Filter device and method for communication between trusted and untrusted domains and computer system
Through a modular method and hardware/software collaborative design, combined with hardware programmable devices and general CPU, a secure communication filter device between a trusted domain and an untrusted domain in the aircraft is realized, solving the problem of insufficient flexibility and simplicity of secure communication in the prior art, and achieving high-performance and low-latency secure communication effect.
Patent Information
- Application Number
- CN202411727483.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-11-29
- Filing Date
- 2024-11-28
- Publication Date
- 2025-05-30
AI Technical Summary
The prior art is difficult to achieve the flexibility and simplicity of secure communication in aircraft, especially under the requirements of high safety assurance levels.
A modular method is used to combine hardware/software collaborative design, and a communication filter device between a trusted domain and an untrusted domain is realized through a combination of hardware programmable devices (such as FPGAs) and a general-purpose CPU. The device includes a chain of hardware and software filters that classify and filter data through demultiplexers and multiplexers, providing a high-performance, low-latency secure communication solution.
It realizes high-performance, low-latency secure communication, improves the flexibility and scalability of the system, and can effectively protect critical systems in the aircraft from attacks.
Smart Images

Figure CN120068172A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a filter device and method for communication between a trusted domain and an untrusted domain, and a computer system for an aircraft including the filter device. Background Art
[0002] In information technology, for example, based on corresponding implementations of the Linux operating system kernel including the Netfilter stack or the BSD / OS Unix operating system, firewall and gateway functions are typically implemented as software functions. These measures have the advantage of wide use. However, due to the safety requirements of an aircraft, such as a high level of safety assurance requiring detailed evidence of the correctness of all parts of the barrier, an embedded solution customized for the needs of such applications is preferred.
[0003] Therefore, the problem of the present invention is to provide a device with improved flexibility and simplicity for secure communication. Summary of the Invention
[0004] According to the present invention, the problem is solved in each case by an embodiment of the present disclosure.
[0005] According to a first aspect of the present invention, there is provided a filter device for communication between a trusted domain and an untrusted domain. The filter device includes: a central processing unit CPU and a hardware programmable device connected to the CPU. The hardware programmable device includes: a first input / output I / O interface connected to the untrusted domain and a second I / O interface connected to the trusted domain. Wherein, the first I / O interface and the second I / O interface are configured to receive data frames from the corresponding untrusted domain and trusted domain and transmit the data frames to the corresponding untrusted domain and trusted domain. A first filter channel configured to filter a first data frame received from the first I / O interface and provide the first filtered data frame to the second I / O interface, and a second filter channel configured to filter a second data frame received from the second I / O interface and provide the second filtered data frame to the first I / O interface; wherein each of the first filter channel and the second filter channel includes: at least two filter chains selected from a hardware filter chain and / or a software filter chain. The hardware filter chain and the software filter chain include hardware filter circuitry, and the software filter chain includes software filter circuitry connected to the CPU. A demultiplexer configured to receive the corresponding first data frame and second data frame from the corresponding first I / O interface and second I / O interface, classify the data streams of the corresponding first data frame and second data frame according to at least one attribute, and input the data streams into the hardware filter chain and the software filter chain according to their classification to provide filtered data streams. A multiplexer configured to combine the filtered data streams from the hardware filter chain and the software filter chain to provide the corresponding first filtered data frame and second filtered data frame, and transmit the first filtered data frame and the second filtered data frame to the corresponding second I / O interface and first I / O interface.
[0006] According to a second aspect of the present invention, there is provided a method for communication between an untrusted domain and a trusted domain. The method includes: receiving a data frame by an input / output I / O interface from one of a trusted domain and an untrusted domain, classifying the received data frame by a demultiplexer according to at least one attribute to provide a classified data stream, inputting the classified data stream into at least two filter chains selected from a hardware filter chain and / or a software filter chain according to its classification. The hardware filter chain and the software filter chain include hardware filter circuitry on a hardware programmable device, and wherein the software filter chain includes software filter circuitry connected to a central processing unit CPU. Filtering the classified data stream by the hardware filter circuitry and the software filter circuitry to provide a filtered data stream, combining the filtered data streams from the hardware filter chain and the software filter chain by a multiplexer to provide a filtered data frame, and transmitting the filtered data frame to the other of the trusted domain and the untrusted domain.
[0007] According to a third aspect of the present invention, a computer system is provided. The computer system includes a trusted domain, an untrusted domain, and a filter device of the present invention connected to the trusted domain and the untrusted domain of the computer system.
[0008] The basic concept of the present invention is: to implement a barrier in a modular way; to identify the required modules; and to select whether it is best to implement each module by means of a (programmable) hardware device or a software device such as a hardware filter or a software filter.
[0009] The present invention employs a combination of a general-purpose central processing unit (CPU) running a software filter and a programmable hardware (custom) device (such as a field-programmable gate array FPGA). These two parts, the CPU (i.e., software) and the hardware programmable device (such as an FPGA), are connected by a data interface that is fast enough.
[0010] Through the application of a modular approach and hardware / software co-design, the solution can be observed by each modular component or block, can be extended by modular blocks, and additional blocks can be added. The filter device provides a high-performance, low-latency hardware-based implementation.
[0011] A particular advantage of the solution according to one aspect of the present invention is the implementation of some of the modules by means of an FPGA / programmable hardware. In long-term large projects, not all future requirements are known a priori. The combination of FPGA / programmable hardware and software provides the advantage of in-field loadability, i.e., replacing programmable hardware blocks in the field. This combines flexibility with performance and scalability.
[0012] Therefore, the filter device of the present invention is an implementation of an Ethernet frame checker, filter, and translator, which performs correctness checks on incoming and outgoing data containing data frames.
[0013] The filter device classifies data frames into so-called "flows" based on properties such as frame attributes. Then, the filter device performs filtering, such as rate limiting and starvation protection for each flow and in-depth analysis of the frame content of the flow. The filter device of the present invention can also be configured to rewrite the flow content with non-uniform translation ("protocol violation"), perform state checks and filtering by considering incoming traffic and outgoing traffic, and perform checks and filtering based on conditions controlled from the security side. The filter device can be observed by means of statistics and event counters for each flow.
[0014] The computer system is preferably an aircraft management system on an aircraft or a part of an aircraft management system. In this case, key parts of the aircraft management system (such as parts related to the navigation of the aircraft) can be located in the trusted domain and require protection by the filter device against attacks.
[0015] Advantageous embodiments and further developments emerge from the description with reference to the drawings.
[0016] According to some aspects of the filter device according to the invention, each of the hardware filter circuit systems includes a flow filter and a rate limiter configured to limit the data rate of the data stream. The flow filter implements a protocol-specific state machine that can examine individual frames based on data collected while iterating over a single frame. A pass / fail decision is ultimately made by these state machines. In the event of a "pass" decision, some frames are directly forwarded according to the connection, while for other flows, the frames are placed in a buffer memory such as a FIFO buffer for further examination by a software translator and a software checker. The rate limiter ensures that for a specific flow, an overload attack such as a denial-of-service attack can be blocked and the security side is not overloaded.
[0017] According to some further aspects of the filter device according to the invention, the hardware filter circuit systems of the software filter chains and the hardware filter chains of the first filter channel and the second filter channel are identical. In this way, the filter circuit systems can be implemented as modules such that these modules are interchangeable between the first filter channel and the second filter channel. This also allows for additional filter channels when these modules are needed due to, for example, new requirements in an aircraft.
[0018] According to some further aspects of the filter device according to the invention, the software filter circuit system is arranged downstream of the hardware filter circuit system in the software filter chain. In this way, the data signal can first be filtered by the hardware filter circuit system, thereby removing potential threats to the software and the CPU before being filtered by the CPU. In this way, the security that the filter device can provide is improved.
[0019] In accordance with some additional aspects of the filter device according to the present invention, the first filter channel and / or the second filter channel include a plurality of hardware filter chains and / or a plurality of software filter chains coupled between respective demultiplexers and multiplexers, wherein the respective demultiplexers and multiplexers are configured to classify received data frames according to at least one attribute, input the classified data stream of the data frames into one of the respective plurality of hardware filter chains and / or the plurality of software filter chains according to their classification, and combine the filtered data streams to provide a first filtered frame and a second filtered frame. The first filter channel and the second filter channel may include different numbers of hardware filter chains and software filter chains. For example, the first filter chain and the second filter chain may include two software filter chains without including hardware filter chains, or three software filter chains and five hardware filter chains. Additional combinations may be contemplated. In this way, the flexibility of the filter device is improved because the filter device can provide more filter channels to filter specific potential threats.
[0020] In accordance with some additional aspects of the filter device according to the present invention, the I / O interface is configured as a Media Access Control (MAC) interface. The MAC interface is the physical layer of Ethernet for transmitting and receiving frames. The MAC interface includes a checker for basic parameters of the incoming frame such as size and the correctness of the frame checksum. This is done prior to flow classification to avoid decisions based on corrupted frame data.
[0021] In accordance with some additional aspects of the filter device according to the present invention, the CPU includes a translator and a checker software block, which are connected to the software filter circuitry and are configured to check the status of data received from the software filter circuitry, and receive pre-filtered data from the software filter chain and translate between different protocols of the received data. The checker can deduce the stateful behavior within and between data streams and even between the incoming direction and the outgoing direction. Thus, the checker improves the ability of the software filter circuitry to filter potentially insecure data. The translator is an additional security advantage for terminating the incoming protocol on the untrusted side of the barrier and continuing the flow using another protocol.
[0022] In accordance with some additional aspects of the filter device according to the present invention, the CPU includes a control and monitoring software block, which is configured to communicate only with a second I / O interface of the programmable hardware that is connected to the trusted domain. Through this control and monitoring software block, the programmable hardware can be reprogrammed securely. Thus, monitoring and configuration are not exposed to the unsecure side - i.e., the untrusted domain - to prevent attacks on the barrier itself.
[0023] According to some further aspects of the filter device according to the invention, the software filter circuitry is configured as a buffer memory, in particular a FIFO buffer, for data exchange with a software unit. In this way, data signals can be stored and retrieved by the CPU when needed.
[0024] The above-described embodiments and further developments can be combined with each other as needed, where useful. In particular, all features of the filter device can be transferred to a method for assembling a display device, and all features of the method for assembling a display device can be transferred to the filter device. Further possible embodiments, further developments, and implementations of the invention also include combinations of features of the invention not explicitly mentioned previously or below in connection with the embodiments. In particular, the person skilled in the art will thereby also add individual aspects as improvements or additions to the respective basic forms of the invention. Description of the Drawings
[0025] The invention will be explained in more detail below based on exemplary embodiments indicated in the schematic drawings, in which:
[0026] Figure 1 A schematic diagram of a filter device for communication between a trusted domain and an untrusted domain according to an embodiment of the invention is shown;
[0027] Figure 2 A schematic diagram of a filter device for communication between a trusted domain and an untrusted domain according to a further embodiment of the invention is shown;
[0028] Figure 3 A schematic diagram of a computer system for an aircraft according to an embodiment of the invention is shown; and
[0029] Figure 4 A flowchart of a method for communication between a trusted domain and an untrusted domain according to a further embodiment of the invention is shown.
[0030] In the drawings, unless otherwise stated, elements, features, and components that are the same, have the same function, and have the same effect are each provided with the same reference numerals. Detailed Description of the Embodiments
[0031] Figure 1 A schematic diagram of a filter device 1 for communication between a trusted domain 4 and an untrusted domain 5 according to an embodiment of the invention is shown.
[0032] The filter device 1 includes a central processing unit CPU 2. Thus, the CPU represents a general software block that can be freely programmed by software. A typically commercially available CPU can be used for this task.
[0033] The filter device further includes a hardware programmable device 3 connected to the CPU 2. In some embodiments, the hardware programmable device is configured as a field programmable gate array FPGA. Thus, the filter device 1 includes a combination of a general-purpose CPU for running software filters and a programmable hardware customization device. The two parts, the CPU 2 (i.e., the software) and the programmable hardware device 3 (e.g., FPGA), are connected by a data interface fast enough.
[0034] The hardware programmable device 3 includes a first input / output I / O interface 6a connected to the untrusted domain 5. The hardware programmable device 3 also includes a second I / O interface 6b connected to the trusted domain 4. The first I / O interface 6a is configured to receive data frames from the untrusted domain 5 and transmit data frames to it. The second I / O interface 6b is configured to receive data frames from the trusted domain 4 and transmit data frames to it.
[0035] In a preferred embodiment, the first I / O interface 6a and the second I / O interface 6b are configured as media access control MAC interfaces. The MAC interface is the physical layer of Ethernet for sending and receiving frames. As described above, the MAC interface includes a checker for basic parameters of the incoming frame such as size and the correctness of the frame checksum. A data frame typically includes a frame synchronization feature consisting of a series of bits or symbols, which indicates to the receiver the start and end of the payload data within the symbol stream or bit stream received by the receiver.
[0036] The hardware programmable device 3 also includes a first filter channel 7a, which is configured to filter the first data frame received from the first I / O interface 6a and provide the first filtered data frame to the second I / O interface 6b. The hardware programmable device 3 also includes a second filter channel 7b, which is configured to filter the second data frame received from the second I / O interface 6b and provide the second filtered data frame to the first I / O interface 6a.
[0037] Each of the first filter channel 7a and the second filter channel 7b includes a hardware filter chain 8 and a software filter chain 9. The hardware filter chain 8 and the software filter chain 9 include hardware filter circuitry 10, and the software filter chain 9 includes software filter circuitry 11 connected to the CPU 2. In Figure 1 the illustrated embodiment, the software filter circuitry 11 is arranged downstream of the hardware filter circuitry 10 in the software filter chain 9. In this way, the data signal can be first filtered by the hardware filter circuitry, thereby removing potential threats to the software and the CPU before being filtered by the CPU. In this way, the security is improved.
[0038] Each of the first filter channel 7a and the second filter channel 7b further includes a demultiplexer 12, which is configured to receive a corresponding first data frame and a second data frame from the corresponding first I / O interface 6a and the second I / O interface 6b, classify the data streams of the corresponding first data frame and the second data frame according to at least one attribute, and input the data streams into the hardware filter chain 8 and the software filter chain 9 according to their classification to provide filtered data streams. Thus, the demultiplexer 12 checks frame fields as attributes (such as source address and destination address, frame type, VLAN tag, IP address, UDP port), and distributes the matching frames to each corresponding flow filter chain. The flow separator can perform a masked comparison of the frame fields. The demultiplexer 12 can also discard non-matching frames.
[0039] In Figure 1 In the illustrated embodiment, the hardware filter circuitry 10 of the software filter chain 9 of the first filter channel 7a and the second filter channel 7b is the same as the hardware filter circuitry 10 of the hardware filter chain 8 of the first filter channel 7a and the second filter channel 7b. In this way, the hardware filter circuitry 10 and the software filter circuitry 11 can be implemented as modules such that these modules are interchangeable between the first filter channel and the second filter channel. This also allows for additional filter channels when these modules are needed due to, for example, new requirements in an aircraft.
[0040] Each of the first filter channel 7a and the second filter channel 7b further includes a multiplexer 13, which is configured to combine the filtered data streams from the hardware filter chain 8 and the software filter chain 9 to provide a corresponding first filtered data frame and a second filtered data frame, and transmit the first filtered data frame and the second filtered data frame to the corresponding second I / O interface 6b and the first I / O interface 6a. The multiplexer 13 is the corresponding device of the demultiplexer 12. It is necessary to determine the order in which the accepted filtered frames can leave the barrier. The multiplexer 13 can also perform prioritization among the filter channels 7a, 7b or the flow filter chains running in parallel. This effectively performs the prioritization of flows in the traffic, and the combination with the rate limiting block also prevents starvation of the flows.
[0041] Figure 2 A schematic diagram of a filter device 1 for communication between a trusted domain 4 and an untrusted domain 5 according to a further embodiment of the present invention is shown.
[0042] Figure 2 The illustrated embodiment of the filter device 1 is based on the filter device 1 described above and Figure 1 the illustrated filter device 1.
[0043] The first filter channel 7a and the second filter channel 7b include at least two filter chains selected from among a plurality of hardware filter chains 8a to 8c and / or a plurality of software filter chains 9a to 9c coupled between the respective demultiplexer 12 and multiplexer 13. In this embodiment, each of the first filter channel 7a and the second filter channel 7b includes six filter chains, namely three hardware filter chains 8 and three software filter chains 9. In additional embodiments, the first filter channel 7a and the second filter channel 7b include different numbers of hardware filter chains 8 and software filter chains 9. In some embodiments, the first filter channel 7a and the second filter channel 7b include two software filter chains 9 and no hardware filter chains 8, or the first filter channel 7a and the second filter channel 7b include three software filter chains 9 and five hardware filter chains 8. Other combinations of n software filter chains 9 and n hardware filter chains 8 are also contemplated.
[0044] The respective demultiplexer 12 and multiplexer 13 are configured to classify received data frames according to at least one attribute, input the classified data stream of the data frames into one of the respective plurality of hardware filter chains 8a to 8c and / or a plurality of software filter chains 9a to 9c according to their classification, and combine the filtered data streams to provide a first filtered frame and a second filtered frame.
[0045] The software filter circuitry 11 is configured as a buffer memory 111 for data exchange with the CPU 2, in particular a FIFO buffer. The buffer memory 111 is capable of storing data streams such that these data streams can be retrieved by the CPU when needed.
[0046] In Figure 2 embodiments, each of the hardware filter circuitries 10 includes a flow filter 101. The hardware filter circuitries 10 further include a rate limiter 102 positioned upstream of the flow filter 101. The flow filter 101 generally implements a protocol-specific state machine that can examine individual frames based on data collected while iterating over a single frame. The pass / fail decisions are ultimately made by these state machines. In the event of a "pass" decision, some frames are directly forwarded according to the connection, while for other flows, the frames are placed in a buffer memory 111 such as a FIFO buffer for further examination by a software translator and a software checker. The rate limiter 102 is configured to limit the data rate of the data stream. The rate limiter 102 ensures that for a particular flow, an overload attack such as a denial of service can be blocked and the security side is not overloaded.
[0047] In Figure 2In an embodiment of the filter device 1 shown, the CPU 2 includes translator and checker software blocks 21a, 21b, which are connected to the software filter circuitry 11 and are configured to check the status of data received from the software filter circuitry and to receive pre-filtered data from the software filter chain and translate between different protocols of the received data.
[0048] The CPU 2 further includes a control and monitoring software block 20, which is configured to communicate only with a second I / O interface 6b of the programmable hardware 3 that is connected to the trusted domain 4. The control and monitoring software block 20 is also capable of reprogramming the circuitry in the hardware programmable device. To this end, the control and monitoring software block 20 communicates only with the secure side of the I / O interface 6b. In this way, monitoring and configuration are not exposed to the insecure side, i.e., the untrusted domain 5, to prevent attacks on the barrier itself.
[0049] Figure 2 Also shown is a physical Ethernet attachment 30 of the aircraft management system 100, which is respectively connected to the first I / O interface and the second I / O interface. Accordingly, incoming data frames as well as filtered data frames are sent by Ethernet via the physical Ethernet attachment 30.
[0050] Figure 3 A schematic diagram of a computer system for an aircraft according to an embodiment of the present invention is shown.
[0051] Figure 3 The computer system 100 shown includes a trusted domain 4, an untrusted domain 5, and a filter device 1 according to an embodiment of the present invention. The filter device 1 is connected to the trusted domain 4 and the untrusted domain 5 for data exchange. In a preferred embodiment, the computer system 100 is integrated in an aircraft. In a preferred embodiment, the computer system 100 is at least part of an aircraft management system on the aircraft and is integrated in the aircraft.
[0052] Figure 4 A flowchart of a method for communication between a trusted domain and an untrusted domain according to a further embodiment of the present invention is shown.
[0053] A method for communication between a trusted domain 4 and an untrusted domain 5 includes the following steps: receiving an S1 data frame by an input / output I / O interface 6a, 6b from one of the trusted domain 4 and the untrusted domain 5. Then, classifying S2 the received data frame by a demultiplexer 12 according to at least one attribute to provide a classified data stream. Inputting S3 the classified data stream into a hardware filter chain 8 and a software filter chain 9 according to its classification. The hardware filter chain 8 and the software filter chain 9 include hardware filter circuitry 10 on a hardware programmable device 3. The software filter chain 9 further includes software filter circuitry 11 connected to a central processing unit CPU 2. In addition, filtering S4 the classified data stream by the hardware filter circuitry 10 and the software filter circuitry 11 to provide a filtered data stream. Combining S5 the filtered data streams from the hardware filter chain 8 and the software filter chain 9 by a multiplexer 13 to provide a filtered data frame. In an additional step, transmitting S6 the filtered data frame to the other of the trusted domain 4 and the untrusted domain 5.
[0054] In the foregoing detailed description, various features have been combined in one or more examples to enhance the rigor of the illustration. However, it should be clear in this case that the foregoing description is merely illustrative and in no way restrictive. It is intended to cover all alternatives, modifications, and equivalents of the various features and exemplary embodiments. Given the foregoing description, many other examples will be immediately and directly apparent to those skilled in the art based on their knowledge of the art.
[0055] Exemplary embodiments have been selected and described so as to best present the basic principles of the invention and its possible applications in practice. Thus, those skilled in the art can modify and utilize the invention and its various exemplary embodiments in the best possible manner for the intended purpose. In the claims and the specification, the terms "comprising" and "having" are used as neutral language concepts corresponding to the term "including". In addition, the use of the terms "a", "an", and "one" should not, in principle, exclude a plurality of features and components described in this way.
[0056] Although at least one exemplary embodiment of the present invention is disclosed herein, it should be understood that modifications, alternatives, and substitutions may be apparent to those of ordinary skill in the art and can be made without departing from the scope of the present disclosure. The present disclosure is intended to cover any adaptation or variation of the exemplary embodiments. Additionally, in the present disclosure, the terms "comprising" or "include" do not exclude other elements or steps, the term "a" or "an" does not exclude a plurality, and the term "or" means one or both. Furthermore, unless the present disclosure or the context otherwise indicates, the features or steps that have been described may also be used in combination with other features or steps and can be used in any order. The present disclosure hereby incorporates by reference the entire disclosure of any patent or application for which the present disclosure claims the benefit or priority.
[0057] List of Reference Numerals
[0058] 1 Filter device
[0059] 2 Central processing unit CPU
[0060] 3 Hardware programmable device
[0061] 4 Trusted domain
[0062] 5 Untrusted domain
[0063] 6a, 6b Input / output I / O interface
[0064] 7a, 7b Filter channel
[0065] 8, 8a to 8c Hardware filter chain
[0066] 9, 9a to 9c Software filter chain
[0067] 10 Hardware filter circuitry
[0068] 11 Software filter circuitry
[0069] 20 Control and monitoring software block
[0070] 21a, 21b Translator and checker software block
[0071] 30 Physical Ethernet attachment
[0072] 100 Computer system
[0073] 101 Flow filter
[0074] 102 Rate limiter
[0075] 111 Buffer memory
Claims
1. A filter device (1) for communication between a trusted domain (4) and an untrusted domain (5), comprising: a central processing unit CPU (2), and A hardware programmable device (3) connected to the CPU (2), the hardware programmable device (3) comprising: a first input / output I / O interface (6a) connected to the untrusted domain (5) and a second I / O interface (6b) connected to the trusted domain (4), wherein the first I / O interface and the second I / O interface (6a, 6b) are configured to receive data frames from the corresponding untrusted domain and the trusted domain (4, 5) and transmit data frames to the corresponding untrusted domain and the trusted domain (4, 5), a first filter channel (7a) configured to filter a first data frame received from the first I / O interface (6a) and provide a first filtered data frame to the second I / O interface (6b), and a second filter channel (7b) configured to filter a second data frame received from the second I / O interface (6b) and provide the second filtered data frame to the first I / O interface (6a); Wherein each of the first filter channel and the second filter channel (7a, 7b) comprises: at least two filter chains selected from a hardware filter chain (8) and / or a software filter chain (9), wherein the hardware filter chain (8) and the software filter chain (9) comprise hardware filter circuitry (10) and the software filter chain (9) comprises software filter circuitry (11) connected to the CPU (2), a demultiplexer (12) configured to receive corresponding first and second data frames from corresponding first and second I / O interfaces (6a, 6b), classify data streams of the corresponding first and second data frames according to at least one attribute, and inputting the data stream into the hardware filter chain (8) and the software filter chain (9) according to its classification to provide a filtered data stream, A multiplexer (13) configured to combine the filtered data streams from the hardware filter chain (8) and the software filter chain (9) to provide corresponding first filtered data frames and second filtered data frames, and to transmit the first filtered data frames and the second filtered data frames to the corresponding second I / O interface and first I / O interface (6a, 6b).
2. The filter device (1) according to claim 1, wherein: Each of the hardware filter circuit systems (10) includes a stream filter (101) and a rate limiter (102), the rate limiter (102) being configured to limit the data rate of the data stream.
3. The filter device (1) according to claim 1 or 2, wherein: The software filter chain (9) of the first filter channel and the second filter channel (7a, 7b) and the hardware filter circuitry (10) of the hardware filter chain (8) are identical.
4. The filter device (1) according to any one of the preceding claims, wherein: The software filter circuitry (11) is arranged downstream of the hardware filter circuitry (10) in the software filter chain (9).
5. The filter device (1) according to any one of the preceding claims, wherein: The first filter channel (7a) and / or the second filter channel (7b) include a plurality of hardware filter chains (8a to 8c) and / or a plurality of software filter chains (9a to 9c) coupled between a corresponding demultiplexer (12) and a multiplexer (13), wherein the corresponding demultiplexer (12) and the multiplexer (13) are configured to: classify a received data frame according to at least one attribute, input the classified data stream of the data frame into one of the corresponding plurality of hardware filter chains (8a to 8c) and / or a plurality of software filter chains (9a to 9c) according to its classification, and combine the filtered data streams to provide a first filtered frame and a second filtered frame.
6. The filter device (1) according to any one of the preceding claims, wherein: The I / O interface (6a, 6b) is configured as a Media Access Control MAC interface.
7. The filter device (1) according to any one of the preceding claims, wherein: The CPU (2) comprises: a translator and checker software block (21a, 21b) connected to the software filter circuit system (11) and configured to check the status of data received from the software filter circuit system, and to receive pre-filtered data from the software filter chain (9) and translate between different protocols of the received data.
8. The filter device (1) according to any one of the preceding claims, wherein: The CPU (2) comprises a control and monitoring software block (20) configured to communicate only with the second I / O interface (6b) of the programmable hardware device (3) connected to the trusted domain (4).
9. The filter device (1) according to any one of the preceding claims, wherein: The software filter circuit system (11) is configured as a buffer memory (111), in particular a FIFO buffer, for exchanging data with the CPU (2).
10. A computer system (100) for an aircraft, comprising a trusted domain (4), an untrusted domain (5) and a filter device (1) according to any one of the preceding claims connected to the trusted domain (4) and the untrusted domain (5) of the aircraft.
11. A method for communication between a trusted domain (4) and an untrusted domain (5), comprising: - receiving (S1) a data frame from one of the trusted domain (4) and the untrusted domain (5) by an input / output I / O interface (6a, 6b), - classifying (S2) the received data frames according to at least one attribute by the demultiplexer (12) to provide a classified data stream, - inputting (S3) the classified data stream into at least two filter chains selected from a hardware filter chain (8) and / or a software filter chain (9) according to its classification, wherein the hardware filter chain (8) and the software filter chain (9) comprise a hardware filter circuit system (10) on a hardware programmable device (3), and wherein the software filter chain (9) comprises a software filter circuit system (11) connected to a central processing unit CPU (2), - filtering (S4) the classified data stream by the hardware filter circuitry and the software filter circuitry (10, 11) to provide a filtered data stream, - combining (S5) by a multiplexer (13) the filtered data streams from the hardware filter chain (8) and the software filter chain (9) to provide a filtered data frame, - Transmitting (S6) the filtered data frame to the other of the trusted domain (4) and the untrusted domain (5).