← Home

IEC 62443-3-1 Clause 7.2 – Public Key Encryption and Key Distribution

Teaching note: Paraphrased from IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007) for learning. The technical report is informational, not a requirements standard. Confirm wording in the published TR. Later normative parts (2-1, 3-3, 4-2) state the shalls.

Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 7.2
Related: Clause 7 | Public Key Infrastructure (PKI) | Digital Certificates | SR 1.8 PKI certificates | SR 1.9 Public key authentication

Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10

Clause 7 pages: Cl. 7 | 7.1 Symmetric key | 7.2 Public key | 7.3 VPN


What it is

Asymmetric (public-key) algorithms use a key pair: a public key that may be shared and a private key that must not. They support encryption, digital signatures and authenticated key exchange. A Public Key Infrastructure (PKI) issues, renews and revokes certificates that bind a public key to an identity.


Vulnerabilities addressed

Secret-key distribution over untrusted paths; spoofed identities; repudiation of signed engineering changes when signatures are used correctly.


Typical deployment

TLS/IPsec handshake, code or configuration signing, device identity certificates, and plant or enterprise CAs. Isolated OT networks can run a local or offline CA.


Known issues and weaknesses


Use in IACS

Justify PKI for the trust domain (users, engineering stations, servers, selected devices), not for every serial instrument. Teaching note: certificates are now common on OT VPNs and some controllers; the TR’s lifecycle warning remains the failure mode.


Recommendations