论文标题

关于安全域中IO-Link无线通信的安全性

On the Security of IO-Link Wireless Communication in the Safety Domain

论文作者

Doebbert, Thomas R., Fischer, Florian, Merli, Dominik, Scholl, Gerd

论文摘要

安全是工业控制系统(ICS)环境及其基础通信基础架构的重要要求。尤其是监督控制和数据采集(SCADA)系统中的最低通信水平 - 现场级别 - 通常缺乏安全措施。由于现场级别内的新兴无线技术向潜在的攻击者展示了最低的通信基础架构,因此必须考虑高于流行通信的普遍概念的其他安全措施。因此,这项工作分析了无线通信协议IO-Linkwireless(IOLW)的安全方面,该协议通常用于传感器和执行器场级通信。最近已经提出了IOLW安全层的一个可能的架构[1]。在本文中,分析了IOLW在其典型环境中的整体攻击表面,并研究了攻击先决条件以评估不同安全措施的有效性。此外,对通信系统进行了增强的安全措施,并总结了结果。同样,研究了通信中安全措施和功能安全原则的干预,这不一定是相互补充,但也可能有矛盾的要求。这项工作旨在讨论并提出对IOLW标准的增强,并在未来的实施中使用其他安全考虑。

Security is an essential requirement of Industrial Control System (ICS) environments and its underlying communication infrastructure. Especially the lowest communication level within Supervisory Control and Data Acquisition (SCADA) systems - the field level - commonly lacks security measures. Since emerging wireless technologies within field level expose the lowest communication infrastructure towards potential attackers, additional security measures above the prevalent concept of air-gapped communication must be considered. Therefore, this work analyzes security aspects for the wireless communication protocol IO-LinkWireless (IOLW), which is commonly used for sensor and actuator field level communication. A possible architecture for an IOLW safety layer has already been presented recently [1]. In this paper, the overall attack surface of IOLW within its typical environment is analyzed and attack preconditions are investigated to assess the effectiveness of different security measures. Additionally, enhanced security measures are evaluated for the communication systems and the results are summarized. Also, interference of security measures and functional safety principles within the communication are investigated, which do not necessarily complement one another but may also have contradictory requirements. This work is intended to discuss and propose enhancements of the IOLW standard with additional security considerations in future implementations.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源