WP 6 Security in Automation Systems      

  WP 6 Security in Automation Systems
Due to the growing usage of open communication technologies and protocols and due to the open system architecture, the security of automation systems becomes an important item.

Using the advantage of office-based technologies implies also the disadvantages in the area of security. In the industrial automation field the security problems are not losing a file but may result in the damage of machines or plants with severe impact of commercial loss.

Also, the security mechanism from the office environment cannot be transferred 1:1 to the specific industrial communication needs with its focus on real time requirements, cyclic data transfer and integration into embedded devices. A definition and implementation of mechanisms to guarantee bug-proofed, secure and intrusion protected data transfer over wired and wireless networks in industrial environments has been targeted in this WP.

Achievements and Results

This work package has had a continuous influence on the whole project and has integrated into the design phases substantial building blocks and considerations.

The following aspects are especially worth to be mentioned:
  • Overall process model applied for maximum transparency
  • Secure transport of fieldbus data with minimum timing influence (cascaded VPN tunnels, supported by VAN routing and QoS mapping)
  • Distributed access control engine
  • Integration of public key infrastructures for runtime and VAN data
  • Packet filter and IDS additions


Work package 6 Security in automation systems
Task 6.1 Status and analysis
Task 6.2 Security mechanisms for automation
Task 6.3 Specification of a Security Layer
Task 6.4 Prototype Implementations
Task 6.5 Validation of Prototype Implementations


Delivery date Deliverable
Feb, 2006 Status and Analysis Report on security mechanisms and security infrastructures
Aug, 2007 Definition of Security mechanisms in industrial environments addressed by VAN; catalogue of attack scenarios
Feb, 2008 Service definition and protocol (functional) specification of a security layer.
Jun, 2008 Security mechanisms prototype implementation.
Sep, 2008 Test report.