Securing IIoT using Defence-in-Depth: Towards an End-to-End Secure Industry 4.0
Aintzane Mosteiro-Sanchez, Marc Barcelo, Jasone Astorga, Aitor Urbieta

TL;DR
This paper analyzes security strategies for Industry 4.0, emphasizing Defence-in-Depth, and proposes an integrated approach combining DiD, Attribute-Based-Encryption, and OSCORE for end-to-end security in IIoT networks.
Contribution
It introduces a novel combination of security layers and encryption methods tailored for lightweight, end-to-end protection in Industry 4.0 environments.
Findings
Analysis of current security strategies in Industry 4.0
Proposal of an integrated security framework combining DiD, ABE, and OSCORE
Foundation for developing lightweight, end-to-end security solutions
Abstract
Industry 4.0 uses a subset of the IoT, named Industrial IoT (IIoT), to achieve connectivity, interoperability, and decentralization. The deployment of industrial networks rarely considers security by design, but this becomes imperative in smart manufacturing as connectivity increases. The combination of OT and IT infrastructures in Industry 4.0 adds new security threats beyond those of traditional industrial networks. Defence-in-Depth (DiD) strategies tackle the complexity of this problem by providing multiple defense layers, each of these focusing on a particular set of threats. Additionally, the strict requirements of IIoT networks demand lightweight encryption algorithms. Nevertheless, these ciphers must provide E2E (End-to-End) security, as data passes through intermediate entities or middleboxes before reaching their destination. If compromised, middleboxes could expose vulnerable…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
