INDUSTRIAL SESSION AUTHORIZATION

Engineering-session authorization for industrial environments.

EWSP verifies the engineering application, workstation, project integrity, endpoint identity, and policy before privileged engineering communication is permitted. Its architecture is designed to re-evaluate authorized context while access remains active.

Native Windows enforcement Endpoint-agnostic architecture Built for segmented environments

EWSPLive authorization
● Agent connected
CURRENT SECURITY STATEAUTHORIZED

The engineering connection passed every required permission check.

01ApplicationPASS
02WorkstationPASS
03EndpointPASS
04ProjectPASS
05PolicyPASS
Trust score100 / 100PERMITTED

THE CONTROL GAP

Network visibility is not the same as session authorization.

Industrial security tools can show what happened on the network. They do not always control whether a specific engineering session should be allowed to continue.

An engineer may begin with valid access, then switch projects, modify code, reach the wrong asset, or operate outside the approved window. That change in context matters.

THE PERMISSION PIPELINE

Authorization requires every mandatory check to pass.

EWSP turns engineering context into a clear, explainable authorization decision.

01PASS

Application

Trusted engineering software

02PASS

Workstation

Approved Windows identity

03PASS

Endpoint

Verified industrial asset

04PASS

Project

Authorized project state

05PASS

Policy

Time and operation permitted

DECISION

Authorized

Communication permitted

If any mandatory check failsBLOCK

EWSP explains the failed condition and prevents unauthorized communication.

HOW EWSP WORKS

Trust the whole session—not only the connection.

1

Establish the session context

EWSP evaluates the workstation, application, project, target endpoint, policy, and approved operating conditions.

2

Authorize the engineering session

Only a session that matches the approved context is permitted to communicate with the protected industrial endpoint.

3

Continuously verify the session

EWSP keeps evaluating the active context. If a required condition changes, authorization can be withdrawn.

4

Enforce locally

A lightweight Windows service and native operating-system filtering act where engineering communication begins—even without continuous cloud connectivity.

THE DIFFERENCE

Authorization at the engineering workstation.

HIDS / OT MONITORINGDetect and explain activity
VPN / ZTNAControl network access
EWSPGovern the engineering session itself

Workstation + application + project + endpoint + policy

WHERE EWSP FITS

A distinct control for privileged engineering operations.

EWSP complements existing security controls by answering a different authorization question.

Existing technologyPrimary question
Firewalls

Can this network traffic flow?

EDR / HIDS

Is this endpoint or process malicious?

PAM

Who may use privileged credentials?

OT monitoring

What is happening in the plant?

EWSP

Should this engineering session be authorized to perform this privileged engineering operation?

DESIGNED TO COMPLEMENT—NOT REPLACE

Add authorization where engineering activity begins.

Industrial engineering platforms

EWSP adds an independent engineering-session authorization layer at the workstation.

OT monitoring platforms

EWSP adds authorization and local enforcement before unapproved communication proceeds.

EDR and endpoint security

EWSP evaluates industrial context even when the application itself is legitimate.

PAM and network access

EWSP evaluates the project, endpoint identity, destination, and policy after access is granted.

These are complementary architectural roles, not claims of current product integration.

60-SECOND PRODUCT WALKTHROUGH

See an authorized session—and a blocked one.

The short walkthrough follows EWSP from Learning through endpoint approval, policy generation, and native first-attempt protection.

▶ Play full-screen

CURRENT PROTOTYPE EVIDENCE

Demonstrated behavior—not inflated claims.

In a two-machine test environment, one Windows system acts as the engineering workstation and another as the simulated industrial endpoint. EWSP learns permitted behavior, creates an approved policy, allows the authorized service, and blocks attempts when mandatory checks fail.

This is an early technical validation, not a claim of plant-wide deployment or PLC-scale performance. Continuous project-integrity re-evaluation remains under development.

Native Windows WFP enforcementAuthorized service permitted; unknown service blocked on its first attempt.

Local Trust EngineApplication, workstation, endpoint, destination, and project checks.

Policy generationApproved inventory translated into enforceable permit and catch-all filters.

Industrial asset lifecycleDiscover, review, approve, reject, and retire.

Explainable authorization decisionsMandatory gates and failure reasons are visible to operators.

Offline enforcementLocal trust and protection without a continuous cloud dependency.

BUILT FOR INDUSTRIAL REALITY

Protocol-specific identity. Unified engineering-session authorization.

Identity providers normalize protocol-specific evidence into a common trust model. The Trust Engine authorizes engineering sessions consistently across industrial endpoints.

EWSP Simulator✓ AVAILABLE
EtherNet/IP (CIP)PLANNED
Siemens S7PLANNED
OPC UAPLANNED
Modbus/TCPPLANNED
Vendor SDKsEXTENSIBLE

Supported today✓ EWSP Simulator

Future identity providers• EtherNet/IP (CIP)
• Siemens S7
• OPC UA
• Modbus/TCP
• Vendor SDKs

ObservationEndpoint Identity ManagerIdentity providerNormalized identityTrust EngineDecision EngineNative WFP enforcement

The Trust Engine remains protocol-independent. Identity providers normalize protocol-specific evidence into a common authorization model.

REQUEST A DEMO

Should this engineering session be authorized?

We are looking for experienced OT security leaders, industrial operators, automation vendors, and design partners to pressure-test EWSP in a real industrial workflow.

contact@ewsp.org

Contact EWSP