Content area

Abstract

In modern industrial control systems (ICSs), communication protocols such as Modbus TCP remain widely used due to their simplicity, interoperability, and real-time performance. However, these communication protocols (e.g., Modbus TCP) were originally designed without security considerations, lacking essential features such as encryption, integrity protection, and authentication. This exposes ICS deployments to severe security threats, including eavesdropping, command injection, and replay attacks, especially when operating over unsecured networks. To address these critical vulnerabilities while preserving the lightweight nature of the protocol, we propose a Modbus TCP security enhancement scheme that integrates ASCON, an NIST-standardized authenticated encryption algorithm, with the CBOR Object Signing and Encryption (COSE) framework. Our design embeds COSE_Encrypt0 structures into Modbus application data, enabling end-to-end confidentiality, integrity, and replay protection without altering the protocol’s semantics or timing behavior. We implement the proposed scheme in C and evaluate it in a simulated embedded environment representative of typical ICS devices. Experimental results show that the solution incurs minimal computational and memory overhead, while providing robust cryptographic guarantees. This work demonstrates a practical pathway for retrofitting legacy ICS protocols with modern lightweight cryptography, enhancing system resilience without compromising compatibility or performance.

Details

1009240
Title
A Security-Enhanced Scheme for ModBus TCP Protocol Based on Lightweight Cryptographic Algorithm
Author
Le, Xiang 1 ; Li, Ji 2   VIAFID ORCID Logo  ; Zhao, Yong 3 ; Fan Zhaohong 2 

 School of Computer Science, Beijing University of Technology, Beijing 100124, [email protected] (Y.Z.), Ningbo HollySys Information Security Research Institute Co., Ltd., Beijing 315100, China 
 Ningbo HollySys Information Security Research Institute Co., Ltd., Beijing 315100, China 
 School of Computer Science, Beijing University of Technology, Beijing 100124, [email protected] (Y.Z.) 
Publication title
Volume
14
Issue
18
First page
3674
Number of pages
25
Publication year
2025
Publication date
2025
Publisher
MDPI AG
Place of publication
Basel
Country of publication
Switzerland
Publication subject
e-ISSN
20799292
Source type
Scholarly Journal
Language of publication
English
Document type
Journal Article
Publication history
 
 
Online publication date
2025-09-17
Milestone dates
2025-08-07 (Received); 2025-09-12 (Accepted)
Publication history
 
 
   First posting date
17 Sep 2025
ProQuest document ID
3254508802
Document URL
https://www.proquest.com/scholarly-journals/security-enhanced-scheme-modbus-tcp-protocol/docview/3254508802/se-2?accountid=208611
Copyright
© 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License.
Last updated
2025-09-26
Database
ProQuest One Academic