Glossary · Industrial cybersecurity
Authentication
In industrial cybersecurity, authentication is the verification of the identity of a user, device or system before it is granted access. It answers the question “who is this?”, not “what may they do?”.
- Cybersecurity
- Standards
In one sentence
Authentication verifies the identity of a user, device or system; it is the step before authorization decides what that identity may do.
Example
Before a service technician can connect to the HMI of an injection molding machine, the machine checks the technician’s personal account and a one-time code instead of a shared maintenance password.
Explained in context
Context cards connect this term with others to answer one question. Also in British English and German.
How it applies
- Cybersecurity: IEC 62443 groups this under the foundational requirement of identification and authentication control, for human users as well as for software processes and devices. Strength requirements grow with the target security level.
- Machine safety: Weak or shared authentication on engineering tools and HMIs makes unauthorized changes to safety parameters possible. Changes that bypass protection also bypass the audit trail.
- Technical documentation: Operating and maintenance manuals should describe how accounts are set up, how default passwords are changed at commissioning, and what to do when a credential is lost.
- Remote access: Remote access needs strong, preferably multi-factor authentication at the boundary of the machine network.
Authentication vs. authorization
Authentication establishes identity. Authorization then determines which actions that identity may perform. A system can authenticate a user correctly and still be insecure if every authenticated user may change everything.