Supporting the integration of new security features in embedded control devices through the digitalization of production

Tobias Rauter*, Johannes Iber, Michael Krisper, Christian Kreiner

*Korrespondierende/r Autor/-in für diese Arbeit

Publikation: Beitrag in Buch/Bericht/KonferenzbandBeitrag in einem KonferenzbandBegutachtung

Abstract

Security is a vital property of Industrial Control Systems (ICS), especially in the context of critical infrastructure. In this work, we focus on distributed control devices for hydro-electric power plants. Much work has been done for specific lifecylce phases of distributed control devices such as development or operational phase. Our aim here is to consider the entire product lifecycle and the consequences of security feature implementations for a single lifecycle stage on other stages. At the same time, recent trends such as the digitization of production is an enabler of production process extensions that support the integration of such security features during the operational phase of a control devices. In particular, we propose a security concept that enables assurance of the integrity of software components and product configuration of other control devices in the same network. Moreover, we show how these concepts result in additional requirements for the production stages. We show how we meet these requirements and focus on a production process by extending previously proposed methods that enable the commissioning of secrets such as private keys during the manufacturing phase. We extend this process by extracting information about the configurations of the actually produced devices during production. Based on this information, the proposed security techniques can be integrated without considerable overhead for bootstrapping.

Originalspracheenglisch
TitelSystems, Software and Services Process Improvement - 24th European Conference, EuroSPI 2017, Proceedings
Herausgeber (Verlag)Springer-Verlag Italia
Seiten360-371
Seitenumfang12
Band748
ISBN (Print)9783319642178
DOIs
PublikationsstatusVeröffentlicht - 2017
Veranstaltung24th European Conference on Systems, Software and Services Process Improvement: EuroSPI 2017 - VSB - Technical University of Ostrava, Ostrava, Tschechische Republik
Dauer: 6 Sept. 20178 Sept. 2017
Konferenznummer: 24
http://2017.eurospi.net/

Publikationsreihe

NameCommunications in Computer and Information Science
Band748
ISSN (Print)1865-0929

Konferenz

Konferenz24th European Conference on Systems, Software and Services Process Improvement
KurztitelEuroSPI 2017
Land/GebietTschechische Republik
OrtOstrava
Zeitraum6/09/178/09/17
Internetadresse

ASJC Scopus subject areas

  • Informatik (insg.)
  • Mathematik (insg.)

Fingerprint

Untersuchen Sie die Forschungsthemen von „Supporting the integration of new security features in embedded control devices through the digitalization of production“. Zusammen bilden sie einen einzigartigen Fingerprint.

Dieses zitieren