Skip to main content

Trust in OT Endpoints

OT Security & Hardware Active

Trust in OT Endpoints

Strengthening cybersecurity for operational technology systems by using Trusted Execution Environments (TEEs) to protect PLCs, SCADA, and other OT devices.

Started: 2025
Funded by: DoD, NSF
Team: 7 researchers

Overview

CREM focuses on strengthening cybersecurity for operational technology (OT) systems by using Trusted Execution Environments (TEEs) in industrial devices. This research project develops TEE solutions specifically designed for Operational Technology endpoints, providing hardware-isolated secure execution for critical industrial operations including PLCs, SCADA systems, and other OT devices.

The project addresses the unique security challenges of OT environments where traditional IT security solutions are often inadequate due to real-time requirements, legacy systems, and safety-critical operations. Our TEE implementation provides secure key-based PLC command validation, secure storage for cryptographic keys and certificates, firmware validation before deployment, and attestation to SCADA systems.

The system maintains real-time performance requirements of OT systems while providing hardware-based isolation and security. This approach enables secure boot, encrypted storage, and isolated execution for industrial control systems without compromising operational efficiency.

Key Features

  • Protecting PLCs, SCADA, and other OT devices with TEEs
  • Secure key-based PLC command validation
  • Secure storage for cryptographic keys and certificates
  • Firmware validation before deployment
  • Attestation to SCADA systems
  • Hardware-based isolation
  • Real-time performance maintained
  • Tamper detection
  • Remote attestation
  • Minimal trusted computing base
  • Legacy system compatibility

Gallery

Related Publications

CARE: Lightweight Attack Resilient Secure Boot Architecture with Onboard Recovery for RISC-V-based SOC

A. Dave, N. Banerjee, and C. Patel
IEEE ISQED, 2021