TY - GEN
T1 - Substation Bill of Materials
T2 - IEEE International Conference on Electrical, Computer and Energy Technologies, ICECET 2025
AU - Yurrebaso, Xabier
AU - Ibanez, Fernando
AU - Longueira-Romero, Angel
N1 - Publisher Copyright:
© 2025 IEEE.
PY - 2025
Y1 - 2025
N2 - Smart grids have undergone a profound digitization process, integrating new data-driven control and supervision techniques, resulting in modern digital substations (DS). Attackers are more focused on attacking the supply chain of the DS, as they a comprise a multivendor environment. In this research work, we present the Substation Bill of Materials (Subs-BOM) schema, based on the CycloneDX specification, that is capable of modeling all the IEDs in a DS and their relationships from a cybersecurity perspective. The proposed Subs-BOM allows one to make informed decisions about cyber risks related to the supply chain, and enables managing multiple DS at the same time. This provides energy utilities with an accurate and complete inventory of the devices, the firmware they are running, and the services that are deployed into the DS. The Subs-BOM is generated using the Substation Configuration Description (SCD) file specified in the IEC 61850 standard as its main source of information.We validated the Subs-BOM schema against the Dependency-Track software by OWASP. This validation proved that the schema is correctly recognized by CycloneDX-compatible tools. Moreover, the Dependency-Track software could track existing vulnerabilities in the IEDs represented by the Subs-BOM.
AB - Smart grids have undergone a profound digitization process, integrating new data-driven control and supervision techniques, resulting in modern digital substations (DS). Attackers are more focused on attacking the supply chain of the DS, as they a comprise a multivendor environment. In this research work, we present the Substation Bill of Materials (Subs-BOM) schema, based on the CycloneDX specification, that is capable of modeling all the IEDs in a DS and their relationships from a cybersecurity perspective. The proposed Subs-BOM allows one to make informed decisions about cyber risks related to the supply chain, and enables managing multiple DS at the same time. This provides energy utilities with an accurate and complete inventory of the devices, the firmware they are running, and the services that are deployed into the DS. The Subs-BOM is generated using the Substation Configuration Description (SCD) file specified in the IEC 61850 standard as its main source of information.We validated the Subs-BOM schema against the Dependency-Track software by OWASP. This validation proved that the schema is correctly recognized by CycloneDX-compatible tools. Moreover, the Dependency-Track software could track existing vulnerabilities in the IEDs represented by the Subs-BOM.
KW - Critital infrastructures
KW - cybersecurity
KW - CycloneDX
KW - IEC 61850
KW - risk assessment
KW - SBOM
KW - Subs-BOM
KW - supply chain attack
UR - https://www.scopus.com/pages/publications/105037142108
U2 - 10.1109/ICECET63943.2025.11472046
DO - 10.1109/ICECET63943.2025.11472046
M3 - Conference contribution
AN - SCOPUS:105037142108
T3 - International Conference on Electrical, Computer, and Energy Technologies, ICECET 2025
BT - International Conference on Electrical, Computer, and Energy Technologies, ICECET 2025
PB - Institute of Electrical and Electronics Engineers Inc.
Y2 - 3 July 2025 through 6 July 2025
ER -