MARATTO

article · International Journal of Computer Applications

Integrating DNP3 Secure Authentication with Transport Layer Security for enhanced industrial control system security

Abstract

Industrial Control Systems (ICS) and SCADA networks underpin critical national infrastructure across the energy, water, and transportation sectors.Yet, they rely predominantly on the DNP3 protocol, which was designed without inherent provisions for message confidentiality, mutual authentication, or replay protection.DNP3 Secure Authentication Version 5 (DNP3-SA) and Transport Layer Security 1.3 (TLS 1.3) address applicationlayer integrity and transport-layer confidentiality, respectively, but their combined deployment as a dual-layer defense-in-depth architecture introduces cryptographic overhead whose feasibility on resource-constrained legacy field devices remains uncharacterized.This study presents a systematic empirical evaluation of the integrated dual-layer architecture using a hardware-in-the-loop cyber-physical testbed replicating a representative substation automation environment comprising a SCADA master station, mid-tier ARMv8 and low-specification ARMv7 outstations, and a software-defined network fabric.Four conditions (unprotected baseline, DNP3-SA only, TLS 1.3 only, and the fully integrated dual-layer configuration) were evaluated across 14,760,000 timestamped message exchange records spanning three message categories, three hardware configurations, and three replications.The dual-layer condition imposed a median latency increase of 12.6 ms (600%) over baseline on mid-tier hardware; hardware security module (HSM) offloading reduced 99th-percentile latency by 64%, restoring performance within IEC 61850 Performance Class P2 and NERC CIP-014 thresholds.Penetration testing across five DNP3specific attack categories aligned with MITRE ATT&CK for ICS showed the integrated architecture achieving a 100% block rate, with a residual 8.7% availability vulnerability under sustained fragmentation storms eliminated by HSM offloading.A oneclass support vector machine anomaly detector achieved a 91.3% detection rate at a 3.2% false-positive rate.The findings confirm that the dual-layer architecture is operationally feasible when configured with HSM acceleration and tiered encryption policies.This research contributes the first empirically grounded characterization of the combined latency envelope of DNP3-SA Version 5 and TLS 1.3, an open, reproducible testbed methodology, and an archived experimental dataset.

Research topics

  • Smart Grid Security and Resilience
  • Security and Verification in Computing
  • Infrastructure Resilience and Vulnerability Analysis

Sustainable Development Goals

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.5120/ijcae4e656f4bcb8

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.