Security Bridge for BACnet MS/TP Bus Injection Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Building management systems (BMS) using Master-Slave/Token Passing (MS/TP) and Building Automation Control Network (BACnet) protocols lack security, allowing hostile devices to inject unwanted communications, compromising the integrity of connected equipment and systems.

Innovation Solution

A security bridge device is introduced into the MS/TP communication bus, equipped with a processing circuit and memory, which selectively forwards packets based on a security configuration, identifying and filtering MS/TP address, Network Protocol Data Unit (NPDU), and Application Protocol Data Unit (APDU) information to prevent unauthorized communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security bridge device is introduced into the MS/TP communication bus, then network security is improved by preventing unauthorized communications, but device complexity increases due to the additional bridge device with processing circuit and security configuration

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a bridge device as an intermediary component in the MS/TP communication bus that selectively forwards packets based on security configurations. This mediator intercepts communications between BACnet devices, applies security rules, and决定是否 forwarding packets, thereby providing security without requiring modifications to the original devices while maintaining protocol compatibility

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The bridge device segments the MS/TP communication bus into multiple network segments, creating isolated zones that can be securely managed. By dividing the network into segments and controlling inter-segment communication through the bridge, the system achieves security through spatial separation while allowing legitimate communications within each segment

Inventive Principle:
Principle #1Segmentation

2Reliability

If the bridge device selectively forwards packets based on security configuration, then unauthorized communications are blocked, but communication overhead increases due to packet inspection and filtering operations

Engineering Contradiction:
Improvecommunication integrityVSAvoidpacket forwarding delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The bridge device performs preliminary actions by pre-configuring security rules and criteria before actual packet forwarding occurs. Security configurations, including allowed MAC addresses, MS/TP addresses, and packet type filters, are established in advance, enabling the bridge to quickly match incoming packets against predefined rules rather than performing complex analysis for each packet

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the bridge device filters MS/TP address, NPDU, and APDU information, then packet injection attacks are prevented, but information loss occurs due to selective blocking of packets

Engineering Contradiction:
Improvesecurity against injection attacksVSAvoidblocked legitimate packets
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The bridge device implements feedback mechanisms by monitoring the effectiveness of security filtering and adjusting configurations based on observed traffic patterns and security threats. The system can learn from blocked packets and legitimate communication requirements, refining security rules to reduce false positives while maintaining protection against injection attacks

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20230308417A1Systems and methods for implementing security protocols in a building management system
Publication Date: 2023.09.28 TYCO FIRE & SECURITY GMBH
  • US20230308417A1 patent drawing
  • US20230308417A1 patent drawing
  • US20230308417A1 patent drawing

AI summary

A building management system network includes a Master-Slave/Token Passing (MS/TP) communication bus. The network further includes a number of Building Automation Control network (BACnet) devices, including a first BACnet device and a second BACnet device, coupled to the MS/TP communication bus. The network further includes a number of bridge devices, including a first bridge device, connected to the MS/TP communication bus. The first bridge device is located on the MS/TP communication bus between the first BACnet device and the second BACnet device. The first bridge device includes a processing circuit and a memory. The processing circuit is configured to receive a first MS/TP packet from the first BACnet device and selectively forward the first MS/TP packet to the second BACnet device based on a first security configuration. The first security configuration is stored in the memory.