Skip to main content
QUICK REVIEW

[论文解读] Enabling a Zero Trust Architecture in a 5G-enabled Smart Grid

Mohammad Ali Alipour, Saeid Ghasemshirazi|arXiv (Cornell University)|Oct 4, 2022
Smart Grid Security and Resilience被引用 11
一句话总结

本文提出了一种专为5G赋能的智能电网设计的零信任(ZT)安全架构,通过持续的身份认证和动态访问控制,应对无处不在的5G连接带来的攻击面扩大问题。该框架整合了自适应信任决策与实时策略执行,显著提升了对关键电力基础设施系统中不断演变的网络威胁的韧性。

ABSTRACT

One of the most promising applications of the IoT is the Smart Grid (SG). Integrating SG's data communications network into the power grid allows gathering and analyzing information from power lines, distribution power stations, and end users. A smart grid (SG) requires a prompt and dependable connection to provide real-time monitoring through the IoT. Hence 5G could be considered a catalyst for upgrading the existing power grid systems. Nonetheless, the additional attack surface of information infrastructure has been brought about by the widespread adoption of ubiquitous connectivity in 5G, to which the typical information security system in the smart grid cannot respond promptly. Therefore, guaranteeing the Privacy and Security of a network in a threatening, ever-changing environment requires groundbreaking architectures that go well beyond the limitations of traditional, static security measures. With "Continuous Identity Authentication and Dynamic Access Control" as its foundation, this article analyzes the Zero Trust (ZT) architecture specific to the power system of IoT and uses that knowledge to develop a security protection architecture.

研究动机与目标

  • 解决5G赋能的物联网集成在智能电网中引入的日益扩大的网络攻击面问题。
  • 克服传统静态安全模型在实时、动态电力系统环境中存在的局限性。
  • 设计一种基于零信任的安全框架,确保持续的信任验证与自适应访问控制。
  • 通过自适应、以身份为中心的访问策略,提升智能电网中的隐私与安全性。

提出的方法

  • 所提出的架构基于持续身份认证与动态访问控制的核心原则构建。
  • 通过实时监控用户与设备行为,持续评估其可信度。
  • 系统集成策略执行点(PEPs),根据上下文风险评估动态调整访问权限。
  • 信任评分通过包括设备完整性、位置和通信模式在内的多因素属性计算得出。
  • 该框架利用5G网络切片技术隔离关键控制流量,并在网络层面实施安全策略。
  • 安全策略通过集中式信任管理引擎执行,该引擎与网络功能及物联网设备协同工作。

实验结果

研究问题

  • RQ1零信任原则如何有效适配5G赋能智能电网的独特需求?
  • RQ2在实时电力系统环境中,哪些机制能够实现持续身份认证与动态访问控制?
  • RQ3与传统安全模型相比,所提出的架构如何减少智能电网中的攻击面?
  • RQ45G网络切片在提升关键基础设施中信任与访问控制方面发挥什么作用?

主要发现

  • 所提出的零信任架构通过强制实施持续认证与实时策略更新,显著降低了未经授权访问的风险。
  • 基于上下文属性的动态访问控制相比静态访问模型,提升了对潜在威胁的响应速度。
  • 5G网络切片的集成增强了关键控制流量的隔离性,降低了攻击者横向移动的可能性。
  • 该框架支持对设备行为与网络状况变化作出响应的自适应信任决策。
  • 该架构在高动态环境中对零日攻击与高级持续性威胁表现出更强的韧性。
  • 系统的模块化设计支持可扩展性,并可与现有智能电网基础设施组件无缝集成。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。