工业4.0的网络安全展望:身份和访问管理的推动者角色

Osama A. Alsaadoun
{"title":"工业4.0的网络安全展望:身份和访问管理的推动者角色","authors":"Osama A. Alsaadoun","doi":"10.2523/IPTC-19072-MS","DOIUrl":null,"url":null,"abstract":"\n Rapid development of intelligent machinery is expected to be foundational to prospective evolution of Industry 4.0, especially for traditional industries such as the energy sector. Nanodevices, context-aware sensors, and advanced forms of robotics are expected to formulate fully autonomous cyber-physical systems capable of replacing contemporary human-operated machinery used to perform significant construction activities in hydrocarbon facilities projects. For instance, oil & gas pipeline construction projects may transform into autonomous processes through means of such intelligent cyber-physical machines leveraging contextual awareness, data mining, and analytics techniques. Such projects typically present production lifecycle vectors comprising of material procurement, logistics, and customer demand, in consistency with typical Industry 4.0 business structuring. The intelligence introduced within such vectors present significant impacts on cybersecurity factors, including production integrity, availability, and relevant confidentiality.\n In this paper, we study influencing factors of cybersecurity on prospective Industry 4.0's main subjects: Industrial Internet of Things (IIoT), extending to those playing role in hydrocarbon construction management. We present the status quo in IIoT cybersecurity challenges and mitigations mechanisms and strategies, in sync with potential developments of advanced cyber-physical industrial machines. The relationship of prospective IIoT advances in tandem with possible cybersecurity challenges is explored. Consequently, a gap analysis is conducted to highlight essential cybersecurity controls and whether they are already present or to be developed. We use identified gaps as engineering elements for a suggested Identity and Access Management (IAM) framework capable of: devising appropriate physical and logical controls, meeting predefined business risk profile, and assuring compliance with state or industrial compliance criteria. To qualitatively ensure validity of the framework, we draw similarity of cybersecurity challenges from similar manufacturing disciplines - to infer applicability, and apply our framework to similar challenges in these industries. We ultimately conclude effectiveness of IAM as an enabler safeguard of Industry 4.0 against relevant cybersecurity issues.\n The summary of our research results is presented as follows: an inventory of major categories of risks applicable to Industry 4.0 cyber-physical subjects, potential gaps in relevant cybersecurity controls, and an IAM framework made of factors designed to address the associated risks. We present a set of effectively implementable blueprints of the IAM framework developed using the Open Group Architecture Framework (TOGAF) technique, a premier methodology in the enterprise architecture modeling.\n Novelty of our work is primarily stemmed from the idea of targeting the hydrocarbon construction management domain with firm forms of cyber-physical subjects, along with demonstrating roles of IAM in protecting the subjects’ intelligent capabilities by enforcing IAM’s cybersecurity controls. Our IAM framework will be flexible to adapt to theoretically all roles that intelligent cyber-physical machines can be designed for, and across the entire lifecycle vectors.","PeriodicalId":11267,"journal":{"name":"Day 3 Thu, March 28, 2019","volume":"488 1","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2019-03-22","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":"{\"title\":\"A Cybersecurity Prospective on Industry 4.0: Enabler Role of Identity and Access Management\",\"authors\":\"Osama A. Alsaadoun\",\"doi\":\"10.2523/IPTC-19072-MS\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"\\n Rapid development of intelligent machinery is expected to be foundational to prospective evolution of Industry 4.0, especially for traditional industries such as the energy sector. Nanodevices, context-aware sensors, and advanced forms of robotics are expected to formulate fully autonomous cyber-physical systems capable of replacing contemporary human-operated machinery used to perform significant construction activities in hydrocarbon facilities projects. For instance, oil & gas pipeline construction projects may transform into autonomous processes through means of such intelligent cyber-physical machines leveraging contextual awareness, data mining, and analytics techniques. Such projects typically present production lifecycle vectors comprising of material procurement, logistics, and customer demand, in consistency with typical Industry 4.0 business structuring. The intelligence introduced within such vectors present significant impacts on cybersecurity factors, including production integrity, availability, and relevant confidentiality.\\n In this paper, we study influencing factors of cybersecurity on prospective Industry 4.0's main subjects: Industrial Internet of Things (IIoT), extending to those playing role in hydrocarbon construction management. We present the status quo in IIoT cybersecurity challenges and mitigations mechanisms and strategies, in sync with potential developments of advanced cyber-physical industrial machines. The relationship of prospective IIoT advances in tandem with possible cybersecurity challenges is explored. Consequently, a gap analysis is conducted to highlight essential cybersecurity controls and whether they are already present or to be developed. We use identified gaps as engineering elements for a suggested Identity and Access Management (IAM) framework capable of: devising appropriate physical and logical controls, meeting predefined business risk profile, and assuring compliance with state or industrial compliance criteria. To qualitatively ensure validity of the framework, we draw similarity of cybersecurity challenges from similar manufacturing disciplines - to infer applicability, and apply our framework to similar challenges in these industries. We ultimately conclude effectiveness of IAM as an enabler safeguard of Industry 4.0 against relevant cybersecurity issues.\\n The summary of our research results is presented as follows: an inventory of major categories of risks applicable to Industry 4.0 cyber-physical subjects, potential gaps in relevant cybersecurity controls, and an IAM framework made of factors designed to address the associated risks. We present a set of effectively implementable blueprints of the IAM framework developed using the Open Group Architecture Framework (TOGAF) technique, a premier methodology in the enterprise architecture modeling.\\n Novelty of our work is primarily stemmed from the idea of targeting the hydrocarbon construction management domain with firm forms of cyber-physical subjects, along with demonstrating roles of IAM in protecting the subjects’ intelligent capabilities by enforcing IAM’s cybersecurity controls. Our IAM framework will be flexible to adapt to theoretically all roles that intelligent cyber-physical machines can be designed for, and across the entire lifecycle vectors.\",\"PeriodicalId\":11267,\"journal\":{\"name\":\"Day 3 Thu, March 28, 2019\",\"volume\":\"488 1\",\"pages\":\"\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2019-03-22\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"6\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Day 3 Thu, March 28, 2019\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.2523/IPTC-19072-MS\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Day 3 Thu, March 28, 2019","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.2523/IPTC-19072-MS","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6

摘要

智能机械的快速发展有望成为工业4.0未来发展的基础,特别是对传统行业,如能源行业。纳米器件、环境感知传感器和先进的机器人技术有望形成完全自主的网络物理系统,取代目前用于碳氢化合物设施项目中执行重大建设活动的人工操作机械。例如,石油和天然气管道建设项目可以通过利用上下文感知、数据挖掘和分析技术的智能网络物理机器转变为自主过程。这些项目通常呈现由材料采购、物流和客户需求组成的生产生命周期向量,与典型的工业4.0业务结构保持一致。在这些载体中引入的情报对网络安全因素产生了重大影响,包括生产完整性、可用性和相关机密性。本文从工业4.0的主要领域工业物联网(IIoT)出发,研究网络安全的影响因素,并将其扩展到油气建设管理中。我们介绍了工业物联网网络安全挑战和缓解机制和策略的现状,并与先进的网络物理工业机器的潜在发展同步。探讨了未来工业物联网的发展与可能的网络安全挑战之间的关系。因此,进行差距分析以突出必要的网络安全控制,以及它们是否已经存在或有待开发。我们使用已识别的差距作为建议的身份和访问管理(IAM)框架的工程元素,该框架能够:设计适当的物理和逻辑控制,满足预定义的业务风险配置,并确保符合国家或行业合规标准。为了定性地确保框架的有效性,我们从类似的制造学科中得出网络安全挑战的相似性-推断适用性,并将我们的框架应用于这些行业的类似挑战。我们最终得出结论,IAM作为工业4.0针对相关网络安全问题的推动者保障的有效性。我们的研究结果总结如下:适用于工业4.0网络物理主题的主要风险类别的清单,相关网络安全控制的潜在差距,以及由旨在解决相关风险的因素组成的IAM框架。我们提出了一组使用开放组架构框架(TOGAF)技术开发的IAM框架的有效实现蓝图,TOGAF是企业架构建模的主要方法。我们工作的新颖性主要源于针对碳氢化合物建设管理领域的想法,该领域具有固定形式的网络物理主体,同时通过执行IAM的网络安全控制来展示IAM在保护主体智能能力方面的作用。我们的IAM框架将灵活地适应理论上智能网络物理机器可以设计的所有角色,并跨越整个生命周期向量。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
A Cybersecurity Prospective on Industry 4.0: Enabler Role of Identity and Access Management
Rapid development of intelligent machinery is expected to be foundational to prospective evolution of Industry 4.0, especially for traditional industries such as the energy sector. Nanodevices, context-aware sensors, and advanced forms of robotics are expected to formulate fully autonomous cyber-physical systems capable of replacing contemporary human-operated machinery used to perform significant construction activities in hydrocarbon facilities projects. For instance, oil & gas pipeline construction projects may transform into autonomous processes through means of such intelligent cyber-physical machines leveraging contextual awareness, data mining, and analytics techniques. Such projects typically present production lifecycle vectors comprising of material procurement, logistics, and customer demand, in consistency with typical Industry 4.0 business structuring. The intelligence introduced within such vectors present significant impacts on cybersecurity factors, including production integrity, availability, and relevant confidentiality. In this paper, we study influencing factors of cybersecurity on prospective Industry 4.0's main subjects: Industrial Internet of Things (IIoT), extending to those playing role in hydrocarbon construction management. We present the status quo in IIoT cybersecurity challenges and mitigations mechanisms and strategies, in sync with potential developments of advanced cyber-physical industrial machines. The relationship of prospective IIoT advances in tandem with possible cybersecurity challenges is explored. Consequently, a gap analysis is conducted to highlight essential cybersecurity controls and whether they are already present or to be developed. We use identified gaps as engineering elements for a suggested Identity and Access Management (IAM) framework capable of: devising appropriate physical and logical controls, meeting predefined business risk profile, and assuring compliance with state or industrial compliance criteria. To qualitatively ensure validity of the framework, we draw similarity of cybersecurity challenges from similar manufacturing disciplines - to infer applicability, and apply our framework to similar challenges in these industries. We ultimately conclude effectiveness of IAM as an enabler safeguard of Industry 4.0 against relevant cybersecurity issues. The summary of our research results is presented as follows: an inventory of major categories of risks applicable to Industry 4.0 cyber-physical subjects, potential gaps in relevant cybersecurity controls, and an IAM framework made of factors designed to address the associated risks. We present a set of effectively implementable blueprints of the IAM framework developed using the Open Group Architecture Framework (TOGAF) technique, a premier methodology in the enterprise architecture modeling. Novelty of our work is primarily stemmed from the idea of targeting the hydrocarbon construction management domain with firm forms of cyber-physical subjects, along with demonstrating roles of IAM in protecting the subjects’ intelligent capabilities by enforcing IAM’s cybersecurity controls. Our IAM framework will be flexible to adapt to theoretically all roles that intelligent cyber-physical machines can be designed for, and across the entire lifecycle vectors.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信