Madtls: Fine-grained Middlebox-aware End-to-end Security for Industrial Communication

Industrial control systems increasingly rely on middlebox functionality such as intrusion detection or in-network processing. However, traditional end-to-end security protocols interfere with the necessary access to in-flight data. While recent work on middlebox-aware end-to-end security protocols for the traditional Internet promises to address the dilemma between end-to-end security guarantees and middleboxes, the current state-of-the-art lacks critical features for industrial communication. Most importantly, industrial settings require fine-grained access control for middleboxes to truly operate in a least-privilege mode....

Eric Wagner, David Heye, Martin Serror, Ike Kunze, Klaus Wehrle, Martin Henze