透過您的圖書館登入
IP:18.217.144.32
  • 期刊

智慧電網之資訊安全標準的研究分析

Research of Information Security Standards for Smart Grid

摘要


智慧電網是利用資訊化以及自動化整合發、輸、配電以及用戶的電網系統,也就是將IT(Information Technology)與OT(Operational Technology)結合在發、輸、配電以及用戶的電力系統。因為電力系統是國家重要的基礎建設,若貿然將其資訊化及自動化,可能會面臨相當大的風險。因此各國專家學者都積極投入智慧電網之網路安全標準的制定,而這些標準內容繁雜,使得相關人員難以尋找所需的資訊安全標準。因此,在本篇文章中,我們首先研析智慧電網及工業自動化的相關資訊安全標準(如IEC62443、IEC62351、NISTIR7628以及ISO27001),然後針對這些標準的差異、使用的安全技術以及面臨的資安威脅進行分類及比較。最後,我們再利用美國政府制訂的網路安全框架(Cybersecurity Framework,CSF)內之五大核心功能來對這些智慧電網標準進行歸類,期望能夠以提供人們在建置或設計智慧電網時,當作資訊安全防護參考指南。

並列摘要


A smart grid is a grid system that integrates power generation, transmission, distribution, and users through information and automation technology. In other words, it combines IT (Information Technology) and OT (Operational Technology) to be used in the power system which includes the power generation, transmission, distribution and users. However, the power system is an important infrastructure, and it will face considerable risks after informatization and automation. Therefore, many expert groups from various countries are actively involved in the drafting of smart grid-related cyber security standards. The content of these standards is complex, making it difficult for relevant personnel to find the required information security standards. Firstly, we will analyze many related information security standards for smart grids and industrial automation, such as IEC 62443, IEC 62351, NISTIR 7628 and ISO 27001 in this paper. Secondly, we will classify and compare the differences between the security technologies and threats of these standards. Finally, we will use the five core functions of the Cybersecurity Framework (CSF) to category these standards and then provide an information security protection guideline when people want to set up or design the smart grids.

參考文獻


M.Z. Gunduz and R. Das, “Analysis of cyber-attacks on smart grid applications”, International Conference on Artificial Intelligence and Data Processing (IDAP), pp. 1-5,2018.
M.Z. Gunduz and R. Das , “Cyber-security on smart grid: Threats and potential solutions,” Computer Networks 169,2020.
H.He, and J. Yan. “Cyber-Physical Attacks and Defences in the Smart Grid: A Survey,” IET Cyber-Physical Systems: Theory & Applications, vol. 1, pp. 13-27,2016.
IEC, IEC 62443-1-1:Industrial communication networks – Network and system security –Part 1-1: Terminology, concepts and models. 2009.
IEC , IEC 62443-3-1:Industrial communication networks – Network and system security –Part 3-1: Security technologies for industrial automation and control systems. 2009.

延伸閱讀