Search papers, labs, and topics across Lattice.
This paper introduces QUIC-TRIP, a transparent security methodology designed to enhance the security of real-time substation communication protocols like R-GOOSE, which are vulnerable to cyber threats such as false data injection and denial-of-service attacks. By implementing a triple-redundant communication scheme at the OSI Transport Layer, QUIC-TRIP ensures data integrity and confidentiality without compromising the performance of existing protocols. Experimental results demonstrate that QUIC-TRIP achieves lower average round-trip times compared to OpenVPN and maintains resilience against DoS attacks, making it a viable solution for secure industrial communications in power systems.
QUIC-TRIP achieves a triple-redundant defense against cyber threats while maintaining low latency, outperforming traditional VPN solutions in critical power system communications.
Modern power systems rely on real-time substation communication protocols, such as the Routable Generic Object-Oriented Substation Event (R-GOOSE), for critical control and protection functions. However, these protocols often lack built-in security features and prioritize availability over confidentiality and integrity, making them susceptible to false data injection and denial-of-service attacks. This vulnerability is exacerbated when communications are transmitted over wide-area or public networks. Addressing these cyber threats is essential to comply with current security mandates, including the DOE's defense-in-depth and zero-trust guidelines. This paper introduces QUIC-TRIP, a transparent security methodology for low-latency IP-based industrial communications. By operating at the Open Systems Interconnection (OSI) Transport Layer (Layer 4), the solution encapsulates and protects data flows without affecting the operation of existing protocol endpoints. Baseline echo Round-Trip Time (RTT) results over a Frankfurt-Amsterdam communication path show that the underlying transport-layer proxy used by QUIC-TRIP achieves a lower average RTT than OpenVPN and only 2.88% higher average RTT than integrated DTLS 1.2, even with DTLS session reuse. We evaluate the resilience of QUIC-TRIP multipath communication under DoS flooding by securing R-GOOSE communications. In these tests, traffic is transparently delivered through three different paths, and QUIC-TRIP forwards the earliest-arriving duplicate while discarding later copies. The framework provides a triple-redundant defense scheme with a measured communication overhead of 32.18% per enabled proxied path, offering a bounded trade-off between resilience and bandwidth cost for time-critical grid operations.