摘要
在工业互联网IT/OT相互融合的发展趋势下,工业控制网络的信息安全问题愈加凸显。分析了工业以太网存在的主要信息安全问题以及通用的解决办法,基于TLS协议进行安全通信设计,但是考虑到基于TLS协议的安全通信方法存在一些工业应用场景限制,所以针对工业以太网协议改进了安全设计,并以Modbus/TCP协议为例进行了实验测试和方案有效性分析。实验结果表明,该方案能够满足工控系统对信息安全的要求,有效防止数据窃听、篡改和伪造等常见网络攻击。
With the development of the integration of IT/OT in the industrial internet, the information security problems of industrial control networks are more and more prominent. The main information security problems existing in industrial Ethernet and the general solutions are analyzed in this paper. The secure communication is designed based on TLS protocol. However, the secure communication method based on TLS protocol has limitations in some industrial application scenarios, so the improved security design is carried out for the industrial Ethernet protocol and the experimental test and validity analysis are carried out on the Modbus/TCP protocol. The results show that this scheme can meet the requirements of industrial control systems for information security and prevent the common network attacks such as data eavesdropping, tampering and forgery effectively.
作者
王靖然
刘明哲
徐皑冬
孙越
周秀芳
WANG Jing-ran;LIU Ming-zhe;XU Ai-dong;SUN Yue;ZHOU Xiu-fang(Key Laboratory of Networked Control Systems,ChineseAcademy of Sciences,Shenyang 110016,China;Institutes for Robotics and Intelligent Manufacturing,ChineseAcademy of Sciences,Shenyang 110016,China;Shenyang Institute of Automation,ChineseAcademy of Sciences,Shenyang 110016,China)
出处
《控制工程》
CSCD
北大核心
2022年第10期1774-1779,共6页
Control Engineering of China
基金
仪表两安融合共性关键技术研究项目(2019YFB2006302)。
关键词
工业以太网
信息安全
TLS
安全通信
Industrial Ethernet
information security
TLS
security communication