An Authentication Vulnerability Assessment of Connected Lighting Systems
Emerging connected lighting systems (CLS) that incorporate distributed intelligence, network interfaces, and sensors can become data-collection platforms that enable a wide range of valuable new capabilities as well as greater energy savings in buildings and cities. However, CLS technology is currently at an early stage of development, and its increased connectivity introduces cybersecurity risks that are new to the lighting industry and that must be addressed for successful integration with other systems. While a number of existing frameworks, guidelines, and tests for evaluating cybersecurity vulnerability may apply to CLS in whole or in part, there is currently no mandatory requirement for cybersecurity testing or certification. The lighting industry, including technology developers and specification organizations, is currently evaluating the suitability of existing frameworks and guidelines for CLS. To support these efforts, Pacific Northwest National Laboratory (PNNL) is conducting a series of studies intended to educate lighting industry stakeholders on specific cybersecurity practices and characterize their implementation in commercially available CLS with varying system architectures, network-communication technologies, and degrees of maturity. This study demonstrates that tests for authentication vulnerabilities can be developed with objective pass/fail criteria, therby facilitating comparisons between CLS. Based on the limited results of this study, it appears that the CLS that are being brought to market have varying levels of authentication vulnerability. It is hoped that these evaluations will support and perhaps accelerate industry discussions on the risks of specific security vulnerabilities, what vulnerabilities should be addressed by in-development of future lighting-specific best practices, and whether any such practices should be included in voluntary lighting standards.