Affiliation:
1. School of Computer and Communication, Lanzhou University of Technology, No. 36, Pengjiaping Road, Qilihe District, Lanzhou 730050, China
Abstract
The European Installation Bus(EIB) protocol, also known as KNX/EIB, is widely used in building and home automation. An extension of the KNX/EIB protocol, EIBsec, is primarily designed to meet the requirements for data transmission security in distributed building automation systems. However, this protocol has some security issues in the request, key distribution, and identity authentication processes. This paper employs a formal analysis method that combines Colored Petri Net (CPN) theory with the Dolev-Yao attack model to evaluate and enhance the EIBsec protocol. It utilizes the CPN Tools to conduct CPN modeling analysis on the protocol and introduces a security assessment model to carry out intrusion detection and security assessment. Through this analysis, vulnerabilities in the protocol, such as tampering and replay attacks, are identified. To address these security concerns, we introduce hash verification and timestamp judgment methods into the original protocol to enhance its security. Subsequently, based on the improved protocol, we conduct CPN modeling and verify the security of the new scheme. Finally, through a comparison and analysis of the performance and security between the original protocol and the improved scheme, it is found that the improved scheme has higher security.
Funder
National Natural Science Foundation of China
Reference43 articles.
1. Safety- and Security-Critical Services in Building Automation and Control Systems;Novak;IEEE Trans. Ind. Electron.,2010
2. The methods of secure data transmission in the KNX system;J. Pol. Saf. Reliab. Assoc.,2014
3. Security in building automation systems;Granzer;IEEE Trans. Ind. Electron.,2009
4. Formal Security Evaluation and Improvement of BACnet/IP Protocol Based on HCPN Model;Feng;Int. J. Netw. Secur.,2022
5. A New Scheme of BACnet Protocol Based on HCPN Security Evaluation Method;Feng;Int. J. Netw. Secur.,2022