Access Control for Asset Administration Shell Applications

Ornella Mboudia, Sebastian Heppner, Torben Miny, Tobias Kleinert · 2025

The Asset Administration Shell is emerging as the standardized digital twin representation for Industrie 4.0 assets, enabling interoperability across organizational and technical boundaries. However, existing access control mechanisms fail to satisfy the Asset Administration Shell’s needs for fine-grained, context-aware, cross-domain security. This paper proposes an access control concept tailored to the Asset Administration Shell, combining Role Based Access Control and Attribute Based Access Control to meet a set of ten key requirements derived from standards, literature, and expert interviews. Our approach follows a technology-neutral architecture, with a concrete prototype implementation using Keycloak as identity provider, Envoy for request interception, and Open Policy Agent for centralized policy based decision-making; thereby separating security concerns from application logic. An evaluation against the defined requirements shows that this prototype meets nine of the ten requirements. Overall, this concept lays the groundwork for future development of secure, scalable, and flexible access control solutions in industrial Asset Administration Shell deployments.

Read the paper · More papers on PaperTik