BACnet Communication Engine for HVAC Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Building automation and control networks (BACnet) face security vulnerabilities due to different network protocols used by various equipment, posing risks to network security and requiring upgrades to more secure communication protocols.
Innovation Solution
A communication engine is introduced that identifies HVAC devices on BACnet networks, upgrades them to a more secure protocol (BACnet/SC), and disables communication using less secure protocols like BACnet/IP, ensuring secure communication and providing diagnostic attributes for tracking insecure communications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If building automation networks use legacy communication protocols (e.g., BACnet/IP), then compatibility with existing equipment is maintained, but network security vulnerabilities increase
Solution Approach 1:
The patent introduces a communication engine as an intermediary device that sits between legacy BACnet/IP devices and the secure network infrastructure. This engine translates and mediates communications, allowing legacy devices to operate securely without requiring their firmware to be upgraded. The communication engine enforces security policies and protocol translation, resolving the contradiction by maintaining compatibility while enhancing security.
Solution Approach 2:
The system segments the network into secure and legacy zones, with the communication engine acting as a gateway. Legacy devices are isolated in a controlled environment where their communications are monitored and translated. This segmentation allows the network to maintain support for legacy protocols in specific segments while protecting the overall system security architecture.
2Reliability
If HVAC devices are upgraded to secure communication protocols, then network security is enhanced, but device complexity and upgrade costs increase
Solution Approach 1:
The communication engine serves as an external intermediary that provides security functionality without requiring modification of the HVAC device firmware. By placing the security enforcement mechanism outside the legacy devices, the system achieves enhanced security while avoiding the complexity and cost of upgrading each individual device's firmware.
Solution Approach 2:
The communication engine automatically discovers legacy devices on the network, assesses their security posture, and implements appropriate security measures without requiring manual intervention at each device. The system self-configures security policies and translates communications automatically, reducing the operational complexity of securing the network.
3Reliability
If all HVAC devices are required to use secure protocols, then network security is improved, but operational flexibility and ease of integration are reduced
Solution Approach 1:
The system applies different security approaches to different devices based on their capabilities. Legacy devices that cannot be upgraded are handled through the communication engine's translation layer, while devices capable of upgrading can use native secure protocols. This localized approach to security enforcement maintains operational flexibility while achieving comprehensive security coverage.
Solution Approach 2:
The communication engine provides universal support for multiple protocol versions and security requirements, acting as a multi-functional gateway. It can translate between BACnet/IP and secure protocols, enforce security policies, and maintain compatibility with various device types, thereby preserving ease of integration across diverse equipment while enforcing security standards.
Data Source
AI summary
A building system includes heating ventilation or air conditioning (HVAC) devices configured for communication on a building automation network and a communication engine. The communication engine is configured to provide a diagnostic attribute. The diagnostic attribute indicates communications with the HVAC devices as being according to a first communication protocol or at least one different communication protocol. Systems and methods may detect insecure communications and/or upgrade in secure communication protocols in wireless or wired networks, such as, BACnet systems and/or subsystems.


