ZTSafe: Safety-Certified Risk-Adaptive Scheduling for Zero-Trust Time-Sensitive Industrial Networks
Abstract
1. Introduction
1.1. Four Gaps
1.2. Core Idea: Propose, Verify, Commit
1.3. Contributions
- Control safety contracts from zero-trust risk. We define a per-loop contract and an offline synthesis procedure (Algorithm 1) that derives its bounds from closed-loop reachability under worst-case disturbances, with a three-way split into theoretical bounds, engineering-calibrated bounds, and explicit safety margins. A dynamic coupling makes the admissible path-risk budget shrink as the plant’s runtime safety margin shrinks.
- A verified-execution architecture with an untrusted optimizer. ZTSafe’s trusted computing base contains only the evidence interface, the contract checker (runtime shield), the fallback library, and the atomic commit controller. The shield validates nine properties of every candidate schedule and outputs accept, reject, or fallback; the two-phase, precision time protocol (PTP)-aligned commit guarantees that the network always runs a complete old, complete new, or complete fallback configuration—never a mixture. Throughout, “verified” denotes acceptance by this independent runtime checker; machine-checked verification of the checker implementation is not claimed.
- Fail-safe guarantees. Under Assumption 1, including correct and uncompromised operation of the remaining trusted base, we prove that shield-accepted schedules keep every admitted critical loop inside its safe set (Theorem 1), that solver failure never causes an unverified configuration to execute (Theorem 2), and that recovery completes within provable per-path budget sums (17.0 ms on the normal path and 16.5 ms on the timeout path with our deployed stage budgets).
- Hardware evaluation against physical—not only network—metrics. On a testbed of eight TSN switches and three physical control loops (water level, motor speed, heading) under fourteen attack and fault scenarios, ZTSafe reduces safe-set violations from 12.8% (strongest baseline) to 0.9%, holds AoI at 0.87× its contract, recovers within three control periods, and executes zero unverified configurations across 10,000 injected solver failures, at an explicit and quantified cost of 1.8 percentage points of on-time completion.
| Algorithm 1: Communication safety contract synthesis (offline, per loop k) |
![]() |
2. Background and Related Work
2.1. TSN and Joint Routing and Scheduling
2.2. Zero-Trust and Trust-Aware Networking
2.3. Networked Control Under Delay and Loss
2.4. Age of Information in Industrial Control
2.5. Runtime Assurance and Safety Shields
2.6. Comparison
3. System Model, Threat Model, and Problem Definition
3.1. Network and Task Model
3.2. Physical Loop Model and Contracts
3.3. Zero-Trust Evidence Interface
3.4. Threat Model
- Compromise end devices that hold valid credentials and produce correctly authenticated traffic;
- Replay stale measurements whose cryptographic tags verify [1];
- Inject burst traffic from compromised devices into the control path;
- Selectively delay frames traversing a compromised switch;
- Selectively drop frames, including consecutive drops targeted at one loop;
- Mount on–off attacks that alternate misbehavior and good conduct to game reputation [17];
- Suppress or locally forge the evidence emitted by nodes it controls;
- Time its actions to coincide with reconfiguration windows;
- Craft workloads that drive the online optimizer toward timeout or infeasibility;
- Combine any of the above across multiple nodes.
3.5. Design Goals
4. Control Safety Contract Synthesis
4.1. Why Deadlines Are Not Enough: A Counterexample
4.2. Offline Control Models
4.3. Safe Sets
4.4. Deriving the Bounds
4.5. Coupling the Risk Budget to the Physical Margin
4.6. Synthesis Algorithm
5. ZTSafe Design and Formal Guarantees
5.1. Architecture Overview
5.2. Conservative Risk Estimation
5.3. Risk-Constrained Joint Routing and Scheduling
- Safety feasibility (hard constraints). For every admitted critical task: end-to-end delay ≤ ; worst-case AoI ≤ ; consecutive-loss exposure ≤ under the current loss model; jitter ≤ ; and aggregated path risk with the dynamic budget (4). These are never traded against the objectives below.
- Critical admission. Maximize , where admits task k and encodes criticality.
- Performance. Minimize , penalizing delay, age, residual risk, and the number of reconfigured flows (schedule churn is itself a disturbance).
5.4. Incremental Online Solving
5.5. Independent Runtime Safety Shield
- Every admitted task has a complete source-to-destination path;
- Every critical path satisfies its risk budget ;
- Delay and AoI bounds hold with the required margins;
- Burst-loss and jitter bounds hold;
- Slot assignments are conflict-free on every link;
- The risk version v is current (bounds have not moved since solving began);
- The topology version is current (no link state change since solving began);
- No safety-critical task has been silently dropped or downgraded relative to ;
- The change set is atomically committable within one protection window.
5.6. Certified Fallback Library
- F1—backup network plan: An alternative routing and GCL for the current task set, precomputed for the most probable failure patterns (single-link loss, single-switch isolation);
- F2—degraded control mode: The loop switches to a mode needing less of the network: halved sampling (e.g., motor loop from 10 to 20 ms with a locally retuned controller), local/embedded control, frozen setpoints, or suspension of maintenance-class traffic;
- F3—fail-safe action: Valves to safe position, speed ramp-down, hold last safe command, or controlled stop—the mode of last resort whose safety does not depend on the network at all.
5.7. Atomic Reconfiguration
5.8. Event-Triggered Repair
5.9. Formal Guarantees
5.9.1. Atomicity
5.9.2. Bounded Recovery
5.9.3. Risk Conservativeness
6. Implementation and Evaluation
6.1. Testbed and Platform
6.2. Software Realization
6.3. Evaluation Methodology
6.4. Exp1: Physical Safety Under Attack (RQ1)
6.5. Exp2: Deadline-Only vs. Safety Contract (RQ2)
6.6. Exp3: Risk Aggregation Comparison (RQ3)
6.7. Exp4: Solver Failure Injection (RQ4)
6.8. Exp5: Atomic vs. Non-Atomic Reconfiguration (RQ5)
6.9. Exp6: Safety–Performance Trade-Off (RQ6)
6.10. Exp7: Scalability (RQ7)
6.11. Ablation Study
7. Discussion and Conclusions
7.1. Model Dependence
7.2. Residual Trusted-Base and Implementation Risk
7.3. Imperfect Risk Estimation
7.4. External Validity of the Scenario Suite
7.5. Availability Versus Safety
7.6. Interfaces to Identity and Analytics
7.7. Conclusions
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
Abbreviations
| AoI | Age of Information |
| CNC | Centralized Network Configuration |
| CPS | Cyber-Physical System |
| CVaR | Conditional Value at Risk |
| ECE | Expected Calibration Error |
| GCL | Gate Control List |
| HIL | Hardware in the Loop |
| IAE | Integral Absolute Error |
| OTC | On-Time Completion |
| PLC | Programmable Logic Controller |
| PTP | Precision Time Protocol |
| SDN | Software-Defined Networking |
| TCB | Trusted Computing Base |
| TSN | Time-Sensitive Networking |
Appendix A
| Group | Symbol | Meaning |
|---|---|---|
| Network | TSN topology: switches/end stations V, links E | |
| Task k: source, destination, period, frame size, contract | ||
| Path-selection variable (task k on path p) | ||
| Slot-assignment variable (task k, link e, slot ) | ||
| Schedule (routing + GCL) active at time t | ||
| Evidence, repair, verification, and commit stage times | ||
| Solver time budget; fallback verification time | ||
| Risk | Evidence for node i: authentication assurance, behavioral anomaly, fault/loss indicators, utilization | |
| Smoothed risk estimate; conservative risk upper bound | ||
| Evidence uncertainty; evidence staleness | ||
| Smoothing factor; uncertainty inflation; staleness inflation; target risk-underestimation rate | ||
| Aggregated risk of path P | ||
| Control | State, input, disturbance of loop k | |
| Safe set of loop k | ||
| Contract: delay, AoI, burst-loss, jitter, risk bounds; safe set | ||
| Runtime safety margin; nominal margin | ||
| Dynamic risk budget; base budget; clip floor | ||
| Fallback entry: trigger set, network plan, control mode, validity conditions |
Appendix B
| ID/Scenario | Capability or Fault | Trigger Mechanism | Expected Response | External Anchor |
|---|---|---|---|---|
| S1 Credentialed replay | Valid-MAC stale measurements from compromised PLC | Sequence/timestamp anomaly raises | Risk bound up; reroute or F2 | ATT&CK ICS T0856 [44]; replay [1] |
| S2 Burst flooding | Authenticated burst traffic into control path | Utilization + latency anomaly | Isolate flow; protect critical slots | T0814 [44] |
| S3 On–off gaming | Alternating misbehavior/ good conduct | Uncertainty stays high | Bound stays high despite calm phases | on–off trust attacks [17] |
| S4 Selective delay | Compromised switch delays chosen frames | Per-hop latency evidence | Path risk over budget; reroute | T0830 [44] |
| S5 Selective drop | Targeted consecutive drops on one loop | Loss evidence ; burst-loss counter | Reroute before exhausted | T0804 [44] |
| S6 Jitter injection | Irregular frame release at compromised node | Jitter measurement vs. | Reroute; tighten schedule | TSN timing surface [14] |
| S7 Coordinated multi-node | S1 + S2 + S4 across three nodes | Multiple evidence streams | Prune region; F1/F2 as needed | stealthy ICS campaigns [35] |
| S8 Evidence suppression | Node stops reporting telemetry | Staleness grows | Bound rises toward 1; avoid node | T0804/T0856 [44] |
| S9 Window-timed attack | Burst timed at reconfiguration windows | Guard-band monitoring | Atomic commit unaffected; retry | TSN reconfiguration abuse [14] |
| S10 Solver stress | Adversarial task churn forcing timeouts | Repair exceeds | Incumbent retained or fallback; no unverified execution | algorithmic-complexity DoS [38] |
| S11 Link failure | Single link down | Topology event | Incremental repair or F1 | transient outage [45] |
| S12 Switch failure | Switch reboot (30 s outage) | Topology event | F1; F2 for stranded loops | crash-restart fault [45] |
| S13 Topology flap | Repeated link up/down (2 s period) | Rapid topology versioning | Hysteresis; fallback if unstable | intermittent fault [45] |
| S14 Stale-risk injection | Evidence delivery delayed en route | Risk-version check fails | Shield rejects candidate (check 6) | delayed telemetry/omission [45] |
Appendix C
| Scenario | ZTSafe (Count) | ZTSafe Rate [95% CI] | SA-TSN (Count) | SA-TSN Rate [95% CI] |
|---|---|---|---|---|
| S1 | 0 | 0.0% [0.00, 0.38] | 198 | 19.8% [17.45, 22.38] |
| S2 | 0 | 0.0% [0.00, 0.38] | 176 | 17.6% [15.36, 20.08] |
| S3 | 41 | 4.1% [3.04, 5.51] | 187 | 18.7% [16.40, 21.23] |
| S4 | 0 | 0.0% [0.00, 0.38] | 142 | 14.2% [12.17, 16.50] |
| S5 | 0 | 0.0% [0.00, 0.38] | 168 | 16.8% [14.61, 19.24] |
| S6 | 0 | 0.0% [0.00, 0.38] | 121 | 12.1% [10.22, 14.27] |
| S7 | 12 | 1.2% [0.69, 2.09] | 214 | 21.4% [18.97, 24.05] |
| S8 | 38 | 3.8% [2.78, 5.17] | 173 | 17.3% [15.08, 19.77] |
| S9 | 0 | 0.0% [0.00, 0.38] | 88 | 8.8% [7.20, 10.72] |
| S10 | 0 | 0.0% [0.00, 0.38] | 61 | 6.1% [4.78, 7.76] |
| S11 | 0 | 0.0% [0.00, 0.38] | 42 | 4.2% [3.12, 5.63] |
| S12 | 0 | 0.0% [0.00, 0.38] | 58 | 5.8% [4.51, 7.42] |
| S13 | 0 | 0.0% [0.00, 0.38] | 74 | 7.4% [5.94, 9.19] |
| S14 | 35 | 3.5% [2.53, 4.83] | 90 | 9.0% [7.38, 10.93] |
| Total | 126 | 0.9% [0.76, 1.07] | 1792 | 12.8% [12.26, 13.36] |
References
- Mo, Y.; Sinopoli, B. Secure Control Against Replay Attacks. In Proceedings of the 47th Annual Allerton Conference on Communication, Control, and Computing; IEEE: Piscataway, NJ, USA, 2009; pp. 911–918. [Google Scholar] [CrossRef] [Scilit]
- Rose, S.; Borchert, O.; Mitchell, S.; Connelly, S. Zero Trust Architecture; Technical Report NIST Special Publication 800-207; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2020. [Google Scholar] [CrossRef] [Scilit]
- Gilman, E.; Barth, D. Zero Trust Networks: Building Secure Systems in Untrusted Networks; O’Reilly Media: Sebastopol, CA, USA, 2017. [Google Scholar]
- IEEE Std 802.1Qbv-2015; IEEE Standard for Local and Metropolitan Area Networks—Bridges and Bridged Networks—Amendment 25: Enhancements for Scheduled Traffic. IEEE: Piscataway, NJ, USA, 2016.
- Kaul, S.; Yates, R.; Gruteser, M. Real-Time Status: How Often Should One Update? In Proceedings of the IEEE INFOCOM; IEEE: Piscataway, NJ, USA, 2012; pp. 2731–2735. [Google Scholar] [CrossRef] [Scilit]
- Craciunas, S.S.; Serna Oliver, R.; Chmelík, M.; Steiner, W. Scheduling Real-Time Communication in IEEE 802.1Qbv Time Sensitive Networks. In Proceedings of the 24th International Conference on Real-Time Networks and Systems (RTNS); ACM: New York, NY, USA, 2016; pp. 183–192. [Google Scholar] [CrossRef] [Scilit]
- Falk, J.; Dürr, F.; Rothermel, K. Exploring Practical Limitations of Joint Routing and Scheduling for TSN with ILP. In Proceedings of the 24th IEEE International Conference on Embedded and Real-Time Computing Systems and Applications (RTCSA); IEEE: Piscataway, NJ, USA, 2018; pp. 136–146. [Google Scholar] [CrossRef] [Scilit]
- Alshiekh, M.; Bloem, R.; Ehlers, R.; Könighofer, B.; Niekum, S.; Topcu, U. Safe Reinforcement Learning via Shielding. In Proceedings of the AAAI Conference on Artificial Intelligence; AAAI: Washington, DC, USA, 2018; pp. 2669–2678. [Google Scholar] [CrossRef] [Scilit]
- Li, Q.; Peng, Y.; Al-Hazemi, F.; Lee, J. 3-D Polarized Spatial Scattering Modulation. IEEE Trans. Commun. 2025, 73, 13413–13425. [Google Scholar] [CrossRef] [Scilit]
- Wei, H.; Peng, Y.; Yue, M.; Al-Hazemi, F.; Lee, J. STAR-RIS-Enabled System Design with Dual-Index Modulation for Industrial IoT System. IEEE Internet Things J. 2025, 13, 2644–2652. [Google Scholar] [CrossRef] [Scilit]
- Reusch, N.; Craciunas, S.S.; Pop, P. Dependability-Aware Routing and Scheduling for Time-Sensitive Networking. IET Cyber-Phys. Syst. Theory Appl. 2022, 7, 124–146. [Google Scholar] [CrossRef] [Scilit]
- IEEE Std 802.1AS-2020; IEEE Standard for Local and Metropolitan Area Networks—Timing and Synchronization for Time-Sensitive Applications. IEEE: Piscataway, NJ, USA, 2020.
- Raagaard, M.L.; Pop, P.; Gutiérrez, M.; Steiner, W. Runtime Reconfiguration of Time-Sensitive Networking (TSN) Schedules for Fog Computing. In Proceedings of the IEEE Fog World Congress (FWC); IEEE: Piscataway, NJ, USA, 2017; pp. 1–6. [Google Scholar] [CrossRef] [Scilit]
- Ergenç, D.; Brülhart, C.; Neumann, J.; Krüger, L.; Fischer, M. On the Security of IEEE 802.1 Time-Sensitive Networking. In Proceedings of the IEEE International Conference on Communications Workshops (ICC Workshops); IEEE: Piscataway, NJ, USA, 2021; pp. 1–6. [Google Scholar] [CrossRef] [Scilit]
- Syed, N.F.; Shah, S.W.; Shaghaghi, A.; Anwar, A.; Baig, Z.; Doss, R. Zero Trust Architecture (ZTA): A Comprehensive Survey. IEEE Access 2022, 10, 57143–57179. [Google Scholar] [CrossRef] [Scilit]
- DeCusatis, C.; Liengtiraphan, P.; Sager, A.; Pinelli, M. Implementing Zero Trust Cloud Networks with Transport Access Control and First Packet Authentication. In Proceedings of the IEEE International Conference on Smart Cloud (SmartCloud); IEEE: Piscataway, NJ, USA, 2016; pp. 5–10. [Google Scholar] [CrossRef] [Scilit]
- Sun, Y.L.; Han, Z.; Liu, K.J.R. Defense of Trust Management Vulnerabilities in Distributed Networks. IEEE Commun. Mag. 2008, 46, 112–119. [Google Scholar] [CrossRef] [Scilit]
- National Institute of Standards and Technology. Implementing a Zero Trust Architecture; Technical Report NIST Special Publication 1800-35; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2025. [Google Scholar] [CrossRef] [Scilit]
- Zanasi, C.; Russo, S.; Colajanni, M. Flexible Zero Trust Architecture for the Cybersecurity of Industrial IoT Infrastructures. Ad Hoc Netw. 2024, 156, 103414. [Google Scholar] [CrossRef] [Scilit]
- Mahfouzi, R.; Aminifar, A.; Samii, S.; Eles, P.; Peng, Z. Security-Aware Routing and Scheduling for Control Applications on Ethernet TSN Networks. ACM Trans. Des. Autom. Electron. Syst. 2019, 25, 1–26. [Google Scholar] [CrossRef] [Scilit]
- Hespanha, J.P.; Naghshtabrizi, P.; Xu, Y. A Survey of Recent Results in Networked Control Systems. Proc. IEEE 2007, 95, 138–162. [Google Scholar] [CrossRef] [Scilit]
- Zhang, W.; Branicky, M.S.; Phillips, S.M. Stability of Networked Control Systems. IEEE Control Syst. Mag. 2001, 21, 84–99. [Google Scholar] [CrossRef] [Scilit]
- Li, Q.; Peng, Y.; AL-Hazemi, F.; Lee, J. Polarized RIS-Assisted Polarized Spatial Scattering Modulation. IEEE Internet Things J. 2025, 12, 33830–33843. [Google Scholar] [CrossRef] [Scilit]
- Blanchini, F. Set Invariance in Control. Automatica 1999, 35, 1747–1767. [Google Scholar] [CrossRef] [Scilit]
- Ames, A.D.; Xu, X.; Grizzle, J.W.; Tabuada, P. Control Barrier Function Based Quadratic Programs for Safety Critical Systems. IEEE Trans. Autom. Control 2017, 62, 3861–3876. [Google Scholar] [CrossRef] [Scilit]
- Tabuada, P. Event-Triggered Real-Time Scheduling of Stabilizing Control Tasks. IEEE Trans. Autom. Control 2007, 52, 1680–1685. [Google Scholar] [CrossRef] [Scilit]
- Heemels, W.P.M.H.; Johansson, K.H.; Tabuada, P. An Introduction to Event-Triggered and Self-Triggered Control. In Proceedings of the 51st IEEE Conference on Decision and Control (CDC); IEEE: Piscataway, NJ, USA, 2012; pp. 3270–3285. [Google Scholar] [CrossRef] [Scilit]
- Barzegaran, M.; Pop, P. Communication Scheduling for Control Performance in TSN-Based Fog Computing Platforms. IEEE Access 2021, 9, 50782–50797. [Google Scholar] [CrossRef] [Scilit]
- Yates, R.D.; Sun, Y.; Brown, D.R.; Kaul, S.K.; Modiano, E.; Ulukus, S. Age of Information: An Introduction and Survey. IEEE J. Sel. Areas Commun. 2021, 39, 1183–1210. [Google Scholar] [CrossRef] [Scilit]
- Ayan, O.; Vilgelm, M.; Klügel, M.; Hirche, S.; Kellerer, W. Age-of-Information vs. Value-of-Information Scheduling for Cellular Networked Control Systems. In Proceedings of the 10th ACM/IEEE International Conference on Cyber-Physical Systems (ICCPS); ACM: New York, NY, USA, 2019; pp. 109–117. [Google Scholar] [CrossRef] [Scilit]
- Sha, L. Using Simplicity to Control Complexity. IEEE Softw. 2001, 18, 20–28. [Google Scholar] [CrossRef] [Scilit]
- Seto, D.; Krogh, B.; Sha, L.; Chutinan, A. The Simplex Architecture for Safe Online Control System Upgrades. In Proceedings of the American Control Conference (ACC); IEEE: Piscataway, NJ, USA, 1998; pp. 3504–3508. [Google Scholar] [CrossRef] [Scilit]
- Bak, S.; Johnson, T.T.; Caccamo, M.; Sha, L. Real-Time Reachability for Verified Simplex Design. In Proceedings of the IEEE Real-Time Systems Symposium (RTSS); IEEE: Piscataway, NJ, USA, 2014; pp. 138–148. [Google Scholar] [CrossRef] [Scilit]
- Reitblatt, M.; Foster, N.; Rexford, J.; Schlesinger, C.; Walker, D. Abstractions for Network Update. In Proceedings of the Proceedings of ACM SIGCOMM; ACM: New York, NY, USA, 2012; pp. 323–334. [Google Scholar] [CrossRef] [Scilit]
- Urbina, D.I.; Giraldo, J.A.; Cardenas, A.A.; Tippenhauer, N.O.; Valente, J.; Faisal, M.; Ruths, J.; Candell, R.; Sandberg, H. Limiting the Impact of Stealthy Attacks on Industrial Control Systems. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS); ACM: New York, NY, USA, 2016; pp. 1092–1105. [Google Scholar] [CrossRef] [Scilit]
- Rockafellar, R.T.; Uryasev, S. Optimization of Conditional Value-at-Risk. J. Risk 2000, 2, 21–41. [Google Scholar] [CrossRef] [Scilit]
- Althoff, M. An Introduction to CORA 2015. In Proceedings of the Workshop on Applied Verification for Continuous and Hybrid Systems (ARCH); EasyChair: Stockport, UK, 2015; pp. 120–151. [Google Scholar] [CrossRef] [Scilit]
- Crosby, S.A.; Wallach, D.S. Denial of Service via Algorithmic Complexity Attacks. In Proceedings of the 12th USENIX Security Symposium; USENIX Association: Berkeley, CA, USA, 2003; pp. 29–44. [Google Scholar]
- Angelopoulos, A.N.; Bates, S. Conformal Prediction: A Gentle Introduction. Found. Trends Mach. Learn. 2023, 16, 494–591. [Google Scholar] [CrossRef] [Scilit]
- Pillay, P.; Krishnan, R. Modeling, Simulation, and Analysis of Permanent-Magnet Motor Drives. II. The Brushless DC Motor Drive. IEEE Trans. Ind. Appl. 1989, 25, 274–279. [Google Scholar] [CrossRef] [Scilit]
- Google. OR-Tools CP-SAT Solver. 2024. Available online: https://developers.google.com/optimization/cp (accessed on 10 July 2026).
- Johansson, K.H. The Quadruple-Tank Process: A Multivariable Laboratory Process with an Adjustable Zero. IEEE Trans. Control Syst. Technol. 2000, 8, 456–465. [Google Scholar] [CrossRef] [Scilit]
- Mohanraj, D.; Aruldavid, R.; Verma, R.; Sathiyasekar, K.; Barnawi, A.B.; Chokkalingam, B.; Mihet-Popa, L. A Review of BLDC Motor: State of Art, Advanced Control Techniques, and Applications. IEEE Access 2022, 10, 54833–54869. [Google Scholar] [CrossRef] [Scilit]
- MITRE Corporation. MITRE ATT&CK for Industrial Control Systems. 2025. Available online: https://attack.mitre.org/matrices/ics/ (accessed on 14 August 2026).
- Avižienis, A.; Laprie, J.C.; Randell, B.; Landwehr, C. Basic Concepts and Taxonomy of Dependable and Secure Computing. IEEE Trans. Dependable Secur. Comput. 2004, 1, 11–33. [Google Scholar] [CrossRef] [Scilit]












| Approach | Dynamic Risk | TSN Det. | AoI/Loss Contract | Physical Safety | Fallback on Solver Failure | Atomic Switch |
|---|---|---|---|---|---|---|
| QoS-TSN scheduling [6,7] | No | Yes | Limited 1 | No | No | Partial |
| Control-aware TSN [28] | No | Yes | Limited 1 | Partial | No | Partial |
| Zero-trust SDN [16] | Yes | No | No | No | No | Partial |
| Security-aware TSN [11,20] | Yes | Yes | Limited | Indirect | Limited | Yes |
| ZTSafe (Proposed) | Yes | Yes | Yes | Yes | Yes | Yes |
| Symbol | Meaning |
|---|---|
| Per-loop communication safety contract: delay, AoI, burst-loss, jitter, and path-risk bounds; safe set | |
| Safe envelope: the set of degradation-bound tuples certified by closed-loop reachability | |
| Conservative (uncertainty- and staleness-inflated) risk upper bound of node i | |
| , | Aggregated path risk; margin-coupled dynamic risk budget |
| Runtime safety margin of loop k: distance of the state to the safe-set boundary | |
| ; | Active schedule; evidence, repair, verification, and commit stage budgets |
| Loop | Safe Set | ||||||
|---|---|---|---|---|---|---|---|
| Water level | 20 ms | 9 ms | 28 ms | 5 | 1.5 ms | 0.30 | level 20–80 cm |
| Motor speed | 10 ms | 2 ms | 15 ms | 2 | 0.5 ms | 0.20 | speed 2600–3000 rpm |
| Heading | 20 ms | 5 ms | 40 ms | 2 | 1.0 ms | 0.25 | heading error ≤ |
| Component | Configuration |
|---|---|
| TSN network | 8 switches, 1 GbE, IEEE 802.1Qbv/Qci/CB; mesh topology (Figure 8) |
| Synchronization | IEEE 802.1AS PTP grandmaster; measured error < 1 μs |
| Streams | 24 flows total, 8 critical control flows, frame sizes 128–256 B |
| Water-level loop | Tank, level sensor, pump; controller C1, period 20 ms |
| Motor-speed loop | BLDC motor [40], encoder, inverter; controller C2, period 10 ms |
| Heading loop | Mobile robot, IMU heading sensor, steering; controller C3, period 20 ms |
| Orchestrator host | 6-core x86, 32 GB RAM, Ubuntu 22.04 (PREEMPT_RT); risk engine, optimizer, shield, fallback manager as separate processes |
| Solver | OR-Tools CP-SAT v9.8 [41] (C++ 17/Python 3.12), budget ms |
| Shield | Independent Rust module, deterministic checks only |
| Risk parameters | , , , |
| Attack injector | Dedicated node; delay/loss/jitter/replay/burst/topology faults |
| Method | Violation Rate | 95% CI | Max Excursion | IAE | Recovery (P99) | OTC | AoI P99/Contract |
|---|---|---|---|---|---|---|---|
| Best-effort Ethernet | 47.3% | [46.5, 48.1] | 3.42 | 2.61 | no recovery | 71.8% | 3.21× |
| QoS-TSN | 34.2% | [33.4, 35.0] | 2.86 | 1.94 | no recovery | 97.8% | 1.64× |
| Control-aware TSN | 18.6% | [18.0, 19.3] | 1.92 | 1.41 | 9.2 | 96.4% | 0.98× |
| Zero-trust SDN | 22.4% | [21.7, 23.1] | 2.13 | 1.67 | 7.5 | 91.2% | 1.38× |
| SA-TSN | 12.8% | [12.3, 13.4] | 1.55 | 1.28 | 5.8 | 96.1% | 1.21× |
| ZTSafe (full) | 0.9% | [0.76, 1.07] | 1.04 | 1.06 | 3.0 | 94.3% | 0.87× |
| Method | Reported Feasible? | Deadline Met | AoI P99 | Max Consec. Losses | Physical Outcome |
|---|---|---|---|---|---|
| QoS-TSN | Yes | 100% | 24.6 ms | 5 | excursion to rpm beyond limit; violations in 8.4% of episodes |
| SA-TSN | Yes | 99.2% | 21.3 ms | 4 | violations in 5.1% of episodes |
| ZTSafe | Rejects plan → F2 (sampling ms, local control) | 100% | 13.8 ms | 1 | 0 violations |
| Risk Model | Attack Admission | False Isolation | Safety Violations | Schedule Feasibility |
|---|---|---|---|---|
| Mean reputation | 14.2% | 2.3% | 6.8% | 98.4% |
| Worst-hop (SA-TSN) | 6.8% | 3.1% | 3.9% | 96.7% |
| Cumulative risk | 5.1% | 4.8% | 3.2% | 94.9% |
| CVaR (level 0.9) | 1.9% | 5.6% | 1.3% | 92.8% |
| Uncertainty-aware bound (ZTSafe) | 1.6% | 3.9% | 0.9% | 94.3% |
| Failure Type | Injected | Unverified Executed | Old Plan Retained | F1/F2/F3 | Safety Violations |
|---|---|---|---|---|---|
| Timeout (5/10/20 ms) | 4000 | 0 | 81.2% | 16.4%/2.1%/0.3% | 0 |
| Solver crash | 1500 | 0 | 76.8% | 19.6%/3.2%/0.4% | 0 |
| Infeasible/illegal candidate | 2000 | 0 | 79.4% | 17.5%/2.8%/0.3% | 0 |
| Incomplete path | 1500 | 0 | 74.1% | 22.3%/3.3%/0.3% | 0 |
| Stale risk version | 1000 | 0 | 68.9% | 27.4%/3.4%/0.3% | 0 |
| Total | 10,000 | 0 | 77.9% | 19.1%/2.7%/0.3% | 0 |
| Update Strategy | Mixed-Config Duration | Transient Blackhole | AoI Spike (×Contract) | Loss Burst (Frames) | Safety Violations |
|---|---|---|---|---|---|
| Per-switch sequential | 41.3 ms | 3.8% of events | 3.2× | 6.1 | 12.4% of episodes |
| Plain batch | 17.6 ms | 1.2% | 1.9× | 3.4 | 4.1% |
| ZTSafe guard-window atomic | 0 ms | 0% | 1.0× | 0 | 0% |
| Safety Violations | Admission Rate | IAE | Fallback Trigger Rate | False Isolation | |
|---|---|---|---|---|---|
| 0 (no uncertainty term) | 4.2% | 97.2% | 1.18 | 2.1% | 2.1% |
| 0.5 | 1.8% | 95.8% | 1.09 | 3.4% | 2.9% |
| 1.0 (deployed) | 0.9% | 94.3% | 1.06 | 4.6% | 3.9% |
| 2.0 | 0.4% | 89.6% | 1.05 | 8.9% | 6.3% |
| Setting | Safety Violations | Admission | OTC | Shield Verify |
|---|---|---|---|---|
| margin | 2.1% | 95.9% | 96.0% | 0.9 ms |
| margin (deployed) | 0.9% | 94.3% | 94.3% | 0.9 ms |
| margin | 0.5% | 92.6% | 92.7% | 0.9 ms |
| margin | 0.3% | 89.8% | 89.9% | 0.9 ms |
| (deployed) | 0.9% | 94.3% | 94.3% | 0.9 ms |
| 0.5% | 91.8% | 91.9% | 0.9 ms | |
| 0.3% | 87.4% | 87.5% | 0.9 ms |
| Level | Scale | Incremental Repair | Full Recompute | Shield Verify | CPU/Mem |
|---|---|---|---|---|---|
| L1 hardware | 8 sw/24 flows | 6.8 ms | 84 ms | 0.9 ms | 18%/210 MB |
| L2 HIL | 16 sw/120 flows | 11.2 ms | 412 ms | 2.3 ms | 34%/480 MB |
| L3 simulation | 64 sw/1000 flows | 38.6 ms | >budget (fallback path) | 9.8 ms | 71%/2.1 GB |
| Variant | Exposed Failure Mode | Violations | Key Symptom |
|---|---|---|---|
| Full ZTSafe | — | 0.9% | — |
| − Safety contract | Deadline met, physics violated | 15.7% | AoI P99 at 1.58× contract |
| − AoI constraint | Stale data arrives on time | 8.3% | 12.4% stale measurements |
| − Risk uncertainty | Optimism under thin evidence | 3.8% | attack admission 6.2% |
| − Safety shield | Illegal candidates execute | 5.4% | 217 illegal configs per |
| − Fallback library | Communication gap when unsolvable | 4.9% | mean gap 86 ms |
| Non-atomic update | Mixed old/new GCLs | 4.1% | 17.6 ms mixed duration |
| Fixed risk threshold | Budget ignores physical margin | 2.6% | near-boundary admission 4.8% |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Zhou, H.; Lei, H.; Yang, M. ZTSafe: Safety-Certified Risk-Adaptive Scheduling for Zero-Trust Time-Sensitive Industrial Networks. Future Internet 2026, 18, 466. https://doi.org/10.3390/fi18090466
Zhou H, Lei H, Yang M. ZTSafe: Safety-Certified Risk-Adaptive Scheduling for Zero-Trust Time-Sensitive Industrial Networks. Future Internet. 2026; 18(9):466. https://doi.org/10.3390/fi18090466
Chicago/Turabian StyleZhou, Haozhe, Hang Lei, and Maolin Yang. 2026. "ZTSafe: Safety-Certified Risk-Adaptive Scheduling for Zero-Trust Time-Sensitive Industrial Networks" Future Internet 18, no. 9: 466. https://doi.org/10.3390/fi18090466
APA StyleZhou, H., Lei, H., & Yang, M. (2026). ZTSafe: Safety-Certified Risk-Adaptive Scheduling for Zero-Trust Time-Sensitive Industrial Networks. Future Internet, 18(9), 466. https://doi.org/10.3390/fi18090466


