Research and Application of a Commercial Cryptography-Based Identity Authentication System for Nuclear Power DCS
摘要
Facing the severe challenges to nuclear power plant (NPP) cybersecurity and the inadequacy of existing single-factor authentication in meeting the requirements of Classified Protection of Cybersecurity 2.0 (CPC 2.0) and Cryptographic Application (CA), this research focuses on the development and application exploration of a dual-factor authentication system based on commercial cryptography. The system is specifically designed to satisfy the stringent constraints of high real-time performance, high reliability, and high availability inherent to the process control layer of Nuclear Power Plant Digital Control System (DCS). A dual-factor authentication mechanism integrating digital certificates and Personal Identification Numbers (PIN) was implemented. This mechanism utilizes hardware cryptographic modules for secure key storage and cryptographic operation acceleration. Performance was optimized through techniques like hardware acceleration and parallel verification. The system design rigorously adheres to the real-time, reliability, and availability demands of the DCS process control layer. Results demonstrate that the system successfully meets the CPC 2.0 Level 3 and CA Level 3 compliance requirements. Authentication latency was effectively controlled below 1.5 s, ensuring the real-time control needs of the DCS system. Engineering validation showed successful industrial deployment within the non-safety-grade DCS of an operational NPP in China, confirming no adverse impact on the original system’s real-time performance or reliability. This research provides a cryptographic compliance assessment-compliant identity authentication solution for NPP critical infrastructure and holds significant demonstration value for the engineering application of commercial cryptography within the nuclear power sector.