KIT | KIT-Bibliothek | Impressum | Datenschutz

RTS-ABAC: Real-Time Server-Aided Attribute-Based Authorization & Access Control for Substation Automation Systems

Gstür, Moritz ORCID iD icon 1; Keppler, Gustav ORCID iD icon 1; Ramadan, Mohammed ORCID iD icon 1; Elbez, Ghada ORCID iD icon 1; Hagenmeyer, Veit ORCID iD icon 1
1 Institut für Automation und angewandte Informatik (IAI), Karlsruher Institut für Technologie (KIT)

Abstract:

Critical energy infrastructures increasingly rely on information and communication technology for monitoring and control, which leads to new challenges with regard to cybersecurity. Recent advancements in this domain, including attribute-based access control (ABAC), have not been sufficiently addressed by established standards such as IEC 61850 and IEC 62351. To address this issue, we propose a novel real-time server-aided attribute-based authorization and access control for time-critical applications called RTS-ABAC. We tailor RTS-ABAC to the strict timing constraints inherent to the protocols employed in substation automation systems (SAS). We extend the concept of conventional ABAC by introducing real-time attributes and time-dependent policy evaluation and enforcement. To safeguard the authenticity, integrity, and non-repudiation of SAS communication and protect an SAS against domain-typical adversarial attacks, RTS-ABAC employs mandatory authentication, authorization, and access control for any type of SAS communication using a bump-in-the-wire (BITW) approach. To evaluate RTS-ABAC, we conduct a testbed-based performance analysis and a laboratory-based demonstration of applicability. ... mehr


Volltext §
DOI: 10.5445/IR/1000191829
Veröffentlicht am 31.03.2026
Originalveröffentlichung
DOI: 10.48550/arXiv.2603.23012
Cover der Publikation
Zugehörige Institution(en) am KIT Institut für Automation und angewandte Informatik (IAI)
Publikationstyp Forschungsbericht/Preprint
Publikationsdatum 24.03.2026
Sprache Englisch
Identifikator KITopen-ID: 1000191829
HGF-Programm 46.23.02 (POF IV, LK 01) Engineering Security for Energy Systems
Verlag arxiv
Umfang 24
Serie Computer Science - Cryptography and Security
Schlagwörter Attribute-Based Access Control, Smart Grid, Digital Substation, Substation Automation System, Cyber-Physical System, Low-Latency Communication, Bump-in-the-Wire, IEC 61850, IEC 62351
Nachgewiesen in OpenAlex
arXiv
Globale Ziele für nachhaltige Entwicklung Ziel 9 – Industrie, Innovation und Infrastruktur
KIT – Die Universität in der Helmholtz-Gemeinschaft
KITopen Landing Page