基于OPC UA的应用程序使用属性证书增强授权机制

G. Karthikeyan, S. Heiss
{"title":"基于OPC UA的应用程序使用属性证书增强授权机制","authors":"G. Karthikeyan, S. Heiss","doi":"10.1109/INDIN41052.2019.8972148","DOIUrl":null,"url":null,"abstract":"In the context of Industrie 4.0, integrity of data is considered as the core of networking and digitalisation. End-to-end security of the communicating entities within and across organizational boundaries is enabled by authentication and authorization methods. In order to ensure authorized access or modification to data, an access control system is used. Such an access control system based on the role of an entity is a Role Based Access Control (RBAC) system. In case of distributed networks, the authorization permissions of the communicating entities is determined both within and across organizational boundaries. For example, each organization defines the authorization permissions for each of its resources for both internal and external access. In case of external access, an organization can determine permissions based on a role assigned to an external entity trying to communicate across its organizational boundaries. Here, trusted association between the role and the identities need to be determined. Thus, the role/roles assigned to the external entity can be determined using an Attribute Certificate (AC). An AC contains the attribute/attributes that determines the characteristics associated with an entity. An Attribute Authority (AA) of an organization that assigns a role attribute to the AC of an entity, issues each AC. Such an AA is created and managed using Public Key Infrastructure (PKI). The OPC UA (Open Platform Communication Unified Architecture) framework has different options for user authentication and one of the options is using X509IdentityToken. Integrating ACs in order to enhance authorization mechanism in the context of Industrie 4.0 is considered in this work. A multilevel PKI is designed in order to demonstrate the feasibility of the approach through a proof of concept implementation that establishes end-to-end secure communication between OPC UA based applications. The advantages and challenges in creating such an infrastructure and further areas of research are discussed briefly.","PeriodicalId":260220,"journal":{"name":"2019 IEEE 17th International Conference on Industrial Informatics (INDIN)","volume":"14 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Enhancing Authorization Mechanisms using Attribute Certificates for OPC UA based Applications\",\"authors\":\"G. Karthikeyan, S. Heiss\",\"doi\":\"10.1109/INDIN41052.2019.8972148\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"In the context of Industrie 4.0, integrity of data is considered as the core of networking and digitalisation. End-to-end security of the communicating entities within and across organizational boundaries is enabled by authentication and authorization methods. In order to ensure authorized access or modification to data, an access control system is used. Such an access control system based on the role of an entity is a Role Based Access Control (RBAC) system. In case of distributed networks, the authorization permissions of the communicating entities is determined both within and across organizational boundaries. For example, each organization defines the authorization permissions for each of its resources for both internal and external access. In case of external access, an organization can determine permissions based on a role assigned to an external entity trying to communicate across its organizational boundaries. Here, trusted association between the role and the identities need to be determined. Thus, the role/roles assigned to the external entity can be determined using an Attribute Certificate (AC). An AC contains the attribute/attributes that determines the characteristics associated with an entity. An Attribute Authority (AA) of an organization that assigns a role attribute to the AC of an entity, issues each AC. Such an AA is created and managed using Public Key Infrastructure (PKI). The OPC UA (Open Platform Communication Unified Architecture) framework has different options for user authentication and one of the options is using X509IdentityToken. Integrating ACs in order to enhance authorization mechanism in the context of Industrie 4.0 is considered in this work. A multilevel PKI is designed in order to demonstrate the feasibility of the approach through a proof of concept implementation that establishes end-to-end secure communication between OPC UA based applications. The advantages and challenges in creating such an infrastructure and further areas of research are discussed briefly.\",\"PeriodicalId\":260220,\"journal\":{\"name\":\"2019 IEEE 17th International Conference on Industrial Informatics (INDIN)\",\"volume\":\"14 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2019-07-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2019 IEEE 17th International Conference on Industrial Informatics (INDIN)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/INDIN41052.2019.8972148\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 IEEE 17th International Conference on Industrial Informatics (INDIN)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/INDIN41052.2019.8972148","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

在工业4.0的背景下,数据的完整性被认为是网络化和数字化的核心。组织边界内和跨组织边界的通信实体的端到端安全性是通过身份验证和授权方法实现的。为了确保对数据的授权访问或修改,使用了访问控制系统。这种基于实体角色的访问控制系统就是基于角色的访问控制系统(role based access control, RBAC)。在分布式网络中,通信实体的授权权限是在组织边界内和跨组织边界确定的。例如,每个组织为其内部和外部访问的每个资源定义授权权限。在外部访问的情况下,组织可以根据分配给试图跨其组织边界进行通信的外部实体的角色来确定权限。在这里,需要确定角色和身份之间的可信关联。因此,可以使用属性证书(Attribute Certificate, AC)确定分配给外部实体的角色。AC包含确定与实体关联的特征的属性/属性。组织的AA (Attribute Authority)为实体的AC分配角色属性,颁发每个AC。AA (Attribute Authority)通过PKI (Public Key Infrastructure)创建和管理。OPC UA(开放平台通信统一架构)框架有不同的用户身份验证选项,其中一个选项是使用X509IdentityToken。本工作考虑集成ac以增强工业4.0背景下的授权机制。为了证明该方法的可行性,设计了一个多级PKI,通过概念验证实现,在基于OPC UA的应用程序之间建立端到端安全通信。简要讨论了创建这种基础设施的优势和挑战以及进一步的研究领域。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Enhancing Authorization Mechanisms using Attribute Certificates for OPC UA based Applications
In the context of Industrie 4.0, integrity of data is considered as the core of networking and digitalisation. End-to-end security of the communicating entities within and across organizational boundaries is enabled by authentication and authorization methods. In order to ensure authorized access or modification to data, an access control system is used. Such an access control system based on the role of an entity is a Role Based Access Control (RBAC) system. In case of distributed networks, the authorization permissions of the communicating entities is determined both within and across organizational boundaries. For example, each organization defines the authorization permissions for each of its resources for both internal and external access. In case of external access, an organization can determine permissions based on a role assigned to an external entity trying to communicate across its organizational boundaries. Here, trusted association between the role and the identities need to be determined. Thus, the role/roles assigned to the external entity can be determined using an Attribute Certificate (AC). An AC contains the attribute/attributes that determines the characteristics associated with an entity. An Attribute Authority (AA) of an organization that assigns a role attribute to the AC of an entity, issues each AC. Such an AA is created and managed using Public Key Infrastructure (PKI). The OPC UA (Open Platform Communication Unified Architecture) framework has different options for user authentication and one of the options is using X509IdentityToken. Integrating ACs in order to enhance authorization mechanism in the context of Industrie 4.0 is considered in this work. A multilevel PKI is designed in order to demonstrate the feasibility of the approach through a proof of concept implementation that establishes end-to-end secure communication between OPC UA based applications. The advantages and challenges in creating such an infrastructure and further areas of research are discussed briefly.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Digital Twin in Industry 4.0: Technologies, Applications and Challenges Using Multi-Agent Systems for Demand Response Aggregators: Analysis and Requirements for the Development Developing a Secure, Smart Microgrid Energy Market using Distributed Ledger Technologies An Intelligent Assistance System for Controlling Wind-Assisted Ship Propulsion Systems OPC UA Information Model and a Wrapper for IEC 61499 Runtimes
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1