On the Security of IIoT Deployments: An Investigation of Secure Provisioning Solutions for OPC UA

被引:13
|
作者
Kohnhauser, Florian [1 ]
Meier, David [2 ]
Patzer, Florian [2 ]
Finster, Soren [1 ]
机构
[1] ABB Corp Res Ctr, D-68526 Ladenburg, Germany
[2] Fraunhofer Inst Optron, Syst Technol & Image Exploitat IOSB, D-76131 Karlsruhe, Germany
来源
IEEE ACCESS | 2021年 / 9卷
关键词
Security; Servers; Standards; Industrial Internet of Things; Usability; Licenses; Industries; Communication system security; device provisioning; Industrial Internet of Things (IIoT); industry; 40; network security; OPC UA; secure provisioning;
D O I
10.1109/ACCESS.2021.3096062
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A key technology for the communication in the Industrial Internet of Things (IIoT) is the Open Platform Communications Unified Architecture (OPC UA). OPC UA is a standard that enables interoperable, secure, and reliable communication between industrial devices. To defend against cyber attacks, OPC UA has built-in security mechanisms that protect the authenticity, integrity, and confidentiality of data in transit. Before communicating securely, it is essential that OPC UA devices are set up in a secure manner. This process is referred to as secure provisioning. An improper provisioning can lead to weak or insecure OPC UA deployments that enable adversaries to eavesdrop or even manipulate communication between industrial devices. Such insecure deployments can also be maliciously provoked by adversaries who tamper with insecure provisioning solutions. Despite secure provisioning is essential for OPC UA security and usability, there exists no overview and systematic analysis on the patchwork of different solutions in industry and academia. This article presents the first investigation of secure device provisioning solutions for the OPC UA communication protocol. First, desired objectives and evaluation criteria for secure provisioning of OPC UA devices are defined. Next, existing and emerging OPC UA provisioning solutions are analyzed and compared based on the elaborated objectives and criteria. Additionally, an outlook into the future of OPC UA provisioning is given, based on solutions from the IoT domain. Finally, the analyzed OPC UA secure provisioning solutions are compared, recommendations are given, and research gaps are identified. It is shown that contemporary provisioning solutions offer an insufficient level of security. Emerging and future solutions provide much higher security guarantees but impose a tradeoff between usability and requirements on devices and infrastructures.
引用
收藏
页码:99299 / 99311
页数:13
相关论文
共 50 条
  • [21] Open-Source OPC UA Security and Scalability
    Muehlbauer, Nikolas
    Kirdan, Erkin
    Pahl, Marc-Oliver
    Carle, Georg
    2020 25TH IEEE INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION (ETFA), 2020, : 262 - 269
  • [22] An Investigation on Database Connections in OPC UA Applications
    Mathias, Selvine G.
    Schmied, Sebastian
    Grossmann, Daniel
    11TH INTERNATIONAL CONFERENCE ON AMBIENT SYSTEMS, NETWORKS AND TECHNOLOGIES (ANT) / THE 3RD INTERNATIONAL CONFERENCE ON EMERGING DATA AND INDUSTRY 4.0 (EDI40) / AFFILIATED WORKSHOPS, 2020, 170 : 602 - 609
  • [23] Trust-based integration of devices using OPC UA Device Provisioning
    Volkmann F.
    Baur N.
    Höme S.
    Palmin A.
    Madsen M.
    VDI Berichte, 2022, 2022 (2399): : 329 - 342
  • [24] EmuFlex: A Flexible OT Testbed for Security Experiments with OPC UA
    Giehl, Alexander
    Heinl, Michael P.
    Embacher, Victor
    19TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY, ARES 2024, 2024,
  • [25] OPC UA Realization for simplified commissioning of adaptive sensing applications for the 5G IIoT
    Abukwaik, Hadil
    Gogolev, Alexander
    Gross, Christian
    Aleksy, Markus
    INTERNET OF THINGS, 2020, 11
  • [26] Secure production within the iiot - hardware-based security solutions protect data and systems
    Pollmann M.
    Pollmann, Malte, 1600, Carl Hanser Verlag (112): : 257 - 260
  • [27] Formal Security Analysis of OPC UA Protocol in Industrial Control System
    Feng, Tao
    Ma, Zhuang-Yu
    Fang, Jun-Li
    International Journal of Network Security, 2022, 24 (03): : 573 - 585
  • [28] THE PERFORMANCE OF OPC-UA SECURITY MODEL AT FIELD DEVICE LEVEL
    Post, Olli
    Seppala, Jari
    Koivisto, Hannu
    ICINCO 2009: PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE ON INFORMATICS IN CONTROL, AUTOMATION AND ROBOTICS, VOL 2: ROBOTICS AND AUTOMATION, 2009, : 337 - 341
  • [29] Secure Framework and Key Agreement Mechanism for OPC-UA in Industrial IoT
    Wei, Min
    Mo, Lian
    Zhuang, Yuan
    Kim, Keecheon
    PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON UBIQUITOUS INFORMATION MANAGEMENT AND COMMUNICATION (IMCOM 2018), 2018,
  • [30] Adopting OPC UA for Efficient and Secure Firmware Transmission in Industry 4.0 Scenarios
    Biondani, Francesco
    Cheng, Dong Seon
    Fummi, Franco
    2024 33RD INTERNATIONAL SYMPOSIUM ON INDUSTRIAL ELECTRONICS, ISIE 2024, 2024,