论文标题

使用基于硬件的安全令牌的实用配置管理的案例

A Case for Practical Configuration Management Using Hardware-based Security Tokens

论文作者

Lackorzynski, Tim, Ostermann, Max, Köpsell, Stefan, Härtig, Hermann

论文摘要

未来的工业网络将包括新的和遗留组件的复杂混合,而行业4.0设想的新用例和应用程序将要求这些网络的灵活性和动态增加。工业安全门户将成为解决这些变化要求的新安全要求的重要组成部分。他们的介绍将进一步提高这些网络已经很高的复杂性,要​​求在正确和安全地配置它们方面做更多的努力。然而,过去的研究表明,大多数工业网络运营商如今已经无法以安全的方式配置工业网络。 因此,我们提出了一种计划,允许工厂运营商以简单且实用的方式配置安全网关,对于未经安全域中培训的员工来说,这也是可以理解的。我们采用硬件安全令牌,可以将每天的配置减少到一种物理互动。我们的结果表明,我们提出的计划的实际可行性,并且不会以任何方式降低工业安全门户的安全水平。

Future industrial networks will consist of a complex mixture of new and legacy components, while new use cases and applications envisioned by Industry 4.0 will demand increased flexibility and dynamics from these networks. Industrial security gateways will become an important building block to tackle new security requirements demanded by these changes. Their introduction will further increase the already high complexity of these networks, demanding more efforts in properly and securely configuring them. Yet, past research showed, that most operators of industrial networks are already today unable to configure industrial networks in a secure fashion. Therefore, we propose a scheme that allows factory operators to configure security gateways in an easy and practical way that is also understandable for staff not trained in the security domain. We employ hardware security tokens that allow to reduce every day configuration to one physical interaction. Our results show the practical feasibility of our proposed scheme and that it does not reduce the security level of industrial security gateways in any way.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源