Industry 4.0 uses a subset of the IoT, named Industrial IoT (IIoT), to achieve connectivity, interoperability, and decentralization. The deployment of industrial networks rarely considers security by design, but this becomes imperative in smart manufacturing as connectivity increases. The combination of OT and IT infrastructures in Industry 4.0 adds new security threats beyond those of traditional industrial networks. Defence-in-Depth (DiD) strategies tackle the complexity of this problem by providing multiple defense layers, each of these focusing on a particular set of threats. Additionally, the strict requirements of IIoT networks demand lightweight encryption algorithms. Nevertheless, these ciphers must provide E2E (End-to-End) security, as data passes through intermediate entities or middleboxes before reaching their destination. If compromised, middleboxes could expose vulnerable information to potential attackers if it is not encrypted throughout this path. This paper presents an analysis of the most relevant security strategies in Industry 4.0, focusing primarily on DiD. With these in mind, it proposes a combination of DiD, an encryption algorithm called Attribute-Based-Encryption (ABE), and object security (i.e., OSCORE) to get an E2E security approach. This analysis is a critical first step to developing more complex and lightweight security frameworks suitable for Industry 4.0.
翻译:工业4.0 工业4.0 利用称为工业IOT(IIoT)的工业IOT的一个子集来实现连通性、互操作性和权力下放。工业网络的部署很少从设计上考虑安全,但随着连通性增加,这在智能制造方面变得势在必行。工业4.0 将OT和IT基础设施结合起来,除了传统工业网络的安全威胁外,还增加了新的安全威胁。国防部DID(DID)战略通过提供多种防御层面来解决这个问题的复杂性,其中每个层面都侧重于特殊威胁。此外,国际工业局网络的严格要求要求使用轻量的加密算法。然而,这些密码器必须提供E2E(End-End)安全,作为通过中间实体或中间箱传送的数据,在到达目的地之前,这些安全必须提供E2(End-E)安全安全安全。中框若不在整个过程中加密,就可能向潜在的攻击者暴露易用信息。本文件分析工业4.0 最相关的安全战略,主要侧重于DiD。为此,它提议将DDD的加密算成一种组合,即称为以属性为基础的加密加密算法。但安全系统(ABE-E2 4-E-E-exxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx