KIT | KIT-Bibliothek | Impressum | Datenschutz

PGB-PKI: A Module-Internal Decentralized PKI for Modular Automation

Madsen, Marwin ORCID iD icon 1; Vater, Malte; Barth, Mike ORCID iD icon 1
1 Institut für Regelungs- und Steuerungssysteme (IRS), Karlsruher Institut für Technologie (KIT)

Abstract (englisch):

Field-level certificate management in industrial automation remains dominated by centralized and largely protocol-specific trust architectures. This conflicts with modular and flexible production systems, where heterogeneous devices inside a Production Gray Box (PGB) may require certificate-based lifecycle operations without direct access to an operator-side public key infrastructure (PKI). This paper presents a Chord-based overlay for protocol-agnostic certificate management that embeds a decentralized PKI into the PGB through threshold operations and a separate admission trust anchor for post-lock device admission. It defines a modular-automation-specific lifecycle covering bootstrapping, distributed key generation, local device identifier issuance, locking, and additional device admission. A prototype provides qualitative evidence that these steps can be executed inside a PGB without depending on operator-side PKI.


Zugehörige Institution(en) am KIT Institut für Regelungs- und Steuerungssysteme (IRS)
Publikationstyp Proceedingsbeitrag
Publikationsdatum 08.09.2026
Sprache Englisch
Identifikator KITopen-ID: 1000194199
Erschienen in 31st IEEE International Conference on Emerging Technologies and Factory Automation (ETFA 2026)
Veranstaltung 31st IEEE International Conference on Emerging Technologies and Factory Automation (ETFA 2026), Västerås, Schweden, 08.09.2026 – 11.09.2026
Verlag Institute of Electrical and Electronics Engineers (IEEE)
Bemerkung zur Veröffentlichung in Press
KIT – Die Universität in der Helmholtz-Gemeinschaft
KITopen Landing Page