arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

针对德国智能计量基础设施的延迟攻击:CLS信道时序约束的安全分析

Delay Attacks on the German Smart Metering Infrastructure: A Security Analysis of CLS Channel Timing Constraints

Fabio Stoll, Benjamin Pottkamp, Heiko Lorenz, Shalaka Kale, Jessica Rövekamp, Joachim Gerlach

arXiv 2608.03751首次发表:更新:

AI 中文总结

本研究分析德国智能计量基础设施CLS信道的延迟攻击可行性,提出含TLS扩展的缓解策略,指出攻击者可引发电网频率偏差,部分信道漏洞或更严重。

AI 中文摘要

本研究分析了针对德国智能计量基础设施(SMI)的可控本地系统(CLS)信道传输控制信号实施延迟攻击的可行性。研究结合理论分析与实验验证,采用符合智能电表网关(SMGW)通用标准保护配置文件的威胁模型,评估若同时利用多个CLS信道实施已识别的攻击向量,对电网可能造成的影响。同时,本研究还概述了缓解策略,包括SMGW配置限制、实现层面变更及协议扩展。研究结果表明,广域网(WAN)中具备足够上下文知识的路径上攻击者可实施延迟攻击,部分已部署协议配置的理论上限约为48小时。从单个CLS扩展至数十万个CLS设备来看,此类攻击者可能引发显著的频率偏差,进而可能导致甩负荷。攻击扩展需针对每个目标实现及配置的上下文知识,此类知识能否在CLS信道间广泛复用尚不明确,但随着标准化推进或更易获取。FNN Steuerbox及使用该资源的应用中受时间限制的传输为特定实现,制造商可解决。相比之下,确保TLS 1.3中应用数据时间限制需协议层面扩展,本研究提出的TLS扩展在保持向后兼容性的同时提供可持续缓解措施。SMI外的其他通信信道(如用于控制CLS的专有远程终端单元)不在本研究范围内,或存在类似或更严重的漏洞。

英文摘要

This work analyzes the feasibility of delay attacks on control signals transmitted via the Controllable Local System (CLS) channel of the German Smart Metering Infrastructure (SMI). It combines theoretical analysis with experimental validation under a threat model aligned to the Common Criteria Protection Profile for the Smart Meter Gateway (SMGW) and assess the potential impact on the power grid if the identified attack vector is exploited across multiple CLS channels simultaneously. We also outline mitigation strategies, including SMGW configuration restrictions, implementation-level changes, and protocol extensions. Our results show that an on-path attacker in the Wide Area Network (WAN) with sufficient contextual knowledge can feasibly execute delay attacks, with a theoretical upper bound of roughly 48 hours for some deployed protocol configurations. Projecting from a single CLS to several hundred thousand CLS devices indicates such an adversary could cause a significant frequency deviation potentially resulting in load shedding. Scaling the attack requires contextual knowledge for each targeted implementation and configuration; whether this knowledge can be broadly reused across CLS channels is uncertain but may become easier to obtain as standardization progresses. Time restricted transmissions in the FNN Steuerbox and in applications using CLS.EEDI are implementation-specific and can therefore be addressed by manufacturers. By contrast, ensuring application-data time limitations in TLS~1.3 requires protocol-level extensions. The TLS extensions proposed here offer a sustainable mitigation while preserving backward compatibility. Other communication channels outside the SMI (for example, proprietary remote terminal units used to control a CLS) are outside this work's scope and may exhibit similar or worse vulnerabilities.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑