0
Per architetti
  • Logo KNX Secure davanti a un'immagine spaziale della terra di notte.

KNX Secure: sicurezza nell'edificio intelligente

Nessuna manipolazione e nessuna registrazione del traffico dati: anche in un edificio intelligente, la protezione dei dati ha la massima priorità. Per questo motivo, utilizziamo il primo standard di sicurezza al mondo indipendente dal produttore e dall'applicazione per gli edifici intelligenti. KNX Secure protegge due volte e mette al sicuro tutti i dati con l'algoritmo AES128.
Disegno lineare KNX Secure per visualizzare la sicurezza nell'edificio intelligente.
1. area protetta
KNX Secure garantisce un elevato livello di sicurezza in aree protette come edifici o appartamenti funzionali e stanze private, grazie alla crittografia e all'autenticazione. La gestione delle chiavi e l'isolamento proteggono dall'accesso non autorizzato, mentre l'accoppiatore di area/linea KNX (accoppiatore di segmento) consente di realizzare un sistema KNX sicuro in aree pubbliche.
2. area pubblica
L'accoppiatore di area/linea collega queste due aree se Secure è attivato nell'ETS. È quindi possibile utilizzare la funzione Secure Proxy. Nonostante l'accessibilità fisica, i dati rimangono protetti dalla crittografia.
Implementazione sicura della tecnologia di automazione degli edifici: con KNX Secure, l'edificio intelligente è sicuro, anche tra dispositivi diversi (ad esempio, JUNG Visu Pro Server) e i loro metodi di connessione. KNX Secure utilizza tecnologie cablate e wireless (KNX RF) per creare una rete flessibile e sicura per la tecnologia di automazione domestica e degli edifici. La crittografia protegge le informazioni sia sul bus KNX (Data Secure) che nella LAN (IP Secure).
Visualizzazione della sicurezza attraverso la topologia intelligente di JUNG
1.  Componente del sistema KNX
2.  Accoppiatore RF KNX
3.  Alimentazione KNX
4.  Nodo RF KNX
5.  Attuatore KNX TP
6.  Sensore KNX TP
7.  JUNG Visu Pro
8.  Router LAN

Doppiamente sicuro con KNX Secure

IP sicuro
Indipendentemente dal mezzo, KNX IP Secure cripta e autentica tutti i telegrammi a livello di rete. I dati trasmessi sono completamente sicuri. In questo modo la comunicazione tra sensore e attuatore nella rete IP non può essere interpretata o manipolata. KNX IP Secure è la prima soluzione di sicurezza indipendente dal produttore riconosciuta come standard di sicurezza internazionale in conformità alla norma EN ISO 22510.
Dati sicuri
KNX Data Secure cripta anche i dati sulla linea bus (doppino) o tramite comunicazione wireless (RF). KNX secure previene scenari di attacco come la registrazione, gli attacchi replay o gli attacchi man-in-the-middle.

In che modo la direttiva NIS 2 influirà sulla progettazione tecnica degli edifici?

Il numero di attacchi informatici alle infrastrutture critiche, alle istituzioni pubbliche e alle aziende sta aumentando rapidamente, causando danni ingenti. In risposta a ciò, l'UE ha introdotto la direttiva NIS 2, che stabilisce requisiti di sicurezza estesi che influenzeranno molti progetti di pianificazione e costruzione nel prossimo futuro.
White paper di JUNG sulla sicurezza informatica
Per tutti coloro che desiderano approfondire l'argomento, JUNG mette a disposizione il white paper “Direttiva NIS-2: significato e conseguenze per i professionisti della progettazione”. Il documento esamina in modo approfondito i settori interessati dalla nuova direttiva, i suoi obblighi e il loro significato pratico per la progettazione e l'automazione degli edifici.

Il white paper dimostra la necessità di considerare insieme i sistemi IT e OT e il ruolo che standard come KNX Secure svolgeranno in futuro. Il contenuto tecnico è stato sviluppato in collaborazione con avvocati di CBH specializzati in diritto informatico. Si tratta di un documento da leggere assolutamente per chiunque sia coinvolto nella progettazione, nella gestione o nell'implementazione. Scoprite di più ora e preparatevi.

Messa in servizio KNX Secure:
sicuro, veloce e semplice, grazie alle app innovative

Affinché un'installazione KNX sia sicura, gli installatori hanno bisogno dei certificati dei dispositivi per i singoli componenti. Questi devono essere integrati in ETS e vengono quindi stampati come codice QR direttamente sui dispositivi JUNG. Il processo di digitazione dei certificati dei dispositivi, che richiede molto tempo ed è soggetto a errori, non è più necessario grazie alle app sicure di JUNG.
1. Scan in certificates
Before the installation, the KNX certificates must be scanned in. This is done most easily with a smartphone and the free JUNG KNX Secure Scanner app. 
2. Install KNX components
As soon as the certificates have been scanned in for all devices, the installer can install the components.
3. Import certificates
With the help of the ETS JUNG Secure Key Loader app, integrators import the previously scanned KNX certificates. With KNX Secure Scanner, they create a protected certificate list or direct the secure keys to a password-protected PDF.
4. Update optional KNX components
All JUNG twisted pair KNX devices can be conveniently updated with the JUNG ETS Service app.
Applicazioni KNX Secure
Scanner sicuro JUNG KNX
Questa app chiude l'interfaccia commerciale tra installazione, distribuzione e integrazione del sistema: gli installatori devono semplicemente scansionare i codici QR. La chiave sicura viene visualizzata nell'app sotto forma di elenco. Con JUNG KNX Secure Scanner è possibile creare un elenco di certificati criptato o creare una documentazione PDF protetta da password per i propri archivi, a seconda delle necessità. L'applicazione è disponibile gratuitamente negli appositi app store.
Caricatore di chiavi sicure JUNG KNX
L'elenco di certificati esportato viene semplicemente trasferito all'ETS con l'applicazione ETS JUNG KNX Secure Key Loader e quindi integrato nel progetto. È possibile combinare più elenchi di certificati nel progetto, in modo che, ad esempio, la progettazione possa procedere parallelamente all'avanzamento del progetto. Questa estensione è disponibile tramite il KNX Association App Shop (my.knx.org) ed è legata al dongle ETS.
App di servizio ETS
Con la nuova applicazione ETS Service, gli integratori possono effettuare comodamente la manutenzione dei componenti KNX. L'estensione consente di installare nuovi firmware nei componenti. Inoltre, possono trasferire le vecchie versioni del firmware nei dispositivi esistenti (ad esempio, in caso di sostituzione di un dispositivo).
Logo remoto IPS davanti all'esterno di un edificio residenziale.

Manutenzione remota del sistema KNX

Manutenzione remota da ogni luogo
Gli integratori di sistema accedono ai componenti KNX del cliente con la manutenzione remota criptata IPS-Remote. A tal fine, è sufficiente l'applicazione ETS IPS-Remote, l'interfaccia IPS 300 SREG o un alimentatore con interfaccia IP e la licenza di manutenzione remota IPS-L legata alla rispettiva interfaccia.
Accesso completo come in loco
Una volta configurati e rilasciati dal cliente, gli integratori di sistema possono mettere in funzione, configurare e mantenere i componenti KNX come di consueto tramite ETS5 con l'interfaccia IPS-Remote.
I requisiti tecnici
Licenza di manutenzione remota IPS-L
La licenza di manutenzione remota IPS-L necessaria per la manutenzione remota può essere acquistata dai clienti tramite la vendita di licenze software nel loro account MyJUNG. Nel portale di assistenza MyJUNG sono riuniti tutti i programmi e i servizi per l'installazione e l'amministrazione dei prodotti JUNG. Con un solo login, gli installatori hanno tutto a portata di mano!
App ETS IPS-Remote
L'applicazione ETS IPS-Remote stabilisce la connessione tra l'ETS e il dispositivo. L'applicazione può essere scaricata gratuitamente dal sito my.knx.org.
Per la manutenzione a distanza di un sistema KNX, sono disponibili due componenti: l'interfaccia IP e l'alimentatore con interfaccia IP. Per i progetti più piccoli, con un massimo di 25 dispositivi KNX, l'alimentatore KNX con interfaccia IP è ideale. Per progetti di grandi dimensioni o per l'installazione a posteriori, ad esempio, della visualizzazione con Smart Visu Server, gli installatori scelgono l'interfaccia IP, integrando così la manutenzione remota separatamente.
Il cliente decide
Il collegamento deve essere rilasciato di volta in volta, se necessario: il cliente può farlo comodamente tramite la visualizzazione (ad esempio, tramite Smart Visu Server) o tramite il collegamento a un sensore a pulsante. In questo modo, il controllo rimane sempre al cliente. La manutenzione a distanza è limitata esclusivamente al bus KNX e ai suoi componenti integrati.
Sostenibile e sicuro
Vengono eliminati i viaggi che richiedono tempo e costi elevati. In questo modo non solo si riducono i costi operativi, ma si rispetta anche l'ambiente. La manutenzione remota è criptata grazie a IP Secure. Inoltre, i server JUNG si trovano senza eccezioni in Germania. Tutti i dati e gli accessi sono quindi soggetti ai severi requisiti del GDPR.
Certificato remoto IPS per la sicurezza, rilasciato da antago.
IPS remoto testato per la sicurezza
In qualità di fornitore di sicurezza informatica, Antago GmbH si è occupata fin dall'inizio del tema delle case intelligenti. In questo contesto, l'azienda ha esaminato da vicino il sistema di manutenzione remota JUNG IPS-Remote.

L'APPROVAZIONE DEL COSTRUTTORE RENDE IL SISTEMA SICURO JUNG

IPS-Remote funziona sempre con il consenso del proprietario dell'edificio per la manutenzione remota. Se ha bisogno di aiuto nella sua casa intelligente, deve prima dare la sua approvazione. Questo riduce al minimo la finestra temporale per un attacco teorico. IPS-Remote garantisce anche il senso di sicurezza del proprietario dell'edificio, perché se qualcosa non è accessibile dall'esterno, non può essere attaccato.
Sicurezza da un unico fornitore
JUNG offre una tecnologia di sistema KNX sicura con una gamma completa di componenti: dalla base con l'interruttore KNX e gli attuatori per veneziane, i pulsanti KNX e i componenti di sistema come accoppiatori di linea, router IP, interfaccia IP o interfaccia dati USB fino alla visualizzazione. Le soluzioni con JUNG KNX Secure garantiscono la sicurezza dei dati grazie ai più moderni processi di crittografia.
Sensori manuali
F 50 pulsante
F 40 pulsante
F 10 pulsante
RF pulsante
Controllore ambiente compatto F 50
Controllore ambiente compatto F 40
Controllore ambiente KNX LS TOUCH
Attuatori
Attuatore per interruttori/attuatore per veneziane
KNX LED Attuatore dimmerabile universale, a 4 ingressi
Attuatore di riscaldamento
Attuatore dimmerabile universale
Attuatore dell'interruttore
Interruttore e attuatore per veneziane
Componenti del sistema
Area KNX / accoppiatore di linea
Router IP Sicuro
IP interface
Power supply with IP interface
Interfaccia dati USB
Interfaccia a pulsante Da 2 a 8 ingressi
Controllo centrale e gateway
Server Smart Visu
Server Visu Pro
IPS Remoto
Gateway DALI-2
Vista dello schermo Alimentazione KNX 320 mA REG, 4 TE durante l'uso.

Scaricare i database in modo semplice e veloce

Il catalogo online di JUNG contiene database, schede tecniche e molto altro per ogni prodotto KNX Secure. Gli integratori hanno sempre a disposizione tutte le informazioni e i download in modo rapido e chiaro.

Esempi di applicazione/casi d'uso

Esempi di applicazione KNX Secure disegno schematico.
A new warehouse fits logistically and architecturally into the arrangement of the existing building. Similarly, there is no need to rethink automation in order to integrate the new warehouse into the existing KNX system.  

Use the already used central devices (e.g. weather station, visualisation) of the existing system and enhance them with the devices in the newly built section.

Objective of the project
  • Resource and cost saving expansion of an existing system
  • Utilisation of synergy effects from the existing system
  • Galvanic separation of the new sections
  • Increase of the maximum expansion length
 
Steps in ETS
  • Add new line
  • Add IPR 300 S REG as KNX IP router
  • Use IPR 300 S REG in unencrypted mode
  • Activate and put filter tables into operation
  • Commission all other devices according to the manufacturer specifications 
Esempi di applicazione KNX Secure disegno schematico, appartamento di nuova costruzione.
Individually design your own realm: KNX provides many automation possibilities. For a new building, create a new KNX project. Then integrate the desired devices after the power supply with IP interface.

With optimal selection of devices you reduce power consumption and increase efficiency. If needed, simply retrofit a visualisation without extending the KNX system components.

Objective of the project
  • Resource and cost saving construction of a new installation
  • High performance and future-proof installation 
 
Steps in ETS
  • Create a new project.
  • Add new line
  • Add 203201SIPSR as KNX data interface
  • Commission all other devices according to the manufacturer specifications
Esempi di applicazione KNX Secure disegno schematico, casa unifamiliare di nuova costruzione.
Your own four walls to your own taste. Here, KNX offers many individual automation possibilities. For a new building, create a new KNX project. To do so, you need an IP interface and then integrate the required devices.

The optional software upgrade of the interface enables remote planning and maintenance: after commissioning, it is thus possible to access the system from outside of the customer network - naturally with the permission of the house owner. Remote maintenance means no more driving time. If needed, a visualisation can be retrofitted without extending the KNX system components.

Objective of the project
  • Resource and cost saving construction of a new installation
  • High performance and future-proof installation
 
In connection with the optional software upgrade:
  • Subsequent project design possible without travel costs
  • The highest level of security during commissioning even from outside the customer network
 
Steps in ETS
  • Create a new project.
  • Add new line
  • Add IPS 300 S REG as the KNX data interface
  • Commission all other devices according to the manufacturer specifications
 
In connection with the software upgrade
  • Purchase the IPS Remote licence via MyJUNG
  • Allocate project password
  • Use IPS 300 S REG in encrypted mode
  • Input the device certificate
  • Allocate the release code for the remote configuration
Esempi di applicazione KNX Secure Disegno schematico, nuova casa bifamiliare.
Two homes under one roof. Here, KNX offers many individual automation possibilities. For a new building, create a new KNX project. You take account of each party with its own KNX IP router and then integrate the desired devices.

This division ensures that each party can only access its own KNX island system. At the same time, central components can, however, be jointly used. In this way, a central weather station provides the two individual house parties with data relevant for automation. 

Objective of the project
  • Exact separation of both living areas
  • Joint use of central components
 
Steps in ETS
  • Create a new project.
  • Add new lines
  • Add IPR 300 S REG as an IP router in each case
  • Use IPR 300 S REG in unencrypted mode
  • Activate and put filter tables into operation
  • Activate the lock for reprogramming the sub-line (e.g. exterior)
  • Commission all other devices according to the manufacturer specifications
Esempi di applicazione KNX Secure disegno schematico, edificio per uffici a più piani.
The demands on multi-floor office buildings are as various as the world of work. For such a new building, you should provide one KNX IP router and one Smart Visu Server per floor. Thus, each floor can function for itself, but still be managed centrally.

If a floor is modernised during its useful life, all other areas are optimally protected against possible construction work damage. Central devices, such as a weather station, are simply integrated into the overall system via a separate or existing KNX IP router. It is recommended to plan a separate line for the central devices.

Objective of the project
  • Functional reliability of the entire system
  • Guaranteed connection between the visualisation and the KNX bus
  • Galvanic separation in the event of a fault
  • Increased speed of transmission of central commands
  • Reduced cabling costs (only install network in each section) 
 
Steps in ETS
  • Create a new project.
  • Add line
  • Add IPR 300 S REG as an IP router in each case
  • Use IPR 300 S REG in unencrypted mode
  • Activate filter tables
  • Use and start up the preferred connection in the application (for visualisation communication)
  • Establish IP tunnelling for visualisation (use reserved tunnel)
  • Commission all other devices according to the manufacturer specifications
Esempi di applicazione KNX Secure disegno schematico, concessionaria auto multipiano.
When planning a car dealership, the organisational, economic and architectural viewpoints should be considered. It is important in addition to be able to easily optimise the building in the future.

To this end, use one IP router per working area. In addition, provide a Smart Visu Server as the central control component. Thus, each area can function for itself, but still be managed centrally. If an area is modernised during its useful life, all other areas are optimally protected against possible construction work damage. You should plan a separate line for the central devices.

After commissioning, individual optimisation of the system can also be made possible from outside the customer network. For this you need an additional IP interface and the software upgrade for the interface. 

Objective of the project
  • Functional reliability of the entire system
  • Guaranteed connection between the visualisation and the KNX bus
  • Galvanic separation in the event of a fault
  • Increased speed for transmission of central commands
  • Reduced cabling costs (only install network in each section)
 
In connection with the optional software upgrade:
  • additional project configuration possible without travel costs
  • The highest level of security during commissioning even from outside the customer network
 
Steps in ETS
  • Create a new project.
  • Add lines
  • Add IPR 300 S REG as an IP router in each case
  • Use IPR 300 S REG in unencrypted mode
  • Activate filter tables
  • Use and start up the preferred connection in the application (for visualisation communication)
  • Establish IP tunnelling for visualisation (use reserved tunnel)
  • Commission all other devices according to the manufacturer specifications

In connection with the software upgrade:
  • Add IPS 300 S REG as the KNX data interface
  • Purchase the IPS Remote licence via myJUNG
  • Allocate project password
  • Use IPS 300 S REG in encrypted mode
  • Input the device certificate
  • Allocate the release code for the remote configuration
Create professional feel-good factors with building automation: provide your guests with the highest level of comfort with state of the art technology in the background and operate your hotel building with maximum energy efficiency.

A central weather station allows location-based weather data to flow into the building automation system. The heating regulation is reduced with rising outdoor temperatures and thus saves money and resources. The system should be operated in a fully encrypted KNXnet / IP network so that you can always benefit from these advantages. This makes potential hacker attacks on your building automation infrastructure significantly more difficult.
 
Objective of the project
  • Resource and cost saving construction of a new installation
  • Optimisation and automation of daily processes
  • Protection of the customer data
  • Encrypted communication
  • Protection from hacker attacks
  • High performance and future-proof installation
 
Steps in ETS
  • Create new project and assign project password
  • Add lines
  • Add IPR 300 S REG as an IP router in each case
  • Use IPR 300 S REG in encrypted mode
  • Input the device certificate
  • Change commissioning password (optional)
  • Change authentication code (optional)
  • Activate filter tables
  • Use and start up the preferred connection in the application (for visualisation communication)
  • Establish IP tunnelling for visualisation (use reserved tunnel)
  • Commission all other devices according to the manufacturer specifications
 
Additional note
  • Passwords are not required when the project is open.
  • The commissioning password must be entered if the project is not open.
Modern hotels set new standards for individual convenience. Provide added value for your guests with building automation and relieve hotel personnel. The smart hotel can cover several areas.

For example, the temperature in all rooms can be set or changed from a central location. A DND (Do Not Disturb) or MUR (Make Up Room) request from the guest can also be viewed at a central location. This allows you to optimally plan and execute the daily cleaning process. As sensitive data are also transmitted in such a hotel, we recommend protecting the data using state of the art technology. Operate a fully encrypted KNXnet/IP network for this to protect your guests and customers. The protection of customer data has the side effect that you as hotel owner are also optimally protected against hacker attacks on your building automation technology.

Objective of the project
  • The security of guest data has the highest priority 
  • Communication according to the latest security standards
  • Each section is considered as its own "island" 
  • Project design can be reproduced almost infinitely
  • JUNG Visu Pro (JVP) Hotel manages central information of each "island" via the KNX-IP interface
  • The required knowledge is reduced to a minimum in the event of a fault 
  • Minimisation of spare device storage 
  • Replacement devices can be pre-programmed
 
Steps in ETS
  • Create new project and assign project password
  • Add lines 
  • Add 203201SIPSR in each case as an IP interface
  • Use 203201SIPSR in encrypted mode
  • Input the device certificate
  • Change commissioning password (optional)
  • Change authentication code (optional)
  • Use and start up the preferred connection in the application (for visualisation communication)
  • Establish IP tunnelling for visualisation (use reserved tunnel)
  • Commission all other devices according to the manufacturer specifications

Additional notes
  • Passwords are not required when the project is open.
  • The commissioning password must be entered if the project is not open.

JUNG Newsletter

Product news, architecture references and smart home trends: With our JUNG newsletters you are always well informed when it comes to trends and news.

Contatti

Non è il suo interlocutore? Qui può trovare l’interlocutore JUNG nel suo paese.