Building Controller Certificate Management with Batch CSR Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The process of requesting, applying, and renewing security certificates in building management systems is time-consuming and tedious, requiring an improved method for efficient certificate management.

Innovation Solution

A system and method where a mobile device or certificate management device communicates with a remote server to batch-download and generate security certificates for controllers and client devices within a building management system, using an API to solicit and upload Certificate Signing Requests (CSRs) for batch generation and distribution of certificates, with options for automatic renewal.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If certificates are requested, applied and renewed individually for each controller and client device, then security certificate management is performed manually, but the process is time-consuming and tedious

Engineering Contradiction:
Improvecertificate management processVSAvoidtime for certificate requests and renewals
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent combines multiple individual certificate operations into a single batch processing operation. The system allows simultaneous solicitation of Certificate Signing Requests from multiple controllers and client devices, and simultaneous generation and distribution of certificates to all devices, transforming a tedious sequential process into an efficient parallel operation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements automatic certificate management where the building management system automatically solicits CSRs from devices, generates certificates, and distributes them without requiring manual intervention. The system also automatically tracks certificate expiration dates and initiates renewal processes, eliminating the need for operators to manually manage each certificate lifecycle.

Inventive Principle:
Principle #25Self-service

2Reliability

If multiple certificates are managed individually, then each certificate can be properly configured, but the overall process becomes complex and tedious

Engineering Contradiction:
Improvecertificate configurationVSAvoidcertificate management process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal certificate management system that handles multiple device types (controllers and client devices) through a single integrated process. The system uses a standardized workflow that automatically adapts to different device types, eliminating the need for separate management procedures for each device category while maintaining proper configuration for all.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces an intermediary certificate management component that mediates between the building management system and individual devices. This intermediary automatically manages the complex tasks of CSR solicitation, certificate generation, and distribution, shielding operators from the complexity while ensuring reliable configuration of all certificates.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If certificates are renewed periodically, then security is maintained, but the manual renewal process is time-consuming

Engineering Contradiction:
Improvesecurity certificate validityVSAvoidcertificate renewal efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements automatic tracking of certificate expiration dates and provides feedback to initiate renewal processes before certificates expire. The system monitors the validity status of all certificates and automatically triggers renewal operations when needed, ensuring continuous security coverage without requiring manual tracking or intervention.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary actions by automatically initiating certificate renewal processes before existing certificates expire. The system proactively manages the certificate lifecycle by scheduling and executing renewal operations in advance, preventing security gaps while eliminating the need for reactive manual renewal efforts.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11237534B2Managing certificates in a building management system
Publication Date: 2022.02.01 HONEYWELL INTERNATIONAL INC
  • US11237534B2 patent drawing
  • US11237534B2 patent drawing
  • US11237534B2 patent drawing

AI summary

A method of providing a plurality of controller certificates for a plurality of controllers within a Building Management System (BMS) includes downloading project information defining the BMS and using the downloaded project information to solicit a Certificate Signing Request (CSR) from each of the plurality of controllers of the BMS. The received CSRs are uploaded to a remote server so that the remote server can generate a corresponding controller certificate for each of the plurality of controllers of the BMS. The generated controller certificates are then downloaded to the corresponding one of the plurality of controllers of the BMS.