A Zero-Trust Architecture for Remote Access in Industrial IoT Infrastructures

被引:10
|
作者
Federici, Fabio [1 ]
Martintoni, Davide [1 ]
Senni, Valerio [1 ]
机构
[1] Collins Aerosp, Appl Res & Technol, I-00185 Rome, Italy
基金
欧盟地平线“2020”;
关键词
access control; industrial IoT; zero-trust; industrial control systems; connected aircraft; IIOT;
D O I
10.3390/electronics12030566
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper considers the domain of Industrial Internet of Things (IIoT) infrastructures and the recurring need for collaboration across teams and stakeholders by means of remote access. The paper describes a secure solution beyond the traditional perimeter-based security approach, which consists of an architecture that supports multi-level authorization to achieve fine-grained access control, better scalability, and maintainability. An implementation of the proposed solution, using open-source technologies, is also discussed and covers the protection of both the network and edge domains of a complex IIoT infrastructure. Finally, the paper presents a risk-driven and model-based process that is designed to support the migration of existing infrastructures to the solution architecture. The approach is validated, taking as a reference two relevant scenarios for the aerospace industry.
引用
下载
收藏
页数:20
相关论文
共 50 条
  • [31] Towards Zero-Trust VoIP Architecture: A Testbed Implementation, Approach, and Lessons Learned
    Fox, Michael
    Hammad, Eman
    Magnussen, Walt
    Schulzrinne, Henning
    2023 IEEE FUTURE NETWORKS WORLD FORUM, FNWF, 2024,
  • [32] Zero-Trust for the System Design Lifecycle
    Van Bossuyt, Douglas L.
    Hale, Britta
    Arlitt, Ryan
    Papakonstantinou, Nikolaos
    JOURNAL OF COMPUTING AND INFORMATION SCIENCE IN ENGINEERING, 2023, 23 (06)
  • [33] An Edge Zero-Trust Model Against Compromised Terminals Threats in Power IoT Environments
    Feng J.
    Yu T.
    Wang Z.
    Zhang W.
    Han G.
    Huang W.
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2022, 59 (05): : 1120 - 1132
  • [34] An analysis of zero-trust architecture and its cost-effectiveness for organizational security
    Adahman, Zillah
    Malik, Asad Waqar
    Anwar, Zahid
    COMPUTERS & SECURITY, 2022, 122
  • [35] SDP Based Zero-Trust Architectures
    Nair, Suku
    PROCEEDINGS OF THE 2022 ACM INTERNATIONAL WORKSHOP ON SECURITY AND PRIVACY ANALYTICS (IWSPA '22), 2022, : 1 - 1
  • [36] Physical Layer Enhanced Zero-Trust Security for Wireless Industrial Internet of Things
    Lei, Wenxin
    Pang, Zhibo
    Wen, Hong
    Hou, Wenjing
    Li, Wen
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2024, 20 (03) : 4327 - 4336
  • [37] A data plane security model of SR-BE/TE based on zero-trust architecture
    Liang Wang
    Hailong Ma
    Ziyong Li
    Jinchuan Pei
    Tao Hu
    Jin Zhang
    Scientific Reports, 12
  • [38] A Learning-Based Zero-Trust Architecture for 6G and Future Networks
    Enright, Michael A.
    Hammad, Eman
    Dutta, Ashutosh
    2022 IEEE FUTURE NETWORKS WORLD FORUM, FNWF, 2022, : 64 - 71
  • [39] A data plane security model of SR-BE/TE based on zero-trust architecture
    Wang, Liang
    Ma, Hailong
    Li, Ziyong
    Pei, Jinchuan
    Hu, Tao
    Zhang, Jin
    SCIENTIFIC REPORTS, 2022, 12 (01)
  • [40] WiP: Towards Zero Trust Authentication in Critical Industrial Infrastructures with PRISM
    Wang, Fuyi
    Wang, Yanping
    Zhang, Leo Yu
    Hertzog, Yuval
    Loewy, Michael
    Valladolid, Dominique
    Medeiros, Julio
    Al-Hawawreh, Muna
    Doss, Robin
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY WORKSHOPS, ACNS 2023 SATELLITE WORKSHOPS, ADSC 2023, AIBLOCK 2023, AIHWS 2023, AIOTS 2023, CIMSS 2023, CLOUD S&P 2023, SCI 2023, SECMT 2023, SIMLA 2023, 2023, 13907 : 336 - 354