← Home

IEC 62443-3-1 Clause 5.4 – Physical/Token Authentication

Teaching note: Paraphrased from IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007) for learning. The technical report is informational, not a requirements standard. Confirm wording in the published TR. Later normative parts (2-1, 3-3, 4-2) state the shalls.

Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 5.4
Related: Clause 5 | 5.5 Smart cards | 10.1 Physical protection | MFA

Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10

Clause 5 pages: Cl. 5 | 5.1 RBAC | 5.2 Password | 5.3 Challenge/response | 5.4 Token | 5.5 Smart card | 5.6 Biometric | 5.7 Location | 5.8 Password management | 5.9 Device-to-device


What it is

Something you have: access card, dongle, USB token or similar physical token presented to a reader or host.


Vulnerabilities addressed

Guessable passwords and shared console logins. A token raises the bar for walk-up use of an engineering station or HMI.


Typical deployment

Door access and/or computer login. In a control room that is already physically controlled, the card alone may enable control actions after the person has been admitted.


Known issues and weaknesses


Use in IACS

The TR judged physical/token authentication as having a strong potential role in IACS, especially combined with a PIN or password.


Recommendations