VLDB 2026 Research / reviewers in the wild / expert
Wolfgang Kastner
dblp:05/6873
· DBLP profile ↗
128ranked-venue papers
4as first author
59since 2021 · last 2026
0000-0001-5420-404XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 106 · 3 first-author · 48 since 2021Applied, interdisciplinary, general and emerging computing · 17 · 1 first-author · 13 since 2021Security and privacy · 13 · 5 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Computer networks · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Web of Things-Driven On-Device Automation for Resource-Constrained Energy Devices
Leonhard Esterbauer, Max Thoma, Tobias Schwarzinger, Thomas I. Strasser, Wolfgang Kastner |
ICWE | 5 |
| 2025 | Trustworthy AI for Security Decision-Making in ICSs: Towards Compliance with the EU AI ActabstractIn Industrial Control Systems (ICSs), security is not a fancy add-on feature but a core requirement for functionality, safe operation, and organization business. To keep up with the ever-growing threat landscape and numerous security standards and regulations, leveraging Artificial Intelligence (AI) capabilities, especially Large Language Models (LLMs), seems essential. However, AI systems built using LLMs can introduce new challenges such as data leakage, generating bias and misinformation, and even new security threats. In this paper, we analyze an AI system that leverages LLMs and knowledge graphs to support security decisions in the design of ICSs, ensuring compliance with the IEC 62443-3-3 standard while aligning with the European AI Act to guarantee trustworthiness and meet legal requirements for use in Europe. Ali Mohammad Hosseini, Thilo Sauter, Wolfgang Kastner |
ETFA | 3 |
| 2025 | Ontology Framework Supporting Security-By-Design of Industrial Control SystemsabstractEnsuring cybersecurity in Industrial Control Systems (ICSs) is essential, as cyber-attacks can lead to substantial economic losses and serious safety hazards. Addressing security early in the product and system life cycle is crucial to preventing expensive fixes and severe consequences later. Since requirements engineering and system architecture design are early activities in system development and are interconnected in nature, it is essential to begin integrating security into these activities. IEC 62443 is a widely used ICS cybersecurity standard that provides security requirements and architectural guidance; however, it relies heavily on human experts and manual effort, making the implementation of the standard costly and time-consuming. This article proposes an ontological framework that supports the integrated engineering of security requirements and system architectures, aiming to achieve security by design and conformance with IEC 62443 with reduced reliance on human experts. To evaluate the quality and usability of the proposed ontology, we examine a use case for requirements elicitation and validation scenarios. The findings highlight the potential of ontological approaches in improving ICS cybersecurity, particularly in terms of standard compliance. Ali Mohammad Hosseini, Wolfgang Kastner, Thilo Sauter |
IEEE Trans. Ind. Informatics | 2 |
| 2024 | Modeling Human Error Factors with Security Incidents in Industrial Control Systems: A Bayesian Belief Network ApproachabstractIndustrial Control Systems (ICSs) are critical in automating and controlling industrial processes. Human errors within ICSs can significantly impact the system’s underlying processes and users’ safety. Thus, it is essential to understand the factors contributing to human errors and implement targeted interventions. Various factors that influence and mitigate human errors must be explored, including organizational, supervisory, personal, and technical factors. In parallel, the impact of a security incident also needs consideration. The paper presents a Bayesian Belief Network (BBN) model developed to model these factors comprehensively and demonstrate their impact, especially in the context of security incidents. Probability distributions are employed with practical assumptions to overcome data limitations, emphasizing the model’s utility in risk assessment. The model’s complexity is addressed using multiple interconnected sub-models, enhancing accuracy and avoiding unnecessary intricacies. Despite challenges in identifying all relevant factors, a sincere effort is made to incorporate diverse research findings. This paper highlights the essential role of BBN models in understanding and mitigating human errors, contributing to the resilience of ICS processes. The use of BBN and probabilistic distributions enables quantitative and probabilistic analysis of the impact of human errors, aiding in developing more robust risk management strategies to improve system resilience in ICSs. Pushparaj Bhosale, Wolfgang Kastner, Thilo Sauter |
ARES | 2 |
| 2024 | Integrated Safety and Security by Design in the IT/OT Convergence of Industrial Systems: A Graph-Based ApproachabstractThe convergence of Information Technology (IT) and Operational Technology (OT) in Industry 4.0 poses fresh challenges, demanding innovative strategies to ensure the safe execution of production processes. With the increasing significance of production system integrity, any security breaches can lead to severe consequences like production downtime, equipment damage, or human harm. Our prior research on Austrian industrial automation stakeholders highlighted the necessity for a cost-effective, all-encompassing approach to the integrated safety and security. We introduced an extensive ontology for safety, security, and operational requirements in IT/OT convergence. This paper presents an approach of Model-Based Systems Engineering (MBSE) for the integrated safety and security by design of industrial systems. We employ the Systems Modeling Language (SysML) 2.0 for precise modeling. We define metadata information that are used as tags for SysML 2.0 model instances. Afterwards, we create a graph-based model of the system. These graphs are used to validate safety and security standards and requirements. Finally, we automatically generate artifacts, such as code or documentation, which adhere to the standards. Our approach is extensible and supports reusability already after covering two standards. Having provided support for the standards IEC 62443-3-3 and IEC 61508, we reuse our approach to validate the standard ISO 13850:2015. Amirali Amiri, Gernot Steindl, Ian Gorton, Siegfried Hollerer, Wolfgang Kastner, Thilo Sauter |
SSE | 5 |
| 2024 | Model-Based Systems Engineering for the Agile Life-Cycle Management of IIoT Based on DevOpsabstractThe domain of Industrial Internet of Things (IIoT) contains a vast variety of standards, protocols, tool suites, coding languages, etc. The Reference Architecture Model Industry (RAMI) 4.0 provides an abstraction of the different views involved in designing IIoT systems. However, the life-cycle model of the reference architecture suggests a progression from the development into production. This progression does not conform well with the best practices of software engineering, e.g., DevOps, where runtime data is given back to the design-time. In this paper, we suggest an agile life-cycle management of the IIoT systems, and propose an approach of Model-Based Systems Engineering (MBSE) based on the System Modeling Language (SysML) 2.0. We define metadata in the domain of event-driven IIoT systems. Architects can create tagged model instances, which are automatically validated against system requirements. The validated models are passed to an artifact generator to create code, test cases, or documentation. Our approach assists in the development and commissioning of system assets. We feed the runtime data to design-time to improve the quality of service. Amirali Amiri, Gernot Steindl, Wolfgang Kastner |
ETFA | 3 |
| 2024 | IT Security Solutions for IT/OT Integration: Identifying Gaps and OpportunitiesabstractIn the contemporary landscape of convergence between Information Technology (IT) and Operational Technology (OT), maintaining asset visibility within the Industrial Control Systems (ICS) infrastructure is paramount. Yet, the escalating targeting of legacy systems and air-gapped networks by cyber threats underscores the need for robust security measures and solutions to counter unauthorized access and malicious activities. This paper presents an analysis aimed at identifying gaps and opportunities in integrating IT Security Solutions with OT environments. These solutions offer comprehensive features such as real-time threat detection, asset identification, network monitoring, and incident response capabilities tailored specifically for the unique challenges posed by industrial control networks. Leveraging the Festo MPS 403–1 system as a case study, we delve into the intricacies of IT/ OT integration and highlight areas necessitating improvement to achieve seamless convergence and harness the advantages of unified systems across industries. Mukund Bhole, Wolfgang Kastner, Thilo Sauter |
ETFA | 2 |
| 2024 | Towards Unveiling Vulnerabilities and Securing IoT Devices: An Ontology-Based ApproachabstractIn the rapidly expanding landscape of Internet of Things (IoT), sensors have emerged as pivotal components, playing a critical role in sensing and data collection. However, this crucial function also renders them susceptible to potential threats such as unauthorized access and security breaches. This paper investigates the vulnerabilities that lead to these threats and offers a comprehensive set of best practices aimed at fortifying the security of IoT devices. We highlight key measures such as secure device design, robust authentication mechanisms, encrypted communication protocols, regular updates, and emphasize the importance of collaborative efforts among stakeholders using an ontological approach. An Ontology provides a structured framework for organizing knowledge, facilitating clearer communication, efficient data management, and enhanced decision-making. Thus, this paper contributes to the development of a more secure and resilient IoT ecosystem. Mukund Bhole, Wolfgang Kastner, Thilo Sauter |
ETFA | 2 |
| 2024 | Comparative Analysis of AAS and AML as a Data Source for Integrated Risk Assessment in ICSabstractIntegrated risk assessment is important to identify, evaluate, and mitigate potential risks in Industrial Control Systems (ICS). It is necessary for safety and security within the organization. The safety and security data necessary for integrated risk assessment are obtained from various data sources that structure and manage information. In this paper, we look into information models as a potential single source of data. We compare different information models: Asset Administration Shell (AAS) and Automation Markup Language (AML). The comparison highlights the strengths and weaknesses, commonalities and differences of each data source in terms of data integration, real-time capability, standardization, design capability, automation possibility, and practical application in risk assessment processes. The findings underscore the importance of selecting appropriate data sources to enhance the accuracy, provide the possibility of updates, and enhance the efficiency of risk assessments in ICS. Pushparaj Bhosale, Wolfgang Kastner, Thilo Sauter |
ETFA | 2 |
| 2024 | Mapping ICS Vulnerabilities: Prioritization and Risk Propagation Analysis with MITRE ATT&CK Framework and Bayesian Belief NetworksabstractThe introduction of Industry 4.0 and the integration of Information Technology (IT) with Operational Technology (OT) have brought significant advancements to Industrial Control Systems (ICS). With the convergence of IT/OT, ICS not only have to counteract against faults for safety reasons, but also have to encounter new challenges stemming from the security realm with an impact on safety issues. Ensuring the security of ICS has gained importance as any breach can cause disruption in industrial processes, leading to system downtime, production loss, and endangering human lives. Vulnerability assessment has become a crucial aspect of security research in ICS. The MITRE ATT&CK framework is one of the knowledge bases used for vulnerability management. It can be used to map identified vulnerabilities to a specific tactic provided by the framework. This mapping provides organizations with a structured approach focusing on identifying potential entry points for attackers and their progression through the system. The attacker's control of ICS could lead to a safety impact on people, processes, and the environment. This paper uses the mapping as a tool to prioritize the vulnerabilities and attacker's propagation through the network and thus help in building an effective risk propagation network using the Bayesian Belief Network (BBN). The implementation of the methodology is done using a Modular Production System (MPS) as a use case. Pushparaj Bhosale, Wolfgang Kastner, Thilo Sauter |
ETFA | 2 |
| 2024 | Evaluation of an Automated Security Risk Assessment Based on a Manual ReferenceabstractThe overall Industry 4.0 developments and the highly dynamic threat landscape enhance the need for continuous security engineering of industrial components, modules, and systems. Security risk assessments play a major role to ensure a secure operation of Industrial Automation and Control Systems (IACSs) but are often neglected due to missing resources and a lack of human experts for the sophisticated manual tasks. To relieve this situation and to increase the degree of automation of security risk assessments, a method for information and process modelling was developed in a previous work. The approach was also implemented prototypically as an expert system but has not been validated, yet. This work therefore presents the validation as an integral part of the overall evaluation of the automated security risk assessment concept. For a systematic validation, a reference security risk assessment is manually defined as a set of data for the comparison with the results of the automated expert system. In addition, the two main hypotheses with regard to the result quality and the process automation evaluated. Marco Ehrlich, Georg Lukas, Lisa Gebauer, Henning Trsek, Jürgen Jasperneite, Wolfgang Kastner, Christian Diedrich |
ETFA | 6 |
| 2024 | Towards Enhancing Security of ICS: System Architecture Development using the Asset Administration ShellabstractConsidering security when designing a system is of utmost importance. Integrating security attributes during the design phase provides effective means. However, this process necessitates the collection and utilization of various types of data related to each asset, which should be collected from different sources, such as data sheets. Developing Industrial Control System (ICS) architecture, as an important activity during design time, enhances security by identifying threats, enforcing controls, enabling compliance, resilience, and monitoring through structured, layered design. Thus, this paper explores the incorporation of a Digital Twin into system architecture to improve the security of ICSs. In particular, we investigate the role of the Asset Administration Shell (AAS) as a standardized meta-model in providing necessary information for the development of secure system architectures. After identifying the information required for specific security activities, the current state of AAS and its capability to provide that information is assessed. Ali Mohammad Hosseini, Thilo Sauter, Wolfgang Kastner |
ETFA | 3 |
| 2024 | Integrating Security into Industrial Control System Architecture Based on IEC 42010abstractIndustrial Control Systems (ICS) are increasingly becoming targets for cybercriminals seeking ransom or aiming to cause disruptive chaos because of the potentially devastating impact of ICS malfunction. Following the security-by-design principle, security measures should be integrated into ICS system design as early as possible. System architecture design is one of the earliest activities in the system development life cycle that can play a key role in enhancing security. Hence, this paper proposes an architectural security framework based on IEC 42010, a standard for system architecture description, aiming at integrating security into system architecture. As part of this framework, an ontology is designed to formalize the system architecture described in SysML v2 (Systems Modelling Language version 2) to facilitate automatic reasoning about system design against specified security requirements and rules. To this end, the transformation rules from the textual notation of SysML v2 to OWL (Web Ontology Language) are specified. A use case is presented and analyzed that demonstrates the practicality of the proposed approach in adding security to the system architecture. Ali Mohammad Hosseini, Thilo Sauter, Wolfgang Kastner |
ETFA | 3 |
| 2024 | Deployment Architectures of MQTT Brokers in Event-Driven Industrial Internet of ThingsabstractThe Industrial Internet of Things (IIoT) involves various standards, protocols, and tools, requiring extensive expertise for system design. The traditional automation pyramid limits scalability due to tightly-coupled components. Integrating IIoT data in the cloud through event-driven communication, like MQTT brokers, provides loose coupling. This integration also aids in resource monitoring and planning, enhancing IIoT application performance. Despite many IIoT architecture studies, there is a lack of empirical comparisons of MQTT broker deployment strategies. This paper examines an edge-cloud aggregation scenario, where IIoT device requests are aggregated at the edge and fog services before being transmitted to the cloud. We study four MQTT deployment architectures and compare the results empirically. We use an Arduino Opta as an IIoT device. Also, we use software-based load generation to support replicability of our experiment and reproducibility of our results. Findings indicate that a central broker on a dedicated virtual machine gives 13.8% improvements of the mean response time compared to the shared deployment of MQTT broker and device gateways. Our results offer insights into effective deployment strategies. Amirali Amiri, Valentin Philipp Just, Gernot Steindl, Stefan Nastic, Wolfgang Kastner, Ian Gorton |
IECON | 5 |
| 2024 | Model-Based Systems Engineering of the Event-Driven Industrial Internet of ThingsabstractThe Industrial Internet of Things (IIoT) is characterized by a multitude of standards, protocols, and tools. Moreover, the convergence of Information Technology (IT) and Operational Technology (OT) brings new architectural styles, e.g., event-driven communication, that are easier to scale and integrate IIoT devices. Architects need extensive expertise to manage the complex task of designing systems that encompass hardware, software, information, communication, and users. Proven approaches such as Model-Based Systems Engineering (MBSE) can simplify the design of IIoT systems by offering abstractions through system models and views. In this paper, we introduce an MBSE approach grounded in Systems Modeling Language (SysML) 2.0. Our method involves defining metadata tailored to event-driven IIoT systems. System designers can generate tagged model instances that undergo automatic validation against system requirements, such as asynchronous messaging, authentication, and health checks. Following validation, these models are utilized by an artifact generator to produce code, test cases, or documentation. Our approach is designed for reusability, and we provide tool support to streamline the implementation of requirements checking for emerging standards and guidelines. This enhances the flexibility and efficiency of IIoT system design, ensuring compliance with diverse and evolving industry requirements. Amirali Amiri, Max Thoma, Gernot Steindl, Christoph Klaassen, Wolfgang Kastner |
IECON | 5 |
| 2024 | From Manual to Semi-Automated Safety and Security Requirements Engineering: Ensuring Compliance in Industry 4.0abstractIn response to the growing need for compliance with diverse safety and security regulations, crucial for safeguarding both humans and machines in the era of Industry 4.0 (I4.0), it has also become increasingly crucial for industries to ensure adherence to safety and security standards. However, navigating the complexities of regulations and standards can be daunting, often leading to inefficiencies in compliance processes. Our goal is to foster a comprehensive understanding of an effective approach to meeting compliance requirements in these related fields. Therefore, this paper introduces a semi-automated method for ensuring compliance with unified safety and security standards within the context of I4.0. This approach empowers management teams to thoroughly analyze the specific requirements necessary to maintain a protected environment. Compliance can be achieved at both the asset component and system levels, aligning with the relevant standards. Additionally, we present a detailed analysis of a use case and its output, demonstrating the practical application and efficacy of our approach. Mukund Bhole, Wolfgang Kastner, Thilo Sauter |
IECON | 2 |
| 2024 | Requirements Analysis for the Evaluation of Automated Security Risk AssessmentsabstractThe overall Industry 4.0 developments and the highly dynamic threat landscape enhance the need for continuous security engineering of industrial components, modules, and systems. Security risk assessments play a major role to ensure a secure operation of Industrial Automation and Control Systems (IACSs) but are mostly neglected due to missing resources and a lack of human experts for the sophisticated manual tasks. Therefore, a method for information and process modelling regarding the automation of security risk assessments has been previously designed, but not yet evaluated. This work in progress begins the evaluation of the automated security risk assessment concept by investigating the related work and identifying the main deficits. The results include a requirements analysis for the verification and an outlook towards future evaluation aspects. Marco Ehrlich, Georg Lukas, Henning Trsek, Jürgen Jasperneite, Wolfgang Kastner, Christian Diedrich |
WFCS | 5 |
| 2023 | Knowledge Representation of Asset Information and Performance in OT EnvironmentsabstractTo make a management decision for the Operational Technology (OT) environment, obtaining OT asset information from a plant is essential. Key Performance Indicators (KPIs) can play a crucial role in evaluating the performance of the manufacturing process, minimizing production costs, assessing process effectiveness, and investigating various settings to improve performance, operations, and quality in OT. This paper aims to provide a detailed examination of how Asset Information Mining Sources (AIMSs) support the process for acquiring both static and runtime OT asset information. Once we have obtained accurate OT asset information, we can calculate the KPIs and incorporate them into a knowledge representation using an ontology-based model. This model can assist the management team in making informed decisions and provide a roadmap for exploring further automation possibilities. Mukund Bhole, Wolfgang Kastner, Thilo Sauter |
ETFA | 2 |
| 2023 | AutomationML use for Safety and Security Risk Assessment in Industrial Control SystemsabstractThe increasing complexity and interconnectedness of Industrial Control Systems (ICSs) necessitate the integration of safety and security measures. Ensuring the protection of both personnel and critical assets has become a necessity. As a result, an integrated risk assessment approach is essential to comprehensively identify and address potential hazards and vulnerabilities. However, the data sources needed for an integrated risk assessment comes in many forms. In this context, Automation Markup Language (AutomationML or AML) emerges as a valuable solution to facilitate data exchange and integration in the risk assessment process. The benefits of utilizing AML include improved interoperability, enhanced documentation, and seamless collaboration between stakeholders. A model, filled with information relevant to integrated risk assessment, is developed to illustrate the effectiveness of AML. Ultimately, this paper showcases how AML serves as a valuable information model in meeting the growing need for comprehensive safety and security risk assessment in ICSs. Pushparaj Bhosale, Wolfgang Kastner, Thilo Sauter |
ETFA | 2 |
| 2023 | Integrated Safety-Security Risk Assessment for Industrial Control System: An Ontology-based ApproachabstractIndustrial control systems (ICSs) are critical to the operation of industrial processes and critical infrastructure. Safety and security are crucial in any system or process, particularly in ICSs where failures can lead to severe consequences such as injury, loss of life, and damage to equipment and infrastructure. However, safety and security are often considered separately during the concept and design stages. An integrated risk assessment approach can combine safety and security considerations and provide a holistic evaluation of the overall risk to ICSs. Ontology-based approaches provide a systematic and structured method for representing knowledge and concepts related to risk assessment in industry. The aim of this paper is to develop an ontology based approach and generate a concept for integrating safety and security risk assessment. A case study is analysed using the ontology with a SPARQL query example. Pushparaj Bhosale, Wolfgang Kastner, Thilo Sauter |
ETFA | 2 |
| 2023 | Towards a Comprehensive Ontology Considering Safety, Security, and Operation Requirements in OTabstractThe convergence of Information Technology (IT) and Operational Technology (OT) increases the interdependencies of operation, safety, and security requirements of OT systems. Cyber attacks may interfere with safety functionality which may lead to severe injuries. A possible conflict between safety and security is the usage of authentication. A safety requirement for machinery is violated if a safety function is not accessible at all times (e.g., due to the usage of authentication). There is a variety of standards and best practices on how to implement security or safety from an isolated viewpoint. Some standards even consider safety and security or link at least to other standards when the other domain has to be considered. However, there is no integrated approach to address conflicts between safety and security. Other relevant domains needed for risk or site managers (e.g., operation, product quality, risk evaluation, and risk treatment) are not addressed in a single holistic standard or approach. Without holistic guidance, risk managers are forced to solve this issue manually on best effort or include knowledge of domain experts who provide their expertise which is typically bound to a single domain in scope of the manager’s interest. Due to the complex interdisciplinary interplay of these domains, knowledge representation using ontologies may be key to model all relations and constraints needed for risk or state managers to consider in their risk managing business process. Therefore, this work presents the results of a literature survey analyzing several ontologies considering at least one relevant domain to address when performing risk management at OT systems. Siegfried Hollerer, Wolfgang Kastner, Thilo Sauter |
ETFA | 2 |
| 2023 | Formal Verification of Safety and Security Properties in Industry 4.0 ApplicationsabstractWith the advent of Industry 4.0 (I4.0) systems, ensuring the safety and security of these systems' design has become a paramount concern for stakeholders. One concern is the increased costs of fixing errors in later phases, such as integration and operation compared to the design phase. Formal verification techniques offer a rigorous approach to verifying the correctness of system behaviours and properties. This paper explains the fundamental principles of formal verification in safety and security domains. We use a SysML-based environment called AVATAR ("Automated Verification of Real Time Software"). It allows for a formal description and verification of safety and security properties. Specifically, we demonstrate the application of AVATAR in verifying the safety and security properties of a Cobot system architecture upon requirements. Moreover, we evaluate the challenges, opportunities, and limitations of using AVATAR in industrial settings and provide recommendations for its enhancement or designing a new methodology for I4.0 application verification. The results show that formal verification techniques can be enhanced to address safety and security concerns in I4.0 complex and critical systems. Ali Mohammad Hosseini, Thilo Sauter, Wolfgang Kastner |
ETFA | 3 |
| 2023 | Towards a Uniform Exchange Format for Home and Building Automation using VDI 3814abstractExchanging technical documents in the building automation domain is a complicated process. Files are distributed either as drawings, spreadsheets, or text documents. Each stakeholder has to re-enter the data into their own system, and changes are revised manually, often even without revision control. This paper presents a uniform exchange format based on the ’graphical’ standard VDI 3814. To increase acceptance, the industry standards XSD and XML were chosen. As a result of this work, a model is provided that covers the concepts and exchange files provided in the VDI 3814 standard. Given a supporting tool, data can be entered, revised, and exchanged automatically. Based on this unified representation, it is subsequently possible to transfer the data into one of the already existing ontologies in this domain by using model transformations. Some of these ontologies are also referred to in this paper. Felix Knorr, Wolfgang Kastner |
ETFA | 2 |
| 2023 | Dynamic Deployment of Fault Detection ModelsabstractThis paper describes an approach for integrating a Machine Learning (ML) model for fault detection into an Asset Administration Shell (AAS), focusing on the seamless deployment of updated versions of this model during operation without causing downtime in production processes. To this end, a generic submodel was developed that conforms to the AAS metamodel definition and can support different types of ML models and application scenarios. In addition, three deployment strategies were identified that allow switching between model versions without downtime. Evolved concepts were evaluated with a proof-of-concept to illustrate the applicability and suitability of the approach. The evaluation shows that the most appropriate deployment strategy depends on the specific use case. Dominik Mailer, Gernot Steindl, Wolfgang Kastner |
ETFA | 3 |
| 2023 | Reference Model for Building AutomationabstractDuring the last decades, the complexity of building automation systems increased, starting with a growing number of sensors and actuators to several communication protocols that need to be interoperable with each other. Different techniques are introduced to handle this complexity and to support engineers during development, like abstraction, layered design, and reference architecture models. Reference architecture models are used in various domains, like in the Smart Grid domain with Smart Grid Architecture Model (SGAM) or in the Industry 4.0 domain with Reference Architecture Model Industrie 4.0 (RAMI 4.0) to reduce the complexity during design and support the modeling process. No such reference architecture model exists for the area of building automation. This paper proposes a reference architecture model for the building automation domain to support engineers in the development and modeling process of a building automation system. Jürgen Pannosch, Wolfgang Kastner |
ETFA | 2 |
| 2023 | Integrated Safety-Security Risk Assessment for Production Systems: A Use Case Using Bayesian Belief NetworksabstractIndustrial control systems (ICSs) are complex networked systems that enable automation of large-scale processes. Depending on the application domain, the risk of the failure of components can have catastrophic repercussions. Up to now, a safety risk assessment is carried out to identify and narrow down possible failures. However, with the recent increase of cybersecurity attacks, a need of an integrated safety and security risk assessment is rising. This encompasses a comprehensive approach to assess the risks associated with ICSs and develop strategies for mitigating those risks. This paper proposes Bayesian Belief Network (BBN) as a representative of a probabilistic method and show its suitability for an integrated safety and security risk assessment. The method is evaluated by means of a use case. It provides risk propagation of functional safety, human safety and shows a propagation path from security to functional safety. The assessment is based on practical vulnerability assessments, technical documentations, manual observation and expert opinions. Pushparaj Bhosale, Wolfgang Kastner, Thilo Sauter |
INDIN | 2 |
| 2023 | Determining the Target Security Level for Automated Security Risk AssessmentsabstractDue to Industry 4.0 developments, the demanded modularity of manufacturing systems generates additional manual efforts for security experts to guarantee a secure operation. The rising utilization of information and the frequent changes of system structures necessitate a continuous and automated security engineering, especially by application of the mandatory security risk assessments. Collecting the required information for these assessments and formalising expert knowledge shall improve the security of modular manufacturing systems in the future. In order to automate the security risk assessment process, this work proposes a method to determine the Target Security Level (SL-T) in conformance to the IEC 62443 standard based on the MITRE ATT&CK framework and the Intel Threat Agent Library (TAL). Marco Ehrlich, Andre Bröring, Christian Diedrich, Jürgen Jasperneite, Wolfgang Kastner, Henning Trsek |
INDIN | 5 |
| 2023 | Safety and Security: A Field of Tension in Industrial PracticeabstractThe convergence of Information Technology (IT) and Operational Technology (OT) leads to an increasing interdependence between the protection goals of security and safety. A cyber-attack targeting safety functions may in turn lead to hazards endangering people and the environment. Furthermore, misusing safety functions may impact availability by causing a machine or production line to stop working. This work analyzes how Austrian stakeholders of industrial automation enterprises address security and safety risks to mitigate undesired situations. The stakeholder analysis performed considers vendors of products or components, integrators, and asset owners of industrial systems. Secure infrastructures, system architectures, and risk management are subject areas of this analysis. The analysis was conducted in two phases. First, an online survey was created where the involved stakeholder offered their answer simultaneously. Considering the results of the survey, individual stakeholder workshops were carried out to obtain additional, more specific perceptions about the stakeholder’s OT system and components with respect to security and safety considerations. The obtained results provide insights into the current practices in the industry regarding safety and security. Siegfried Hollerer, Wolfgang Kastner, Thilo Sauter |
INDIN | 2 |
| 2023 | Combining Models for Safety and Security Concerns in Automating Digital ProductionabstractThe IEC 62061:2021 standard requires production owners to ensure both functional safety and information security for their industrial applications. Unfortunately, traditional models of functional safety and information security have been designed in isolation and are difficult to combine. This paper introduces the Safety & Security Combination (SafeSecCombi) approach to combine models for functional safety and security concerns in automating digital production. SafeSecCombi (i) validates causes for desired and undesired effects regarding safety in an industrial production process by linking these causes to products, production processes, and production resources; (ii) identifies Industrial Internet of Things (IIoT) assets that can cause unsafe behavior in case of a successful security attack; and (iii) analyzes risks of security attacks to these IIoT assets. Therefore, SafeSecCombi provides a model for the combined analysis of safety and security concerns regarding a Cyber-Physical Production System (CPPS). In a feasibility study on an industrial work cell for metal processing with a collaborative robot, we evaluated the effectiveness and efficiency of the SafeSecCombi approach. Results indicate that the SafeSecCombi approach is feasible and effective, and provides safety and security experts with actionable, context-specific causes for security-related safety issues and countermeasures that are well grounded in engineering models, as a foundation to address the IEC 62061:2021 requirements. Sebastian Kropatschek, Siegfried Hollerer, David Hoffman, Dietmar Winkler 0001, Arndt Lüder, Thilo Sauter, Wolfgang Kastner, Stefan Biffl |
INDIN | 7 |
| 2023 | Sensor Node Fault Detection in Wireless Sensor Networks Utilizing Node-Level DiagnosticsabstractSensor node faults are a serious threat to wireless sensor networks. They can cause node crashes or lead to the transmission of corrupted data. Especially the latter endangers the quality of subsequent data analyses. Most related fault detection approaches consider the sensor nodes as black boxes. They neglect vital information available on the node level. Consequently, most of these approaches can not distinguish between (i) irregular but correctly sensed data events and (ii) data corruption caused by soft faults. In contrast, our contribution integrates node-level diagnostics with the characteristics of the sensor data. We utilize this node-level diagnostic information to present our fault detection approach. Based on simulations and practical experiments, we show the correctness and efficiency of our approach. The results show that our approach offers a high fault detection rate and can differentiate between events and faults. Furthermore, it consumes a justifiably small overhead of resources and energy. Dominik Widhalm, Karl M. Göschka, Wolfgang Kastner |
SRDS | 3 |
| 2023 | A Safety and Security Requirements Management Methodology in Reconfigurable Collaborative Human-Robot ApplicationabstractThe current industry has to adapt to rapidly changing customers' needs. Reconfigurable manufacturing, therefore, provides capacity and functionality on demand which is essential for competitiveness in fast-changing markets. Furthermore, Industry 4.0 or even more so, Industry 5.0 emphasizes human-centred production with collaborative robots, Cobots, to create human-robot interactions. In such scenarios, safety and security are difficult to address due to the intrinsic features of reconfigurable manufacturing, like exposure to numerous requirements changes in a short period. As safety and security can conflict in different phases of the system life-cycle, one of the earliest activities to avoid conflicts is requirements engineering which can significantly diminish the cost and time of fixing issues compared to later phases like operation. This paper proposes a methodology for safety and security requirements interaction management, including conflict detection and resolution, and shows its applicability through a reconfigurable collaborative human-robot use case. Based on the proposed methodology, we detected and resolved two safety and security requirement conflicts. Ali Mohammad Hosseini, Clara Wiederschwinger-Fischer, Mukund Bhole, Wolfgang Kastner, Thilo Sauter, Sebastian Schlund |
WFCS | 4 |
| 2023 | Safety and Security Requirements in AAS Integration: Use Case DemonstrationabstractThe Digital Twin (DT) paradigm has received attention for its potential in diverse industrial sectors like manufacturing, automotive, healthcare, electric grid, and transportation. The Asset Administration Shell (AAS) as an instantiation of the DT paradigm is proposed by Plattform Industrie 4.0, aiming to exchange asset-related data and services from when the asset is produced to its disposal in an interoperable way involving the key stakeholders. In Industrial Control Systems (ICS), AAS integration can bring about new safety and security concerns. Although there are standards covering safety and security separately, no finalised standard supports safety and security in a combined way. The increase in safety and security concerns because of AAS integration and recent cyber attacks that showed security and safety are interconnected, encourage us to explore one of the earliest activities in system development, requirement specification. Therefore, this paper investigates the impact of AAS integration into a use case on safety and security requirements specification according to IEC 62443 and 61511. The results highlight the interconnection of safety and security requirements in the proposed use case due to AAS integration and illustrate security requirements that potentially can affect safety. Ali Mohammad Hosseini, Thilo Sauter, Wolfgang Kastner |
WFCS | 3 |
| 2023 | Buffer Management for TSN-Enabled End StationsabstractThe change of industrial automation towards a highly interconnected architecture is still ongoing. Time-sensitive networking (TSN) is an essential element for this transition. This paper focuses on TSN end stations, mainly answering how to implement a software-based worst-case execution time (WCET) analyzable buffer management. The two-level segregated fit (TLSF) algorithm was chosen, implemented, and evaluated based on an asymptotic complexity analysis of dynamic storage allocation algorithms. The implemented and improved TLSF algorithm showed similar timing behavior as calculated when executed on a time-predictable platform. The paper concludes by outlining further research. Christoph Lehr, Patrick Denzler, Thomas Frühwirth, Wolfgang Kastner |
WFCS | 4 |
| 2023 | Authenticated UWB-Based Positioning of Passive DronesabstractDrones can be downed by spoofing attacks. As a countermeasure, the European Space Agency has adopted a broadcast authentication protocol called Timed Efficient Loss-tolerant Authentication (TESLA) in the European Global Navigation Satellite System (GNSS), Galileo. In this work, we will assess the potential of using TESLA for indoor positioning systems that are based on ultra-wideband (UWB) technology. The initial findings from our experiments indicate that authentication methods based on TESLA can provide protection to an UWB-based indoor positioning system against signal spoofing, Mahyar Shariat, Wolfgang Kastner |
WFCS | 2 |
| 2022 | Risk Assessments Considering Safety, Security, and Their Interdependencies in OT EnvironmentsabstractInformation Technology (IT) and Operational Technology (OT) are converging further, which increases the number of interdependencies of safety and security risks arising in industrial architectures. Cyber attacks interfering safety functionality may lead to serious injuries as a consequence. Intentionally triggering a safety function may introduce a security vulnerability during the emergency procedure, e.g., by opening emergency exit doors leading to enabling unauthorized physical access. This paper introduces a risk evaluation methodology to prioritize and manage identified threats considering security, safety, and their interdepedencies. The presented methodology uses metrics commonly used in the industry to increase its applicability and enable the combination with other risk assessment approaches. These metrics are Common Vulnerability Scoring System (CVSS), Security Level (SL) from the standard IEC 62443 and Safety Integrity Level (SIL) from the standard IEC 61508. Conceptional similarities of those metrics are considered during the risk calculation, including an identified relation between CVSS and SL. Besides this relation, the skill level and resources of threat actors, threats enabling multiple identified attacks, the SIL of safety-relevant components affected, business criticality of the targeted asset, and the SL-T of the zone targeted by the attack are considered for risk evaluation. The industrial architecture to be analyzed is separated into zones and conduits according to IEC 62443, enabling the analyzed system to be compliant with its requirements. Siegfried Hollerer, Thilo Sauter, Wolfgang Kastner |
ARES | 3 |
| 2022 | A Model Based Framework for Testing Safety and Security in Operational Technology EnvironmentsabstractToday’s industrial control systems consist of tightly coupled components allowing adversaries to exploit security attack surfaces from the information technology side, and, thus, also get access to automation devices residing at the operational technology level to compromise their safety functions. To identify these concerns, we propose a model-based testing approach which we consider a promising way to analyze the safety and security behavior of a system under test providing means to protect its components and to increase the quality and efficiency of the overall system. The structure of the underlying framework is divided into four parts, according to the critical factors in testing of operational technology environments. As a first step, this paper describes the ingredients of the envisioned framework. A system model allows to overview possible attack surfaces, while the foundations of testing and the recommendation of mitigation strategies will be based on process-specific safety and security standard procedures with the combination of existing vulnerability databases. Mukund Bhole, Wolfgang Kastner, Thilo Sauter |
ETFA | 2 |
| 2022 | Automating Safety and Security Risk Assessment in Industrial Control Systems: Challenges and ConstraintsabstractCurrently, risk assessment of industrial control systems is static and performed manually. With the increased convergence of operational technology and information technology, risk assessment has to incorporate a combined safety and security analysis along with their interdependency. This paper investigates the data inputs required for safety and security assessments, also if the collection and utilisation of such data can be automated. A particular focus is put on integrated assessment methods which have the potential for automation. In case the overall process to identify potential hazards and threats and analyze what could happen if they occur can be automated, manual efforts and cost of operation can be reduced, thus also increasing the overall performance of risk assessment. Pushparaj Bhosale, Wolfgang Kastner, Thilo Sauter |
ETFA | 2 |
| 2022 | Concurrent OPC UA information model access, enabling real-time OPC UA PubSubabstractOngoing changes in industrial automation aim to-wards a flat and highly interconnected architecture that includes end-to-end real-time enabled machine-to-machine communications. Several technologies, such as OPC Unified Architecture (OPC UA) publish-subscribe and time-sensitive networking (TSN), facilitate that change. While OPC UA PubSub and TSN can already provide real-time capabilities, the parallel operation with standard OPC UA client-server remains an open challenge. This article presents preliminary results for solving concurrent information model access between OPC UA PubSub and client-server. The results include the overall RT-TSN-OPC UA concept, an analysis of common concurrent data access mechanisms for their suitability, and identifying critical code segments in the open62541 OPC UA stack. The paper concludes by outlining further research focusing on implementing and evaluating a wait-and obstruction-free mechanism into open62541. Patrick Denzler, Mohammad Ashjaei, Thomas Frühwirth, Victor Nicholas Ebirim, Wolfgang Kastner |
ETFA | 5 |
| 2022 | Comparing Different Persistent Storage Approaches for Containerized Stateful ApplicationsabstractCyber-physical systems are highly distributed, flexible, and closely connected to the physical world. State preservation is an essential aspect of operating cyber-physical systems. If stateful applications fail, the current state needs to be restored so that the system can operate again. With the entry of edge computing, applications can now be containerized close to the equipment and allow new use cases. The lack of persistent storage in containers to ensure statefulness requires external, centralized, or distributed solutions. This paper explores this spectrum by comparing three experimental implementations and indicates possible causes for state loss. The underlying aim is to provide a starting point for choosing which state preservation approach is most suitable for which application type. The paper concludes with future research steps. Patrick Denzler, Daniel Ramsauer, Thomas Preindl, Wolfgang Kastner, Alexander Gschnitzer |
ETFA | 4 |
| 2022 | Functional Safety Use Cases in the Context of Reconfigurable Manufacturing SystemsabstractFlexibility and reconfiguration of manufacturing systems have been subjects of research for almost half a century. In recent years, with the emergence of customized mass production as a goal of Industry 4.0 (I4.0), Reconfigurable Manufacturing Systems (RMSs) have experienced a renaissance. The objective of rapid reconfiguration of production facilities is a fundamental condition for the realization of customized mass production. Besides the configuration of machinery and their programs, this also affects the configuration of the safety system. In this paper, core characteristics of Reconfigurable Safety Systems (RSSs) are proposed, which extend the characteristics of RMSs. Furthermore, we explore use cases of discrete manufacturing and identify service groups and services that are needed for the technical implementation of rapid safety reconfiguration within RMSs in order to allow flexible, reliable, and safe operation of machinery. Dieter Etz, Patrick Denzler, Thomas Frühwirth, Wolfgang Kastner |
ETFA | 4 |
| 2022 | Functional Smart Grid Application DevelopmentabstractDue to the increasing complexity of power grids, the development complexity of smart grid applications has continued to rise in recent years. Smart grid applications are currently being developed for specific power grids and not in a grid-independent way causing significant repetitive engineering effort. This paper gives an overview of the state of the art of application development in the smart grid domain, as well as approaches that try to cope with the mentioned problem. In particular, solutions are examined where the grid-independent application is modeled using a functional description. These approaches are then reviewed for limitations and weaknesses in order to make suggestions on how an integrated framework for the development of such applications could look like. Finally, an overview of research questions to reach this goal is presented. Felix Knorr, Thomas Frühwirth, Wolfgang Kastner |
ETFA | 3 |
| 2022 | Ontology for Rating Dependability AttributesabstractAn important field of application for the Internet of Things (IoT) is the area of monitoring and control, which imposes requirements on dependability. As devices in the IoT become increasingly capable, they can make use of concepts and technologies provided by the area of knowledge engineering to cope with these requirements. Existing work in this area mainly covers dependability threats and means, but dependability attributes are less well investigated.This paper presents a dependability rating ontology that enables the quantification of dependability attributes and, thus, makes them comparable. This is achieved by combining a dependability tree ontology with an ontology covering metrics and scales. IoT devices can use the dependability rating ontology, e.g., to improve their control algorithms, which is demonstrated on the switching optimization problem, a Smart Grid use-case. Thomas Frühwirth, Thomas Preindl, Wolfgang Kastner |
IECON | 3 |
| 2022 | Energy Efficient Protocols for LLNs - Metrics and MeasurementsabstractEnergy efficiency is arguably the primary concern of most new propositions for the Industrial Internet of Things (IIoT) focusing on Low Power and Lossy Networks (LLNs), be it novel or improved protocols or new applications. While simulations are mostly used to evaluate new approaches, they might only approximate the energy consumption, generally done via abstract metrics that are assumed to correlate directly with actual energy usage. We analyze the behavior of two different Internet of Things (IoT) development boards in detail and in a second step operating in realistic scenarios, comparing two different multicast routing protocols and various configurations. While focusing on the IEEE 802.15.4/6LoWPAN, we show that the actual energy consumption of real devices is considerably more complex than simulations are able to model, and can drastically change depending on device type and hardware configuration. We further analyze prominent metrics that are, according to our results, able to estimate energy consumption, show their limitations and how their accuracy can be improved. Philipp Raich, Stefan Adelmann, Wolfgang Kastner |
IECON | 3 |
| 2022 | Utilising Kronecker Algebra to Detect Unexpected Behaviour in Distributed SystemsabstractCurrent industrial trends require flexible and reconfigurable manufacturing systems, with Cyber-Physical Production Systems (CPPS) playing a crucial role. However, the increased flexibility and decentralisation increase the risk of unexpected or emerging system behaviour. Message sequence charts (MSCs) have proven helpful in the early stages of system design to capture intended scenarios. This paper introduces a process that utilises MSCs to identify unexpected system behaviour. After synthesising the MSCs into finite state machines, the process suggests applying Kronecker algebra to verify intended and identify unintended scenarios. The process is illustrated by an example depicting an auto-lock mechanism. The paper concludes by outlining further research focusing on implementing the process and identifying emergence at runtime. Patrick Denzler, Johann Blieberger, Wolfgang Kastner |
ISORC | 3 |
| 2022 | Combined Modeling Techniques for Safety and Security in Industrial Automation: A Case StudyabstractThe interconnection of automation technology with IT systems, also referred to as Industry 4.0, enables cyber attacks to impact safety (e.g., TRITON malware). Conversely, installed safety functions and requirements may also affect security requirements (e.g., the emergency stop function has to be avail-able without prior authentication and authorization). Therefore, threat modeling (TM) methods considering security, safety, and their interdependence are needed to get a comprehensive view of potential flaws of an industrial architecture. This paper presents a case study of the TM methods STRIDE-LM and Failure-Attack-CounTermeasure (FACT) graph w.r.t. the identification of safety and security flaws and their interdependence, with the aim to provide an impression of possible solutions to the described problem. The study was applied to a use case derived from a stakeholder analysis showing common characteristics and requirements of industrial automation systems. As STRIDE-LM was designed only to consider security flaws, it was extended to cover safety aspects as well. Preliminary results of the application of the TM methods show differences in efficiency, precision, and the granularity of information provided. Siegfried Hollerer, Marta Chabrová, Thilo Sauter, Wolfgang Kastner |
SIN | 4 |
| 2022 | Data Driven Transformer Level Misconfiguration Detection in Power Distribution GridsabstractAs more novel devices are integrated into the electricity grid due to the changes taking place in the energy system, ways of detecting deviations from the intended settings are needed. If misconfigurations of, for example, reactive power control curves of inverters go unnoticed, the safe and reliable operation of the power grid can no longer be ensured due to possible voltage violations or overloadings. Therefore, methods of detection of misconfigurations of said inverters using operational data at transformers are presented and compared. These methods include preprocessing by dimensionality reduction as well as detection by supervised learning approaches. The data used is of high reliability as it was collected in a lab setting reenacting typical and relevant grid operation situations. Furthermore, this data was recreated by simulation to validate the simulation data, which could also potentially be used for detection applications on a bigger scale. The results for both data sources were compared and conclusions drawn about applicability and usability for grid operators. David Fellner, Thomas I. Strasser, Wolfgang Kastner, Behnam Feizifar, Ibrahim Faiek Abdulhadi |
SMC | 3 |
| 2022 | Timing Analysis of TSN-Enabled OPC UA PubSubabstractIndustrial automation is changing towards a flat and highly interconnected architecture, with requirements for end-to-end real-time enabled machine-to-machine communications. Technologies such as time-sensitive networking (TSN) and OPC Unified Architecture (OPC UA) publish-subscribe provide the necessary features. While TSN is well explored, OPC UA's execution time behavior remains unknown. This article presents findings made while extending the open62541 OPC UA Pub Sub stack with the 802.1q VLAN tag to enable IEEE 802.1Qbv time-aware scheduling. The results include end-to-end timing measures and worst-case execution time analyses considering various payloads. Time-predictable T-CREST platforms host the publisher and subscriber, and a TSN network handles message transmission. The paper concludes by outlining further research focusing on dynamic memory access, buffer management, and the inclusion of non-priority access to the Ethernet port. Patrick Denzler, Thomas Frühwirth, Daniel Scheuchenstuhl, Martin Schoeberl, Wolfgang Kastner |
WFCS | 5 |
| 2022 | A Safety and Security Reference Architecture for Asset Administration Shell DesignabstractWith the introduction of Industry 4.0 (I4.0), man-ufacturing systems are moving towards digitalization which is one of the principal visions of I4.0. In industrial automation systems, safety and security are fundamental aspects that will gain even more importance in the future, even more so as systems become more interconnected in I4.0. The Asset Administration Shell (AAS) is one of the key enabling concepts towards the realization of I4.0, and its generic approach ensures applicability in different areas. Nevertheless, the lack of a reference for developing such applications has led to a diverse collection of implementation efforts. This is an interoperability issue that may increase safety and security concerns in future I4.0 applications. This paper proposes a safety and security reference architecture to provide a firm ground for developing safe and secure AAS-based applications in the context of I4.0. It breaks down critical aspects of AAS development into understandable elements to facilitate decision-making for the key stakeholders, from vendors to system integrators to operators who aim to move towards I4.0 realization. Ali Mohammad Hosseini, Thilo Sauter, Wolfgang Kastner |
WFCS | 3 |
| 2021 | A Centralised or Distributed Risk Assessment using Asset Administration ShellabstractThe application of Industry 4.0 (I4.0) architectures to the conservative nature of present Industrial Control System (ICS) has brought along many challenges. The ever-changing and dynamically altering threat landscape has led to many hazards and risks w.r.t. safe and secure operation of underlying assets. To understand and manage such risks, organizations perform assessments. Risk assessments performed today are typically handled in a centralized manner on a higher layer of the automation pyramid. The concept of the Asset Administration Shell (AAS) for I4.0 component might provide means to access and process data at the component level throughout the lifecycle, thus taking the assessment from a strictly centralized to a distributed manner. This paper, thus, focuses on the possibility of risk assessment either performed centrally or in a distributed manner aiming at highlighting data sources, acquisition, and processing mechanisms for the same relying on the AAS. Pushparaj Bhosale, Wolfgang Kastner, Thilo Sauter |
ETFA | 2 |
| 2021 | Communication and container reconfiguration for cyber-physical production systemsabstractThe Fourth Industrial Revolution, or Industry 4.0, aims to advance flexibility and reconfigurability in current production systems. This paper sets cyber-physical production systems in context with Industry 4.0 concepts and architectures. The combination points out the importance of the interplay between communication and component reconfiguration when changes occur. A solution that utilizes fog computing, container-based deployment and Kubernetes functionality is presented and evaluated in simplified reconfiguration scenarios. The findings show the feasibility and the challenges of the solution and point towards further research to successfully create reconfigurable cyber-physical production systems. Patrick Denzler, Daniel Ramsauer, Thomas Preindl, Wolfgang Kastner |
ETFA | 4 |
| 2021 | Building Blocks for Flexible Functional Safety in Discrete Manufacturing and Process IndustriesabstractDiscrete manufacturing and process industries move towards flexible production to cope with individualization. Safety systems often counteract these developments. In this paper, a generalized methodology to draft an overall safety concept using different technologies is presented. Motivated by use-cases from both domains, requirements for future safety systems are described and summarized in a structured way. These requirements are then generalized and classified in building blocks to fulfill the needs of flexible functional safety. A methodology to structure safety systems and their general parts is presented. The used building blocks refer to aspects as interfaces, communication, and certification. Within the building blocks different technologies can be applied, to fulfill the part of the safety system accordingly. Anselm Klose, Florian Pelzer, Dieter Etz, Diana Strutzenberger, Thomas Frühwirth, Wolfgang Kastner, Leon Urbas |
ETFA | 6 |
| 2021 | Is Arduino a suitable platform for sensor nodes?abstractOver the last years, a significant amount of research papers based their practical evaluation of wireless sensor network-related topics on deployments consisting of Arduino-based sensor nodes. Arduino, on the other hand, offers prototyping boards not tailored for in-the-field deployments. Also, the boards are not specifically designed for ultra low power operation required for long-lasting wireless sensor nodes.We consequently raise the question, whether Arduino is indeed a suitable platform for wireless sensor nodes. For this reason, we evaluated recent Arduino boards by (i) comparing their specifications with common sensor nodes and (ii) analyzing their power consumption in active as well as different sleep modes. Additionally, we evaluated the software components provided by Arduino (i.e., bootloader and libraries).In conclusion, Arduino offers an easy-to-use and cheap basis for early development or analysis, but it falls short in terms of high power consumption as well as issues caused by the bootloader and other integrity issues in the libraries. Therefore, Arduino may be suitable to support the sensor node development but has noticeable drawbacks for actual deployments. Dominik Widhalm, Karl M. Göschka, Wolfgang Kastner |
IECON | 3 |
| 2021 | Identification of security threats, safety hazards, and interdependencies in industrial edge computing
Patrick Denzler, Siegfried Hollerer, Thomas Frühwirth, Wolfgang Kastner |
SEC | 4 |
| 2021 | Experiences from Adjusting Industrial Software for Worst-Case Execution Time AnalysisabstractWorst-case execution time (WCET) analysis is a prevalent way to ensure the timely execution of programs in time-critical systems. With the advent of new technologies such as fog computing and time-sensitive networking (TSN), the interest in timing analysis has increased in industrial communication. This paper highlights experiences made while adjusting the publisher of the open62541 OPC UA stack to enable WCET analysis, following a simple process combined with the open-source platform T-CREST. The main challenges are the required knowledge about the code and the specific communication software characteristics like variable message sizes. Other findings indicate the need for other types of annotation for indirect recursion or callback functions. The paper provides the foundation for further research on adjusting the implementation of existing industrial communication protocols for WCET analysis. Patrick Denzler, Thomas Frühwirth, Andreas Kirchberger, Martin Schoeberl, Wolfgang Kastner |
ISORC | 5 |
| 2021 | Node-level indicators of soft faults in wireless sensor networksabstractFaults in wireless sensor nodes tend to be the norm rather than the exception. Our paper addresses the following problems: How can we make sure the sensed data has not been distorted by faults? And when we experience anomalies in the sensed data, how can we distinguish between rare but correctly measured events and incorrect data due to faults? The focus of this paper is specifically on soft faults, because (i) they deteriorate the data quality and (ii) are hard to distinguish from irregular but correct events. Many papers on how to detect soft faults have been proposed, but they mostly rely on assumptions on the network's deployment or the nature of the collected data. Therefore, they are insufficient as they can miss faults or misinterpret correct data. In this paper, our key idea is to augment the existing fault-detection approaches with node-level information as additional input. Our contribution is to show the existence of such node-level information that can improve (i) the detection of soft faults and (ii) the distinction between faults and events. This node-level information - called fault indicators - can then be included in existing fault detection schemes. Based on practical experiments, we show that using such fault indicators indeed improves the detection rate and reduces the risk of missing fault-induced variations of sensor data. Dominik Widhalm, Karl M. Göschka, Wolfgang Kastner |
SRDS | 3 |
| 2021 | Static Timing Analysis of OPC UA PubSubabstractIndustrial automation is changing towards higher integration and seamless communication. A stepping stone is end-to-end real-time machine-to-machine communication, now becoming feasible with technologies such as time-sensitive networking (TSN) and OPC Unified Architecture (OPC UA) publish-subscribe. While TSN takes care of communication, the OPC UA stack's execution time behavior remains unknown. This paper highlights experiences made while adjusting the OPC UA subscriber of the open62541 stack for worst-case execution time (WCET) analysis. Two directly connected time-predictable T-CREST platforms hosting the publisher and subscriber delivered end-to-end timing measures validating the WCET estimates. The paper concludes by outlining further research with several time-predictable publishers and subscribers. Patrick Denzler, Thomas Frühwirth, Andreas Kirchberger, Martin Schoeberl, Wolfgang Kastner |
WFCS | 5 |
| 2021 | Towards a Threat Modeling Approach Addressing Security and Safety in OT EnvironmentsabstractIn Industry 4.0, Information Technology (IT) and Operational Technology (OT) tend to converge further with an increasing interdependence of safety and security issues to be considered. On one hand, cyber attacks are possible which can alter implemented safety functionality leading to situations where people are harmed, serious injuries may occur or the environment gets damaged. On the other side, safety can also impact security. For instance, the misuse of a Safety Instrumented System (SIS) may force a machine or a production line to shut down resulting in a denial of service. To prevent or mitigate risks from such scenarios, this paper proposes a threat modeling technique which addresses an integrated view on safety and security. The approach is tailored to the industrial automation domain considering plausible attacks and evaluating risks based on three different metrics. The metrics selected consist of Common Vulnerability Scoring System (CVSS) used as an international standard for rating cyber security vulnerabilities, Security Level (SL) from IEC 62443 to rate cyber security risks in OT environments w.r.t. the underlying architecture, and Safety Integrity Level (SIL) from IEC 61508 to rate safety risks. Due to the variety of use cases involving the chosen metrics, the approach is also feasible for followup analyses, such as integrated safety and security assessments or audits. Siegfried Hollerer, Wolfgang Kastner, Thilo Sauter |
WFCS | 2 |
| 2021 | Towards Adding Safety and Security Properties to the Industry 4.0 Asset Administration ShellabstractIndustry 4.0 (I4.0) intends to make manufacturing agile, more efficient, and more customer-oriented. Considerable efforts have been made to enhance the safety and security aspects of I4.0 systems. However, the lack of a standard model has prevented the convergence toward safety and security. Plattform Industrie 4.0 has introduced the Asset Administration Shell (AAS) with the Reference Architectural Model Industry (RAMI 4.0) to integrate assets into the world of information. This paper draws the potential capabilities of AAS in bringing safety and security to I4.0 systems. For this goal, a safety and security model is proposed based on RAMI 4.0 to be used as a reference for developing the AAS model. A level control system is used as an illustrative example of an Industrial Control System (ICS) to demonstrate how to respond to I4.0 safety and security challenges using the AAS model. Ali Mohammad Hosseini, Thilo Sauter, Wolfgang Kastner |
WFCS | 3 |
| 2021 | A Computational Model for 6LoWPAN Multicast RoutingabstractReliable group communication is an important cornerstone for various applications in the domain of Industrial Internet of Things (IIoT). Yet, despite various proposals, state-of- the-art (open) protocol stacks for IPv6-enabled Low Power and Lossy Networks (LLNs) have little to offer, regarding standardized or agreed-upon protocols for correct multicast routing, not to mention reliable multicast. We present an informal computational model, which allows us to analyze the respective candidates for multicast routing. Further, we focus on the IEEE 802.15.4/6LoWPAN stack and discuss prominent multicast routing protocols and how they fit into this model. Philipp Raich, Wolfgang Kastner |
WFCS | 2 |
| 2020 | SoK: a taxonomy for anomaly detection in wireless sensor networks focused on node-level techniquesabstractWireless sensor networks play an important role in today's world: When measuring physical conditions, the quality of the sensor readings ultimately impacts the quality of various data analytical services. To maintain data correctness and quality, run-time measures such as anomaly detection techniques are gaining significance. In particular, the detection of threatening node anomalies caused by sensor node faults has become a crucial task. Dominik Widhalm, Karl M. Göschka, Wolfgang Kastner |
ARES | 3 |
| 2020 | Creating Character-based Templates for Log Data to Enable Security Event ClassificationabstractLog data analysis is an essential task when it comes to understanding a computer's or a network's system behavior, and enables security analysis, fault diagnosis, performance analysis, or intrusion detection. An established technique for log analysis is log line clustering, which allows to group similar events and to detect outliers, malicious clusters or changes in system behavior. However, log line clusters usually lack meaningful descriptions that are required to understand the information provided by log lines within a cluster. Template generators allow to produce such descriptions in form of patterns that match all log lines within a cluster and therefore describe the common features of the lines. Current approaches only allow generation of token-based (e.g., space-separated words) templates, which are often inaccurate, because they do not recognize words that can be spelled differently as similar and require further information on the structure and syntax of the data, such as predefined delimiters. Consequently, novel character-based template generators are required that provide robust templates for any type of computer log data, which can be applied in security information and event management (SIEM) solutions, for continuous auditing, quality inspection and control. In this paper, we propose a novel approach for computing character-based templates, which combines comparison-based methods and heuristics. To achieve this goal, we solve the problem of efficiently calculating a multi-line alignment for a group of log lines and compute an accurate approximation of the optimal character-based template, while reducing the runtime from $O(n^m)$ to $O(mn^2)$. We demonstrate the accuracy of our approach in a detailed evaluation, applying a newly introduced measure for accuracy, the Sim-Score, which can be computed independently from a ground truth, and the established F-Score. Furthermore, we assess the robustness of the algorithm and the influence of different log data properties on the quality of the resulting templates. Markus Wurzenberger, Georg Höld, Max Landauer, Florian Skopik, Wolfgang Kastner |
AsiaCCS | 5 |
| 2020 | Towards Consolidating Industrial Use Cases on a Common Fog Computing PlatformabstractConverging Information Technology (IT) and Operations Technology (OT) in modern factories remains a challenging task. Several approaches such as Cloud, Fog or Edge computing aim to provide possible solutions for bridging OT that requires strict real-time processing with IT that targets computing functionality. In this context, this paper contributes to ongoing Fog computing research by presenting three industrial use cases with a specific focus on consolidation of functionality. Each use case exemplifies scenarios on how to use the computational resources closer to the edge of the network provided by a Fog Computing Platform (FCP). All use-cases utilize the same proposed FCP, which allows drawing a set of requirements on future FCPs, e.g. hardware, virtualization, security, communication and resource management. The central element of the FCP is the Fog Node (FN), built upon commercial off-the-shelf (COTS) multicore processors (MCPs) and virtualization support. Resource management tools, advanced security features and state of the art communication protocols complete the FCP. The paper concludes by outlining future research challenges by comparing the proposed FCP with the identified requirements. Patrick Denzler, Jan Ruh, Marine Kadar, Cosmin Avasalcai, Wolfgang Kastner |
ETFA | 5 |
| 2020 | Flexible Safety Systems for Smart ManufacturingabstractSmart manufacturing is realizing the idea and potential of Industry 4.0 in reality. An essential part of smart manufacturing are production facilities that dynamically adapt to changing production needs. This brings completely new challenges to functional safety systems, which are mandatory for the protection of man, machine, and environment. Currently, functional safety systems are designed and certified in a static way. The safety design and the configuration are derived from the risk assessment which is performed during the design of a machine. Once the system is put into operation, the safety configuration is not changed anymore. This approach constitutes an impediment to flexibility which smart manufacturing production facilities require nowadays.This paper proposes the design of a self-organizing safety system with the objective to assist an engineer who operates a smart manufacturing facility by discovering all safety-related devices and generating automatically a suitable safety configuration. This configuration will be deployed to the system automatically after adaptation and validation by the safety engineer. The proposed self-organizing safety system, simplifies the safety configuration in a dynamically changing environment. Consequently, it would reduce engineering efforts and decrease machine downtime which improves profitability. Dieter Etz, Thomas Frühwirth, Wolfgang Kastner |
ETFA | 3 |
| 2020 | Towards Data-Driven Malfunctioning Detection in Public and Industrial Power GridsabstractInvestigation of a concept for remote detection of malfunctioning grid supporting devices using minimal data is proposed in this work. The operation of future electricity grids highly depends on the behaviour of these devices and their support functions such as reactive power dispatch used for voltage control. Synthesising and utilizing operational data of a distribution grid, a functionality is being developed to enable better surveillance of grid connected devices ensuring security of supply and resiliency. In a first step, data driven approaches for anomaly detection are explored. They are applied to the operational data of the device to detect unwanted behaviour. Results show first indicators of applicability and possible obstacles. David Fellner, Helfried Brunner, Thomas I. Strasser, Wolfgang Kastner |
ETFA | 4 |
| 2020 | Open Monitoring Platform for Mobile BroadbandabstractEnhanced Mobile Broadband (eMBB) is just around the corner, and its performance aspect makes it interesting for Vehicle-to-Vehicle (V2V) communication. Fair benchmarking of communication networks has been a research topic for decades. In contrast to wired networks, mobile networks lack a quick, accurate, and data-saving tool to describe the properties of the connection in a vehicle. Therefore, this work aims to create a crowdsourcing-ready and easily expandable software platform capable of analyzing the current network conditions in a quick and data-saving way. Based on literature research, we identified CRUSP as quick, data-saving, and accurate method to characterize mobile communication networks. Afterwards, we realized Constant Rate Ultra Short Probing (CRUSP) in a flexible software platform for performing, gathering, and analyzing measurements. The evaluation of the software was performed in a configurable and shielded reference cell and delivered an average error of 2.44% to iPerf3, a popular reference tool. In conclusion, the results indicated that the developed software operates accurately in Long-Term Evolution (LTE) networks. Wolfgang Hofer, Philipp Svoboda, Wolfgang Kastner, Vaclav Raida, Markus Rupp |
VTC Spring | 3 |
| 2019 | Ontology-Based OPC UA Data Access via Custom Property FunctionsabstractCyber Physical Production Systems have a need of sharing and interlinking information and knowledge over different domains. In the area of industrial automation, OPC Unified Architecture (OPC UA) is a widely used and established standard for communication and information modeling. We propose an ontology-based OPC UA data access method utilizing custom property functions, which enables interlinking between OPC UA information and other factory data. To avoid duplicated data and to reduce the communication overhead in the proposed method, the OPC UA run-time data are loaded on-demand and are not persistently stored in the triplestore. To enable fast and easy ontology-based access and interlinking of the OPC UA information, the needed ontology is automatically generated from the OPC UA information model. A proof of concept demonstrates the application of our approach for a laboratory use-case of a Packed-Bed Regenerator. Gernot Steindl, Thomas Frühwirth, Wolfgang Kastner |
ETFA | 3 |
| 2019 | A Model-Driven and Ontology-based Engineering Approach for Smart Grid Automation ApplicationsabstractDue to the increasing power system complexity caused by a higher penetration of distributed energy resources, advanced engineering methods are required which can handle power system aspects together with information and communication technologies and new automation concepts. In order to handle such a complexity, various engineering concepts have been introduced by providing support such as guidelines, code generation, and reasoning for the development of smart grid use cases and applications in the last few years. Nevertheless, none of these approaches covers all phases in the engineering of smart grid solutions and the corresponding requirements. In this paper, two approaches-focusing on rapid development and on the identification of application inconsistencies-are selected and combined to cover a wider scope of the requirements for smart grid automation application engineering. The integration of the two approaches is shown using an example use case, where multiple functions for a battery energy management system are designed, implemented, and validated. Claudia Zanabria, Filip Andren, Thomas I. Strasser, Wolfgang Kastner |
IECON | 4 |
| 2019 | AECID-PG: A Tree-Based Log Parser Generator To Enable Log Analysis
Markus Wurzenberger, Max Landauer, Florian Skopik, Wolfgang Kastner |
IM | 4 |
| 2018 | Security and Privacy Implementations within the AnyPLACE Energy Management SolutionabstractWith the increasing number of energy aware devices, energy management solutions can provide the necessary means to visualize, overlook and automate devices as well as communication with external services. To protect users from malicious attacks and data abuse, security and privacy aspects need to be included into the design and implementation from the very beginning. Within the AnyPLACE solution, we set out to create a security and privacy centric energy management solution. We present a survey of best practice guidelines and EU-wide security and privacy regulatory frameworks including the General Data Protection Regulation (GDPR). Based on the results of our survey, we defined implementation requirements and present the security and privacy architecture of the AnyPLACE implementation. Christian Kudera, Viktor Ullmann, Markus Kammerstetter, Wolfgang Kastner |
ETFA | 4 |
| 2018 | Ontology-Based Optimization of Building Automation SystemsabstractModern buildings are equipped with various complex automation systems that produce vast amounts of data. The operation of these systems has significant influence on energy demands and user comfort in the premises. Therefore, an optimal configuration of the systems to increase energy efficiency is desired by the operators of the buildings. An automated decision-making process that evaluates and analyzes the bulk of available data can help to achieve these objectives. Hence, this work introduces a framework for the automatic generation of recommended configuration changes to increase energy efficiency and user comfort. The approach makes extensive use of semantic building information modeling as basis for the selection of potentially useful measures as well as for their assessment. Expected consequences of configuration changes are forecasted via simulation. Additionally, current results of an application of the proposed solution in an office building are discussed. Stefan Gaida, Wolfgang Kastner, Filip Petrushevski, Milos Sipetic |
IECON | 2 |
| 2018 | Towards Model-Driven Development of Hybrid Simulation Models in Industrial EngineeringabstractIn order to analyze and optimize energy efficiency of complex industrial facilities, methods for hybrid discrete/continuous modeling and simulation are necessary that allow to incorporate thermal-physical dynamic behavior as well as discrete aspects like entity flow into an integrated simulation model while at the same time remaining manageable for large-scale applications. One promising approach follows component-based hierarchical modeling based on a formal system specification, called hyPDEVS. However, this approach faces challenges for widespread adoption in industry due to the generic nature of the formalism and related difficulties in applying it to real-world scenarios. In an attempt to support the development of hybrid simulation models based on hyPDEVS, we present a domain-specific model abstraction for industrial facilities that is intended to allow developing application models in a platform-independent manner. Thereby, we follow a model-driven engineering paradigm that promotes the separation of model specification from the concrete implementation, i.e. source code. Compared to typical co-simulation solutions, this approach provides better semantic integration of discrete and continuous modeling aspects, thereby promoting modularity and reuse of model components. Bernhard Heinzl, Wolfgang Kastner |
IECON | 2 |
| 2018 | Context-aware optimization strategies for universal application in smart building energy managementabstractIn building operation, the continuous forward planning of energy-efficient schedules to maintain user comfort is a challenging task. Although the design of building energy management systems is an active field of research, existing solutions are often faced with limited reusability due to specialization on certain buildings, comfort parameters, or building automation technologies. Thus, this work introduces a set of context-aware strategies that are generally applicable for the optimization in building energy management systems. For this purpose, machinereadable semantics of the building and the building automation system is exploited in order to design a heuristic approach. The aim is to reduce the optimization effort while targeting both energy efficiency and cross-domain comfort satisfaction on a building-independent level. An embedding of the proposed approach into common metaheuristics is described to provide a basis for further reuse. Finally, case studies are used for evaluation of a proof-of-concept implementation. Daniel Schachinger, Wolfgang Kastner |
INDIN | 2 |
| 2017 | Incremental Clustering for Semi-Supervised Anomaly Detection applied on Log DataabstractAnomaly detection based on white-listing and self-learning has proven to be a promising approach to detect customized and advanced cyber attacks. Anomaly detection aims at detecting significant deviations from normal system and network behavior. A well-known method to classify anomalous and normal system behavior is clustering of log lines. However, this approach has been applied for forensic purposes only, where log data dumps are investigated retrospectively. In order to make this concept applicable for on-line anomaly detection, i.e., at the time the log lines are produced, some major extensions to existing approaches are required. Especially distance based clustering approaches usually fail building the required large distance matrices and rely on time-consuming recalculations of the cluster-map on every arriving log line. An incremental clustering approach seems suitable to solve this issues. Thus, we introduce a semi-supervised concept for incremental clustering of log data that builds the basis for a novel on-line anomaly detection solution based on log data streams. Its operation is independent from the syntax and semantics of the processed log lines, which makes it generally applicable. We demonstrate that that the introduced anomaly detection approach allows to achieve both a high recall and a high precision while maintaining linear complexity. Markus Wurzenberger, Florian Skopik, Max Landauer, Philipp Greitbauer, Roman Fiedler, Wolfgang Kastner |
ARES | 6 |
| 2017 | A distributed multi-agent system for switching optimization in low-voltage power gridsabstractInformation and communication technology plays a crucial role in increasing reliability and efficiency of our critical infrastructure. This paper presents a distributed multi-agent system for switching optimization in low-voltage power grids. As opposed to centralized approaches, the overall optimization procedure is not implemented in a single node but emerges from the behavior and interaction of the participating agents. Thereby, the communication strictly follows a predefined interaction protocol. Losses are reduced by balancing loads among all available transformers. Based on a small distribution network, an exemplary optimization run is discussed in detail. Furthermore, FNCS, a state-of-the-art co-simulation framework, is used to evaluate the actual potential for energy saving. Thomas Frühwirth, Alfred Einfalt, Konrad Diwold, Wolfgang Kastner |
ETFA | 4 |
| 2017 | Coordinating redundant OPC UA serversabstractCoordination is an important aspect of large scale distributed systems. The Open Platform Communications Unified Architecture (OPC UA) standard series presents an important challenge for coordination in its specifications for server redundancy. This paper discerns the coordination needs of OPC UA server redundancy and presents a solution based on the integration of OPC UA and ZooKeeper. A detailed description of the architecture, data model, and components of the resulting system is given. This is accompanied by a discussion of an implementation based on the open source ZooKeeper and open62541 libraries. The resulting system is shown to be capable of meeting the coordination needs of OPC UA redundancy. Ahmed Ismail, Wolfgang Kastner |
ETFA | 2 |
| 2017 | Ontology-based generation of optimization problems for building energy managementabstractIn general, a trade-off between comfort satisfaction and minimization of energy consumption or overall costs needs to be found by building energy management systems. Additionally, the design of energy management strategies often requires high effort and expert knowledge in order to model the dynamics within a building, which leads to very specific solutions with limited reuse. Thus, this work presents an approach for the automatic generation of optimization problems for building energy management based on machine-readable semantics. For this purpose, an ontology hosts all relevant information necessary for the optimization problem formulation. Information extraction and transformation into the optimization problem domain are addressed. Moreover, a case study demonstrates the functionality of the proposed procedure. Daniel Schachinger, Wolfgang Kastner |
ETFA | 2 |
| 2017 | Enabling hardware-in-the-loop for building automation networks: A case study for BACnet and PowerDEVSabstractHardware-in-the-Loop (HIL) is a well-established concept for developing and testing embedded systems. While it is widely used in industrial automation and the automotive area, it is rarely applied to Building Automation Systems (BAS). This work proposes the interconnection of a prominent building automation protocol, namely Building Automation and Control network (BACnet), and a simulator, PowerDEVS, to facilitate HIL testability of new and existing building automation networks. The Discrete Event Systems Specification formalism, used by PowerDEVS, is especially geared towards systems that show both discrete event and continuous state characteristics. Hence, the field of BAS is a prime candidate for such simulators. Further, the interconnection of HIL simulation and BAS via building automation networks allows for easy and location-independent testing of single field devices on one hand, and distributed BAS applications on the other hand. Therefore, design issues, and the pros and cons of a bridging solution between BAS and simulators are discussed throughout the course of this work. The paper introduces a modular software architecture for the interconnection of building automation networks and simulation. This allows for easy portability of the proposed design to other HIL simulators or building automation network protocols. The feasibility of the proposed approach is validated by means of a proof-of-concept. Stefan Seifried, Franz Josef Preyser, Wolfgang Kastner |
IECON | 3 |
| 2016 | Efficient High-Speed WPA2 Brute Force Attacks Using Scalable Low-Cost FPGA Clustering
Markus Kammerstetter, Markus Muellner, Daniel Burian, Christian Kudera, Wolfgang Kastner |
CHES | 5 |
| 2016 | Discovery in SOA-governed industrial middleware with mDNS and DNS-SDabstractResearch efforts for the Industrial Internet of Things (IIoT) have placed great emphasis on the use of vertical integration as a mainline strategy for the realisation of the fourth industrial revolution (Industrie 4.0). The present paper proposes the use of a distributed Gateway Service Bus (GSB) as a plant-wide and resilient platform for vertical integration, field level reconfiguration, and distributed execution in heterogeneous environments. A basic service set composed of network, discovery, and management services is developed using technologies from P2P networks as cooperative systems and zero configuration networking to achieve a survivable distributed GSB. For evaluation, the resulting implementation is executed on 11 virtual machines (VM) and across two subnets in 33 consecutive runs. Results were consistent in showing that the proposed service set is capable of achieving network-wide discovery of published resources in less than 3 seconds. Ahmed Ismail, Wolfgang Kastner |
ETFA | 2 |
| 2016 | An advanced data analytics framework for energy efficiency in buildingsabstractToday's buildings provide continuously growing amounts of data monitored from diverse sensors. With regard to the similarly increasing energy needs of buildings, accurate evaluation and analysis of these data can be used in order to improve energy efficiency and reduce overall energy consumption of buildings. Hence, this work introduces a comprehensive framework based on well-known data analytics methods to process the bulk of data and extract exploitable knowledge for further usage. The approach includes the descriptive evaluation and interpretation of sensed data, the prediction of future energy needs based on a set of potential actions, and the prescription of energy efficiency measures in the form of user instructions and configuration files for building automation systems. Additionally, identified use case scenarios are described, which will be used for evaluation of the presented data analytics framework. Furthermore, current results as well as ongoing work and expected future results are discussed in this work in progress. Daniel Schachinger, Stefan Gaida, Wolfgang Kastner, Filip Petrushevski, Clemens Reinthaler, Milos Sipetic, Gerhard Zucker |
ETFA | 3 |
| 2016 | Applying the SGAM methodology for rapid prototyping of smart Grid applicationsabstractIn order to handle the increasing complexity of smart grid systems, detailed use case and requirements engineering has become indispensable. For this purpose the Smart Grid Reference Architecture Model (SGAM) has emerged as the major methodology. This paper presents a textual Domain Specific Language (DSL) based on SGAM, optimized for rapid prototyping of smart grid applications using a model-driven engineering approach with automatic code generation. The goal of this approach is to support the development process of smart Grid applications, from use case description to implementation. The paper presents a use case described by the DSL and shows how an IEC 61499 control application and an IEC 61850 communication configuration can be automatically generated. Filip Andren, Thomas I. Strasser, Wolfgang Kastner |
IECON | 3 |
| 2016 | Linked data for building managementabstractIn the life cycle of buildings, plenty of different disciplines and companies are involved. Therefore, a unified information base for the whole building and its components and technical equipment is highly beneficial. One approach aiming at this goal is Building Information Modelling (BIM). There exist standards mostly focusing on architectural and building physical properties, like the Green Building XML schema (gbXML). A further improvement would be to include a description of the technical equipment and building automation components as well, and to make the resulting model accessible in a unified way. This paper aims at a holistic knowledge base for buildings providing views on static building and automation systems configuration as well as runtime information, i.e., access to live values of datapoint originating in the building automation systems. This includes sensor values, setpoints, calculated or aggregated values as well as time series of historical values. Andreas Fernbach, Igor Pelesic, Wolfgang Kastner |
IECON | 3 |
| 2016 | IMU-based smart fitness devices for weight trainingabstractThe automated tracking and analysis of sport activities has become increasingly important in the recent years. While it is already very common in endurance sports, in weight training the tracking is still done mainly manually, which is a tedious task. This work aims at exploring the problem of automated tracking and analysing of weight training exercises by the use of low-power smart fitness devices based on inertial measurement units (IMUs), sensors containing accelerometers and gyroscopes. Therefore, basic state-of-the-art signal and data processing approaches, including various filtering techniques, sensor fusion, time series segmentation and classification methods like hidden Markov models (HMMs), support vector machines (SVMs) and nearest neighbours classifiers, are studied and applied to the specific problem domain. A proof-of-concept approach of the proposed methods is implemented on a purpose-built constrained embedded system. Finally, a comprehensive evaluation based on dumbbell exercises is done. The developed prototype achieves a segmentation misdetection rate of 1.5 %, a classification accuracy of 99.7 % and an average response time of about 300 ms. In conclusion, the results show that the initially specified requirements are met and that an accurate and fast tracking of selected weight training exercises is possible. Peter Hausberger, Andreas Fernbach, Wolfgang Kastner |
IECON | 3 |
| 2016 | Open traffic data platform for scenario-based controlabstractIntegrating formally separated control systems of a city by means of Information and Communication Technology (ICT) is well known under the term “Smart City”. The benefit is a more energy and cost efficient city. In the domain of road traffic an open traffic data platform shall be the base for smart road traffic infrastructure and services. The idea is to pool available data from road side sensors as well as aggregated data from sensor fusion units at a single place. Due to a highly scalable technology the platform can provide data to any system. The results are that fewer sensors are required for more accurate and efficient services. Klaus Pollhammer, Thomas Novak 0001, Philipp Raich, Wolfgang Kastner, Albert Treytl |
IECON | 4 |
| 2016 | Co-operative peer-to-peer systems for industrial middlewareabstractWith the ever-increasing emphasis on the importance of vertical integration for the fourth industrial revolution (Industrie 4.0), we contend that the largest potential lies in the replacement of single-purpose gateway-ing solutions with distributed gateway service bus (GSB) technologies. Within this paper, we primarily focus on the aspect of routing between variously grouped GSB components. We base our study on the premise that the most applicable technologies for such a scenario would be those of inter-system routing protocols from the domain of peer-to-peer (P2P) cooperative systems networking. We therefore summarize the basic principles governing such protocols and, using them, present a study that observes the conversion of a single system P2P networking protocol into an inter-system routing protocol. The final protocol is evaluated extensively using 50 Xen-based virtual machines deployed on 32-bit embedded devices and a 64-bit server. Ahmed Ismail, Wolfgang Kastner |
WFCS | 2 |
| 2016 | A generic dependability layer for building automation networksabstractThis paper introduces a concept for bringing dependability into the area of building automation. The proposed approach is able to extend existing building automation networks with dependability features. For this purpose, the communication stack of a particular system is extended by adding an intermediate layer. This so-called dependability layer is transparent to allow seamless integration. Thereby, reliability is addressed in terms of fault tolerance by offering redundant network topologies. A heartbeat mechanism and an acknowledgment procedure as well as a specific message format satisfy the safety requirements. Moreover, the dependability layer offers security mechanisms that establish a secured channel among communicating nodes. Lukas Krammer, Wolfgang Kastner, Thilo Sauter |
WFCS | 2 |
| 2015 | Dependability demands and state of the art in the internet of thingsabstractThe number of devices connected to the Internet of Things (IoT) has steadily been increasing over the last years and so has the variety of applications. There is no sign for this trend to weaken. A broad subset of them imposes requirements on attributes, such as availability, reliability, safety and many more. These attributes are commonly subsumed under the term dependability. In this paper we first give a brief introduction to dependability. Three application scenarios typical for the IoT are presented and their demands for each dependability attribute are discussed. Furthermore, an overview of the current state of the art is presented. Last, a summary of required technologies and future research topics to enable dependability in the IoT is given. Thomas Frühwirth, Lukas Krammer, Wolfgang Kastner |
ETFA | 3 |
| 2015 | Guarded state machines in OPC UAabstractCurrently, an increasing number of initiatives are observed aiming at enriching automation environment with modern Information and Communication Technologies (ICT). The desired solutions should lead to increasing and facilitating interoperability of production systems and their components. To realize this vision, a key component is an open and standardized communication platform. Meanwhile, OPC Unified Architecture (OPC UA) is accepted as communication solution, especially because of its capabilities to create extensible information models. As part of the ongoing research project OPC4Factory, semantically rich OPC UA interfaces based on specific information models for a robotized manufacturing cell are developed. In addition to the static hierarchical structure, the information model should also describe the dynamic behavior of the modeled system. State machines provide proven means to model the dynamic behavior of manufacturing machines. However, whether a transition of a state machine can be executed often depends on certain conditions. In UML, these conditions are reflected by guards. Unfortunately, a similar functionality is neither provided by the current OPC UA specification nor by companion standards. For this reason, an amendment to the OPC UA information model is introduced, enabling guards in OPC UA. Thereby, new object and reference types allow to model operations in an OPC UA server's address space. Exposing this information has several advantages over hiding it in the server's source code regarding the required implementation effort as well as the client's possibilities to react to rejected transition requests. Thomas Frühwirth, Florian Pauker, Andreas Fernbach, Iman Ayatollahi, Wolfgang Kastner, Burkhard Kittl |
IECON | 5 |
| 2015 | Interoperable integration of building automation systems using RESTful BACnet Web servicesabstractBuilding automation domain is affected by a diversity of standards and technologies. With the upcoming Internet of Things heading for a pervasive network of interconnected smart things and the need for efficient and intelligent energy management systems, the necessity of integrating these heterogeneous building automation environments soars. Thus, standardized, interoperable, secure, and scalable solutions are required. Well-established Web service technologies based on the Internet Protocol act as key enabler to realize this vision. In this work, an approach for the seamless and interoperable integration of building automation systems based on RESTful BACnet/WS is presented. In order to ease the integration process, the BAC-net/WS specification is described as formal, machine-readable object model. Additionally, most common building blocks of building automation systems including logical as well as physical resources are specified in the form of type definitions to unify integration. Furthermore, a proof-of-concept implementation of a BACnet/WS server is realized in order to illustrate the functional capability of the presented approach. Daniel Schachinger, Christoph Stampfel, Wolfgang Kastner |
IECON | 3 |
| 2015 | From textual programming to IEC 61499 artifacts: Towards a model-driven engineering approach for smart grid applicationsabstractDuring the last years the increasing installation of distributed energy resources, electric vehicles bus also energy storage systems has lead to new challenges in terms of power system planning and operation. New intelligent approaches turning power distribution grids into Smart Grids are necessary. For their realization standardized automation, control and communication systems are essential. Moreover, an integrated engineering approach for the development of Smart Grid applications using these standards is equally required. Model-driven engineering methods well known from computer science together with implementation methods from automation domain have the potential to provide the basis for such a required integrated engineering concept. The main aim of this paper therefore is to facilitate the integration of legacy Smart Grid applications into a model-driven engineering approach. It introduces transformation rules for the conversion of applications implemented with textual programming languages into the IEC 61499 reference model. A brief overview of existing model-driven approaches applied in industrial environments is provided and their applicability for Smart Grid application development is discussed. The special requirements of the Smart Grid domain is taken into account by the proposed transformation approach and provided examples. Filip Andren, Thomas I. Strasser, Wolfgang Kastner |
INDIN | 3 |
| 2015 | Model-driven integration of building automation systems into Web service gatewaysabstractAccessing building automation systems (BASs) via standardized interfaces gains importance in the context of the Internet of Things (IoT). Web service gateway technologies can be used to integrate BASs in order to provide access via common Web interfaces. Therefore, an integration approach supporting multiple building automation technologies as well as multiple gateway technologies is needed. For this purpose, the model-driven methodology is used to define such a procedure. In this paper, an efficient, automatic, and reusable workflow for the integration of BASs into the IoT is presented by means of specifying modeling languages, model transformations, and code generation in accordance with the concept of Model-Driven Architecture (MDA). The aim is to convert a platform-independent model of a BAS into executable program code representing the underlying datapoints. Furthermore, a proof-of-concept implementation based on an exemplary BAS is implemented and evaluated in order to demonstrate the functionality and the advantages of this model-driven approach. Daniel Schachinger, Wolfgang Kastner |
WFCS | 2 |
| 2014 | Breaking Integrated Circuit Device Security through Test Mode Silicon Reverse EngineeringabstractIntegrated Circuit (IC) device manufacturing is a challenging task and often results in subtle defects that can render a chip unusable. To detect these defects at multiple stages during the IC production process, test modes are inserted (Design For Testability). On the downside, attackers can use these test modes to break IC device security and extract sensitive information such as the firmware implementation or secret key material. While in high security smart cards the testing circuits are physically removed during production for this reason, in the majority of digital ICs the testing modes remain intact. Often they are undocumented, well-hidden and contain secret test commands. Utilizing search algorithms and/or side channel information, several attacks on secret testing modes have been presented lately. Accordingly, countermeasures that frequently rely on obfuscation techniques have been proposed as more advanced cryptographic methods would require significantly more space on the die and thus cause higher production costs. In this work, we show that limited effort silicon reverse engineering can be effectively used to discover secret testing modes and that proposed obfuscation based countermeasures can be circumvented without altering the analysis technique. We describe our approach in detail at the example of a proprietary cryptographic game authentication chip of a well known gaming console and present an FPGA implementation of the previously secret authentication algorithm. Markus Kammerstetter, Markus Muellner, Daniel Burian, Christian Platzer, Wolfgang Kastner |
CCS | 5 |
| 2014 | Prospect: peripheral proxying supported embedded code testingabstractEmbedded systems are an integral part of almost every electronic product today. From consumer electronics to industrial components in SCADA systems, their possible fields of application are manifold. While especially in industrial and critical infrastructures the security requirements are high, recent publications have shown that embedded systems do not cope well with this demand. One of the reasons is that embedded systems are being less scrutinized as embedded security analysis is considered to be more time consuming and challenging in comparison to PC systems. One of the key challenges on proprietary, resource constrained embedded devices is dynamic code analysis. The devices typically do not have the capabilities for a full-scale dynamic security evaluation. Likewise, the analyst cannot execute the software implementation inside a virtual machine due to the missing peripheral hardware that is required by the software to run. In this paper, we present PROSPECT, a system that can overcome these shortcomings and enables dynamic code analysis of embedded binary code inside arbitrary analysis environments. By transparently forwarding peripheral hardware accesses from the original host system into a virtual machine, PROSPECT allows security analysts to run the embedded software implementation without the need to know which and how embedded peripheral hardware components are accessed. We evaluated PROSPECT with respect to the performance impact and conducted a case study by doing a full-scale security audit of a widely used commercial fire alarm system in the building automation domain. Our results show that PROSPECT is both practical and usable for real-world application. Markus Kammerstetter, Christian Platzer, Wolfgang Kastner |
AsiaCCS | 3 |
| 2014 | An OPC UA information model for cross-domain vertical integration in automation systemsabstractBridging the two domains of building and industrial automation systems at their management levels is a topic hardly regarded so far. Nevertheless, cross-domain integration promises significant benefits in terms of resource consumption and costs optimisation where systems of both worlds encounter each other. To this aim, this work presents an OPC UA information modelling framework providing a holistic information base for both domains. This facilitates the implementation of cross-domain management applications in the context of smart grids with the potential goals to coordinate the reuse of waste energy, to avoid peak loads and to predict energy demand. Andreas Fernbach, Wolfgang Kastner, Stefan Mätzler, Martin Wollschlaeger |
ETFA | 2 |
| 2014 | Building automation systems integration into the Internet of Things the IoT6 approach, its realization and validationabstractBuilding automation is concerned with monitoring and control of building services equipment. Over the last years, many different control network protocols have materialized for this task. Ideally, an all-in-one solution would be desired which allows total control of all conceivable scenarios. Even despite the long timespan of development, no single specific protocol has yet emerged that covers all application domains. Rather, many different protocols co-exist that rarely interact. For purposes of management-level system integration, a common, preferably open format for access to data points which is aligned with IT standards is a key asset. Following the current trends in information technology, Web Services for machine-to-machine interaction over a network seem to be a reasonable choice here. Based on them, an integration into the future Internet of Things (IoT) can be achieved. The IoT thereby promises to provide a dynamic global network infrastructure with self configuring capabilities resting upon interoperable communication protocols. This paper will focus on challenges and approaches allowing a cross-domain interaction of building automation systems while at the same time discussing their seamless integration into the IoT. Wolfgang Kastner, Mario Jerome Kofler, Markus Jung, Günther Gridling, Jürgen Weidinger |
ETFA | 1 |
| 2014 | Identifying unsecured building automation installationsabstractBuilding automation systems rely more and more on IP-based communication, which allows easier management, maintenance and, in general, interaction with other domains. When the connection to the Internet comes into play, security mechanisms need to be deployed to prevent attacks on these systems. Based on a worldwide scan of IPv4 addresses, this paper illustrates that security awareness is unfortunately still neglected. Thousands of building automation systems are directly connected to the Internet, allowing unauthenticated and unauthorized access to their underlying datapoints. Fritz Praus, Wolfgang Kastner |
ETFA | 2 |
| 2014 | Architecture-driven smart grid security managementabstractThe introduction of smart grids goes along with an extensive use of ICT technologies in order to support the integration of renewable energy sources. However, the use of ICT technologies bears risks in terms of cyber security attacks which could negatively affect the electrical power grid. These risks need to be assessed, mitigated and managed in a proper way to ensure the security of both current and future energy networks. Existing approaches have been either restricted to very specific components of the smart grid (e.g., smart meters), or provide a high-level view only. We therefore propose an architecture-driven security management approach for smart grids which goes beyond a mere abstract view without focusing too much on technical details. Our approach covers architecture modeling, risk identification and assessment as well as risk mitigation and compliance checking. We have proven the practical usability of this process together with leading manufacturers and utilities. Markus Kammerstetter, Lucie Langer, Florian Skopik, Wolfgang Kastner |
IH&MMSec | 4 |
| 2013 | Authorization as a service in smart grids: Evaluating the PaaS paradigm for XACML policy decision pointsabstractThis paper introduces an architecture offering authorization as a service for smart grids environments founding on the two standards XACML and SAML. A software prototype is deployed with the Platform as a Service (PaaS) framework Appscale. Appscale is an open source implementation of Google's App Engine framework enabling the execution of applications in a cloud environment without the need to take care of the issues arising out of the distributed computing model. Evaluation of the prototype focuses on its scalability. Load tests are run against the system in various configurations with all distributed databases offered by Appscale. The recorded results are ranging from a very unstable behavior to the awaited scalability dependent on the number of nodes used for App-scale deployment. Gregor Ryba, Markus Jung, Wolfgang Kastner |
ETFA | 3 |
| 2013 | Towards a common modeling approach for Smart Grid automationabstractCurrently, the electric energy system is experiencing major changes. Higher penetration of Distributed Generation (DG) create problems and challenges which have not been reported in the past. New and advanced Information and Communication Technologies (ICT) as well as innovative control concepts are often seen as key enablers to manage and optimize the future electric energy infrastructure. This applies also to the development of corresponding standards and information models. However, until now the focus was mostly towards the unification of communication and modeling standards, e.g., power utility automation addressed by IEC 61850 and Common Information Model (CIM). This paper focuses on the first steps towards a common modeling approach for automation concepts in Smart Grids. It proposes an automation model based on the IEC 61499 reference model for distributed automation highly integrated with the well accepted IEC 61850 interoperability approach. Filip Andren, Thomas I. Strasser, Wolfgang Kastner |
IECON | 3 |
| 2013 | Efficient group communication based on Web services for reliable control in wireless automationabstractThe ongoing demand for more energy efficiency within commercial buildings and homes is a driving motivation for using IT and IP technologies within underlying building automation systems (BAS). Building data and access to automation systems should be made available within internal and external IT systems enabling visionary cloud computing based interaction scenarios. Web services and service-oriented architectures are a promising approach to provide such a communication infrastructure. Communication protocols like CoAP and EXI enable Web service communication on embedded devices but are currently limited to a client-server interaction model with unicast based message exchange. Several existing building automation systems use a group communication approach to exchange process data, which allows to create basic control scenarios without the need of a central control unit. This group communication model for process data is strongly tied to the application layer services and information models of the according BAS. This paper presents a group communication model for CoAP and EXI based Web services, contributes further details on the implementation and provides an evaluation compared to client-server based interaction scenarios. Markus Jung, Wolfgang Kastner |
IECON | 2 |
| 2013 | A software-based redundancy concept for building automation networksabstractReliability in automation networks is an important topic. Thus, redundant communication is fundamental in this context. In contrast to other automation domains, building automation networks facilitate Ethernet and IP communication and require reliable and predictable communication that are ideally based on standard network technologies. Since automation components are often based on commonly used operating systems, software-based solutions come into play. However, pure software-based solutions are inefficient and often infeasible due to limited processing resources. Thus, a hybrid redundancy concept is proposed that facilitates standard hardware components in combination with lightweight software modules. This paper presents a new redundancy mechanism for Ethernet networks based on a ring topology. This approach makes use of VLAN-capable Ethernet switches in combination with software modules for controlling the network traffic. Thereby, VLANs are used to provide physical redundancy by preventing from Ethernet loops. The proposed concept can therefore be used on different platforms and provides a transparent and reliable communication channel for automation applications. The concept is theoretically analyzed. Finally, a proof-of-concept shows the feasibility. Lukas Krammer, Dominik Bunyai, Wolfgang Kastner |
IECON | 3 |
| 2013 | An OPC UA cross-domain information model for energy management in automation systemsabstractInteroperability between different technologies in the industrial and building domains of automation has already become a significant research topic. Extending this thought towards cross-domain interoperability, synergy effects arise from the resulting unified view to process data of both domains. This facilitates savings of energy, working time and materials. In this work a cross-domain information model aiming at this goal is proposed. Stefan Mätzler, Martin Wollschlaeger, Andreas Fernbach, Wolfgang Kastner, Michael Huschke |
IECON | 4 |
| 2013 | Efficient broadcast authentication for Wireless Sensor and Actuator NetworksabstractIn the last decade, broadcast authentication for Wireless Sensor and Actuator Networks (WSANs) has evolved to a prosperous research topic. There basically exist two different approaches to verify a message's originator. On the one hand, public-key cryptography is well-suited to sign and verify messages. However, this may not be feasible for low-cost, lowpower nodes with limited processing capabilities as can be found in WSANs. On the other hand, schemes that are based on symmetric-key cryptography require some kind of asymmetry which is crucial for broadcast authentication. Plenty of them are based on the TESLA protocol. TESLA achieves asymmetry by the use of one-way key chains with delayed disclosure of keys by requiring time synchronization. However, the authentication delay introduced by TESLA leads to some major disadvantages. This paper addresses the security demands of WSANs and proposes a broadcast authentication scheme allowing instantaneous message authentication. The basic scheme is further extended with a probabilistic model. The proposed concept is theoretically analyzed and the improvement of the security level is examined. Furthermore, storage requirements and the computational effort are investigated and compared to other approaches. Finally, a typical use case, i.e., streetlight management, is depicted. Stefan Szucsich, Lukas Krammer, Wolfgang Kastner, Thomas Novak 0001 |
IECON | 3 |
| 2013 | Shortening of product ramp-up by using a centralized knowledge baseabstractThe manufacturing industry is still struggling with predictability of quality, duration and costs for the ramp-up of new products. However, new product ramp-up becomes increasingly crucial due to further shortening of product life-cycles and the pressure on more sustainable and efficient manufacturing. In this paper, we introduce an approach based on a centralized knowledge base that comprises product and process master data, equipment structure, historical measurement results and means to apply quality management methods. The approach uses a knowledge base driven workflow that ensures knowledge exchange and reuse of existing knowledge within the production line. Based on a real-world use case from semiconductor manufacturing we evaluate how well this workflow enables knowledge reuse to guide product and process engineers to support a shift from a risky ramp-up project to a predictable ramp-up process. Roland Willmann, Estefanía Serral, Wolfgang Kastner, Stefan Biffl |
INDIN | 3 |
| 2012 | Certificate management in OPC UA applications: An evaluation of different trust modelsabstractOPC Unified Architecture (OPC UA) provides a powerful and inherent security model. These mechanisms rely on software certificates. In an automation system where OPC UA is applied, a strategy must be defined how to manage these certificates, i.e. an organised way of distribution, validation and revocation needs to be found. In general, there exist different concepts of how to achieve this goal. Moreover, there are various, in some cases platform dependent frameworks available which assist the developer in implementing a suitable concept. The aim of this paper is to give an overview of these concepts and frameworks and discuss their positive and negative aspects depending on the structure of different environments in which OPC UA applications shall be embedded. Andreas Fernbach, Wolfgang Kastner |
ETFA | 2 |
| 2012 | An ISA88 Phase in IEC 61131-3 code based on the concepts of a Normalized flow elementabstractEvolvability is one of the most desirable non-functional requirements of software architectures. In the area of automation control, the permanent shift of the requirements and the prevention of side-effects are key points. In addition, adaptability and flexibility in manufacturing systems continue to gain importance. This paper proposes an approach to achieve evolvability in IEC 61131-3 based software modules, from a structural point of view, i.e., starting from an individual line of code. We based our design of an evolvable ISA88 Equipment Phase on the Normalized Systems theory recently introduced. It seems indeed possible to develop evolvable IEC 61131-3 based modules with the existing, commercially available development environments. However, our guidelines require a disciplined programming style in extending software, based on a limited set of anticipated changes. Dirk van der Linden, Wolfgang Kastner, Herwig Mannaert |
ETFA | 2 |
| 2012 | Information model for distributed traffic management applicationsabstractToday's Traffic Management Systems (TMS) are widely used in urban and interurban environments. Due to the rising amount of traffic, TMS were deployed to smooth every day traffic flow. Current TMS follow a strictly centralized and hierarchical approach. This approach as well as the heterogeneous connection of sensors and actuators cause higher installation costs and limit the flexibility of the system. This paper introduces a generic information model for sensors and actuators used in TMS that allows a decentralized approach with autonomously cooperating sensors and actuators at field level. For this purpose, the information modeling scheme of ZigBee, a widely used wireless standard, is used. However, the proposed model can also be applied to wired applications. Finally, practical sample applications are presented, illustrating specific parts of the information model. Stefan Szucsich, Lukas Krammer, Wolfgang Kastner, Thomas Novak 0001 |
ETFA | 3 |
| 2012 | Detecting user dissatisfaction in ambient intelligence environmentsabstractOne of the reasons that explains the slow uptake of smart home technologies has been addressed several times due to a lack of designs better aware of usability and the real context when families experience their daily life. The present paper introduces a system model for ambient intelligence (AmI) environments that boosts a friendly system-user's adaptation. To that end, system self-checking capabilities based on the detection of levels of user dissatisfaction or disagreement are developed. Félix Iglesias, Wolfgang Kastner |
ETFA | 2 |
| 2012 | Limiting constraints for ZigBee networksabstractWireless communication has many interesting applications in the field of home and building automation. Besides proprietary solutions of different vendors, ZigBee has gained acceptance in this domain. Since in particular in building automation a high amount of nodes needs to be covered, the question about the applicability of ZigBee for large networks may arise. For this reason, this paper analyzes the constraints regarding ZigBee's network size. Furthermore, relations to other automation domains are established, where the proposed concepts can be used too. Starting with a scalable and regular network structure, the limits of ZigBee are figured out analytically. This analysis is then backed up by the results of an OMNeT++ simulation. Moreover, the simulation allows reasoning on further performance-related criteria for ZigBee networks. Dominik Bunyai, Lukas Krammer, Wolfgang Kastner |
IECON | 3 |
| 2011 | Interoperability at the management level of building automation systems: A case study for BACnet and OPC UAabstractIn modern building automation systems a plethora of different networking technologies exists. Therefore, interoperability between devices using various technologies is a key requirement. The use of Web Services as a platform-and technological-independent method of communication is a promising approach to address this challenge. Since IP extensions to available technologies are more and more established in building automation systems the network infrastructure and necessary protocols for Web Services communication are already present. However, providing appropriate concepts to model information that can be accessed in a generic way are still missing. OPC Unified Architecture (OPC UA) is a powerful and promising standard that aims at solving this challenge. This work discusses an approach to map the interworking model of BACnet to OPC UA. Using the resulting information model BACnet applications can be represented in OPC UA and, thus, be accessed by OPC UA clients in a standard and well-defined way. Andreas Fernbach, Wolfgang Granzer, Wolfgang Kastner |
ETFA | 3 |
| 2011 | An OPC UA interface for an evolvable ISA88 control moduleabstractNormalized systems theory has recently been proposed to engineer evolvable information systems. This theory includes a potential of improvement in control software for the automation of production systems. This paper aims at contributing towards evolvable and therefore easy-to-maintain control software. We introduce IEC 61131-3 code which complies with the theorems of normalized systems, forming a building block which complies with the model of an ISA88 control module, accessible via an OPC UA interface. Since OPC UA brings control software to a new level, it enables original intra-process projects to interoperate in an inter-process context. OPC UA offers new possibilities for system integration, but might also lead to a larger impact of evolvability problems. Dirk van der Linden, Herwig Mannaert, Wolfgang Kastner, Vincent Vanderputten, Herbert Peremans, Jan Verelst |
ETFA | 3 |
| 2011 | Integrating CCTV systems into BACnetabstractClosed-Circuit Television (CCTV) systems are used in modern buildings for different purposes. By the use of smart cameras, dedicated safety or security-critical events that may lead to an alarm condition can be detected autonomously (e.g., safety events like fire or security events like glass break). Integrating CCTV systems into building automation systems provides the opportunity to react to critical events by, for example, informing the operator about the occurrence of such events, providing relevant video data, and most important concurrently initiating appropriate actions (e.g., smoke extraction in case of fire). This paper focuses on the integration of such smart camera systems into BACnet based networks. At first, a short introduction to BACnet and its interworking model is given. Afterwards, a possible way of integrating CCTV systems into BACnet is presented. The functionality of this model is shown by a proof-of-concept implementation which is also described in this paper. Christian Mauser, Wolfgang Granzer, Wolfgang Kastner |
ETFA | 3 |
| 2011 | Procedure-based availability SLAs for Traffic Management SystemsabstractToday's Traffic Management Systems (TMS) shall meet various demands. One of them is availability of service. Failures in the system reduce the level of availability and have direct impact on the total cost of ownership (TCO) because of additional maintenance costs. Consequently, parameters of availability of service are often subject of contracts (so called Service Level Agreements) among system owners, maintenance contractors and component vendors. With the growing complexity of such multi-vendor systems consisting of various subsystems and components interconnected over numerous levels of hierarchy, enforcement of these agreements is becoming a challenging and complex task. Thus, procedure-based reasoning concepts are required in order to correctly map the gathered low-level resource metrics like the liveness of a particular component to the root-cause of the problem from a system perspective and consequently the right application specific SLA-parameters (such as availability of a node or a network). In this paper, we demonstrate the application of the LoM2HiS-framework as an example technology for the automatic enforcement of SLAs concerning availability in the field of TMS. It is illustrated, how the framework could be extended for procedure-based reasoning. Finally, we present first simulation results. Christoph Stögerer, Thomas Novak 0001, Wolfgang Kastner, Lukas Krammer |
ETFA | 3 |
| 2011 | Impact of user habits in smart home controlabstractLifestyle and habits of users have a direct effect on the energy performance of dwellings and facilities. Hence, in the built environment, advanced control strategies must adapt to user behaviors trying to keep a commitment between energy consumption and comfort requirements. In previous works, the suitability of predictive control based on occupancy profiles for the optimization of HVAC systems has been shown. Resting upon this basis, the present work performs a sensitivity analysis for control strategies based on usage profiles, where the input under variation is the level of habit-regularity of users. Therefore, different hypothetical user models are created and tested. The results of this analysis provide a better understanding of how user behavior affects the energy and comfort performance in dwellings under smart control and paves the way for enhanced controller design. Félix Iglesias, Wolfgang Kastner, Christian Reinisch |
ETFA | 2 |
| 2010 | Distributed monitoring for component-based traffic management systemsabstractEmbedded software in the field of traffic management and control systems has an increasing demand on availability. Typically in case of a failure, hardware circuit watchdogs reset the whole system targeting the goal, that after some acceptable time the system is up and the applications are running correctly again. Also software-based monitoring solutions implementing standard patterns like the Watchdog Pattern, the Safety Executive Pattern or extensions to it might be applied. As these patterns target monitoring of components on a single node, extensions for monitoring distributed components using WBEM-technology for distributed monitoring will be shown. For a proof-of-concept implementation the Windows Management Instrumentation has been applied. Christoph Stögerer, Wolfgang Kastner |
ETFA | 2 |
| 2010 | Usage profiles for sustainable buildingsabstractThe ultimate goal of sustainable homes and buildings is to work towards energy efficiency automatically taking into account user comfort always acknowledging the residents' desires. Such environments demand for a friendly coexistence between technology and usability to assure an optimized reality in terms of comfort, economic and energy savings. The ThinkHome project is geared towards this mission. It aims at exploiting automation systems and mechanisms based on artificial intelligence to further improve the sustainability of buildings. ThinkHome is designed in a way to relieve the smart home inhabitants from cumbersome tasks such as readjustments of their preferences by introducing learning capabilities and context awareness in the home. Part of the ThinkHome project, this paper proposes an advanced use case for energy savings. It involves the necessity of defining usage profiles which help the underlying system to be aware about the stability of users' behaviors and perform its strategies always with sustainable goals in mind. Félix Iglesias, Wolfgang Kastner |
ETFA | 2 |
| 2010 | Security Analysis of Open Building Automation Systems
Wolfgang Granzer, Wolfgang Kastner |
SAFECOMP | 2 |
| 2009 | Functional Safety in Building AutomationabstractBuilding automation systems comprise services to automatically control, monitor and manage buildings with key areas being heating, ventilation, and air conditioning, lighting and shading. Typically, they do not provide safety-related services that are handled in a stand-alone fashion. However, a tight integration should allow the sharing of transmission path and the possibility of message exchange between the different application domains (e.g., lighting and fire alarm). Still, the integrity and adequate performance of all integrated applications must be assured. This paper surveys general safety standards and application dependent standards and points out what requirements have to be met by a safety-related building automation technology. The focus is on fire alarm and social alarm systems, due to their prevalence in today's buildings. Without question, demands in these domains are high and a challenge to meet. For this reason, the paper concludes with the proposal for a safety enhancement for KNX/EIB. Wolfgang Kastner, Thomas Novak 0001 |
ETFA | 1 |
| 2009 | System Management Standards for Traffic Management SystemsabstractToday's traffic management systems require interoperability of control units from different vendors on manifold communication infrastructures. The management of these control units is getting a complex task as different vendors supply proprietary management instrumentations (e. g. for uploading new firmware, update of contents, configuration, diagnostics and troubleshooting). A standardized data model and communication interface provides new possibilities for system owners and simplifies engineering for maintenance personnel. Additional to novel functional opportunities, a decrease in operative costs can be expected because of eased troubleshooting and update tasks. This paper summarizes the state of the art of existing application management standards and shows their applicability for the domain of traffic management systems. Christoph Stögerer, Wolfgang Kastner |
ETFA | 2 |
| 2009 | Securing IP backbones in building automation networksabstractThe use of IP networks as common backbone is becoming of increased interest in today's building automation systems (BAS). With the use of IP also new attack scenarios that threaten the overall security of BAS are introduced. Due to the absence of native security mechanisms in IP and because of its long standing and pervasive use in the IT world, many vulnerabilities exist that are well-known to attackers. To counteract these threats, this paper presents a generic concept to secure IP backbones that is tailored to the use in building automation. A main advantage of the concept is its flexibility. Due to the used protocol architecture, it is applicable to available BAS standards without the need of an adaption of existing BAS protocols. As a proof-of-concept, a prototype implementation for the KNX standard is also presented. Wolfgang Granzer, Daniel Lechner, Fritz Praus, Wolfgang Kastner |
INDIN | 4 |
| 2009 | Enhanced control application development in Building AutomationabstractBuilding automation systems (BAS) lack a common application model. Thus, the development of control applications (CAs) is not a very straightforward task and requires profound expertise. When in addition security has to be considered, inexperienced developers are overwhelmed by the manifold demands and constraints. This paper presents an approach to ease the CA development and at the same time to provide security for their execution. The main idea is to base the application model on a generic ontology and to provide a sandbox for the execution environment. The programming concept, configuration and management issues as well as the workflow are described in detail. Finally, a proof of concept for BACnet and KNX is given. Fritz Praus, Wolfgang Granzer, Wolfgang Kastner |
INDIN | 3 |
| 2008 | Denial-of-service in automation systemsabstractSecurity aspects of todaypsilas automation systems gain increasing importance. One critical point regarding security is the exchange of control data over the network. Recently, cryptographic techniques have been developed that can protect the transmitted data against a malicious interference. However, there are security threats which cannot be prevented using cryptographic techniques. Typical representatives are denial-of-service (DoS) attacks. Therefore, this paper presents a novel, generic approach how such DoS attacks can be prevented or, if prevention is not possible, can be detected at least. Wolfgang Granzer, Christian Reinisch, Wolfgang Kastner |
ETFA | 3 |
| 2008 | Secure and customizable software applications in embedded networksabstractImproved technology and economically feasible costs allow a widespread deployment of embedded systems in various application domains - ranging from integration into cars, industrial automation up to building automation. A sophisticated security architecture considering the challenging constraints on these systems and providing secure communication, secure software as well as physical security is needed. This paper presents an approach to allow untrusted, possible (intentional) malicious software to be executed securely on a low end embedded system. A proof of concept and an evaluation for a building automation system is given. Fritz Praus, Thomas Flanitzer, Wolfgang Kastner |
ETFA | 3 |
| 2008 | Extending the Watchdog Pattern for multi-threaded windows based traffic management and control applicationsabstractApplications in the field of traffic management and control systems have an increasing demand on availability. Typically, hardware circuit watchdogs reset the whole system in case of failure targeting the goal, that after some acceptable time the system is up and the applications are running correctly again. Depending on the hardware and operating systems used, this can take a reasonable time. Software-based monitoring solutions have the ability to restart only faulty software components which shortens recovery duration. Normally, they implement standard-patterns like the watchdog pattern or safety executive pattern. As these patterns are primarily targeting the monitoring of components two approaches for monitoring threads and the activity of every component involved are presented in this paper. Christoph Stögerer, Wolfgang Kastner |
ETFA | 2 |
| 2007 | Multicast communication in wireless home and building automation: ZigBee and DCMPabstractWith an ever increasing performance, wireless technologies present a more and more attractive alternative to wired media. This is also true for home and building automation (HBA) systems. In HBA, large areas must be covered at low cost. This precludes the use of dedicated network infrastructure. At the same time, the allowable power consumption and thus transmission power of sensors in particular is severely restricted. Hence, efficient peer-to-peer communication schemes are required. Especially for multicast communication, optimized protocols can make a difference. Therefore, this paper shows how DCMP (dynamic core based multicast routing protocol for ad hoc wireless networks) can be used to improve multicast in ZigBee networks. Christian Reinisch, Wolfgang Kastner, Georg Neugschwandtner |
ETFA | 2 |
| 2005 | Programming fieldbus nodes: a RAD approach to customizable applicationsabstractThe European installation bus (EIB), part of the KNX standard, is a field bus for home and building automation. Bus coupling units (BCUs) provide a generic platform for embedded nodes based on the M68HC05 microcontroller family. A set of open source tools for developing and downloading BCU programs based on the GNU tool chain is presented. It uses a RAD-like (rapid application development) approach. The tool set also supports separating application development and deployment and includes a multi-user and network-capable daemon for EIB access and network management. Issues in porting the GNU C compiler to the target platform are highlighted Georg Neugschwandtner, Wolfgang Kastner, Martin Kögler |
ETFA | 2 |
| 2005 | Communication systems for building automation and controlabstractBuilding automation systems (BAS) provide automatic control of the conditions of indoor environments. The historical root and still core domain of BAS is the automation of heating, ventilation and air-conditioning systems in large functional buildings. Their primary goal is to realize significant savings in energy and reduce cost. Yet the reach of BAS has extended to include information from all kinds of building systems, working toward the goal of "intelligent buildings". Since these systems are diverse by tradition, integration issues are of particular importance. When compared with the field of industrial automation, building automation exhibits specific, differing characteristics. The present paper introduces the task of building automation and the systems and communications infrastructure necessary to address it. Basic requirements are covered as well as standard application models and typical services. An overview of relevant standards is given, including BACnet, LonWorks and EIB/KNX as open systems of key significance in the building automation domain. Wolfgang Kastner, Georg Neugschwandtner, Stefan Soucek, H. Michael Newman |
Proc. IEEE | 1 |
| 2001 | How dynamic networks work: A short tutorial on spontaneous networksabstractThe current race of the information technology society to connect any device to higher networks (e.g. to the Internet), has led to various applications that were unbelievable a couple of years ago. Unfortunately, with all the increasing amount of connectivity, setup, configuration and handling of electronic devices has become more and more complex and often today's users are overwhelmed by functionality and required knowledge. To solve this problem, industry has turned to create intelligent devices, that do the interconnection work almost automatically and, therefore, are able to connect to so-called dynamic networks. At the very moment, some competitive approaches try to fight this challenge with common concepts behind, but slightly different technologies used. This paper starts with a short motivation why dynamic networks could be of interest for factory automation systems, too. Afterwards, we provide a tutorial on up-to-date spontaneous networks. We start with an insight into the approach proposed by Sun Microsystems, called Java Intelligent Network Infrastructure, followed by a quick overview on Microsoft's approach, called Universal Plug and Play. Next, a proposed standard for wireless communication, called Blue-tooth, is presented. Finally, we show some dynamic features of the well-known Common Object Request Broker Architecture. Wolfgang Kastner, Markus Leupold |
ETFA (1) | 1 |