Overview
IEC TS 62351-8:2011 - "Power systems management and associated information exchange - Data and communications security - Part 8: Role‑based access control" specifies role‑based access control (RBAC) for power system information and communications. The Technical Specification focuses on interoperable access control of users and automated agents to data objects in power systems, enabling secure, vendor‑neutral authorization across utility systems and devices.
Key topics and technical requirements
- RBAC process model: Separation of subjects (users/agents), roles, and rights to simplify and standardize authorization decisions.
- Role definition and mapping: Guidance on defining roles, criteria for role creation, and role‑to‑right mappings - including mandatory roles and rights for logical device access control in power systems.
- Access tokens and profiles: Defines access token structures and supported profiles (examples include X.509 identity certificates, X.509 attribute certificates, and software tokens). Mandatory and optional token fields and identification methods are specified for interoperability.
- Push and Pull architectures: Describes general architectures for PUSH (tokens pushed to services) and PULL (services query LDAP‑enabled directories) authorization models and LDAP directory organization.
- Session and message approaches: Supports both session‑based RBAC and message‑based RBAC for different communication patterns.
- Transport and verification: Notes transport profile considerations (TCP‑based and non‑Ethernet protocols) and token verification requirements (authenticity, integrity, validity period) plus revocation methods.
- Interoperability & extensibility: Mechanisms to ensure backward compatibility and to extend roles/rights lists; mapping guidance to other authorization mechanisms.
Practical applications and who uses it
IEC TS 62351-8 is intended for implementers and stakeholders in electric utility and smart grid environments who need standardized, interoperable authorization:
- Utility cybersecurity architects designing access control for SCADA, substation automation, and distribution systems.
- Device and software vendors implementing RBAC-aware products interoperable across supplier ecosystems.
- System integrators and OEMs integrating IEC 61850 (substation automation), CIM/IEC 61968 (distribution/utility management), AMI and DER systems with consistent access control.
- Security engineers and auditors validating role assignments, token formats, and revocation procedures.
Practical use cases include secure logical‑device access, role‑based service authorization, and federated access via LDAP/X.509 infrastructures.
Related standards
- IEC 62351 series - broader guidance on data and communications security for power systems.
- IEC 61850 - substation automation (role mapping examples referenced).
- IEC 61968 / CIM - distribution management interfaces referenced for role definitions.
Keywords: IEC TS 62351-8, role-based access control, RBAC, power systems security, access token, X.509, LDAP, smart grid interoperability.