Wenxin Lei, Zhibo Pang, Hong Wen, Wenjing Hou, Xiaoling Zhang
{"title":"Edge-enabled Zero Trust Architecture for ICPS with Spatial and Temporal Granularity","authors":"Wenxin Lei, Zhibo Pang, Hong Wen, Wenjing Hou, Xiaoling Zhang","doi":"10.1109/ICPS58381.2023.10127999","DOIUrl":null,"url":null,"abstract":"Motivated by the rapid advancement of industrial cyber-physical systems (ICPS) and rising voices in favor of zero trust (ZT) security, in this paper, we present an edge-enabled zero trust architecture (ZTA) for ICPS. ZT is thought to be relevant to ICPS with the spatial and temporal granularity in the suggested architecture. In addition to continuous authentication and a dynamic access-control mechanism at the temporal granularity, we recommend edge segmentation at the spatial granularity with microservices as the division units. Finally, we conduct a security assessment of the proposed architecture in the presence of threats faced by ICPS. Overall, our analysis shows that the proposed ZTA helps to promote the security of ICPS.","PeriodicalId":426122,"journal":{"name":"2023 IEEE 6th International Conference on Industrial Cyber-Physical Systems (ICPS)","volume":"36 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-05-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 IEEE 6th International Conference on Industrial Cyber-Physical Systems (ICPS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICPS58381.2023.10127999","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
Motivated by the rapid advancement of industrial cyber-physical systems (ICPS) and rising voices in favor of zero trust (ZT) security, in this paper, we present an edge-enabled zero trust architecture (ZTA) for ICPS. ZT is thought to be relevant to ICPS with the spatial and temporal granularity in the suggested architecture. In addition to continuous authentication and a dynamic access-control mechanism at the temporal granularity, we recommend edge segmentation at the spatial granularity with microservices as the division units. Finally, we conduct a security assessment of the proposed architecture in the presence of threats faced by ICPS. Overall, our analysis shows that the proposed ZTA helps to promote the security of ICPS.