Industrial Cybersecurity Pulse
  • SUBSCRIBE
  • Threats & Vulnerabilities
  • Strategies
  • IIoT & Cloud
  • Education
  • Networks
  • IT/OT
  • Facilities
  • Regulations
  • Threats & Vulnerabilities
  • Strategies
  • IIoT & Cloud
  • Education
  • Networks
  • IT/OT
  • Facilities
  • Regulations
  • Resources
  • Helpful Links
  • Editorial Calendar
  • Advertise
  • Contribute
  • Content Partners
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
SUBSCRIBE
  • Resources
  • Helpful Links
  • Editorial Calendar
  • Advertise
  • Contribute
Industrial Cybersecurity Pulse
Subscribe
Industrial Cybersecurity Pulse
  • Threats & Vulnerabilities
  • Strategies
  • IIoT & Cloud
  • Education
  • Networks
  • IT/OT
  • Facilities
  • Regulations
  • IIoT & Cloud

Increasing smart factory cybersecurity using a trusted execution environment

  • Lauren Thompson
  • June 10, 2022
Courtesy: CFE Media
Courtesy: CFE Media
Total
0
Shares
0
0
0
0

As the manufacturing industry adopts digitized operations and the industrial internet of things (IIoT), sensitive data and online systems become increasingly vulnerable to theft and manipulation. SecureAmerica Institute (SAI) partners at The University of Texas at Dallas (UT Dallas) are building a trusted execution environment to thwart bad actors and enable end-to-end data protection in smart manufacturing environments as part of SAI’s nationwide initiative to empower a secure domestic manufacturing base.

With the rise of the IIoT (interconnected sensors, instruments and other devices networked together through computer applications), smart factories are using IIoT technology to automate and monitor manufacturing processes and controlling these processes using networks or web interfaces outside of the workplace. As this control moves from analog to digital, it becomes more vulnerable to attacks.

Think of this process like unlocking a door. Physical locks require keys for access, but with smart manufacturing technology, doors to online systems and data can be unlocked by simply using a smartphone. This is why both hardware and software protection are needed.

“Our project focuses on protecting data generated by IIoT devices so attackers cannot eavesdrop on or steal data from smart factories or manipulate smart manufacturing processes,” said Dr. Chung Hwan Kim, assistant professor in UT Dallas’s department of computer science.

Bad actors may try to extract data from a manufacturing entity to form an attack that targets specific components of a system or process. Once sensitive data is collected, an attack is deployed through a compromised cloud network or unauthorized network access.

A well-executed attack could have catastrophic ramifications for U.S. national security. For example, if the targeted industrial base is a nuclear factory, attackers may attempt to destroy the power plant or take control of operations. But if data and machine communications are routed through a trusted execution environment, the security around it becomes much more difficult to penetrate.

“With the recent advancement of hardware technologies, we can actually create a black box within each IIoT device,” Kim said. “We then place our hardware, or trusted execution environment, within the device. This program is invisible from outside detection. Any new data generated by IIoT technology will go into this black box, and is transferred to a different location before going to the cloud.”

The UT Dallas team has already produced two different prototypes of their trusted execution environment with plans to keep expanding the project.

“The entire lifetime of sensor data can be placed into the black box using this hardware technology,” Kim continued. “The necessary program code will then run in the black box so manufacturers can safely use the protected sensor data.”

“IIoT devices are becoming prolific as low-cost distributed data sources to support the modern digital manufacturing enterprise. These devices often rely on small, low-cost computing without robust security,” said Dr. Darrell Wallace, SAI deputy director and chief technology officer. “This project offers an end-to-end data protection approach that enhances the security of these devices and serves the SAI mission to enhance the robustness of domestic manufacturing.”

Original content can be found at Texas A&M University.

Do you have experience and expertise with the topics mentioned in this article? You should consider contributing content to our CFE Media editorial team and getting the recognition you and your company deserve. Click here to start this process.

Lauren Thompson

Lauren Thompson is a contributor to Texas A&M Engineering news.

Related Topics
  • CFE Content
  • Featured
Previous Article
  • Strategies

New approach allows for faster ransomware detection

  • Matt Shipman
  • June 7, 2022
Read More
Next Article
A good cybersecurity program is focused on threat detection, incident response and vulnerability management. Courtesy: Chris Vavra, CFE Media and Technology
  • Strategies

Smart manufacturing needs smart security, communication

  • Chris Vavra
  • June 13, 2022
Read More
You May Also Like
Read More

How a desert water utility helped protect critical infrastructure

A robot powered by OSARO’s machine learning system picks consumer goods. Courtesy: A3/OSARO
Read More

Industrial robot utilization requires cybersecurity strategy

Courtesy: Brett Sayles
Read More

Throwback attack: Russia launches its first cyberattack on the U.S. with Moonlight Maze

Read More

Throwback attack: Russia breaches Wolf Creek Nuclear Power facility

Courtesy: CFE Media and Technology
Read More

Lack of qualified cybersecurity personnel for critical infrastructure

Figure 1: PLCs, HMIs, and other Ethernet-capable automation devices used for modern automation systems can no longer rely on “cybersecurity by obscurity” and “air gaps.” They must progressively adopt advanced IT type security features. Courtesy: AutomationDirect
Read More

Cybersecurity-centered systems and fundamentals

Read More

Port and maritime cybersecurity vulnerabilities are getting more focus

Figure 1: For smaller organizations with limited network resources, it can be tempting to plug your machine directly into the business network. Courtesy: DMC
Read More

Securing your facility

SUBSCRIBE

GET ON THE BEAT

Keep your finger on the pulse of top industry news

SUBSCRIBE TODAY!
VULNERABILITY PULSE
  • Mitsubishi Electric - June 14, 2022
  • Meridian Cooperative - June 14, 2022
  • Johnson Controls - June 14, 2022
  • Microsoft - June 14, 2022
  • Citrix - June 14, 2022

RECENT NEWS

  • Protecting the power grid through cyber-physical threat response
  • How to secure Industry 4.0 in a highly connected world
  • Managing external connections to your operational technology (OT) environment
  • Webcast: Addressing Cybersecurity Challenges in Industry 4.0
  • How a desert water utility helped protect critical infrastructure

EDUCATION BEAT

Introduction to Cybersecurity within Cyber-Physical Systems

Cyber-physical systems serve as the foundation and the invention base of the modern society making them critical to both government and business.

REGISTER NOW!
HACKS & ATTACKS
  • Ron Brash Interview: Expert advice on finding the root of the ransomware problem
  • Throwback Attack: How the modest Bowman Avenue Dam became the target of Iranian hackers
  • Minimizing the REvil impact delivered via Kaseya servers
  • Key takeaways from 2020 ICS-CERT vulnerabilities
Industrial Cybersecurity Pulse

Copyright 2022 CFE Media and Technology.
All rights reserved.


BETA

Version 1.0

  • Content Partners
  • Contact Us
  • Privacy Policy
  • Terms and Conditions

Input your search keywords and press Enter.

By using this website, you agree to our use of cookies. This may include personalization of content and ads, and traffic analytics. Review our Privacy Policy for more information. ACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT