Balluff - BVS CA-BN Technical Documentation
Loading...
Searching...
No Matches
Operation

This product is developed and maintained in accordance with applicable cybersecurity requirements and internal secure development processes.

Intended Use

BVS CA-BN devices are intended exclusively for:

  • Capturing digital image data in the visible or sensor-dependent extended spectral range
  • Transmitting image data into a host system
  • Integration into industrial image processing and automation systems performing tasks such as:
    • Quality control
    • Identification
    • Measurement
    • Robotics
    • Process monitoring
  • Operation within the voltage, temperature, humidity, and environmental conditions specified in this technical manual.

BVS CA-BN devices provide communication interfaces to:

  • Configure and control the device
  • Acquire and transfer individual images or a continuous stream of image data to a host systems for visualization, storage, or further processing in an application
  • Support typical machine vision use cases such as inspection, automation, and monitoring
Note
BVS CA-BN devices itself:
  • Do not perform any safety-related or decision-making function
  • Do not process the image content for deriving decisions from that processing (e.g., no face recognition, object detection, classification or safety logic is incorporated into the device). It may however modify the image data by other means (e.g., by flipping the image data in memory before transferring it). See e.g. Use Cases or the individual device features described by this manual for what the device is capable of
  • Do not operate autonomously

All application-level behavior, including any processing to derive decisions from the acquired data, interpretation of the acquired data, or system response based on acquired data is the sole responsibility of the integrator using an SDK like Impact Acquire.

Intended Users

Devices belonging to the BVS CA-BN family are intended exclusively for:

  • Machine manufacturers (OEMs)
  • Qualified developers
  • System integrators with knowledge of the used programming language and image acquisition systems as well as the underlying operating system and the characteristics of the electrical and mechanical environment in which the device is deployed
  • Qualified service and maintenance technicians trained in secure system integration and deployment practices

Users are expected to:

  • Understand and implement appropriate security measures for device access and communication interfaces
  • Ensure that access to systems using BVS CA-BN devices is restricted to authorized individuals only

BVS CA-BN device are not intended to be used by:

  • private users
  • children or minors
  • untrained personnel

Intended Environment

BVS CA-BN devices are intended to be used in controlled environments such as:

  • Industrial automation systems
  • Laboratory or development environments
  • Machine vision and inspection systems

In addition, the secure and compliant use of BVS CA-BN devices requires that:

  • Any BVS CA-BN device is usually integrated into a larger system and is not used standalone
  • The execution environment (OS, network, and system security) is controlled by the integrator or the operator of the device
  • Logical access to BVS CA-BN devices is controlled via appropriate authentication and authorization mechanisms
  • The physical deployment of the complete system ensures that devices and host systems are not accessible to unauthorized personnel

Safety-Related Product Limitations

BVS CA-BN devices are designed to capture and provide image data. The device

  • does not make any autonomous safety-related decisions
  • does not replace a safety control system
  • does not replace access control
  • does not replace cybersecurity infrastructure
  • does not perform active network monitoring

Safety functions for the overall system must be provided by the system architecture of the integrator or machine manufacturer.

Forseeable Misuse

BVS CA-BN devices are not foreseen and intended for:

  • Direct use in safety-critical systems where failure could endanger human life or health
  • Applications requiring certified functional safety (e.g., IEC 61508, ISO 13849)
  • Applications processing and storing private data (portraits, body images, biometrical data, etc.) without additional security measures
  • Application processing or storing critical or sensitive data without additional security measures
  • Uncontrolled deployment in hostile or publicly accessible network environments without additional security measures
  • Use as a standalone product without embedding it into some sort of application running on a system or machine with an access controlled security layer
  • Use as the sole security component for
    • Energy supply
    • Water supply
    • Defense systems
    • Aviation
    • Rail safety
    • Medical life-support systems
  • Use by private users
  • Use by end users without technical expertise

Responsibilities Of The Integrator

The integrator of BVS CA-BN devices is responsible for:

  • Defining the final application behavior and risk profile
  • Implementing appropriate security measures in the host application and deployment environment
  • Ensuring compliance with applicable regulations (including CRA, if applicable to the final product)
  • Validating that the system design is suitable for the intended operational context

Protocols And Technologies

BVS CA-BN devices utilize the following industry-standard protocols and technologies for image transfer and communication with a host application:

PCIe

BVS CA-BN devices are built on the PCIe standard:

  • Protocol: Proprietary PCIe-based communication protocol
  • Transport: PCIe Gen. 2, 2-4 lanes
  • Purpose: High-bandwidth device communication using PCIe
  • Standard Compliance: Proprietary PCIe-based communication protocol
  • Security Considerations: Unencrypted traffic; should be used on isolated/trusted environments only

GenICam™ (Generic Interface For Cameras)

BVS CA-BN devices utilize the GenICam™ standard:

  • Version: GenICam 3.x
  • Purpose: Standardized device feature access and configuration
  • XML Schema: GenApi (Generic Application Programming Interface)

Security And Vulnerability Management

Vulnerability Disclosure

Security vulnerabilities should be reported to:

Known Security Limitations

Warning
The PCIe protocol operates without encryption and authentication
Device Configuration Security:
  • Device configuration and control interfaces are not protected by authentication or access control mechanisms. Any user with network or physical access might be able to modify device settings
  • Some devices may allow to store user or application specific data inside the device itself (e.g., user-defined configuration files, calibration data, etc.). This data is stored in non-volatile memory. The device does not provide any encryption or access control for this data.

Third-Party Dependencies

Detailed information on third-party components BVS CA-BN devices rely on can be found here: Legal Notice

Apart from the third-party components, BVS CA-BN devices themselves also depend on the operating system it is deployed on as well as an SDK like Impact Acquire to control it.

Note
Users are responsible for maintaining up-to-date operating system patches and security updates for the host environment.

Secure Deployment Recommendations

  • Network Isolation: Deploy devices on dedicated VLANs
  • Access Control: Implement least-privilege access to device interfaces
  • Update Management: Regularly check for firmware updates and security patches

Standards Compliance

BVS CA-BN devices adheres to:

  • EU Cyber Resilience Act (CRA): Security-by-design principles
  • IEC 62443-4-1: Secure product development life-cycle
  • GDPR: No personal data processing (device identifiers only)

Data Processing

Collected Information

BVS CA-BN devices do not collect personally identifiable information (PII) or sensitive data.

Data Storage

BVS CA-BN devices might store configuration and operational data inside non-volatile memory. No external cloud storage is used.

  • Local configuration files can be stored by the user or the controlling application
  • Some devices might even offer to store user specific data inside the device itself (e.g., user-defined configuration files, calibration data, etc.). This data is stored in non-volatile memory and can be accessed by the user via an application
  • No telemetry or analytics is transmitted externally

None of this information is personally identifiable information (PII) or sensitive data. It is used solely for device management, diagnostics, and performance optimization. None of this information is transmitted externally or stored in the cloud without the users explicit consent.

Improper Use

Warning
Improper use of BVS CA-BN devices can lead to security vulnerabilities, data breaches, and operational failures. Users must ensure that the device is used in accordance with the intended use and within secure environments. Improper use includes, but is not limited to
  • deploying the device in untrusted networks
  • failing to apply security patches
  • using the device in safety-critical applications without appropriate safeguards
  • using the device to process sensitive or personal data without implementing necessary security measures
  • using the device in a manner that
    • violates applicable laws or regulations
    • exposes the devices to unauthorized access or control
    • allows for the execution of arbitrary code or commands on the device
    • allows for denial of service (DoS) attacks or other disruptions on the device
    • allows for the injection of invalid data or commands into the device
    • allows for the disclosure of sensitive information or business secrets to unauthorized parties
    • allows for the compromise of the integrity or confidentiality of the data being processed or transmitted by the device
    • allows for the circumvention of security controls or access restrictions implemented on the host system or device
See also

Potential Risks

  • Espionage: Attacker may try to steal business secrets or other interesting data (from the network) depending on what kind of image data is captured. This could be mitigated by using isolated networks and secure access controls. An attacker could also try to gain access to the host system and steal data from there
  • Sabotage: Attacker may attempt to disrupt or impact operation (via the network)
  • Extortion: Attacker may attempt to extort money from user by threaten to disclose stolen information
  • Attackers could identify a vulnerability in BVS CA-BN devices and try to exploit it in order to get access to the host on which BVS CA-BN devices run
  • Attackers might be able to trigger a buffer overflow and execute arbitrary code
  • Attackers might be able to trigger a denial of service (DoS) condition and make the host system or the device unavailable for a certain period of time
  • Attackers might be able to inject invalid data into the device or the host system and cause unexpected behavior
  • See Known Security Limitations as well

All this could be mitigated by using secure host systems and keeping them up to date with security patches for every software component running on that system. Also the firmware of BVS CA-BN devices should be kept up to date with the latest security patches.