What Is IEC 62443 for Industrial Systems?
来源:微芯发布时间:2023-09-271317浏览
询问 AIDiscover how the IEC 62443 security standard for Industrial IoT (IIoT) or Industry 4.0 applies to secure elements and how it affects embedded products.
Watch the video.
The IEC 62443 is a cyber security standard for the industrial market that affects how semiconductor devices are selected. The following questions and answers come from our Ask Our Experts | About Secure Elements playlist on YouTube.
Can you give us a quickoverview of the IEC 62443 standard?
IEC 62443 is a specification thatis targeted at the industrial market. It is a document that is nearly 900 pageslong, which can be a little daunting, but it’s narrowly focused on the industrialautomation and control systems market. Virtually all of the major players in this space haveadopted it, beginning in the twenty-teens and now into 2020 and beyond. So, thisspecification has been maturing over time.
Those 900 pages are brokenup into four major sections. First, you have your general section which coversterms, a glossary, and an overview of security topics.
Next is policies and procedures; withinpolicies and procedures, they actually define different levels of security. Levelzero is no security at all; level one is protections against accidental errorsthat you may have designed in your system; level two is based on simplesorts of attacks, but intentional attacks on your device, using basically a moderate levelof resources and access to design databases or documentation related to that specificproduct. Then it moves to level four, which also uses sophisticated attack methods, butalso increases the level of knowledge; so you would have somebody that is very knowledgeable about the design ofthe platform and using sophisticated attacks.
As wemove from policies and procedures, now we go to system level, which is where things getinteresting for our customers, where they have to be concerned about those devices actuallyattaching to a network. In those sorts of areas, they'll define some risksassociated with their particular node. You may determine a variety of ways that a hacker may tryand attack a node, and if they do attack a node and they're successful there, you can explore what othernodes might they have success attacking; it is sort of an attack tree analysis.
Thenat the component level, that is really where silicon products come in, and that is where wecan help our customers select the right device like our CryptoAuthentication™ ECC family orCryptoAutomotive™ Trust Anchor security ICs as well, and we can help them satisfy all theserequirements. We ourselves have our own risks and vulnerabilities that have been defined indocuments like the Attack Potential to Smartcards Version 3.1 and beyond, where they've identifiedthe types of attacks that are known that you should protect against, which we have and wehave third-party assessments to prove that.
To help our customers withthat selection, we've also put together an application note and a blog post that highlights someof the vulnerabilities that have been defined in these sets of IEC 62443 documentation, where wecan identify how a specific feature of a device can be associated with the spec and help themimplement and prove compliance to IEC 62443.
Want More?
Make sure to read our blog post on IEC 62443. For more information, check out our Ask Our Experts | About Secure Elements playlist on YouTube and ourSecure Elementsweb page.
Support at Every Step
We arecommitted topartneringwith you andmakingsure you have what you need to succeed.
About
Support
Quick Links
Microchip Technology Inc.
2355 West Chandler Blvd.
Chandler, Arizona, USA
新闻来源:微芯,文中所述为作者独立观点,不代表icspec立场。更多精彩资讯请下载icspec App。如对本稿件有异议,请联系微信客服specltkj。