首页> 外文会议>International Symposium on Systems Engineering >An Architecture-based Modeling Approach Using Data Flows for Zone Concepts in Industry 4.0
【24h】

An Architecture-based Modeling Approach Using Data Flows for Zone Concepts in Industry 4.0

机译:一种基于架构的建筑建模方法,使用行业中的区域概念进行数据流4.0

获取原文

摘要

Smart factories in Industry 4.0 (I4.0) offer economic advantages that base on the universal integration of the associated value chain. Within it, IT relies on new and complex technologies like cyber-physical systems (CPS), that integrate hardware and software with new sensor and communication capabilities. Hence, such production systems become more vulnerable against malicious attacks due to bigger attack surfaces. Therefore, it is essential to address security as early as possible, i.e. during design process (Security by Design). In order to support security risk assessments during the design process, the standard IEC 62443 recommends to define zones addressing multiple security levels instead of using one security level for the complete factory. General ideas, rules and guidelines to define a cybersecurity zone concept are sufficiently described. However, approaches that allow both the model-based system design of industrial automation and control systems (IACS) and the zones, taking into account data flows, represent a gap in this research area. Our approach closes this gap by supporting the modeling of zones and taking explicitly defined data flows into account in a model-based system engineering tool that we created ourselves. To this, we present our domain-specific language (DSL), which meets the basic requirements of IEC 62443, and propose a methodology that takes into account the data flow between zones. The applicability of the approach is validated with means of a fictitious smart factory use case.
机译:工业中的智能工厂4.0(i4.0)提供了基于相关价值链的普遍集成的经济优势。在其中,它依赖于网络 - 物理系统(CPS)等新的和复杂技术,该技术与新的传感器和通信功能集成了硬件和软件。因此,由于更大的攻击表面,这种生产系统变得更容易受到恶意攻击的影响。因此,必须尽早解决安全性,即在设计过程中(设计安全)。为了在设计过程中支持安全风险评估,标准IEC 62443建议定义寻址多个安全级别的区域,而不是使用完整工厂的一个安全级别。定义网络安全区概念的一般思想,规则和指导方针被充分描述。然而,考虑到数据流的工业自动化和控制系统(IACS)和区域的基于模型的系统设计的方法代表了该研究区域的差距。我们的方法通过支持区域的建模并在我们创建自己的基于模型的系统工程工具中考虑明确定义的数据流来关闭这种差距。为此,我们介绍了我们的域名语言(DSL),它符合IEC 62443的基本要求,并提出了一种考虑到区域之间的数据流的方法。该方法的适用性通过虚拟智能工厂用例验证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号