Skip to content

Public Key Infrastructure in Production: Resources and Real-Time as Central Challenges

In a nutshell: PKI systems for production environments must be resource-efficient, network-independent, and deterministically fast while managing millions of devices and multiple trust domains.

PKI implementations in production facilities differ significantly in technology from classical IT environments. Resource constraints, isolated network zones, and strict real-time requirements demand specialized architectural approaches.

Securing networked production facilities through Public Key Infrastructure (PKI) encounters characteristics that do not occur in standard IT environments. Operational Technology (OT) devices such as programmable logic controllers, remote terminal units, sensors, and measuring instruments are often equipped with minimal CPU, RAM, and storage capacity. This leads to practical bottlenecks: complete certificate revocation lists (CRLs) do not fit in working memory, and time-critical TLS handshakes can be interrupted.

A second structural problem is network isolation. Many production environments have severely limited or no direct internet connectivity. This means: OCSP responders and cloud-based services are not reliably accessible during ongoing operations. Certificate management and revocation list distribution must therefore function locally and across isolated zone boundaries – without external dependencies.

Availability and latency behavior are critical. Production facilities tolerate no unplanned downtime. The Certificate Authority is classified as part of critical infrastructure; failures in revocation list distribution directly jeopardize operational stability. Furthermore, industrial network protocols demand deterministic communication with strictly defined latencies. Certificate checks must neither delay connection establishment nor create variable delays – otherwise strictly timed real-time processes will fail.

The volume of machine identities further compounds complexity. In modern factories, sensors, controllers, and edge gateways require their own cryptographic identities; the total number quickly reaches seven-figure numbers. Manual administration is not feasible – automated lifecycle processes are necessary. Added to this: multiple actors such as internal teams, external service providers, and original equipment manufacturers work in overlapping trust domains. This requires strict segmentation and comprehensive auditing of all access rights.


Source: www.it-daily.net · Published 14 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: