Aug 2026· Future Internet· Vol 18, pp. 466· 0 citations· 27 references
TL;DR
This paper presents ZTSafe, a scheduling architecture that treats physical safety—not attack blocking—as the object of guarantee, and synthesizes a communication safety contract that bounds delay, age of information (AoI), consecutive losses, jitter, and path risk such that the physical state remains in its safe set.
Abstract
Zero-trust security continuously re-evaluates the trustworthiness of industrial devices and reacts by rerouting, isolating, or rescheduling traffic. In a time-sensitive network (TSN) that carries feedback control loops, however, every such reaction is itself a control-plane disturbance: a reroute that meets every deadline can still deliver stale measurements, and an optimizer that crashes mid-reconfiguration can leave the network in an undefined state. This paper presents ZTSafe, a scheduling architecture that treats physical safety—not attack blocking—as the object of guarantee. The guarantee has two distinct layers: compliance with the communication contract yields a deterministic invariance result conditional on the stated plant, disturbance, synchronization, and trusted-base assumptions, whereas the risk bound’s 1−δ coverage is an empirical probabilistic calibration result. ZTSafe (i) synthesizes, offline and per control loop, a communication safety contract that bounds delay, age of information (AoI), consecutive losses, jitter, and path risk such that the physical state remains in its safe set under those assumptions; (ii) converts zero-trust evidence into conservative risk upper bounds and couples the admissible path-risk budget to the runtime safety margin of the plant; and (iii) places the scheduling optimizer outside the trusted computing base: an independent runtime shield checks every proposed schedule against the contracts, and on solver timeout, crash, or infeasibility the system atomically switches to a pre-checked fallback instead of executing an unverified approximate solution. Here, “verified” means independently checked by the shield, not machine-verified; a systematic shield defect or compromise of the remaining trusted computing base voids the deterministic claim. On a hardware TSN testbed with three physical control loops and fourteen attack and fault scenarios, ZTSafe reduces safe-set violations by 92.9% relative to the strongest baseline (12.8% to 0.9%; two-proportion z=39.4, p<10−15) while sustaining 94.3% on-time completion of critical traffic, recovers within three control periods, and executes zero unverified configurations across 10,000 injected solver failures.
Runtime assurance pairs a verified fallback with an untrusted controller and a switching monitor, and is the leading route to admitting learned policies into safety-relevant network control. Its guarantee rests on a condition it assumes rather than requires: that the monitor's estimation error is zero, or at worst stoc...
Cyber–physical systems (CPSs) rely on sensing, computation, and communication to support distributed coordination in industrial and integrated energy applications, but this dependence also exposes them to malicious data manipulation. This article proposes an encrypted and trust-aware periodic event-triggered fault-tole...
Qi Wu, Jun Yang, Shun-Jiang Wang· IEEE Internet of Things Jour...· 0 citations
Zero Trust (ZT) replaces the implicit trust of perimeter-based security with explicit, continuous, context-aware authorization. This shift is particularly relevant to IoT and cyber-physical systems, whose heterogeneous, long-lived, and remotely connected components make persistent trust untenable. Yet their physical co...
Self-triggered reinforcement learning control (RL-STC) learns the sparsest control schedule that preserves Lyapunov-decreasing stability under a Run-Time Assurance (RTA) override. We invert this: an adversarial RL agent learns the sparsest jamming or Denial-of-Service (DoS) schedule that destabilizes the closed loop, w...
Adam Haroon, Erick J. Rodríguez-Seda, Tristan K. Schuler et al.· 0 citations
Autonomous unmanned vehicles are vital to tactical missions, mission-critical public-safety operations like search and rescue and disaster response. However, their reliance on open wireless links and standard Robot Operating System (ROS 2) middleware exposes a broad cyber-physical attack surface. A compromise of these...
Ryne Gonzales, Ethan Liesdyanto, Rex Worley et al.· 0 citations
Industrial control-system anomaly alarms are most useful when they distinguish unusual telemetry from loss of safety or recovery margin. This paper presents RACER-ICS, an operator-oriented framework that combines a one-step predictive residual, rolling physical invariants, held-out empirical block-quantile calibration,...