Building Management System Data Privacy Configurator
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Building management systems (BMS) face increased vulnerability to data breaches due to their transition from closed proprietary systems to open, connected systems, compromising personally identifiable information (PII) security, and struggle to comply with evolving privacy regulations.
Innovation Solution
Implementing a data privacy configurator within the BMS that presents a survey to users to identify types of PII collected and set corresponding data privacy settings, which are then used to set constraints for securing and managing PII, ensuring compliance with privacy regulations and protecting against unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If building management systems transition from closed proprietary systems to open connected systems, then convenience and connectivity are improved, but security and vulnerability to data breaches worsen
Solution Approach 1:
The patent segments PII data into different categories (e.g., name, address, social security number) and applies different privacy protection levels and constraints to each category. This allows the system to maintain open connectivity while selectively protecting sensitive data elements through granular privacy settings and access controls.
Solution Approach 2:
The patent introduces privacy parameters and constraint mechanisms as intermediaries between the open BMS system and PII data. These privacy parameters act as a layer of protection that mediates access to PII, allowing the system to remain connected and open while enforcing security through configurable privacy settings and constraints on data collection, storage, and sharing.
2Adaptability or versatility
If building management systems collect and store personally identifiable information, then functionality and service capability are improved, but compliance with privacy regulations becomes more difficult
Solution Approach 1:
The patent implements preliminary action by establishing privacy parameters, constraints, and compliance rules before PII data is collected or processed. The system pre-configures privacy settings, defines acceptable uses, and sets constraints on data sharing and retention, thereby simplifying ongoing compliance management while enabling comprehensive data collection for enhanced functionality.
Solution Approach 2:
The patent uses parameter changes by making privacy settings and constraints configurable and adaptable. The system allows privacy parameters to be modified based on different regulatory requirements and functional needs, enabling the BMS to maintain versatility in data collection while adapting compliance mechanisms to different jurisdictions and use cases through parameter adjustment rather than system redesign.
3Reliability
If building management systems implement enhanced security measures for PII, then data protection is improved, but system complexity and implementation difficulty increase
Solution Approach 1:
The patent applies universality by creating a multi-functional privacy parameter framework that handles multiple security and compliance functions through a unified mechanism. The privacy parameters serve multiple purposes simultaneously: they control data collection, manage access permissions, enforce retention policies, and ensure regulatory compliance, thereby improving data protection without proportionally increasing system complexity.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Methods and systems for managing data privacy of personal identifiable information in a building management system may include presenting a data privacy survey via a user interface of a data processing system. The data privacy survey may identify a plurality of types of personal identifiable information (PII) that will be collected by the building management system, and a plurality of data privacy settings for each of the plurality of types of PII. A setting change to at least one of the plurality of data privacy settings for at least one of the plurality of types of PII may be set, in which one or more constraints in the building management system for each of the plurality of types of PII may be implemented in the building management system.