Security assessment and improvement of building ethernet KNXnet/IP protocol
Feng, Tao; Zhang, Bugang; Liu, Chunyan; Zheng, Lu
2024-03-23
发表期刊DISCOVER APPLIED SCIENCES
卷号6期号:4
摘要KNXnet/IP is a KNX-building automation protocol that communicates through an IP network. It is mainly used in the field of smart home and building automation control, allowing remote access to KNX devices through an IP network, so that building functions can be managed and controlled anywhere through an Internet connection. However, with the development of smart homes and building automation, such physical devices based on IP communication are more and more frequently in contact with the Internet, resulting in more and more security issues for home devices and buildings exposed to the Internet. This paper uses the formal analysis method-colored Petri net (CPN) combined with the CPN Tools to model the KNXnet/IP protocol and analyze the protocol interaction process. Based on the Dolev-Yao attacker model, the security of the KNXnet/IP protocol is evaluated and tested, and it is verified whether there are three types of attackable vulnerabilities in the protocol: replay, tampering, and spoofing. After CPN modeling analysis and verification, it is found that tampering and replay vulnerabilities in the original protocol. Therefore, we introduce timestamp and hash to strengthen the security mechanism of the protocol, which ensures the integrity, confidentiality, and freshness of the security mechanism of the protocol. After the final analysis and verification, the improvement scheme proposed in this paper can effectively improve the security performance of the protocol.
关键词KNXnet/IP protocol Security assessment Formal analysis Dolev-Yao Coloured petri nets
DOI10.1007/s42452-024-05707-6
收录类别ESCI ; EI
语种英语
资助项目National Natural Science Foundation of China
WOS研究方向Science & Technology - Other Topics
WOS类目Multidisciplinary Sciences
WOS记录号WOS:001189583700004
出版者SPRINGER
EI入藏号20241315802176
EI主题词Automation
EI分类号402 Buildings and Towers ; 722.3 Data Communication, Equipment and Techniques ; 723 Computer Software, Data Handling and Applications ; 723.5 Computer Applications ; 731 Automatic Control Principles and Applications ; 731.1 Control Systems ; 921.4 Combinatorial Mathematics, Includes Graph Theory, Set Theory
原始文献类型Article
EISSN3004-9261
引用统计
文献类型期刊论文
条目标识符https://ir.lut.edu.cn/handle/2XXMBERH/170189
专题计算机与通信学院
通讯作者Feng, Tao
作者单位Lanzhou Univ Technol, Sch Comp & Commun, Lanzhou, Peoples R China
第一作者单位兰州理工大学
通讯作者单位兰州理工大学
第一作者的第一单位兰州理工大学
推荐引用方式
GB/T 7714
Feng, Tao,Zhang, Bugang,Liu, Chunyan,et al. Security assessment and improvement of building ethernet KNXnet/IP protocol[J]. DISCOVER APPLIED SCIENCES,2024,6(4).
APA Feng, Tao,Zhang, Bugang,Liu, Chunyan,&Zheng, Lu.(2024).Security assessment and improvement of building ethernet KNXnet/IP protocol.DISCOVER APPLIED SCIENCES,6(4).
MLA Feng, Tao,et al."Security assessment and improvement of building ethernet KNXnet/IP protocol".DISCOVER APPLIED SCIENCES 6.4(2024).
条目包含的文件
条目无相关文件。
个性服务
查看访问统计
谷歌学术
谷歌学术中相似的文章
[Feng, Tao]的文章
[Zhang, Bugang]的文章
[Liu, Chunyan]的文章
百度学术
百度学术中相似的文章
[Feng, Tao]的文章
[Zhang, Bugang]的文章
[Liu, Chunyan]的文章
必应学术
必应学术中相似的文章
[Feng, Tao]的文章
[Zhang, Bugang]的文章
[Liu, Chunyan]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
暂无评论
 

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。