Millions of smart meters, solar panels, and other grid-based devices rely on the Open smart grid protocol
for communication and control — it's similar to SCADA's role for
industrial systems. But new research shows that its creators made the
common mistake of rolling their own encryption, and doing a poor job of it. The researchers believe this threatens the entire system.
They say, "This function has been found to be extremely weak, and
cannot be assumed to provide any authenticity guarantee whatsoever."
Security analyst Adam Crain added, "Protocol designers should stick to
known good algorithms or even the 'NIST-approved' short list. In this
instance, the researchers analyzed the OMA digest function and found
weaknesses in it. The weaknesses in it can be used to determine the
private key in a very small number of trials.
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.