Author
Listed:
- Riccardo Bacca
(Centro Interdipartimentale di Ricerca Industriale—CIRI ICT, Alma Mater Studiorum—Università di Bologna, 40126 Bologna, Italy)
- Andrea Melis
(Department of Computer Science and Engineering (DISI), Alma Mater Studiorum—Università di Bologna, 40126 Bologna, Italy)
- Lorenzo Rinieri
(Department of Computer Science and Engineering (DISI), Alma Mater Studiorum—Università di Bologna, 40126 Bologna, Italy)
- Roberto Girau
(Department of Computer Science and Engineering (DISI), Alma Mater Studiorum—Università di Bologna, 40126 Bologna, Italy)
- Marco Prandini
(Department of Computer Science and Engineering (DISI), Alma Mater Studiorum—Università di Bologna, 40126 Bologna, Italy)
- Franco Callegati
(Department of Computer Science and Engineering (DISI), Alma Mater Studiorum—Università di Bologna, 40126 Bologna, Italy)
Abstract
Industrial digitalization is moving from Industry 4.0 toward Industry 5.0’s emphasis on resilience, human-centric operation, and sustainability. This shift is enabled by the convergence of Operational Technology and Information Technology, but this integration also broadens the exposure of industrial infrastructures to cyber threats targeting communication integrity and process continuity. Mitigating these risks requires network control that is both programmable and aware of each asset’s operational context. However, there is still a lack of operational interfaces that translate the semantics of industrial assets into programmable, runtime-enforceable network behavior. In this paper, following a Design Science Research methodology, we introduce an asset-aware, closed-loop network control abstraction in which the industrial network itself is modeled as a managed asset through Asset Administration Shells. Asset state, lifecycle phase, and operational intent are translated into network policies enforced at runtime on programmable data planes, while in-network telemetry is exposed at the asset level and correlated with operational metrics. We validate the abstraction on a hybrid testbed that combines virtualized components with industrial-grade hardware and virtualized 5G connectivity, through three security-oriented use cases: (i) asset-driven customization of forwarding policies; (ii) human-centric secure maintenance with controlled remote access over 5G; and (iii) anomaly detection and isolation based on cross-layer telemetry correlation. The results show that asset-level operations can drive programmable network enforcement and make network telemetry available at the asset layer. Finally, the work outlines a first step toward standardizing network-oriented asset submodels by separating control-plane operations from data-plane state and telemetry.
Suggested Citation
Riccardo Bacca & Andrea Melis & Lorenzo Rinieri & Roberto Girau & Marco Prandini & Franco Callegati, 2026.
"Toward Secure Software-Defined Industrial Networks Through Asset Administration Shell Digital Twins,"
Future Internet, MDPI, vol. 18(7), pages 1-31, June.
Handle:
RePEc:gam:jftint:v:18:y:2026:i:7:p:347-:d:1979227
Download full text from publisher
More about this item
Keywords
;
;
;
;
;
;
;
;
JEL classification:
- P4 - Political Economy and Comparative Economic Systems - - Other Economic Systems
Statistics
Access and download statistics
Corrections
All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:gam:jftint:v:18:y:2026:i:7:p:347-:d:1979227. See general information about how to correct material in RePEc.
If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.
We have no bibliographic references for this item. You can help adding them by using this form .
If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.
For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: MDPI Indexing Manager The email address of this maintainer does not seem to be valid anymore. Please ask MDPI Indexing Manager to update the entry or send us the correct address
(email available below). General contact details of provider: https://www.mdpi.com .
Please note that corrections may take a couple of weeks to filter through
the various RePEc services.