Modbus protocol security enhancement method and system in unicast communication scene

By introducing the target function code into the Modbus protocol for identity authentication and key negotiation, the problem of the inability to verify the identity of both parties in the Modbus protocol and the data is easily tampered with, the security and integrity of data transmission are achieved, and it is suitable for low-computing industrial control equipment.

CN120342628AActive Publication Date: 2025-07-18XIDIAN UNIV

Patent Information

Application Number
CN202510501321.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-21
Publication Date
2025-07-18
Estimated Expiration
2045-04-21

AI Technical Summary

Technical Problem

The existing Modbus protocol cannot effectively protect the identity validity of both parties in the communications, the integrity and confidentiality of data transmission, and is vulnerable to malicious attacks and data leakage.

Method used

By introducing the target function code into the Modbus protocol for identity authentication and key negotiation, the master node and slave node share the ciphertext, and use random numbers and preset keys to generate message authentication code for two-way authentication, ensuring the legitimacy and data security of both parties to the communication.

Benefits of technology

The Modbus protocol is implemented to ensure the validity of the identity of both parties in the communication, ensure the integrity and confidentiality of data during the transmission process, prevent illegal equipment access and data tampering, and is suitable for low-computing equipment, reducing computing overhead and delays.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342628A_ABST
    Figure CN120342628A_ABST
Patent Text Reader

Abstract

The invention provides a Modbus protocol security enhancement method and system in a unicast communication scene, and relates to the technical field of industrial control networks. Comprising the following steps: sharing a first ciphertext and a second ciphertext between a master node and a slave node; the master node generates a first message authentication code according to the second ciphertext, a preset key and the first random number, and sends the first message to the slave node by using the target function code; the slave node authenticates the identity of the master node according to the first message authentication code, the first ciphertext, the preset key and the second random number; when the slave node successfully authenticates the identity of the master node, the slave node generates a second message authentication code according to the first ciphertext, the preset key and the second random number, and sends a second message to the master node by using the target function code; and the master node authenticates the identity of the slave node according to the second message authentication code, the second ciphertext, the preset key and the first random number. Therefore, the validity of the identities of the two communication parties can be ensured, and the integrity and confidentiality of the data in the transmission process are guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of industrial control networks, and particularly to a method and system for enhancing the security of the Modbus protocol in a unicast communication scenario. Background Art

[0002] In the field of industrial control systems, security enhancement is the key to ensuring that the system is protected from malicious attacks and data leakage. The core technologies for security enhancement mainly include identity authentication, key negotiation, and data encryption and decryption. These core technologies together form the basis for protecting data transmission and device communication. Identity authentication refers to the process in network communication where two communicating parties (usually the master node and the slave node) verify each other's identities before exchanging data to ensure that only legitimate devices can participate in the communication. The process of identity authentication is an important part of ensuring the security of the system. Especially in protocols without a built-in identity authentication mechanism (such as the Modbus protocol), adding identity authentication can prevent unauthorized devices from accessing the network, thereby reducing potential security risks. Key negotiation is the process by which two communicating parties securely generate a shared key over an insecure channel. Commonly used Modbus protocols (such as Modbus TCP protocol, Modbus RTU / ASCII protocol) transmit data in plain text, making the communication channel vulnerable to eavesdropping. There is no security enhancement mechanism in the Modbus protocol. Therefore, any device can communicate with the master node or the slave node, resulting in risks such as inability to verify identities and easy tampering of data. Therefore, in the application of the Modbus protocol, how to enhance the security of point-to-point communication has become an urgent problem to be solved in the field of industrial automation.

[0003] Currently, for the security enhancement of the Modbus protocol, traditional security enhancement methods are usually adopted. However, in traditional security enhancement methods, any device can communicate with the Modbus host or slave, and the legitimacy of the communicating party cannot be verified. Therefore, malicious devices (such as devices forged by hackers or attackers) can easily access the network and communicate, steal data, or launch attacks, resulting in the inability to guarantee the validity of the identities of both communicating parties; attackers can capture and modify data packets, or cause abnormal behavior of the system by replaying legitimate commands, resulting in the inability to guarantee the integrity of data during transmission; there is no dynamic negotiation of keys during communication, which means that the communication between devices may not have effective encryption protection, or the keys may be static and easily stolen. Once the keys are leaked, attackers can decrypt and forge communication data, resulting in the inability to guarantee the confidentiality of data during transmission. Summary of the Invention

[0004] The purpose of the embodiments of the present invention is to provide a method and system for enhancing the security of the Modbus protocol in a unicast communication scenario, so as to solve the problems in the prior art that the validity of the identities of both communication parties cannot be guaranteed, and the integrity and confidentiality of data during transmission cannot be guaranteed.

[0005] To solve the above technical problems, the embodiments of the present invention provide the following technical solutions:

[0006] The first aspect of the present invention provides a method for enhancing the security of the Modbus protocol in a unicast communication scenario. The Modbus protocol includes a target function code for performing identity authentication and key negotiation using messages. The method includes:

[0007] Share a first ciphertext and a second ciphertext between the master node and the slave node. The first ciphertext is the ciphertext corresponding to the master node, and the second ciphertext is the ciphertext corresponding to the slave node;

[0008] The master node generates a first message authentication code based on the second ciphertext, a preset key, and a first random number, and sends a first message to the slave node using the target function code. The first message is a message generated based on the first message authentication code, and the first message includes the first message authentication code;

[0009] The slave node authenticates the identity of the master node based on the first message authentication code, the first ciphertext, the preset key, and a second random number;

[0010] When the slave node successfully authenticates the identity of the master node, the slave node generates a second message authentication code based on the first ciphertext, the preset key, and the second random number, and sends a second message to the master node using the target function code. The second message is a message generated based on the second message authentication code, and the second message includes the second message authentication code;

[0011] The master node authenticates the identity of the slave node based on the second message authentication code, the second ciphertext, the preset key, and the first random number, so as to enhance the security of the Modbus protocol.

[0012] The second aspect of the present invention provides a system for enhancing the security of the Modbus protocol in a unicast communication scenario. The Modbus protocol includes a target function code for performing identity authentication and key negotiation using messages. The system includes:

[0013] A sharing module for sharing a first ciphertext and a second ciphertext between the master node and the slave node. The first ciphertext is the ciphertext corresponding to the master node, and the second ciphertext is the ciphertext corresponding to the slave node;

[0014] A first generation module for the master node to generate a first message authentication code based on the second ciphertext, a preset key, and a first random number, and send a first message to the slave node using the target function code. The first message is a message generated based on the first message authentication code, and the first message includes the first message authentication code;

[0015] The first authentication module is used to authenticate the identity of the master node by a slave node based on the first message authentication code, the first ciphertext, a preset key, and a second random number;

[0016] The second generation module is used to, when the slave node successfully authenticates the identity of the master node, generate a second message authentication code by the slave node based on the first ciphertext, the preset key, and the second random number, and send a second message to the master node by using a target function code. The second message is a message generated based on the second message authentication code, and the second message includes the second message authentication code;

[0017] The second authentication module is used to authenticate the identity of the slave node by the master node based on the second message authentication code, the second ciphertext, the preset key, and the first random number, so as to implement the security enhancement of the Modbus protocol.

[0018] Compared with the prior art, for the method and system for enhancing the security of the Modbus protocol in the unicast communication scenario provided by the present invention, the Modbus protocol includes a target function code for performing identity authentication and key negotiation by using messages. A first ciphertext and a second ciphertext are shared between the master node and the slave node; the master node generates a first message authentication code based on the second ciphertext, the preset key, and the first random number, and sends a first message to the slave node by using the target function code; the slave node authenticates the identity of the master node based on the first message authentication code, the first ciphertext, the preset key, and the second random number; when the slave node successfully authenticates the identity of the master node, the slave node generates a second message authentication code based on the first ciphertext, the preset key, and the second random number, and sends a second message to the master node by using the target function code; the master node authenticates the identity of the slave node based on the second message authentication code, the second ciphertext, the preset key, and the first random number, so as to implement the security enhancement of the Modbus protocol. In this way, through the shared first ciphertext and second ciphertext, it can be ensured that the master node and the slave node sharing the ciphertext communicate, the legitimacy of the master node and the slave node can be verified, the slave node can authenticate the identity of the master node by the generated first message authentication code, the master node authenticates the identity of the slave node by the generated second message authentication code, and the messages are sent by using the target function code for negotiation authentication, so as to ensure the validity of the identities of both communication parties and guarantee the integrity and confidentiality of data during the transmission process. Description of the Drawings

[0019] By reading the following detailed description with reference to the drawings, the above and other objects, features, and advantages of the exemplary embodiments of the present invention will become easy to understand. In the drawings, several embodiments of the present invention are shown in an exemplary rather than restrictive manner, and the same or corresponding reference numerals represent the same or corresponding parts, where:

[0020] Figure 1Schematically shows a flowchart of the Modbus protocol security enhancement method in a unicast communication scenario;

[0021] Figure 2 Schematically shows a schematic diagram of the Modbus TCP message format;

[0022] Figure 3 Schematically shows a schematic diagram of the Modbus RTU / ASCII message format;

[0023] Figure 4 Schematically shows a schematic diagram of the identity authentication and session key negotiation process in the first embodiment of the present invention;

[0024] Figure 5 Schematically shows a structural diagram of the Modbus protocol security enhancement system in a unicast communication scenario. Detailed implementation manners

[0025] Hereinafter, the exemplary embodiments of the present invention will be described in more detail with reference to the accompanying drawings. Although the exemplary embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present invention can be more thoroughly understood and the scope of the present invention can be fully conveyed to those skilled in the art.

[0026] It should be noted that: Unless otherwise specified, the technical terms or scientific terms used in the present invention should be the ordinary meanings understood by those skilled in the art to which the present invention belongs.

[0027] Hereinafter, the method in the embodiments of the present invention will be described in detail.

[0028] Figure 1 Schematically shows a flowchart of the Modbus protocol security enhancement method in a unicast communication scenario in the embodiments of the present invention. Refer to Figure 1 As shown, the Modbus protocol includes a target function code for identity authentication and key negotiation using messages. The method may include:

[0029] S101. Share a first ciphertext and a second ciphertext between the master node and the slave node.

[0030] Among them, the first ciphertext is the ciphertext corresponding to the master node, and the second ciphertext is the ciphertext corresponding to the slave node.

[0031] Before sharing the first ciphertext and the second ciphertext between the master node and the slave node, the method further includes:

[0032] Step A1: Use a custom function to set an unoccupied function code as the target function code.

[0033] Among them, the target function code is used to indicate identity authentication and key negotiation using the first message and the second message.

[0034] The Modbus protocol includes the Modbus TCP protocol and the Modbus RTU / ASCII protocol.

[0035] To ensure compatibility with traditional Modbus protocols, the present invention fully considers the use of function codes in the Modbus protocol. Function codes are the core fields in the Modbus protocol used to distinguish different operation types, such as reading registers, writing registers, etc.

[0036] In traditional Modbus protocols, function codes are used to specify the operations that the master requests the slave to perform. The standard function code range is from 0x01 to 0x7F, covering common read and write operations. However, the protocol also reserves some function code ranges (such as 0x65 to 0x72 and 0x64 to 0x6E) for users to customize specific functions. In the present invention, the unoccupied function code can select the 0x6D function code (decimal 109) to utilize the custom function of the 0x6D function code.

[0037] In the present invention, by utilizing the custom function of the 0x6D function code, the 0x6D function code is set as the function code for indicating identity authentication and key negotiation using the first message and the second message. Function codes are not only used to identify the type of communication operation but also used to identify the process of identity authentication and key negotiation to ensure the realization of security enhancement functions without changing the existing Modbus protocol framework. Specifically, the present invention extends the use of the unoccupied function code, i.e., the 0x6D function code, to support security operations such as encrypted communication, authentication, and key exchange, while maintaining compatibility with traditional Modbus devices.

[0038] By using the function code 0x6D, the present invention, without changing the existing system architecture, identifies the message transmission in the process of identity authentication and key negotiation, ensuring the authentication of both communication parties and the negotiation of secure keys.

[0039] Figure 2 Schematically shows a schematic diagram of the Modbus TCP message format, see Figure 2As shown in the figure, in the Modbus TCP protocol, the message frame consists of three parts: the message header (Modbus Application Protocol, MBAP), the Protocol Data Unit (PDU), and the checksum. Among them, the MBAP is the message header with a length of 7 bytes, which is composed of a transaction identifier, a protocol identifier, a length, and a unit identifier; the PDU is composed of a function code and a data field. The function code is 1 byte in total, and the length of the data field is variable; the checksum is responsible for verifying the data of the message and has a length of 2 bytes. Table 1 shows the MBAP message header format, which includes: a transaction identifier with a length of 2 bytes, indicating the sequence number of the message. The transaction identifier initiated by the master device should be unique for each transaction to distinguish different requests. A protocol identifier with a length of 2 bytes, indicating the protocol to which the message belongs. In the Modbus TCP protocol, the value of this field is generally 0x0000, referring to the Modbus TCP protocol. A length with a length of 2 bytes, indicating how many bytes (including the data field) there are in the message after this field. A unit identifier with a length of 1 byte, indicating the node address of the receiving slave node of the message, including a 3-bit domain ID and a 5-bit node ID. The PDU includes two parts: a function code and data. The function code is 1 byte in total, indicating the operation type of the message, such as reading holding registers, writing a single register or multiple registers, etc.

[0040] Table 1 MBAP message header format

[0041]

[0042] Figure 3 Schematically shows a schematic diagram of the Modbus RTU / ASCII message format. See Figure 3 As shown in the figure, in the Modbus RTU / ASCII protocol, the message frame mainly consists of four parts: a device address, a function code, data, and a checksum. The lengths of both the device address and function code fields are 1 byte. Among them, the device address field is similar to the unit identifier field in the Modbus TCP protocol, and the custom part of the function code field is the same as that in the Modbus TCP protocol. The length of the data field is variable. In Modbus RTU, the checksum is a CRC checksum, with a total of 2 bytes; in Modbus ASCII, the checksum is an LRC checksum, also 2 bytes.

[0043] Specifically, the first ciphertext and the second ciphertext are shared between the master node and the slave node, including:

[0044] Step B1: The master node generates a first ciphertext based on a first random number, a preset key, and the master node address, generates a third message based on the first ciphertext, and sends the third message to the slave node using the target function code.

[0045] Among them, the third message includes the first ciphertext.

[0046] Specifically, the expression for generating the first ciphertext is:

[0047] C1 = F enc (K pre,l , R1||MID);

[0048] Among them, C1 is the first ciphertext, K pre,l is the preset key, R1 is the first random number, MID is the master node address, F enc (·) is the function for performing the encryption operation, and || is the concatenation operator.

[0049] Generating the third message based on the first ciphertext and sending the third message to the slave node using the target function code specifically means putting the first ciphertext into the data field of the Modbus TCP protocol, filling in the MBAP message header in the message frame and calculating the checksum to generate the third message, and sending the third message to the slave node using the target function code, and the host node increments the corresponding counter CTRl by 1; or, putting the first ciphertext into the data in the message frame of the Modbus RTU / ASCII protocol, filling in the slave node address and calculating the checksum to generate the third message, and sending the third message to the slave node using the target function code, and the host node increments the corresponding counter CTR l by 1.

[0050] The counter CTR l can prevent message replay.

[0051] Step B2: The slave node generates a second ciphertext based on a second random number, a preset key, and the slave node address, generates a fourth message based on the second ciphertext, and sends the fourth message to the master node using the target function code.

[0052] Among them, the fourth message includes the second ciphertext.

[0053] Specifically, the expression for generating the second ciphertext is:

[0054] C2 = F enc (K pre,l , R2||SID);

[0055] Among them, C2 is the second ciphertext, K pre,l is the preset key, R2 is the second random number, SID is the slave node address, F enc (·) is the function for performing the encryption operation, and || is the concatenation operator.

[0056] Generate the fourth message according to the second ciphertext, and send the fourth message to the master node using the target function code. Specifically, put the second ciphertext into the data field of the Modbus TCP protocol, fill in the MBAP message header in the message frame and calculate the checksum to generate the fourth message, and send the fourth message to the master node using the target function code. The slave node increments the corresponding counter CTR l by 1; alternatively, put the second ciphertext into the data in the message frame of the Modbus RTU / ASCII protocol, fill in the master node address and calculate the checksum to generate the fourth message, and send the fourth message to the master node using the target function code. The slave node increments the corresponding counter CTR l by 1.

[0057] S102. The master node generates the first message authentication code according to the second ciphertext, the preset key and the first random number, and sends the first message to the slave node using the target function code.

[0058] Among them, the first message is the message generated according to the first message authentication code, and the first message includes the first message authentication code.

[0059] Specifically, the master node generates the first message authentication code according to the second ciphertext, the preset key and the first random number, and sends the first message to the slave node using the target function code, including:

[0060] Step C1: The master node generates the first session key according to the second ciphertext, the preset key and the first random number through the key derivation function.

[0061] Specifically, step C1 includes:

[0062] Step C11: The master node decrypts the second ciphertext using the preset key to obtain the decrypted second random number.

[0063] The expression of the decrypted second random number is:

[0064] R2'||SID = F dec (K pre,l , C2);

[0065] Among them, R2' is the decrypted second random number, SID is the slave node address, F dec (·) is the function for performing the decryption operation, K pre,l is the preset key, and C2 is the second ciphertext.

[0066] Step C12: The master node generates the first session key according to the first random number and the decrypted second random number through the key derivation function.

[0067] The expression of the first session key is:

[0068] K1 sess,l = KDF(R1 || R2');

[0069] Wherein, K1 sess,l is the first session key, KDF is a key derivation function, R1 is the first random number, and R2' is the decrypted second random number.

[0070] Step C2: The master node generates a first message authentication code according to the first session key and the first random number, generates a first message according to the first message authentication code, and sends the first message to the slave node by using the target function code.

[0071] Specifically, the expression of the first message authentication code is:

[0072] AUTH1 = F mac (K1 sess,l , R1);

[0073] Wherein, AUTH1 is the first message authentication code, and F mac (·) is a one-way function for generating a message authentication code, K1 sess,l is the first session key, and R1 is the first random number.

[0074] Generate a first message according to the first message authentication code, and send the first message to the slave node by using the target function code. Specifically, put the first message authentication code into the data field of the Modbus TCP protocol, fill in the MBAP message header in the message frame and calculate the checksum to generate the first message, and send the first message to the slave node by using the target function code. The master node increments the corresponding counter CTR l by 1; or, put the first message authentication code into the data in the message frame of the Modbus RTU / ASCII protocol, fill in the slave node address and calculate the checksum to generate the first message, and send the first message to the slave node by using the target function code. The master node increments the corresponding counter CTR l by 1.

[0075] S103. The slave node authenticates the identity of the master node according to the first message authentication code, the first ciphertext, the preset key, and the second random number.

[0076] Specifically, the slave node authenticates the identity of the master node according to the first message authentication code, the first ciphertext, the preset key, and the second random number, including:

[0077] Step D1: The slave node decrypts the first ciphertext by using the preset key to obtain the decrypted first random number.

[0078] The expression of the decrypted first random number is:

[0079] R1' || MID = Fdec (K pre,l , C1);

[0080] Wherein, R1' is the decrypted first random number, MID is the main node address, F dec (·) is the function for performing decryption operation, K pre,l is the pre-set key, and C1 is the first ciphertext.

[0081] Step D2: The slave node generates a second session key according to the decrypted first random number and the second random number through a key derivation function.

[0082] The expression of the second session key is:

[0083] K2 sess,l = KDF(R1' || R2);

[0084] Wherein, K2 sess,l is the second session key, KDF is the key derivation function, R2 is the second random number, and R1' is the decrypted first random number.

[0085] Step D3: The slave node generates a first verified message authentication code according to the second session key and the decrypted first random number.

[0086] The expression of the first verified message authentication code is:

[0087] XAUTH1 = F mac (K2 sess,l , R1');

[0088] Wherein, XAUTH1 is the first verified message authentication code, F mac (·) is the one-way function for generating the message authentication code, K2 sess,l is the second session key, and R1' is the decrypted first random number.

[0089] Step D4: The slave node determines whether the first verified message authentication code is the same as the first message authentication code.

[0090] The slave node determines whether the first verified message authentication code is the same as the first message authentication code. If they are the same, step D5 is executed; if they are not the same, step D6 is executed.

[0091] Step D5: The slave node authenticates the main node successfully.

[0092] When the slave node determines that the first verified message authentication code is the same as the first message authentication code, the slave node authenticates the main node successfully and then continues to execute step S104.

[0093] Step D6: The slave node authenticates the main node failed.

[0094] When the slave node determines that the first verified message authentication code is different from the first message authentication code, the slave node fails to authenticate the master node. After the slave node fails to authenticate the master node, it can return to step S101 to continue execution until the slave node successfully authenticates the master node. After the slave node fails to authenticate the master node, it can also end the authentication.

[0095] S104. When the slave node successfully authenticates the identity of the master node, the slave node generates a second message authentication code based on the first ciphertext, the preset key, and the second random number, and sends the second message to the master node using the target function code.

[0096] Among them, the second message is a message generated based on the second message authentication code, and the second message includes the second message authentication code.

[0097] Specifically, when the slave node successfully authenticates the identity of the master node, the slave node generates a second message authentication code based on the first ciphertext, the preset key, and the second random number, and sends the second message to the master node using the target function code, including:

[0098] Step E1: When the slave node successfully authenticates the identity of the master node, the slave node generates a second session key based on the first ciphertext, the preset key, and the second random number through a key derivation function.

[0099] Specifically, step E1 includes:

[0100] Step E11: When the slave node successfully authenticates the identity of the master node, the slave node decrypts the first ciphertext using the preset key to obtain the decrypted first random number.

[0101] The expression of the decrypted first random number in step E11 is the same as the expression of the decrypted first random number in step D1.

[0102] Step E12: Generate a second session key based on the decrypted first random number and the second random number through a key derivation function.

[0103] The expression of the second session key in step E12 is the same as the expression of the second session key in step D2.

[0104] Step E2: The slave node generates a second message authentication code based on the second session key and the second random number, generates a second message based on the second message authentication code, and sends the second message to the master node using the target function code.

[0105] Specifically, the expression of the second message authentication code is:

[0106] AUTH2 = F mac (K2 sess,l , R2);

[0107] Among them, AUTH2 is the second message authentication code, Fmac (·) is a one-way function for generating a message authentication code, K2 sess,l is the second session key, and R2 is the second random number.

[0108] Generate a second message according to the second message authentication code, and send the second message to the master node by using the target function code. Specifically, put the second message authentication code into the data field of the Modbus TCP protocol, fill in the MBAP message header in the message frame and calculate the checksum to generate the second message, and send the second message to the master node by using the target function code. The slave node adds 1 to the corresponding counter CTR l ; or, put the second message authentication code into the data in the message frame of the Modbus RTU / ASCII protocol, fill in the master node address and calculate the checksum to generate the second message, and send the second message to the master node by using the target function code. The slave node adds 1 to the corresponding counter CTR l by 1.

[0109] S105. The master node authenticates the identity of the slave node according to the second message authentication code, the second ciphertext, the preset key, and the first random number, so as to enhance the security of the Modbus protocol.

[0110] Specifically, the master node authenticates the identity of the slave node according to the second message authentication code, the second ciphertext, the preset key, and the first random number, so as to enhance the security of the Modbus protocol, including:

[0111] Step F1: The master node decrypts the second ciphertext by using the preset key to obtain the decrypted second random number.

[0112] The expression of the decrypted second random number in Step F1 is the same as the expression of the decrypted second random number in Step C11.

[0113] Step F2: Generate the first session key through a key derivation function according to the first random number and the decrypted second random number.

[0114] The expression of the first session key in Step F2 is the same as the expression of the first session key in Step C12.

[0115] Step F3: The master node generates a second verified message authentication code according to the first session key and the decrypted second random number.

[0116] The expression of the second verified message authentication code is:

[0117] XAUTH2 = F mac (K1 sess,l , R2');

[0118] where XAUTH2 is the second verified message authentication code, Fmac (·) is a one-way function for generating a message authentication code, and K1 sess,l is the first session key, and R2′ is the decrypted second random number.

[0119] Step F4: The master node determines whether the second verified message authentication code and the second message authentication code are the same.

[0120] The master node determines whether the second verified message authentication code and the second message authentication code are the same. If they are the same, step F5 is executed; if they are not the same, step F6 is executed.

[0121] Step F5: The master node successfully authenticates the slave node's identity to achieve the security enhancement of the Modbus protocol.

[0122] Step F6: The master node fails to authenticate the slave node's identity.

[0123] When the master node determines that the second verified message authentication code and the second message authentication code are different, the master node fails to authenticate the slave node's identity. After the master node fails to authenticate the slave node's identity, it can return to step S101 to continue execution until the master node successfully authenticates the slave node's identity. After the master node fails to authenticate the slave node's identity, it can also end the authentication.

[0124] The following Embodiment 1 is for the security enhancement of the Modbus TCP protocol in the unicast communication scenario. The Modbus TCP protocol includes a target function code for indicating identity authentication and key negotiation using a message:

[0125] The two nodes for identity authentication are respectively denoted as the master node and the slave node.

[0126] Figure 4 Schematically shows a schematic diagram of the identity authentication and session key negotiation process of Embodiment 1 of the present invention. Refer to Figure 4 As shown, the security enhancement method for the Modbus TCP protocol in the unicast communication scenario includes:

[0127] Step S1: The master node generates a random number R 11 , encrypts the random number R pre,l1 using the preset key K 11 and the master node address MID1 of the master node to obtain the ciphertext C 11 , puts the ciphertext C 11 into the data field of the Modbus TCP protocol, fills in the MBAP packet header and calculates the checksum to generate a packet containing the ciphertext C 11 , and sends the packet containing the ciphertext C 11 to the slave node using the 0x6D function code. The host node increments the corresponding counter CTR l1 by 1.

[0128] Ciphertext C 11 has the same expression as the first ciphertext in step B1.

[0129] Step S2: Generate a random number R from the node 21 , and use the preset key K pre,l1 to encrypt the random number R 21 and the ciphertext C obtained from the slave node address SID1 21 , put the ciphertext C 21 into the data field of the Modbus TCP protocol, fill in the MBAP message header and calculate the checksum to generate a message containing the ciphertext C 21 , and use the function code 0x6D to send the message containing the ciphertext C 21 to the master node, and the slave node increments the corresponding counter CTR l1 by 1.

[0130] Ciphertext C 21 has the same expression as the second ciphertext in step B2.

[0131] Step S3: After the master node receives the ciphertext C 21 , it decrypts it using the preset key K pre,l1 , obtains the decrypted random number R of the slave node from the data field of the Modbus TCP protocol 21 ', and based on the decrypted random number R 21 ' and the random number R 11 , generates a session key K1 sess,l1 .

[0132] Session key K1 sess,l1 has the same expression as the first session key in step C12.

[0133] Similarly, the slave node uses the preset key K pre,l1 to decrypt the ciphertext C 11 to obtain the corresponding decrypted random number R of the master node from the data field of the Modbus TCP protocol 11 ', and based on the decrypted random number R 11 ' and the random number R 21 , generates a session key K2 sess,l1 .

[0134] Session key K2 sess,l1 has the same expression as the second session key in step D2.

[0135] Step S4: The master node uses the session key K1 sess,l1 to calculate the message authentication code AUTH of the random number R 11 11 ​, put the message authentication code AUTH 11 into the data field of the Modbus TCP protocol, fill in the MBAP header and calculate the checksum to generate a message containing the message authentication code AUTH 11 of the message. Use the function code 0x6D to send the message containing the message authentication code AUTH 11 to the slave node, and the master node increments the corresponding counter CTR l1 by 1.

[0136] The expression of the message authentication code AUTH 11 is the same as the expression of the first message authentication code in step C2.

[0137] Step S5: After receiving the message authentication code AUTH 11 , according to the session key K2 sess,l1 and the decrypted random number R 11 ', calculate the verified message authentication code XAUTH 11 , and compare the verified message authentication code XAUTH 11 with the message authentication code AUTH 11 to check if they are equal. If the verified message authentication code XAUTH 11 is equal to the message authentication code AUTH 11 , the slave node successfully authenticates the identity of the master node.

[0138] The expression of the verified message authentication code XAUTH 11 is the same as the expression of the first verified message authentication code in step D3.

[0139] If the verified message authentication code XAUTH 11 is not equal to the message authentication code AUTH 11 , the slave node fails to authenticate the identity of the master node. After the authentication of the master node fails, it can return to step S1 to continue execution until the slave node successfully authenticates the master node. After the authentication of the master node fails, the authentication can also end.

[0140] Step S6: The slave node uses the session key K2 sess,l1 to calculate the message authentication code AUTH 21 of the random number R 21 , put the message authentication code AUTH 21 into the data field of the Modbus TCP protocol, fill in the MBAP header and calculate the checksum to generate a message containing the message authentication code AUTH 21 of the message. Use the function code 0x6D to send the message containing the message authentication code AUTH 21 to the master node, and the slave node increments the corresponding counter CTR l1 by 1.

[0141] Message Authentication Code AUTH 21 The expression of is the same as that of the second message authentication code in step E2.

[0142] Step S7: After the master node receives the message authentication code AUTH 21 According to the session key K1 sess,l1 and the decrypted random number R 21 ' Calculate the verified message authentication code XAUTH 21 and compare the verified message authentication code XAUTH 21 with the message authentication code AUTH 21 to check if they are equal. If the verified message authentication code XAUTH 21 is equal to the message authentication code AUTH 21 the master node successfully authenticates the slave node's identity.

[0143] The expression of the verified message authentication code XAUTH 21 is the same as that of the second verified message authentication code in step F3.

[0144] The verified message authentication code XAUTH 21 and the message authentication code AUTH 21 If they are not equal, the master node fails to authenticate the slave node's identity. After the master node fails to authenticate the slave node's identity, it can return to step S1 to continue execution until the master node successfully authenticates the slave node's identity. After the master node fails to authenticate the slave node's identity, it can also end the authentication.

[0145] The Modbus TCP protocol is implemented based on symmetric cryptographic algorithms. For example, the national cipher SM4 symmetric key algorithm can be used for encryption or decryption, and the national cipher SM3 algorithm can be used to generate the verified message authentication code.

[0146] The following Example 2 is a security enhancement for the Modbus RTU / ASCII protocol in the unicast communication scenario. The Modbus RTU / ASCII protocol includes target function codes for indicating identity authentication and key negotiation using messages:

[0147] The two nodes for identity authentication are respectively denoted as the master node and the slave node.

[0148] The security enhancement method for the Modbus RTU / ASCII protocol in the unicast communication scenario includes:

[0149] Step 1: The master node generates a random number R 12 encrypts the random number R 12 using the preset key Kpre,l2 and the master node address MID2 of the master node to obtain the ciphertext C 12 and sends the ciphertext C 12Put it into the data of Modbus RTU / ASCII protocol, fill in the slave node address and calculate the check code to generate the ciphertext C 12 of the message, and use the function code 0x6D to send the message containing the ciphertext C 12 to the slave node, and the host node increments the corresponding counter CTR l2 by 1.

[0150] Ciphertext C 12 has the same expression as the first ciphertext in step B1.

[0151] Step 2: The slave node generates a random number R 22 , uses the preset key K pre,l2 to encrypt the random number R 22 and the slave node address SID2 to obtain the ciphertext C 22 , put the ciphertext C 22 into the data of Modbus RTU / ASCII protocol, fill in the master node address and calculate the check code to generate the ciphertext C 22 of the message, and use the function code 0x6D to send the message containing the ciphertext C 22 to the master node, and the slave node increments the corresponding counter CTR l2 by 1.

[0152] Ciphertext C 22 has the same expression as the second ciphertext in step B2.

[0153] Step 3: After receiving the ciphertext C 22 , the master node uses the preset key K pre,l2 to decrypt it, obtains the decrypted random number R 22 ' of the slave node from the data of Modbus RTU / ASCII protocol, and based on the decrypted random number R 22 ' and the random number R 12 , generates the session key K1 sess,l2 .

[0154] Session key K1 sess,l2 has the same expression as the first session key in step C12.

[0155] Similarly, the slave node uses the preset key K pre,l2 to decrypt the ciphertext C 12 to obtain the corresponding decrypted random number R 12 ' of the master node from the data of Modbus RTU / ASCII protocol, and based on the decrypted random number R 12 ' and the random number R 22 , generates the session key K2 sess,l2 .

[0156] Session key K2 sess,l2 has the same expression as the second session key in step D2.

[0157] Step 4: The master node uses the session key K1 sess,l2 to calculate the random number R 12 and the message authentication code AUTH 12 of. Put the message authentication code AUTH 12 into the data of the Modbus RTU / ASCII protocol, fill in the slave node address and calculate the checksum to generate a message containing the message authentication code AUTH 12 of the message. Use the function code 0x6D to send the message containing the message authentication code AUTH 12 to the slave node. The master node increments the corresponding counter CTR l2 by 1.

[0158] The message authentication code AUTH 12 has the same expression as the first message authentication code in step C2.

[0159] Step 5: After receiving the message authentication code AUTH 12 , the slave node calculates the verified message authentication code XAUTH sess,l2 based on the session key K2 12 and the decrypted random number R 12 , and compares the verified message authentication code XAUTH 12 with the message authentication code AUTH 12 to check if they are equal. If the verified message authentication code XAUTH 12 is equal to the message authentication code AUTH 12 , the slave node successfully authenticates the master node's identity.

[0160] The verified message authentication code XAUTH 12 has the same expression as the first verified message authentication code in step D3.

[0161] The verified message authentication code XAUTH 12 is not equal to the message authentication code AUTH 12 , the slave node fails to authenticate the master node's identity. After the slave node fails to authenticate the master node, it can return to step 1 and continue execution until the slave node successfully authenticates the master node. After the slave node fails to authenticate the master node, it can also end the authentication.

[0162] Step 6: The slave node uses the session key K2 sess,l2 to calculate the random number R 22 and the message authentication code AUTH 22 of. Put the message authentication code AUTH 22Put it into the data of Modbus RTU / ASCII protocol, fill in the master node address and calculate the check code to generate a message containing the message authentication code AUTH 22 of the message, and use the function code 0x6D to send the message containing the message authentication code AUTH 22 to the master node. The slave node will increment the corresponding counter CTR l2 by 1.

[0163] The expression of the message authentication code AUTH 22 is the same as the expression of the second message authentication code in step E2.

[0164] Step 7: After the master node receives the message authentication code AUTH 22 , according to the session key K1 sess,l2 and the decrypted random number R 22 ' calculate the verified message authentication code XAUTH 22 , and compare the verified message authentication code XAUTH 22 with the message authentication code AUTH 22 to check if they are equal. When the verified message authentication code XAUTH 22 is equal to the message authentication code AUTH 22 , the master node successfully authenticates the identity of the slave node.

[0165] The expression of the verified message authentication code XAUTH 22 is the same as the expression of the second verified message authentication code in step F3.

[0166] When the verified message authentication code XAUTH 22 is not equal to the message authentication code AUTH 22 , the master node fails to authenticate the identity of the slave node. After the master node fails to authenticate the identity of the slave node, it can return to step 1 to continue execution until the master node successfully authenticates the identity of the slave node. After the master node fails to authenticate the identity of the slave node, it can also end the authentication.

[0167] The Modbus RTU / ASCII protocol is implemented based on symmetric cryptography algorithms. For example, the national cryptography SM4 symmetric key algorithm can be used for encryption or decryption, and the national cryptography SM3 algorithm can be used to generate the verified message authentication code.

[0168] In the first and second embodiments of the present invention, by introducing two-way authentication, it is ensured that both communication parties (the master node and the slave node) authenticate each other before the start of communication. The master node and the slave node generate encrypted data by using their respective preset keys to ensure the legitimacy of both parties' identities and prevent illegal devices from accessing. By introducing random number generation in the identity authentication process, independent session keys can be generated by both parties before each communication. By encrypting the random number with their respective preset keys, the communication parties can ensure that the generated keys are confidential and unique, thus preventing the session keys from being stolen or forged. The present invention fully complies with the current national standard GB / T 19582—2008 "Industrial Automation Network Specification Based on Modbus Protocol" of the Modbus protocol. Without making any modifications to the frame format of the current Modbus protocol, it can be compatible with the traditional Modbus TCP protocol and the Modbus RTU / ASCII protocol, and there is no need to update the hardware or significantly update the software of the original devices. Only by simply adding custom function codes can the identity authentication and key negotiation functions be supported, which is convenient for seamless integration and deployment in the existing system.

[0169] In terms of security, the present invention effectively prevents common network attacks and ensures the security of communication by introducing technologies such as random numbers, key negotiation, and message authentication codes. Each session generates a new session key and random number to prevent replay attacks, that is, the same message cannot be reused in different sessions. In addition, through identity authentication and message integrity verification, the present invention effectively prevents man-in-the-middle attacks and avoids attackers from tampering with data or pretending to be legitimate devices for communication. At the same time, all communication data is encrypted and authenticated to ensure that only authenticated devices can participate in communication, thus effectively preventing forged devices from accessing the network. These security mechanisms jointly guarantee the integrity, confidentiality, and credibility of the system and reduce potential security risks.

[0170] In terms of performance, compared with the existing solutions of traditional identity authentication based on public key infrastructure or digital signatures, the present invention adopts a symmetric encryption and message authentication code mechanism, significantly reducing the computational overhead. Moreover, there are only 4 types of cryptographic elements in the present invention, specifically the preset key, session key, first random number, and second random number, while there are as many as 11 types of cryptographic elements in the existing solutions. The management of such a large number of cryptographic elements is complex in industrial control systems; among them, there are asymmetric cryptographic operations. Considering that the computing power of device nodes in the actual industrial control network is very limited. Specifically, for current industrial control devices such as remote terminal units (RTUs), programmable logic controllers (PLCs), sensors, etc., the microcontrollers of these devices are mostly 8-bit, 16-bit, or 32-bit, with a main frequency ranging from 10 MHz to 200 MHz. These asymmetric cryptographic operations take a long time, all in the order of seconds, resulting in high latency. Traditional public key algorithms and digital signatures are often difficult to implement on these devices and are not suitable for industrial control network scenarios. For example, for the 84 MHz Arduino Due, the operation time for generating a single key using the public key signature algorithm P521 is 1860 ms / byte, and even when only using public key encryption, the single encryption operation time is 1503 ms / byte. However, through the use of the preset key and the identity authentication method based on symmetric encryption in the present invention, the single encryption operation time using the symmetric encryption algorithm AES128 is 6.58 us / byte, which can ensure that the identity authentication and key negotiation of low-computing-power devices are not restricted by resources. By introducing a key negotiation mechanism based on random number generation, the present invention can quickly generate a session key between devices and ensure data integrity and identity authentication through a message authentication code. The key negotiation and authentication method of the present invention can be completed in a short time and is suitable for industrial control systems with high real-time requirements. Compared with the traditional authentication mechanism based on public key encryption and multiple rounds of interaction, the present invention reduces the number of message exchanges in the authentication process, reduces latency, and improves the overall communication efficiency.

[0171] The authentication process of the present invention is directly carried out between the master node and the slave node in a decentralized manner without relying on an external authentication server, reducing the system complexity and potential failure points and enhancing the system reliability. The present invention is applicable not only to the Modbus TCP protocol but also to the Modbus RTU / ASCII protocol, featuring strong adaptability and compatibility. Whether through Ethernet connection (Modbus TCP) or serial communication (Modbus RTU / ASCII), this solution can provide effective identity authentication and security guarantee for Modbus communication in different environments, enhancing its deployability in different industrial control systems. Without large-scale system reconstruction or protocol replacement, it can be easily integrated into existing industrial automation systems, reducing the implementation complexity and cost. Due to its low computing requirements and simplified protocol process, device manufacturers and system integrators can conveniently apply this solution to existing Modbus devices and networks, thereby enhancing the security of the entire system.

[0172] The method for enhancing the security of the Modbus protocol in the unicast communication scenario of the present invention has broad application prospects, not limited to industrial control networks, but also can be used for various purposes such as device authentication and secure data transmission in multiple fields (such as intelligent transportation, industrial Internet of Things, smart home, driverless, digital currency, etc.).

[0173] Based on the above Figure 1 implementation method, it can be seen that the Modbus protocol of the present invention includes target function codes for identity authentication and key negotiation using messages, and the first ciphertext and the second ciphertext are shared between the master node and the slave node; the master node generates the first message authentication code based on the second ciphertext, the preset key, and the first random number, and sends the first message to the slave node using the target function code; the slave node authenticates the identity of the master node based on the first message authentication code, the first ciphertext, the preset key, and the second random number; when the slave node successfully authenticates the identity of the master node, the slave node generates the second message authentication code based on the first ciphertext, the preset key, and the second random number, and sends the second message to the master node using the target function code; the master node authenticates the identity of the slave node based on the second message authentication code, the second ciphertext, the preset key, and the first random number to achieve the security enhancement of the Modbus protocol. In this way, through the shared first ciphertext and second ciphertext, it can be ensured that the master node and the slave node sharing the ciphertext communicate, the legitimacy of the master node and the slave node can be verified, the slave node can authenticate the identity of the master node through the generated first message authentication code, the master node authenticates the identity of the slave node through the generated second message authentication code, and the messages are sent and negotiated for authentication using the target function code, which can ensure the validity of the identities of both communication parties and guarantee the integrity and confidentiality of data during transmission.

[0174] Based on the same inventive concept, as an implementation of the above-mentioned method for enhancing the security of the Modbus protocol in a unicast communication scenario, an embodiment of the present invention further provides a system for enhancing the security of the Modbus protocol in a unicast communication scenario. Figure 5 It is a structural diagram of the system for enhancing the security of the Modbus protocol in a unicast communication scenario in an embodiment of the present invention. Refer to Figure 5 As shown, the Modbus protocol includes target function codes for performing identity authentication and key negotiation using messages. The system may include:

[0175] A sharing module 501 for sharing a first ciphertext and a second ciphertext between a master node and a slave node. The first ciphertext is the ciphertext corresponding to the master node, and the second ciphertext is the ciphertext corresponding to the slave node;

[0176] A first generation module 502 for the master node to generate a first message authentication code according to the second ciphertext, a preset key, and a first random number, and send a first message to the slave node using the target function code. The first message is a message generated according to the first message authentication code, and the first message includes the first message authentication code;

[0177] A first authentication module 503 for the slave node to authenticate the identity of the master node according to the first message authentication code, the first ciphertext, the preset key, and a second random number;

[0178] A second generation module 504 for the slave node to generate a second message authentication code according to the first ciphertext, the preset key, and the second random number when the slave node successfully authenticates the identity of the master node, and send a second message to the master node using the target function code. The second message is a message generated according to the second message authentication code, and the second message includes the second message authentication code;

[0179] A second authentication module 505 for the master node to authenticate the identity of the slave node according to the second message authentication code, the second ciphertext, the preset key, and the first random number to achieve the security enhancement of the Modbus protocol.

[0180] The device may further include:

[0181] A setting module for setting an unoccupied function code as the target function code using a custom function. The target function code is used to indicate performing identity authentication and key negotiation using the first message and the second message.

[0182] The shared module 501 is specifically used for the master node to generate a first ciphertext based on a first random number, a preset key, and the master node address, generate a third message according to the first ciphertext, and send the third message to the slave node using a target function code. The third message includes the first ciphertext. The slave node generates a second ciphertext according to a second random number, a preset key, and the slave node address, generates a fourth message according to the second ciphertext, and sends the fourth message to the master node using the target function code. The fourth message includes the second ciphertext.

[0183] The first generation module 502 is specifically used for the master node to generate a first session key through a key derivation function according to the second ciphertext, the preset key, and the first random number. The master node generates a first message authentication code according to the first session key and the first random number, generates a first message according to the first message authentication code, and sends the first message to the slave node using the target function code.

[0184] The first generation module 502, where the master node generates a first session key through a key derivation function according to the second ciphertext, the preset key, and the first random number, includes: the master node decrypts the second ciphertext using the preset key to obtain the decrypted second random number. The master node generates a first session key through a key derivation function according to the first random number and the decrypted second random number.

[0185] The first authentication module 503 is specifically used for the slave node to decrypt the first ciphertext using the preset key to obtain the decrypted first random number. The slave node generates a second session key through a key derivation function according to the decrypted first random number and the second random number. The slave node generates a first verified message authentication code according to the second session key and the decrypted first random number. The slave node determines whether the first verified message authentication code is the same as the first message authentication code. If they are the same, the slave node successfully authenticates the master node. If they are not the same, the slave node fails to authenticate the master node.

[0186] The second generation module 504 is specifically used for the slave node to generate a second session key through a key derivation function according to the first ciphertext, the preset key, and the second random number when the slave node successfully authenticates the identity of the master node. The slave node generates a second message authentication code according to the second session key and the second random number, generates a second message according to the second message authentication code, and sends the second message to the master node using the target function code.

[0187] The second generation module 504, when the slave node successfully authenticates the identity of the master node, the slave node generates a second session key through a key derivation function according to the first ciphertext, the preset key, and the second random number, includes: when the slave node successfully authenticates the identity of the master node, the slave node decrypts the first ciphertext using the preset key to obtain the decrypted first random number. Generate a second session key through a key derivation function according to the decrypted first random number and the second random number.

[0188] The second authentication module 505 is specifically configured for the master node to decrypt the second ciphertext using a preset key to obtain the decrypted second random number; generate a first session key through a key derivation function according to the first random number and the decrypted second random number; the master node generates a second verified message authentication code according to the first session key and the decrypted second random number; the master node determines whether the second verified message authentication code is the same as the second message authentication code; if they are the same, the master node successfully authenticates the slave node's identity to achieve the security enhancement of the Modbus protocol; if they are not the same, the master node fails to authenticate the slave node's identity.

[0189] It should be noted here that the description of the embodiments of the Modbus protocol security enhancement system in the unicast communication scenario above is similar to the description of the embodiments of the Modbus protocol security enhancement method in the unicast communication scenario, and has beneficial effects similar to those of the embodiments of the Modbus protocol security enhancement method in the unicast communication scenario. For the technical details not disclosed in the embodiments of the Modbus protocol security enhancement system in the unicast communication scenario of the present invention, please refer to the description of the embodiments of the Modbus protocol security enhancement method in the unicast communication scenario of the present invention for understanding.

[0190] The above are only the specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present invention, and all of them should be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A method for enhancing the security of the Modbus protocol in a unicast communication scenario, characterized in that, The Modbus protocol includes target function codes for identity authentication and key negotiation using messages, including: Share a first ciphertext and a second ciphertext between the master node and the slave node. The first ciphertext is the ciphertext corresponding to the master node, and the second ciphertext is the ciphertext corresponding to the slave node; The master node generates a first message authentication code according to the second ciphertext, a preset key, and a first random number, and sends a first message to the slave node using the target function code. The first message is a message generated according to the first message authentication code, and the first message includes the first message authentication code; The slave node authenticates the identity of the master node according to the first message authentication code, the first ciphertext, the preset key, and a second random number; When the slave node successfully authenticates the identity of the master node, the slave node generates a second message authentication code according to the first ciphertext, the preset key, and the second random number, and sends a second message to the master node using the target function code. The second message is a message generated according to the second message authentication code, and the second message includes the second message authentication code; The master node authenticates the identity of the slave node according to the second message authentication code, the second ciphertext, the preset key, and the first random number to enhance the security of the Modbus protocol.

2. The Modbus protocol security enhancement method in the unicast communication scenario according to claim 1, characterized in that Before sharing the first ciphertext and the second ciphertext between the master node and the slave node, the method further includes: Using the custom function, set the unoccupied function code as the target function code, and the target function code is used to indicate identity authentication and key negotiation using the first message and the second message.

3. The method for enhancing the security of the Modbus protocol in the unicast communication scenario according to claim 1, wherein The sharing of the first ciphertext and the second ciphertext between the master node and the slave node includes: The master node generates the first ciphertext according to the first random number, the preset key, and the master node address, generates a third message according to the first ciphertext, and sends the third message to the slave node using the target function code. The third message includes the first ciphertext; The slave node generates the second ciphertext according to the second random number, the preset key, and the slave node address, generates a fourth message according to the second ciphertext, and sends the fourth message to the master node using the target function code. The fourth message includes the second ciphertext.

4. The method for enhancing the security of the Modbus protocol in the unicast communication scenario according to claim 1, characterized in that, The master node generates a first message authentication code according to the second ciphertext, a preset key, and a first random number, and sends a first message to the slave node using the target function code, including: The master node generates a first session key through a key derivation function according to the second ciphertext, the preset key, and the first random number; The master node generates the first message authentication code according to the first session key and the first random number, generates the first message according to the first message authentication code, and sends the first message to the slave node using the target function code.

5. The method for enhancing the security of the Modbus protocol in the unicast communication scenario according to claim 4, wherein The master node generates a first session key through a key derivation function according to the second ciphertext, the preset key, and the first random number, including: The master node decrypts the second ciphertext using the preset key to obtain the decrypted second random number; The master node generates the first session key through the key derivation function according to the first random number and the decrypted second random number.

6. The method for enhancing the security of the Modbus protocol in the unicast communication scenario according to claim 1, wherein The slave node authenticates the identity of the master node according to the first message authentication code, the first ciphertext, the preset key and the second random number, including: The slave node decrypts the first ciphertext using the preset key to obtain the decrypted first random number; The slave node generates the second session key through the key derivation function according to the decrypted first random number and the second random number; The slave node generates a first verified message authentication code according to the second session key and the decrypted first random number; The slave node determines whether the first verified message authentication code is the same as the first message authentication code; If they are the same, the slave node successfully authenticates the master node; If they are not the same, the slave node fails to authenticate the master node.

7. The method for enhancing the security of the Modbus protocol in the unicast communication scenario according to claim 1, wherein When the slave node successfully authenticates the identity of the master node, the slave node generates a second message authentication code according to the first ciphertext, the preset key and the second random number, and sends a second message to the master node using the target function code, including: When the slave node successfully authenticates the identity of the master node, the slave node generates the second session key through the key derivation function according to the first ciphertext, the preset key and the second random number; The slave node generates the second message authentication code according to the second session key and the second random number, generates the second message according to the second message authentication code, and sends the second message to the master node using the target function code.

8. The method for enhancing the security of the Modbus protocol in the unicast communication scenario according to claim 7, characterized in that, When the slave node successfully authenticates the identity of the master node, the slave node generates the second session key through the key derivation function according to the first ciphertext, the preset key and the second random number, including: When the slave node successfully authenticates the identity of the master node, the slave node decrypts the first ciphertext using the preset key to obtain the decrypted first random number; According to the decrypted first random number and the second random number, the second session key is generated through the key derivation function.

9. The method for enhancing the security of the Modbus protocol in the unicast communication scenario according to claim 1, characterized in that, The master node authenticates the identity of the slave node according to the second message authentication code, the second ciphertext, the preset key and the first random number to enhance the security of the Modbus protocol, including: The master node decrypts the second ciphertext using the preset key to obtain the decrypted second random number; According to the first random number and the decrypted second random number, the first session key is generated through the key derivation function; The master node generates a second verified message authentication code according to the first session key and the decrypted second random number; The master node determines whether the second verified message authentication code is the same as the second message authentication code; If they are the same, the master node successfully authenticates the identity of the slave node to enhance the security of the Modbus protocol; If they are not the same, the master node fails to authenticate the identity of the slave node.

10. A Modbus protocol security enhancement system in a unicast communication scenario, characterized in that, The Modbus protocol includes target function codes for identity authentication and key negotiation using messages, including: A sharing module for sharing a first ciphertext and a second ciphertext between the master node and the slave node, where the first ciphertext is the ciphertext corresponding to the master node and the second ciphertext is the ciphertext corresponding to the slave node; A first generation module for the master node to generate a first message authentication code according to the second ciphertext, a preset key, and a first random number, and send a first message to the slave node using the target function code, where the first message is a message generated according to the first message authentication code and the first message includes the first message authentication code; A first authentication module for the slave node to authenticate the identity of the master node according to the first message authentication code, the first ciphertext, the preset key, and a second random number; A second generation module for the slave node to generate a second message authentication code according to the first ciphertext, the preset key, and the second random number when the slave node successfully authenticates the identity of the master node, and send a second message to the master node using the target function code, where the second message is a message generated according to the second message authentication code and the second message includes the second message authentication code; A second authentication module for the master node to authenticate the identity of the slave node according to the second message authentication code, the second ciphertext, the preset key, and the first random number to enhance the security of the Modbus protocol.

Citation Information

Patent Citations

  • TPM-based Modbus / TCP security enhancement method

    CN105721500A

  • Secret key negotiation method and device

    CN106603485A

  • Real-time acquisition and communication system and method of signal data

    CN109688555A

  • Modbus TCP protocol safety enhancement method and system

    CN113472520A

  • Power system network security communication method

    CN117278214A

Cited By

  • Modbus protocol security enhancement method in multicast communication scene

    CN120301603A

  • Method for enhancing security of modbus protocol in multicast communication scenario

    CN120301603B