0% found this document useful (0 votes)
26 views4 pages

Security Guidelines for RAMI4.0

Security is an integral part of RAMI4.0 that applies across all levels and aspects of the reference architecture model. It must be considered for objects/assets at each stage of the life cycle from design through production, usage and maintenance. A risk analysis is required to determine the appropriate security measures needed for individual components and the overall system based on the hierarchy and value stream axes. 'Security by design' means incorporating security systematically from the start of the development process through implementation and usage.

Uploaded by

papi charca
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
26 views4 pages

Security Guidelines for RAMI4.0

Security is an integral part of RAMI4.0 that applies across all levels and aspects of the reference architecture model. It must be considered for objects/assets at each stage of the life cycle from design through production, usage and maintenance. A risk analysis is required to determine the appropriate security measures needed for individual components and the overall system based on the hierarchy and value stream axes. 'Security by design' means incorporating security systematically from the start of the development process through implementation and usage.

Uploaded by

papi charca
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

GUIDELINE

Security in RAMI4.0
The many new opportunities that are opened up by of three axes1. This structure allows the relevant aspect of a
Industrie 4.0 also bring a host of different challenges. particular asset to be shown at every point in time along
‘Security by design’, for example, becomes an indispens­ its life cycle, thus allowing complex interrelationships to
able element in design within Industrie 4.0. In many cases, be broken down into smaller, clearer sections. The three
security will be the enabler of new business models. axes are as follows:

Security acts as a skeleton that carries and holds together ●● Architecture axis (layers) – made up of six different
all of the structural elements within RAMI4.0 and, as a layers indicating the information depending the view
result, the design of the Industrie 4.0 component. This to the asset;
paper seeks to provide the reader with a clear overview
of the various security aspects within RAMI4.0. Various ●● Process axis (value stream) – depicts the various stages
security measures are explored using a range of examples within the life of an asset and the value creation pro­
that are built upon on all three of the RAMI4.0 axes. cess based on IEC 62890;

RAMI4.0 – Reference architecture model for ●● Hierarchy axis (hierarchy levels) – assigns the func­
Industrie 4.0 tional models to individual levels based on DIN EN
62264-1 and DIN EN 61512-1.
RAMI4.0 describes the key elements of an object/asset
based upon the use of a structured layer model consisting

Reference architecture model for Industrie 4.0

els
Layers: Layers Life Cy
cl hy Lev 2 Hierarchy Levels:
Security applies to all of IEC 62 e Value Stre rarc 151 All objects/assets are
890 am Hie //IEC 6
the different levels. Risks 64 subjected to security
Business
622
must be considered for the
Functional
IEC considerations (risk
object/asset as a whole. analysis) and need to
Information possess or provide
Communication
the relevant security
Value Stream: characteristics for
Integration fulfilling their tasks/
The owner of the object
must consider security Asset Con providing protection.
Enterp nected Wor
across its entire life-cycle. Work rise ld
Devel
Statio Cente
opm
ent Main n rs
ten Con
Field D trol Device
Usagance
e
Type Prod
uctio
n Main Produ evice
ten
Usagance
e
ct
Instan
ce

Source: Plattform Industrie 4.0 and ZVEI


As can be seen from the figure, security is embedded within granted and to manage a number of different machines,
RAMI4.0 and has an integral nature within the model. It is to transmit the relevant contracts securely, and to monitor
not depicted as an individual layer or hierarchy level, but which jobs have been completed.
impacts upon the whole life-cycle within all layers and at
all hierarchy levels. Like the use of steel for reinforcing a Value Stream
building, security ensures the stability of RAMI4.0 and pro­
tects against potential attacks. Security applies to the whole of the life-cycle which, in
RAMI4.0, is represented by the process axis. This axis com­
Hierarchy Levels prises the design stage, moving on to production, imple­
mentation, and usage and maintenance of the object/asset.
The hierarchy axis essentially maps the automation pyra­
mid, depicting the various different components, the ‘Security by design’ concerns all of the different actors
product, and the outside world (connected world). The involved – the manufacturer, the integrator, as well as the
type and extent of protection needed must be determined asset owner, in accordance with the type of responsibility
for both the individual elements, and for the system as a held. While defining standards and developing compo­
whole. In the first instance, this requires a risk analysis nents, security needs to be planned right from the very
which includes a diagnosis of threats and potential. The start and to be provided in line with needs. This applies to
results of this analysis will be the basis for the election of both technical and organisational measures (processes).
the security measures that are need to be undertaken in
order to protect the individual Industrie 4.0 component. Right from the planning process, it is vital to factor in the
security functions that are shown to be necessary based
Let us take a machine (station) in a production or process on risk analysis or requirements by other components.
environment (work unit) as an example. The machine During the development and production process, a con­
must be able to process relevant materials correctly and sistent method for avoiding errors must be used, e. g. fol­
without disruption. It must also be able to protect process lowing the Security Development Lifecycle (SDL) devel­
logic against unauthorised changes, access or readouts. oped by Microsoft2.

Machine operators need to be able to identify themselves, When using components and systems, not only existing
giving rise to the need for an authorisation concept that security requirements need to be met, but any potential
enables various different types of intervention to be speci­ weaknesses in operation also need to be eliminated. Any
fied. updates that are required must be developed, passed on,
and integrated on time.
At the level of the production environment, the key task is
to manage staff and the authorisation rights that have been

1 Reference architecture model Industrie 4.0 (RAMI4.0). DIN SPEC 91345.


2 [Link]
Layers application in question. Manufacturers, integrators, and
asset owners are all called upon to implement a holistic
While identifying security requirements, the six layers of security concept that brings technical and organisa­
the architecture axis enable various different aspects of tional measures together. Using RAMI4.0 as a basis for
an object/asset to be considered in a systematic manner. designing security enables every kind of security
For example, this applies to the layers of communication requirement to be implemented for any conceivable
and business as follows. By an analysis of the business application.
models the relevant security threats and security require­
ments will be identified. Thus, at the communication As part of this process, RAMI4.0 enables existing security
layer, measures may be needed to encrypt data based on standards to be integrated, especially VDI/VDE 2182
secure identities. For the decision which communication and IEC 62443. The VDI/VDE 2182 standard addresses
links have to be protected, e. g. by encryption, it must be such issues as feedback on the requirements from the
clear, what information shall be transmitted via these various actors that are part of the process. This standard
links. describes communication between the manufacturer,
integrator, and asset owner as a key element within
Working together with others security, thus enabling the relevant requirements to be
passed on and implemented. IEC 62443 outlines a refer­
Security plays a role at all points of intersection between ence model for industrial communication networks and
the various levels. This means that requirements are sets out how this can be used to raise security require­
derived for every point of intersection by a specific ments and identify security technologies. Both VDI/VDE
analysis. A solution must then be found for each of 2182 and IEC 62443 provide support for a holistic secu­
these requirements based on the relevant capabilities of rity concept which can be assessed by using ‘protection
the Industrie 4.0 components involved in the specific levels’.

AUTHORS:
Michael Jochem, Robert Bosch GmbH | Wolfgang Klasen, Siemens AG | Lukas Linke, ZVEI | Lutz Jaenicke, Phoenix
Contact Cybersecurity AG | Thomas Gamer, ABB AG | Mario Stolz, NXP Semiconductors Germany GmbH | Jens
Mehrfeld, Bundesamt für Sicherheit in der Informationstechnik | Andreas Teuscher, Sick AG | Wolfgang Fritsche,
IABG GmbH

Imprint
Published by Text and editing Design and production Status
Federal Ministry for Economic Plattform Industrie 4.0 PRpetuum GmbH, Munich April 2016
Affairs and Energy (BMWi) Bertolt-Brecht-Platz 3
10117 Berlin
Illustrations
Public Relations
GKSD – Fotolia
11019 Berlin, Germany
[Link]

You might also like