BMS Cyber Risk Detection Through Account and Network Policy Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Building Management Systems (BMS) face challenges in easily assessing and mitigating cybersecurity risks, making them vulnerable to cyber threats from both internal and external attacks due to lack of effective security management features.

Innovation Solution

A method for automatically detecting and mitigating cybersecurity risks in BMS by evaluating user account and network device settings, identifying security risks, and presenting policy recommendations through a user interface, allowing users to implement changes based on input or automated responses to enhance cyber health.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If BMS includes basic security features for user account management, then security management capability is improved, but ease of assessing and mitigating cybersecurity risks deteriorates due to technical limitations

Engineering Contradiction:
Improvesecurity management capabilityVSAvoidease of assessing and mitigating cybersecurity risks
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a dashboard as an intermediary interface between the administrator and the complex security settings. The dashboard automatically evaluates security risks, generates policy recommendations, and presents them in an easily consumable format, bridging the gap between basic security features and effective security assessment without requiring deep technical expertise from administrators

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs self-service by automatically evaluating security settings, identifying risks, and generating policy recommendations without requiring manual analysis by administrators. The automated risk evaluation and recommendation generation enable the system to assess and mitigate cybersecurity risks independently, improving ease of operation while maintaining security capability

Inventive Principle:
Principle #25Self-service

2Device complexity

If BMS lacks automated security risk detection and mitigation features, then device complexity is reduced, but vulnerability to cyber threats increases

Engineering Contradiction:
Improvesystem simplicityVSAvoidvulnerability to cyber threats
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by automatically evaluating security settings and generating policy recommendations before cyber threats can exploit vulnerabilities. The system proactively identifies security risks in user accounts and network devices and provides remediation guidance in advance, preventing potential attacks rather than responding to them after occurrence

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The dashboard provides continuous feedback by monitoring security settings, evaluating risks, and presenting policy recommendations to administrators. This feedback loop enables the system to maintain awareness of security posture and guide remediation efforts, reducing vulnerability to cyber threats while maintaining relatively simple system architecture through intelligent monitoring and recommendation mechanisms

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3786821A1Detection and mitigation of cyber security risks for building management system
Publication Date: 2021.03.03 JOHNSON CONTROLS TYCO IP HLDG LLP
  • EP3786821A1 patent drawingFigure 1
  • EP3786821A1 patent drawingFigure 2
  • EP3786821A1 patent drawingFigure 3

AI summary

A method for automatically detecting and mitigating risks related to cybersecurity in a Building Management System (BMS) includes evaluating settings of a user account of the BMS; identifying a security risk associated with the settings of the user account; evaluating settings of a network device of the BMS; identifying another security risk associated with the settings of the network device, presenting a user interface, wherein the user interface allows a user to view a policy recommendation associated with either security risk; and implementing the change in the settings of the user account or a change in the settings of the network device based at least in part on an input from the user via the user interface or an automated response to the policy recommendation. The method allows for administrators to easily view and change settings of user accounts and network devices to improve the cybersecurity of the BMS.