Identity for Industry 4.0 (IoT, OT & Smart Infrastructure)
Combined Session
Wednesday, May 20, 2026 14:30—15:30
Location: B 09
Log in to download presentations
Wednesday, May 20, 2026 14:30—15:30
Location: B 09
Watch the video
In military operations, solving for reliable security at the tactical edge requires identity systems to remain responsive and operational in disrupted, degraded, intermittent, and low-bandwidth (DDIL) scenarios. Identity systems must continue to operate the same in theater whether or not connectivity to the home base is available. However, one does not need to be in the military to recognize the potential value of replicating these deployment patterns for OT. A DDIL-capable identity architecture ensures robust industrial operations and security regardless the connectivity status of the factory floor. In this talk Jon Lehtinen will walk through the components, architecture, use cases, and operation of a DDIL identity system to show how solving for DDIL scenarios can keep your staff, OT, and IT functional even if you lose the connection to the outside world.
Watch the video
European regulation is changing the identity design brief for Industry 4.0. In manufacturing, identity can no longer stop at workforce access or remote supplier access. NIS2 raises expectations for cyber risk management, reporting, and supply-chain security across 18 critical sectors, while the Cyber Resilience Act requires products with digital elements to be secure by default and maintained through their expected support period, with reporting obligations starting on 11 September 2026 and the main obligations applying from 11 December 2027.
This session explains why factories now need four identity planes: workforce, third-party, machine, and product. It shows how that shift changes the way organizations handle machine and gateway identity, product lifecycle trust, and the evidence needed for governance and incident response. Rather than treating NIS2 and the CRA as compliance checklists, the session turns them into a practical identity architecture problem for operations, suppliers, machines, and connected products.
Attendees will leave with:
- a clear model for separating workforce, third-party, machine, and product identities in a factory environment
- a practical view of how CRA changes product lifecycle identity, from secure defaults to updates and support periods
- a concrete understanding of how NIS2 shifts identity from access alone to evidence, review, and accountability after incidents or supplier activity
Watch the video
Industry 4.0 is moving faster than the identity layer underneath it. Sensors, robots, autonomous vehicles and AI agents now make decisions across organisational borders in real time - yet most still authenticate with vendor PKI, OAuth bearer tokens, or device certificates that cannot rotate, cannot prove provenance, and cannot survive a quantum break. The result is a trust gap at the very edge where Industry 4.0 actually has to work.
This talk introduces the missing layer. KERI gives every device and agent a self-certifying, post-quantum-ready identifier. ACDCs carry verifiable credentials with full chain-of-authority provenance. The GLEIF vLEI anchors that chain in a globally interoperable root of legal-entity identity. Drawing on Veridian's production deployments and complaint GLEIF vLEI tooling, the session shows how this stack lands on real Industry 4.0 problems - device onboarding, OT command authority and cross-operator interoperability - verifiable in milliseconds, with no bilateral integrations.