IP Library Patent Application 17704609
Patent Application
App. No. 17/704,609

SYSTEMS AND METHODS FOR IMPLEMENTING SECURITY PROTOCOLS IN A BUILDING MANAGEMENT SYSTEM

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/704,609
Abstract

A building management system network includes a Master-Slave/Token Passing (MS/TP) communication bus. The network further includes a number of Building Automation Control network (BACnet) devices, including a first BACnet device and a second BACnet device, coupled to the MS/TP communication bus. The network further includes a number of bridge devices, including a first bridge device, connected to the MS/TP communication bus. The first bridge device is located on the MS/TP communication bus between the first BACnet device and the second BACnet device. The first bridge device includes a processing circuit and a memory. The processing circuit is configured to receive a first MS/TP packet from the first BACnet device and selectively forward the first MS/TP packet to the second BACnet device based on a first security configuration. The first security configuration is stored in the memory.

Claims (67)

1 . A building management system communication network configured to reduce security risk, the network comprising:

a Master-Slave/Token Passing (MS/TP) communication bus;

a plurality of Building Automation Control network (BACnet) devices coupled to the MS/TP communication bus, the plurality of BACnet devices comprising a first BACnet device coupled to the first MS/TP communication bus and a second BACnet device coupled to the MS/TP communication bus;

a plurality of bridge devices coupled to the MS/TP communication bus, the plurality of bridge devices comprising a first bridge device, the first bridge device located on the MS/TP communication bus between the first BACnet device and the second BACnet device, the first bridge device comprising a processing circuit and a memory, the processing circuit configured to:

receive a first MS/TP packet from the first BACnet device, and

selectively forward the first MS/TP packet to the second BACnet device based on a first security configuration, the first security configuration stored in the memory.

2 . The network of claim 1 , wherein the processing circuit is further configured to automatically detect the plurality of BACnet devices.

3 . The network of claim 1 , wherein the network further comprises a management device, the management device configured to provide the first security configuration to the memory.

4 . The network of claim 3 , wherein the management device is a user device comprising a user interface, the user interface configured to allow a user to configure the first security configuration.

5 . The network of claim 1 , wherein:

the first MS/TP packet comprises at least one of MS/TP address information; Network Protocol Data Unit (NPDU) information; or Application Protocol Data Unit (APDU) information,

the processing circuit is configured to identify the at least one of MS/TP address information; NPDU information; or APDU information from the MS/TP packet, and

the first security configuration is based on the at least one of MS/TP information; NPDU information; or APDU information.

6 . The network of claim 1 , wherein:

the first MS/TP packet comprises a BACnet request,

the processing circuit is further configured to identify a BACnet service type from the BACnet request, and

the first security configuration is based on the BACnet service type.

7 . The network of claim 1 , wherein:

the first MS/TP packet comprises a BACnet request,

the bridge device further comprises a Network Answer Translation (NAT) interface coupled to the processing circuit, the NAT interface configured to provide the processing circuit with a second security configuration,

the processing circuit is further configured to selectively forward a second MS/TP packet from the second BACnet device to the first BACnet device based on the second security configuration, and

the second security configuration is configured such that the processing circuit does not selectively forward the second MS/TP packet unless the second MS/TP packet comprises a BACnet response to the BACnet request.

8 . The network of claim 1 , wherein:

the processing circuit is further configured to automatically provide to the first BACnet device with a second MS/TP packet responsive to the first MS/TP packet not being selectively forwarded to the second BACnet device based on the security configuration, and

the second MS/TP packet comprises:

a rejection response; and

information to proxy the second BACnet device as a provider of the second MS/TP packet.

9 . The network of claim 1 , wherein the first bridge device is coupled to the MS/TP communication bus transparently, such that the first BACnet device and the second BACnet device are operationally unaware of the first bridge device.

10 . The network of claim 1 , wherein the plurality of bridge devices are configured to communicate wirelessly with one another, such that the plurality of bridge devices form a point-to-point wireless network.

11 . A method for reducing security risk on a building management system communication network comprising a Master-Slave/Token Passing (MS/TP) communication bus, and a plurality of Building Automation Control network (BACnet) devices coupled to the MS/TP communication bus, the plurality of BACnet devices comprising a first BACnet device and a second BACnet device, the method comprising:

providing a bridge device coupled to the MS/TP communication bus and located between the first BACnet device and the second BACnet device, wherein the bridge device comprises a processing circuit;

receiving, by the processing circuit, a first MS/TP packet from the first BACnet device;

identifying, by the processing circuit, at least one of MS/TP address information, Network Protocol Data Unit (NPDU) information, and Application Protocol Data Unit (APDU) information, from the first MS/TP packet;

configuring, by the processing circuit, a first security configuration, wherein the first security configuration is based on the at least one of the MS/TP address information, NPDU information, or APDU information; and

selectively forwarding, by the processing circuit, the first MS/TP packet to the second BACnet device, based on the first security configuration.

12 . The method of claim 11 , further comprising automatically detecting, via the processing circuit, the plurality of BACnet devices.

13 . The method of claim 11 , further comprising automatically providing a second MS/TP packet to the first BACnet device responsive to the first MS/TP packet not being selectively forwarded to the second BACnet device based on the first security configuration, wherein the second MS/TP packet comprises:

a rejection response; and

information to proxy the second BACnet device as a provider of the second MS/TP packet.

14 . The method of claim 11 , wherein the bridge device is coupled to the MS/TP communication bus and located between the first BACnet device and the second BACnet device transparently, such that the first BACnet device and the second BACnet device are operationally unaware of the bridge device.

15 . The method of claim 11 , wherein the bridge device further comprises a Network Answer Translation (NAT) interface coupled to the processing circuit, wherein the method further comprising:

configuring, by the NAT interface, a second security configuration;

providing, by the NAT interface, the second security configuration to the processing circuit;

identifying, by the processing circuit, that the first MS/TP packet comprises a BACnet request; and

selectively forwarding, by the processing circuit, a second MS/TP packet from the second BACnet device to the first BACnet device based on the second security configuration, wherein the second security configuration is configured such that the processing circuit does not selectively forward the second MS/TP packet unless the second MS/TP packet comprises a BACnet response to the BACnet request.

16 . A bridge device for reducing security risk on a building management system communication network, the bridge device comprising:

a first interface coupled to a first Master-Slave/Token Passing (MS/TP) network segment of an MS/TP communication bus;

a second interface coupled to a second network segment of the MS/TP communication bus; and

a communications processor, the communications processor configured to:

receive an MS/TP packet from the first MS/TP network segment via the first interface, and

selectively forward the MS/TP packet to the second MS/TP network segment via the second interface based on a security configuration.

17 . The bridge device of claim 16 , wherein:

the bridge device further comprises a power component, and

the power component is configured to convert the transmission of the MS/TP packet into electrical power, such that the bridge device is powered by activity of the MS/TP communication bus.

18 . The bridge device of claim 16 , wherein:

the first MS/TP packet comprises at least one of MS/TP address information; Network Protocol Data Unit (NPDU) information; or Application Protocol Data Unit (APDU) information,

the processing circuit is configured to identify the at least one of MS/TP address information; NPDU information; or APDU information from the MS/TP packet, and

the first security configuration is based on the at least one of MS/TP information; NPDU information; or APDU information.

19 . The bridge device of claim 16 , wherein:

the MS/TP packet comprises a Building Automation Control network (BACnet) BACnet request,

the processing circuit is further configured to identify a BACnet service type from the BACnet request, and

the security configuration is based on the BACnet service type.

20 . The bridge device of claim 16 , wherein:

the processing circuit is further configured to automatically provide to the first MS/TP network segment a second MS/TP packet responsive to the first MS/TP packet not being selectively forwarded to the second MS/TP network segment BACnet device based on the security configuration, and

the second MS/TP packet comprises:

a rejection response; and

information to proxy a BACnet device coupled to the second MS/TP network segment device as a provider of the second MS/TP packet.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 18, 2024
From: JOHNSON CONTROLS TYCO IP HOLDINGS LLP
To: TYCO FIRE & SECURITY GMBH
Reel/Frame 066957/0796 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 7, 2022
From: ZIMMERMAN, NATHAN; EDLER, JOSHUA; SHEAHAN, JACOB R.
To: JOHNSON CONTROLS TYCO IP HOLDINGS LLP
Reel/Frame 060430/0012 →