How CIP Security Prevents Malicious Communications

Security breaches are an ever-increasing threat, with bad actors continuously looking for ways to cause disruption and destruction. To combat these threats and safeguard end users, lawmakers around the world are introducing new regulations aimed at technology providers. 

The EU’s Cyber Resilience Act is one such regulation, which requires manufacturers to adopt a secure-by-design approach and manage cybersecurity risks throughout a product’s entire lifecycle. This will affect hardware and software manufacturers who sell products in the EU market. Those affected must achieve compliance by December 11, 2027, which means now is the time to get up to speed on requirements and take action.  

Enabling Common Industrial Protocol (CIP™) Security is one crucial step toward achieving compliance for EtherNet/IP devices.  

Why CIP Security?

The purpose of Common Industrial Protocol (CIP™) Security for an EtherNet/IP device is to protect itself from malicious communications. A CIP Security enabled device can reject:

  • Data that has been altered
  • Messages sent by suspicious people or devices
  • Messages that request actions that are not allowed

But how exactly does CIP Security protect your devices? How does it help you maintain data integrity, device authenticity and data confidentiality?

The simple answer is CIP Security adds secure connection and encryption capabilities to your devices that allow it to communicate with other devices in a secure manner. The technical answer requires us to go a little more in depth.

Potential EtherNet/IP Threats

EtherNet/IP does not have built-in security meaning there is no protection from “bad actors” attempting to spoof devices and make/respond to connections on your network.

For example, if your EtherNet/IP adapter does not have a current exclusive owner connection with a scanner, a spoofed scanner can connect to your adapter and assert the adapter outputs. This is one of many scenarios that threaten the security of your EtherNet/IP devices. When these scenarios are brought to life, it could wreak havoc on your networks.

Here’s a high-level overview of the different threats that can take place on your domain:

  • Spoofed IP and MAC addresses
  • Hacked devices running code that’s not their own
  • Spoofed scanners: any capable entity can act as a scanner and connect to your device if they have the IP address and connection point information for an unprotected adapter
  • Spoofed adapters: any capable entity can act as an adapter device if it has the IP address and connection point information, and the connection points are exposed
  • Injected connection data which is monitored on the wire
  • Message tampering: intentional changing of message contents by a bad actor, or unintentional corruption via noise or interference

With CIP Security, EtherNet/IP connections are made with a secure transport mechanism that uses Transport Layer Security (TLS) or Datagram Transport Layer Security (DTLS) protocols. These protocols ensure data integrity, data authenticity and authorization.

TLS is used for Transmission Control Protocol (TCP) messages, which carry EtherNet/IP Explicit Messages. DTLS is used for User Datagram Protocol (UDP) messages, which carry EtherNet/IP Implicit Messages.

To authenticate devices, CIP Security ensures communications are coming from valid devices by using Digital Certificates (Certs) or pre-shared keys (PSKs).

Below is a high-level diagram of how the TLS protocol is used to initiate a connection for explicit messages using Certificates:

To explain further, the scanner makes a connection to the adapter using TCP port 2221. The adapter passes its Certificate or a pre-shared key to the scanner, and the scanner verifies it is a trusted adapter. Then the scanner passes its Certificate or PSK to the adapter so the adapter can verify it’s a trusted scanner.

They then go through an encryption handshake process to establish which cipher suite will be used for message encryption. Finally, once all of that is completed, CIP messaging begins. Each message is encrypted before sending and decrypted when received. This prevents messages from being tampered with or altered and also prevents unauthorized viewing of messages. The entire process works the same for DTLS, except it uses UDP and either port 2221 or 44818, depending on the message class.

Enabling CIP Security Functionality with Pyramid

As cybersecurity regulations like the EU’s Cyber Resilience Act take effect, manufacturers can no longer afford to treat device security as an afterthought. CIP Security provides a proven, standards-based path to secure EtherNet/IP communications, ensuring device integrity, confidentiality, and authenticity.  

Pyramid makes it easy to implement CIP Security and achieve ODVA conformance. With our NetStaX EtherNet/IP Secure Stack add-ons (EIPS-SECURE, EIPA-SECURE, ESDK-SECURE, EADK-SECURE), you can integrate CIP Security into your existing applications with pre-tested, ready-to-use components that simplify compliance and reduce your time to market. Secure your devices today and ensure your products are resilient, compliant, and future-ready. 

 

Explore NetStaX Secure Stack Add-Ons

Further Reading

EtherNetIP

NetStaX v5.6.1: Protecting Against Silent Buffer Overflow in Ethernet/IP Stack Explicit Messages

Legacy Version Licensing Support Changes for EIPScan and EDITT

Building CRA-Ready EtherNet/IP Products with CIP Security

Connect with Us

Looking for a solution?

Get connected to our team of experts. See if we can solve the challenges you face, whether you have ongoing needs, a one-time project, or want to work through initial questions.

IntelliWORKS MES

Industrial Protocol Connectivity