Cybersecurity Assurance for IoT Lighting Systems

CEW 2 Lighting Controls Association 400

Jan 14, 2022

By Jared Morello, VP of Specification Sales, Legrand North America.

We live in a world of connected, intelligent devices referred to as the Internet of Things (IoT), and each year new products are brought online to solve modern-day challenges.
Connected devices communicate to share information with other devices and systems within a network and are often implemented into the environments of companies in diverse sectors such as manufacturing, healthcare, education, and commercial offices. When equipped and installed correctly with a building’s large-scale automation system, IoT devices and systems help to warrant safe and secure facilities for occupants while reducing operational expenses (OPEX) by optimizing and automating many services, including lighting and HVAC controls.

During a commercial building’s planning and development phase, its lighting system is often a more extensive discussion. IoT lighting systems, which generally include digital sensors, communication interfaces, and actuator drivers, are programmed using advanced control algorithms and can be organized into lighting networks to operate remotely. This not only eliminates the need for the overall system to work in manual mode and reduces costs, but increases energy efficiency, occupant comfort and productivity, as well as cybersecurity assurance.

Understanding Risks

Unfortunately, as the demand for integrated technology such as lighting systems in commercial buildings increases and the flow of data travelling through buildings becomes more complex, potential exposure to cyber threats increases. In recent years there have been multiple instances of hackers entering a corporate network through a compromised device, often tracing back to poorly implemented security. The results are expensive and problematic — leading to loss of revenue and productivity, theft of private information, and erosion of occupant confidence.

In many cases, these cybersecurity attacks, including sniffing and vectoring, and man-in-the-middle (MIT) threats, are caused by poor commission technology, the security features integrated within a device or system at the time of manufacturing that is automatically activated when powered on. MIT attacks are most associated with lighting systems as they are used as an avenue to access a building’s larger network.

When commissioning a new smart lighting system, facility managers must first investigate national and regional requirements and then evaluate a system’s commission technology components. This process includes understanding the system’s device authentication, zero-touch encryption provisions, and lighting network isolation ahead of installation.

The Importance of Encryption

All wireless lighting control systems rely on encryption to protect communication between devices on the network. Although encryption is necessary, it is not sufficient on its own, as it only prevents eavesdropping rather than identifying whom one is communicating with, which is where device authentication comes into play. Identity-based authentication ensures that a device only communicates with another authorized device and prevents it from downloading malicious software (malware) and becoming a security risk. Mutual authentication, encryption, and the ability to securely download firmware are fundamental building blocks of device security.

Network-layer encryption is the first line of defence to prevent an attacker from reading or breaking into the network. Encryption provides a structure for private communication by translating the communication between devices into a code. The device receiving the information can decrypt if the two devices share the same “key.” In wireless systems, the shared keys often must be set or “provisioned” on every device or every zone of devices. During commissioning, this can be an enormous task that is time-consuming, prone to errors, and often unmanageable over the system’s lifetime. More troublingly, it exposes the security keys to the installer’s commissioning tools and sometimes to the installer themselves. Without using key pairs to prove identity, devices that receive the public key are assumed to be authentic and there’s no way for another device or commissioning tool to challenge their authentication. Here is where zero-touch encryption comes into play.

Zero-touch encryption is a type of encryption provisioning that provides a preloaded digital identity and security profile, making the system automatically secure. The contractor never has to set up security keys for the facility manager — this happens automatically, which is why it’s called “zero-touch.” However, it’s important to note that this software can be insufficient by itself — if an attacker discovers a system’s preloaded identity, they then have access to the entire network. To combat this, lighting control systems should proactively replace the pre-existing profile with a new one upon commissioning. This step allows each (sub)network to have unique encryption, and should be handled by the system without the user’s interaction to ease the commissioning process. Embedding strong security into commercial lighting controls and building systems makes it possible for an install of a wireless lighting system to be completed in a matter of hours, compared to several weeks for traditional wired systems or older wireless systems without this technology.

Regarding network isolation, a key component in ensuring that Operational Technology (OT) network vulnerabilities do not lead to vulnerabilities on the Information Technology (IT) network, it’s of great importance to understand the need for this separation. In late 2013, during the peak of the retail season, hackers breached Target’s private network and accessed credit card data for thousands of consumers. The hackers gained entry using network credentials stolen from a provider of refrigeration and HVAC equipment to Target. Incidents like this makes it essential to maintain separation from a building’s network and seek out a lighting system designed to operate on a parallel network that never intersects with a private network.

After the installation and commissioning process is complete of a chosen security integrated IoT lighting system, the benefits and values of a secure system become much more apparent to facility managers, including ease of maintenance and lighting quality.

Protection Starts with Specification

Many centralized, networked lighting systems provide excellent monitoring and control capabilities. For example, the system may set off alarm notifications via email, text, or other methods about issues requiring immediate attention. The system may also provide the facility manager with daily reports on equipment, making operations more responsive and efficient.

Additionally, an IoT lighting system provides a tool for facility managers to guarantee comfortable visual conditions of building occupants working on completing tasks efficiently and safely. These systems support quality lighting by enabling control of light level, spatial brightness, and colour output. Ease of monitoring ensures lighting is provided without interruption while delivering data to the facility manager, which they can leverage to gain insight into user preferences. This information can also be valuable for future lighting designs.

As for cybersecurity assurance, a secure lighting system solution offers a facility manager a way to combat and track vulnerabilities with technology already built within before it’s too late and internal communications and data are shared.

More devices are connected to building networks every day, and it’s of the utmost importance that building owners work together with facility managers and building operators to understand that the opportunities for security threats are also increasing within all building systems. IBM cybersecurity experts analyzing past breaches noted that 20 percent of attacks are initially caused by compromised credentials in a 2021 report. Hackers often exploit a less well-known security hole in IoT devices, including holes within lighting systems connected to a building’s larger network. Thus, educating and understanding the security assurance within IoT devices is paramount and relatively intuitive with the right strategy and system in place.

As specialists in electrical and digital building infrastructures, Legrand highly encourages those evaluating a new networked lighting system to ensure that the chosen manufacture adheres to all government requirements. In addition, all selected products within the system have been extensively tested its security capabilities through third-party certifications, such as the ioXt Alliance Certification program or other programs meeting DesignLights Consortium (DLC) Networked Lighting Control System Technical Requirements (Version 5), also known as NLC5.

Published with the written permission of Lighting Control Association

Source

Related Articles


Latest Articles

  • Hazardous Environment vs. Intrinsically Safe Sensors: Understanding the Differences

    Hazardous Environment vs. Intrinsically Safe Sensors: Understanding the Differences

    May 5, 2025 Sensors designed for industrial applications often face harsh conditions, including extreme temperatures, high humidity, exposure to chemicals, and the presence of combustible gases or dust. Two common classifications for sensors used in such environments are hazardous environment sensors and intrinsically safe sensors. While they share some overlap, they serve different purposes and… Read More…

  • The Wild and Wonderful of Thermal by FLIR – How Thermal Imaging is Augmenting More Than Just Cameras

    The Wild and Wonderful of Thermal by FLIR – How Thermal Imaging is Augmenting More Than Just Cameras

    May 5, 2025 By Krystie Johnston Teledyne FLIR OEM launched their Thermal by FLIR about six years ago, to expand support for original equipment manufacturers (OEMs) who integrate FLIR thermal camera technology into their products. Since then, these collaborations have taken thermal into completely new spaces. Mike Walters, Vice President of Emerging Product Management at FLIR… Read More…

  • Ontario Leads Residential Sector Increase in February Construction Investment

    Ontario Leads Residential Sector Increase in February Construction Investment

    May 5, 2025 Overall, investment in building construction rose 1.5% (+$331.7 million) to $22.4 billion in February, with gains being recorded across all components. The residential sector increased 1.8% to $15.7 billion, while the non-residential sector was up 0.8% to $6.8 billion. Year over year, investment in building construction grew 8.9% in February. On a constant dollar basis (2017=100), investment in building construction… Read More…

  • MCEE 2025 Marks Big Return to the Palais des congrès

    MCEE 2025 Marks Big Return to the Palais des congrès

    May 4, 2025 By Electro-Federation Canada Canada’s largest Mechanical, Plumbing, Hydronics, HVAC, Electrical and Lighting Expo did not disappoint. On April 24-25, more than 6,000 attendees flocked to the Palais des congrès in the heart of Montreal to attend the Mechanical, Conditioning, Electrical, and Equipment (MCEE) trade show to see the latest products, learn about… Read More…


Changing Scene

  • City Electric Supply Bids Farewell to Vickey Mackay and Brian Doucette

    City Electric Supply Bids Farewell to Vickey Mackay and Brian Doucette

    May 5, 2025 After decades of leadership, City Electric Supply bid a warm farewell to two incredible branch managers in their Ottawa District — Vicky Mackay (Ottawa Central & Kemptville) and Brian Doucette (Pembroke). “Their dedication, leadership, and lasting impact will be felt for years to come,” said City Electric Supply on LinkedIn. City Electric Supply are also introducing… Read More…

  • 2025 Skills Ontario Competition & Career Exploration Showcase Highlights the Future Skilled Trade and Technology Workforce

    2025 Skills Ontario Competition & Career Exploration Showcase Highlights the Future Skilled Trade and Technology Workforce

    May 5, 2025 Canada’s largest skilled trades and technology conference, the Skills Ontario Competition, is back at the Toronto Congress Centre May 5th – May 6th. Ian Howcroft, CEO of Skills Ontario, said Skills Ontario is changing lives and inspiring leaders through skilled trades and technologies through events like the Skills Ontario Competition. “We look forward… Read More…

  • Manitoba Government Honours Highest Achieving New Journeypersons

    Manitoba Government Honours Highest Achieving New Journeypersons

    May 4, 2025 The Manitoba government is proud to acknowledge the outstanding work and commitment of newly certified journeypersons, as well as recognize employers and their contributions to Manitoba’s skilled trades, Business, Mining, Trade and Job Creation Minister Jamie Moses announced last night at the Legislative Building during the 33rd annual Apprenticeship Highest Achievement Awards… Read More…

  • Acuity Acquires Sports Lighting Startup M3 Innovation

    Acuity Acquires Sports Lighting Startup M3 Innovation

    May 4, 2025  Acuity Inc. has acquired the business assets of M3 Innovation, LLC, a sports lighting startup that uses innovative technology to lower the overall cost of the installation and operation of sports lighting solutions.   The acquisition has already closed, and the solution is now part of the Acuity Brands Lighting (ABL) business portfolio. M3 Innovation’s products and innovative technology will be available through Acuity’s independent sales network as part of their Lithonia Lighting® brand and through direct sales and utility channels as part of their Holophane® brand.   “We are excited to welcome M3 Innovation to ABL. The founders are thought… Read More…