{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T15:34:23Z","timestamp":1783697663532,"version":"3.55.0"},"reference-count":38,"publisher":"MDPI AG","issue":"1","license":[{"start":{"date-parts":[[2026,1,4]],"date-time":"2026-01-04T00:00:00Z","timestamp":1767484800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/100000015","name":"U.S. Department of Energy, Office of Cybersecurity, Energy Security, and Emergency Response","doi-asserted-by":"publisher","award":["DE-CR0000050"],"award-info":[{"award-number":["DE-CR0000050"]}],"id":[{"id":"10.13039\/100000015","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>Industrial Control Systems (ICS) are fundamental to the operation, monitoring, and automation of critical infrastructure in sectors such as energy, water utilities, manufacturing, transportation, and oil and gas. According to the Purdue Model, ICS encompasses tightly coupled OT and IT layers, becoming increasingly interconnected. Smart grids represent a critical class of ICS; thus, this survey examines encryption and relevant protocols in smart grid communications, with findings extendable to other ICS. Encryption techniques implemented at both the protocol and network layers are among the most effective cybersecurity strategies for protecting communications in increasingly interconnected ICS environments. This paper provides a comprehensive survey of encryption practices within the smart grid as the primary ICS application domain, focusing on protocol-level solutions (e.g., DNP3, IEC 60870-5-104, IEC 61850, ICCP\/TASE.2, Modbus, OPC UA, and MQTT) and network-level mechanisms (e.g., VPNs, IPsec, and MACsec). We evaluate these technologies in terms of security, performance, and deployability in legacy and heterogeneous systems that include renewable energy resources. Key implementation challenges are explored, including real-time operational constraints, cryptographic key management, interoperability across platforms, and alignment with NERC CIP, IEC 62351, and IEC 62443. The survey highlights emerging trends such as lightweight Transport Layer Security (TLS) for constrained devices, post-quantum cryptography, and Zero Trust architectures. Our goal is to provide a practical resource for building resilient smart grid security frameworks, with takeaways that generalize to other ICS.<\/jats:p>","DOI":"10.3390\/jcp6010011","type":"journal-article","created":{"date-parts":[[2026,1,5]],"date-time":"2026-01-05T08:40:53Z","timestamp":1767602453000},"page":"11","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Encryption for Industrial Control Systems: A Survey of Application-Level and Network-Level Approaches in Smart Grids"],"prefix":"10.3390","volume":"6","author":[{"given":"Mahesh","family":"Narayanan","sequence":"first","affiliation":[{"name":"Department of Electrical Engineering and Computer Science, Florida Atlantic University, Boca Raton, FL 33431, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Muhammad Asfand","family":"Hafeez","sequence":"additional","affiliation":[{"name":"Department of Electrical Engineering and Computer Science, Florida Atlantic University, Boca Raton, FL 33431, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3126-8945","authenticated-orcid":false,"given":"Arslan","family":"Munir","sequence":"additional","affiliation":[{"name":"Department of Electrical Engineering and Computer Science, Florida Atlantic University, Boca Raton, FL 33431, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2026,1,4]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"141","DOI":"10.1016\/0166-3615(94)90017-5","article-title":"The Purdue enterprise reference architecture","volume":"24","author":"Williams","year":"1994","journal-title":"Comput. Ind."},{"key":"ref_2","unstructured":"Ujvarosi, A. (2016). Evolution of SCADA systems. Bulletin of the Transilvania University of Brasov. Series I-Engineering Sciences, Transilvania University Press."},{"key":"ref_3","first-page":"129","article-title":"Chapter Six\u2014Industry 4.0: Industrial Internet of Things (IIOT)","volume":"Volume 117","author":"Raj","year":"2020","journal-title":"The Digital Twin Paradigm for Smarter Systems and Environments: The Industry Use Cases"},{"key":"ref_4","first-page":"18","article-title":"The impact of IT\/OT Convergence on digital transformation in manufacturing","volume":"2","author":"George","year":"2024","journal-title":"Partn. Univers. Int. Innov."},{"key":"ref_5","unstructured":"Chaiyasoonthorn, S., Wiboonrat, M., Mitatha, S., Sriudomsilp, T., and Siripongdee, S. (2024, January 10\u201313). The Information Technology (IT) and Operational Technology (OT) Convergence in Industrial World. Proceedings of the CBI+EDOC\u201924 (BIWeek 2024)\u2014Case Reports, Vienna, Austria."},{"key":"ref_6","first-page":"28","article-title":"Cybersecurity Implications of IT and OT Convergence","volume":"122","author":"Ehuan","year":"2025","journal-title":"Chem. Eng."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"469","DOI":"10.1016\/j.compeleceng.2018.01.015","article-title":"Cyber-security in smart grid: Survey and challenges","volume":"67","author":"Kaabouch","year":"2018","journal-title":"Comput. Electr. Eng."},{"key":"ref_8","first-page":"101","article-title":"An introduction to information security","volume":"800","author":"Nieles","year":"2017","journal-title":"NIST Spec. Publ."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Khan, M.U. (2023). Blockchain Technology for the Security of Internet of Things: Challenges, Solutions, and Future Trends. arXiv.","DOI":"10.31224\/3060"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Sharma, R., Dangi, S., and Mishra, P. (2021, January 7\u20139). A comprehensive review on encryption based open source cyber security tools. Proceedings of the 2021 6th International Conference on Signal Processing, Computing and Control (ISPCC), Solan, India.","DOI":"10.1109\/ISPCC53510.2021.9609369"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"100394","DOI":"10.1016\/j.ijcip.2020.100394","article-title":"Securing SCADA and critical industrial systems: From needs to security mechanisms","volume":"32","year":"2021","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"key":"ref_12","first-page":"116","article-title":"Energy challenge, power electronics & systems (PEAS) technology and grid modernization","volume":"1","author":"Geetha","year":"2019","journal-title":"Int. Res. J. Multidiscip. Technovation"},{"key":"ref_13","unstructured":"Knapp, E.D. (2024). Industrial Network Security: Securing Critical Infrastructure Networks for Smart Grid, SCADA, and Other Industrial Control Systems, Elsevier."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Oluyede, M.S., Mart, J., Olusola, A., and Olatuja, G. (2024). The Performance Analysis of Macsec in Different Network Environments. Sci. Prepr.","DOI":"10.14293\/PR2199.000736.v1"},{"key":"ref_15","unstructured":"Dubroca, S. (2016, January 10\u201312). MACsec: Encryption for the wired LAN. Proceedings of the Netdev 1.1, Seville, Spain."},{"key":"ref_16","unstructured":"Zhao, Q., Zhang, X., Meng, Z., Yan, P., Liang, Z., and Yang, R. Study on Substation High Reliable Communication and Deterministic-Delay. Proceedings of the 16th Annual Conference of China Electrotechnical Society: Volume I."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"215","DOI":"10.36548\/rrrj.2023.2.001","article-title":"Cybersecurity and confidentiality in smart grid for enhancing sustainability and reliability","volume":"2","author":"Jha","year":"2023","journal-title":"Recent Res. Rev. J."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Almulla, Z.T., and Rahman, H. (2025, January 18\u201321). The Role of Network Segmentation and Micro-Segmentation in Operational Technology Security. Proceedings of the 2025 International Conference on Artificial Intelligence in Information and Communication (ICAIIC), Fukuoka, Japan.","DOI":"10.1109\/ICAIIC64266.2025.10920695"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"B\u00fclb\u00fcl, N.S., Ergen\u00e7, D., and Fischer, M. (2021, January 4\u20137). SDN-based self-configuration for time-sensitive IoT networks. Proceedings of the 2021 IEEE 46th Conference on Local Computer Networks (LCN), Edmonton, AB, Canada.","DOI":"10.1109\/LCN52139.2021.9524979"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Carcano, A., Fovino, I.N., Masera, M., and Trombetta, A. (2008, January 13\u201315). Scada malware, a proof of concept. Proceedings of the International Workshop on Critical Information Infrastructures Security, Rome, Italy.","DOI":"10.1007\/978-3-642-03552-4_19"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"105183","DOI":"10.1109\/ACCESS.2025.3577972","article-title":"Implementation and Analysis of a Secure Communication with SunSpec Modbus and Transport Layer Security Protocols for Short-Term Energy Management Systems","volume":"13","author":"Ferst","year":"2025","journal-title":"IEEE Access"},{"key":"ref_22","first-page":"227","article-title":"DNPSec: Distributed network protocol version 3 (DNP3) security framework","volume":"1","author":"Majdalawieh","year":"2006","journal-title":"Adv. Comput. Inform. Syst. Sci. Eng."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Bagaria, S., Prabhakar, S.B., and Saquib, Z. (2011, January 14\u201316). Flexi-DNP3: Flexible distributed network protocol version 3 (DNP3) for SCADA security. Proceedings of the 2011 International Conference on Recent Trends in Information Systems, Chennai, India.","DOI":"10.1109\/ReTIS.2011.6146884"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Darwish, I., Igbe, O., Celebi, O., Saadawi, T., and Soryal, J. (2015, January 3\u20135). Smart grid DNP3 vulnerability analysis and experimentation. Proceedings of the 2015 IEEE 2nd International Conference on Cyber Security and Cloud Computing, New York, NY, USA.","DOI":"10.1109\/CSCloud.2015.86"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"203","DOI":"10.3233\/JCS-181139","article-title":"Secure authentication in the grid: A formal analysis of DNP3 SAv5","volume":"27","author":"Cremers","year":"2019","journal-title":"J. Comput. Secur."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"1474","DOI":"10.1109\/TII.2016.2587883","article-title":"Securing DNP3 broadcast communications in SCADA systems","volume":"12","author":"Amoah","year":"2016","journal-title":"IEEE Trans. Ind. Inform."},{"key":"ref_27","unstructured":"Nousiainen, A. (2024). Applying Cybersecurity for IEC 60870-5-104 Communication Between Control Station and Substation. [Master\u2019s Thesis, University of Vaasa, School of Technology and Innovations]."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Ghanem, K., Hansawangkit, J., Asif, R., Ugwuanyi, S., McPherson, R., and Irvine, J. (2021, January 22\u201324). Bandwidth efficient secure authentication and encryption techniques on IEC-60870-5-104 for remote outstations. Proceedings of the 2021 International Conference on Smart Applications, Communications and Networking (SmartNets), Glasgow, UK.","DOI":"10.1109\/SmartNets50376.2021.9555411"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Ilgner, P., Stusek, M., Cika, P., and Sikora, M. (2020, January 5\u20137). SCADA-based Message Generator for Multi-Vendor Smart Grids: Integration and Verification of TASE. 2. Proceedings of the 2020 12th International Congress on Ultra Modern Telecommunications and Control Systems and Workshops (ICUMT), Brno, Czech Republic.","DOI":"10.1109\/ICUMT51630.2020.9222445"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Ilgner, P., Cika, P., and Stusek, M. (2021). SCADA-based message generator for multi-vendor smart grids: Distributed integration and verification of TASE.2. Sensors, 21.","DOI":"10.3390\/s21206793"},{"key":"ref_31","unstructured":"Saleki, N. (2023). Establishing Secure Remote Access Within Ics Network. [Master\u2019s Thesis, Eindhoven University of Technology, Department of Mathematics and Computer Science]."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Niu, X., Cook, M.M., and Pezaros, D. (2024, January 22). Examining the suitability of stream ciphers for Modbus-TCP encryption on resource constrained devices. Proceedings of the 17th European Workshop on Systems Security (EuroSec \u201924), Athens, Greece.","DOI":"10.1145\/3642974.3652287"},{"key":"ref_33","unstructured":"Moore, T., and Shenoi, S. (2010, January 15\u201317). High Security with Low Latency in Legacy SCADA Systems. Proceedings of the Critical Infrastructure Protection IV, Washington, DC, USA."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Yi, M., Mueller, H., Yu, L., and Chuan, J. (2017, January 11\u201314). Benchmarking cloud-based SCADA system. Proceedings of the 2017 IEEE International Conference on Cloud Computing Technology and Science (CloudCom), Hong Kong.","DOI":"10.1109\/CloudCom.2017.25"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Aboulsamh, R.M., Albugaey, M.T., Alghamdi, D.O., Abujaid, F.H., Alsubaie, S.N., and Saqib, N.A. (2024, January 3\u20134). Secure Communication Protocols for SCADA Systems: Analysis and Comparisons of Different Secure Communication Protocols. Proceedings of the 2024 Seventh International Women in Data Science Conference at Prince Sultan University (WiDS PSU), Riyadh, Saudi Arabia.","DOI":"10.1109\/WiDS-PSU61003.2024.00050"},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Ugwuanyi, S., Ghanem, K., and Abdulhadi, I. (2024, January 14\u201317). Implementing secure layer 2 tunneling protocols for IEC 61850-90-5 based routable and non-routable GOOSE and SV messages. Proceedings of the 2024 IEEE PES Innovative Smart Grid Technologies Europe (ISGT EUROPE), Dubrovnik, Croatia.","DOI":"10.1109\/ISGTEUROPE62998.2024.10863237"},{"key":"ref_37","unstructured":"Industrial Control Systems Cyber Emergency Response Team (2016). Recommended Practice: Improving Industrial Control System Cybersecurity with Defense-in-Depth Strategies, Technical Report."},{"key":"ref_38","first-page":"3927","article-title":"Quantum-Resistant Cryptographic Primitives Using Modular Hash Learning Algorithms for Enhanced SCADA System Security","volume":"84","author":"Singh","year":"2025","journal-title":"Comput. Mater. Contin."}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/6\/1\/11\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,5]],"date-time":"2026-01-05T09:08:32Z","timestamp":1767604112000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/6\/1\/11"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,1,4]]},"references-count":38,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,2]]}},"alternative-id":["jcp6010011"],"URL":"https:\/\/doi.org\/10.3390\/jcp6010011","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,1,4]]}}}