论文标题
DERAUTH:用于分布式能源的基于电池的身份验证方案
DERauth: A Battery-based Authentication Scheme for Distributed Energy Resources
论文作者
论文摘要
在过去的几十年中,电力系统经历了急剧转变,以解决能源需求的增长,减少碳排放并提高功率质量和能源效率。向智能电网概念的这种转变涉及分布式能源资源(DERS)(例如屋顶太阳能电池板和存储系统)的利用,在改善对发电的控制的同时,有助于网格分散化。为了将DER无缝整合到电力系统中,嵌入式设备用于支持DERS的通信和控制功能。结果,此类组件的漏洞可以移植到工业环境中。不安全的控制网络和协议进一步加剧了问题。为了降低攻击表面,我们提出了针对DERS,DERAUTH的身份验证方案,该方案将电池储能系统(BESS)的固有熵作为信任根。使用质疑的机制来实现DER身份验证,该机制依赖于相应的Der bess最先进(SOC)和电压测量值。动态更新过程可确保BESS状态是最新的。我们评估了在原型开发中使用锂离子(Li-ion)电池的概念验证。评估了我们设计的鲁棒性,以防止神经网络执行的建模攻击。
Over the past decades, power systems have experienced drastic transformations in order to address the growth in energy demand, reduce carbon emissions, and enhance power quality and energy efficiency. This shift to the smart grid concept involves, among others, the utilization of distributed energy resources (DERs) such as rooftop solar panels and storage systems, contributing towards grid decentralization while improving control over power generation. In order to seamlessly integrate DERs into power systems, embedded devices are used to support the communication and control functions of DERs. As a result, vulnerabilities of such components can be ported to the industrial environment. Insecure control networks and protocols further exacerbate the problem. Towards reducing the attack surface, we present an authentication scheme for DERs, DERauth, which leverages the inherent entropy of the DER battery energy storage system (BESS) as a root-of-trust. The DER authentication is achieved using a challenge-reply mechanism that relies on the corresponding DER's BESS state-of-charge (SoC) and voltage measurements. A dynamically updating process ensures that the BESS state is up-to-date. We evaluate our proof-of-concept in a prototype development that uses lithium-ion (li-ion) batteries for the BESS. The robustness of our design is assessed against modeling attacks performed by neural networks.