Building Management System Malicious User Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Building management systems (BMS) face challenges in detecting and preventing malicious user activity, as unauthorized access can lead to severe disruptions in building controls, such as altering HVAC, security, and lighting systems, without adequate real-time monitoring and verification processes.

Innovation Solution

A BMS that includes a user access point, building subsystems, and a controller configured to compare user inputs with user and equipment profiles to determine a safety value. If the safety value exceeds a predetermined range, a verification process is initiated, involving contact with authorized users via email, text message, or automated phone calls to confirm intended changes before implementing them.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated control is increased in building management systems, then system efficiency and productivity are improved, but vulnerability to malicious usage and difficulty of monitoring increases

Engineering Contradiction:
Improvesystem efficiencyVSAvoidvulnerability to malicious usage
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system continuously monitors user inputs and system state changes, comparing them against established profiles and safety ranges. This feedback loop enables real-time detection of anomalous behavior that deviates from normal operational patterns, allowing the system to identify potential malicious activities while maintaining automated control.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system pre-establishes user profiles, equipment profiles, and safety ranges before malicious activities can occur. By having these reference parameters ready in advance, the system can immediately compare incoming user inputs against them and detect anomalies without delay, enabling proactive prevention rather than reactive response.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If real-time monitoring and verification processes are implemented, then system security and reliability are improved, but system complexity and operational overhead increase

Engineering Contradiction:
Improvesystem securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The monitoring system applies different levels of scrutiny to different aspects of system operation. Critical parameters and high-risk operations receive enhanced verification through safety value assessment and profile comparison, while routine operations proceed with standard monitoring. This differentiated approach maintains security without uniformly increasing complexity across all system functions.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system automatically performs monitoring, comparison, and verification functions without requiring manual intervention. The controller autonomously assesses safety values, compares inputs against profiles, and determines whether verification is needed, reducing operational overhead while maintaining high security standards through automated decision-making.

Inventive Principle:
Principle #25Self-service

3Reliability

If safety verification processes are implemented for user inputs, then system integrity is protected, but response time and operational speed may be reduced

Engineering Contradiction:
Improvesystem integrityVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The system applies verification processes selectively rather than universally. By assessing safety values and comparing inputs against profiles, the system determines whether full verification is necessary or if standard processing suffices. This partial application of verification maintains system integrity for critical operations while allowing faster processing for routine, low-risk inputs.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10909240B2Building management system with malicious user detection and prevention
Publication Date: 2021.02.02 TYCO FIRE & SECURITY GMBH
  • US10909240B2 patent drawing
  • US10909240B2 patent drawing
  • US10909240B2 patent drawing

AI summary

A building management system (BMS) includes a user access point configured to receive a user input corresponding to the BMS. The system includes at least one building subsystem in communication with the user access point and configured to control subsystem equipment in response to the user input. Additionally, the system includes a controller configured to: receive the user input, and receive access point data. The controller is further configured to compare the user input and access point data to a user profile and/or an equipment profile. Additionally, the controller is configured to determine a safety value using the comparison, and determine if the safety value is outside of a predetermined safety range. If the safety value is outside of the predetermined safety range, the controller is configured to initiate a verification process.