UPS Controller Command Segmentation and Local Switch Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Uninterruptible power supplies (UPS) are vulnerable to malicious commands from unauthorized sources, which can compromise their operation and security, particularly in configurations where remote access is allowed without adequate filtering or authentication.

Innovation Solution

A UPS system that includes a controller to differentiate between unrestricted and restricted commands based on configuration settings, with the ability to filter and discard unauthorized commands, and an out-of-band switch to ensure that configuration settings can only be modified locally, preventing remote tampering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the UPS allows all remote commands without filtering, then the ease of operation is improved, but the security is worsened due to vulnerability to malicious commands

Engineering Contradiction:
Improveremote command executionVSAvoidmalicious commands
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments commands into two distinct categories: unrestricted commands and restricted commands. This segmentation is implemented through configuration settings that classify commands based on their security requirements. Unrestricted commands can be executed remotely without additional authentication, while restricted commands require local configuration changes or enhanced authentication. This segmentation resolves the contradiction by allowing easy remote execution of safe commands while blocking malicious attempts at restricted commands.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces configuration settings as an intermediary layer between remote commands and UPS execution. These settings act as a filter that intermediates command processing, determining whether a command should be unrestricted or restricted based on pre-defined security policies. This intermediary mechanism allows the system to maintain ease of operation for legitimate commands while providing security against malicious ones.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If the UPS filters all remote commands, then the security is improved, but the ease of operation is worsened due to restricted access

Engineering Contradiction:
Improvemalicious commandsVSAvoidremote command execution
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

By segmenting commands into unrestricted and restricted categories, the patent avoids the need to filter all commands uniformly. Legitimate unrestricted commands continue to execute remotely without interruption, maintaining ease of operation, while only restricted commands subject to additional security measures. This selective approach resolves the contradiction by applying filtering only where necessary.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security qualities to different commands based on their local characteristics. Some commands are inherently safe and don't require filtering (unrestricted), while others pose security risks and require local configuration changes or enhanced authentication (restricted). This local quality approach ensures that security measures are applied selectively rather than universally, maintaining operational ease for safe commands.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If configuration settings can be modified remotely, then the adaptability is improved, but the security is worsened due to remote tampering

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidremote tampering
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments configuration modification rights between local and remote access. Local access (via hardware switch or local user interface) provides full adaptability to modify any configuration setting, while remote access is restricted to specific non-critical settings or requires enhanced authentication. This segmentation resolves the contradiction by preserving adaptability for local administrators while preventing remote tampering.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary anti-action by requiring local configuration changes before allowing certain remote operations. The hardware switch or local user interface must be configured in a specific state before the UPS will accept certain remote commands. This preliminary security measure prevents remote tampering while still allowing adaptability through local configuration.

Inventive Principle:
Principle #9Preliminary anti-action

4Productivity

If the UPS executes all received commands, then the productivity is improved, but the reliability is worsened due to execution of malicious commands

Engineering Contradiction:
Improvecommand execution speedVSAvoidsystem operation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments command execution into two pathways: unrestricted commands execute immediately without additional verification, maintaining high productivity, while restricted commands require local configuration validation or enhanced authentication before execution. This segmentation allows the system to maintain fast response times for legitimate commands while ensuring reliability through additional checks on potentially harmful commands.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-configuring security policies that classify commands as unrestricted or restricted before execution. This preliminary classification allows the UPS to quickly determine the appropriate execution pathway without adding significant overhead to legitimate commands, while ensuring that restricted commands undergo necessary security validation first.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3416264A1Uninterruptible power supply communication
Publication Date: 2018.12.19 SCHNEIDER ELECTRIC IT CORP
  • EP3416264A1 patent drawingFigure 1
  • EP3416264A1 patent drawingFigure 2
  • EP3416264A1 patent drawingFigure 3

AI summary

According to one aspect, embodiments provide a UPS comprising an input configured to receive input power, a backup input configured to receive backup power from a backup power source, an output configured to provide output power, a communication stack including an external system interface configured to communicate with at least one external device, a local user interface including a switch, the switch having a first position corresponding to a filtering mode and a second position corresponding to a non-filtering mode, the switch being communicatively decoupled from the communication stack, and a controller configured to receive, through the communication stack, commands from an external entity, detect a position of the switch, identify, responsive to detection of the position of the switch corresponding to the filtering mode, that the commands are disallowed commands, and responsive to identifying the disallowed commands, ignore the disallowed commands without executing the disallowed commands.