|
International Journal of Computer Applications
Foundation of Computer Science (FCS), NY, USA
|
| Volume 187 - Issue 138 |
| Published: August 2026 |
| Authors: Stephen Kofi Dotse, Samuel Yao Sebuabe, Harriet K.O. Lamptey, Kwame Assa-Agyei, Ezekiel Annan Okoe, Marthin Doe |
10.5120/ijcae4e656f4bcb8
|
Stephen Kofi Dotse, Samuel Yao Sebuabe, Harriet K.O. Lamptey, Kwame Assa-Agyei, Ezekiel Annan Okoe, Marthin Doe . Integrating DNP3 Secure Authentication with Transport Layer Security for Enhanced Industrial Control System Security. International Journal of Computer Applications. 187, 138 (August 2026), 44-57. DOI=10.5120/ijcae4e656f4bcb8
@article{ 10.5120/ijcae4e656f4bcb8,
author = { Stephen Kofi Dotse,Samuel Yao Sebuabe,Harriet K.O. Lamptey,Kwame Assa-Agyei,Ezekiel Annan Okoe,Marthin Doe },
title = { Integrating DNP3 Secure Authentication with Transport Layer Security for Enhanced Industrial Control System Security },
journal = { International Journal of Computer Applications },
year = { 2026 },
volume = { 187 },
number = { 138 },
pages = { 44-57 },
doi = { 10.5120/ijcae4e656f4bcb8 },
publisher = { Foundation of Computer Science (FCS), NY, USA }
}
%0 Journal Article
%D 2026
%A Stephen Kofi Dotse
%A Samuel Yao Sebuabe
%A Harriet K.O. Lamptey
%A Kwame Assa-Agyei
%A Ezekiel Annan Okoe
%A Marthin Doe
%T Integrating DNP3 Secure Authentication with Transport Layer Security for Enhanced Industrial Control System Security%T
%J International Journal of Computer Applications
%V 187
%N 138
%P 44-57
%R 10.5120/ijcae4e656f4bcb8
%I Foundation of Computer Science (FCS), NY, USA
Industrial Control Systems (ICS) and SCADA networks underpin critical national infrastructure across the energy, water, and transportation sectors. Yet, they rely predominantly on the DNP3 protocol, which was designed without inherent provisions for message confidentiality, mutual authentication, or replay protection. DNP3 Secure Authentication Version 5 (DNP3-SA) and Transport Layer Security 1.3 (TLS 1.3) address application-layer integrity and transport-layer confidentiality, respectively, but their combined deployment as a dual-layer defense-in-depth architecture introduces cryptographic overhead whose feasibility on resource-constrained legacy field devices remains uncharacterized. This study presents a systematic empirical evaluation of the integrated dual-layer architecture using a hardware-in-the-loop cyber-physical testbed replicating a representative substation automation environment comprising a SCADA master station, mid-tier ARMv8 and low-specification ARMv7 outstations, and a software-defined network fabric. Four conditions (unprotected baseline, DNP3-SA only, TLS 1.3 only, and the fully integrated dual-layer configuration) were evaluated across 14,760,000 timestamped message exchange records spanning three message categories, three hardware configurations, and three replications. The dual-layer condition imposed a median latency increase of 12.6 ms (600%) over baseline on mid-tier hardware; hardware security module (HSM) offloading reduced 99th-percentile latency by 64%, restoring performance within IEC 61850 Performance Class P2 and NERC CIP-014 thresholds. Penetration testing across five DNP3-specific attack categories aligned with MITRE ATT&CK for ICS showed the integrated architecture achieving a 100% block rate, with a residual 8.7% availability vulnerability under sustained fragmentation storms eliminated by HSM offloading. A one-class support vector machine anomaly detector achieved a 91.3% detection rate at a 3.2% false-positive rate. The findings confirm that the dual-layer architecture is operationally feasible when configured with HSM acceleration and tiered encryption policies. This research contributes the first empirically grounded characterization of the combined latency envelope of DNP3-SA Version 5 and TLS 1.3, an open, reproducible testbed methodology, and an archived experimental dataset.