Cyber defense and response system for buildings

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smart building systems are vulnerable to cyber attacks and operational anomalies, with existing detection methods failing to distinguish between cyber attacks and physical system faults, leading to ineffective responses.

Innovation Solution

A cyber defense response system that utilizes nodes to collect data from building systems, compares data across multiple buildings, and employs algorithms to differentiate between cyber attacks and system faults, triggering automated targeted control responses to mitigate attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If existing anomaly detection methods are used in smart building systems, then system connectivity and remote control capabilities are enabled, but the systems become vulnerable to cyber attacks and cannot distinguish between cyber attacks and physical system faults

Engineering Contradiction:
Improvesmart building system connectivityVSAvoiddetection accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the detection process into multiple specialized components: a cyber attack detection module that analyzes network traffic patterns, a physical fault detection module that monitors system operational parameters, and a differentiation engine that compares results from both modules to determine the nature of anomalies. This segmentation allows the system to maintain smart connectivity while achieving reliable distinction between cyber attacks and physical faults through specialized detection pathways.

Inventive Principle:
Principle #1Segmentation

2Speed

If automated response systems are implemented to respond to detected anomalies, then response speed is improved, but false responses may occur due to inability to distinguish attack types

Engineering Contradiction:
Improveresponse speedVSAvoidanomaly classification accuracy
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The system implements a feedback mechanism where the automated response is conditioned on the output of the anomaly differentiation process. The cyber attack detection module and physical fault detection module continuously monitor system state and provide feedback to the differentiation engine, which adjusts the response strategy based on the classified anomaly type. This feedback loop ensures that automated responses are both rapid and accurately targeted, preventing false responses by continuously verifying the nature of detected anomalies.

Inventive Principle:
Principle #23Feedback

3Difficulty of detecting and measuring

If comprehensive monitoring of building systems is implemented, then detection capability is improved, but system complexity and computational requirements increase

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoiddetection system complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The system introduces intermediary components that simplify the detection architecture: a data preprocessing layer that filters and normalizes incoming data from multiple building systems, a feature extraction module that identifies relevant anomaly indicators, and a rule-based filtering system that eliminates common benign variations. These intermediaries reduce the complexity of the core detection algorithms while maintaining comprehensive monitoring capability, as they prepare data in a standardized format that is easier to analyze.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3693882B1Cyber defense and response system for buildings
Publication Date: 2025.09.03 CARRIER CORP
  • EP3693882B1 patent drawingFigure 1
  • EP3693882B1 patent drawingFigure 2
  • EP3693882B1 patent drawingFigure 3

AI summary

A method for a building system includes determining a relationship between first data from a first building device 30-38 and second data from a second building device 30-38. It is determined whether there is an anomaly based on the relationship. An automatic targeted control response is provided if the anomaly indicates an attack.