АДАПТАЦІЯ АРХІТЕКТУРИ НУЛЬОВОЇ ДОВІРИ ДЛЯ КІБЕРФІЗИЧНИХ РОБОТОТЕХНІЧНИХ СИСТЕМ: БАЗОВІ ВИМОГИ ТА МЕЖІ СТІЙКОСТІ БЕЗПРОВОДОВОГО КАНАЛУ
DOI:
https://doi.org/10.28925/2663-4023.2026.34.1359Ключові слова:
Zero Trust, кібербезпека, кіберфізична система, робототехнічна система, ns-3, стійкість, безпроводовий зв’язок, безперервна верифікація, авторизація, політика безпекиАнотація
Проаналізовано проблему застосування підходу нульової довіри ‘Zero Trust’ (ZT) для безпеки кіберфізичних робототехнічних систем ‘Cyber-Physical Robotic Systems’ (CPRS). Обґрунтовано, що тісна взаємодія мережевих обчислень, сенсорів, актуаторів і систем фізичного керування формує єдину площину ризику, де компрометація ідентифікаційних даних, телеметрії чи каналів зв’язку загрожує як витоком інформації, так і небезпечними фізичними інцидентами. Досліджувана сфера охоплює промислові й мобільні роботи, безпілотні літальні апарати, сервісні та колаборативні роботи, функціонування яких залежить від кіберкомпонентів, здатних впливати на фізичну поведінку. У межах розробки архітектури сформульовано п’ять базових вимог ZT: перевірювана ідентифікація, контекстна авторизація, сегментація мережі, оцінювання актуальності й надійності телеметрії, а також адаптивне реагування з обмеженою експлуатацією та локальною відмовостійкістю. Для визначення меж стійкості безпроводового каналу керування проведено симуляційне моделювання в середовищі ns-3 (стандарт IEEE 802.11ax WiFi 6, одна точка доступу, 20 клієнтських станцій). На основі аналізу 140 трас (відстані 30–125 м, сумарне навантаження 100 Мбіт/с) оцінено сукупну корисну пропускну здатність (aggregate goodput), затримку p95 та відсоток втрат пакетів. Виявлено двоетапний характер деградації каналу зв'язку: межа раннього часового погіршення зафіксована на відстані 40 м (стрибок затримки p95 до 351,8 мс майже без втрат), а межа стійкої деградації втрат — на 50 м (втрати 9,61%). За критичної відстані 125 м goodput знижується до 0,387 Мбіт/с із втратами 99,81%. Встановлено, що отримані межі стійкості безпроводового зв’язку є визначальними для доставки телеметрії та вибору режимів реагування, проте ізольовано не гарантують реалізації ZT. Для комплексної валідації архітектури нульової довіри запропоновано конвеєр синхронізованого аналізу мережевих метрик, подій безпеки та фізичного стану робота.
Завантаження
Посилання
Yaacoub, J.-P. A., Noura, H. N., Salman, O., & Chehab, A. (2021). Robotics Cyber Security: Vulnerabilities, Attacks, Countermeasures, and Recommendations. Int. J. Inf. Secur., 21, 115–158. https://doi.org/10.1007/s10207-021-00545-8
Pu, H., He, L., Cheng, P., Sun, M., & Chen, J. (2023). Security of Industrial Robots: Vulnerabilities, Attacks, and Mitigations. IEEE Netw., 37, 111–117. https://doi.org/10.1109/mnet.116.2200034
Haskard, A., & Herath, D. (2025). Secure Robotics: Navigating Challenges at the Nexus of Safety, Trust, and Cybersecurity in Cyber-Physical Systems. ACM Comput. Surv., 57, 1–48. https://doi.org/10.1145/3723050
Yu, Z., Gao, H., Cong, X., Wu, N., & Song, H. (2023). A Survey on Cyber-Physical Systems Security. IEEE Internet Things J., 10, 21670–21686. https://doi.org/10.1109/jiot.2023.3289625
Syed, N., Shah, S. W., Shaghaghi, A., Anwar, A., Baig, Z. A., & Doss, R. (2022). Zero Trust Architecture (ZTA): A Comprehensive Survey. IEEE Access, 10, 57143–57179. https://doi.org/10.1109/access.2022.3174679
He, Y., Huang, D., Chen, L., Ni, Y., & Ma, X. (2022). A Survey on Zero Trust Architecture: Challenges and Future Trends. Wirel. Commun. Mob. Comput., 2022(1). https://doi.org/10.1155/2022/6476274
Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero Trust Architecture. NIST Special Publication 800-207. https://doi.org/10.6028/NIST.SP.800-207
Cybersecurity and Infrastructure Security Agency. (2023). Zero Trust Maturity Model, Version 2.0. CISA Guidance. https://www.cisa.gov/resources-tools/resources/zero-trust-maturity-model
Feng, X., & Hu, S. (2023). Cyber-Physical Zero Trust Architecture for Industrial Cyber-Physical Systems. IEEE Trans. Ind. Cyber Phys. Syst., 1, 394–405. https://doi.org/10.1109/ticps.2023.3333850
Hasan, S., Amundson, I., & Hardin, D. S. (2023). Zero Trust Architecture Patterns for Cyber-Physical Systems. SAE Tech. Pap. Ser.. https://doi.org/10.4271/2023-01-1001
Bello, A., Diyan, M., & Asghar, I. (2025). Zero Trust Implementation for Legacy Systems using Dynamic Microsegmentation, Role-Based Access Control (RBAC), and Attribute-Based Access Control (ABAC). In 2025 4th Int. Conf. on Computing and Information Technology (ICCIT), 181–189. https://doi.org/10.1109/iccit63348.2025.10989392
Zanasi, C., Russo, S., & Colajanni, M. (2024). Flexible Zero Trust Architecture for the Cybersecurity of Industrial IoT Infrastructures. Ad Hoc Netw., 156, 103414. https://doi.org/10.1016/j.adhoc.2024.103414
Paul, B., & Rao, M. (2022). Zero-Trust Model for Smart Manufacturing Industry. Appl. Sci. https://doi.org/10.3390/app13010221
Li, K., Li, C., Yuan, X., Li, S.-F., Zou, S., Ahmed, S. S., Ni, W., Niyato, D., Jamalipour, A., Dressler, F., & Akan, O. B. (2025). Zero-Trust Foundation Models: A New Paradigm for Secure and Collaborative Artificial Intelligence for Internet of Things. IEEE Internet Things J., 12, 46269–46293. https://doi.org/10.1109/jiot.2025.3603957
Mahmud, R., Jin, J., Kua, J., Afrin, M., Mistry, S., & Krishna, A. (2025). Trusted Microservice Orchestration for Secure Edge Computing in Industrial Cyber-Physical Systems. IEEE Netw., 39, 70–78. https://doi.org/10.1109/mnet.2025.3541032
Zhukabayeva, T., Zholshiyeva, L., Karabayev, N., Khan, S., & Alnazzawi, N. (2025). Cybersecurity Solutions for Industrial Internet of Things-Edge Computing Integration: Challenges, Threats, and Future Directions. Sens., 25. https://doi.org/10.3390/s25010213
Zanasi, C., Marasco, I., & Colajanni, M. (2025). Graph based threat detection system for a microsegmentation Zero Trust Architecture. In 2025 IEEE Conf. on Dependable, Autonomic and Secure Computing (DASC), 31–39. https://doi.org/10.1109/
dasc68382.2025.00012
Goerke, N., Timmermann, D., & Baumgart, I. (2021). Who Controls Your Robot? An Evaluation of ROS Security Mechanisms. In 2021 7th Int. Conf. on Automation, Robotics and Applications (ICARA), 60–66. https://doi.org/10.1109/icara51699.2021.9376468
Xia, L., Gao, X., & Shi, W. (2025). Investigating Security Threats in Multi-Tenant ROS 2 Systems. 2025 IEEE International Conference on Robotics and Automation (ICRA), 16441–16448. https://doi.org/10.1109/icra55743.2025.11127490
Shaik, A. K., Mohammadi, A., & Malik, H. A. M. (2025). A Systematic Review of Sensor Vulnerabilities and Cyber-Physical Threats in Industrial Robotic Systems. IET Cyber Phys. Syst. Theory Appl., 10. https://doi.org/10.1049/cps2.70023
Bhardwaj, A., Bharany, S., Rehman, A., Tejani, G. G., & Hussen, S. (2025). Securing Cyber-Physical Robotic Systems for Enhanced Data Security and Real-Time Threat Mitigation. EURASIP J. Inf. Secur., 2025. https://doi.org/10.1186/s13635-025-00186-7
Holdbrook, R., Odeyomi, O., Yi, S., & Roy, K. (2024). Network-Based Intrusion Detection for Industrial and Robotics Systems: A Comprehensive Survey. Electron. https://doi.org/10.3390/electronics13224440
Burg, A., Chattopadhyay, A., & Lam, K.-Y. (2018). Wireless Communication and Security Issues for Cyber-Physical Systems and the Internet-of-Things. Proceedings of the IEEE, 106(1), 38–60. https://doi.org/10.1109/JPROC.2017.2780172
Guo, P., Kim, H., Virani, N., Xu, J., Zhu, M., & Liu, P. (2017). Exploiting Physical Dynamics to Detect Actuator and Sensor Attacks in Mobile Robots. arXiv:1708.01834. https://doi.org/10.48550/arXiv.1708.01834
Ge, Y., & Zhu, Q. (2024). GAZETA: GAme-Theoretic Zero-Trust Authentication for Defense Against Lateral Movement in 5G IoT Networks. IEEE Trans. Inf. Forensics Secur., 19, 540–554. https://doi.org/10.1109/TIFS.2023.3326975
Tushkanova, O., Levshun, D., Branitskiy, A., Fedorchenko, E., Novikova, E., & Kotenko, I. (2023). Detection of Cyberattacks and Anomalies in Cyber-Physical Systems: Approaches, Data Sources, Evaluation. Algorithms, 16, 85. https://doi.org/10.3390/a16020085
Moriano, P., Hespeler, S., Li, M., & Mahbub, M. (2024). Adaptive Anomaly Detection for Identifying Attacks in Cyber-Physical Systems: A Systematic Literature Review. Artif. Intell. Rev., 58. https://doi.org/10.1007/s10462-025-11292-w
Ji, R., Padha, D., Singh, Y., & Sharma, S. (2024). Review of Intrusion Detection System in Cyber-Physical System Based Networks: Characteristics, Industrial Protocols, Attacks, Data Sets and Challenges. Trans. Emerg. Telecommun. Technol., 35. https://doi.org/10.1002/ett.5029
Zhukabayeva, T., Ahmad, Z., Adamova, A., Karabayev, N., & Abdildayeva, A. (2025). An Edge-Computing-Based Integrated Framework for Network Traffic Analysis and Intrusion Detection to Enhance Cyber-Physical System Security in Industrial IoT. Sens., 25. https://doi.org/10.3390/s25082395
Manzoor, S., Yin, Y., Gao, Y., Hei, X., & Cheng, W. (2020). A Systematic Study of IEEE 802.11 DCF Network Optimization From Theory to Testbed. IEEE Access, 8, 154114–154132. https://doi.org/10.1109/access.2020.3018088
Venkateswaran, S. K., Tai, C.-L., Garnayak, R., Ben-Yehezkel, Y., Alpert, Y., & Sivakumar, R. (2024). IEEE 802.11ax Target Wake Time: Design and Performance Analysis in ns-3. In 2024 Workshop on ns-3. https://doi.org/10.1145/3659111.3659115
Assasa, H., Grosheva, N., Ropitault, T., Blandino, S., Golmie, N., & Widmer, J. (2021). Implementation and Evaluation of a WLAN IEEE 802.11ay Model in Network Simulator ns-3. In 2021 Workshop on ns-3. https://doi.org/10.1145/3460797.3460799
Hasan, S., Amundson, I., & Hardin, D. (2024). Zero-trust Design and Assurance Patterns for Cyber-Physical Systems. J. Syst. Archit., 155, 103261. https://doi.org/10.1016/
j.sysarc.2024.103261
Botta, A., Rotbei, S., Zinno, S., & Ventre, G. (2023). Cyber Security of Robots: A Comprehensive Survey. Intell. Syst. Appl., 18, 200237. https://doi.org/10.1016/
j.iswa.2023.200237
Campanile, L., Gribaudo, M., Iacono, M., Marulli, F., & Mastroianni, M. (2020). Computer Network Simulation with ns-3: A Systematic Literature Review. Electron. https://doi.org/10.3390/electronics9020272
Jeffrey, N., Tan, Q., & Villar, J. (2023). A Review of Anomaly Detection Strategies to Detect Threats to Cyber-Physical Systems. Electron. https://doi.org/10.3390/
electronics12153283
Puccetti, T., Nardi, S., Cinquilli, C., Zoppi, T., & Ceccarelli, A. (2024). ROSPaCe: Intrusion Detection Dataset for a ROS2-Based Cyber-Physical System and IoT Networks. Sci. Data, 11. https://doi.org/10.1038/s41597-024-03311-2
Manzoor, S., Manzoor, M., Manzoor, H., Adan, D. E., & Kayani, M. A. (2023). Which Simulator to Choose for Next Generation Wireless Network Simulations? NS-3 or OMNeT++. IEEC 2023. https://doi.org/10.3390/engproc2023046036
Pakhomov, M. V. (2026). ns3-wifi6-zero-trust-cprs: ns-3 Simulation Environment and Traces for the 20 STA / 1 AP IEEE 802.11ax Campaign [Source code]. GitHub. https://github.com/m1fril/ns3-wifi6-zero-trust-cprs
Dhiman, P., Saini, N., Gulzar, Y., Turaev, S., Kaur, A., Nisa, K. U., & Hamid, Y. (2024). A Review and Comparative Analysis of Relevant Approaches of Zero Trust Network Model. Sens., 24. https://doi.org/10.3390/s24041328
Dattatreya, V., Adudhodla, M., Anupkant, S., Bande, V., Prasad, C. G. V. N., & Manellore, P. K. R. (2025). Edge-Forged Resilience: A Zero-Trust Security Architecture for Autonomous Cyber-Physical Systems in Industry 5.0. In 2025 6th Int. Conf. on Smart Electronics and Communication (ICOSEC), 1262–1268. https://doi.org/10.1109/
icosec67334.2025.11459650
Kim, S., Park, K.-J., & Lu, C. (2022). A Survey on Network Security for Cyber-Physical Systems: From Threats to Resilient Design. IEEE Commun. Surv. Tutor., 24, 1534–1573. https://doi.org/10.1109/comst.2022.3187531
Kayan, H., Nunes, M., Rana, O., Burnap, P., & Perera, C. (2021). Cybersecurity of Industrial Cyber-Physical Systems: A Review. ACM Comput. Surv., 54, 1–35. https://doi.org/10.1145/3510410
Nweke, L. O. (2021). A Survey of Specification-based Intrusion Detection Techniques for Cyber-Physical Systems. Int. J. Adv. Comput. Sci. Appl., 12. https://doi.org/10.14569/ijacsa.2021.0120506
Tan, S., Guerrero, J., Xie, P., Han, R., & Vasquez, J. (2020). Brief Survey on Attack Detection Methods for Cyber-Physical Systems. IEEE Syst. J., 14, 5329–5339. https://doi.org/10.1109/jsyst.2020.2991258
Xing, W., & Shen, J. (2024). Security Control of Cyber-Physical Systems under Cyber Attacks: A Survey. Sens., 24. https://doi.org/10.3390/s24123815
Ferrag, M., Maglaras, L., Moschoyiannis, S., & Janicke, H. (2020). Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study. J. Inf. Secur. Appl., 50. https://doi.org/10.1016/j.jisa.2019.102419
Da Silva, E. F., Santoso, F., & Zheng, L. (2025). A Deep Learning-Based Intrusion Detection System for Safeguarding ROS 2-Powered Unmanned Ground Vehicles Against DoS Attacks. In 2025 Int. Joint Conf. on Neural Networks (IJCNN), 1–9. https://doi.org/10.1109/ijcnn64981.2025.11229203
Santoso, F., & Finn, A. (2023). A Data-Driven Cyber-Physical System Using Deep-Learning Convolutional Neural Networks: Study on False-Data Injection Attacks in an Unmanned Ground Vehicle Under Fault-Tolerant Conditions. IEEE Trans. Syst. Man Cybern. Syst., 53, 346–356. https://doi.org/10.1109/tsmc.2022.3170071
Fernandez, I., Neupane, S., Chakraborty, T., Mitra, S., Mittal, S., Pillai, N., Chen, J., & Rahimi, S. (2024). A Survey on Privacy Attacks Against Digital Twin Systems in AI-Robotics. In 2024 IEEE 10th Int. Conf. on Collaboration and Internet Computing (CIC), 70–79. https://doi.org/10.1109/cic62241.2024.00019
Alauthman, A., & Shraa, T. (2025). Performance Evaluation and Latency Optimization of Wi-Fi 7 in High-Density Wireless Environments. Int. J. Electr. Electron. Eng. Telecommun.. https://doi.org/10.18178/ijeetc.14.6.354-364
Ahrar, E. M., Wilhelmi, F., Galati-Giordano, L., Imputato, P., Menth, M., & Avallone, S. (2025). R-TWT in Wi-Fi 7 and Beyond: Enabling Bounded Latency, Energy Efficiency, and Reliability. In 2025 IEEE 30th Int. Conf. on Emerging Technologies and Factory Automation (ETFA), 1–8. https://doi.org/10.1109/etfa65518.2025.11205686
Alauthman, A., & Shraa, T. (2025). Deep Reinforcement Learning-Driven Dynamic Spectrum Access in Dense Wi-Fi Environments. IEEE Access, 13, 178663–178680. https://doi.org/10.1109/access.2025.3621489
Yang, S., Guo, J., & Rui, X. (2024). Formal Analysis and Detection for ROS2 Communication Security Vulnerability. Electron. https://doi.org/10.3390/electronics13091762
Soriano, E., Martin, F., & Guardiola, G. (2024). Implementing a Robot Intrusion Prevention System (RIPS) for ROS 2. arXiv:2412.19272. https://arxiv.org/abs/2412.19272
Santoso, F., & Finn, A. (2024). Trusted Operations of a Military Ground Robot in the Face of Man-in-the-Middle Cyberattacks Using Deep Learning Convolutional Neural Networks: Real-Time Experimental Outcomes. IEEE Trans. Dependable Secur. Comput., 21, 2273–2284. https://doi.org/10.1109/tdsc.2023.3302807
Zailan, N. S. B., Ong, L.-Y., & Lim, H. (2026). NAVBOT25: Dataset for ROS-Based Autonomous Robot Navigation. Data Br., 65. https://doi.org/10.1016/j.dib.2026.112617
Yaseen, Y. A., Almomani, I., & Al-Akhras, M. (2025). A Survey of Security Threats and Defense Mechanisms in ROS2-Based Internet of Drones Systems. In 2025 Int. Conf. on Computer and Applications (ICCA), 1–6. https://doi.org/10.1109/icca66035.2025.11430817
Papoutsakis, M., Hatzivasilis, G., Michalodimitrakis, E., Ioannidis, S., Michael, M. K., Savva, A. D., Nikolaou, P., Stokkou, E., & Bozdemir, G. (2025). SESAME: Automated Security Assessment of Robots and Modern Multi-Robot Systems. Electron. https://doi.org/10.3390/electronics14050923
Muriithi, G., Papari, B., Arsalan, A., Timilsina, L., Muriithi, A., Buraimoh, E., Khan, A., Ozkan, G., Edrington, C. S., & Papari, A. (2025). Zero Trust Architecture for Electric Transportation Systems: A Systematic Survey and Deep Learning Framework for Replay Attack Detection. IEEE Open J. Veh. Technol., 6, 2171–2194. https://doi.org/10.1109/ojvt.2025.3592041
Опубліковано
Як цитувати
Номер
Розділ
Ліцензія
Авторське право (c) 2026 Михайло Пахомов, Володимир Соколов

Ця робота ліцензується відповідно до Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.