User authentication-based access control verification
Final Review Decision on Appropriateness of Profit-Sharing System
Sensestone, together with the Korea Water Resources Corporation (K-water), verified a user authentication-based OT security system for water supply monitoring and control facilities. This project is significant in that it complemented the limitations of existing password-based authentication methods in the operating environment of national infrastructure and confirmed the feasibility of actual field application.
Sensestone announced on the 11th that the project 'Development of User Authentication System for Strengthening Security of Water Supply Monitoring and Control Equipment,' jointly conducted with the Korea Water Resources Corporation, received a favorable evaluation in the final review of the performance sharing system.
This project was undertaken to address security vulnerabilities associated with fixed-value passwords and shared account systems used in the operating environment of water supply monitoring and control equipment. The two companies conducted verification by applying user identification, authentication, access control, and audit log management functions to an actual operating environment.
Sensestone focused on implementing a user authentication system based on the OTAC Trusted Access Gateway (TAG) without changing existing monitoring and control equipment. OTAC TAG is a security solution specialized for industrial control environments that identifies and authenticates users prior to accessing OT endpoints and controls access based on authority.
During the demonstration process, on-site inspections, testbed verification, and accredited testing were conducted. The Korea Water Resources Corporation provided the test environment and field requirements, while the Climate Technology Innovation Office and the Information Security Office participated in the project operation and technical review process.
Through this project, Sensestone confirmed that it can improve issues identified in existing OT environments, such as the lack of user identification, fixed password-based authentication, and inadequate access history management. By implementing a user-specific authentication and audit log system, it reduced unauthorized access and established a foundation to track access history in the event of an incident.
Sensestone explained that this project supports compliance with the FR1 user identification and authentication requirements of IEC 62443-4-2 and IEC 62443-3-3. It also anticipates the possibility of linking with demonstration cases of the National Intelligence Service's guidelines for establishing security monitoring for control systems.
In the future, Sensestone plans to pursue joint patent applications with the Korea Water Resources Corporation and expand the scope of application from PLC to various OT endpoints such as RTU, DCS, and HMI.
"This achievement was made possible thanks to the trust of the Korea Water Resources Corporation, which verified it together with us until the very end at actual national infrastructure sites," said Yoo Chang-hoon, CEO of Sensestone. "We will continue to develop practical OT security technologies that operate in industrial and national infrastructure environments."