A practical challenge-response authentication mechanism for a Programmable Logic Controller control system with one-time password in nuclear power plants

Instrumentation and Control (I&C) systems of nuclear power plants (NPPs) have been continuously digitalized. These systems have a critical role in the operation of nuclear facilities by functioning as the brain of NPPs. In recent years, as cyber security threats to NPP systems have increased, re...

Full description

Bibliographic Details
Main Authors: JunYoung Son, Sangkyun Noh, JongGyun Choi, Hyunsoo Yoon
Format: Article
Language:English
Published: Elsevier 2019-10-01
Series:Nuclear Engineering and Technology
Online Access:http://www.sciencedirect.com/science/article/pii/S1738573319303018
Description
Summary:Instrumentation and Control (I&C) systems of nuclear power plants (NPPs) have been continuously digitalized. These systems have a critical role in the operation of nuclear facilities by functioning as the brain of NPPs. In recent years, as cyber security threats to NPP systems have increased, regulatory and policy-related organizations around the world, including the International Atomic Energy Agency (IAEA), Nuclear Regulatory Commission (NRC) and Korea Institute of Nuclear Nonproliferation and Control (KINAC), have emphasized the importance of nuclear cyber security by publishing cyber security guidelines and recommending cyber security requirements for NPP facilities. As described in NRC Regulatory Guide (Reg) 5.71 and KINAC RS015, challenge response authentication should be applied to the critical digital I&C system of NPPs to satisfy the cyber security requirements. There have been no cases in which the most robust response authentication technology like challenge response has been developed and applied to nuclear I&C systems. This paper presents a challenge response authentication mechanism for a Programmable Logic Controller (PLC) system used as a control system in the safety system of the Advanced Power Reactor (APR) 1400 NPP. Keywords: Nuclear power plant, I&C, Regulatory guide, PLC, Cyber security requirements, Challenge response, One time password, Authentication
ISSN:1738-5733