Historically, the power distribution grid was a passive system with limited control capabilities. Due to its increasing digitalization, this paradigm has shifted: the passive architecture of the power system itself, which includes cables, lines, and transformers, is extended by a communication infrastructure to become an active distribution grid. This transformation to an active system results from control capabilities that combine the communication and the physical components of the grid. It aims at optimizing, securing, enhancing, or facilitating the power system operation. The combination of power system, communication, and control capabilities is also referred to as a “smart grid”. A multitude of different architectures exist to realize such integrated systems. They are often labeled with descriptive terms such as “distributed,” “decentralized,” “local,” or “central." However, the actual meaning of these terms varies considerably within the research community.This paper illustrates the conflicting uses of prominent classification terms for the description of smart grid architectures. One source of this inconsistency is that the development of such interconnected systems is not only in the hands of classic power engineering but requires input from neighboring research disciplines such as control theory and automation, information and telecommunication technology, and electronics. This impedes a clear classification of smart grid solutions. Furthermore, this paper proposes a set of well-defined operation architectures specialized for use in power systems. Based on these architectures, this paper defines clear classifiers for the assessment of smart grid solutions. This allows the structural classification and comparison between different smart grid solutions and promotes a mutual understanding between the research disciplines. This paper presents revised parts of Chapters 4.2 and 5.2 of the dissertation of Drayer (Resilient Operation of Distribution Grids with Distributed-Hierarchical Architecture. Energy Management and Power System Operation, vol. 6, 2018).
Smart grids offer benefits compared to the current power grid by using technologies, such as advanced metering infrastructure and demand-response schemes. However, the introduction of these technologies also leads to challenges in the areas of privacy and identification of disobedient users. Current solutions to these challenges heavily rely on a trusted third party, which may lead to scenarios where the privacy of obedient consumers cannot be preserved. To tackle these concerns, anonymity provides a promising approach to obviating privacy preservation in smart grids. In this paper, a threshold-based anonymous identification scheme (TAI) for overload audit and privacy preservation in smart grids is proposed, where the use of a trusted third party is no longer required. Privacy preservation depends on the power consumption of consumers in the presence of a demand-response request from the power provider that defines an acceptable consumption threshold at periods of power shortage. Consumers must follow the instruction and curtail their consumption to meet the threshold. By doing so, the consumers who adhere to the power providers' instructions keep their anonymity, whilst the disobedient are be identified. According to our security and performance analysis, TAI significantly improves efficiency compared to previous anonymous identification schemes, while providing anonymity and identification.
With the ongoing adoption of remotely communicating and interacting control systems harbored by critical infrastructures, the potential attack surface of such systems also increases drastically. Therefore, not only the need for standardized and manufacturer-agnostic control system communication protocols has grown, but also the requirement to protect those control systems' communication. There have already been numerous security analyses of different control system communication protocols; yet, these have not been combined with each other sufficiently, mainly due to three reasons: First, the life cycles of such protocols are usually much longer than those of other Internet and communication technologies, therefore legacy protocols are often not considered in current security analyses. Second, the usage of certain control system communication protocols is usually restricted to a particular infrastructure domain, which leads to an isolated view on them. Third, with the accelerating pace at which both control system communication protocols and threats against them develop, existing surveys are aging at an increased rate, making their re-investigation a necessity. In this paper, a comprehensive survey on the security of the most important control system communication protocols, namely Modbus, OPC UA, TASE.2, DNP3, IEC 60870-5-101, IEC 60870-5-104, and IEC 61850 is performed. To achieve comparability, a common test methodology based on attacks exploiting well-known control system protocol vulnerabilities is created for all protocols. In addition, the effectiveness of the related security standard IEC 62351 is analyzed by a pre- and post-IEC 62351 comparison.
In this paper, we indicate the increasing interests in providing network security and privacy in Smart Grids, and propose a novel usage data aggregation scheme. The proposed scheme combines multiple cryptosystems to achieve anonymity and multidimensional data aggregation without a trusted third party. In our approach, smart meters transmit usage reports through hop-by-hop communication. If the communication is delayed or fails at one hop, it is possible to reroute the traffic through another hop. Therefore, the robustness of grid communication networks is improved. Additionally, an aggregation tree is constructed in order to optimize the aggregation time. Finally, smart meters utilize a highly efficient hash-based message authentication code to ensure data integrity and identity authentication. Although some existing approaches can achieve similar security features, our scheme has lower computational cost according to performance analysis and experiments.
Smart meters enable a fine-granular monitoring of power consumption and distributed power production in costumers' premises, which are used to predict the power requirements for the near future. The goals are to offer more security of supply as well as to minimize the power requirement estimation errors. However, to benefit from this information, the communication infrastructure that transmits the energy-related data needs to fulfill stringent requirements with respect to dependability, while remaining monetarily feasible. This paper discusses the usage of network function virtualization (NFV) technologies and constructs a virtual advanced metering infrastructure (AMI) network to transmit energy-related information in a dependable and cost-effective way. After the discussion of dependability requirements of AMI and the shortcomings of current approaches, the reliability and availability of a new architecture based on NFV is analyzed using analysis. Finally, a cost model is developed to compare the Virtual Network Function approach to current AMIs.
In this work, a secure wireless sensor network (WSN) for the surveillance, monitoring and protection of critical infrastructures was developed. To guarantee the security of the system, the main focus was the implementation of a unique security concept, which includes both security on the communication level, as well as mechanisms that ensure the functional safety during its operation. While there are many theoretical approaches in various subdomains of WSNs-like network structures, communication protocols and security concepts-the construction, implementation and real-life application of these devices is still rare. This work deals with these aforementioned aspects, including all phases from concept-generation to operation of a secure wireless sensor network. While the key focus of this paper lies on the security and safety features of the WSN, the detection, localization and classification capabilities resulting from the interaction of the nodes' different sensor types are also described.
The Smart Grid is expected to increase the efficiency of the current power grid, to cope with volatile power production based on renewable resources, to reduce the need for fossil-based energy resources, and to guarantee the stability of power supply. To achieve these objectives, today’s power grid is enhanced by information and communication technology to increase the information flow and to enable a sophisticated power production and power demand management. However, as the power grid is extended to a network of networks, it does not only become smarter, but also more vulnerable to security threats. This chapter discusses the current status and future developments of the Smart Grid and its challenges. Enhancements in terms of energy efficiency and new energy management approaches are covered as well as novel security challenges in different parts of the Smart Grid architecture. In short, this chapter analyzes some of the most striking risks and threats concerning the new Smart Grid infrastructure and discusses interdependencies between energy efficiency and security in the Smart Grid.
Schon seit Langem spielen verteilte IT-Systeme eine entscheidende Rolle in der Datenverarbeitung. Infolge der zunehmenden Vernetzung durch das Internet wurde es in den letzten Jahren moglich, global erreichbare, hochverteilte Systeme zu erschaffen. Durch die rasante Entwicklung derartiger Systeme entstehen einerseits neue Anforderungen an die Performanz (z.B. Leistungsfahigkeit und Bandbreite), wahrend andererseits die steigende Komplexitat von hochverteilten Systemen deren Absicherung (z.B. Datensicherheit und Datenschutz) immer schwieriger gestaltet. Zwei hochaktuelle Beispiele fur hochverteilte Systeme sind Smart Grid und Cloud Computing, die im Folgenden naher betrachtet werden. Smart Grid – Energieinformationsnetzwerke der Zukunft Das intelligente Elektrizitatsnetz (“Smart Grid”) wird langfristig unser heutiges, starres und hierarchisches Stromnetz ablosen. Kernziele des Smart Grid sind die Integration erneuerbarer Energiequellen, eine erhohte Versorgungssicherheit, sowie die Bereitstellung von Infrastrukturen fur eMobilitat unter Berucksichtigung effizienter Verfahren hinsichtlich der Energieverwendung. Zur Realisierung dieser Ziele sind mehrere Schritte notwendig. Als Basis dieser Entwicklung dient die Verflechtung des bisher isolierten Energienetzes mit modernen Kommunikationsinfrastrukturen (vgl. Berl et al. 2013). Dies erlaubt die Integration dezentraler Energieproduktions- (z.B. Photovoltaik) und Energiespeicheranlagen (z.B. Akkumulatoren im Bereich eMobilitat), sowie die Verwendung von intelligenten Stromzahlern („Smart Meter“) und ermoglicht damit eine neue Qualitat des Energiemanagements (z.B. durch Fernwartung und -uberwachung). Neben den entstehenden Chancen durch diese
In this paper a secure wireless sensor network (WSN) developed within the MOVEDETECT project is presented. The goal of the project was to design, implement and demonstrate a secure WSN for the protection of critical infrastructure. In order to provide a reliable service, the system must detect any kind of tampering with the sensor nodes, prevent eavesdropping and manipulation of the communication as well as detect, track and classify intruders in the protected region. Therefore based on previous experiences, a real-world WSN was developed, which addresses practical issues like water proofing, energy consumption, sensor deployment and visualization of the WSN state, but also provides a unique security concept, a interesting combination of sensors and sophisticated sensor data processing and analysis. The system was evaluated by examining firstly the sensors and the sensor processing algorithms and then conducting realistic field test.
Wireless sensor networks (WSNs) have a vast field of applications, including environment monitoring, battlefield surveillance and target tracking systems. As WSNs are usually deployed in remote or even hostile environments and sensor nodes are prone to node compromise attacks, the adoption of dynamic key management is extremely important. However, the resource-constrained nature of sensor nodes hinders the use of dynamic key management solutions designed for wired and ad hoc networks. Hence, many dynamic key management schemes have been proposed for WSNs recently. This paper investigates the special requirements of dynamic key management in sensor network environments, and introduces several basic evaluation metrics. In this work, the state of the art dynamic key management schemes are classified into different groups and summarized based on the evaluation metrics. Finally, several possible future research directions for dynamic key management are provided.
Increasing demand in energy consumption, missed modernisations, and the increasing difficulties in predicting power production due to volatile renewable energy sources (e.g., based on wind or sun) impose major challenges to the power grid. Power supply and power demand are closely interconnected with the need to maintain the power grid in a stable state with a sufficient quality of power. This requires energy-relevant information to be exchanged through the so called Energy Information Network. Communication, however, is challenging within the Energy Information Network due to privacy, security, resiliency, and quality-of-service requirements. Particularly, the resilience of communication within the Energy Information Network needs to be considered to maintain the power grid in a stable and controlled state. This paper suggests a Virtualised Energy Information Network (VEIN), where the Energy Information Network is divided into multiple virtual networks that run over a common substrate network. Furthermore, this paper discusses benefits of this approach in terms of privacy, security, and resilience and points out open research questions.
Increasing demand in energy consumption, missed modernisations, and the increasing difficulties in predicting power production due to volatile renewable energy sources (e.g.; based on wind or sun) impose major challenges to the power grid. Power supply and power demand are closely interconnected with the need to maintain the power grid in a stable state with a sufficient quality of power. This requires energy-relevant information to be exchanged through the so called Energy Information Network. Communication, however, is challenging within the Energy Information Network due to privacy, security, resiliency, and quality-of-service requirements. Particularly, the resilience of communication within the Energy Information Network needs to be considered to maintain the power grid in a stable and controlled state. This paper suggests a Virtualised Energy Information Network (VEIN), where the Energy Information Network is divided into multiple virtual networks that run over a common substrate network. Furthermore, this paper discusses benefits of this approach in terms of privacy, security, and resilience and points out open research questions.
— Modern sensors are portable, embeddable, they offer multiple connectivity options and enough processing power that allows the performance of advanced operations. Multiple sensors can be used together forming a wireless sensor network (WSN). Ubiquitous WSNs are expected to play a significant role in the future, assisting users in their everyday life. In this paper we present an intriguing application of WSNs: health monitoring of hospital patients. We focus on the security aspects of this application and identify security threats and requirements. Moreover, we argue that existing security solutions are energy hungry, therefore they are inappropriate for WSNs and we propose a new security design approach: adaptable security. Our design approach advocates that security mechanisms should be able to adapt their complexity by ranking the security requirements of each operation, achieving this way better energy efficiency. I. INTRODUCTION Wireless sensors are expected to become a core component of future ubiquitous networks. As technology evolves, sensors become smaller, smarter, with even more processing and interconnection capabilities and their application field becomes wider and wider. Sensors are already embedded in daily usage devices—such as smartphones—and the fact that they are being used on regular basis reveals their great potentials. Due to their size, sensors, can be very pervasive which combined with their advanced sensing and inteconnection features may jeopardize user's privacy. On the other hand security mechanisms require complex computations which lead to increased energy consumption and therefore limit the operational scope of sensors. As security mechanisms have not been designed with energy efficiency in mind, they cannot always be applied in sensor networks without firstly being reconsidered and modified. In this paper we introduce the concept of adaptable security, i.e, how security mechanisms can be adapted in order to satisfy the security and energy requirements of a specific application. The use case application for this paper is the health monitoring of hospitals' inmates
On the basis of the bachelor thesis performance comparison of cryptographic algorithms in Smart Grid applica- tions supervised by Dipl. Inf. Michael Niedermeier and Prof. Dr. Hermann de Meer at the chair of Computer Networks and Communications, this paper covers the analysis of the privacy ensuring capabilities of homomorphic cryptography in the Smart Grid with regard to its energy efficiency. The Paillier algorithm serves as an example and is used in two different architectural scenarios which are introduced and than compared to asymmetric and symmetric cryptography regarding their efficiency and practical applicability.
Introduction. Resource monitoring holds a very important position within the energy efficient computing paradigm. The underlying idea is to monitor the energy consumption behavior of appliances in different scenarios to develop consumption signatures. The signatures can help to deduce detailed consumption information which can be used to improve energy savings. There are many contemporary works being done in this direction where researchers investigate resource monitoring systems and their application. Additionally, efforts are being made to utilize collected samples of monitored information in useful ways [1]. Though the overall idea is very strong, there are certain research challenges which need to be overcome before turning this vision into reality. One of the most widely discussed among these is the privacy implications of such systems [3] and usability of collected information in a constructive manner. Detection theory through hypothesis testing is a tool that can be used to advance state-ofthe-art in privacy in energy monitoring. Compromising privacy can be thought of as deducing the profile of a user from observed data. In the context of process energy data monitoring, a profile corresponds to selecting one out of a finite set of N possible processes that are ran on a physical machine. Privacy concerns are raised when a malicious entity builds a set of empirical probability mass functions (p.m.f.), one for each process. Each p.m.f. captures the statistics of instantaneously consumed energy of the process. This task can be performed easily offline by taking multiple observations from each process that is running separately on every machine. A privacy breach exists, if, during the time a process runs on a physical machine, the malicious entity takes observations of the energy consumption level. Various factors may inherently limit the amount of observations taken. The question for the entity that seeks to compomise privacy is to identify the process that is running with good accuracy. Virtualization comes into stage to the support of privacy preservation; By appropriately mixing two or more processes (and thus p.m.f’s) on a virtualized machine, the privacy is protected, in the sense that the individual processes are made indistinguishable. This is also one of the core research questions in EuroNF SJRP SPEC where we want to address this interrelation between energy consumption monitoring and their impact on user privacy.
In this paper, the performance of the emerging MPEG-4 SVC CODEC is evaluated. In the first part, a brief introduction on the subject of quality assessment and the development of the MPEG-4 SVC CODEC is given. After that, the used test methodologies are described in detail, followed by an explanation of the actual test scenarios. The main part of this work concentrates on the performance analysis of the MPEG-4 SVC CODEC - both objective and subjective. Please note that this document is only a shortened version of the assessment. Further experimental results can be found in the extended version available at the Computing Research Repository (CoRR).
David W. Hutchison合作论文数Faculty of Science and Technology;Lancaster University;Computing Department2