Skip to main content
U.S. Department of Energy
Office of Scientific and Technical Information

PUF-Based Two-Factor Authentication Protocol for Securing the Power Grid Against Insider Threat

Conference · · 2022 IEEE Kansas Power and Energy Conference (KPEC)
 [1];  [2];  [2];  [3];  [2];  [2];  [2]
  1. Georgia Institute of Technology,School of Electrical and Computer Engineering,Atlanta,Georgia; Georgia Institute of Technology
  2. Georgia Institute of Technology,School of Electrical and Computer Engineering,Atlanta,Georgia
  3. Georgia Institute of Technology,School of Computer Science,Atlanta,Georgia

Recent advances in smart grid technologies have enabled additional distributed control paradigms that allow more efficient and reliable operation. However, this creates new security concerns for the grid, such as attackers using spoofed grid control devices to generate false measurements. This paper introduces a two-factor authentication protocol leveraging standard public-key cryptography as one authentication factor and a hardware-based fingerprint, known as a Physical Unclonable Function, as a second authentication factor. This protocol incurs a small overhead and prevents cyber-attacks even when an adversary is able to compromise the cryptographic keys stored in the non-volatile memory of an intelligent control device.

Research Organization:
Georgia Institute of Technology
Sponsoring Organization:
U.S. Department of Energy
DOE Contract Number:
CR0000004
OSTI ID:
1997022
Report Number(s):
DOE-GATECH-00004-3
Journal Information:
2022 IEEE Kansas Power and Energy Conference (KPEC), Journal Name: 2022 IEEE Kansas Power and Energy Conference (KPEC)
Country of Publication:
United States
Language:
English

References (6)

PUF Modeling Attacks on Simulated and Silicon Data journal November 2013
The rust language conference October 2014
Certificate-based sequential aggregate signature conference March 2009
PUF-Based Authentication and Key Agreement Protocols for IoT, WSNs, and Smart Grids: A Comprehensive Survey journal June 2022
Bad Data Injection Attack Propagation in Cyber-Physical Power Delivery Systems conference September 2018
The 2015 Ukraine Blackout: Implications for False Data Injection Attacks journal July 2017

Similar Records

Multi-factor authentication
Patent · Mon Oct 20 20:00:00 EDT 2014 · OSTI ID:1160234

A Cryptographic Method for Defense Against MiTM Cyber Attack in the Electricity Grid Supply Chain
Conference · Sun Apr 24 00:00:00 EDT 2022 · 2022 IEEE Power & Energy Society Innovative Smart Grid Technologies Conference (ISGT) · OSTI ID:1997526

Secure Firmware Update and Device Authentication for Smart Inverters using Blockchain and Physically Uncloable Function (PUF)-Embedded Security Module
Conference · Tue Jan 04 23:00:00 EST 2022 · 2021 6th IEEE Workshop on the Electronic Grid (eGRID) · OSTI ID:2344968