{"title":"Cyber-Physical Zero Trust Architecture for Industrial Cyber-Physical Systems","authors":"Xiaomeng Feng;Shiyan Hu","doi":"10.1109/TICPS.2023.3333850","DOIUrl":null,"url":null,"abstract":"In recent years, zero trust architecture (ZTA) has become an emerging security architecture. When deploying to industrial systems, an important consideration of the ZTA is the effective modeling of the cross-layer penetration between cyber and physical layers. An ineffective model of cross-layer penetration can lead to inferior performance in mitigating cross-layer failures. To tackle this issue, this paper develops a subset of the ZTA dedicated to industrial cyber-physical systems (ICPS), called the Cyber-Physical-ZTA, to model cross-layer penetration. Its uniqueness mainly consists of two innovative techniques, namely, a multi-layer access control engine and an integrated physical model-based and data-driven policy optimizer. The multi-layer access control engine can evaluate the trust scores for each component considering their cross-layer impact, while the integration of data-driven and model-based approaches can improve efficiency in optimizing access policies. Our simulations are conducted to demonstrate the effectiveness of Cyber-Physical-ZTA. In comparison to the standard ZTA, with no rules added to detect cross-layer penetration, the multi-access policy engine of the Cyber-Physical-ZTA increases the detection probability against false data injection (FDI) attacks by more than 31%.","PeriodicalId":100640,"journal":{"name":"IEEE Transactions on Industrial Cyber-Physical Systems","volume":"1 ","pages":"394-405"},"PeriodicalIF":0.0000,"publicationDate":"2023-11-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"IEEE Transactions on Industrial Cyber-Physical Systems","FirstCategoryId":"1085","ListUrlMain":"https://ieeexplore.ieee.org/document/10330693/","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
In recent years, zero trust architecture (ZTA) has become an emerging security architecture. When deploying to industrial systems, an important consideration of the ZTA is the effective modeling of the cross-layer penetration between cyber and physical layers. An ineffective model of cross-layer penetration can lead to inferior performance in mitigating cross-layer failures. To tackle this issue, this paper develops a subset of the ZTA dedicated to industrial cyber-physical systems (ICPS), called the Cyber-Physical-ZTA, to model cross-layer penetration. Its uniqueness mainly consists of two innovative techniques, namely, a multi-layer access control engine and an integrated physical model-based and data-driven policy optimizer. The multi-layer access control engine can evaluate the trust scores for each component considering their cross-layer impact, while the integration of data-driven and model-based approaches can improve efficiency in optimizing access policies. Our simulations are conducted to demonstrate the effectiveness of Cyber-Physical-ZTA. In comparison to the standard ZTA, with no rules added to detect cross-layer penetration, the multi-access policy engine of the Cyber-Physical-ZTA increases the detection probability against false data injection (FDI) attacks by more than 31%.