Browse > Article
http://dx.doi.org/10.5392/JKCA.2022.22.09.064

Public Key-Based Operator Authentication Mechanism for Access Control of Multi-Control Systems in OT Control Network  

Kim, Dae-Hwi (배재대학교 사이버보안학과)
Jo, In-June (배재대학교 사이버보안학과)
Publication Information
Abstract
The method of accessing multiple control systems in the OT control network centered on operation technology uses the operator authentication technology of each control system. An example is ID/PW operator authentication technology. In this case, since the OT control network is composed of multiple control systems, operator authentication technology must be applied to each control system. Therefore, the operator must bear the inconvenience of having to manage authentication information for each control system he manages. To solve these problems, SSO technology is used in business-oriented IT networks. However, if this is introduced into the OT control network as it is, the characteristics of the limited size of the OT control network and rapid operator authentication are not reflected, so it cannot be seen as a realistic alternative. In this paper, a public key-based authentication mechanism was newly proposed as an operator authentication technology to solve this problem. In other words, an integrated public key certificate that applies equally to all control systems in the OT control network was issued and used to access all control systems, thereby simplifying the authentication information management and making access to the control system more efficient and secure.
Keywords
OT Control Network; Operator Authentication; Public key; Multi SCADA Control Systems; Security;
Citations & Related Records
Times Cited By KSCI : 1  (Citation Analysis)
연도 인용수 순위
1 김일용, 임희택, 지대범, 박재표, "산업제어시스템 환경에서 효과적인 네트워크보안모델," 한국산학기술학회논문지, 제19권, 제4호, pp.664-673, 2018.   DOI
2 이은배, 김기영, "망 분리기반의 정보보호에 대한 고찰," 한국정보보호학회지, 제20권, 제1호, pp.39-46, 2010(2).
3 윤병남, 반형식, "공공분야의 정보보호- 공공분야의 공인인증서비스-," 한국통신학회 정보보와통신 논문지, 제19권, 제8호, pp.20-29, 2002.
4 Pascal Ackerman, Industrial Cybersecurity, Packt Publishing Limited, 2017.
5 행정안전부, 국가정보원, 한국정보사회진흥원, 국가기관 망분리 구축 가이드, 2008.
6 이현정, 조대일, 고갑승, "망분리환경에서 안전한 서비스 연계를 위한 단방향 망간자료전송 시스템 보안모델연구," Asia-pacific Journal of Multimedia Services Convergent with Art, Humanities, and Sociology, Vol.5, No.6, pp.539-547, 2015.   DOI
7 조인준, "SCADA제어망에서 강화된 운용자 인증 방안," 한국콘텐츠학회논문지, 제19권, 제12호, pp.416-424, 2019.   DOI
8 백종현, 김민정, 이진주, "지능형 교통시스템 보안아키 텍쳐 및 PKI 인증체계연구," 한국정보과학회 논문지, 제35권, 제1호, pp.32-36, 2017,