Building Automation Controller Security Scanning Before Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Building automation systems face security vulnerabilities due to exposed communication ports and lack of real-time security assessments, which can lead to public exposure and increased risk of cyberattacks.

Innovation Solution

A method and system that allow users to initiate external security scans through a user interface, with the controller forwarding requests to a cloud service for real-time security assessments, including validation of firewalls, Ethernet and Wi-Fi configurations, open ports, and security certificates, to generate a report and recommendation list for addressing vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If real-time security scans are performed on controllers, then security vulnerabilities are detected, but public exposure increases due to frequent scanning

Engineering Contradiction:
Improvesecurity vulnerability detectionVSAvoidpublic exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs security assessments at the time of installation before the controller is deployed to the public network. This preliminary action ensures that security vulnerabilities are addressed before the controller becomes publicly accessible, eliminating the need for frequent subsequent scans while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system proactively identifies and remediates security vulnerabilities before they can be exploited. By performing security checks in advance and providing recommendation lists for resolution, the system prevents potential security breaches rather than merely detecting them after exposure.

Inventive Principle:
Principle #9Preliminary anti-action

2Reliability

If comprehensive security assessments are performed, then security vulnerabilities are identified, but the complexity of the assessment process increases

Engineering Contradiction:
Improvesecurity vulnerability identificationVSAvoidassessment process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security assessment process is divided into multiple independent components: firewall validation, service configuration validation, Ethernet and Wi-Fi configuration validation, open port determination, security certificate validation, and egress point validation. Each component can be executed independently and contributes to the overall security assessment without requiring the entire complex process to run simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A cloud-based service acts as an intermediary to perform the complex security assessment tasks. The controller forwards scan requests to the cloud service, which executes the comprehensive security checks and returns results. This intermediary approach offloads the computational complexity from the local controller while maintaining thorough security validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security scans are performed frequently, then security vulnerabilities are detected in real-time, but the time required for multiple site visits increases

Engineering Contradiction:
Improvereal-time security detectionVSAvoidsite visit time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security assessments are performed at installation time before the controller is deployed to the public network. This preliminary security check ensures that vulnerabilities are identified and can be addressed before the system goes live, eliminating the need for subsequent site visits for security remediation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides immediate feedback through security assessment reports and recommendation lists that guide users in resolving vulnerabilities. This feedback mechanism enables users to address security issues remotely without requiring additional site visits, reducing time loss while maintaining real-time security monitoring capability.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11818162B2Network security management for a building automation system
Publication Date: 2023.11.14 TRANE INTERNATIONAL INC
  • US11818162B2 patent drawing
  • US11818162B2 patent drawing
  • US11818162B2 patent drawing

AI summary

Methods and systems for performing an electronic security assessment of a building automation system are provided. The building automation system includes a controller and a network of electronic devices connected in electronic communication. The method includes requesting, by the controller, an electronic security scan of the controller with a data set of the controller via a secured channel to a cloud-based service. The method also includes initiating the electronic security scan of the controller based on the data set of the controller. The method further includes electronically assessing security vulnerabilities of the building automation system. The method also includes electronically assessing, by the controller, security vulnerabilities of the network of electronic devices connected in electronic communication with the controller. Also the method includes determining a recommendation list for resolving security vulnerabilities of the building automation system based on the electronically assessing security vulnerabilities.