PI White Paper: Security Extensions for PROFINET



Within the scope of the far-reaching digitization of production processes, the IT security of pro-duction plants is gaining in importance. The pervasive networking in companies, the vertical in-tegration and the trend toward flatter system hierarchies require comprehensive approaches for IT security in production. Previous concepts, which relied primarily on isolating the production plants, must be supplemented with new concepts that make provision for the protection of com-ponents.

PROFIBUS & PROFINET International (PI) recognized this necessity and tasked the CB/WG 10 Security working group with the development of a concept. This document provides an initial look at the results of the work thus far. It is intended to serve as a starting point for a discussion with manufacturers, integrators and users. The objective of this discussion is a coordinated and via-ble concept that will make industrial communication with PROFINET fit for the requirements of the future.

This document first describes the motivation and the procedure for the development of a security concept. Next, the security requirements are determined and the actors in the security process named and distinguished from one another. This document then discusses the necessary addi-tions to the PROFINET protocol and the additional protocols required for the system startup. The points at which changes will be necessary are described at the end. The document closes with a list of the specifications that are going to be changed and an outlook for the further course of action.

