State-Aware Zero Trust Architecture for Offshore Wind Farms Based on Software-Defined Perimeter
Abstract
Offshore wind farms rely heavily on remote monitoring, maintenance, and control because physical access is constrained by weather and marine conditions. This dependence expands connectivity in operational technology environments and increases exposure to reconnaissance, asset discovery, and subsequent attack progression, which conventional perimeter protection cannot sufficiently restrict after access is obtained. To address this problem, this paper proposes a zero trust architecture for offshore wind farms based on Software Defined Perimeter. The proposed design places gateways between operational layers, reduces the security burden on legacy assets, and applies different communication procedures to normal, warning, and critical conditions. Normal operation uses lightweight authenticated reporting, warning conditions activate selective retransmission to preserve data visibility, and critical conditions allow only separately authorized control sessions protected through mutual authentication and encryption. A virtual testbed compared the proposed and perimeter architectures through external and internal attack scenarios, while a separate communication experiment used a 5% packet loss condition. The evaluated attack sequences were constrained under the stated trust assumptions, while mean warning-state report loss was 4.2 percentage points below the lightweight baseline. The proposed scheme matched the full recovery baseline’s reported mean loss rate with less communication volume.