{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T10:05:20Z","timestamp":1778493920832,"version":"3.51.4"},"reference-count":39,"publisher":"MDPI AG","issue":"6","license":[{"start":{"date-parts":[[2019,6,4]],"date-time":"2019-06-04T00:00:00Z","timestamp":1559606400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Industrial Automation and Control Systems (IACS) are broadly utilized in critical infrastructures for monitoring and controlling the industrial processes remotely. The real-time transmissions in such systems provoke security breaches. Many security breaches have been reported impacting society severely. Hence, it is essential to achieve secure communication between the devices for creating a secure environment. For this to be effective, the keys used for secure communication must be protected against unauthorized disclosure, misuse, alteration or loss, which can be taken care of by a Key Management Infrastructure. In this paper, by considering the generic industrial automation network, a comprehensive key management infrastructure (CKMI) is designed for IACS. To design such an infrastructure, the proposed scheme employs ECDH, matrix method, and polynomial crypto mechanisms. The proposed design handles all the standard key management operations, viz. key generation, device registration, key establishment, key storage, device addition, key revocation, key update, key recovery, key archival, and key de-registration and destruction. The design supports secure communication between the same and different levels of IACS devices. The proposed design can be applied for major industrial automation networks to handle the key management operations. The performance analysis and implementation results highlight the benefits of the proposed design.<\/jats:p>","DOI":"10.3390\/fi11060126","type":"journal-article","created":{"date-parts":[[2019,6,5]],"date-time":"2019-06-05T09:37:58Z","timestamp":1559727478000},"page":"126","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["CKMI: Comprehensive Key Management Infrastructure Design for Industrial Automation and Control Systems"],"prefix":"10.3390","volume":"11","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9022-3464","authenticated-orcid":false,"given":"Pramod","family":"T. C.","sequence":"first","affiliation":[{"name":"Department of Computer Technology, Dayananda Sagar University, Bangalore, Karnataka 560078, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9606-0128","authenticated-orcid":false,"given":"Thejas","family":"G. S.","sequence":"additional","affiliation":[{"name":"School of Computing and Information Sciences, Florida International University, Miami, FL 33199, USA"},{"name":"Department of Computer Science and Engineering, Siddaganga Institute of Technology, Tumkur, Karnataka 572103, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3203-833X","authenticated-orcid":false,"given":"S. S.","family":"Iyengar","sequence":"additional","affiliation":[{"name":"School of Computing and Information Sciences, Florida International University, Miami, FL 33199, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4990-1689","authenticated-orcid":false,"given":"N. R.","family":"Sunitha","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Siddaganga Institute of Technology, Tumkur, Karnataka 572103, India"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2019,6,4]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"20","DOI":"10.1016\/j.ijcip.2017.07.002","article-title":"Cybersecurity protection for power grid control infrastructures","volume":"18","author":"Jarmakiewicz","year":"2017","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"key":"ref_2","first-page":"139","article-title":"Key pre-distribution schemes to support various architectural deployment models in WSN","volume":"8","author":"Pramod","year":"2016","journal-title":"Int. J. Inf. Comput. Secur."},{"key":"ref_3","first-page":"761","article-title":"Industrial cyber vulnerabilities: Lessons from Stuxnet and the Internet of Things","volume":"72","author":"Trautman","year":"2017","journal-title":"Univ. Miami Law Rev."},{"key":"ref_4","unstructured":"Pramod, T., and Sunitha, N. (2017). SCADA: Analysis of Attacks on Communication Protocols. Proceedings of International Symposium on Sensor Networks, Systems and Security, Springer."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"1674","DOI":"10.1016\/j.neucom.2017.10.009","article-title":"A survey on security control and attack detection for industrial cyber-physical systems","volume":"275","author":"Ding","year":"2018","journal-title":"Neurocomputing"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"52","DOI":"10.1016\/j.ijcip.2015.02.002","article-title":"A survey of cyber security management in industrial control systems","volume":"9","author":"Knowles","year":"2015","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Thejas, G.S., Boroojen, K.G., Kshitij, C., Isha, B., Iyengar, S.S., and Sunitha, N.R. (2019, January 18\u201320). Deep Learning-based Model to Fight Against Ad Click Fraud. Proceedings of the 2019 ACM Southeast Conference (ACM SE \u201919), Kennesaw, GA, USA.","DOI":"10.1145\/3299815.3314453"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"111","DOI":"10.1016\/j.ijcip.2018.10.011","article-title":"Key pre-distribution scheme with join leave support for SCADA systems","volume":"24","author":"Pramod","year":"2019","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Rao, N., Brooks, R., and Wu, C. (2018). Intelligent Access Control: A Self-Adaptable Trust-Based Access Control (SATBAC) Framework Using Game Theory Strategy. Proceedings of International Symposium on Sensor Networks, Systems and Security. ISSNSS 2017, Springer.","DOI":"10.1007\/978-3-319-75683-7"},{"key":"ref_10","first-page":"130","article-title":"A framework for designing cryptographic key management systems","volume":"800","author":"Barker","year":"2013","journal-title":"NIST Spec. Publ."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Ray, A., \u00c5kerberg, J., Gidlund, M., and Bj\u00f6rkman, M. (2013, January 25\u201328). Initial key distribution for industrial wireless sensor networks. Proceedings of the IEEE International Conference on Industrial Technology (ICIT), Cape Town, South Africa.","DOI":"10.1109\/ICIT.2013.6505862"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Tawde, R., Nivangune, A., and Sankhe, M. (2015, January 19\u201320). Cyber security in smart grid SCADA automation systems. Proceedings of the 2015 International Conference on Innovations in Information, Embedded and Communication Systems (ICIIECS), Coimbatore, India.","DOI":"10.1109\/ICIIECS.2015.7192918"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Krotofil, M., and Gollmann, D. (2013, January 29\u201331). Industrial control systems security: What is happening?. Proceedings of the 2013 11th IEEE International Conference on Industrial Informatics (INDIN), Bochum, Germany.","DOI":"10.1109\/INDIN.2013.6622963"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"1152","DOI":"10.1109\/JPROC.2005.849714","article-title":"Security for industrial communication systems","volume":"93","author":"Dzung","year":"2005","journal-title":"Proc. IEEE"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Barker, E., Barker, W., Burr, W., Polk, W., and Smid, M. (2006). Recommendation for Key Management-Part 1: General (revised), NIST. NIST Special Publication, Citeseer.","DOI":"10.6028\/NIST.SP.800-57p1r2006"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"785","DOI":"10.1109\/49.223881","article-title":"Principles of key management","volume":"11","author":"Fumy","year":"1993","journal-title":"IEEE J. Sel. Areas Commun."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Pramod, T.C., and Sunitha, N.R. (2015, January 8\u201311). KMI for SCADA and WirelessHART in IACS. Proceedings of the 2015 IEEE 20th Conference on Emerging Technologies & Factory Automation (ETFA), Luxembourg.","DOI":"10.1109\/ETFA.2015.7301620"},{"key":"ref_18","unstructured":"(2016, November 14). IEC61850. Available online: https:\/\/en.wikipedia.org\/wiki\/IEC_61850."},{"key":"ref_19","unstructured":"(2016, November 14). IEC62351. Available online: https:\/\/en.wikipedia.org\/wiki\/IEC_62351."},{"key":"ref_20","unstructured":"Beaver, C., Gallup, D., Neumann, W., and Torgerson, M. (2019, May 29). Key Management for SCADA. Cryptog. Information Sys. Security Dept., Sandia Nat. Labs, Tech. Rep. SAND2001-3252, Available online: https:\/\/prod-ng.sandia.gov\/techlib-noauth\/access-control.cgi\/2001\/013252.pdf."},{"key":"ref_21","unstructured":"Dawson, R., Boyd, C., Dawson, E., and Nieto, J.M.G. (2006, January 16\u201319). SKMA: A key management architecture for SCADA systems. Proceedings of the 2006 Australasian Workshops on Grid Computing and e-Research\u2014Volume 54, Hobart, Australia."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"1154","DOI":"10.1109\/TPWRD.2008.2005683","article-title":"Advanced key-management architecture for secure SCADA communications","volume":"24","author":"Choi","year":"2009","journal-title":"IEEE Trans. Power Deliv."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"714","DOI":"10.1109\/TPWRD.2009.2036181","article-title":"Efficient secure group communications for SCADA","volume":"25","author":"Choi","year":"2010","journal-title":"IEEE Trans. Power Deliv."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Swaminathan, P., Padmanabhan, K., Ananthi, S., and Pradeep, R. (2006, January 14\u201317). The Secure Field Bus (SecFB) protocol-network communication security for secure industrial process control. Proceedings of the TENCON 2006\u20142006 IEEE Region 10 Conference, Hong Kong, China.","DOI":"10.1109\/TENCON.2006.344134"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Kim, J.Y., and Choi, H.K. (2012, January 1\u20134). An efficient and versatile key management protocol for secure smart grid communications. Proceedings of the 2012 IEEE Wireless Communications and Networking Conference (WCNC), Shanghai, China.","DOI":"10.1109\/WCNC.2012.6214081"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"4746","DOI":"10.1109\/TIE.2012.2216237","article-title":"A key management scheme for secure communications of advanced metering infrastructure in smart grid","volume":"60","author":"Liu","year":"2013","journal-title":"IEEE Trans. Ind. Electron."},{"key":"ref_27","unstructured":"Sleeper, M. (2019, May 29). Key Management for Secure Power SCADA. Dartmouth Computer Science Technical Report TR2008-628. Available online: https:\/\/www.cs.dartmouth.edu\/~trdata\/reports\/TR2008-628.pdf."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"12","DOI":"10.1109\/MNET.2013.6423186","article-title":"A layered encryption mechanism for networked critical infrastructures","volume":"27","author":"Cao","year":"2013","journal-title":"IEEE Netw."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"629","DOI":"10.1109\/JSYST.2013.2260942","article-title":"Efficient authentication and key management mechanisms for smart grid communications","volume":"8","author":"Nicanfar","year":"2014","journal-title":"IEEE Syst. J."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"46947","DOI":"10.1109\/ACCESS.2019.2909011","article-title":"A Trusted-ID Referenced Key Scheme for Securing SCADA Communication in Iron and Steel Plants","volume":"7","author":"Qian","year":"2019","journal-title":"IEEE Access."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"375","DOI":"10.1109\/TSG.2011.2120634","article-title":"Fault-tolerant and scalable key management for smart grid","volume":"2","author":"Wu","year":"2011","journal-title":"IEEE Trans. Smart Grid"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"171","DOI":"10.1504\/IJCCBS.2017.084930","article-title":"Key management infrastructure design and novel techniques to establish secure communications in critical infrastructures","volume":"7","author":"Pramod","year":"2017","journal-title":"Int. J. Crit. Comp. Based Syst."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Blundo, C., De Santis, A., Herzberg, A., Kutten, S., Vaccaro, U., and Yung, M. (1993). Perfectly-secure key distribution for dynamic conferences. Advances in Cryptology CRYPTO92, Springer.","DOI":"10.1007\/3-540-48071-4_33"},{"key":"ref_34","unstructured":"Blom, R. (1984). An optimal class of symmetric key generation systems. Advances in Cryptology, Springer."},{"key":"ref_35","unstructured":"Enge, A. (2012). Elliptic Curves and Their Applications to Cryptography: An Introduction, Springer Science & Business Media."},{"key":"ref_36","unstructured":"Krivoshein, K.D., and Christensen, D.D. (1999). Process Control System Including Automatic Sensing and Automatic Configuration of Devices. (5,980,078), U.S. Patent."},{"key":"ref_37","unstructured":"Stallings, W. (2006). Cryptography and Network Security, 4\/E, Pearson Education India."},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Potlapally, N.R., Ravi, S., Raghunathan, A., and Jha, N.K. (2003, January 25\u201327). Analyzing the energy consumption of security protocols. Proceedings of the 2003 International Symposium on Low Power Electronics and Design, Seoul, Korea.","DOI":"10.1145\/871516.871518"},{"key":"ref_39","unstructured":"(2017, December 17). Crypto++ 5.6.0 Benchmarks. Available online: http:\/\/www.cryptopp.com\/benchmarks.html."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/11\/6\/126\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T12:56:07Z","timestamp":1760187367000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/11\/6\/126"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,6,4]]},"references-count":39,"journal-issue":{"issue":"6","published-online":{"date-parts":[[2019,6]]}},"alternative-id":["fi11060126"],"URL":"https:\/\/doi.org\/10.3390\/fi11060126","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,6,4]]}}}