Caching-based Multicast Message Authentication in Time-critical Industrial Control Systems

08/08/2023
by   Utku Tefek, et al.
0

Attacks against industrial control systems (ICSs) often exploit the insufficiency of authentication mechanisms. Verifying whether the received messages are intact and issued by legitimate sources can prevent malicious data/command injection by illegitimate or compromised devices. However, the key challenge is to introduce message authentication for various ICS communication models, including multicast or broadcast, with a messaging rate that can be as high as thousands of messages per second, within very stringent latency constraints. For example, certain commands for protection in smart grids must be delivered within 2 milliseconds, ruling out public-key cryptography. This paper proposes two lightweight message authentication schemes, named CMA and its multicast variant CMMA, that perform precomputation and caching to authenticate future messages. With minimal precomputation and communication overhead, C(M)MA eliminates all cryptographic operations for the source after the message is given, and all expensive cryptographic operations for the destinations after the message is received. C(M)MA considers the urgency profile (or likelihood) of a set of future messages for even faster verification of the most time-critical (or likely) messages. We demonstrate the feasibility of C(M)MA in an ICS setting based on a substation automation system in smart grids.

READ FULL TEXT
research
03/15/2021

Take a Bite of the Reality Sandwich: Revisiting the Security of Progressive Message Authentication Codes

Message authentication guarantees the integrity of messages exchanged ov...
research
06/23/2023

Preventing EFail Attacks with Client-Side WebAssembly: The Case of Swiss Post's IncaMail

Traditional email encryption schemes are vulnerable to EFail attacks, wh...
research
05/19/2022

BP-MAC: Fast Authentication for Short Messages

Resource-constrained devices increasingly rely on wireless communication...
research
11/17/2020

Secure Location-Aware Authentication and Communication for Intelligent Transportation Systems

Intelligent transportation systems (ITS) are expected to effectively cre...
research
09/07/2019

OptSample: A Resilient Buffer Management Policy for Robotic Systems based on Optimal Message Sampling

Modern robotic systems have become an alternative to humans to perform r...
research
01/15/2020

Cumulative Message Authentication Codes for Resource-Constrained Networks

In emerging applications, such as intelligent automotive systems, Intern...
research
08/29/2023

LoVe is in the Air – Location Verification of ADS-B Signals using Distributed Public Sensors

The Automatic Dependant Surveillance-Broadcast (ADS-B) message scheme wa...

Please sign up or login with your details

Forgot password? Click here to reset