Security Development Lifecycle for Cyber-Physical Production Systems

被引:0
作者
Eckhart, Matthias [1 ,2 ]
Ekelhart, Andreas [1 ,2 ]
Lueder, Arndt [4 ]
Biffl, Stefan [3 ]
Weippl, Edgar [1 ,2 ,5 ]
机构
[1] Christian Doppler Lab SQI, Vienna, Austria
[2] SBA Res, Vienna, Austria
[3] TU Wien, Vienna, Austria
[4] Otto von Guericke Univ, Magdeburg, Germany
[5] St Polten Univ Appl Sci, St Polten, Austria
来源
45TH ANNUAL CONFERENCE OF THE IEEE INDUSTRIAL ELECTRONICS SOCIETY (IECON 2019) | 2019年
关键词
Cyber-physical production systems; information security; security development lifecycle; security by design;
D O I
暂无
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
As the connectivity within manufacturing processes increases in light of Industry 4.0, information security becomes a pressing issue for product suppliers, systems integrators, and asset owners. Reaching new heights in digitizing the manufacturing industry also provides more targets for cyber attacks, hence, cyber-physical production systems (CPPSs) must be adequately secured to prevent malicious acts. To achieve a sufficient level of security, proper defense mechanisms must be integrated already early on in the systems' lifecycle and not just eventually in the operation phase. Although standardization efforts exist with the objective of guiding involved stakeholders toward the establishment of a holistic industrial security concept (e.g., IEC 62443), a dedicated security development lifecycle for systems integrators is missing. This represents a major challenge for engineers who lack sufficient information security knowledge, as they may not be able to identify security-related activities that can be performed along the production systems engineering (PSE) process. In this paper, we propose a novel methodology named Security Development Lifecycle for Cyber-Physical Production Systems (SDL-CPPS) that aims to foster security by design for CPPSs, i.e., the engineering of smart production systems with security in mind. More specifically, we derive security-related activities based on (i) security standards and guidelines, and (ii) relevant literature, leading to a security-improved PSE process that can be implemented by systems integrators. Furthermore, this paper informs domain experts on how they can conduct these security-enhancing activities and provides pointers to relevant works that may fill the potential knowledge gap. Finally, we review the proposed approach by means of discussions in a workshop setting with technical managers of an Austrian-based systems integrator to identify barriers to adopting the SDL-CPPS.
引用
收藏
页码:3004 / 3011
页数:8
相关论文
共 37 条
  • [1] Hardware Identification via Sensor Fingerprinting in a Cyber Physical System
    Ahmed, Chuadhry Mujeeb
    Mathur, Aditya P.
    [J]. 2017 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY COMPANION (QRS-C), 2017, : 517 - 524
  • [2] Al Faruque M, 2015, 2015 INTERNATIONAL CONFERENCE ON HARDWARE/SOFTWARE CODESIGN AND SYSTEM SYNTHESIS (CODES+ISSS), P30, DOI 10.1109/CODESISSS.2015.7331365
  • [3] [Anonymous], 6244332 IEC
  • [4] [Anonymous], 21824 VDIVDE
  • [5] [Anonymous], IND CONTR VULN 2017
  • [6] [Anonymous], 6244333 IEC
  • [7] [Anonymous], 47 WINS
  • [8] [Anonymous], 2017, INTRO MULTIDISCIPLIN
  • [9] [Anonymous], 6244341 IEC
  • [10] [Anonymous], 2004, Design methodology for mechatronic systems, VDI 2206