BS DD IEC TS 62351-4-2007 Power systems management and associated information exchange - Data and communications security - Profiles including MMS《动力系统管理和相关的信息交换 数据和通信安全 包括MMS的剖面》.pdf
《BS DD IEC TS 62351-4-2007 Power systems management and associated information exchange - Data and communications security - Profiles including MMS《动力系统管理和相关的信息交换 数据和通信安全 包括MMS的剖面》.pdf》由会员分享,可在线阅读,更多相关《BS DD IEC TS 62351-4-2007 Power systems management and associated information exchange - Data and communications security - Profiles including MMS《动力系统管理和相关的信息交换 数据和通信安全 包括MMS的剖面》.pdf(18页珍藏版)》请在麦多课文档分享上搜索。
1、 g49g50g3g38g50g51g60g44g49g42g3g58g44g55g43g50g56g55g3g37g54g44g3g51g40g53g48g44g54g54g44g50g49g3g40g59g38g40g51g55g3g36g54g3g51g40g53g48g44g55g55g40g39g3g37g60g3g38g50g51g60g53g44g42g43g55g3g47g36g58exchange Data and communications security Part 4: Profiles including MMS ICS 33.200Power systems ma
2、nagement and associated information DRAFT FOR DEVELOPMENTDD IEC/TS 62351-4:2007DD IEC/TS 62351-4:2007This Draft for Development was published under the authority of the Standards Policy and Strategy Committee on 31 July 2007 BSI 2007ISBN 978 0 580 56446 8to withdraw it. Comments should be sent to th
3、e Secretary of the responsible BSI Technical Committee at British Standards House, 389 Chiswick High Road, London W4 4AL.The UK participation in its preparation was entrusted to Technical Committee PEL/57, Power systems management and associated information exchange.A list of organizations represent
4、ed on this committee can be obtained on request to its secretary.This publication does not purport to include all the necessary provisions of a contract. Users are responsible for its correct application.Amendments issued since publicationAmd. No. Date Commentsresponsible for its conversion to an in
5、ternational standard. A review of this publication will be initiated not later than 3 years after its publication by the international organization so that a decision can be taken on its status. Notification of the start of the review period will be made in an announcement in the appropriate issue o
6、f Update Standards.According to the replies received by the end of the review period, the responsible BSI Committee will decide whether to support the conversion into an international Standard, to extend the life of the Technical Specification or National forewordThis Draft for Development is the UK
7、 implementation of IEC/TS 62351-4:2007.This publication is not to be regarded as a British Standard.It is being issued in the Draft for Development series of publications and is of a provisional nature. It should be applied on this provisional basis, so that information and experience of its practic
8、al application can be obtained.Comments arising from the use of this Draft for Development are requested so that UK experience can be reported to the international organization TECHNICAL SPECIFICATION IECTS 62351-4First edition2007-06Power systems management and associated information exchange Data
9、and communications security Part 4: Profiles including MMS Reference number IEC/TS 62351-4:2007(E) DD IEC/TS 62351-4:2007CONTENTS 1 Scope and object3 1.1 Scope3 1.2 Object .3 2 Normative References 3 3 Terms and definitions .4 4 Security issues addressed by this technical specification4 4.1 Security
10、 for application and transport profiles4 4.2 Security threats countered.5 4.3 Attack methods countered .5 5 A-Profile security5 5.1 MMS .6 5.2 Logging .6 5.3 ACSE 6 5.3.1 Peer entity authentication 6 5.3.2 AARQ9 5.3.3 AARE 96 T-Profile security 9 6.1 TCP T-Profiles.9 6.1.1 Conformance to this techni
11、cal specification .9 6.1.2 Use of TLS in TCP T-Profiles.9 6.1.3 TP0 .10 6.1.4 RFC 100611 6.1.5 TLS requirements 11 6.1.6 Use of TLS 11 6.2 OSI T-Profiles .12 6.3 Certificate authority support 13 7 Conformance13 7.1 General conformance 13 7.2 Conformance of IEC 60870-6 TASE.2 security 13 Bibliography
12、14 Figure 1 Application and transport profiles .5 Figure 2 Non-secure and secure TCP T-Profiles IEC 62351.10 Table 1 TP0 maximum sizes 10 Table 2 Recommended cipher suite combinations12 Table 3 Supported cipher suites.13 DD IEC/TS 62351-4:2007 2 POWER SYSTEMS MANAGEMENT AND ASSOCIATED INFORMATION EX
13、CHANGE DATA AND COMMUNICATIONS SECURITY Part 4: Profiles including MMS 1 Scope and object 1.1 Scope This part of IEC 62351 specifies procedures, protocol extensions, and algorithms to facilitate securing ISO 9506 Manufacturing Message Specification (MMS) based applications. It is intended that this
14、technical specification be referenced as a normative part of other IEC TC 57 standards that have the need for using MMS in a secure manner. This technical specification represents a set of mandatory and optional security specifications to be implemented for applications when using ISO/IEC 9506 (Manu
15、facturing Automation Specification). NOTE Within the scope of IEC TC 57, there are two identified standards that may be impacted: IEC 61850-8-1 and IEC 60870-6. This specification contains a set of specifications that are to be used by referencing standards in order to secure information transferred
16、 when using MMS. The recommendations are based upon specific communication profile protocols used in order to convey MMS information. IEC 61850-8-1 and IEC 60870-6 make use of MMS in a 7-layer connection-oriented mechanism. Each of these standards is used over either the OSI or TCP profiles. 1.2 Obj
17、ect The initial audience for this specification is intended to be the members of the working groups developing or making use of the protocols within IEC TC 57. For the measures described in this specification to take effect, they must be accepted and referenced by the specifications for the protocol
18、s themselves, where the protocols make use of ISO 9506. This document is written to enable that process. The subsequent audience for this specification is intended to be the developers of products that implement these protocols. Portions of this specification may also be of use to managers and execu
19、tives in order to understand the purpose and requirements of the work. 2 Normative References IEC 60870-6 (all parts), Telecontrol equipment and systems IEC 62351-1, Power systems management and associated information exchange Data and communications security Part 1: Communication network and system
20、 security Introduction to security issues DD IEC/TS 62351-4:2007 3 IEC 62351-3, Power systems management and associated information exchange Data and communications security Part 3: Communication network and system security Profiles including TCP/IP ISO/IEC 9594-8:2005 /ITU-T Recommendation X.509:20
21、05, Information technology Open Systems Interconnection The Directory: Public-key and attribute certificate frameworks ISO 9506 (all parts), Industrial automation systems Manufacturing Message Specification RFC 1006, ISO Transport Service on top of the TCP Version: 3 RFC 2313, PKCS #1: RSA Encryptio
22、n Version 1.5 RFC 2246, The TLS Protocol, Version 1.0 RFC 3447, Public-Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 3 Terms and definitions For the purposes of this document, the terms and definitions contained in IEC 62351-2 as well as the following terms and de
23、finitions apply. 3.3 bilateral agreement agreement between two control centres which includes the data elements to be accessed and the means to access them. IEC 60870-6-503:2002, definition 3.3 3.4 bilateral table computer representation of the bilateral agreement. The representation used is a local
24、 matter IEC 60870-6-503:2002, definition 3.4 4 Security issues addressed by this technical specification 4.1 Security for application and transport profiles The communication security, specified in this specification, shall be discussed in terms of: application profiles: an A-Profile defines the set
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- BSDDIECTS6235142007POWERSYSTEMSMANAGEMENTANDASSOCIATEDINFORMATIONEXCHANGEDATAANDCOMMUNICATIONSSECURITYPROFILESINCLUDINGMMS

链接地址:http://www.mydoc123.com/p-548344.html