0
For architects
  • KNX Secure logo in front of a space image of the earth at night.

KNX Secure: security in the smart building

Data protection is key, especially in a smart building. To ensure that there can be no manipulation and recording of data traffic, KNX Secure uses the world's first manufacturer and application-independent security standard for smart buildings, protecting twice and securing all data with the AES128 algorithm.
Line drawing KNX Secure for visualising security in the smart building.
1. Secured area
KNX Secure ensures high security with encryption and authentication in secured areas such as functional buildings or apartments and private utility rooms. Key management and isolation protect against unauthorised access.
2. Public area
Across public areas, the JUNG area and line coupler makes a secure KNX system possible. Despite physical accessibility, the data remain protected due to encryption, as the coupler separates the two KNX lines and secures them with KNX Secure.
Secure implementation of building automation technology: with KNX Secure, the smart building is secure, even across different devices (e.g. JUNG Visu Pro Server) and their connection methods. KNX Secure uses both wired and wireless technologies (KNX RF) to create a flexible and secure network for home and building automation technology. The encryption secures the information both on the KNX bus (Data Secure) and in the LAN (IP Secure).
Visualisation of safety through intelligent JUNG topology
1.  KNX system component
2.  KNX RF converter
3. KNX power supply
4.  KNX RF node
5.  KNX TP actuator
6.  KNX TP sensor
7.  JUNG Visu Pro
8.  LAN router

Doubly secure with KNX Secure

IP Secure
Independent of the medium, KNX IP Secure encrypts and authenticates all telegrams at the network level. As data transmitted is completely secure, communication between the sensor and actuator in the IP network cannot be interpreted or manipulated. KNX IP Secure is the first manufacturer-independent security solution that is recognised as an international security standard in accordance with the EN ISO 22510 standard.
Data Secure
KNX Data Secure also encrypts the data on the bus line (twisted pair) or via wireless communication (RF). KNX secure prevents attack scenarios such as recording, replay attacks or man-in-the-middle attacks.

Commissioning KNX Secure:
secure, fast and simple, thanks to innovative apps

To ensure that a KNX installation is secure, installers need device certificates for each individual component. They then need to be integrated into ETS and printed as a QR code directly on JUNG devices. With JUNG secure apps, the time-intensive and error-prone process of keying in device certificates is removed. 
1. Scan in certificates
Before installation, the KNX certificates are required to be scanned using a smartphone with the free JUNG KNX Secure Scanner app. 
2. Install KNX components
As soon as certificates are scanned for all devices, the installer can install the components.
3. Import certificates
With the help of the ETS JUNG Secure Key Loader app, integrators can import previously scanned KNX certificates. With KNX Secure Scanner, they can then create a protected certificate list or direct the secure keys to a password-protected PDF.
4. Update optional KNX components
All JUNG twisted pair KNX devices can be conveniently updated with the JUNG ETS Service app.
KNX Secure apps
JUNG KNX Secure Scanner
This app synchronises the trades interface between installation, distribution and system integration. Installers simply scan the QR codes, and the Secure key appears in the app as a list view. With JUNG KNX Secure Scanner, you can create an encrypted certificate list or create password-protected PDF documentation for your records as needed. The app is available free of charge from the appropriate app stores.
JUNG KNX Secure Key Loader
The exported certificate list is simply transferred to the ETS with the ETS JUNG KNX Secure Key Loader app and thus integrated into the project. Multiple certificate lists can be combined in the project so that, for example, the project design can run parallel to the project progress. This extension is available via the KNX Association App Shop (my.knx.org) and is bound to the ETS dongle. 
ETS Service app
With the new ETS Service app, integrators can conveniently maintain KNX components. The extension makes it possible to install new firmware in the components. Moreover, they can transfer older firmware versions into existing devices (e.g. when a device is replaced).
IPS remote logo in front of the exterior of a residential building.

Remote maintenance of the KNX system

Remote maintenance from everywhere
System integrators access the customer's KNX components with the IPS-Remote encrypted remote maintenance. For this, you simply need the ETS app IPS-Remote, the IP interface IPS 300 SREG or a power supply with IP interface and the remote maintenance licence IPS-L bound to the respective interface.
Complete access as if on site
Once set up and released by the customer, system integrators can commission, configure and maintain KNX components as usual via ETS5 with the IPS-Remote interface.
The technical requirements
IPS-L remote maintenance licence
The IPS-L remote maintenance licence needed for the remote maintenance can be purchased by customers via the software licence sale in their MyJUNG account. In the MyJUNG service portal, all programs and services for the installation and administration of the JUNG products are brought together. With just one login, installers have everything to hand!
ETS app IPS-Remote
The ETS app IPS-Remote establishes the connection between ETS and the device. The app can be downloaded for free at my.knx.org.
For remote maintenance of a KNX system, two components are available: the IP interface and the -power supply with IP interface. For smaller projects with up to 25 KNX devices, the KNX power supply with IP interface is ideal. With large projects or for retrofitting of, for example, visualisation with Smart Visu Server, installers pick the IP interface and thus supplement the remote maintenance separately.
The customer decides
The connection must be released each time as necessary - the customer can do this conveniently via the visualisation (e.g. via Smart Visu Server) or via connection to a push-button sensor. In this way, the control always remains with the customer. Remote maintenance is limited exclusively to the KNX bus and its integrated components.
Sustainable and secure
Time-consuming and cost-intensive journeys are eliminated. This reduces not just the operational costs but is also kind to the environment. The remote maintenance is encrypted using IP Secure. In addition, the JUNG servers are without exception in Germany. All data and access are thus subject to the strict requirements of GDPR.
IPS remote certificate for security, awarded by antago.
IPS-Remote auf Sicherheit geprüft
Als Anbieter für IT-Sicherheit hat sich die Antago GmbH von Anfang an auch mit dem Thema Smart Home beschäftigt. In dem Zusammenhang hat sich das Unternehmen die Fernwartung JUNG IPS-Remote genauer angeschaut.

FREIGABE DURCH DEN BAUHERREN MACHT DAS SYSTEM SICHER

JUNG IPS-Remote arbeitet bei der Fernwartung grundsätzlich mit der Zustimmung des Bauherrn. Benötigt dieser Hilfe in seinem Smart Home, muss er zunächst eine Freigabe erteilen. Dadurch ist das Zeitfenster eines theoretischen Angriffs auf ein Minimum reduziert. IPS-Remote garantiert zudem auch die gefühlte Sicherheit beim Bauherrn, denn wenn etwas nicht von außen erreichbar ist, kann es auch nicht angegriffen werden.
JUNG offers secure KNX system technology with a comprehensive range of components: from the foundation of KNX switch and blinds actuators, to the KNX push-buttons and system components such as line couplers, IP routers, IP interface or USB data interface up to visualisation. Solutions with JUNG KNX Secure guarantee data security based on the most modern encryption processes.
Manual sensors
F 50 push-button
F 40 push-button
F 10 push-button
RF push-button
Room controller F 50
Room controller F 40
KNX room controller LS TOUCH
Actuators
Switch actuator/ blinds actuator
KNX LED Universal dimming actuator, 4-gang
Heating actuator
Universal dimming actuator
Switch actuator
Switch and blinds actuator
System components
Area / line coupler
IP router Secure
IP interface
Power supply with IP interface
USB data interface
push-button interface
Central controls and gateways
Smart Visu Server
Visu Pro Server
DALI-2 Gateway
Screen view KNX power supply 320 mA REG, 4 TE during use.

Download databases quickly & easily

The JUNG online catalogue contains databases, data sheets and much more for every KNX Secure product. Integrators always have all the information and downloads quickly and clearly available.

Application examples/use cases

KNX Secure application examples schematic drawing.
A new warehouse fits logistically and architecturally into the arrangement of the existing building. Similarly, there is no need to rethink automation in order to integrate the new warehouse with the existing KNX system.  

Use existing central devices (e.g. weather station, visualisation) of the current system and enhance them with the devices in the newly built section.

Objective of the project
  • Resource and cost saving expansion of an existing system
  • Utilisation of synergistic effects from the existing system
  • Galvanic separation of the new sections
  • Increase of the maximum expansion length
 
Steps in ETS
  • Add new line
  • Add IPR 300 S REG as KNX IP router
  • Use IPR 300 S REG in unencrypted mode
  • Activate and put filter tables into operation
  • Commission all other devices according to the manufacturer specifications 
KNX Secure application examples schematic drawing, new build apartment.
Individually design your own realm: KNX provides many automation possibilities. For a new building, create a new KNX project, then integrate the desired devices after the power supply is laid with IP interface.

With optimal selection of devices, you can reduce power consumption and increase efficiency. If needed, simply retrofit a visualisation without extending the KNX system components.

Objective of the project
  • Resource and cost saving construction of a new installation
  • High performance and future-proof installation 
 
Steps in ETS
  • Create a new project.
  • Add new line
  •  Add 203201SIPSR as KNX data interface
  • Commission all other devices according to the manufacturer specifications
KNX Secure application examples schematic drawing, new build detached house.
Your own four walls to your own taste. Here, KNX offers many individual automation possibilities. For a new building, create a new KNX project. To do so, you need an IP interface which is then used to integrate the required devices.

The optional software upgrade of the interface enables remote planning and maintenance: after commissioning, it is thus possible to access the system from outside of the customer network with the permission of the house owner. Remote maintenance means no more waiting time. If needed, a visualisation can be retrofitted without extending the KNX system components.

Objective of the project
  • Resource and cost saving construction of a new installation
  • High performance and future-proof installation
 
In connection with the optional software upgrade:
  • Subsequent project design possible without travel costs
  • The highest level of security during commissioning even from outside the customer network
 
Steps in ETS
  • Create a new project.
  • Add new line
- Add IPS 300 S REG as the KNX data interface
  • Commission all other devices according to the manufacturer specifications
 
In connection with the software upgrade
  • Purchase the IPS Remote licence via MyJUNG
  • Allocate project password
  • Use IPS 300 S REG in encrypted mode
  • Input the device certificate
  • Allocate the release code for the remote configuration
KNX Secure application examples schematic drawing, new two-family house.
Two homes under one roof. Here, KNX offers many individual automation possibilities. For a new building, create a new KNX project. Consider each home's own KNX IP router and then integrate the desired devices.

This division ensures that each party can only access its own KNX island system. At the same time, central components can, however, be jointly used. In this way, a central weather station provides the two individual house parties with data relevant for automation. 

Objective of the project
  • Exact separation of both living areas
  • Joint use of central components
 
Steps in ETS
  • Create a new project.
  • Add new lines
  • Add IPR 300 S REG as an IP router in each case
  • Use IPR 300 S REG in unencrypted mode
  • Activate and put filter tables into operation
  • Activate the lock for reprogramming the sub-line (e.g. exterior)
  • Commission all other devices according to the manufacturer specifications
KNX Secure application examples schematic drawing, multi-storey office building.
There are many demands on multi-floor office buildings. For such a new building, you should provide one KNX IP router and one Smart Visu Server per floor. Thus, each floor can function by itself, but still be managed centrally.

If a floor undergoes renovation, all other areas are optimally protected against possible construction work damage. Central devices, such as a weather station, are simply integrated into the overall system via a separate or existing KNX IP router. It is recommended to plan a separate line for the central devices.

Objective of the project
  • Functional reliability of the entire system
  • Guaranteed connection between the visualisation and the KNX bus
  • Galvanic separation in the event of a fault
  • Increased speed of transmission of central commands
  • Reduced cabling costs (only install network in each section) 
 
Steps in ETS
  • Create a new project.
  • Add line
  • Add IPR 300 S REG as an IP router in each case
  • Use IPR 300 S REG in unencrypted mode
  • Activate filter tables
  • Use and start up the preferred connection in the application (for visualisation communication)
  • Establish IP tunnelling for visualisation (use reserved tunnel)
  • Commission all other devices according to the manufacturer specifications
KNX Secure application examples schematic drawing, multi-storey car dealership.
When planning a car dealership, the organisational, economic and architectural viewpoints should be considered. It is important for these buildings to be able to easily optimise and renovate in the future.

To this end, use one IP router per working area. In addition, provide a Smart Visu Server as the central control component. Thus, each area can function for itself, but still be managed centrally. If an area undergoes renovation, all other areas are optimally protected against possible construction work damage. You should plan a separate line for the central devices.

After commissioning, individual optimisation of the system can also be made possible from beyond the building's network. For this, you need an additional IP interface and the software upgrade for the interface. 

Objective of the project
  • Functional reliability of the entire system
  • Guaranteed connection between the visualisation and the KNX bus
  • Galvanic separation in the event of a fault
  • Increased speed for transmission of central commands
  • Reduced cabling costs (only install network in each section)
 
In connection with the optional software upgrade:
  • additional project configuration possible without travel costs
  • The highest level of security during commissioning even from outside the customer network
 
Steps in ETS
  • Create a new project.
  • Add lines
  • Add IPR 300 S REG as an IP router in each case
  • Use IPR 300 S REG in unencrypted mode
  • Activate filter tables
  • Use and start up the preferred connection in the application (for visualisation communication)
  • Establish IP tunnelling for visualisation (use reserved tunnel)
  • Commission all other devices according to the manufacturer specifications

In connection with the software upgrade:
  • Add IPS 300 S REG as the KNX data interface
  • Purchase the IPS Remote licence via myJUNG
  • Allocate project password
  • Use IPS 300 S REG in encrypted mode
  • Input the device certificate
  • Allocate the release code for the remote configuration
Create a professional yet feel-good atmosphere for guests with building automation: provide them with the highest level of comfort with state-of-the-art technology in the background and operate your hotel building with maximum energy efficiency.

A central weather station allows location-based weather data to flow into the building automation system. The heating regulation is reduced with rising outdoor temperatures and thus saves money and resources. The system should be operated in a fully encrypted KNXnet / IP network so that you can always benefit from these advantages. This makes potential hacker attacks on your building automation infrastructure significantly more difficult.
 
Objective of the project
  • Resource and cost saving construction of a new installation
  • Optimisation and automation of daily processes
  • Protection of the customer data
  • Encrypted communication
  • Protection from hacker attacks
  • High performance and future-proof installation
 
Steps in ETS
  • Create new project and assign project password
  • Add lines
  •  Add IPR 300 S REG as an IP router in each case
  • Use IPR 300 S REG in encrypted mode
  • Input the device certificate
  • Change commissioning password (optional)
  • Change authentication code (optional)
  • Activate filter tables
  • Use and start up the preferred connection in the application (for visualisation communication)
  • Establish IP tunnelling for visualisation (use reserved tunnel)
  • Commission all other devices according to the manufacturer specifications
 
Additional note
  • Passwords are not required when the project is open.
  • The commissioning password must be entered if the project is not open
Modern hotels set new standards for individual convenience. Provide added value for your guests with building automation and reduce the workload for hotel personnel. 

For example, the temperature in all rooms can be set or changed from a central location. A DND (Do Not Disturb) or MUR (Make Up Room) request from the guest can also be viewed at a central location. This allows you to optimally plan and execute the daily cleaning process. As sensitive data are also transmitted in such a hotel, we recommend protecting the data using state-of-the-art technology. Operate a fully encrypted KNXnet/IP network for this to protect your guests and customers. The protection of customer data has the side effect that you as hotel owner are also optimally protected against hacker attacks on your building automation technology.

Objective of the project
  • The security of guest data has the highest priority 
  • Communication according to the latest security standards
  • Each section is considered as its own "island" 
  • Project design can be reproduced almost infinitely
  • JUNG Visu Pro (JVP) Hotel manages central information of each "island" via the KNX-IP interface
  • The required knowledge is reduced to a minimum in the event of a fault 
  • Minimisation of spare device storage 
  • Replacement devices can be pre-programmed
 
Steps in ETS
  • Create new project and assign project password
  • Add lines 
  • Add 203201SIPSR in each case as an IP interface
  • Use 203201SIPSR in encrypted mode
  • Input the device certificate
  • Change commissioning password (optional)
  • Change authentication code (optional)
  • Use and start up the preferred connection in the application (for visualisation communication)
  • Establish IP tunnelling for visualisation (use reserved tunnel)
  • Commission all other devices according to the manufacturer specifications

Additional notes
  • Passwords are not required when the project is open.
  • The commissioning password must be entered if the project is not open.

JUNG Newsletter

Product news, architecture references and smart home trends: With our JUNG newsletters you are always well informed when it comes to trends and news.

Contacts

Do you have any questions, requests, or suggestions about our products and solutions? Please contact us. We hope we can help you!