UPS Controller Command Segmentation and Local Switch Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Uninterruptible power supplies (UPS) are vulnerable to malicious commands from unauthorized sources, which can compromise their operation and security, particularly in configurations where remote access is allowed without adequate filtering or authentication.
Innovation Solution
A UPS system that includes a controller to differentiate between unrestricted and restricted commands based on configuration settings, with the ability to filter and discard unauthorized commands, and an out-of-band switch to ensure that configuration settings can only be modified locally, preventing remote tampering.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the UPS allows all remote commands without filtering, then the ease of operation is improved, but the security is worsened due to vulnerability to malicious commands
Solution Approach 1:
The patent segments commands into two distinct categories: unrestricted commands and restricted commands. This segmentation is implemented through configuration settings that classify commands based on their security requirements. Unrestricted commands can be executed remotely without additional authentication, while restricted commands require local configuration changes or enhanced authentication. This segmentation resolves the contradiction by allowing easy remote execution of safe commands while blocking malicious attempts at restricted commands.
Solution Approach 2:
The patent introduces configuration settings as an intermediary layer between remote commands and UPS execution. These settings act as a filter that intermediates command processing, determining whether a command should be unrestricted or restricted based on pre-defined security policies. This intermediary mechanism allows the system to maintain ease of operation for legitimate commands while providing security against malicious ones.
2Object-affected harmful factors
If the UPS filters all remote commands, then the security is improved, but the ease of operation is worsened due to restricted access
Solution Approach 1:
By segmenting commands into unrestricted and restricted categories, the patent avoids the need to filter all commands uniformly. Legitimate unrestricted commands continue to execute remotely without interruption, maintaining ease of operation, while only restricted commands subject to additional security measures. This selective approach resolves the contradiction by applying filtering only where necessary.
Solution Approach 2:
The patent applies different security qualities to different commands based on their local characteristics. Some commands are inherently safe and don't require filtering (unrestricted), while others pose security risks and require local configuration changes or enhanced authentication (restricted). This local quality approach ensures that security measures are applied selectively rather than universally, maintaining operational ease for safe commands.
3Adaptability or versatility
If configuration settings can be modified remotely, then the adaptability is improved, but the security is worsened due to remote tampering
Solution Approach 1:
The patent segments configuration modification rights between local and remote access. Local access (via hardware switch or local user interface) provides full adaptability to modify any configuration setting, while remote access is restricted to specific non-critical settings or requires enhanced authentication. This segmentation resolves the contradiction by preserving adaptability for local administrators while preventing remote tampering.
Solution Approach 2:
The patent implements preliminary anti-action by requiring local configuration changes before allowing certain remote operations. The hardware switch or local user interface must be configured in a specific state before the UPS will accept certain remote commands. This preliminary security measure prevents remote tampering while still allowing adaptability through local configuration.
4Productivity
If the UPS executes all received commands, then the productivity is improved, but the reliability is worsened due to execution of malicious commands
Solution Approach 1:
The patent segments command execution into two pathways: unrestricted commands execute immediately without additional verification, maintaining high productivity, while restricted commands require local configuration validation or enhanced authentication before execution. This segmentation allows the system to maintain fast response times for legitimate commands while ensuring reliability through additional checks on potentially harmful commands.
Solution Approach 2:
The patent implements preliminary action by pre-configuring security policies that classify commands as unrestricted or restricted before execution. This preliminary classification allows the UPS to quickly determine the appropriate execution pathway without adding significant overhead to legitimate commands, while ensuring that restricted commands undergo necessary security validation first.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
According to one aspect, embodiments provide a UPS comprising an input configured to receive input power, a backup input configured to receive backup power from a backup power source, an output configured to provide output power, a communication stack including an external system interface configured to communicate with at least one external device, a local user interface including a switch, the switch having a first position corresponding to a filtering mode and a second position corresponding to a non-filtering mode, the switch being communicatively decoupled from the communication stack, and a controller configured to receive, through the communication stack, commands from an external entity, detect a position of the switch, identify, responsive to detection of the position of the switch corresponding to the filtering mode, that the commands are disallowed commands, and responsive to identifying the disallowed commands, ignore the disallowed commands without executing the disallowed commands.