Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 7.2
Related:
Clause 7
|
Public Key Infrastructure (PKI)
|
Digital Certificates
|
SR 1.8 PKI certificates
|
SR 1.9 Public key authentication
Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10
Clause 7 pages: Cl. 7 | 7.1 Symmetric key | 7.2 Public key | 7.3 VPN
Asymmetric (public-key) algorithms use a key pair: a public key that may be shared and a private key that must not. They support encryption, digital signatures and authenticated key exchange. A Public Key Infrastructure (PKI) issues, renews and revokes certificates that bind a public key to an identity.
Secret-key distribution over untrusted paths; spoofed identities; repudiation of signed engineering changes when signatures are used correctly.
TLS/IPsec handshake, code or configuration signing, device identity certificates, and plant or enterprise CAs. Isolated OT networks can run a local or offline CA.
Justify PKI for the trust domain (users, engineering stations, servers, selected devices), not for every serial instrument. Teaching note: certificates are now common on OT VPNs and some controllers; the TR’s lifecycle warning remains the failure mode.