Secure Granular Interoperability with OPC UA

Venesa Watson, J. Sassmannshausen, K. Waedt
{"title":"Secure Granular Interoperability with OPC UA","authors":"Venesa Watson, J. Sassmannshausen, K. Waedt","doi":"10.18420/inf2019_ws34","DOIUrl":null,"url":null,"abstract":"Open Platform Communications Unified Architecture (OPC UA) is the communication standard earmarked for future industrial automation, particularly for the Industry 4.0 (I4.0) infrastructure where it provides the key services for interoperability and built-in communication security. OPC UA defines several models for these services and has already been deployed by industrial partners in their efforts to achieve I4.0 market readiness and to provide more robust systems. Of particular interest is the security services offered by OPC UA, as they are expected to strengthen the security posture of industrial automation systems, which have so far suffered a number of sophisticated cyber-attacks. In general, cyber-attacks are more severe based on the level of access acquired by the attacker, for example, an attacker with unrestricted administrative level access can issue more powerful commands. It is safe to say then that a more stringent access control security concept can offer systems greater protection from unauthorized access. Several access control models exist, which are categorized under two headings discretionary (data owners/users set the access control rules) and non-discretionary (security administrators control the access granted to users). Here, a non-discretionary access control model, namely the attribute-based access control (ABAC) model is compared to the role-based access control (also non-discretionary) typically assumed with OPC UA, to ascertain how a more granular security structure with ABAC could provide additional security advantages for industry.","PeriodicalId":434189,"journal":{"name":"GI-Jahrestagung","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"GI-Jahrestagung","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.18420/inf2019_ws34","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

Abstract

Open Platform Communications Unified Architecture (OPC UA) is the communication standard earmarked for future industrial automation, particularly for the Industry 4.0 (I4.0) infrastructure where it provides the key services for interoperability and built-in communication security. OPC UA defines several models for these services and has already been deployed by industrial partners in their efforts to achieve I4.0 market readiness and to provide more robust systems. Of particular interest is the security services offered by OPC UA, as they are expected to strengthen the security posture of industrial automation systems, which have so far suffered a number of sophisticated cyber-attacks. In general, cyber-attacks are more severe based on the level of access acquired by the attacker, for example, an attacker with unrestricted administrative level access can issue more powerful commands. It is safe to say then that a more stringent access control security concept can offer systems greater protection from unauthorized access. Several access control models exist, which are categorized under two headings discretionary (data owners/users set the access control rules) and non-discretionary (security administrators control the access granted to users). Here, a non-discretionary access control model, namely the attribute-based access control (ABAC) model is compared to the role-based access control (also non-discretionary) typically assumed with OPC UA, to ascertain how a more granular security structure with ABAC could provide additional security advantages for industry.
与OPC UA的安全粒度互操作性
开放平台通信统一架构(OPC UA)是未来工业自动化专用的通信标准,特别是工业4.0 (I4.0)基础设施,它为互操作性和内置通信安全提供关键服务。OPC UA为这些服务定义了几种模型,并且已经被工业合作伙伴部署,以实现工业4.0的市场准备并提供更强大的系统。特别令人感兴趣的是OPC UA提供的安全服务,因为它们有望加强工业自动化系统的安全态势,这些系统迄今遭受了许多复杂的网络攻击。一般来说,网络攻击的严重程度取决于攻击者获得的访问权限级别,例如,具有不受限制的管理级别访问权限的攻击者可以发出更强大的命令。可以肯定地说,更严格的访问控制安全概念可以为系统提供更好的保护,防止未经授权的访问。存在几种访问控制模型,可分为两大类:自主(数据所有者/用户设置访问控制规则)和非自主(安全管理员控制授予用户的访问权限)。这里,将非自由支配的访问控制模型,即基于属性的访问控制(ABAC)模型与OPC UA通常假设的基于角色的访问控制(也是非自由支配的)进行比较,以确定具有ABAC的更细粒度的安全结构如何为工业提供额外的安全优势。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信