华南理工大学学报(自然科学版) ›› 2016, Vol. 44 ›› Issue (4): 63-70.doi: 10.3969/j.issn.1000-565X.2016.04.010

• 动力与电气工程 • 上一篇    下一篇

结合域含义的GOOSE 报文加解密方法

王智东1,2 王钢1 许志恒1 童晋方1 石泉1 朱革兰1†   

  1. 1. 华南理工大学 电力学院,广东 广州 510640; 2. 华南理工大学 广州学院电气工程学院,广东 广州 510800
  • 收稿日期:2015-05-14 修回日期:2016-01-29 出版日期:2016-04-25 发布日期:2016-04-12
  • 通信作者: 朱革兰(1968-) ,女,博士,助理研究员,主要从事电力系统及自动化研究. E-mail:glzhu1@scut.edu.cn
  • 作者简介:王智东(1980-) ,男,博士生,主要从事电力通信及其信息安全研究. E-mail: zdwang@ scut. edu. cn
  • 基金资助:
    国家自然科学基金资助项目( 51477057)

Encryption and Decryption Methods of GOOSE Packets Based on Domain Implication

WANG Zhi-dong1,2 WANG Gang1 XU Zhi-heng1 TONG Jin-fang1 SHI Quan1 ZHU Ge-lan1   

  1. 1.School of Electric Power,South China University of Technology,Guangzhou 510640,Guangdong,China; 2.School of Electrical Engineering,Guangzhou College of South China University of Technology,Guangzhou 510800,Guangdong,China
  • Received:2015-05-14 Revised:2016-01-29 Online:2016-04-25 Published:2016-04-12
  • Contact: 朱革兰(1968-) ,女,博士,助理研究员,主要从事电力系统及自动化研究. E-mail:glzhu1@scut.edu.cn
  • About author:王智东(1980-) ,男,博士生,主要从事电力通信及其信息安全研究. E-mail: zdwang@ scut. edu. cn
  • Supported by:
    Supported by the National Natural Science Foundation of China( 51477057)

摘要: 尽管加密方法由于耗时较大而不被IEC62351 推荐用于GOOSE 等实时报文,但许多电力工程实践中仍加密GOOSE 报文以加强网络信息安全性. 文中以经典的对称加密算法Rijndael 为例,从密钥长度、分组长度和分组模式等方面分析影响GOOSE 报文加密耗时的因素. 结合GOOSE 的域含义,提出基于关键信息的GOOSE 加密方法,在保证报文信息保密的基础上减少耗时; 同时,利用GOOSE 报文的StNum、SqNum 和T 等具有时间同步意义的信息防止经典的报文重放攻击,利用GOOSE 报文的CRC 验证码保障报文的完整性. 嵌入式平台的耗时特性表明,文中提出的GOOSE 报文加解密方法满足GOOSE报文的实时性要求.

关键词: GOOSE 报文, 对称加密, 完整性, 实时性

Abstract: Although IEC62351 suggests no encryption algorithm for GOOSE and other real-time packets due to the huge time consumption of encryption algorithms,many practical power projects still encrypt GOOSE packets to strengthen the security of network information.In this paper,the classical Rijndael symmetric encryption algorithm is adopted as an example to analyze such factors affecting the time consumption of GOOSE packets encryption as the secret key length,the packet length and the packet mode.Then,in order to reduce the time consumption without weakening the packet confidentiality,a GOOSE encryption method based on critical information is proposed with the combination of packet domain implication.Moreover,GOOSE messages such as StNum,SqNum and T,which possess time synchronization functions,are used to prevent replay attacks,and the CRC verification code in GOOSE packets is used to ensure the integrity of the message.Finally,the time-consuming characteristics of the proposed GOOSE encryption and decryption algorithms are tested on an embedded platform,and the results show that the proposed method meets the real-time requirements of power systems well.

Key words: GOOSE packet, symmetric encryption, integrity, real-time performance

中图分类号: