Faculty of Computing and Informatics, Universiti Malaysia Sabah, Kota Kinabalu 88400, Sabah, Malaysia.
School of Computer Science, Universiti Sains Malaysia, Gelugor 11900, Penang, Malaysia.
Sensors (Basel). 2021 Oct 6;21(19):6647. doi: 10.3390/s21196647.
The inherent complexities of Industrial Internet of Things (IIoT) architecture make its security and privacy issues becoming critically challenging. Numerous surveys have been published to review IoT security issues and challenges. The studies gave a general overview of IIoT security threats or a detailed analysis that explicitly focuses on specific technologies. However, recent studies fail to analyze the gap between security requirements of these technologies and their deployed countermeasure in the industry recently. Whether recent industry countermeasure is still adequate to address the security challenges of IIoT environment are questionable. This article presents a comprehensive survey of IIoT security and provides insight into today's industry countermeasure, current research proposals and ongoing challenges. We classify IIoT technologies into the four-layer security architecture, examine the deployed countermeasure based on CIA+ security requirements, report the deficiencies of today's countermeasure, and highlight the remaining open issues and challenges. As no single solution can fix the entire IIoT ecosystem, IIoT security architecture with a higher abstraction level using the bottom-up approach is needed. Moving towards a data-centric approach that assures data protection whenever and wherever it goes could potentially solve the challenges of industry deployment.
工业物联网 (IIoT) 架构固有的复杂性使其安全和隐私问题成为极具挑战性的问题。已经发表了许多调查来审查物联网安全问题和挑战。这些研究提供了对 IIoT 安全威胁的总体概述,或者对明确关注特定技术的详细分析。然而,最近的研究未能分析这些技术的安全要求与其在行业中的部署对策之间的差距。最近的行业对策是否仍然足以应对 IIoT 环境的安全挑战是值得怀疑的。本文对 IIoT 安全进行了全面调查,并深入了解当今的行业对策、当前的研究提案和正在面临的挑战。我们将 IIoT 技术分为四层安全架构,根据 CIA+安全要求检查部署的对策,报告当今对策的不足,并突出剩余的未决问题和挑战。由于没有单一的解决方案可以解决整个 IIoT 生态系统,因此需要使用自下而上的方法构建具有更高抽象级别的 IIoT 安全架构。转向以数据为中心的方法,无论数据在何处以及何时使用,都可以确保数据保护,这可能会解决行业部署的挑战。