BAC Gateway Isolating Client Access from Building Automation Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing building automation and control (BAC) networks face challenges in providing flexible access to building data while maintaining security and avoiding network traffic issues as more users access the network.

Innovation Solution

A system that enables isolated client device interaction with BAC networks by maintaining a data warehouse of BAC data externally and using a BAC access management system with API-based access, implementing a permissions-based access control protocol to manage user access and control functionalities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If direct access to BAC networks is provided for flexible user interaction, then ease of operation and adaptability improve, but security risks and network traffic issues worsen

Engineering Contradiction:
Improveflexible access to building dataVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a BACnet gateway as an intermediary component that sits between the BAC network and external systems. The gateway translates and mediates communication, allowing third-party applications to access building data without direct connections to the BAC network. This resolves the contradiction by providing flexible access through the gateway while maintaining network security through isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system architecture is segmented into distinct layers: the BAC network layer, the gateway layer, and the application layer. This segmentation allows different levels of access control and isolation, enabling flexible data access for applications while protecting the core BAC network from direct exposure to external threats.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If more users are allowed to access the BAC network for increased versatility, then adaptability improves, but network traffic and security risks worsen

Engineering Contradiction:
Improveuser access flexibilityVSAvoidnetwork traffic issues
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The gateway acts as a traffic mediator that handles all communication between external users and the BAC network. It consolidates and manages network traffic, preventing multiple direct connections from overwhelming the BAC network. Applications communicate with the gateway rather than directly with BAC devices, reducing overall network traffic load.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The gateway creates virtual representations or copies of BAC data and devices, allowing multiple applications to access these copies simultaneously without generating actual traffic to the BAC network. This enables versatile user access while keeping the original network traffic minimal.

Inventive Principle:
Principle #26Copying

3Ease of operation

If direct connections are established for application access, then ease of operation improves, but system complexity and security management worsen

Engineering Contradiction:
Improveapplication accessVSAvoidaccess control management
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The gateway serves as a centralized access control intermediary that simplifies security management. Instead of managing individual access permissions for each application to each BAC device, the gateway provides a single point of control where access policies can be uniformly applied and managed.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The gateway provides universal access control functionality that serves multiple applications and users through a single system. It handles authentication, authorization, and data translation for all connections, reducing the overall complexity compared to implementing separate access control mechanisms for each application.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12301542B2Systems configured to enable isolated client device interaction with building automation and control (BAC) networks, including third-party application access framework
Publication Date: 2025.05.13 WILLOW TECH CORP PTY LTD
  • US12301542B2 patent drawing
  • US12301542B2 patent drawing
  • US12301542B2 patent drawing

AI summary

Various embodiments employ technology solutions to enable isolated client device interaction with building automation and control (BAC) networks, for example including configuration of a third-party application access framework which enables access to physical devices in a built environment. For example, a data exchange gateway interfaces a system with a BAC (Building Automation and Control) network, wherein the BAC network provides via the gateway, on a periodic basis, data values presented by each of a plurality of physical devices on the BAC network. A data exchange module receives periodic data values and causes recording of those values in a BAC database isolated from the BAC network. A permissions rules module control access to data in the BAC database. An API request handling module handles requests from third-party software platforms via an API.