PTP Authentication for Secure LAN and WAN Time Synchronization in the Power Grid
Speakers
- Herbert Falk (Outside the Box Consulting Services, LLC)
Description
Accurate time synchronization is essential for digital substation automation, enabling precise coordination of protection, control, and monitoring systems in power grids. The Precision Time Protocol (PTP), as defined by IEEE 1588-2019, provides sub-microsecond accuracy and includes an authentication feature to secure time synchronization against network-based attacks, such as network spoofing and man-in-the-middle attempts, which could compromise time synchronization and therefore decrease the grid reliability. Current substation time synchronization using PTP is limited to the substation’s LAN, requiring physical presence for access. In future digital substations, PTP synchronization will extend to WAN communication. Securing WAN communication including PTP is critical for the reliability of the time infrastructure of the digital substation, and overall grid. Additionally, implementing PTP security in the LAN provides an extra layer of protection. This paper presents the integration of a Time Synchronization clock system, serving as a PTP grandmaster, with the Group Domain of Interpretation (GDOI) security concept to enhance the security of time synchronization in digital substation automation. The GDOI security concept, which utilizes Key Distribution Center (KDC) servers for key management and KDC clients embedded in PTP-enabled devices for secure key distribution and authentication, ensures the integrity and authenticity of PTP messages, preventing unauthorized access and packet tampering. While the system effectively mitigates network-layer threats, it does not address GNSS spoofing or jamming, which require separate countermeasures. This presentation is finalized with experimental results demonstrating synchronization accuracy within 100 nanoseconds and robust protection against common cyber threats, ensuring reliable operation of critical power infrastructure.