From IEC 60870-5-7: Par. 5:
"Devices complying with this standard shall provide information along with the Interoperability Tables identifying which ASDUs the device/station considers critical, requiring authentication. Refer to 10.10. If an ASDU is identified as critical, the ACT or DEACT cause of transmission shall be considered mandatory critical, but not ACTCON or ACT_TERM"
The normative also allows ACTCON and ACT_TERM ASDUs in monitor direction to be Non-Critical (except during the Aggressive Mode Authentication initialization).
Issue:
Non-Critical ASDU in monitor direction allows (M_xx_yy_1) MITM attacks by sending erroneous values (measures and signals) to the Master Station.
Non-Critical ACTCON or ACT_TERM allows reply attacks by sending (for example) negative confirms to the Master station, while the Controlled Station could execute the request and send back the correct response instead.
Proposal
All ASDUs types in monitor direction (M_xx_yy_1), included ACTCON and ACT_TERM, shall always be considered Critical, except M_EI_NA_1 for which the frequent reception condition on Controlling Station is already threated in the state machine by the Security Statistics management (see IEC 62351-5, Par. 7.3.2).
Discussion
Created
Status
Accepted as editorial
21 Feb 25
Approval (Editoral)
More detailed clarification follows:
All ASDUs types in monitor direction and control direction, regardless the Cause of Transmission (CoT) value, shall always be considered critical and have to be authenticated, except M_EI_NA_1 for which the frequent reception condition on Controlling Station is already treated in the state machine by the Security Statistics management (see IEC 62351-5:2013, Par. 7.3.2).
This resolution is already considered in IEC TS 60870-5-7 Ed.2 (expected to be published in March 2025).