., voltage readings, device running status). In other words,
stations, engineering workstations, manufacturing execution such attacks attempt to deliberately modify the original infor-
Authorized licensed use limited to: Maharaja Institute of Tech. Downloaded on June 20,2025 at 04:21:42 UTC from IEEE Xplore. Restrictions apply.
1002 IEEE COMMUNICATIONS SURVEYS & TUTORIALS, VOL. 14, NO. 4, FOURTH QUARTER 2012

mation in the smart grid communication system in order to itself. The successfully attacked and subverted automation
corrupt critical data exchange in the smart grid. system could be used for various attacks on the communi-
The risk of attacks targeting data integrity in the power cation systems or data or users of external third parties, e.g.,
networks is indeed real. A notable example is the recent via Distributed DoS (DDoS) or worm attacks. Consequences
work [42], which proposed a new type of attacks, called false could reach from a damaged reputation of a smart grid system
data injection attacks, against the state estimation in the power owner up to legal liability for the damages of the third
grid. It assumed that an attacker has already compromised one party. The risk to third parties through possible safety-relevant
or several meters and pointed out that the attacker can take failures of the plant arising out of attacks against the plant
advantage of the configuration of a power system to launch automation system is covered by other security objectives,
attacks by injecting false data to the monitoring center, which most notably authorization/access control.
can legitimately pass the data integrity check used in current
power systems. J. Trust
The new designs of future smart grid communication sys-
E. Authentication tems form a multi-layered architecture. The growth of smart
Authentication is concerned with determination of the true grid systems resulted in a plentifulness of power system
identity of a communication system participator and mapping related software applications, developed in many different
of this identity to a system-internal principal (e.g., valid programming languages and platforms. Extending old appli-
user account) by which this user is known to the system. cations or developing new ones usually involves integrating
Most other security objectives, most notably authorization, legacy systems. Therefore approaching the security of future
distinguish between legitimate and illegitimate users based on smart grid communication networks cannot be done with a
authentication. complete new start.
In parallel to the development of smart grid communication
F. Authorization systems, the complete and monolithic cyber security infras-
tructure is not a viable option. Instead, multi-layer architec-
Authorization, also known as access control, is concerned ture, advanced control methodologies and dependable software
with preventing access to the system by persons or systems infrastructure as well as device protection mechanisms and
without permission to do so. In the wider sense, authorization hardware monitoring anchors have to be specified at the same
refers to the mechanism that distinguishes between legitimate time. Advanced control approaches have to include predictive
and illegitimate users for all other security objectives, e.g., and self-adaptive intelligence at higher level and cross-layer
confidentiality, integrity, etc. In the narrower sense of access mapping to the different technical layers. The dependable
control, it refers to restricting the ability to issue commands to software infrastructures have to be designed to identify and
the plant control system. Violation of authorization may cause isolate higher-layer independent applications as well as to
safety issues. secure cross-layer communications. With such architecture, it
should have the flexibility of incorporating parts of existing
G. Auditability infrastructure with the frontiers and interfaces to adjacent
Auditability is concerned with being able to reconstruct systems. Furthermore, the architecture needs the flexibility
the complete history of the system behavior from historical to interchange or update the part of the system in a secure
records of all (relevant) actions executed on it. This security way at a later stage due to new laws and regulations or new
objective is mostly relevant to discover and find reasons for developments in the energy market [43].
malfunctions in the system after the fact, and to establish the
scope of the malfunction or the consequences of a security IV. CHALLENGES
incident. Note that auditability without authentication may Smart grid is a conglomeration of different legacy systems
serve diagnostic purposes, but does not provide accountability. paired with new technologies and architectural approaches,
based on different standards and regulations that all need to
H. Nonrepudiability be amalgamated into a communication network to support the
Nonrepudiability refers to being able to provide irrefutable challenges of the future electricity network. To support this
proof to a third party of who initiated a certain action in the objective, the cyber security architecture for smart grid com-
system, even if this actor is not cooperating. This security munications are being presented on the basis of cyber security
objective is relevant to establish accountability and liability. and architecture requirements, dependency on legacy installa-
In the context of smart grid systems, this is most important tions, and the regulations and industry standards. This section
regarding to regulatory requirements, violation of this security provides an overview of classifying functions and systems
requirement has typically legal/commercial consequences. in a future smart grid communication network. Furthermore,
it introduces methods for defining security controls and thus
enabling the further development of a compliance process with
I. Third-party Protection regard to trusted connectivity in smart grid communications.
Third-party protection refers to averting damage done to The major challenges in building and operating a secure
third parties via the communication systems, that is, damage smart grid communication system include internetworking,
that does not involve safety hazards of the controlled plant security policy and operations, security services, efficiency and
Authorized licensed use limited to: Maharaja Institute of Tech. Downloaded on June 20,2025 at 04:21:42 UTC from IEEE Xplore. Restrictions apply.
YAN et al.: A SURVEY ON CYBER SECURITY FOR SMART GRID COMMUNICATIONS 1003

scalability, and the differences between enterprise network and B. Security Policy and Operations
smart grid network security.
The reliability of a smart grid depends on the proper
operations of many components and the proper connectivity
A. Internetworking between them [49]. To disrupt a smart grid system, an attacker
The interconnected smart grid communication systems are might attempt to gain electronic access to a component and
riddled with vulnerabilities that vary across the networks due configure it to impersonate as another component and/or report
to the lack of built-in security in many applications and a false condition or alarm. One of the simplest types of attacks
devices. This should not be the model for a network as that an adversary might attempt is the DoS attack, where the
important as the smart grid. Layers of cyber security defense adversary prevents authorized devices from communicating by
of smart grid should be built into the solution to minimize consuming excessive resources on one device. For example,
the threats from interruption, interception, modification, and it is a well-known issue that if a node, such as a server or an
fabrication. access control device, uses an authentication protocol which
is prior to authentication and authorization, then the node may
Keeping the network private, i.e. where all transport facili-
be subject to DoS attacks. Smart grid protocol designers must
ties are wholly owned by a utility, would greatly minimize
ensure that proper care and attention is given to this threat
the threats from intruders, as there would be no potential
during protocol development.
for access from intruders over the Internet. But having a
completely separate network is not feasible in today’s highly Many organizations will be involved in the operations of
connected world. It makes good business sense to reuse a smart grid. As more distributed intelligence entities are
communication facilities, such as the Internet. A minimally added to the smart grid communication network, it will be
secured smart grid connected with Internet as commonly found essential that those entities (people or devices) can authenticate
with commercial networks, opens the grid to threats from and determine the authorization status of other entities from
multiple types of attacks. These include cyber attacks from a remote organization. This issue is commonly referred to
hostile groups looking to cause an interruption to the power as federated identity management. There are many possible
supply [33], [44]. technical solutions to this issue based on different security
One of these cyber attacks is worm infestations which have policies, such as those offered by Security Assertion Markup
proven to negatively impact critical network infrastructures. Language (SAML) [50], Web Services Trust (WS-Trust) [51],
Such threats have largely been the result of leaving a network and PKI [52]. Not only will vendors need to offer consis-
vulnerable to threats from the Internet. For example, there tent technical solutions, but organizations will further need
have been DoS attacks on a single network that disrupted all consistent security policies. Great care must be taken by
directory name servers, thus prohibiting users from connecting organizations to ensure their security policies and practices are
to any of the resources. It demonstrates the fragility of an not in conflict with those of other organizations with which
interconnected smart grid communication infrastructure [45]. they will need interoperability. At least a minimum set of
operational security policies for the organizations operating
All connections to the Internet from a smart grid network
a smart grid is formally adopted and documented in industry
need to be highly secure. Intrusion detection is needed not
only at the points where a smart grid network connects to the standards [53].
Internet, but also critical points within the network as well as
vulnerable wireless interfaces [46].
C. Security Services
The components, systems, networks, and architecture are all
important to the security design and reliability of the smart Managing and maintaining a secure smart grid will be
grid communication solutions. But its inevitable that an inci- as equally vital as developing, deploying and integrating a
dent will occur at some point and one must be prepared with secure smart grid solution. Security services will help network
the proper incident response plan. This can vary between com- operators to identify, control and manage security risks in
mercial providers and private utility networks. A private utility smart grid communications.
network is likely to provide better consistency of the incident According to EPRI, every aspect of a smart grid must
response plan in the event of a security incident, assuming be secure [19]. Cyber security technologies are not enough
the private network is built upon a standardized framework of to achieve secure operations without policies, on-going risk
hardware and software. The speed of the response decreases assessment, and training. The development of these human
exponentially as the number of parties involved increases. focused procedures takes time and needs to take time to ensure
Conversely, a private network would ideally depend on fewer that they are done correctly.
parties, therefore a more efficient incident response process A smart grid requires access to cost-effective, high-
would provide for more rapid response and resolution. The performance security services, including expertise in mobility,
rapidity of the response is critical during situations that involve security, and system integration. These security services can be
a blackout [47]. tailored per utility to best fit their needs and help them achieve
Criticalness of a device or a system also determines how their organizational objectives. Fig. 2 illustrates a typical
prone it will be to attacks. History has shown that private set of security services in smart grid communications [54].
networks by their inherent nature are less prone to attacks. As It describes a framework that operationalizes cyber security
a result, it is recommended as the best approach in situations across the people, process, policy and technology foundations
where security is paramount [48]. of each organization.
Authorized licensed use limited to: Maharaja Institute of Tech. Downloaded on June 20,2025 at 04:21:42 UTC from IEEE Xplore. Restrictions apply.
1004 IEEE COMMUNICATIONS SURVEYS & TUTORIALS, VOL. 14, NO. 4, FOURTH QUARTER 2012

6HFXULW\ protecting data against modification by unauthorized persons


$VVHVVPHQW
,QFLGHQW 6HFXUH'HVLJQ or entities. Data confidentiality refers to the prevention of data
5HVSRQVH DQG
3ODQQLQJ 3HRSOH ,PSOHPHQWDWLRQ
access by unauthorized persons or entities. Maintaining data
availability involves ensuring that no person or entity could
3URFHVV
7HFKQRORJ\ deny access to those authorized users and systems. In smart
0DQDJHG 5LVN grid, the first priority is always human safety. The second
3ROLF\
6HFXULW\ 0DQDJHPHQW priority is to ensure the system reliability. For instance, a cyber
6HFXULW\ attack could create a blackout (system outage), a brownout
3ROLF\ (degraded power quality) or shift the power grid system from
its economically optimal running condition. The third priority
Fig. 2. Smart Grid Security Services [54] is the protection of equipment and power lines [53].
2) Different Security Architecture: In enterprise networks,
D. Efficiency and Scalability the data server resides at the center of the network and requires
more protection than the edge nodes, which are used as access
Ensuring system availability is a high priority in critical points by end users. In smart grid networks, EMS sits at
systems like the smart grid which requires that several key the center (in the control center) whereas RTU/PLCs sit at
issues be addressed. First, the system must be efficient in the edge. Usually, only devices (such as re-closer, circuit
its use of computation and communication resources so that breaker), which are controlled directly by RTU/PLCs, can
resources do not get overwhelmed and all requests can be do harm to human life, operation, or damage equipment and
handled. Second, the system must have good error manage- power lines. EMS/SCADA and data log servers cannot do
ment built in to ensure proper handling of failures (e.g., any damage directly. Therefore, in smart grid communication
those resulting from bad messages). Furthermore, the error systems, edge nodes need a subset of the controls used for
management functions must be fail-safe in nature so they do central devices [56].
not lead to resource exhaustion even in the face of adversarial
3) Different Technology Base: In enterprise networks, Win-
action. Third, the system must have adequate redundancy built
dows, Unix and Linux are widely used as operating systems,
into it so that, if sub-systems fail or are compromised, then
whereas Ethernet is used to connect all devices with IP-
the entire system does not collapse. Fourth, the system should
based protocols. Therefore, common security solutions are
support auxiliary security functions that may be deployed in
designed based on these common architectures. However, in
the smart grid communication system to detect to and respond
current smart grid communication systems, besides the com-
to cyber attacks [49].
mon operating systems above, many utilities use proprietary
Since many existing cyber security scheme such as key
operating systems and networks facilities, and many different
management schemes are not suitable for deployment in smart
communication protocols (IEC61850, DNP 3.0, ICCP, etc.)
grid, in [55] the authors proposed a novel key management
are in use rather than ordinary TCP/IP suits. Thus, it is
scheme which combines symmetric key technique and elliptic
very difficult to develop common host-based or network-based
curve public key technique. The symmetric key scheme is
security solutions for smart grid applications [57].
based on the Needham-Schroeder authentication protocol. The
known threats including the man-in-the-middle attack and the
replay attack can be effectively eliminated under the proposed V. C URRENT S OLUTIONS
scheme. The advantages of the key management scheme for In this section, we survey several existing solutions on cyber
smart grid communication include strong security, scalability, security for smart grid communications. We focus on the tech-
fault-tolerance and efficiency. nologies being deployed, the key smart grid communication
applications being implemented and the outlines of power
E. Differences between Enterprise Network and Smart Grid industry trials that have recently been announced in privacy,
Network Security integrity, authentication and trusted computing.
During the last decade, the IT industry has witnessed
the development of many cyber security solutions to protect
A. Privacy
enterprise networks and to reduce the vulnerabilities to cyber
attacks. From firewalls to intrusion detection systems (IDS) Privacy of smart grid communication systems is important
and Virtual Private Networks (VPN), these solutions have been to the eventual acceptance by the public. Smart grid commu-
quite effective in securing the IT infrastructure at business nications must assure that the communication data preserves
and office automation levels. However, the enterprise network privacy anywhere at anytime.
based cyber security solutions come short of providing the In [44], the authors proposed a method for compressed me-
same level of security at the control and automation levels. ter reading for smart metering in smart grid communications.
There are three major differences between enterprise network The distinguishing feature of the compressed meter reading is
and smart grid network security. that the active smart meters are allowed to transmit simulta-
1) Different Security Objectives: In enterprise networks, neously and the access point (AP) is able to distinguish the
the main security objective is to protect data. The following reports from different smart meters. The simultaneous access
major concerns exist: 1) data integrity; 2) data confidentiality; results in uniform delays, in contrast to the possible large delay
and 3) data availability. Preserving data integrity refers to in carrier sensing multiple access (CSMA) technique. The
Authorized licensed use limited to: Maharaja Institute of Tech. Downloaded on June 20,2025 at 04:21:42 UTC from IEEE Xplore. Restrictions apply.
YAN et al.: A SURVEY ON CYBER SECURITY FOR SMART GRID COMMUNICATIONS 1005

random sequence used in the compressed sensing enhances providing root of trust, (2) a security kernel providing an
the privacy of the meter reading. isolated execution environment for trusted processes whose
In [58], the authors described a method for securely computations and memory are safe from tampering, (3) a cryp-
anonymizing frequent (for example, every few minutes) elec- tographically protected storage for sensitive data decipherable
trical metering data sent by a smart meter. Although such only by the dedicated process, and (4) shielded communication
frequent metering data may be required by a utility or channels with remote processes.
electrical energy distribution network for operational reasons,
2) Process integrity: The integrity of a process essentially
the data may not necessarily be attributable to a specific
depends on the genuineness of its code. It is important not only
smart meter or consumer. However, it needs to be securely
to detect changes in software but also to ensure that newly de-
attributable to a specific location (e.g. a group of houses or
veloped code is trustworthy. A modified code may yield mali-
apartments) within the electricity distribution network. The
cious behavior that would compromise the data. We can ensure
proposed method provides a 3rd party escrow mechanism for
the integrity of a process using fingerprints, i.e., cryptographic
authenticated anonymous meter readings which are difficult
digest or hash functions of its code. When communicating
to associate with a particular smart meter or customer. This
with an ally or competitor process both parties will assure
method does not preclude the provision of attributable meter-
the integrity of each other by comparing stored fingerprints
ing data that is required for other purposes such as billing,
with reported Platform Configuration Registers (PCR) values
account management or marketing research purposes.
before transmitting any data. To enforce process integrity, it
In [59], the authors presented a home electrical power
applies software engineering techniques that enhance software
routing scheme that can be used to moderate the home’s load
security, including safe software architecture and compilation
signature in order to hide appliance usage information. A
techniques for intrusion prevention [67], security specification
power management model using a rechargeable battery with
and management [68], software quality assurance throughout
a power mixing algorithm is proposed. Then, the protection
software lifecycle, and security testing [69].
level is evaluated by proposing three different privacy metrics:
an information theoretic (relative entropy), a clustering classi- 3) Data integrity: Verifying the genuineness of data de-
fication, and a correlation/regression one. This paper sets the pends on whether the data is collected or generated. Collected
ground for further research on the subject of optimizing home data is primitive data given to a process and its integrity is
energy management hiding load signatures. application specific. Some techniques to ensure integrity of
In smart grid communication systems, any stored data collected data are semantic check (i.e., integration of logic
should be encrypted using storage keys shielded similar to into the process to verify data semantics), certificate (i.e.,
the mechanisms proposed in [60]–[62]. While a Storage Root signatures from trusted central authorities), and trusted path
Key (SRK) can be used to develop a key chain by encrypting (i.e., ensuring that the data come from an authenticated user
individual storage keys whose private part will not be exposed or sensing device) [70].
to the host system. The storage keys then may seal potentially Generated data integrity depends on genuineness of the
unlimited data on any medium [63]. process and collected data. Overall, data integrity requires
a chain of trust. Ensuring the integrity of generated data
B. Integrity requires ensuring the integrity of the generating process as
well as the integrity of input data to the process. Ensuring the
Several integrity policy models (e.g., Biba [64], LOMAC integrity of input data requires ensuring the genuineness of
[65], and Clark-Wilson [66]) have been developed to govern the communicating process or the input device.
integrity levels of a system. The Biba model ensures that
processes can not corrupt data in higher levels and are not Integrity evaluation involves verifying the source, its in-
corrupted by data from lower level processes [64]. The tegrity, and freshness of the measurements and requires knowl-
LOMAC model dynamically sets the integrity level of a edge of fingerprints (i.e., SHA-1 hashes) of the code involved
process to the minimum integrity level of data it interacts in blind processing. Secure root processes of the TPM are
with [65]. Similarly, the Clark-Wilson model allows a process utilized to develop authenticators that ensure integrity of
to discard or upgrade the integrity level of data thus allowing processes using the Core Root of Trust for Measurement
it to interact with lower integrity level data [66]. In smart grid (CRTM) [71]–[73]. Moreover, as CRTM performs integrity
communications, however, it might leave the policy decisions measurement at load-time, run-time vulnerabilities will be
to a user but focus on mechanisms to provide security services. detected using run-time attestation [70] and verifiable code
In the following, system integrity, process integrity, and data execution [74].
integrity are discussed: Integrity measurement of a complete interactive system
1) System integrity: System integrity is a binary property is a challenging task, as thousands of measurements and
that indicates whether the system has a trustworthy execu- knowledge of their fingerprints may be required for various
tion environment. Using trusted computing functionalities, software [75], [76]. In [77] the authors investigated the in-
it performs binary attestation to verify the integrity of a tegrity of a known set of processes loaded in a deterministic
system and its enforcement capabilities. Particularly, all parties order and running in an isolated environment from the rest
in blind processing will challenge peers to ensure that the of the processes. Using a security kernel, a system needs to
remote system conforms to Trusted Computing Group (TCG) ensure integrity of the TPM, the BIOS, the security kernel and
specifications with (1) a Trusted Platform Module (TPM) a well-known set of processes providing blind processing.
Authorized licensed use limited to: Maharaja Institute of Tech. Downloaded on June 20,2025 at 04:21:42 UTC from IEEE Xplore. Restrictions apply.
1006 IEEE COMMUNICATIONS SURVEYS & TUTORIALS, VOL. 14, NO. 4, FOURTH QUARTER 2012

M Comm | T | Sign[ H ( M Comm | T ) PRA ] M |T | HMAC ( M |T , K AB )


$ %

Fig. 4. HMAC approach for authentication and integrity [81].


$ %

that was known to A before encrypted it, computes its own


   

M Re spone | T | Sign[ H ( M | T ) PRB ] hash H (MComm |T ), and compares H with H. If they


 
match, then B knows that MComm |T and MComm |T are
Fig. 3. Digital signature approach for authentication and integrity [81]. identical. Therefore, B can conclude that the message must
have been sent by A, since A’s public key can faithfully
decrypt something encrypted by A’s private key only; and that
C. Authentication the combination of message and timestamp were not altered
in transit. To guard against replay, when B confirms that the
Smart grid communications must be authenticated by timestamp it received matches what A tried to send, it will
adding to the information flow transmission to verify whether record the timestamp in its own log. If it receives another
a communication entity is the one that is claimed and the message with the same timestamp later, it knows that the later
transmitted data has integrity [78]. The mechanisms that pro- message must be a replay, and can discard that.
vide authentication usually also provide integrity, the ability The digital signature approach might introduce more com-
to verify that a message has arrived unaltered from its original putational overhead than is necessary. Since confidentiality
state. Authentication and integrity can help smart grid system does not merit as much concern as authentication and integrity
to protect against the most common cyber attacks, including for real-time control in smart grid, an approach that does
man-in-the-middle, forgery, impersonation, and message mod- not require an encryption step, HMAC [82], might be more
ification. Numerous tools exist for providing authentication appropriate. Fig. 4 shows A sends a message M to B at
and integrity, including hashes and keyed hashes such as SHA- time T using HMAC to provide authentication and integrity.
1 or HMAC-SHA-1 and digital signatures such as RSA or A and B share some secret, KAB . Along with M and T,
ECC signatures [79]. A computes and sends to B the HMAC of the combination
One of the sophisticated attacks that authentication proto- M |T . When this message arrives at B, B computes its own
cols must address is the replay attack, in which an adversary HMAC of the combination M |T it received. If the HMAC B
captures messages and replays them to the devices later. A computes matches the HMAC value received from A, then B
message may have dramatically different effects depending can conclude, assuming no other entities have knowledge of
upon when it is received. For example, a message to increase the secret key KAB it shares with A, that A must have sent the
reactive power output by 10 MVAr is appropriate to deal with a message and that no third party altered the combination M |T
low voltage situation. However, if the same message is delayed in transit. Therefore, B has authenticated the sender of the
and resent during a time when the system is experiencing high message and verified the integrity of the contents. Verification
voltages, the result of the same message will be the opposite of message freshness works as that B will maintain a log of
of what was intended. There are two popular ways for helping received timestamps and reject later messages that have an
ensure that a message is fresh and not a replay. If the system identical timestamp to one that appears in the log already.
can support the notion of time and at least loose clock synchro- The reduced computational expense of HMAC makes it the
nization, then timestamps can provide freshness. Therefore, preferred authentication and integrity approach for situations
timestamps have their own constraint on synchronization [80]. where confidentiality is not a primary concern.
Other options include the use of nonces (random numbers) and
sequence numbers. Nonces usually involve an extra message
exchange while sequence numbers, which identify the order of D. Trusted Computing
individual TCP packets, need reliable communication channels Considering the incredible size of the cyber security threat
to ensure synchronization. Any authentication effort must and severe consequences from cyber attacks, the smart grid
provide some way to ensure that a message is current and cyber security protection must be extremely tight to the cyber
not the rebroadcast of a previously sent communication. security requirements. Smart grid communication requires a
In [81], the authors proposed an authentication and integrity comprehensive security plan that encompasses virtually all
approach that used digital signatures and timestamps. Fig. 3 il- aspects of smart grid operations. One component of such
lustrates this approach. Parties A and B reside within the same a plan includes trusted computing. Fig. 5 shows a basic
communication realm. A transmits to B the message MComm trusted computing model [83]. Such platforms and associated
and a timestamp T in plaintext, along with the digital signature mechanisms are used to ensure that malware is not introduced
of the message and timestamp combination, MComm |T . It into software processing devices. The main design goal is the
computes the digital signature by hashing MComm |T and realization of a minimal and therefore manageable, stable and
then encrypting it with its private key P RA . The recipient evaluable security kernel for conventional hardware platforms,
B receives the plaintext message MComm and timestamp T, servers, embedded systems, and mobile devices like PDAs and
along with the digital signature. It decrypts the signature smartphones. All requirements are fulfilled by extracting only
using A’s public key to unwrap the hash H(MComm |T ) security-critical operations and data to the security kernel.
Authorized licensed use limited to: Maharaja Institute of Tech. Downloaded on June 20,2025 at 04:21:42 UTC from IEEE Xplore. Restrictions apply.
YAN et al.: A SURVEY ON CYBER SECURITY FOR SMART GRID COMMUNICATIONS 1007

in the widespread deployment of a number of mobile code

&RQILJXUDWLRQ
$33

$SSOLFDWLRQ
&ULWLFDO
technologies. Mobile code is the code which is downloaded

6HFXULW\
/HJDF\
and run on your PC, typically by your browser, without
2SHUDWLQJ $SSOLFDWLRQ/D\HU the users’ knowledge. Examples of mobile code include Ac-
6\VWHP tiveX, Flash animation, Java, JavaScript, PDF, Postscript, and
Shockwave. The Department of Homeland Security (DHS)
Control System Security Program recommends tight controls
7UXVWHG6RIWZDUH/D\HU
6HFXULW\.HUQHO on mobile code in critical control systems for the nation’s
critical infrastructure and key resources (CIKR) [86].
5HVRXUFH0DQDJHPHQW/D\HU
To address this concern, the adoption of, and adherence
to, strict code signing standards by smart grid suppliers
+DUGZDUHOD\HU 7UXVWHG&RPSXWLQJ6XSSRUW
and operators are proposed. Mechanisms for enforcing such
standards on general purpose computers, such as PCs, have
Fig. 5. Trusted Computing model [83] been put forth by the Trusted Computing Group and are
well documented [87]. Such standards should cover all critical
devices including field deployed units, such as RTU and IED,
There are two categories of devices for which the mal- network devices, such as routers, switches, and firewalls, and
ware protection problems should be considered: embedded control center equipment, such as servers and user consoles.
computer systems and general purpose computer systems. The standards should cover embedded systems, as well as
Embedded systems are computer systems that are designed to general purpose computers, their operating systems, drivers,
perform a specific task or set of tasks. They are intended to run and applications, as well as all mobile codes. That is, no
only software that is supplied by the manufacture. By contrast, mobile code should be allowed to run on a critical PC or
general purpose systems are intended to support third party server that has not been signed by an authority that is able
software purchased by the specific consumer who purchased to determine the trustworthiness of the code. Considering
the system. A PC is an excellent example of a general purpose that it is certain that hardware and software elements for
system. A microwave oven, or cable television set-top box, critical components of the grid will come from many different
are examples of embedded systems. The problem of malware providers, it is likely that a trust management framework will
protection should be considered separately for each category. have to be established for smart grid. This framework will
For embedded systems the problem of protecting the system likely require the establishment of a set of criteria that are
against the installation of malware can be solved with high to be met by vendors who wish to sell critical components
degrees of assurance. First and foremost the manufacturer to smart grid operators. Additionally it is likely that one or
must implement secure software development processes. Many more accreditation organizations will need to be established to
standard models for such processes are defined [84]. Second, audit suppliers to determine that they are meeting the specified
if the device is intended to be field upgradable, the man- criteria [87].
ufacturer must provide a secure software upgrade solution.
The predominant method of doing this is to manufacture the
VI. C ONCLUSION
embedded system hardware with secure storage containing
keying material for a software validation. Typically the hard- As a critical infrastructure, smart grid requires comprehen-
ware is configured with the public key of a secure signing sive solutions for cyber security. A comprehensive communi-
server operated by the manufacturer. With this key, the device cation architecture with security built in from the very begin-
can validate any newly downloaded software prior to running ning is necessary. A smart grid communication security solu-
it. Such a proactive approach can provide higher levels of tion requires a holistic approach including traditional schemes
assurance than can be obtained with a reactive approach such such as PKI technology, trusted computing elements, authen-
as a virus checker. tication mechanisms based on industry standards. Clearly,
For devices which are intended to run for long periods of securing the smart grid communication infrastructure will
time (e.g., years) without booting, it is useful to have a method require the use of standards-based state-of-the-art security
of performing secure software validation on running code. It protocols. To achieve the vision put forth, there are many steps
is possible to have background tasks that can periodically which need to be taken. Primary among them is the need for
perform such functions without disrupting the operations of a cohesive set of requirements and standards for smart grid
the device. It is further possible to couple such background security. Industry and other participants should continue the
validation steps with other operational aspects of the device, work that has begun under the direction of NIST to accomplish
such that if the device is found to be compromised, secure these foundational steps quickly. However, the proper attention
hardware on the device (needed to bring up and maintain se- must be paid to creating the requirements and standards, as
curity associations with remote entities) will prevent the local they will be utilized for many years, given the lifecycle of
device from establishing and maintaining security associations utility components. In this paper, we present the background
with the remote entities. In [85], the authors described some and requirements for smart grid communication security. After
methods to provide remote device attestation. discussing the challenge of smart grid communication security,
To make matters worse, the rapid adoption of cloud comput- the current research and solutions are surveyed. This paper
ing and sophisticated Internet based applications has resulted gives an insight to smart grid communication security in
Authorized licensed use limited to: Maharaja Institute of Tech. Downloaded on June 20,2025 at 04:21:42 UTC from IEEE Xplore. Restrictions apply.
1008 IEEE COMMUNICATIONS SURVEYS & TUTORIALS, VOL. 14, NO. 4, FOURTH QUARTER 2012

architecture features, system designs as well as technical [25] Draft smart grid cyber security strategy and requirements, NIST IR
development. 7628, Sep. 2009 [Online]. Available: [Link]
drafts/nistir-7628/[Link]
[26] S. Widergren, A. Levinson, J. Mater, and R. Drummond, “Smart grid
interoperability maturity model,” in 2010 IEEE Power and Energy
R EFERENCES Society General Meeting, , 2010, pp. 1-6.
[27] S. Rohjans, M. Uslar, R. Bleiker, J. Gonzalez, M. Specht, T. Suding,
[1] C. W. Gellings, M. Samotyj, B. Howe, “The future’s smart delivery
and T. Weidelt, “Survey of Smart Grid Standardization Studies and
system (electric power supply),” IEEE Power and Energy Mag., vol.2,
Recommendations,” in First IEEE International Conference on Smart
no.5, pp. 40-48, Sept.-Oct. 2004.
Grid Communications (SmartGridComm 2010), pp. 583-588, 2010.
[2] H. Farhangi, “The path of the smart grid,” IEEE Power and Energy
[28] National Institute of Standards and Technology, “Announcing the Ad-
Mag., vol. 8, pp. 18-28, 2010.
vanced Encryption Standard (AES),” in Federal Information Processing
[3] S. M. Amin, B. F. Wollenberg, “Toward a smart grid: power delivery
Standards Publication, Nov. 26, 2001.
for the 21st century,” IEEE Power and Energy Mag., vol.3, no.5, pp.
[29] National institute of Standards and Technology, “Data Encryption Stan-
34-41, Sept.-Oct. 2005.
dard,” Federal Information Processing Standards (FIPS) Publication 46-
[4] Litos Strategic Communication “The Smart Grid: An Introduction ,” 31
7, USA, 1999.
May 2009 [Online]. Available: [Link]
/DocumentsandMedia/DOE SG Book Single [Link] [30] IEEE Std 802.11i, “IEEE Standard for Information Technology-
Telecommunications and Information Exchange Between Systems- Lo-
[5] H. Khurana, M. Hadley, L. Ning, and D. A. Frincke, “Smart-grid security
issues,” IEEE Security and Privacy, vol. 8, pp. 81-85, 2010. cal and Metropolitan Area Networks- Specific Requirements Part 11:
Wireless LAN Medium Access Control (MAC) and Physical Layer
[6] S. Clements, H. Kirkham, “Cyber-security considerations for the smart
(PHY) Specifications Amendment 6: Medium Access Control (MAC)
grid,” in IEEE Power and Energy Society General Meeting 2010, pp.
Security Enhancements,” pp. 1-175, 2004.
1-5, 2010.
[31] IEEE Std 802.16e, “IEEE Standard for Local and Metropolitan Area
[7] C. H. Hauser, D. E. Bakken, A. Bose, “A Failure to Communicate,”
Networks Part 16: Air Interface for Fixed and Mobile Broadband
IEEE Power and Energy Mag., pp. 47-55, Mar- Apr, 2005.
Wireless Access Systems Amendment 2: Physical and Medium Access
[8] J. Fan, S. Borlase, “The evolution of distribution,” IEEE Power and
Control Layers for Combined Fixed and Mobile Operation in Licensed
Energy Mag., vol. 7, pp. 63-68, 2009.
Bands and Corrigendum 1,” pp. 1-822, 2006.
[9] T. Baumeister, “Literature Review on Smart Grid Cyber Security,” Tech
[32] A. Bendahmane, M. Essaaidi, A. El Moussaoui, and A. Younes, “Grid
Report, 2010.
computing security mechanisms: State-of-the-art,” in International Con-
[10] C. Lo and N. Ansari, “The Progressive Smart Grid System from
ference on Multimedia Computing and Systems (ICMCS ’09), pp. 535-
Both Power and Communications Aspects,” IEEE Commun. Surveys
540, 2009.
& Tutorials, pp. 1-23, 2011.
[33] P. McDaniel and S. McLaughlin, “Security and Privacy Challenges in
[11] S. Hong, and M. Lee, “Challenges and Direction toward Secure Com-
the Smart Grid,” IEEE Security & Privacy, vol. 7, pp. 75-77, 2009.
munication in the SCADA System,” in Eighth Annual Communication
Networks and Services Research Conference (CNSR 2010), pp.381-386, [34] K. Allan, “Power to the people [power energy saving],” Engineering &
2010. Technology, vol. 4, pp. 46-49, 2009.
[12] V. C. Gungor and F. C. Lambert, “A survey on communication networks [35] T. S. Sidhu and Y. Yin, “Modelling and simulation for performance eval-
for electric system automation,” Computer Networks, vol. 50, pp. 877- uation of IEC61850-based substation communication systems,” IEEE
897, 2006. Trans. Power Del., vol. 22, no. 3, pp. 1482C1489, July 2007.
[13] L. Wenpeng, D. Sharp, and S. Lancashire, “Smart grid communication [36] C. L. Schuba, I. V. Krsul, M. G. Kuhn, E. H. Spafford, A. Sundaram,
network capacity planning for power utilities,” in IEEE Transmission and D. Zamboni, “Analysis of a denial of service attack on tcp,” in Proc.
and Distribution Conference and Exposition, pp.1-4, 2010. IEEE Symposium on Security and Privacy (S&P 1997), May 1997.
[14] E. Liu, M. L. Chan, C. W. Huang, N. C. Wang, and C. N. Lu, [37] A. Yaar, A. Perrig, and D. Song, “Pi: A path identification mechanism
“Electricity grid operation and planning related benefits of advanced to defend against DDoS attacks,” in Proc. IEEE Symposium on Security
metering infrastructure,” in 5th International Conference on Critical and Privacy (S&P 2003), 2003.
Infrastructure (CRIS2010), pp. 1-5, 2010. [38] J. Mirkovic and P. Reiher, “A taxonomy of DDoS attack and DDoS
[15] P. P. Parikh, M. G. Kanabar, and T. S. Sidhu, “Opportunities and defense mechanisms,” SIGCOMM Comput. Commun. Rev., vol. 34, no.
challenges of wireless communication technologies for smart grid appli- 2, pp. 39C53, 2004.
cations,” in IEEE Power and Energy Society General Meeting,pp. 1-7, [39] M. Strasser, S. Capkun, C. Popper, and M. Cagalj, “Jamming-resistant
2010. key establishment using uncoordinated frequency hopping,” in Proc.
[16] A. R. Metke; R. L. Ekl, “Security Technology for Smart Grid Networks,” IEEE Symposium on Security and Privacy (S&P 2008), May 2008, pp.
IEEE Trans. Smart Grid, vol. 1, pp. 99-107, 2010. 64C78.
[17] C. H. Wells, A. Moore, K. Tjader, and W. Isaacs, “Cyber secure [40] C. Popper, M. Strasser, and S. Capkun, “Jamming-resistant broadcast
synchrophasor platform,” in IEEE/PES Power Systems Conference and communication without shared keys,” in Proc. 18th USENIX Security
Exposition (PSCE 2011), pp. 1-4, 2011. Symposium (Security 09), Aug. 2009.
[18] D. Dzung, M. Naedele, T. P. Von Hoff, and M. Crevatin, “Security [41] Y. Liu, P. Ning, H. Dai, and A. Liu, “Randomized differential DSSS:
for Industrial Communication Systems,” Proc. IEEE, vol. 93, pp. 1152- Jamming-resistant wireless broadcast communication,” in Proc. 29th
1177, 2005. IEEE Conference on Computer Communications (INFOCOM 10), Mar.
[19] Report to NIST on Smart Grid Interoperability Standards Roadmap 2010.
EPRI, Jun. 17, 2009 [Online]. Available: [Link] [42] Y. Liu, P. Ning, and M. Reiter, “False data injection attacks against
[Link] state estimation in electric power grids,” in Proc. ACM Conference on
[20] M. Zafirovic-Vukotic, R. Moore, M. Leslie, R. Midence, and M. Computer and Communications Security (CCS 09), Sept. 2009.
Pozzuoli, “Secure SCADA network supporting NERC CIP,” in Power [43] N. Kuntze, C. Rudolph, M. Cupelli, J. Liu, and A. Monti, “Trust
& Energy Society General Meeting, 2009. PES ’09. IEEE, 2009, pp. infrastructures for future energy networks,” in IEEE Power and Energy
1-8. Society General Meeting 2010, pp. 1-7, 2010.
[21] J. M. Guerrero, J. C. Vasquez, J. Matas, L. G. de Vicuna, and M. Castilla, [44] L. Husheng, M. Rukun, L. Lifeng, and R. C. Qiu, “Compressed Meter
“Hierarchical Control of Droop-Controlled AC and DC Microgrids: A Reading for Delay-Sensitive and Secure Load Report in Smart Grid,”
General Approach Toward Standardization,” Industrial Electronics, IEEE in First IEEE International Conference on Smart Grid Communications
Transactions on, vol. 58, pp. 158-172, 2011. (SmartGridComm2010), pp. 114-119, 2010.
[22] IEEE Guide for Electric Power Substation Physical and Electronic [45] G. Carl, G. Kesidis, R. R. Brooks, and R. Suresh, “Denial-of-service
Security, IEEE Std 1402-2000, 2000. attack-detection techniques,” IEEE Internet Computing, vol. 10, pp. 82-
[23] D. Dumont, “Cyber security concerns of Supervisory Control and Data 89, 2006.
Acquisition (SCADA) systems,” in IEEE International Conference on [46] S. Kent, “On the trail of intrusions into information systems,” IEEE
Technologies for Homeland Security (HST 2010), pp. 473-475, 2010. Spectrum, vol. 37, pp. 52-56, 2000.
[24] T. Zhang, W. M. Lin, Y. F. Wang, S. Deng, C. C. Shi, and L. Chen, [47] C. W. Ten, G. Manimaran, and C. C. Liu, “Cybersecurity for Critical
“The design of information security protection framework to support Infrastructures: Attack and Defense Modeling,” IEEE Trans. Systems,
Smart Grid,” in International Conference on Power System Technology Man and Cybernetics, Part A: Systems and Humans, vol.40, no.4,
(POWERCON 2010), pp. 1-5, 2010. pp.853-865, July 2010.
Authorized licensed use limited to: Maharaja Institute of Tech. Downloaded on June 20,2025 at 04:21:42 UTC from IEEE Xplore. Restrictions apply.
YAN et al.: A SURVEY ON CYBER SECURITY FOR SMART GRID COMMUNICATIONS 1009

[48] W. Dong, L. Yan, M. Jafari, P. Skare, and K. Rohde, “An integrated [73] F. C. Schweppe and J. Wildes, “Power system static-state estimation,”
security system of protecting Smart Grid against cyber attacks,” in IEEE Trans. Power App. Syst., pp. 120-125, Jan, 1970.
Innovative Smart Grid Technologies (ISGT 2010), pp. 1-7, 2010. [74] A. Seshadri, M. Luk, E. Shi, A. Perrig, L. van Doorn, and P. Khosla, “Pi-
[49] M. Jensen, C. Sel, U. Franke, H. Holm, and L. Nordstrom, “Availability oneer: Verifying integrity and guaranteeing execution of code on legacy
of a SCADA/OMS/DMS system - A case study,” in IEEE Innovative platforms,” In ACM Symposium on Operating Systems Principles, pp.
Smart Grid Technologies Conference Europe (ISGT Europe 2010), pp.1- 1-15, Oct. 2005.
8, 2010. [75] J. M. McCune, A. Perrig, A. Seshadri, and L. van Doorn, “Turtles all the
[50] T. Komura, Y. Nagai, S. Hashimoto, M. Aoyagi, and K. Takahashi, way down: research challenges in user-based attestation,” In proceedings
“Proposal of Delegation Using Electronic Certificates on Single Sign- of the 2nd USENIX workshop on Hot topics in security (HOTSEC07),
On System with SAML-Protocol,” in Ninth Annual International Sym- pp. 1-5, Berkeley, CA, USA, 2007.
posium on Applications and the Internet (SAINT ’09), pp. 235-238, [76] F. Stumpf, A. Fuchs, S. Katzenbeisser, and C. Eckert, “Improving the
2009. scalability of platform attestation,” In Proc. 3rd ACM workshop on
[51] C. Yongkai and T. Shaohua, “Security Scheme for Cross-Domain Scalable trusted computing (STC 08), pp. 1-10, New York, NY, USA,
Grid: Integrating WS-Trust and Grid Security Mechanism,” in Interna- 2008.
tional Conference on Computational Intelligence and Security(CIS ’08), [77] M. H. Gunes and C. Y. Evrenosoglu, “Blind processing: Securing data
pp.453-457, 2008. against system administrators,” in IEEE/IFIP Network Operations and
[52] R. Perlman, “An overview of PKI trust models,” IEEE Network, vol. Management Symposium Workshops (NOMS Wksps 2010), pp. 304-
13, pp. 38-43, 1999. 311, 2010.
[53] R. J. Thomas, “Putting an action plan in place,” IEEE Power and Energy [78] International Standards Organization and International Electrotechnical
Mag., vol. 7, pp. 26-31, 2009. Commission, ISO/IEC 9798-1:1997 Information Technology-Security
[54] A. R. Metke and R. L. Ekl, “Smart Grid Security Technology,” in Techniques- Entity Authentication Parts.
Innovative Smart Grid Technologies (ISGT2010), pp. 1-7, 2010. [79] W. Stallings, “Network security essentials : applications and standards.”
[55] D. Wu and C. Zhou, “Fault-tolerant and scalable key management for Boston: Prentice Hall, 2011.
smart grid,” IEEE Trans. Smart Grid, vol. 2, pp. 375-381, 2011. [80] R. J. Anderson, R. M. Needham, “Robustness principles for public
[56] T. M. Overman, R. W. Sackman, “High assurance smart grid: smart key protocols,” in Proc. 15th Annu. Int. Cryptology Conf. Advances
grid control systems communications architecture,” in First IEEE Inter- in Cryptology (CRYPTO95), pp. 236-247,1995.
national Smart Grid Communications (SmartGridComm 2010), Confer- [81] K. M. Rogers, R. Klump, H. Khurana, A. A. Aquino-Lugo, and T. J.
ence, pp.19-24, 2010. Overbye, “An Authenticated Control Framework for Distributed Voltage
[57] E. Santacana, G. Rackliffe, L. Tang, X.M. Feng, “Getting smart,” IEEE Support on the Smart Grid,” IEEE Trans. Smart Grid, vol. 1, pp. 40-47,
Power and Energy Mag., vol. 8, pp. 41-48, 2010. 2010.
[58] C. Efthymiou and G. Kalogridis, “Smart Grid Privacy via Anonymiza- [82] Q. Dang, “Recommendation for Applications Using Approved Hash
tion of Smart Metering Data,” in First IEEE International Conference Algorithms” National Institute of Standards and Technology Special
on Smart Grid Communications (SmartGridComm 2010), pp. 238-243, Publication, 2009.
2010. [83] European Multilaterally Secure Computing Base, “Towards trustworthy
[59] G. Kalogridis, C. Efthymiou, S. Z. Denic, T. A. Lewis, and R. Cepeda, systems with open standards and trusted computing,” 2005 [Online]
“Privacy for Smart Meters: Towards Undetectable Appliance Load Available: [Link]
Signatures,” in First IEEE International Conference on Smart Grid [84] N. Davis, “Secure software development life cycle processes,” Software
Communications (SmartGridComm 2010), pp. 232-237, 2010. Eng. Inst., Carnegie Mellon Univ., 2009.
[60] E. Cesena, G. Ramunno, and D. Vernizzi, “Secure storage using a sealing [85] M. Shaneck, K. Mahadevan, V. Kher, and Y. Kim, “Remote software
proxy,” In Proc. 1st European Workshop on System Security, pages 27- based attestation for wireless sensors,” Comput. Sci. Eng., Univ. Min-
34, New York, NY, USA, 2008. nesotał Twin Cities, 2005
[61] U. Kühn, M. Selhorst, and C. Stüble, “Realizing property-based attesta- [86] U. S. Department of Homeland Security “Catalog of Control Systems
tion and sealing with commonly available hard and software,” In Proc. Security: Recommendations for Standards Developers,” Sep. 2009.
2007 ACM workshop on Scalable trusted computing, pp. 50-57, New [87] D. Challener, K. Yoder, R. Catherman, D. Safford, and L. V. Doorn , “A
York, NY, USA, 2007. Practical Guide to Trusted Computing”, Upper Saddle River, NJ: IBM
[62] U. Kühn and C. Stüble, “User-friendly and secure tpm-based hard disk Press.
key management,” In Proc. First International Conference Future of
Trust in Computing, pp. 171-177, Berlin, Germany, 2009.
[63] H. S. Fhom, N. Kuntze, C. Rudolph, M. Cupelli, J. Liu, and A. Monti, “A
user-centric privacy manager for future energy systems,” in International
Conference on Power System Technology (POWERCON2010), pp. 1-7, Ye Yan is the Ph.D. student in the Department of
2010. Computer and Electronics Engineering at University
[64] K. J. Biba, “Integrity considerations for secure computer systems,” of Nebraska-Lincoln. He has published several re-
Technical report, MITRE Corp., Apr, 1977. search articles in international journals and confer-
[65] T. Fraser, “Lomac: Low water-mark integrity protection for cots envi- ences. He has been serving as TPC members on
ronments,” In IEEE Symposium on Security and Privacy, pp. 230C245, IEEE conferences and reviewers for many inter-
2000. national journals and conferences. He is a student
[66] D. D. Clark and D. R. Wilson, “A Comparison of Commercial and member of IEEE.
Military Computer Security Policies,” In IEEE Symposium on Security
and Privacy, pp. 184-194, 1987.
[67] D. Kirovski, M. Drinic, and M. Potkonjak, “Enabling trusted soft-
ware integrity,” In proceedings of the 10th international conference
on Architectural support for programming languages and operating
systems(ASPLOS-X), pp. 108-120, New York, NY, USA, 2002.
[68] I. Sommerville, “Software Engineering,” Addison-Wesley, 8th edition,
2007.
[69] R. S. Pressman, “Software Engineering: A Practitioners Approach,”
McGraw Hill, 7th edition, 20010.
[70] E. Shi and A. Perrig, “Bind: A fine-grained attestation service for secure
distributed systems,” In IEEE Symposium on Security and Privacy, pp.
154-168, 2005.
[71] M. Alam, X. Zhang, M. Nauman, T. Ali, and J.-P. Seifert, “Model-
based behavioral attestation,” In Proc. 13th ACM symposium on Access
control models and technologies (SACMAT 08), pp. 175-184, New York,
NY, USA, 2008.
[72] R. Sailer, T. Jaeger, X. Zhang, and L. V. Doorn, “Attestation-based policy
enforcement for remote access,” In 11th ACM conference on Computer
and Communications Security, pp. 308-317, 2004.
Authorized licensed use limited to: Maharaja Institute of Tech. Downloaded on June 20,2025 at 04:21:42 UTC from IEEE Xplore. Restrictions apply.
1010 IEEE COMMUNICATIONS SURVEYS & TUTORIALS, VOL. 14, NO. 4, FOURTH QUARTER 2012

Yi Qian is an Assistant Professor in the Department Hamid Sharif is the Charles J. Vranek Professor
of Computer and Electronics Engineering, Univer- of the College of Engineering at the University of
sity of Nebraska-Lincoln (UNL). His research in- Nebraska-Lincoln. He is also the Director of the
terests include information assurance and network Advanced Telecommunications Engineering Labo-
security, network design, network modeling, simu- ratory (TEL) at University of Nebraska. Professor
lation and performance analysis for next generation Sharif has published a large number of research
wireless networks, wireless ad-hoc and sensor net- articles in international journals and conferences
works, vehicular networks, broadband satellite net- and has been the recipient of a number of best
works, optical networks, high-speed networks and paper awards. Dr. Sharif has been serving on many
the Internet. Prior to joining UNL, he worked in IEEE and other international journal editorial boards
the telecommunications industry, academia, and the and currently is the co-editor-in-chief for the Wiley
U.S. government. Some of his previous professional positions include serving Journal of Security and Communication Networks. He has contributed to the
as a senior member of scientific staff and a technical advisor at Nortel IEEE in many roles including the elected Chair of the Nebraska Section,
Networks, a senior systems engineer and a technical advisor at several start-up elected Chair of the Nebraska Computer Chapter, elected Chair of the
companies, an Assistant Professor at University of Puerto Rico at Mayaguez, Nebraska Communications Chapter, and the Chapter Coordinator for the IEEE
and a senior researcher at National Institute of Standards and Technology. He Region 4 in US.
has a successful track record to lead research teams and to publish research
results in leading scientific journals and conferences. Several of his recent
journal articles on wireless network design and wireless network security are
among the most accessed papers in the IEEE Digital Library. Dr. Yi Qian is
a member of ACM and a senior member of IEEE. He is currently serving as David Tipper is an Associate Professor and Director
the Vice Chair for Conferences - Communications and Information Security of the Graduate Telecommunications and Network-
Technical Committee (CISTC) for IEEE Communications Society. He is also ing Program at the University of Pittsburgh. He
serving as the IEEE Communications Society CISTC Representative to the is a graduate of the University of Arizona (Ph.D.
Ad Hoc Committee on Smart-Grid Communications. EE, M.S.S.I.E.) and Virginia Tech (B.S.E.E.). His
current research focuses on network design, energy
efficiency, information assurance techniques, time
varying network performance analysis and control.

Authorized licensed use limited to: Maharaja Institute of Tech. Downloaded on June 20,2025 at 04:21:42 UTC from IEEE Xplore. Restrictions apply.

Common questions

Powered by AI

The main challenges in building a secure smart grid communication system include internetworking, security policy and operations, security services, efficiency, and scalability. These differ from securing enterprise networks as the smart grid security focuses primarily on human safety and system reliability, whereas enterprise networks prioritize data integrity, confidentiality, and availability . In terms of architecture, smart grid networks have control systems like EMS at the center, whereas enterprise networks focus on protecting a central data server. Thus, these challenges necessitate distinct approaches in security design for smart grids .

Integrating existing infrastructure with new smart grid technologies offers opportunities such as leveraging existing investments and ensuring continuity of operations. However, it also poses challenges including compatibility issues, increased system complexity, and potential security vulnerabilities from legacy systems that do not align with modern cybersecurity standards. Successfully overcoming these challenges requires careful planning and advanced architectural designs that can adapt to both old and new components .

False data injection attacks involve an attacker compromising one or several meters to inject bogus data into the power grid's monitoring systems. This type of attack is sophisticated as it bypasses data integrity checks that current systems rely on, by exploiting system configuration vulnerabilities. Unlike brute-force attacks, these are tactical in compromising critical operational data such as state estimations, thus potentially leading to incorrect decision-making and system instability .

Using a combination of symmetric key and elliptic curve public key techniques in smart grid networks is highly effective. This approach offers strong security features, as elliptic curve cryptography ensures secure exchange of keys over potentially insecure networks, while symmetric keys facilitate fast and efficient encryption of communication. This combination also supports scalability and fault-tolerance, making it well-suited to the dynamic and broad-ranging requirements of smart grid systems .

In enterprise networks, security objectives focus on protecting data integrity, confidentiality, and availability to prevent unauthorized modifications, access, or denials. In contrast, smart grid networks prioritize human safety, system reliability, and equipment protection. This differentiation is critical because it influences the design and implementation of protective measures; ensuring human safety and systems reliability dictate a different approach and prioritization compared to data-centric objectives in enterprises .

Authentication and authorization are crucial in smart grid cybersecurity as they ensure that only legitimate users and systems access the network. Authentication confirms the true identity of users or systems, which is the foundational step for securing interactions. Authorization determines the access levels and permissions for authenticated users, preventing unauthorized activities across the system, thus protecting data confidentiality and integrity and safeguarding the system operations .

Robust error management in smart grid systems ensures that failures, such as those from malicious messages, are handled properly without causing further resource exhaustion. It is vital in defending against cyber threats as it includes mechanisms for detecting, responding to, and recovering from errors or attacks, thus maintaining operational integrity and preventing system failures that adversaries could exploit to disrupt services .

Jamming-resistant broadcast communication can significantly enhance security in smart grid communications by mitigating the vulnerabilities of wireless-based systems to jamming attacks. Techniques such as DSSS (Direct-Sequence Spread Spectrum) or frequency hopping enable communication to sustain service levels even under attempts of signal interference. By protecting the communication channel’s reliability and availability, it maintains critical operations against intentional disruptions .

DoS attacks can severely impact smart grid communication networks by disrupting time-critical communications, such as GOOSE messages which have a 4 ms delay constraint as per IEC 61850. The easy access to communication channels by intruders makes wireless-based systems particularly vulnerable to jamming attacks. Such disruptions can lead to delays or failures in critical data exchanges, affecting the reliability and safety of power operations .

Flexibility in smart grid communication architecture allows for the integration of existing legacy systems with new technologies, adjustments to regulatory changes, and the incorporation of technological advancements. This can be achieved through architectures that isolate applications to maintain independent operations while securing cross-layer communications, ensuring compliance and adapting dynamically to market and regulatory developments .

You might also like