Tomas Lindström

dblp:274/1858 · DBLP profile ↗
← Back
5ranked-venue papers
0as first author
5since 2021 · last 2024
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 4 · 4 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2024 Redundancy Link Security Analysis: An Automation Industry Perspective
abstract
Industrial automation and control systems are responsible for running our most important infrastructures, providing electricity and clean water, producing medicine and food, along with many other services and products we take for granted. The safe and secure operation of these systems is therefore of great importance. Reliability is a fundamental requirement, with spatial controller redundancy being one important fault-tolerance mechanism. In current control system solutions, controller redundancy is implemented using state and heartbeat transfer communicated over dedicated physical links, based on an assumption of implicit trust. However, with the emerging network-centric control strategies there is a desire to transition into dynamic redundancy scenarios, where such dedicated links are unfeasible. In this paper, an approach for a threat-model based security analysis is presented from the perspective of the automation industry. The approach is applied to the communication links used for supporting control system redundancy within a network-centric architecture.
Björn Leander, Bjarne Johansson, Saad Mubeen, Mohammad Ashjaei, Tomas Lindström
ETFA5
2023 Dependability and Security Aspects of Network-Centric Control
abstract
Industrial automation and control systems are responsible for running our most important infrastructures, providing electricity and clean water, producing medicine and food, along with many other services and products we take for granted. The safe and secure operation of these systems is therefore of great importance.One of the emerging trends in industrial automation systems is the transition from static hierarchical controller-centric systems to flexible network-centric systems. This transition has a great impact on the characteristics of industrial automation systems. In this article we describe the network-centric design strategy for industrial automation systems and describe the impact on dependability and security aspects that this strategy brings, looking at both challenges and possibilities.
Björn Leander, Bjarne Johansson, Tomas Lindström, Olof Holmgren, Thomas Nolte, Alessandro Vittorio Papadopoulos
ETFA3
2023 Access Control Enforcement Architectures for Dynamic Manufacturing Systems
abstract
Industrial control systems are undergoing a trans-formation driven by business requirements as well as technical advances, aiming towards increased connectivity, flexibility and high level of modularity, that implies a need to revise existing cybersecurity measures. Access control, being one of the major security mechanisms in any system, is largely affected by these advances.In this article we investigate access control enforcement architectures, aiming at the principle of least privilege1in dynamically changing access control scenarios of dynamic manufacturing systems. Several approaches for permission delegation of dynamic access control policy decisions are described. We present an implementation using the most promising combination of architecture and delegation mechanism for which available industrial standards are applicable.
Björn Leander, Aida Causevic, Tomas Lindström, Hans A. Hansson
ICSA3
2022 Simulation Environment for Modular Automation Systems
abstract
When developing products or performing experimental research studies, the simulation of physical or logical systems is of great importance for evaluation and verification purposes. For research-, and development-related distributed control systems, there is a need to simulate common physical environments with separate interconnected modules independently controlled, and orchestrated using standardized network communication protocols.The simulation environment presented in this paper is a bespoke solution precisely for these conditions, based on the Modular Automation design strategy. It allows easy configuration and combination of simple modules into complex production processes, with support for individual low-level control of modules, as well as recipe-orchestration for high-level coordination. The use of the environment is exemplified in a configuration of a modular ice-cream factory, used for cybersecurity-related research.
Björn Leander, Tijana Markovic, Aida Causevic, Tomas Lindström, Hans A. Hansson, Sasikumar Punnekkat
IECON4
2021 A Questionnaire Study on the Use of Access Control in Industrial Systems
abstract
Industrial systems have traditionally been kept isolated from external networks. However, business benefits are pushing for a convergence between the industrial systems and new information technology environments such as cloud computing, as well as higher level of connectivity between different systems. This makes cybersecurity a growing concern for industrial systems. In strengthening security, access control is a fundamental mechanisms for providing security in these systems. However, access control is relatively immature in traditional industrial systems, as compared to modern IT systems, and organizations' adherence to an established cybersecurity standard or guideline can be a deciding factor for choices of access control techniques used. This paper presents the results of a questionnaire study on the usage of access control within industrial system that are being developed, serviced or operated by Swedish organizations, contrasted to their usage of cybersecurity standards and guidelines. To be precise, the article focuses on two fundamental requirements of cybersecurity: identification and authentication control, and presents related findings based on a survey of the Swedish industry. The goal of the study is breaching the gap between the current state and the requirements of emerging systems with regards to access control.
Björn Leander, Aida Causevic, Tomas Lindström, Hans A. Hansson
ETFA3