Building Automation Security Scanning via Cloud Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Building automation systems face security vulnerabilities due to exposure of communication ports and lack of real-time security assessments, which can lead to public exposure and increased risk of cyberattacks.

Innovation Solution

A method and system that allow users to initiate external security scans through a user interface, with the controller forwarding requests to a cloud service for real-time security assessments, including validation of firewalls, Ethernet and Wi-Fi configurations, open ports, and security certificates, generating a report with recommendations for addressing vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If real-time security scans are performed on building automation systems, then security vulnerabilities can be detected promptly, but system exposure to cyberattacks increases during the scanning process

Engineering Contradiction:
Improvesecurity vulnerability detectionVSAvoidcyberattack risk during scanning
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a cloud-based service as an intermediary to perform security scans remotely. The controller forwards security scan requests to the cloud service, which then conducts the actual scanning operations. This mediator approach allows vulnerability detection without requiring direct external access to the building automation system, thereby reducing cyberattack risk during scanning while maintaining reliable security assessment capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive security assessments are conducted covering firewalls, ports, configurations, and certificates, then security coverage is improved, but system complexity and assessment time increase

Engineering Contradiction:
Improvesecurity assessment coverageVSAvoidsecurity assessment system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security assessment system into distinct functional modules: firewall validation, port scanning, configuration validation, and certificate verification. Each module independently assesses specific security aspects and generates separate findings. This segmentation enables comprehensive security coverage while managing complexity through modular design, allowing each component to be developed, maintained, and executed independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The cloud-based service performs multiple security assessment functions (firewall validation, port scanning, configuration checks, certificate verification) through a single unified platform. This multi-functional approach consolidates what would otherwise require multiple separate tools and processes, improving security coverage while actually reducing overall system complexity by providing a comprehensive solution in one system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If security scans are performed frequently to reduce public exposure, then security monitoring is improved, but resource consumption and system load increase

Engineering Contradiction:
Improvesecurity monitoring frequencyVSAvoidresource consumption during scanning
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements periodic security scanning where the cloud-based service conducts comprehensive security assessments at scheduled intervals rather than continuously. Between scan periods, the system maintains security posture without active scanning. This periodic approach ensures regular security monitoring to reduce public exposure while avoiding continuous resource consumption and system load associated with constant scanning operations.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP4024758A1Network security management for a building automation system
Publication Date: 2022.07.06 TRANE INTERNATIONAL INC
  • EP4024758A1 patent drawingFigure 1
  • EP4024758A1 patent drawingFigure 2
  • EP4024758A1 patent drawingFigure 3A

AI summary

Methods and systems for performing an electronic security assessment of a building automation system are provided. The building automation system includes a controller and a network of electronic devices connected in electronic communication. The method includes requesting, by the controller, an electronic security scan of the controller with a data set of the controller via a secured channel to a cloud-based service. The method also includes initiating the electronic security scan of the controller based on the data set of the controller. The method further includes electronically assessing security vulnerabilities of the building automation system. The method also includes electronically assessing, by the controller, security vulnerabilities of the network of electronic devices connected in electronic communication with the controller. Also the method includes determining a recommendation list for resolving security vulnerabilities of the building automation system based on the electronically assessing security vulnerabilities.