Device Management Profile Comparison for BMS Cyberattack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Building management systems (BMS) are vulnerable to cyberattacks due to the coexistence of IT and OT/IoT devices, lack of sophisticated detection mechanisms, and isolation of multi-tier architecture systems, leading to potential security breaches that can spread across organizational infrastructure.

Innovation Solution

A method and system using a device management layer with a device management client and server to enforce security by comparing base and real-time product-platform profiles, detecting attacks, generating alerts, and communicating attackable profiles via secure channels to prevent further breaches and spread.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Power

If web-enabled devices are deployed to improve processing capabilities, then processing capability is improved, but vulnerability to cyberattacks increases

Engineering Contradiction:
Improveprocessing capabilityVSAvoidvulnerability to cyberattacks
Core Design Contradiction:
PowerVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by capturing a baseline product-platform profile during the boot-up process before the device is fully operational. This baseline profile serves as a reference state that enables future detection of unauthorized changes or attacks, allowing the system to prepare defensive measures in advance rather than reacting after compromise occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors the device's product-platform profile during operation and compares it against the stored baseline profile. This feedback mechanism detects deviations that indicate potential security breaches, enabling real-time identification of attacks while maintaining the device's web-enabled functionality and processing capabilities.

Inventive Principle:
Principle #23Feedback

2Difficulty of detecting and measuring

If sophisticated detection mechanisms are implemented to detect attacks, then detection capability is improved, but device complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoiddevice complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The system creates a simplified copy or representation of the device's state through the product-platform profile, which captures essential configuration parameters and control settings. This profile copy enables complex security detection without requiring the full complexity of the actual device system, as comparisons are performed on the streamlined profile data rather than the entire device architecture.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The security detection mechanism is segmented into distinct functional components: a device management client that captures and stores the baseline profile during boot-up, and a monitoring function that compares real-time profiles against the baseline. This segmentation allows the detection capability to be implemented as a modular addition rather than a monolithic complex system, reducing overall device complexity while maintaining sophisticated detection ability.

Inventive Principle:
Principle #1Segmentation

3Productivity

If multi-tier architecture systems are used to manage buildings efficiently, then building management efficiency is improved, but security breach propagation risk increases

Engineering Contradiction:
Improvebuilding management efficiencyVSAvoidsecurity breach propagation risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The device management client is designed with multi-functionality, serving both the original building management functions and the additional security monitoring function. By integrating attack detection capabilities into the existing multi-tier architecture rather than adding separate dedicated security systems, the solution maintains building management efficiency while simultaneously addressing security breach propagation risks across the distributed system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240330472A1Method and system to enforce security on devices using device managament layer
Publication Date: 2024.10.03 TYCO FIRE & SECURITY GMBH
  • US20240330472A1 patent drawing
  • US20240330472A1 patent drawing
  • US20240330472A1 patent drawing

AI summary

A method to enforce security on a device by a device management client running on the device is provided. The method includes receiving a base product-platform profile of the device during a boot-up process of the device. The base product-platform profile indicates one or more control parameters of the device set at a time of installation of an application stack on the device. The method further includes comparing the one or more control parameters in the base product-platform profile with corresponding one or more control parameters in a real-time product-platform profile of the device. The method further includes detecting an attack to the device based on at least one of the one or more control parameters in the base product-platform profile being different from a corresponding control parameter in the real-time product-platform profile.