Internet-Draft Security Protocol for Modbus Serial Link August 2026
Liu, et al. Expires 14 February 2027 [Page]
Workgroup:
iotops
Internet-Draft:
draft-liu-iotops-modbus-seriallink-sec-spec-07
Published:
Intended Status:
Informational
Expires:
Authors:
P. Liu, Ed.
Pengcheng Laboratory
R. Yang, Ed.
Pengcheng Laboratory
R. Chen, Ed.
China Mobile
R. Fu, Ed.
China Telecom
Y. Zhang, Ed.
Pengcheng Laboratory

Modbus Serial Link Communication Security Protocol Reference Specification and implementation guide

Abstract

The Modbus TCP protocol has adopted TLS-based security standards; however, Modbus serial communication over EIA/TIA-485 multi-point systems, commonly used in 2-wire or 4-wire configurations, lacks standardized security mechanisms. These systems support cable lengths exceeding 1000m at baud rates up to 9600 bit/s with AWG26 or thicker cables, while Category 5 cables can reach up to 600m. As an application layer protocol, despite its widespread application, the absence of encryption and authentication in Modbus protocol via serial links exposes plaintext data to risks such as MIM interception, modification under attacks such as side-channel analysis etc., particularly in long-distance or bridged network scenarios. Enhancing Modbus serial link security requires introducing proper encryption and authentication methods tailored to varied deployment environments onsidering the characteristics of serial links. A proposed security standard guide outlines lightweight encryption and authentication mechanisms to improve confidentiality and integrity while maintaining compatibility with existing Modbus devices, offering a practical upgrade path for secure industrial control systems.

Status of This Memo

This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79.

Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet-Drafts is at https://datatracker.ietf.org/drafts/current/.

Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress."

This Internet-Draft will expire on 14 February 2027.

Table of Contents

1. IANA Considerations

This memo includes no request to IANA.

2. Security Considerations

This specification defines the reference native security protocol specification for the case with pure serial link communication, which (e.g., RS485-based Modbus) remains an unresolved challenge. Serial Modbus transmits data in plaintext, leaving it susceptible to interception, modification, and hardware-based side-channel attacks. There are currently no formal standards addressing security for Modbus over RS485, which is still widely used due to its simplicity and long-distance capabilities. Currently, for any EIA/TIA-485 multi-point system, whether it is a 2-wire or 4-wire configuration, the maximum length for cables with a maximum baud rate of 9600bit/s and AWG26 (or thicker) specifications can reach over 1000m. For RS485 Modbus, a sufficiently wide cable diameter should allow for a maximum length of over 1000m, and for RS485 Modbus using Category 5 cables, the maximum length can reach 600m. This lack of encryption and authentication mechanisms poses risks, particularly in scenarios involving relays or bridged networks. While Modbus TCP has seen notable advancements in security through TLS-based solutions, serial Modbus communication requires more attention. Introducing lightweight encryption and authentication mechanisms for serial links could provide a practical way to enhance security and protect legacy systems without significant infrastructure changes. Therefore, it is very necessary and valuable to improve and enhance the communication security of Modbus protocol under serial link mode, for reference by relevant institutions and organizations in various industries, in order to ensure the practical application security of various industrial control systems. With the introduction of the Modbus serial link security standard, the introduction of encryption and authentication mechanisms in the serial link communication channel of the Modbus protocol significantly improves its security, providing a relatively simple and direct upgrade path for existing devices that use Modbus extensively.

3. References

3.1. Normative References

[RFC2119]
Bradner, S., "Key words for use in RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, DOI 10.17487/RFC2119, , <https://www.rfc-editor.org/info/rfc2119>.
[RFC8174]
Leiba, B., "Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words", BCP 14, RFC 8174, DOI 10.17487/RFC8174, , <https://www.rfc-editor.org/info/rfc8174>.

3.2. Informative References

[RFC5280]
Cooper, D., Santesson, S., Farrell, S., Boeyen, S., Housley, R., and W. Polk, "Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile", RFC 5280, DOI 10.17487/RFC5280, , <https://www.rfc-editor.org/rfc/rfc5280>.
[RFC8439]
Nir, Y. and A. Langley, "ChaCha20 and Poly1305 for IETF Protocols", RFC 8439, DOI 10.17487/RFC8439, , <https://www.rfc-editor.org/rfc/rfc8439>.
[IEC62443-3-3]
"System Security Requirements and Security Levels", IEC 62443, .
[IEC62443-4-2]
"Technical Security Requirements for IACS Components", IEC 62443, .
[IEC62351-3]
"Power Systems Management and Associated Information Exchange – Data and Communications Security – Part 3: Communication Network and System Security for Profiles Including TCP/IP", IEC 62351, .
[IEC62351-4]
"Power Systems Management and Associated Information Exchange – Data and Communications Security – Part 4: Profiles Including MMS and Derivatives", IEC 62351, .
[NISTSP800-82]
"Guide to Industrial Control Systems (ICS) Security", NIST SP800, .
[ENISA-ICS-Security-Guidelines]
"Good Practices for Security of Industrial Control Systems", ENISA ICS-Security-Guidelines, .
[ETSI-SAGE-TS35.221]
"Specification of the 3GPP Confidentiality and Integrity Algorithms 128-EEA3 and 128-EIA3.Document 1:128-EEA3 and 128-EIA3 Specification", ETSI/SAGE TS35.221, .
[ETSI-SAGE-TS35.222]
"Specification of the 3GPP Confidentiality and Integrity Algorithms 128-EEA3 and 128-EIA3.Document 1:128-EEA3 and 128-EIA3 Specification", ETSI/SAGE TS35.222, .
[NIST.FIPS.203]
"Module-Lattice-Based Key-Encapsulation Mechanism Standard", NIST FIPS.203, .
[NIST.FIPS.204]
"Module-Lattice-Based Digital Signature Standard", NIST FIPS.204, .

Authors' Addresses

Penghui Liu (editor)
Pengcheng Laboratory
No.2 Xingke 1 Street
Shenzhen
518055
China
Rongwei Yang (editor)
Pengcheng Laboratory
No.2 Xingke 1 Street
Shenzhen
518055
China
Meiling Chen (editor)
China Mobile
No.32 Xuanwumen West Street
Beijing
100000
China
Yu Fu (editor)
China Telecom
No. 3 Penglaiyuan South Street
Beijing
100000
China
Weizhe Zhang (editor)
Pengcheng Laboratory
No.2 Xingke 1 Street
Shenzhen
518055
China