Comment on 'Privacy-Enhanced Data Aggregation Scheme Against Internal Attackers in Smart Grid'

Research output: Contribution to journalArticlepeer-review

43 Scopus citations

Abstract

Quite recently, Fan et al. (IEEE Trans. Ind. Informat., vol. 10, no. 1, pp. 666-675, 2014) proposed a new data aggregation scheme for smart grid communications, and claimed that it can achieve not only user's privacy-preservation, but also data integrity requirement. However, in this paper, we show that Fan et al.'s scheme has a serious security flaw and cannot meet data integrity requirement at all. Specifically, by observing the user registration procedure in Fan et al.'s scheme, we find that each user's private key can be easily derived from the information published by the aggregator. Then, with the derived private key, an attacker can inject polluted data to user's real data without being detected. As a result, data integrity will be completely violated. We hope that with our comment, similar mistakes can be avoided in future design of privacy-preserving data aggregation with data integrity protection.

Original languageEnglish
Article number7329980
Pages (from-to)2-5
Number of pages4
JournalIEEE Transactions on Industrial Informatics
Volume12
Issue number1
DOIs
StatePublished - Feb 2016
Externally publishedYes

Keywords

  • Data aggregation
  • Data integrity
  • Privacypreserving
  • Smart grid

Fingerprint

Dive into the research topics of 'Comment on 'Privacy-Enhanced Data Aggregation Scheme Against Internal Attackers in Smart Grid''. Together they form a unique fingerprint.

Cite this