IEC TR 62541-2-2016 OPC unified architecture - Part 2 Security Model《OPC统一架构.第2部分 安全模型》.pdf
《IEC TR 62541-2-2016 OPC unified architecture - Part 2 Security Model《OPC统一架构.第2部分 安全模型》.pdf》由会员分享,可在线阅读,更多相关《IEC TR 62541-2-2016 OPC unified architecture - Part 2 Security Model《OPC统一架构.第2部分 安全模型》.pdf(40页珍藏版)》请在麦多课文档分享上搜索。
1、 IEC TR 62541-2 Edition 2.0 2016-10 TECHNICAL REPORT OPC unified architecture Part 2: Security Model IEC TR 62541-2:2016-10(en) colour inside THIS PUBLICATION IS COPYRIGHT PROTECTED Copyright 2016 IEC, Geneva, Switzerland All rights reserved. Unless otherwise specified, no part of this publication m
2、ay be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and microfilm, without permission in writing from either IEC or IECs member National Committee in the country of the requester. If you have any questions about IEC copyright or have an enquiry
3、about obtaining additional rights to this publication, please contact the address below or your local IEC member National Committee for further information. IEC Central Office Tel.: +41 22 919 02 11 3, rue de Varemb Fax: +41 22 919 03 00 CH-1211 Geneva 20 infoiec.ch Switzerland www.iec.ch About the
4、IEC The International Electrotechnical Commission (IEC) is the leading global organization that prepares and publishes International Standards for all electrical, electronic and related technologies. About IEC publications The technical content of IEC publications is kept under constant review by th
5、e IEC. Please make sure that you have the latest edition, a corrigenda or an amendment might have been published. IEC Catalogue - webstore.iec.ch/catalogue The stand-alone application for consulting the entire bibliographical information on IEC International Standards, Technical Specifications, Tech
6、nical Reports and other documents. Available for PC, Mac OS, Android Tablets and iPad. IEC publications search - www.iec.ch/searchpub The advanced search enables to find IEC publications by a variety of criteria (reference number, text, technical committee,). It also gives information on projects, r
7、eplaced and withdrawn publications. IEC Just Published - webstore.iec.ch/justpublished Stay up to date on all new IEC publications. Just Published details all new publications released. Available online and also once a month by email. Electropedia - www.electropedia.org The worlds leading online dic
8、tionary of electronic and electrical terms containing 20 000 terms and definitions in English and French, with equivalent terms in 15 additional languages. Also known as the International Electrotechnical Vocabulary (IEV) online. IEC Glossary - std.iec.ch/glossary 65 000 electrotechnical terminology
9、 entries in English and French extracted from the Terms and Definitions clause of IEC publications issued since 2002. Some entries have been collected from earlier publications of IEC TC 37, 77, 86 and CISPR. IEC Customer Service Centre - webstore.iec.ch/csc If you wish to give us your feedback on t
10、his publication or need further assistance, please contact the Customer Service Centre: csciec.ch. IEC TR 62541-2 Edition 2.0 2016-10 TECHNICAL REPORT OPC unified architecture Part 2: Security Model INTERNATIONAL ELECTROTECHNICAL COMMISSION ICS 25.040.40; 35.100.01 ISBN 978-2-8322-3641-3 Registered
11、trademark of the International Electrotechnical Commission Warning! Make sure that you obtained this publication from an authorized distributor. colour inside 2 IEC TR 62541-2:2016 IEC 2016 CONTENTS FOREWORD . 4 1 Scope 6 2 Normative references. 6 3 Terms, definitions and abbreviations 8 3.1 Terms a
12、nd definitions 8 3.2 Abbreviations 12 3.3 Conventions for security model figures 12 4 OPC UA security architecture. 12 4.1 OPC UA security environment . 12 4.2 Security objectives 13 4.2.1 Overview 13 4.2.2 Authentication 13 4.2.3 Authorization 13 4.2.4 Confidentiality 14 4.2.5 Integrity . 14 4.2.6
13、Auditability . 14 4.2.7 Availability . 14 4.3 Security threats to OPC UA systems 14 4.3.1 Overview 14 4.3.2 Message flooding . 14 4.3.3 Eavesdropping . 15 4.3.4 Message spoofing 15 4.3.5 Message alteration . 15 4.3.6 Message replay 15 4.3.7 Malformed Messages . 15 4.3.8 Server profiling . 16 4.3.9 S
14、ession hijacking . 16 4.3.10 Rogue Server . 16 4.3.11 Compromising user credentials . 16 4.4 OPC UA relationship to site security 17 4.5 OPC UA security architecture 17 4.6 SecurityPolicies 19 4.7 Security Profiles 20 4.8 User Authorization 20 4.9 User Authentication . 20 4.10 Application Authentica
15、tion . 20 4.11 OPC UA security related Services . 21 4.12 Auditing 21 4.12.1 General 21 4.12.2 Single Client and Server . 22 4.12.3 Aggregating Server 23 4.12.4 Aggregation through a non-auditing Server . 23 4.12.5 Aggregating Server with service distribution 24 5 Security reconciliation 25 5.1 Reco
16、nciliation of threats with OPC UA security mechanisms 25 5.1.1 Overview 25 IEC TR 62541-2:2016 IEC 2016 3 5.1.2 Message flooding . 25 5.1.3 Eavesdropping . 26 5.1.4 Message spoofing 26 5.1.5 Message alteration . 26 5.1.6 Message replay 26 5.1.7 Malformed Messages . 27 5.1.8 Server profiling . 27 5.1
17、.9 Session hijacking . 27 5.1.10 Rogue Server . 27 5.1.11 Compromising user credentials . 27 5.2 Reconciliation of objectives with OPC UA security mechanisms 27 5.2.1 Overview 27 5.2.2 Application Authentication 28 5.2.3 User Authentication 28 5.2.4 Authorization 28 5.2.5 Confidentiality 28 5.2.6 In
18、tegrity . 28 5.2.7 Auditability . 28 5.2.8 Availability . 29 6 Implementation and deployment considerations 29 6.1 Overview. 29 6.2 Appropriate timeouts . 29 6.3 Strict Message processing . 29 6.4 Random number generation 29 6.5 Special and reserved packets 30 6.6 Rate limiting and flow control . 30
19、 6.7 Administrative access 30 6.8 Alarm related guidance 30 6.9 Program access 30 6.10 Audit event management . 31 6.11 Certificate management 31 Bibliography . 36 Figure 1 OPC UA network model 13 Figure 2 OPC UA security architecture . 18 Figure 3 Simple Servers . 22 Figure 4 Aggregating Servers .
20、23 Figure 5 Aggregation with a non-auditing Server . 24 Figure 6 Aggregate Server with service distribution. 25 Figure 7 Manual Certificate handling 32 Figure 8 CA Certificate handling . 33 Figure 9 Certificate handling 34 4 IEC TR 62541-2:2016 IEC 2016 INTERNATIONAL ELECTROTECHNICAL COMMISSION _ OP
21、C UNIFIED ARCHITECTURE Part 2: Security Model FOREWORD 1) The International Electrotechnical Commission (IEC) is a worldwide organization for standardization comprising all national electrotechnical committees (IEC National Committees). The object of IEC is to promote international co-operation on a
22、ll questions concerning standardization in the electrical and electronic fields. To this end and in addition to other activities, IEC publishes International Standards, Technical Specifications, Technical Reports, Publicly Available Specifications (PAS) and Guides (hereafter referred to as “IEC Publ
23、ication(s)”). Their preparation is entrusted to technical committees; any IEC National Committee interested in the subject dealt with may participate in this preparatory work. International, governmental and non- governmental organizations liaising with the IEC also participate in this preparation.
24、IEC collaborates closely with the International Organization for Standardization (ISO) in accordance with conditions determined by agreement between the two organizations. 2) The formal decisions or agreements of IEC on technical matters express, as nearly as possible, an international consensus of
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- IECTR6254122016OPCUNIFIEDARCHITECTUREPART2SECURITYMODELOPC 统一 架构 部分 安全 模型 PDF

链接地址:http://www.mydoc123.com/p-1238093.html