CFP last date
21 September 2026
Reseach Article

Integrating DNP3 Secure Authentication with Transport Layer Security for Enhanced Industrial Control System Security

by Stephen Kofi Dotse, Samuel Yao Sebuabe, Harriet K.O. Lamptey, Kwame Assa-Agyei, Ezekiel Annan Okoe, Marthin Doe
International Journal of Computer Applications
Foundation of Computer Science (FCS), NY, USA
Volume 187 - Number 138
Year of Publication: 2026
Authors: Stephen Kofi Dotse, Samuel Yao Sebuabe, Harriet K.O. Lamptey, Kwame Assa-Agyei, Ezekiel Annan Okoe, Marthin Doe
10.5120/ijcae4e656f4bcb8

Stephen Kofi Dotse, Samuel Yao Sebuabe, Harriet K.O. Lamptey, Kwame Assa-Agyei, Ezekiel Annan Okoe, Marthin Doe . Integrating DNP3 Secure Authentication with Transport Layer Security for Enhanced Industrial Control System Security. International Journal of Computer Applications. 187, 138 ( Aug 2026), 44-57. DOI=10.5120/ijcae4e656f4bcb8

@article{ 10.5120/ijcae4e656f4bcb8,
author = { Stephen Kofi Dotse, Samuel Yao Sebuabe, Harriet K.O. Lamptey, Kwame Assa-Agyei, Ezekiel Annan Okoe, Marthin Doe },
title = { Integrating DNP3 Secure Authentication with Transport Layer Security for Enhanced Industrial Control System Security },
journal = { International Journal of Computer Applications },
issue_date = { Aug 2026 },
volume = { 187 },
number = { 138 },
month = { Aug },
year = { 2026 },
issn = { 0975-8887 },
pages = { 44-57 },
numpages = {9},
url = { https://ijcaonline.org/archives/volume187/number138/integrating-dnp3-secure-authentication-with-transport-layer-security-for-enhanced-industrial-control-system-security/ },
doi = { 10.5120/ijcae4e656f4bcb8 },
publisher = {Foundation of Computer Science (FCS), NY, USA},
address = {New York, USA}
}
%0 Journal Article
%1 2026-08-31T03:10:12+05:30
%A Stephen Kofi Dotse
%A Samuel Yao Sebuabe
%A Harriet K.O. Lamptey
%A Kwame Assa-Agyei
%A Ezekiel Annan Okoe
%A Marthin Doe
%T Integrating DNP3 Secure Authentication with Transport Layer Security for Enhanced Industrial Control System Security
%J International Journal of Computer Applications
%@ 0975-8887
%V 187
%N 138
%P 44-57
%D 2026
%I Foundation of Computer Science (FCS), NY, USA
Abstract

Industrial Control Systems (ICS) and SCADA networks underpin critical national infrastructure across the energy, water, and transportation sectors. Yet, they rely predominantly on the DNP3 protocol, which was designed without inherent provisions for message confidentiality, mutual authentication, or replay protection. DNP3 Secure Authentication Version 5 (DNP3-SA) and Transport Layer Security 1.3 (TLS 1.3) address application-layer integrity and transport-layer confidentiality, respectively, but their combined deployment as a dual-layer defense-in-depth architecture introduces cryptographic overhead whose feasibility on resource-constrained legacy field devices remains uncharacterized. This study presents a systematic empirical evaluation of the integrated dual-layer architecture using a hardware-in-the-loop cyber-physical testbed replicating a representative substation automation environment comprising a SCADA master station, mid-tier ARMv8 and low-specification ARMv7 outstations, and a software-defined network fabric. Four conditions (unprotected baseline, DNP3-SA only, TLS 1.3 only, and the fully integrated dual-layer configuration) were evaluated across 14,760,000 timestamped message exchange records spanning three message categories, three hardware configurations, and three replications. The dual-layer condition imposed a median latency increase of 12.6 ms (600%) over baseline on mid-tier hardware; hardware security module (HSM) offloading reduced 99th-percentile latency by 64%, restoring performance within IEC 61850 Performance Class P2 and NERC CIP-014 thresholds. Penetration testing across five DNP3-specific attack categories aligned with MITRE ATT&CK for ICS showed the integrated architecture achieving a 100% block rate, with a residual 8.7% availability vulnerability under sustained fragmentation storms eliminated by HSM offloading. A one-class support vector machine anomaly detector achieved a 91.3% detection rate at a 3.2% false-positive rate. The findings confirm that the dual-layer architecture is operationally feasible when configured with HSM acceleration and tiered encryption policies. This research contributes the first empirically grounded characterization of the combined latency envelope of DNP3-SA Version 5 and TLS 1.3, an open, reproducible testbed methodology, and an archived experimental dataset.

References
  1. P. Sangewar and A. Buchade, “Security aspects in SCADA and industrial control systems: A review,” in 2020 IEEE International Conference on Advances and Developments in Electrical and Electronics Engineering (ICADEE), 2020, pp. 1–6.
  2. D. Fauri, J. de Ruiter, E. Costante, J. den Hartog, S. Etalle, and E. Zambon, “Leveraging protocol specifications for automated network security assessments,” in Proceedings of the 2017 Workshop on Cyber-Physical Systems Security and Privacy (CPS-SPC), 2017, pp. 51–62.
  3. A. Duka, R. Gumzej, and M. Colnarič, “Security enhancement of DNP3 protocol in SCADA systems,” International Journal of Critical Infrastructure Protection, vol. 18, pp. 10–20, 2017.
  4. R. Tom and V. Dan, “Post-quantum secure DNP3 authentication: Requirements, challenges, and a migration roadmap,” International Journal of Critical Infrastructure Protection, vol. 48, pp. 100710, 2025.
  5. O. Sen, D. Van Der Velde, P. Linnartz, M. Hayes, H. Nahrstedt, and M. Henze, “Investigating the performance of cryptographic protocols for resource-constrained DNP3 outstations in substation automation,” IEEE Transactions on Smart Grid, vol. 13, no. 5, pp. 3868–3880, 2022.
  6. N. Kaâniche, M. Laurent, and Y. Roudier, “Selective cryptographic enforcement in heterogeneous ICS environments: A risk-proportionate framework,” Computers & Security, vol. 138, pp. 103651, 2024.
  7. Z. Lu and Q. Feng, “Hash-based authentication for DNP3 multicast communications in power grid environments,” IET Cyber-Physical Systems: Theory & Applications, vol. 3, no. 4, pp. 160–168, 2018.
  8. A. Mosteiro-Sanchez, M. Barcelo, J. Astorga, and A. Urbieta, “Securing ICS communications: A review of schemes for SCADA and IoT security,” Computers & Industrial Engineering, vol. 148, pp. 106737, 2020.
  9. M. Conti, D. Donadel, and F. Turrin, “A survey on OT and IT security in industrial control systems,” IEEE Communications Surveys & Tutorials, vol. 23, no. 3, pp. 1942–1976, 2021.
  10. C. Cremers, M. Horvat, J. Hoyland, S. Scott, and T. van der Merwe, “A comprehensive symbolic analysis of TLS 1.3,” in Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (CCS), 2018, pp. 1773–1788.
  11. C. Wai and C. Lee, “Intrusion detection in encrypted DNP3 streams: A behavioural anomaly detection approach,” Computers & Security, vol. 127, pp. 103106, 2023.
  12. M. Babić, K. Kuk, B. Popović, and M. Petrović, “Security challenges of legacy SCADA/ICS communication protocols,” Applied Sciences, vol. 12, no. 5, pp. 2659, 2022.
  13. N. Akhtar and A. Masood, “A survey on SCADA security: Challenges, solutions, and future directions,” Journal of Information Security and Applications, vol. 58, pp. 102741, 2021.
  14. M. Ferst, R. de Freitas Vieira, J. Medeiros, and M. Abdelouahab, “Implementation of security with DNP3 in Modbus protocol using TLS,” IEEE Latin America Transactions, vol. 16, no. 2, pp. 476–482, 2018.
  15. P. Michaelides, S. Louvros, and S. Kotsopoulos, “Empirical evaluation of AES-256 and HMAC-SHA-256 overhead in DNP3 secure authentication deployments,” IEEE Communications Letters, vol. 28, no. 3, pp. 611–615, 2024.
  16. Y. Hu, A. Yang, H. Li, Y. Sun, and L. Sun, “A survey of intrusion detection systems for industrial control systems,” Future Generation Computer Systems, vol. 139, pp. 1–18, 2023.
  17. J. Rubio-Hernán, L. De Cicco, and J. García-Alfaro, “Revisiting a watermark-based detection scheme to handle cyber-physical attacks,” in Proceedings of the 11th International Conference on Availability, Reliability and Security (ARES), 2017, pp. 31–37.
  18. I. Fovino, A. Carcano, M. Masera, and A. Trombetta, “An experimental investigation of malware attacks on SCADA systems,” International Journal of Critical Infrastructure Protection, vol. 2, no. 4, pp. 139–145, 2009.
  19. S. Kwon, J. Yun, and Y. Kim, “A study on the vulnerability of DNP3 protocol in the SCADA system,” in Proceedings of the International Conference on Information Science and Security (ICISS), 2017, pp. 1–4.
  20. O. Sen, P. Zech, B. Klaer, M. Henze, and A. Monti, “Encrypted traffic analysis for ICS intrusion detection: A DNP3 case study,” IEEE Internet of Things Journal, vol. 11, no. 6, pp. 10221–10235, 2024.
  21. R. Candell, M. Kashef, Y. Liu, K. Lee, and S. Foufou, “Industrial wireless systems guidelines (NIST Special Publication 1200-2),” National Institute of Standards and Technology, Gaithersburg, MD, 2015.
  22. M. Tabaa, F. Monteiro, H. Bensag, and A. Dandache, “Green industrial internet of things from a smart industry perspective,” Energy Reports, vol. 4, pp. 216–225, 2018.
  23. M. Moharir, M. Chaudhary, and S. Sengupta, “ICSSIM and CR-ICS: Modular emulation platforms for ICS security evaluation,” Journal of Network and Computer Applications, vol. 221, pp. 103757, 2025.
  24. S. Rajesh and C. Satyanarayana, “Secure MODBUS communication using AES, RSA, and HASH algorithms for industrial IoT environments,” International Journal of Innovative Technology and Exploring Engineering, vol. 8, no. 12, pp. 4614–4619, 2019.
  25. Y. Huang, A. Zobaa, and Z. Wang, “Secure communication in smart grids: Challenges, opportunities, and research directions,” IEEE Access, vol. 9, pp. 18707–18728, 2021.
  26. U. Atutxa, A. Almeida, and J. Uribe, “Hardware-accelerated cryptographic offloading for constrained ICS devices in substation automation,” IEEE Transactions on Industrial Informatics, vol. 18, no. 4, pp. 2512–2521, 2022.
  27. H. Bajwa, K. Sood, and S. Chandra, “Adversarial machine learning threats in industrial control system environments,” Computers & Security, vol. 140, pp. 103789, 2025.
  28. S. Figueroa-Lorenzo, J. Añorga, and S. Arrizabalaga, “A role-based access control model in Modbus SCADA systems: A centralized model approach,” Sensors, vol. 19, no. 20, pp. 4455, 2019.
  29. N. Ferry, J. Rossebo, and L. Sela Perelman, “Side-channel vulnerability assessment of cryptographic implementations on resource-constrained ICS hardware,” Journal of Hardware and Systems Security, vol. 7, no. 1, pp. 43–61, 2023.
  30. S. Dokku, R. Ramasamy, and S. Sengupta, “Machine learning-driven anomaly detection in encrypted ICS traffic,” IEEE Transactions on Network and Service Management, vol. 22, no. 1, pp. 110–125, 2025.
  31. D. Upadhyay, J. Manero, M. Zaman, and S. Sampalli, “IoT-integrated SCADA security: Lightweight cryptographic frameworks and threat modelling,” IEEE Internet of Things Journal, vol. 11, no. 4, pp. 6118–6131, 2024.
  32. M. Lotto, M. Shafiq, and K. Bian, “Transition strategies for legacy DNP3 infrastructure: Costs, risks, and regulatory alignment,” IEEE Transactions on Smart Grid, vol. 15, no. 2, pp. 1834–1846, 2024.
  33. IEEE, IEEE standard for electric power systems communications—Distributed Network Protocol (DNP3) (IEEE Std 1815-2012), Institute of Electrical and Electronics Engineers, New York, NY, 2012.
  34. R. Trungadi, N. Sharma, and M. Misra, “Heterogeneous industrial communication security: Evaluating lightweight TLS variants for Modbus and DNP3 environments,” Ad Hoc Networks, vol. 162, pp. 103537, 2025.
  35. U. Ani, H. He, and A. Tiwari, “Human factor security: Evaluating the cybersecurity capacity of the industrial workforce,” Journal of Systems and Information Technology, vol. 21, no. 2, pp. 2–35, 2019.
  36. D. Bhamare, P. Bhatt, and T. Salman, “Cybersecurity threat analysis and attack modelling of critical infrastructure systems,” IEEE Access, vol. 7, pp. 124379–124389, 2019.
  37. M. Kaouk, J. M. Flaus, M. L. Potet, and R. Groz, “A review of intrusion detection systems for industrial control systems,” in Proceedings of the 6th International Symposium on Digital Forensic and Security (ISDFS), 2018, pp. 1–8.
Index Terms

Computer Science
Information Sciences

Keywords

DNP3; Secure Authentication; Transport Layer Security; Industrial Control Systems; SCADA; defense-in-depth; anomaly detection; cryptographic overhead; hardware security module; MITRE ATT&CK for ICS