Operational Technology
Pages
Page 34 of 37
Principle 6. Ensure key management is maintainable and diversified
Key management is an integral part of enacting a resilient and secure encryption scheme.
RF networks which are comprised of a substantial number of discrete devices will require keying on a large-scale, if encryption is to be implemented. If the devices do not support key management methods (that is, they rely on manual input of keys into each individual device) then the security of the system is more likely to be compromised. This is because manual key management methods on enterprise scale are burdensome to operators, and may lead to a number of security weaknesses such as:
- storing key material insecurely to enable ease of use
- using simple keys that are easy to remember
- using the same key across the entire estate
- reducing the frequency that keys are changed (or not changing them at all)
Key management should be centralised and ideally administrators should be able to re-key devices OTA to reduce the manual workload required compared to keying a large number of devices locally. This process should be as intuitive as possible in order to encourage users to make the appropriate security decisions. An additional security measure would be to key devices on a per-system or per-region basis. This will limit the blast radius of a compromised key, and prevent an attacker gaining access to the entirety of the radio estate through the use of a single, universally-used key.
If OTA keying (OTAK) is to be implemented, it is imperative that keys are suitably protected prior to transmission across the network. The OTAK mechanism should be robust and hardened against replay attack as this function is integral to the overall security of the network and any cryptographic protections put in place. Regular key changes should take place at scheduled intervals (or when compromise is suspected) to limit the time that a compromised key is useful to an attacker.
Effective key management depends on maintaining an accurate understanding of which RF devices and links are deployed, and how they are grouped (for example by system, region, or function). Without this visibility, re‑keying activities become error‑prone and increase the risk of key reuse, orphaned devices, or inconsistent cryptographic states across the RF estate.