DocumentCode :
2640982
Title :
Security design of remote maintenance system for nuclear power plants based on ISO/IEC 15408
Author :
Watabe, Ryosuke ; Oi, Tadashi ; Endo, Yoshio
Author_Institution :
Mitsubishi Electr. Corp., Hyogo
fYear :
2007
fDate :
17-20 Sept. 2007
Firstpage :
1700
Lastpage :
1704
Abstract :
As a method to reduce periodic inspection time and mean recovery time on fault occurrence, remote maintenance systems for nuclear power plants (NPPs) are proposed, which augment efficiencies in maintenance operations for the plants by surveying them remotely and achieving collaborations between on-site operators and remote plant designers and expert operators. In particular, with the spread of Internet technology and Internet security protection technology in recent years, there is a tendency to build remote maintenance systems using the Internet without dedicated communication lines. However, the biggest concern of customers such as electric power companies is security. It is highly necessary to give assurance of the security of remote maintenance systems coherently and consistently in order to introduce such systems based on Internet technology into NPPs. However, there exist various ways of thinking about security. Furthermore, there has not been a general agreement on how to give assurance of the security of remote maintenance systems for NPPs. So we have applied ISO/IEC 15408 to remote maintenance systems for NPPs. It is used to evaluate the security level of IT products and systems. Based on ISO/IEC 15408, we have listed assets to be protected, threats to the assets, security objectives against the threats, and security functional requirements that achieve the security objectives. Also, we have shown relations between the threats and the security objectives, and relations between the security objectives and the security functional requirements. As a result, we have concretized a necessary and sufficient security design of remote maintenance systems for NPPs that can protect the instrumentation and control (I&C) system against intrusion, impersonation, tapping, obstruction and destruction. In this paper, we describe the background of the remote maintenance systems for NPPs, a summary of the systems, and its security design based on ISO/IEC 15408.
Keywords :
ISO standards; Internet; maintenance engineering; nuclear engineering computing; nuclear power stations; security of data; ISO/IEC 15408; Internet; nuclear power plant; remote maintenance system; security design; Collaboration; Communication system security; IEC standards; ISO standards; Inspection; Instruments; Internet; Power generation; Power system protection; Power system security; ISO/IEC 15408; Instrumentation and Control System; Nuclear Power Plants; Protection Profile; Remote Maintenance System; Security Target;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
SICE, 2007 Annual Conference
Conference_Location :
Takamatsu
Print_ISBN :
978-4-907764-27-2
Electronic_ISBN :
978-4-907764-27-2
Type :
conf
DOI :
10.1109/SICE.2007.4421257
Filename :
4421257
Link To Document :
بازگشت