Confidential Computing with Attested Key Release for Zero-Trust Industrial Cyber-Physical Systems
Abstract
Industrial cyber-physical systems increasingly use cloud analytics, remote maintenance, software-defined gateways, and virtualized edge compute. This convergence expands the attack surface while operational technology (OT) remains constrained by safety, availability, determinism, long asset lifetimes, and narrow maintenance windows. This paper presents an OTspecific method for using confidential computing with attested key release (AKR): cryptographic material is released only to workloads that prove, through remote attestation, that they execute inside an approved trusted execution environment (TEE) and an approved deployment configuration. The core contribution is an Attested Release Contract (ARC), a policy object that binds TEE measurements, signed configuration manifests, site and role context, minimum security versions, operational modes, fallback behavior, and credential lifetime into one release decision. The paper also defines a fail-safe release state machine, a protocol blueprint covering replay, impersonation, rollback, verifier compromise, and service exhaustion, and an OPC UA gateway case study that includes legacy coexistence and analytical latency constraints. The result is a zero-trust pattern that reduces host-secret exposure while keeping hard real-time control outside the attestation critical path. The paper does not claim a new TEE primitive or measured implementation result.