Security
These clauses segment the wireless network, keep authentication on the plant side of every outside link, and make every key and session timer a recorded, tested number, because security settings change the roam and can drop a vehicle on a schedule.
Security settings shape the roam and set timers that can end a session on schedule. These clauses put wireless devices in their own segment, keep the authentication server close to the floor, choose security and roaming together, record every rekey and session timer, and watch for access points you do not own. They sit inside your security program; they do not replace it.
6.1 Wireless in its own segment shall
Wireless devices shall sit in their own network segment, and access points shall connect through a boundary protection device that enforces the owner's security policy between the wireless segment and the rest of the control network.
6.2 Authentication inside the plant shall
Authentication of plant floor clients shall not depend on any link outside the plant. The authentication server, or a local proxy or replica of it, shall sit inside the plant's network zone, and its round trip multiplied by the number of exchanges in one full authentication shall be counted in the outage budget for every join and reauthentication.
6.3 Security chosen together with roaming shall
The security configuration of each SSID that carries control traffic shall be one under which every client model on it completes a fast transition, and roam time under that configuration shall be measured on the production client before the configuration is approved.1
6.4 Key and session timers recorded and tested shall
The design shall record every key and session timer on control SSIDs and the authentication server: group key rekey, pairwise rekey, 802.1X reauthentication period, RADIUS Session-Timeout and Termination-Action, and idle timeout. Where a session timeout is sent, the Termination-Action shall request reauthentication rather than end the session. Each client model shall pass several cycles of every timer before rollout.2
6.5 Unapproved access points detected, never jammed shall
The wireless system shall detect access points and networks it does not own in production areas, alert a named person to any heard on a control channel or connected to the wired network, and shall not deauthenticate, contain, or jam networks the owner does not own.
About this page
Built from 12 sources: 4 standards bodies and labs, 1 regulator or government source, 1 protocol owner or alliance and 6 vendor documents. Researched and drafted with AI assistance, then reviewed and approved by Ben Rutter on . How pages are made
- First published
- Last updated
Change history (1)
- First published
Cite this page
Plain
Ben Rutter. "Security." OT Wireless, published October 6, 2026, updated October 5, 2026. https://otwireless.com/clauses/security/
APA 7
Rutter, B. (2026, October 6). Security. OT Wireless. https://otwireless.com/clauses/security/
BibTeX
@misc{rutter2026security,
author = {Rutter, Ben},
title = {{Security}},
year = {2026},
howpublished = {\url{https://otwireless.com/clauses/security/}},
organization = {OT Wireless},
}