Modern Building Automation Systems (BAS) consist of sensors and actuators that are connected via an IP-based network and offer their functionality via RESTful APIs. Because a single device can be exploited by an attacker to perform attacks within the local network, we put devices into isolated groups. These groups are isolated MAC-layer Trust Zones to reduce the attack surface in contrast to a BAS with fully connected devices. We propose an algorithm that leverages the so far neglected potential of Building Information Modeling (BIM) to compute Trust Zones. We assure unimpaired operation of all applications while limiting the number of infrastructure devices. The proposed mechanisms are demonstrated considering sensors and actuators that are connected via wired Ethernet and the IEEE 802.11s WLAN mesh standard. At the application layer we make exemplary use of the Constrained Application Protocol (CoAP). Finally, we experimentally evaluate the device acquisition and selection based on our network partitioning algorithm.
Modern surgical devices are full of innovations and provide plenty of functionalities. However, they only perform to their full potential if they are properly configured. Only a small subset of surgical device functionalities is used due to the high complexity of today's device systems and the omnipresent situation that only the circulating nurses can (re-)configure non-sterile devices. Hence, there is a huge need for safe and effective assistance supporting the operating room (OR) staff to continuously work with the potentially best device setting to increase patient's safety and clinical outcome. Therefore, we propose a concept for situation-aware parameter recommendations and automatic (re-)configuration. Free access to adequate data is a prerequisite to extract knowledge for assistive systems and to provide situation awareness during execution. Thus, manufacturer-independent medical device interoperability is a basic requirement. Consequently, we use the new IEEE 11073 Service-oriented Device Connectivity (SDC) standards family, including Device Specializations. As part of the developing committee we introduce the idea and concept behind Device Specializations and highlight their use for assistive systems in the domain of minimal invasive surgery. To ensure safety and effectiveness of the assistive functionalities, our concept enforces deterministic rules providing a predictable and approvable behavior. We demonstrate our concept by the use case of a smart surgical double roller pump using an interpreter-based Rule Execution Engine.
Due to the fact that every smart building is a unique composition of devices, services, and users there is no one-fits-all security architecture. With our proposal we address this problem by using Building Information Modeling (BIM) as source of information for our security concept. Using BIM, models are created throughout the planning of a building, which do not consist only of 3D information such as typical CAD drawings, but also provide a rich set of metadata about the building elements including devices, their interrelationships and networking. Thus, BIM can be used to derive security configurations for each individual embedded device, its services and the network as a whole. We demonstrate the function of a general Security Controller to partition the network on MAC layer. Furthermore, we draw an overall picture of the proposed architecture and the range of possible applications.
In this paper, we analyze the state of the art in distributed ledger technologies and blockchains and investigate potential applications in the Internet of Things (IoT) domain. Afterwards, we discuss interoperability of blockchains, and their use in smart contracts, and artificial intelligence.
The Building Automation and Control networks (BACnet) protocol is one of the most widely used protocols in the building automation domain. In order to meet growing security requirements, an optional security architecture is defined in the BACnet standard. The purpose of this paper is to carry out a performance analysis on a BACnet/IP network, which is secured according to this security architecture. The additional time costs for client and server devices as well as the transmission costs are evaluated with regard to all levels of security defined in the standard. In this context, message signing with HMAC in combination with MD5 or SHA-256 and message encryption with AES-128 is investigated. To the best of the authors’ knowledge there are no works dealing with the performance of secured BACnet networks. The results should serve for further comparison with BACnet Secure Connect (BACnet/SC), which is currently under development and makes use of state-of-the-art security mechanisms like the Transport Layer Security (TLS).
This paper investigates research, made on semantic information models for building automation systems. It analyzes what information domains are covered to provide context, the vocabulary provided to describe building automation devices and functions, and how these models are structured. The intention is to find out good practices and try to identify trends, commonalities, differences, and possible next steps.
The microservice approach has created a hype in the domain of cloud and enterprise application business. Before, grown, monolithic, software has been pushed to the limits of maintainability and scalability. The microservice architecture approach utilizes the service oriented architecture together with best practices and recent developments in software virtualization to overcome those issues. One monolithic application is split up into a set of distributed services. Those are strongly decoupled to enable high maintainability and scalability. In this case an application is split up in a top down manner.In the internet of things, applications need to be put together from a set of small and independent services. Thus, creating value added services would require to freely combine services of different vendors to fully make use of the IoT's heterogeneity.Even though the direction is different, many of the requirements in microservices are similar to those of the internet of things. This paper investigates patterns and best practices that are used in the microservices approach and how they can be used in the internet of things. Since the companies using microservices have made considerations on how services have to be designed to work together properly, IoT applications might adopt several of these design decisions to improve the ability to create value added applications from a multitude of services.
This paper presents how the reference architecture of the ITEA2 project Building as a Service (BaaS) could be applied on different classes of devices to show its flexibility and suitability for the heterogeneous environment of building automation systems. For this purpose technologies are identified and discussed that could be used for the implementation. The approach of the reference architecture is applied on three different classes of devices that are used in today's building automation systems or are intended to be used in the future. The selected devices span the range from a small sensor node up to a high performance system.
Assistive systems collect large amounts of data in the internet of things and compute behavior and intentions of users in the cloud. Our approach is to push these computations (interpreted as database queries) as close as possible to the local sensors of the internet of things. We aim at replacing privacy-compromising cloud-based computations by fogor edge-based computations or even by processing on the local sensors directly. Not only can this approach solve privacy problems, but also results in a better performance and energy-efficiency of the whole system: sensor-based computations are the (privacy-respecting) sunny side of the cloud. This position paper will give a short motivation and state of the art in different areas (from databases to wireless sensor networks) and will present our approach in combining modern interfaces to different sensors and concepts of database theory such as query rewriting and query containment.
The vision of the smart home is increasingly becoming reality. Devices become smart, interconnected and accessible through the Internet. In the classical building automation domain already a lot of devices are interconnected providing interfaces for control or collecting data. Unfortunately for historical reasons they use specialized protocols for their communication hampering the integration into newly introduced smart home technologies. In order to make use of the valuable information gateways are required. BACnet as a protocol of the building automation domain already can make use of IP and defined a way to represent building data as Web services in general, called BACnet/WS. But using full fledged Web services would require too much resources in the scenario of smart home thus we need a more resource friendly solution. In this work a Devices Profile for Web Services (DPWS) adaptation of the BACnet/WS specification is proposed. DPWS enables Web service conform communication with a focus on a small footprint, which in turn enables interdisciplinary communication of constrained devices.
As of today, building automation systems are present in almost any commercial building. They perform climate control, lightning control, access control, surveillance, and quite a few other tasks. As a result of their evolutionary development, building automation systems are divided into separate silos of disciplines that are not well integrated with each other. As of today, a variety of communication protocols, data models and engineering approaches are used by different vendors. Existing standardized building automation protocols as BACnet or KNX allow integration of some disciplines on the communication level but fail to provide means for common description of devices, services and data on the semantic level. This means that building automation applications that span multiple disciplines require a high effort for development, engineering and maintenance. If devices from multiple vendors are integrated in one installation, a set of different engineering tools and vendor-specific knowledge is required. In the ITEA “Building as a Service” (BaaS) project we try to overcome these deficiencies and define a common way to develop, engineer, commission, operate and maintain building automation systems following a service oriented approach. The whole process will be supported by semantic models to reduce costs and time-to-market, which is a quite new approach. In this paper we will present the current state of the work with special regard to domain modeling and model driven processes that are currently being specified for the BaaS platform.