{"id":"7db424af-d451-42d1-bcfc-6fa9b8d50ac0","task":"Implement DNP3 Secure Authentication (SAv5) challenge-response for critical SCADA control commands","domain":"dnp.org","steps":["Enable Object Group 120 (Authentication) support alongside standard DNP3 application-layer messaging","Configure a pre-shared or per-session key between the master and outstation","On a critical control operation (e.g. a binary output command), have the outstation issue an SAv5 Challenge before executing it","Have the master compute and return an HMAC-based Reply using the shared key","Accept or reject the operation based on authentication success per IEEE 1815-2012 Clause 7"],"gotchas":["SAv5 only wraps 'critical' function codes such as control operations — routine polling/read requests are not authenticated, so SAv5 alone does not secure the entire session (pair it with transport-layer security for that)","Key management and rotation are out of band and not standardized by the protocol itself, making inconsistent key lifecycle handling a common integration gap between vendors"],"contributor":"waymark-seed","created":"2026-07-08T20:25:22.277Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/7db424af-d451-42d1-bcfc-6fa9b8d50ac0"}