Advanced search
Start date
Betweenand


A Secure IIoT Gateway Architecture based on Trusted Execution Environments

Full text
Author(s):
Froehlich, Antonio Augusto ; Horstmann, Leonardo Passig ; Hoffmann, Jose Luis Conradi
Total Authors: 3
Document type: Journal article
Source: Journal of Network and Systems Management; v. 31, n. 2, p. 30-pg., 2023-04-01.
Abstract

Industrial Internet of Things (IIoT) gateways are affected by many cybersecurity threats, compromising their security and dependability. These gateways usually represent single points of failure on the IIoT infrastructure. When compromised, they can disrupt the entire system, including the security of the IIoT devices and the confidentiality and privacy of the data. This paper introduces a Secure IIoT Gateway Architecture that encompasses Trusted Execution Environment concepts and consolidated security algorithms to achieve a secure IIoT environment. Sensitive procedures of the IIoT, like device admission, bootstrapping, key management, authentication, and data exchange among operational technology (OT) and information technology (IT) are handled by the gateway inside the secure execution domain. The bootstrapping does not require devices to have any pre-stored secret or a pre-established secure channel to any trusted third party. Moreover, our architecture includes mechanisms for IIoT devices to safely interact with the Cloud without assuming the integrity of the gateways between them, enabling continuous verification of gateway integrity. A formal proof of the proposed solution security is provided. Finally, the security of the proposed architecture is discussed according to the specified requirements. (AU)

FAPESP's process: 21/02384-7 - Development of an integrity checking protocol and a Gateway IIoT implementation based on a Trusted Execution Environment (TEE)
Grantee:José Luis Conradi Hoffmann
Support Opportunities: Scholarships in Brazil - Technical Training Program - Technical Training
FAPESP's process: 20/05142-1 - Secure industrial IoT gateway
Grantee:Antônio Augusto Medeiros Fröhlich
Support Opportunities: Research Grants - Research Partnership for Technological Innovation - PITE
FAPESP's process: 21/02385-3 - Machine Learning and Performance Monitoring for Integrity Checking in IIoT Gateways
Grantee:Leonardo Passig Horstmann
Support Opportunities: Scholarships in Brazil - Technical Training Program - Technical Training