Security concerns become increasingly important in safety-critical industrial cyberphysical systems. Different options for security certification exist. We describe a Common Criteria certification for a MILS separation kernel, and IEC 62443 analysis and certifications for the smart grid, railway and subway pilots using the MILS approach in the research project certMILS.
We describe compositional architectures and certifications in the research project certMILS. Compositional architectures enable re-use of certified COTS (commercial off-the-shelf) components with a well-defined delegation of responsibilities between component developers and system integrators during cyber physical system design and certification. We show how we used a Common Criteria certified MILS (Multiple Independent Levels of Safety / Security) platform for compositional designs and IEC 62443-4-1/62443-4-2 security evaluations and certifications for composed systems from the domains of smart grid, railway, and subway, that are safety- and security-critical.
In this paper, we analyze the state of the art in distributed ledger technologies and blockchains and investigate potential applications in the Internet of Things (IoT) domain. Afterwards, we discuss interoperability of blockchains, and their use in smart contracts, and artificial intelligence.
The secure integration of model-based, safety-critical applications implemented in the programming suite Ansys SCADE is explained with the help of a demonstrator. The interoperability between the embedded devices of the demonstrator is achieved using the new TRDP middleware. Remote connections are secured using the Wire-Guard secure network channel. The demonstrator security concept addresses the different life cycles of its heterogeneous components by adoption of the robust MILS separation architecture. The goal of this open demonstrator is to show how these essential technologies can be composed to a secure safety-critical system.
Tracking of goods, containers, and vehicles in harbors is a challenging task because seaports typically are in a secluded area with limited networking capability. Existing solutions use the combination of RFID tagging and Wireless Sensor Networks (WSN). A harbor is considered a harsh industrial environment with metallic components and surfaces. These conditions influence the wireless networking performance. In addition, harbors' areas vary from 500 ha to 7500 ha. Hence, the coverage range of wireless systems and the exposition to interference are considered. LoRa (Long Range) technology becomes a promising solution among other Low Power Wide Area Networks (LPWAN). Therefore, we investigate the LoRa technology to locate and track assets in harbors. Through ns-3 simulations on scalability, interval rate, and coverage range performance metrics, we evaluated the feasibility to use LoRa in seaports. In our experiments, we applied 1000 LoRa nodes within a radius of 2500 m to the gateway. The results exhibit a probability of successful transmission of 85% in an interval of 300 sec.
Security and cryptography protocols are seen by many as black-magic, largely due to their complex mathematical algorithms and entangled state-machines. This complexity has also led to numerous vulnerabilities in past years. Recent developments have simplified conformance requirements, and also introduced formal proofs to mainstream security protocols. In this work-in-progress publication we discuss, how this evolution has greatly improved the situation for critical systems, and how the architecture of MILS systems can raise the confidence for high-assurance systems. Keywords—security, formal modeling, safety critical systems, CPS I. SECURITY IN CRITICAL SYSTEMS Critical systems are required to be reliable, available, maintainable and safe according to accepted and governing standards, e.g., EN 50126 in the railway domain. These attributes are a result of qualified processes and guided methods, requiring specially trained engineers, operators and maintainers to minimize application risks. The processes specifically require that access is limited to that qualified and authorized group to assure the integrity of the processes and the system (product). Physical access barriers, e.g., locked doors, typically have a constant ratio between cost of securing and effort to bypass, largely due to the required physical attendance of the intruder with the specific knowledge to that barrier. The introduction of electronic and networked access to critical systems as Cyber-Physical Systems (CPS), in principle, has not changed this paradigm, but removed the latter physical appearance of an intruder. This has introduced negative scaling effects making even well secured systems with only a small security vulnerability cheap for large scale attacks. The current mitigation trend in IT systems is to automate and improve testing methods, and to shorten time to update, i.e., patch vulnerabilities. In contrast, critical systems have stricter update policies and typically run on non-standardized hardware. As a consequence, testing requires more effort for a much smaller number of operative products. Modifying a critical system’s software requires re-certification – even if it is "just" a security update. Current research is developing methodologies to reduce the fore-said re-certification effort through dependable partitioning of a system, applying the Multiple Independent Levels of Security (MILS) architecture (Fig. 1). For example, the system design could split the application into a safe control component and an independent transmission component with security functions, such as remote authorization, authentication and encryption. The safety function within the control application would be independent of corruptions within the transmission component, if it can continue operation in degraded mode without transmission data. The data flow between the components is guarded by the MILS separation kernel, allowing only predefined data flows between the two domains. Depending on attack vectors, system and application design, the security relevant transmission component could then also be of lower confidence level and classified with a low Software Safety Integrity Level (SSIL), being less susceptible to re-certification requirements. A MILS system is composed of components. For the system to perform a critical safety function, it needs evaluation and certification to standards required by governmental authorities. As mentioned before, evaluation for security of a composed system of apriori certified components, requires special methodologies. Furgel et.al. [1] present the methodology for "Non-Interfering Composed Evaluation" within Common Criteria. The key requirement for non-interference is that the execution of one component does not undermine another component’s security policy. For the general case, this demands that all internal states of a component are well defined and well known at any time, as well as all implicit and explicit interfaces between components are clearly defined and accurately described. For a component to demonstrate the adequate evidence for evaluation, this either requires formal methods / proofs or exhaustive testing, including robustness testing.
High assurance Cyber-Physical Systems (CPS) are the supporting pillars of the critical infrastructure. They support the power grid, the water supply, transportation systems and many other devices, where failure or undefined behaviour lead to risk for loss of life, danger to the environment and defective operational safety of production. Rigorous testing practices have assured reliable behaviour even for failure scenarios in their predictable environments. However, previously isolated systems have become connected to the Internet and expose an attack surface that is hard to predict. While the safety of high assurance CPS is well tested with a controlled residual risk, security risks will rise throughout the deployment of a system. Hence, this paper describes research for a testing methodology to tackle emerging threats and preserve certified security assurance.
Complex safety-critical devices require dependable communication. Dependability includes confidentiality and integrity as much as safety. Encrypting gateways with demilitarized zones, Multiple Independent Levels of Security architectures and the infamous Air Gap are diverse integration patterns for safety-critical infrastructure. Though resource restricted embedded safety devices still lack simple, certifiable, and efficient cryptography implementations. Following the recommended formal methods approach for safety-critical devices, we have implemented proven cryptography algorithms in the qualified model based language Scade as the Safety Leveraged Implementation of Data Encryption (SLIDE) library. Optimization for the synchronous dataflow language is discussed in the paper. The implementation for public-key based encryption and authentication is evaluated for real-world performance. The feasibility is shown by execution time benchmarks on an industrial safety microcontroller platform running a train control safety application.
Bluetooth Low Energy Beacons currently provide a great potential for indoor localization to users with smart devices. This paper implements a security concept to mitigate weaknesses of current beacon concepts against forgery and request tracking. The method authenticates beacons with dynamic data by attaching secure signatures. The architecture is especially useful as a many-to-many solution. A test setup shows applicability in a public transportation vehicle to accompany the passenger information system and traveller route planning. A setup on a tram equipped with up to five beacons provided securely authenticated passenger guidance in and around the tram, referencing even a user's device in a pocket.
The Speed and Distance Monitoring (SaDM) in a train control system is a cyber physical system, which constantly has to process information about the train and its environment. The specification of such systems, however, is often done in an informal way, hindering formal analysis and optimization. In this paper, we propose to use Parametric Synchronous Dataflow Graphs (PSDF) to formally specify the SaDM. For this purpose, the information about the environment is modeled via piecewise constant functions, where each discontinuity corresponds to a physical location. As the number of relevant locations depends on the actual track side and, thus, is unknown a priori, we use parameters to construct consistent PSDF models. Based on our formal model, we have implemented the SaDM using SCADE.
Increasingly efficient vehicle power supplies foster the development of automotive transmissions, which use electromechanical actuators for activating the clutch and changing the gears. Known solutions are classified and evaluated. Two electromechanically actuated transmission applications are presented: a load-shiftable, 2-speed drive for electric vehicles and a 4-speed hybrid double clutch transmission. Both transmissions use the same electromechanically actuated multi-disc brakes which control the flow of power through a planetary gear by braking the ring gear.
In many application areas, robots most suitably employ classical PID controllers and the like. In the field of autonomous mobile robots, however, further adaptation features are required in order to adapt to dynamically changing environmental conditions. In recent contests, the particular research area of soccer-playing robots, called RoboCup, has observed the emergence of omnidirectional driven robots. Such drives consist of three independently controllable motors with which a robot can simultaneously perform both translational movements and rotations, which yield a significant advantage in soccer games. This paper describes how a Kohonen-feature-map-based neural network is able to learn the required capabilities and how to adapt to changing environmental conditions.