ODVA released a new pull model for configuration data in CIP Security, the cybersecurity extension for EtherNet/IP networks. This update builds on the existing pull model for CIP Security certificates, which helps to enable more efficient distribution of device authenticity information. The new configuration model allows for parameters in JSON format to be automatically accessible by EtherNet/IP-capable devices, helping to make integration more flexible for a wider range of connected technologies.
This expanded capability allows configuration data to be made available to both CIP-enabled devices and non-CIP devices, such as smartphones and tablets. With hierarchical metadata more readily available, the pull model helps to enhance more secure communication across diverse platforms and environments.
The pull model introduces two main technical components:
Configuration Delivery Format: A file-based, encoded format using JSON that preserves CIP structure while decoupling configuration from the transport layer.
Pull/Query Mechanism: A method by which a device retrieves its configuration, suited for scenarios where the traditional object/server/attribute approach is not applicable.
Use cases for the configuration pull model include:
Mobile Applications: Apps on devices that lack CIP target functionality can now receive secure configuration data.
Private/Public Network Bridging: Devices behind Network Address Translation (NAT) can be configured from software located on public networks.
Device Replacement: Configuration and certificates can both be automatically retrieved, helping to streamline replacement and minimize downtime.
The JSON file includes a digital signature, helping to ensure data authenticity independent of the transmission method. This design helps to improve compatibility with more modern deployment requirements, particularly as the industry connects more devices via wireless networks, Single Pair Ethernet, and integrates factory-level systems with enterprise and cloud infrastructure for analytics.
CIP Security already incorporates open, established security technologies, including TLS and DTLS for secure transport, HMAC and hashes for data integrity, X.509v3 certificates, OAuth 2.0, and OpenID Connect for identity and access management. With the addition of the pull model for configuration, the system now supports a more adaptable, scalable defense-in-depth strategy.
This capability helps to address emerging requirements as industries prepare for global regulations, such as the EU’s CRA (Cyber Resilience Act), and aim to comply with international standards, such as IEC 62443. By enabling secure access from mobile and non-CIP devices and simplifying device replacement, the new configuration pull model helps to strengthen CIP Security’s role as a more robust cybersecurity layer for EtherNet/IP networks.
Follow ARC Advisory Group for the latest trends in sustainability, automation, and next generation technology.