论文标题

使用深入的防御性确保IIOT:朝向端到端的安全行业4.0

Securing IIoT using Defence-in-Depth: Towards an End-to-End Secure Industry 4.0

论文作者

Mosteiro-Sanchez, Aintzane, Barcelo, Marc, Astorga, Jasone, Urbieta, Aitor

论文摘要

工业4.0使用IoT的一个子集,名为工业物联网(IIOT)来实现连通性,互操作性和权力下放。工业网络的部署很少会通过设计考虑安全性,但是随着连接性的增加,这在智能制造中必须做到这一点。 OT和IT基础架构在行业4.0中的结合增加了超出传统工业网络的新安全威胁。在深入(DID)策略中的防御性通过提供多个防御层来解决该问题的复杂性,这些防御层集中在一组特定的威胁上。此外,IIOT网络的严格要求需要轻巧的加密算法。然而,这些密码必须在到达目的地之前通过中间实体或中间箱提供E2E(端到端)安全性。如果受到妥协,如果中间框未加密在此路径中,则可能会将脆弱的信息暴露于潜在的攻击者中。本文对行业4.0中最相关的安全策略进行了分析,主要侧重于DIT。考虑到这些,它提出了DID的组合,即一种称为基于属性的加热算法(ABE)和对象安全性(即Oscore)的加密算法,以获取E2E安全方法。该分析是开发适合行业4.0的更复杂和轻巧的安全框架的关键第一步。

Industry 4.0 uses a subset of the IoT, named Industrial IoT (IIoT), to achieve connectivity, interoperability, and decentralization. The deployment of industrial networks rarely considers security by design, but this becomes imperative in smart manufacturing as connectivity increases. The combination of OT and IT infrastructures in Industry 4.0 adds new security threats beyond those of traditional industrial networks. Defence-in-Depth (DiD) strategies tackle the complexity of this problem by providing multiple defense layers, each of these focusing on a particular set of threats. Additionally, the strict requirements of IIoT networks demand lightweight encryption algorithms. Nevertheless, these ciphers must provide E2E (End-to-End) security, as data passes through intermediate entities or middleboxes before reaching their destination. If compromised, middleboxes could expose vulnerable information to potential attackers if it is not encrypted throughout this path. This paper presents an analysis of the most relevant security strategies in Industry 4.0, focusing primarily on DiD. With these in mind, it proposes a combination of DiD, an encryption algorithm called Attribute-Based-Encryption (ABE), and object security (i.e., OSCORE) to get an E2E security approach. This analysis is a critical first step to developing more complex and lightweight security frameworks suitable for Industry 4.0.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源