What is the difference between KNX Data Secure and KNX IP Secure?
KNXKNX Data Secure protects individual group telegrams at the application layer: telegrams for secured group addresses are authenticated and encrypted end-to-end, from the sending device to the receiving device, regardless of whether they travel over twisted pair, an IP tunnel, or both. Thinka supports KNX Data Secure — import the .knxkeys file exported from ETS to enable it.
KNX IP Secure (Secure Tunneling) encrypts the KNXnet/IP transport itself, so the tunnel connection between an IP client and the interface is authenticated and encrypted. Thinka does not currently support KNX IP Secure.
KNX Data Secure still protects you over a plain tunnel: Thinka forwards bus telegrams to tunnel clients in their original, still-encrypted form. A device that opens an unauthorized tunnel to Thinka cannot read the contents of Data Secure group addresses and cannot write to them, because KNX devices reject telegrams without a valid authentication code. Group addresses that are not secured with Data Secure remain readable and writable over an open tunnel, so protect those with network isolation.