BACnet Communication Engine for HVAC Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Building automation and control networks (BACnet) face security vulnerabilities due to different network protocols used by various equipment, posing risks to network security and requiring upgrades to more secure communication protocols.

Innovation Solution

A communication engine is introduced that identifies HVAC devices on BACnet networks, upgrades them to a more secure protocol (BACnet/SC), and disables communication using less secure protocols like BACnet/IP, ensuring secure communication and providing diagnostic attributes for tracking insecure communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If building automation networks use legacy communication protocols (e.g., BACnet/IP), then compatibility with existing equipment is maintained, but network security vulnerabilities increase

Engineering Contradiction:
Improvenetwork securityVSAvoidprotocol compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a communication engine as an intermediary device that sits between legacy BACnet/IP devices and the secure network infrastructure. This engine translates and mediates communications, allowing legacy devices to operate securely without requiring their firmware to be upgraded. The communication engine enforces security policies and protocol translation, resolving the contradiction by maintaining compatibility while enhancing security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the network into secure and legacy zones, with the communication engine acting as a gateway. Legacy devices are isolated in a controlled environment where their communications are monitored and translated. This segmentation allows the network to maintain support for legacy protocols in specific segments while protecting the overall system security architecture.

Inventive Principle:
Principle #1Segmentation

2Reliability

If HVAC devices are upgraded to secure communication protocols, then network security is enhanced, but device complexity and upgrade costs increase

Engineering Contradiction:
Improvenetwork securityVSAvoidfirmware upgrade complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The communication engine serves as an external intermediary that provides security functionality without requiring modification of the HVAC device firmware. By placing the security enforcement mechanism outside the legacy devices, the system achieves enhanced security while avoiding the complexity and cost of upgrading each individual device's firmware.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The communication engine automatically discovers legacy devices on the network, assesses their security posture, and implements appropriate security measures without requiring manual intervention at each device. The system self-configures security policies and translates communications automatically, reducing the operational complexity of securing the network.

Inventive Principle:
Principle #25Self-service

3Reliability

If all HVAC devices are required to use secure protocols, then network security is improved, but operational flexibility and ease of integration are reduced

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice integration ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies different security approaches to different devices based on their capabilities. Legacy devices that cannot be upgraded are handled through the communication engine's translation layer, while devices capable of upgrading can use native secure protocols. This localized approach to security enforcement maintains operational flexibility while achieving comprehensive security coverage.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The communication engine provides universal support for multiple protocol versions and security requirements, acting as a multi-functional gateway. It can translate between BACnet/IP and secure protocols, enforce security policies, and maintain compatibility with various device types, thereby preserving ease of integration across diverse equipment while enforcing security standards.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11368493B2System for and method of detecting communication security in building automation and control networks
Publication Date: 2022.06.21 TYCO FIRE & SECURITY GMBH
  • US11368493B2 patent drawing
  • US11368493B2 patent drawing
  • US11368493B2 patent drawing

AI summary

A building system includes heating ventilation or air conditioning (HVAC) devices configured for communication on a building automation network and a communication engine. The communication engine is configured to provide a diagnostic attribute. The diagnostic attribute indicates communications with the HVAC devices as being according to a first communication protocol or at least one different communication protocol. Systems and methods may detect insecure communications and/or upgrade in secure communication protocols in wireless or wired networks, such as, BACnet systems and/or subsystems.