Secure Onboarding of IIoT Devices using OPC UA

被引:2
作者
Kohnhaeuser, Florian [1 ]
Gruener, Sten [1 ]
Heuschkel, Jens [1 ]
机构
[1] ABB Corp Res Ctr, Ladenburg, Germany
来源
2022 IEEE 27TH INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION (ETFA) | 2022年
关键词
OPC UA; secure onboarding; Industry; 4.0;
D O I
10.1109/ETFA52439.2022.9921547
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In today's Industrial Internet of Things (IIoT), a broad range of communication protocols are utilized. Built-in security mechanisms enable these protocols to protect communication and defend against network attacks. However, before IIoT devices can utilize these security mechanisms, they need to be securely onboarded in the network. Although several onboarding solutions exist, there is no widely applicable and easy solution for all protocols. Thus, owners of IIoT devices must currently perform multiple processes until they can securely use a device in operation, which requires a high amount of manual effort and onboarding infrastructure. In this work, we present a generic secure onboarding solution for a broad range of network protocols based on OPC UA. OPC UA is particularly suited for this task, as it is one of the most widespread IIoT protocols and one of few protocols whose standard defines a secure onboarding. Our solution leverages the OPC UA onboarding process to equip other IIoT protocols with the initial trust and credentials to establish secure connections. To this end, only minor extensions to the OPC UA implementation on devices are necessary, such that device owners can reuse their OPC UA onboarding infrastructure without any modifications. As a proof of concept for our solution, we demonstrate the secure onboarding of an HTTPS web server. Our implementation fully reuses the reference implementation OPC UA sample server as infrastructure and only needs minor extensions to the IIoT device.
引用
收藏
页数:4
相关论文
共 12 条
[1]  
[Anonymous], 2020, OPC Unified Architecture Part 5: Information Model
[2]  
Barnes R., 2019, Automatic Certificate Management Environment (ACME) RFC 8555
[3]  
Institute of Electrical and Electronics Engineers (IEEE), 2018, 8021AR2018 IEEE
[4]   On the Security of IIoT Deployments: An Investigation of Secure Provisioning Solutions for OPC UA [J].
Kohnhauser, Florian ;
Meier, David ;
Patzer, Florian ;
Finster, Soren .
IEEE ACCESS, 2021, 9 :99299-99311
[5]   Industry 4.0 [J].
Lasi, Heiner ;
Kemper, Hans-Georg ;
Fettke, Peter ;
Feld, Thomas ;
Hoffmann, Michael .
BUSINESS & INFORMATION SYSTEMS ENGINEERING, 2014, 6 (04) :239-242
[6]   Looking back to look forward: Lessons learnt from cyber-attacks on Industrial Control Systems [J].
Miller, Thomas ;
Staves, Alexander ;
Maesschalck, Sam ;
Sturdee, Miriam ;
Green, Benjamin .
INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2021, 35
[7]  
OPC Foundation, 2022, OFF OPC UA
[8]  
OPC Foundation, 2022, OPC Unified Architecture Part 1: Overview and Concepts
[9]  
OPC Foundation, 2018, OPC UNIFIED ARCHITEC
[10]  
Pritikin M., 2020, INTERNET DRAFTDRAFT