In brief: PKI implementations in production require solutions for resource-constrained devices, network isolation, and real-time requirements that differ significantly from classical IT security.
Securing operational technology networks through public key infrastructure encounters specific technical hurdles that differ fundamentally from classical IT environments. Resource constraints, network isolation, and strict real-time requirements demand adapted architectural solutions.
In OT environments, resource constraints on endpoint devices fundamentally shape PKI architecture. Programmable logic controllers (PLCs), remote terminal units (RTUs), and sensors typically have only limited CPU, RAM, and storage capacity. This leads to practical problems: complete certificate revocation lists (CRLs) do not fit in working memory, and the TLS handshake becomes time-critical.
Network topology further complicates certificate validation during ongoing operations. Many production zones are completely air-gapped or subject to strict segmentation rules, which eliminates constant availability of external OCSP responders or cloud services. Certificate management must function reliably locally and across isolated zone boundaries without requiring central online services to be available.
Availability and real-time communication are non-negotiable in critical infrastructure operations. Certificate authority outages or errors in certificate revocation list distribution directly endanger facility stability. Industrial network protocols also demand deterministic communication with firmly defined latencies – unsuitable certificate validation can cause unpredictable delays in connection establishment and thereby jeopardize the real-time requirements of processes.
The scaling dimension significantly increases complexity. Modern manufacturing facilities operate tens of millions of devices, each requiring its own cryptographic machine identity. Manual management is impossible; automated provisioning and revocation procedures are mandatory. Additionally, there is segmentation by trust domains: internal operations teams, external maintenance service providers, and original equipment manufacturers (OEMs) must be able to act within strict access boundaries, which requires comprehensive auditability.
Source: www.it-daily.net · Published July 14, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.