A Case for Practical Configuration Management Using Hardware-based Security Tokens

05/25/2022
by   Tim Lackorzynski, et al.
0

Future industrial networks will consist of a complex mixture of new and legacy components, while new use cases and applications envisioned by Industry 4.0 will demand increased flexibility and dynamics from these networks. Industrial security gateways will become an important building block to tackle new security requirements demanded by these changes. Their introduction will further increase the already high complexity of these networks, demanding more efforts in properly and securely configuring them. Yet, past research showed, that most operators of industrial networks are already today unable to configure industrial networks in a secure fashion. Therefore, we propose a scheme that allows factory operators to configure security gateways in an easy and practical way that is also understandable for staff not trained in the security domain. We employ hardware security tokens that allow to reduce every day configuration to one physical interaction. Our results show the practical feasibility of our proposed scheme and that it does not reduce the security level of industrial security gateways in any way.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
05/25/2022

Secure and Efficient Tunneling of MACsec for Modern Industrial Use Cases

Trends like Industry 4.0 will pose new challenges for future industrial ...
research
03/27/2020

Assessing the Security of OPC UA Deployments

To address the increasing security demands of industrial deployments, OP...
research
09/17/2020

Can ROS be used securely in industry? Red teaming ROS-Industrial

With its growing use in industry, ROS is rapidly becoming a standard in ...
research
07/24/2021

Secure Links: Secure-by-Design Communications in IEC 61499 Industrial Control Applications

Increasing automation and external connectivity in industrial control sy...
research
06/08/2018

An Industrial Social Network for Sharing Knowledge Among Operators

Due to the increasing complexity of modern automatic machines typically ...
research
08/24/2020

Towards Flexible Security Testing of OT Devices

In the factory of the future traditional and formerly isolated Operation...
research
01/14/2022

Securing IIoT using Defence-in-Depth: Towards an End-to-End Secure Industry 4.0

Industry 4.0 uses a subset of the IoT, named Industrial IoT (IIoT), to a...

Please sign up or login with your details

Forgot password? Click here to reset