Airborne system virtual partition secure communication apparatus and method

By introducing a virtual partition security communication device into the airborne system, the communication security risks between virtual partitions with high and low security levels are resolved, the isolation and protection of security levels are achieved, and the secure transmission of data packets between virtual partitions is ensured.

CN119883511BActive Publication Date: 2025-10-21XIAN AVIATION COMPUTING TECH RES INST OF AVIATION IND CORP OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411956975.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-29
Publication Date
2025-10-21
Estimated Expiration
2044-12-29

AI Technical Summary

Technical Problem

In an airborne system, there are security risks in the communication between virtual partitions with high and low security levels. How to ensure that the communication of the low security level virtual partition does not reduce the security level of the high security level virtual partition?

Method used

An airborne system virtual partition security communication device is used, including a virtual partition security communication initialization module, an authentication and identification module, a policy checking module and a transmission module. By generating security tokens, authentication and identification, and access control policy checking, the secure transmission of data packets between virtual partitions is ensured.

Benefits of technology

It realizes secure communication between airborne virtual partitions, prevents low-security-level virtual partitions from reducing the security level of high-security-level virtual partitions, and ensures communication security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119883511B_ABST
    Figure CN119883511B_ABST
Patent Text Reader

Abstract

The on-board system virtual partition security communication device and method of the present application defines an on-board virtual partition security communication device, which comprises a virtual partition security communication initialization module, a virtual partition security token authentication and identification module, a virtual partition security communication strategy checking module, a virtual partition security communication transmission module and a virtual partition security communication interface service module. The on-board virtual partition security token creation and mapping process and the on-board virtual partition data security communication control process are used to realize the security authentication and strong access control of the on-board virtual partition communication, and provide a solution for the on-board virtual partition communication security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of airborne system virtual partitions, and in particular relates to an airborne system virtual partition security communication device and method. Background Art

[0002] With the advancement of information technology and the promotion of digital aviation technology, onboard subsystems such as onboard information systems, maintenance systems, and cabin systems in civil aircraft are moving towards integration. Integrated onboard computing platforms can integrate multiple onboard subsystems into a single computing platform. To improve performance and efficiency, multi-core and virtualization technologies are increasingly being used in onboard systems. Onboard computing platforms now utilize virtual partitioning, which allows different applications to reside in separate virtual partitions and enable data exchange between applications through inter-virtual partition communication. However, due to the varying security levels of applications, communication between high-security and low-security virtual partitions presents security risks. Ensuring communication security so that communication between low-security virtual partitions does not compromise the security of high-security virtual partitions is a key challenge in onboard inter-virtual partition communication. Summary of the Invention

[0003] In view of this, the airborne system virtual partition secure communication device of the present invention solves the problem of lack of secure communication between airborne virtual partitions.

[0004] An airborne system virtual partition security communication device is applicable to an airborne virtual partition computer. The airborne virtual partition computer is equipped with a communication management unit and a virtual partition, including:

[0005] The virtual partition security communication initialization module 101 runs in the communication management unit and is used by the onboard virtual partition computer to create an onboard virtual partition security token, an inter-virtual partition access control policy rule set, and a virtual partition data communication control token during the initialization phase, and to establish a virtual partition and security token mapping table.

[0006] The virtual partition security token authentication and verification module 102 runs in the communication management unit and is used to authenticate the virtual partition identifier of a data packet sent by the onboard virtual partition computer from the virtual partition security communication interface service module 105 in the source virtual partition during the working phase of the onboard virtual partition computer, verify and verify the onboard virtual partition security token, and generate an authentication result.

[0007] Virtual partition security communication policy checking module 103: runs in the communication management unit, and is used to check the virtual partition communication access control policy of the data packet and generate a check result;

[0008] The virtual partition secure communication transmission module 104 runs in the communication management unit, receives the data packet, calls the virtual partition security token authentication module 102 and the virtual partition secure communication policy check module 103 to perform an inspection, and sends the data packet that passes the inspection to the virtual partition secure communication interface service module 105 in the destination virtual partition of the onboard virtual partition computer;

[0009] Virtual partition security communication interface service module 105: runs in the virtual partition, provides a calling interface to the application in the virtual partition of the onboard virtual partition computer, and is responsible for receiving and sending data packets with the virtual partition security communication transmission module 104. It receives data packets that have passed the inspection of the virtual partition security communication transmission module 104 and sends the data packets.

[0010] The technical beneficial effects of the present invention are:

[0011] The virtual partition security communication interface service module and the virtual partition security communication transmission module in the airborne system virtual partition security communication device can solve the security communication interface problem between the virtual partition and the communication management unit.

[0012] The virtual partition security token authentication and identification module and the virtual partition security communication strategy checking module in the airborne system virtual partition security communication device of the method of the present invention can solve the problem of lack of communication security control of communication data packets between virtual partitions. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0014] Figure 1 It is the system composition of the present invention. DETAILED DESCRIPTION

[0015] The embodiments of the present disclosure are described in detail below with reference to the accompanying drawings.

[0016] The following describes the embodiments of the present disclosure through specific examples, and those skilled in the art can easily understand other advantages and effects of the present disclosure from the contents disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all of the embodiments. The present disclosure can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present disclosure. It should be noted that, in the absence of conflict, the following embodiments and features in the embodiments can be combined with each other. Based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present disclosure.

[0017] It should be noted that various aspects of the embodiments within the scope of the appended claims are described below. It should be apparent that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is merely illustrative. Based on this disclosure, it should be understood by those skilled in the art that an aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects described herein can be used to implement an apparatus and / or practice a method. In addition, other structures and / or functionalities other than one or more of the aspects described herein can be used to implement this apparatus and / or practice this method.

[0018] like Figure 1 The airborne system virtual partition security communication device shown is applicable to an airborne virtual partition computer. The airborne virtual partition computer is equipped with a communication management unit and a virtual partition, which includes:

[0019] The virtual partition security communication initialization module 101 runs in the communication management unit and is used by the onboard virtual partition computer to create an onboard virtual partition security token, an inter-virtual partition access control policy rule set, and a virtual partition data communication control token during the initialization phase, and to establish a virtual partition and security token mapping table.

[0020] The virtual partition security token authentication and verification module 102 runs in the communication management unit and is used to authenticate the virtual partition identifier of a data packet during the working phase of the onboard virtual partition computer, verify and verify the onboard virtual partition security token, and generate an authentication result. The data packet is data sent by the onboard virtual partition computer during the working phase from the virtual partition security communication interface service module 105 in the source virtual partition (the sending end of the communication is generally the source end).

[0021] Virtual partition security communication policy checking module 103: runs in the communication management unit, is used to check the virtual partition communication access control policy of the data packet and generate the check result;

[0022] The virtual partition secure communication transmission module 104 runs in the communication management unit, receives data packets, calls the virtual partition security token authentication module 102 and the virtual partition secure communication policy check module 103 to perform checks, and sends the data packets that pass the checks to the virtual partition secure communication interface service module 105 in the destination virtual partition of the onboard virtual partition computer;

[0023] Virtual partition security communication interface service module 105: runs in the virtual partition, provides a calling interface to the application in the virtual partition of the onboard virtual partition computer, and is responsible for receiving and sending data packets with the virtual partition security communication transmission module 104. It receives data packets that have passed the inspection of the virtual partition security communication transmission module 104 and sends data packets.

[0024] Technical effect: The device can ensure the communication security between virtual partitions in an onboard virtual partition computer, so that the communication of low-security-level virtual partitions will not reduce the security level of high-security-level virtual partitions.

[0025] Secondly, a method for secure communication of virtual partitions of an airborne system is provided, which is applicable to an airborne virtual partition computer. The airborne virtual partition computer is equipped with a communication management unit and a virtual partition. The method includes:

[0026] S1: During the initialization phase of the airborne system virtual partition security communication device, the airborne virtual partition security token creation and mapping process is executed. Specifically,

[0027] Step 1.1: The virtual partition security communication initialization module 101 generates a virtual partition security token;

[0028] Step 1.2: The virtual partition security communication initialization module 101 generates an inter-virtual partition access control policy rule set;

[0029] Step 1.3: The virtual partition security communication initialization module 101 generates a virtual partition data communication control token;

[0030] Step 1.4: The virtual partition security communication initialization module 101 uses the virtual partition identifier, virtual partition security token, and virtual partition data communication control token of the onboard virtual partition computer to establish a virtual partition and security token mapping table. Step S1 ends the process.

[0031] S2: During the working phase of the airborne system virtual partition security communication device, the airborne virtual partition data security communication control process is executed. Specifically,

[0032] Step 2.1: The application in the source virtual partition of the onboard virtual partition computer uses the virtual partition secure communication interface service module 105 to send the onboard original data to be sent, where the onboard original data to be sent is the communication data of the application in the source virtual partition;

[0033] Step 2.2: The virtual partition secure communication interface service module 105 packages the onboard virtual partition identifier, the onboard virtual partition security token, and the original data to be sent to form a data packet and sends it to the virtual partition secure communication transmission module 104;

[0034] Step 2.3: The virtual partition security communication transmission module 104 receives the data packet, calls the virtual partition security token authentication and identification module 102 to verify the virtual partition security token in the data packet, and generates an authentication result;

[0035] Step 2.4: The authentication result is determined by the virtual partition security token authentication module 102 to determine whether the authentication result of the onboard virtual partition security token is the same as the comparison result generated in step 1.1. If so, the process proceeds to step 2.5; if not, the process ends.

[0036] Step 2.5: The virtual partition secure communication transmission module 104 calls the virtual partition secure communication policy check module 103 to perform a virtual partition communication access control policy check on the data packet and generate a check result. If the check result is passed, the process proceeds to step 2.6. If the check result is failed, the process ends.

[0037] Step 2.6: The virtual partition secure communication transmission module 104 sends the data packet that has passed the check in step 2.5 to the virtual partition secure communication interface service module 105 of the destination virtual partition (destination reception), and the virtual partition secure communication interface service module 105 of the destination virtual partition sends the data in the data packet to the application (the application at the receiving end), ending the process.

[0038] Operation process

[0039] The present invention defines a method for secure data communication between airborne virtual partitions.

[0040] Step 1: During the device initialization phase, the onboard virtual partition security token creation and mapping process is executed.

[0041] Step 1.1: The virtual partition security communication initialization module 101 generates a virtual partition security token.

[0042] Step 1.2: The virtual partition security communication initialization module 101 generates an inter-virtual partition access control policy rule set.

[0043] Step 1.3: The virtual partition security communication initialization module 101 generates a virtual partition data communication control token.

[0044] Step 1.4: The virtual partition security communication initialization module 101 uses the virtual partition identifier, the virtual partition security token, and the virtual partition data communication control token to establish a virtual partition and security token mapping table, and the process ends.

[0045] Step 2: During the device working phase, execute the data security communication control process between the onboard virtual partitions.

[0046] Step 2.1: The application in the source virtual partition uses the virtual partition secure communication interface service module 105 to send data.

[0047] Step 2.2: The virtual partition secure communication interface service module 105 packages the virtual partition identifier, the virtual partition security token and the data and sends them to the virtual partition secure communication transmission module 104 .

[0048] Step 2.3: The virtual partition secure communication transmission module 104 receives the data packet sent by the virtual partition secure communication interface service module 105 and calls the virtual partition security token authentication and verification module 102 to verify the virtual partition security token in the data packet.

[0049] Step 2.4: The virtual partition security token authentication and identification module 102 authenticates the virtual partition identifier and verifies and identifies the virtual partition security token. If the authentication passes, step 2.5 is executed; otherwise, the process ends.

[0050] Step 2.5: The virtual partition secure communication transmission module 104 calls the virtual partition secure communication policy checking module 103 to perform a virtual partition communication access control policy check on the data packet. If the check passes, step 2.6 is executed, otherwise the process ends.

[0051] Step 2.6: The virtual partition secure communication transmission module 104 sends the data packet to the virtual partition secure communication interface service module 105 of the destination virtual partition.

[0052] Step 2.7: The virtual partition secure communication interface service module 105 of the destination virtual partition sends the data in the data packet to the application, and the process ends.

[0053] The secure authentication and strong access control of airborne virtual partition communication are achieved by using the airborne virtual partition security token creation and mapping process and the airborne virtual partition data secure communication control process. The above method provides a solution for the secure communication between airborne virtual partitions.

[0054] The above are only specific embodiments of the present disclosure, but the scope of protection of the present disclosure is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this disclosure should be included in the scope of protection of the present disclosure. Therefore, the scope of protection of the present disclosure should be based on the scope of protection of the claims.

Claims

1. An onboard system virtual partition security communication device, suitable for an onboard virtual partition computer, wherein the onboard virtual partition computer is equipped with a communication management unit and a virtual partition, characterized in that: include, The virtual partition security communication initialization module 101 runs in the communication management unit and is used by the onboard virtual partition computer to create an onboard virtual partition security token, an inter-virtual partition access control policy rule set, and a virtual partition data communication control token during the initialization phase, and to establish a virtual partition and security token mapping table. The virtual partition security token authentication and verification module 102 runs in the communication management unit and is used to authenticate the virtual partition identifier of a data packet sent by the onboard virtual partition computer from the virtual partition security communication interface service module 105 in the source virtual partition during the working phase of the onboard virtual partition computer, verify and verify the onboard virtual partition security token, and generate an authentication result. Virtual partition security communication policy checking module 103: runs in the communication management unit, and is used to check the virtual partition communication access control policy of the data packet and generate a check result; The virtual partition secure communication transmission module 104 runs in the communication management unit, receives the data packet, calls the virtual partition security token authentication module 102 and the virtual partition secure communication policy check module 103 to perform an inspection, and sends the data packet that passes the inspection to the virtual partition secure communication interface service module 105 in the destination virtual partition of the onboard virtual partition computer; Virtual partition security communication interface service module 105: runs in the virtual partition, provides a calling interface to the application in the virtual partition of the onboard virtual partition computer, and is responsible for receiving and sending data packets with the virtual partition security communication transmission module 104. It receives data packets that have passed the inspection of the virtual partition security communication transmission module 104 and sends the data packets.

2. A method for secure communication of virtual partitions of an airborne system, using the airborne system virtual partition secure communication device according to claim 1, applicable to an airborne virtual partition computer, wherein the airborne virtual partition computer is equipped with a communication management unit and a virtual partition, characterized in that: The methods include, S1: During the initialization phase of the airborne system virtual partition security communication device, executing an airborne virtual partition security token creation and mapping process; S2: During the working phase of the airborne system virtual partition security communication device, a data security communication control process between airborne virtual partitions is executed.

3. The airborne system virtual partition secure communication method according to claim 2, characterized in that: S1 includes: Step 1.1: the virtual partition security communication initialization module 101 generates the virtual partition security token; Step 1.2: the virtual partition security communication initialization module 101 generates the inter-virtual partition access control policy rule set; Step 1.3: The virtual partition secure communication initialization module 101 generates the virtual partition data communication control token; Step 1.4: The virtual partition security communication initialization module 101 uses the virtual partition identifier of the onboard virtual partition computer and the virtual partition security token and virtual partition data communication control token to establish a virtual partition and security token mapping table. Step S1 ends the process.

4. The airborne system virtual partition secure communication method according to claim 3, characterized in that: S2 includes Step 2.1: The application in the source virtual partition of the onboard virtual partition computer uses the virtual partition secure communication interface service module 105 to send the onboard original data to be sent, where the onboard original data to be sent is the communication data of the application in the source virtual partition; Step 2.2: The virtual partition secure communication interface service module 105 packages the onboard virtual partition identifier, the onboard virtual partition security token and the original data to be sent to form the data packet and sends it to the virtual partition secure communication transmission module 104; Step 2.3: The virtual partition secure communication transmission module 104 receives the data packet, calls the virtual partition security token authentication and identification module 102 to verify the virtual partition security token in the data packet, and generates an authentication result; Step 2.4: The authentication result is judged by the virtual partition security token authentication and authentication module 102 to determine whether the authentication result of the onboard virtual partition security token is the same as the comparison result generated in step 1.

1. If so, proceed to step 2.5; if not, the process ends.

5. The airborne system virtual partition secure communication method according to claim 4, characterized in that: S2 also includes, Step 2.5: The virtual partition secure communication transmission module 104 calls the virtual partition secure communication policy check module 103 to perform a virtual partition communication access control policy check on the data packet and generate a check result. If the check result is passed, the process proceeds to step 2.

6. If the check result is failed, the process ends. Step 2.6: The virtual partition secure communication transmission module 104 sends the data packet that passes the check in step 2.5 to the virtual partition secure communication interface service module 105 of the destination virtual partition, and the virtual partition secure communication interface service module 105 of the destination virtual partition sends the data in the data packet to the application, ending the process.

Citation Information

Patent Citations

  • Virtualization authority control communication method based on partition operating system

    CN113157402A

  • Internal and external network embedded self-adaptive rapid information interaction physical security architecture system

    CN115098340A