Volltext-Downloads (blau) und Frontdoor-Views (grau)

Formal Modeling and Verification of Generic Credential Management Processes for Industrial Cyber–Physical Systems

  • Industrial cyber-physical systems (ICPS) face rising cyberattacks, requiring secure credential management also in resource-constrained embedded systems. Standards specifying field level communication of ICPS (e.g., PROFINET or OPC UA) define protocol-specific credential management processes, yet lack formal security verification. We propose a generic model capturing initial security onboarding andIndustrial cyber-physical systems (ICPS) face rising cyberattacks, requiring secure credential management also in resource-constrained embedded systems. Standards specifying field level communication of ICPS (e.g., PROFINET or OPC UA) define protocol-specific credential management processes, yet lack formal security verification. We propose a generic model capturing initial security onboarding and automated credential provisioning. Using ProVerif, an automatic symbolic protocol verifier, we formalize certificate-based authentication under a Dolev-Yao adversary, verifying private key secrecy, component authentication, and mutual authentication with the operator domain. Robustness checks confirm resilience against key leakage and highlight the vulnerabilities of the trust on first use concept proposed by the standards. Our model offers the first formal guarantees for secure credential management in ICPS.zeige mehrzeige weniger

Metadaten exportieren

Weitere Dienste

Suche bei Google Scholar

Statistik

frontdoor_oas
Metadaten
Dokumentart:Zeitschriftenartikel, wissenschaftlich
Review-Status:Begutachtet (reviewed)
Zitierlink: https://opus.hs-offenburg.de/11563
Bibliografische Angaben
Titel (Englisch):Formal Modeling and Verification of Generic Credential Management Processes for Industrial Cyber–Physical Systems
Verfasserangaben:Julian GöppertStaff MemberORCiD, Axel SikoraStaff MemberORCiDGND
Erscheinungsjahr:2025
Datum der Erstveröffentlichung:16.10.2025
Verlag:IEEE
Erste Seite:349
Letzte Seite:352
Titel des übergeordneten Werkes (Englisch):IEEE Embedded Systems Letters
Jahrgang (Band):17
Heft (Ausgabe):5
ISSN:1943-0663 (Print)
ISSN:1943-0671 (Elektronisch)
DOI:https://doi.org/10.1109/LES.2025.3598202
Sprache:Englisch
Inhaltliche Informationen
Fakultäten / Einrichtungen:Fakultät Elektrotechnik, Medizintechnik und Informatik (EMI) (ab 04/2019)
Forschung:ivESK - Institut für verlässliche Embedded Systems und Kommunikationselektronik
Sammlungen der Hochschule Offenburg:Bibliografie
Freies Schlagwort / Tag:Communication; credential management; cyber- security; proverif; public key certificates
Gefördert durch (Auswahl):Bundesministerium für Wirtschaft und Energie
Formale Angaben
Relevanz für "Jahresbericht über Forschungsleistungen":5-fach | Wiss. Zeitschriftenartikel reviewed: AGQ-Positivlisten
Open-Access-Status: Closed 
Lizenz (Deutsch):License LogoUrheberrechtlich geschützt