Building Automation Security Scanning for Exposed Port Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Building automation systems face security vulnerabilities due to exposed communication ports and lack of real-time security assessments, which can lead to public exposure and increased risk of cyberattacks.

Innovation Solution

A method and system that allow users to initiate external security scans through a user interface, with the controller forwarding requests to a cloud service for real-time security assessments, including validation of firewalls, Ethernet and Wi-Fi configurations, open ports, and security certificates, generating a report with recommendations to address vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If real-time security scans are performed on building automation systems, then security vulnerability detection is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity vulnerability detectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud-based security scanning service as an intermediary between the building automation controller and the security assessment process. The controller forwards security scan requests to cloud services, which perform the actual security assessments and return results. This mediator approach allows comprehensive security scanning without significantly increasing the complexity of the local building automation system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive security assessments are conducted including firewall validation, port scanning, and certificate verification, then security detection capability is improved, but scan time and processing duration increase

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidsecurity scan duration
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs security assessments at the time of installation and before the technician leaves the site. This preliminary action ensures that security vulnerabilities are identified and can be addressed immediately during the installation phase, rather than discovering issues later when response time is limited.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements scheduled security scans that can be performed periodically or on-demand. The system allows for automated periodic security assessments to be conducted at configured intervals, balancing comprehensive security checking with operational efficiency by not requiring continuous scanning.

Inventive Principle:
Principle #19Periodic action

3Reliability

If security scans are performed frequently to reduce public exposure, then security monitoring is improved, but system resource consumption and operational disruption increase

Engineering Contradiction:
Improvesecurity monitoring effectivenessVSAvoidsystem operational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements scheduled periodic security scans that can be configured to run at specific intervals or during off-peak hours. This approach maintains effective security monitoring while minimizing disruption to building automation operations by not performing scans continuously or during critical operational periods.

Inventive Principle:
Principle #19Periodic action

4Measurement precision

If multiple security validation checks are performed including Ethernet configuration, Wi-Fi configuration, and protocol validation, then security detection precision is improved, but device complexity and operational complexity increase

Engineering Contradiction:
Improvesecurity validation accuracyVSAvoidsystem operation simplicity
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The building automation controller performs self-assessment of its own security configuration by executing security scan requests and processing validation results automatically. The system can identify its own vulnerabilities and generate reports without requiring manual intervention for each validation check, simplifying the operational process while maintaining comprehensive security assessment.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11463470B2Network security management for a building automation system
Publication Date: 2022.10.04 TRANE INTERNATIONAL INC
  • US11463470B2 patent drawing
  • US11463470B2 patent drawing
  • US11463470B2 patent drawing

AI summary

Methods and systems for performing an electronic security assessment of a building automation system are provided. The building automation system includes a controller and a network of electronic devices connected in electronic communication. The method includes requesting, by the controller, an electronic security scan of the controller with a data set of the controller via a secured channel to a cloud-based service. The method also includes initiating the electronic security scan of the controller based on the data set of the controller. The method further includes electronically assessing security vulnerabilities of the building automation system. The method also includes electronically assessing, by the controller, security vulnerabilities of the network of electronic devices connected in electronic communication with the controller. Also the method includes determining a recommendation list for resolving security vulnerabilities of the building automation system based on the electronically assessing security vulnerabilities.