Authors:
Ludwig Seitz
1
;
Marco Tiloca
2
;
Martin Gunnarsson
2
and
Rikard Höglund
2
Affiliations:
1
Combitech AB, Malmö, Sweden
;
2
Cybersecurity Unit, RISE Research Institutes of Sweden, Sweden
Keyword(s):
Security, Software Update, Industrial Control Systems, Internet of Things.
Abstract:
This paper analyzes the problem and requirements of securely distributing software updates over the Internet, to devices in an Industrial Control System (ICS) and more generally in Internet of Things (IoT) infrastructures controlling a physical system, such as power grids and water supply systems. We present a novel approach that allows to securely distribute software updates of different types, e.g., device firmware and customer applications, and from sources of different type, e.g., device operators, device manufacturers and third-party library providers. Unlike previous works on this topic, our approach keeps the device operator in control of the update process, while ensuring both authenticity and confidentiality of the distributed software updates.