Access Control for Asset Administration Shell Applications
IEEE International Conference on Emerging Technologies and Factory Automation (ETFA), pp. 1–7
Abstract
The Asset Administration Shell is emerging as the standardized digital twin representation for Industrie 4.0 assets, enabling interoperability across organizational and technical boundaries. However, existing access control mechanisms fail to satisfy the Asset Administration Shell’s needs for fine-grained, context-aware, cross-domain security. This paper proposes an access control concept tailored to the Asset Administration Shell, combining Role Based Access Control and Attribute Based Access Control to meet a set of ten key requirements derived from standards, literature, and expert interviews. Our approach follows a technology-neutral architecture, with a concrete prototype implementation using Keycloak as identity provider, Envoy for request interception, and Open Policy Agent for centralized policy based decision-making; thereby separating security concerns from application logic. An evaluation against the defined requirements shows that this prototype meets nine of the ten requirements. Overall, this concept lays the groundwork for future development of secure, scalable, and flexible access control solutions in industrial Asset Administration Shell deployments.
Authors 4
-
Affiliation as printed
RWTH Aachen University,Chair of Information and Automation Systems,Aachen,Germany
-
Affiliation as printed
RWTH Aachen University,Chair of Information and Automation Systems,Aachen,Germany
-
Affiliation as printed
RWTH Aachen University,Chair of Information and Automation Systems,Aachen,Germany
-
Affiliation as printed
RWTH Aachen University,Chair of Information and Automation Systems,Aachen,Germany
Cited by 1 stored of 1
1 result
No patents citing this paper on Lens.org (checked 2026-10-06).
References 7
7 results