Securing Over-the-Air Firmware Updates (FOTA) for Industrial Internet of Things (IIOT) Devices

被引:1
|
作者
Crowther, Kenneth G. [1 ]
Upadrashta, Radhika [1 ]
Ramachandra, Gururaj [1 ]
机构
[1] Xylem, Washington, DC 20003 USA
关键词
IIOT; FOTA; cybersecurity; OT security; firmware security; digital transformation; shared responsibility;
D O I
10.1109/HST56032.2022.10025441
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Industrial Internet of Things (IIOT) is increasingly relying on over-the-air firmware updates (FOTA) to deliver tailored analytics to control systems for critical infrastructure. Connected IIOT with FOTA can deliver significant value by decreasing capital investments, enabling customizable functionalities, or improving operational efficiencies. FOTA also increases exposure to threats targeting critical infrastructure, which could lead to safety or mission damage (i.e., failures could result in loss of life or loss of critical functions). This paper presents a security baseline for FOTA by creating a secure "pipeline" for IIOT firmware. It first provides a generic reference architecture that defines connections between the IIOT device, a gateway for communication outside the control network, cloud storage and configuration logic, and the device- vendor's development environment. It describes attacks against various aspects of the reference architecture and explains the security controls that the device-vendor should implement to ensure that the benefits of FOTA for continuous upgradable security and efficiency outweigh the risks from additional exposure. It also provides some follow-on recommendations that utilities should consider before installing IIOT with FOTA capabilities, including: securing the device with secure boot and chain of trust, securing all communication channels with unique endpoint identification and encryption, taking the human out of the build and update processes, and hardening components involved in FOTA for continuous monitoring. This paper emphasizes that these types of connected devices promote a need for a shared responsibility model of cybersecurity.
引用
收藏
页数:8
相关论文
共 50 条
  • [1] Securing Over-The-Air IoT Firmware Updates using Blockchain
    He, Xinchi
    Alqahtani, Sarra
    Gamble, Rose
    Papa, Mauricio
    [J]. INTERNATIONAL CONFERENCE ON OMNI-LAYER INTELLIGENT SYSTEMS (COINS), 2019, : 164 - 171
  • [2] Over-the-Air Firmware Updates for Constrained NB-IoT Devices
    Mahfoudhi, Farouk
    Sultania, Ashish Kumar
    Famaey, Jeroen
    [J]. SENSORS, 2022, 22 (19)
  • [3] Towards Firmware Analysis of Industrial Internet of Things (IIoT) Applying Symbolic Analysis to IIoT Firmware Vetting
    Palavicini, Geancarlo, Jr.
    Bryan, Josiah
    Sheets, Eaven
    Kline, Megan
    San Miguel, John
    [J]. IOTBDS: PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON INTERNET OF THINGS, BIG DATA AND SECURITY, 2017, : 470 - 477
  • [4] Secure over-The-Air Firmware Updates for Sensor Networks
    Kerliu, Kevin
    Ross, Alexandra
    Tao, Gong
    Yun, Zelin
    Shi, Zhijie
    Han, Song
    Zhou, Shengli
    [J]. 2019 IEEE 16TH INTERNATIONAL CONFERENCE ON MOBILE AD HOC AND SENSOR SYSTEMS WORKSHOPS (MASSW 2019), 2019, : 97 - 100
  • [5] Over-the-Air Software Updates in the Internet of Things: An Overview of Key Principles
    Bauwens, Jan
    Ruckebusch, Peter
    Giannoulis, Spilios
    Moerman, Ingrid
    De Poorter, Eli
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2020, 58 (02) : 35 - 41
  • [6] iOTA: An Approach to Secure Over-The-Air Updates on the Internet of Things Scenario
    Peter, Cleber S.
    Oliveira, Thayna
    Monks, Eduardo M.
    Motta, Fernanda P.
    Barbosa, Jorge L., V
    Yamin, Adenauer C.
    [J]. PROCEEDINGS OF THE 27TH BRAZILIAN SYMPOSIUM ON MULTIMEDIA AND THE WEB (WEBMEDIA '21), 2021, : 173 - 176
  • [7] Over-the-air firmware update for IoT devices on the wild
    Berriel de Sousa, Maria Julia
    Gomez Gonzalez, Luis Fernando
    Ferdinando, Erick Mascagni
    Borin, Juliana Freitag
    [J]. INTERNET OF THINGS, 2022, 19
  • [8] Secure firmware Over-The-Air updates for IoT: Survey, challenges, and discussions
    El Jaouhari, Saad
    Bouvet, Eric
    [J]. INTERNET OF THINGS, 2022, 18
  • [9] Securing the Industrial Internet of Things for Critical Infrastructure (IIoT-CI)
    O'Raw, John
    Laverty, David
    Morrow, D. John
    [J]. 2019 IEEE 5TH WORLD FORUM ON INTERNET OF THINGS (WF-IOT), 2019, : 70 - 75
  • [10] Universal Firmware Upgrade Over-The-Air for IoT Devices with Security
    Thakur, Poonam
    Bodade, Varsha
    Achary, Angitha
    Addagatla, Madhuri
    Malviya, Neeraj Kumar
    Pingle, Yogesh
    [J]. PROCEEDINGS OF THE 2019 6TH INTERNATIONAL CONFERENCE ON COMPUTING FOR SUSTAINABLE GLOBAL DEVELOPMENT (INDIACOM), 2019, : 27 - 30