Increasing numbers of cyberattacks and stringent regulations necessitate cryptographic protection for field-level communication in Industrial Internet of Things (IIoT) networks. This requires device-specific credentials, comprising a private key, a public key certificate, a trust anchor, and optional authorization attributes for IIoT components. This paper proposes a generic and protocol-independent credential management model spanning the entire lifecycle of IIoT components, from manufacturing to disposal. The model’s novel contributions include: (1) a credentialing entity orchestrating secure credential provisioning, renewal, and revocation, (2) dedicated control domain credentials enabling mutual authentication and authorization, and (3) lifecycle-oriented processes ensuring scalability and automation. These features bridge Information Technology (IT) and Operational Technology (OT) environments, satisfy security requirements (e.g., origin verification, protected initial credential provisioning, mutually authenticated and authorized subsequent credential management), and support resource-constrained systems. This enables secure and scalable credential management for diverse IIoT protocols and contextualizes existing approaches, enhancing trust and manageability in IIoT environments. The model is validated with a physical CANopen-FD-specific implementation, proving the feasibility for IIoT networks lacking native credential management. Formal security analysis using ProVerif proves robustness against impersonation, unauthorized access, and man-in-the-middle attacks under a Dolev-Yao adversary, addressing the lack of formal verification in existing standards.
Göppert et al. (Thu,) studied this question.