Building Automation and Control Systems increasingly rely on BACnet/IP to interconnect heterogeneous field devices and supervisory applications. Although BACnet Secure Connect provides end-to-end protection via TLS, its adoption in smart-building deployments is hindered by the limited capabilities of legacy devices and the additional communication overhead. In this paper, we propose an in-network security approach for BACnet/IP communications based on two P4-programmable boundary switches that transparently provide confidentiality, integrity, and authentication across exposed network segments without requiring modifications to BACnet endpoints. The solution combines AES-based encryption with support for 128-, 192-, and 256-bit keys and SHA-256 HMAC protection. The proposed approach is validated on a virtualized testbed that we developed on top of the NIST Net-Zero Energy Residential Test Facility (NZERTF) HVAC reference scenario. Experimental results show that the proposed in-network approach achieves a mean RTT between 1393μs and 1541μs, thus reducing latency by 22.8%−30.2%with respect to BACnet/SC (1995 μ s), while remaining above plaintext BACnet/IP (951 μs) by 46.5%−62.0%.
Rinieri, L., Iacobelli, A., Melis, A., Girau, R., Callegati, F., Prandini, M. (2026). In-Network Security for Smart Buildings BACnet Communications. IEEE [10.1109/netsoft70012.2026.11603540].
In-Network Security for Smart Buildings BACnet Communications
Rinieri, Lorenzo;Iacobelli, Antonio;Melis, Andrea;Girau, Roberto;Callegati, Franco;Prandini, Marco
2026
Abstract
Building Automation and Control Systems increasingly rely on BACnet/IP to interconnect heterogeneous field devices and supervisory applications. Although BACnet Secure Connect provides end-to-end protection via TLS, its adoption in smart-building deployments is hindered by the limited capabilities of legacy devices and the additional communication overhead. In this paper, we propose an in-network security approach for BACnet/IP communications based on two P4-programmable boundary switches that transparently provide confidentiality, integrity, and authentication across exposed network segments without requiring modifications to BACnet endpoints. The solution combines AES-based encryption with support for 128-, 192-, and 256-bit keys and SHA-256 HMAC protection. The proposed approach is validated on a virtualized testbed that we developed on top of the NIST Net-Zero Energy Residential Test Facility (NZERTF) HVAC reference scenario. Experimental results show that the proposed in-network approach achieves a mean RTT between 1393μs and 1541μs, thus reducing latency by 22.8%−30.2%with respect to BACnet/SC (1995 μ s), while remaining above plaintext BACnet/IP (951 μs) by 46.5%−62.0%.I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.



