Dynamic MUD Policy System for Smart Building Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The Manufacturer Usage Description (MUD) specification is static and not scalable for dynamic building systems, failing to adapt to changes in device configurations or additions/removals, and is not suitable for fine-grain access control in smart buildings.

Innovation Solution

A dynamic MUD policy system that uses building model queries to generate and implement access policies, allowing the MUD file to adapt to changes in the building model, including new or removed devices, by referencing entities and relationships within the BRICK building model.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the MUD specification is used for network security, then device access control is implemented, but the system is static and not scalable for dynamic building configurations

Engineering Contradiction:
Improvenetwork securityVSAvoidadaptability to building changes
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transforms the static MUD specification into a dynamic system by introducing building model queries that automatically update access policies when the building model changes. The MUD file now contains query statements that reference building model entities, enabling automatic regeneration of access control rules without manual intervention when devices are added or removed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system establishes a feedback loop where changes in the building model trigger automatic updates to the MUD file. The building model acts as a dynamic data source that continuously informs the access policy generation, ensuring the MUD specification remains synchronized with the actual building configuration.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If the MUD specification is used for access control, then device interactions are controlled, but manual reconfiguration is required when devices are added or removed

Engineering Contradiction:
Improveaccess control managementVSAvoidtime for manual reconfiguration
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system enables self-service by allowing the building model to automatically generate and update MUD file contents. When devices are added or removed from the building model, the system automatically regenerates the appropriate access control policies without requiring manual configuration, reducing both time and human intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements preliminary action by pre-defining query templates in the MUD file that reference building model entities. These queries are prepared in advance and automatically resolved when the building model changes, eliminating the need for manual policy creation when new devices are added.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the MUD specification is used for device access control, then network security is provided, but fine-grain access control for smart building applications is not achieved

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess policy granularity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by enabling different access policies for different building model entities and their relationships. The query-based approach allows specific access control rules to be defined for particular device types, zones, or functional relationships within the building model, achieving fine-grain control tailored to local requirements.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11411999B2Building system with dynamic manufacturer usage description (MUD) files based on building model queries
Publication Date: 2022.08.09 TYCO FIRE & SECURITY GMBH
  • US11411999B2 patent drawing
  • US11411999B2 patent drawing
  • US11411999B2 patent drawing

AI summary

A building security system for a building includes one or more memory devices configured to store instructions. The instructions, when executed on one or more processors, cause the one or more processors to receive an access policy data structure for a building device, the access policy data structure indicating access policies for interactions of one or more other building devices with the building device, wherein the access policy data structure identifies the one or more other building devices with one or more building model queries, generate a dynamic access policy data structure for the building device by resolving the one or more building model queries with a building model to identify the one or more other building devices, wherein the dynamic access policy data structure comprises the access policies, and implement the access policies of the dynamic access policy data structure based on the one or more other building devices.