On the Security of IIoT Deployments: An Investigation of Secure Provisioning Solutions for OPC UA

被引:13
|
作者
Kohnhauser, Florian [1 ]
Meier, David [2 ]
Patzer, Florian [2 ]
Finster, Soren [1 ]
机构
[1] ABB Corp Res Ctr, D-68526 Ladenburg, Germany
[2] Fraunhofer Inst Optron, Syst Technol & Image Exploitat IOSB, D-76131 Karlsruhe, Germany
来源
IEEE ACCESS | 2021年 / 9卷
关键词
Security; Servers; Standards; Industrial Internet of Things; Usability; Licenses; Industries; Communication system security; device provisioning; Industrial Internet of Things (IIoT); industry; 40; network security; OPC UA; secure provisioning;
D O I
10.1109/ACCESS.2021.3096062
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A key technology for the communication in the Industrial Internet of Things (IIoT) is the Open Platform Communications Unified Architecture (OPC UA). OPC UA is a standard that enables interoperable, secure, and reliable communication between industrial devices. To defend against cyber attacks, OPC UA has built-in security mechanisms that protect the authenticity, integrity, and confidentiality of data in transit. Before communicating securely, it is essential that OPC UA devices are set up in a secure manner. This process is referred to as secure provisioning. An improper provisioning can lead to weak or insecure OPC UA deployments that enable adversaries to eavesdrop or even manipulate communication between industrial devices. Such insecure deployments can also be maliciously provoked by adversaries who tamper with insecure provisioning solutions. Despite secure provisioning is essential for OPC UA security and usability, there exists no overview and systematic analysis on the patchwork of different solutions in industry and academia. This article presents the first investigation of secure device provisioning solutions for the OPC UA communication protocol. First, desired objectives and evaluation criteria for secure provisioning of OPC UA devices are defined. Next, existing and emerging OPC UA provisioning solutions are analyzed and compared based on the elaborated objectives and criteria. Additionally, an outlook into the future of OPC UA provisioning is given, based on solutions from the IoT domain. Finally, the analyzed OPC UA secure provisioning solutions are compared, recommendations are given, and research gaps are identified. It is shown that contemporary provisioning solutions offer an insufficient level of security. Emerging and future solutions provide much higher security guarantees but impose a tradeoff between usability and requirements on devices and infrastructures.
引用
收藏
页码:99299 / 99311
页数:13
相关论文
共 50 条
  • [41] OPC UA Security for Protecting Substation and Control Center Data Communication in the Distribution Domain of the Smart Grid
    Jafary, Peyman
    Repo, Sami
    Salmenpera, Mikko
    Koivisto, Hannu
    PROCEEDINGS 2015 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL INFORMATICS (INDIN), 2015, : 645 - 651
  • [42] Multi-level user and role concept for a secure plug-and-work based on OPC UA and AutomationML
    Schleipen, Miriam
    Selyansky, Evgeny
    Henssen, Robert
    Bischoff, Tino
    PROCEEDINGS OF 2015 IEEE 20TH CONFERENCE ON EMERGING TECHNOLOGIES & FACTORY AUTOMATION (ETFA), 2015,
  • [43] OPC UA Based ERP Agents: Enabling Scalable Communication Solutions in Heterogeneous Automation Environments
    Hoffmann, Max
    Meisen, Tobias
    Jeschke, Sabina
    ADVANCES IN PRACTICAL APPLICATIONS OF CYBER-PHYSICAL MULTI-AGENT SYSTEMS: THE PAAMS COLLECTION, PAAMS 2017, 2017, 10349 : 120 - 131
  • [44] Integration of distributed Automation Solutions using OPC UA Combination of purposeful Middleware-Approaches
    Riedl, Matthias
    Simon, Rene
    Grewe, Axel
    AUTOMATION 2012, 2012, 2171 : 59 - 62
  • [45] A Privacy, Security, Safety, Resilience and Reliability Focused Risk Assessment Methodology for IIoT Systems Steps to Build and Use Secure IIoT Systems
    Nakamura, Emilio Tissato
    Ribeiro, Sergio Luis
    2018 GLOBAL INTERNET OF THINGS SUMMIT (GIOTS), 2018, : 67 - 72
  • [46] OPC UA based multi-agent systems - Intelligent automation solutions for traditional production infrastructures
    Hoffmann, Max
    Buescher, Christian
    Meisen, Tobias
    Jeschke, Sabina
    ATP EDITION, 2016, (7-8): : 46 - 57
  • [47] Insights into Mapping Solutions Based on OPC UA Information Model Applied to the Industry 4.0 Asset Administration Shell
    Cavalieri, Salvatore
    Salafia, Marco Giuseppe
    COMPUTERS, 2020, 9 (02)
  • [48] The interplay of asset administration shell, AutomationML and OPC UA - Recommendations for action for the selection and use of existing interoperability solutions
    Drath R.
    Mosch C.
    Hoppe S.
    Faath A.
    Barnstedt E.
    Schleipen M.
    VDI Berichte, 2023, 2023 (2419): : 319 - 336
  • [49] Dynamic Security Analysis of Embedded Systems' Firmwares (Network and Distributed System Security (NDSS) Symposium). A Forensic I/O Recorder for Industrial Control Systems Using PLCs and OPC UA
    Karagiozidis, Alexios
    Gergeleit, Martin
    18TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY & SECURITY, ARES 2023, 2023,
  • [50] From a wired to a wireless secure EPR: Can we re-use existing security solutions?
    Ferreira, A
    Oliveira-Palhares, E
    Correia, R
    Costa-Pereira, A
    39TH ANNUAL 2005 INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY, PROCEEDINGS, 2005, : 93 - 96