Industrial Security Provisioning
A device includes a network interface, memory, and logic in data communication with the network interface and memory. The memory is configured to store instructions. When executed by the logic, the instructions are configured to: determine topology information for a node of a network, determine a desired security level for the node based on the topology information, determine a function for the node, determine a security feature to implement the desired security level based on the function, and implement the security feature on the node.
1 . A method, comprising:
determining topology information for a first node of a network;
determining a function of the first node;
based on the function and the topology information, determining a security feature; and
implementing the security feature at the first node.
2 . The method of claim 1 , wherein determining the topology information comprises determining a location for the first node.
3 . The method of claim 2 , wherein the determination of the location is based on a parameter of the network.
4 . The method of claim 2 , wherein the determination of the location is based on a location service.
5 . The method of claim 1 , wherein determining the security feature for the first node comprises determining a hardware profile of the first node.
6 . The method of claim 5 , wherein determining the security feature comprises determining allowed security options associated with the hardware profile.
7 . The method of claim 6 , wherein the allowed options for the hardware profile are based on a size of the first node.
8 . The method of claim 1 , wherein determining the security feature comprising determining a maximum security level for the first node based on the topological information.
9 . The method of claim 1 , wherein determining the security feature comprising determining a minimum security level for the first node based on the topological information.
10 . The method of claim 1 , further comprising implementing the security feature at a second node in response to a status change at the first node.
11 . The method of claim 10 , wherein the first and second node have the same topology information.
12 . The method of claim 10 , wherein status change comprises the first node going offline.
13 . The method of claim 1 , further comprising responsive to a task change, adding a second node to a task group associated with the first node.
14 . The method of claim 13 , wherein adding the second node comprises implementing another security feature on the second node.
15 . A method, comprising:
determining a location of a first node of a network;
determining a security preference for the location;
based on the security preference, determining a security level for the first node;
determining a function of the first node;
determining a security feature for the security level;
based on the function, determining support for the security feature by the node; and
when the node supports the security feature, causing the first node to implement the security feature.
16 . The method of claim 15 , further comprising assigning the first node to a task group based on the function and the location.
17 . The method of claim 16 , further comprising assigning a second node to the task group based on a status of the first node.
18 . The method of claim 15 , wherein the location comprises a position along a manufacturing chain.
19 . A system, comprising:
a network;
a function node interconnected by the network, the function node configured to:
implement security features;
perform a function within a task group;
a control node interconnected to the functional node by the network, the control node configured to:
determine a first location of the function node;
determine the task group for the function node;
based on the determined first location and the task group, determine a first security level for the functional node;
based on the function of the node and the first security level, determine a selected feature of the security features to implement;
cause the function node to implement the selected feature; and
assign the function node to the task group.
20 . The system of claim 19 , wherein:
the function node comprises a nomadic node; and
the control node is further configured to:
instruct the node to relocate to a second location; and
based on the second location determine a second security level.