Hybrid OPC UA: Enabling Post-Quantum Security for the Industrial Internet of Things

被引:0
作者
Paul, Sebastian [1 ]
Guerin, Esther [1 ]
机构
[1] Robert Bosch GmbH, Corp Sect Res & Adv Engn, Renningen, Germany
来源
2020 25TH IEEE INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION (ETFA) | 2020年
关键词
Industrial IoT; Hybrid key exchange; OPC UA; Post-quantum cryptography;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cyber-physical systems (CPS) are considered a crucial part for providing connectivity in industrial environments. However, the recent increase in connectivity has led to an extended attack vector. Therefore, it is important that CPS are secured against current and - due to their long life span - also against future threats, such as quantum computers. The security of present communication can be broken once a sufficiently powerful quantum computer is available. To protect against this attack vector, applications and protocols should start utilizing quantum-resistant primitives. One approach that maintains common security guarantees and protects against quantum computer attacks is to use hybrid constructions: a combination of classically secure and quantum-resistant schemes. In this work, we propose a hybrid key exchange mechanism for the industrial communication protocol Open Platform Communications Unified Architecture (OPC UA). We describe four distinct instantiations based on selected quantum-resistant key encapsulation mechanisms (KEMs), namely NewHope, NTRU, CRYSTALS-Kyber, and Saber. We implement our resulting quantum-resistant modifications of OPC UA on two different ARM based platforms and present detailed performance footprints. Finally, we show the feasibility of employing hybrid quantum-resistant key exchange within OPC UA preserving industrial communication against future threats.
引用
收藏
页码:238 / 245
页数:8
相关论文
共 32 条
[1]  
Alkim E., 2019, NIST POSTQUANTUM CRY
[2]  
Alperin-Sheriff J., 2019, NIST Focus on the Cortex M4
[3]  
Antonakakis M, 2017, PROCEEDINGS OF THE 26TH USENIX SECURITY SYMPOSIUM (USENIX SECURITY '17), P1093
[4]  
Avanzi R., 2019, CRYSTALS KYBER ALGOR
[5]   Hybrid Key Encapsulation Mechanisms and Authenticated Key Exchange [J].
Bindel, Nina ;
Brendel, Jacqueline ;
Fischlin, Marc ;
Goncalves, Brian ;
Stebila, Douglas .
POST-QUANTUM CRYPTOGRAPHY, PQCRYPTO 2019, 2019, 11505 :206-226
[6]  
Braithwaite Matt, 2016, Experimenting with Post-Quantum Cryptography
[7]  
BSI, 2017, OPC UA SEC AN 2017 0
[8]  
Campagna M., 2019, Hybrid Post-Quantum Key Encapsulation Methods (PQ KEM) for Transport Layer Security 1.2 (TLS). Internet-Draft (work in progress
[9]   Highly viscous polymeric foam flowing through an orifice [J].
Chen, Ching-Hsien ;
Hallmark, Bart ;
Davidson, John Frank .
PROCEEDINGS OF 33RD INTERNATIONAL CONFERENCE OF THE POLYMER PROCESSING SOCIETY (PPS-33), 2019, 2139
[10]  
DAnvers J.-P., 2019, NIST POST QUANTUM CR