{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/18425"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/18425","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Secure multicast for power grid communications","abstract":"Secure multicast for power grid systems faces a number of challenges like complex and error-prone group configuration, inefficient group key management, real-time challenges to existing security protocols and the balance among correctness, efficiency, feasibility and cost. We propose an application-aware approach to setting up secure multicast for power grid communications that automatically derives group memberships and verifies configuration conformance from data dependencies in system specifications. We present an analytic publish-subscribe model, which formally depicts the relationships between data objects, publishers, subscribers and group controllers in a secure multicast system. Based on the model, we study anomalies in multicast functionality configurations like redundant and unauthorized publications, source-anomaly and data-dissatisfaction subscriptions. Algorithms are developed to detect the anomalies and verify the configuration conformance. A practical architecture is designed for automatic and error-resistant group configuration. It transforms the application layer system specifications to the network layer group security associations, policies and credentials. We also demonstrate the feasibility of raising link layer control messages to the network layer and protecting timing critical multicast traffic using one of the off-the-shelf network layer security protocols, namely IPsec. We provide experimental evidence that native IPsec multicast is capable of addressing latency constraints in medium scale networks. To evaluate the approach, we present a case study of IEC 61850 power substation networks and have developed a demo system, SecureSCL. The case study shows the benefits a real-world application gains from the automatically-generated group security configurations and demonstrates the practicality and efficiency of the approach. This work provides a cross-layer approach of automatically self-generated group configuration for power grid communications, addressing key concerns of both system implementation and conformance analysis. The proposed multicast model and verification mechanism can be extended for generic secure communication configurations. On the other hand, the prototype system SecureSCL has a potential of being developed into a realistic application for power substations.","abstract_html":"Secure multicast for power grid systems faces a number of challenges like complex and error-prone group configuration, inefficient group key management, real-time challenges to existing security protocols and the balance among correctness, efficiency, feasibility and cost. We propose an application-aware approach to setting up secure multicast for power grid communications that automatically derives group memberships and verifies configuration conformance from data dependencies in system specifications. We present an analytic publish-subscribe model, which formally depicts the relationships between data objects, publishers, subscribers and group controllers in a secure multicast system. Based on the model, we study anomalies in multicast functionality configurations like redundant and unauthorized publications, source-anomaly and data-dissatisfaction subscriptions. Algorithms are developed to detect the anomalies and verify the configuration conformance. A practical architecture is designed for automatic and error-resistant group configuration. It transforms the application layer system specifications to the network layer group security associations, policies and credentials. We also demonstrate the feasibility of raising link layer control messages to the network layer and protecting timing critical multicast traffic using one of the off-the-shelf network layer security protocols, namely IPsec. We provide experimental evidence that native IPsec multicast is capable of addressing latency constraints in medium scale networks. To evaluate the approach, we present a case study of IEC 61850 power substation networks and have developed a demo system, SecureSCL. The case study shows the benefits a real-world application gains from the automatically-generated group security configurations and demonstrates the practicality and efficiency of the approach. This work provides a cross-layer approach of automatically self-generated group configuration for power grid communications, addressing key concerns of both system implementation and conformance analysis. The proposed multicast model and verification mechanism can be extended for generic secure communication configurations. On the other hand, the prototype system SecureSCL has a potential of being developed into a realistic application for power substations.","abstract_has_math":false,"creators":["Zhang, Jianqing"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Gunter, Carl A.","Campbell, Roy H.","Sanders, William H.","King, Samuel T.","Mix, Scott"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2011,"date_issued":"2011-01-14T22:50:24Z","date_published":"2011-01-14T22:50:24Z","updated_at":"2026-07-22T22:25:11Z","subjects":["Power grid communications","Multicast","Security","Application-Aware","SecureSCL"],"languages":["en"],"rights":["Copyright 2010 Jianqing Zhang"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/18425","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Gunter, Carl A.","Campbell, Roy H.","Sanders, William H.","King, Samuel T.","Mix, Scott"]},{"key":"dc:creator","label":"Author","values":["Zhang, Jianqing"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2011-01-14T22:50:24Z","2010-12"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Power grid communications","Multicast","Security","Application-Aware","SecureSCL"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2010 Jianqing Zhang"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/18425"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Secure multicast for power grid systems faces a number of challenges like complex and error-prone group configuration, inefficient group key management, real-time challenges to existing security protocols and the balance among correctness, efficiency, feasibility and cost. We propose an application-aware approach to setting up secure multicast for power grid communications that automatically derives group memberships and verifies configuration conformance from data dependencies in system specifications. We present an analytic publish-subscribe model, which formally depicts the relationships between data objects, publishers, subscribers and group controllers in a secure multicast system. Based on the model, we study anomalies in multicast functionality configurations like redundant and unauthorized publications, source-anomaly and data-dissatisfaction subscriptions. Algorithms are developed to detect the anomalies and verify the configuration conformance. A practical architecture is designed for automatic and error-resistant group configuration. It transforms the application layer system specifications to the network layer group security associations, policies and credentials. We also demonstrate the feasibility of raising link layer control messages to the network layer and protecting timing critical multicast traffic using one of the off-the-shelf network layer security protocols, namely IPsec. We provide experimental evidence that native IPsec multicast is capable of addressing latency constraints in medium scale networks. To evaluate the approach, we present a case study of IEC 61850 power substation networks and have developed a demo system, SecureSCL. The case study shows the benefits a real-world application gains from the automatically-generated group security configurations and demonstrates the practicality and efficiency of the approach. This work provides a cross-layer approach of automatically self-generated group configuration for power grid communications, addressing key concerns of both system implementation and conformance analysis. The proposed multicast model and verification mechanism can be extended for generic secure communication configurations. On the other hand, the prototype system SecureSCL has a potential of being developed into a realistic application for power substations.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2010-09-16T17:21:26Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 1 Zhang_Jianqing.pdf: 1696280 bytes, checksum: d17a3dafc2ca44073e0939d1aa28f0c6 (MD5)","Made available in DSpace on 2011-01-14T22:50:24Z (GMT). No. of bitstreams: 2 Zhang_Jianqing.pdf: 1696283 bytes, checksum: b14c5532af7a18618fa23c5578600120 (MD5) license.txt: 4064 bytes, checksum: 39240dc034772b882c4f858af60084db (MD5)"]},{"key":"dc:title","label":"Title","values":["Secure multicast for power grid communications"]}]}],"canonical_facts":{"dc:contributor":["Gunter, Carl A.","Campbell, Roy H.","Sanders, William H.","King, Samuel T.","Mix, Scott"],"dc:creator":["Zhang, Jianqing"],"dc:date":["2011-01-14T22:50:24Z","2010-12"],"dc:description":["Secure multicast for power grid systems faces a number of challenges like complex and error-prone group configuration, inefficient group key management, real-time challenges to existing security protocols and the balance among correctness, efficiency, feasibility and cost. We propose an application-aware approach to setting up secure multicast for power grid communications that automatically derives group memberships and verifies configuration conformance from data dependencies in system specifications. We present an analytic publish-subscribe model, which formally depicts the relationships between data objects, publishers, subscribers and group controllers in a secure multicast system. Based on the model, we study anomalies in multicast functionality configurations like redundant and unauthorized publications, source-anomaly and data-dissatisfaction subscriptions. Algorithms are developed to detect the anomalies and verify the configuration conformance. A practical architecture is designed for automatic and error-resistant group configuration. It transforms the application layer system specifications to the network layer group security associations, policies and credentials. We also demonstrate the feasibility of raising link layer control messages to the network layer and protecting timing critical multicast traffic using one of the off-the-shelf network layer security protocols, namely IPsec. We provide experimental evidence that native IPsec multicast is capable of addressing latency constraints in medium scale networks. To evaluate the approach, we present a case study of IEC 61850 power substation networks and have developed a demo system, SecureSCL. The case study shows the benefits a real-world application gains from the automatically-generated group security configurations and demonstrates the practicality and efficiency of the approach. This work provides a cross-layer approach of automatically self-generated group configuration for power grid communications, addressing key concerns of both system implementation and conformance analysis. The proposed multicast model and verification mechanism can be extended for generic secure communication configurations. On the other hand, the prototype system SecureSCL has a potential of being developed into a realistic application for power substations.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2010-09-16T17:21:26Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 1 Zhang_Jianqing.pdf: 1696280 bytes, checksum: d17a3dafc2ca44073e0939d1aa28f0c6 (MD5)","Made available in DSpace on 2011-01-14T22:50:24Z (GMT). No. of bitstreams: 2 Zhang_Jianqing.pdf: 1696283 bytes, checksum: b14c5532af7a18618fa23c5578600120 (MD5) license.txt: 4064 bytes, checksum: 39240dc034772b882c4f858af60084db (MD5)"],"dc:identifier":["http://hdl.handle.net/2142/18425"],"dc:language":["en"],"dc:rights":["Copyright 2010 Jianqing Zhang"],"dc:subject":["Power grid communications","Multicast","Security","Application-Aware","SecureSCL"],"dc:title":["Secure multicast for power grid communications"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:11Z"}