Detection and survival method against adversarial attacks on automated systems
Summary
The USPTO granted Patent US12598075B2 to Morgan State University covering methods for device authentication and intrusion detection in BACnet MS/TP building automation networks. The patent describes an extended message format using hashed device identifiers and physical unclonable functions (PUFs) to prevent adversaries from exploiting known device IDs. The invention reallocates data field bytes to create an extended header CRC field for transmitting authentication hashes.
What changed
The USPTO granted Patent US12598075B2 covering cryptographic authentication methods for BACnet MS/TP networks. The patent discloses a protocol utilizing hashed device identifiers combined with random numbers to authenticate devices on building automation networks. The extended header CRC field is created by reallocating bytes from the standard data field, enabling transmission of hash values without modifying the existing frame structure. A secondary countermeasure incorporates physical unclonable functions (PUFs) into the extended header CRC.
Entities manufacturing building automation equipment or developing BACnet-compatible devices may benefit from reviewing this patent portfolio to understand existing intellectual property in authentication and network security for industrial control systems. The technology applies to any organization deploying or securing BACnet MS/TP networks in commercial buildings, manufacturing facilities, or critical infrastructure.
What to do next
- Monitor for updates
Source document (simplified)
Detection and survival method against adversarial attacks on automated systems
Grant US12598075B2 Kind: B2 Apr 07, 2026
Assignee
Morgan State University
Inventors
Kevin Kornegay, Tsion M. Yimer, Edmund H. Smith
Abstract
Methods provide device authentication for an intrusion detection system implementing building automation and control network (BACnet) Master-Slave/Token-Passing (MS/TP). An authentication protocol provides countermeasures to vulnerabilities in the BACnet MS/TP physical layer by utilizing an extended message format to cloak device identifiers (IDs). Adversaries are prevented from using known device IDs to gain access to the network. An authenticating device hashes a device identifier of a device to be authenticated combined with a random number. The authenticating device receives a hash of the random number plus the device identifier from the device. The authenticating device compares the hashes and authenticates the device if the hashes match. To transmit the hash, the BACnet MS/TP frame format includes an extended header cyclic redundancy check (CRC) field having bytes reallocated from the data field of the frame format. Another countermeasure utilizes a physical unclonable function (PUF) of the device in the extended header CRC.
CPC Classifications
H04L 9/3236 H04L 9/0869 H04L 9/3278 H04L 63/14 G06F 21/57
Filing Date
2024-01-22
Application No.
18419037
Claims
15
Related changes
Get daily alerts for ChangeBridge: Patent Grants - Networking (H04L)
Daily digest delivered to your inbox.
Free. Unsubscribe anytime.
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get alerts for this source
We'll email you when ChangeBridge: Patent Grants - Networking (H04L) publishes new changes.