Avionics system safety verification and evaluation system
By designing an avionics system safety verification and evaluation system, the problem of avionics system safety verification was solved, and quantitative safety assessment and protocol compliance testing were achieved, thereby improving the safety and quality of avionics systems.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINESE AERONAUTICAL RADIO ELECTRONICS RES INST
- Filing Date
- 2025-12-31
- Publication Date
- 2026-05-01
AI Technical Summary
The lack of effective tools and methods for safety verification of avionics systems in the current technology makes it difficult to quantify and evaluate safety, which affects system quality.
Design an avionics system safety verification and evaluation system, including an asset scanning module, a verification process control module, a safety verification module, and a compliance verification module. Collect information through active and passive scanning, conduct safety and protocol compliance tests, and generate test results and reports.
It has achieved comprehensive quantitative safety verification and FACE protocol compliance assessment of avionics systems, provided a streamlined test data collection and report backup process, and supported user-defined test plans, thereby improving the safety and quality of avionics systems.
Smart Images

Figure CN121958003A_ABST
Abstract
Description
A safety verification and evaluation system for avionics systems Technical Field
[0001] This invention relates to the field of avionics system safety verification and evaluation, and specifically to an avionics system safety verification and evaluation system. Background Technology
[0002] Avionics systems generally require their constituent hardware, operating systems, software, platform components, and middleware to possess a certain level of security and comply with specific protocol requirements in terms of security. In avionics system design, security design is a crucial component, directly determining the robustness and quality of the system. For a long time, design and development units have not paid sufficient attention to avionics system security verification during actual engineering development, and have also lacked corresponding verification tools, methods, and environments. This makes it difficult to quantify and assess the security of avionics systems, easily overlooking hard-to-detect security flaws and thus affecting the final quality of the avionics system. Therefore, there is an urgent need to develop a set of avionics system security and component compliance verification tools to achieve the verification and quantitative assessment of avionics system security and protocol compliance, thereby improving the security and quality of avionics systems. Summary of the Invention
[0003] The purpose of this invention is to provide an avionics system safety verification and evaluation system that can comprehensively and quantitatively verify and evaluate the safety of avionics systems and their compliance with the security requirements of the FACE protocol.
[0004] The objective of this invention is achieved through the following technical solution:
[0005] A safety verification and evaluation system for avionics systems includes an asset scanning module, a verification process control module, a safety verification module, and a compliance verification module.
[0006] The asset scanning module is used to collect information on various hardware devices, software components and current operating processes in the avionics system, and then classify and organize them to form a list of verification targets.
[0007] The verification process control module is used to control the test verification process according to the test plan configured by the user. It calls the compliance verification module and the security verification module respectively to perform protocol compliance testing and security verification testing for each verification target listed in the verification target list, and generates security test result data and compliance report.
[0008] Preferably, the asset scanning module first uses tools to detect network hosts and scanning ports, and detects hardware characteristics and version information. It then actively scans and acquires assets within the unknown avionics system network. Next, it collects traffic from the target network, analyzes the protocols in the traffic, continuously monitors undiscovered assets in known networks, and continuously acquires information to complete the attributes of detected assets and continuously monitor and deeply scan undiscovered assets. Ultimately, it achieves the discovery and full lifecycle management of all assets within the avionics network.
[0009] Preferably, for each verification target, the verification process control module first calls the security verification module to perform security testing, and then calls the compliance verification module to perform FACE protocol compliance verification testing.
[0010] Preferably, the security verification module is tested according to the following criteria:
[0011] Operating system security testing standards: Test whether known operating system vulnerabilities within the avionics system have been patched; test whether the operating system within the avionics system can prevent unauthorized system privilege acquisition; test whether the operating system within the avionics system can prevent sensitive port services from being exposed to the outside.
[0012] Network security testing standards: Test whether the firewall of the network system within the avionics system has a reasonable security policy, and test whether the network system within the avionics system can prevent common network attacks;
[0013] Component / Service / Remote Procedure Call Security Testing Standards: Test whether the components within the avionics system comply with the component security policy, test whether the avionics system can prevent sensitive services from being exposed to the outside, and test whether the remote procedure calls within the avionics system can reject illegal requests;
[0014] Communication security testing standards: Test whether the communication system within the avionics system can block risky communication protocols and disable relevant ports; test whether the communication system within the avionics system can reject unauthorized login requests.
[0015] Password / Authentication Security Testing Standards: Test whether the authentication and access control system within the avionics system can correctly identify legitimate and illegitimate identities and permissions, and test and evaluate the password encryption strength of the password management system within the avionics system.
[0016] Preferably, the compliance verification module tests the compliance of the software under test, platform components, and middleware with the FACE protocol according to preset standards to determine whether they comply with the corresponding FACE standard and whether they comply with the corresponding security level of the FACE standard.
[0017] Preferably, the avionics system safety verification and evaluation system also includes a data collection and audit recording module, which is used to collect safety test result data and compliance reports generated during the testing and verification process of various terminals in the avionics system, and to record the audit results for use by other modules.
[0018] Preferably, the avionics system safety verification and evaluation system also includes a report generation and conclusion evaluation module, which generates a verification report based on the safety test result data and compliance report generated during the testing and verification process.
[0019] Preferably, the verification report includes the test results for all test items, and in addition, provides an evaluation conclusion based on preset rules, using a scoring system and veto items.
[0020] Preferably, the avionics system safety verification and evaluation system also includes a data backup and push module for backing up and pushing all test, verification and evaluation deliverables.
[0021] Preferably, the data backup and push module performs backups according to the backup location, backup time, and backup frequency configured by the user, and pushes all test, verification, and evaluation products to a specified location on a specified server.
[0022] The beneficial effects of this invention are as follows:
[0023] 1. This invention achieves comprehensive and quantitative compliance verification for the security of avionics networks and for the security requirements of the FACE protocol.
[0024] 2. This invention enables active and passive scanning of target assets in avionics networks, as well as test data collection and audit recording. It also enables standardized security testing and timed backup of verification reports.
[0025] 3. This invention allows users to write their own security testing schemes, thereby achieving high configurability. Attached Figure Description
[0026] Figure 1 is a structural block diagram of an avionics system safety verification and evaluation system.
[0027] Figure 2 is a schematic diagram of the verification and evaluation process of the avionics system safety verification and evaluation system. Detailed Implementation
[0028] The present invention will now be described in further detail with reference to the accompanying drawings and embodiments.
[0029] Referring to Figure 1, this embodiment illustrates an avionics system safety verification and evaluation system, comprising an asset scanning module, a verification process control module, a security verification module, a compliance verification module, a data collection and audit recording module, a report generation and conclusion evaluation module, and a data backup and push module. First, the asset scanning module scans the hardware and software assets within the avionics system to form a list of verification targets. Then, the verification process control module manages the security verification module and the compliance verification module to perform security and compliance verification on each target, generating corresponding security test result data and compliance reports. Next, the data collection and audit recording module records the audit results, and the report generation and conclusion evaluation module generates a verification report. Finally, the data backup and push module backs up the corresponding data and reports according to the server location, backup time, and backup frequency specified by the user. Each module is described in detail below.
[0030] The asset scanning module collects information on various hardware devices, software components, and currently running processes within the avionics system, categorizing and organizing this information to form a verification target list. The module employs both active and passive detection methods. Active detection proactively discovers assets by using tools to probe network hosts, scan ports, and detect hardware characteristics and version information. Passive detection collects traffic from the target network and analyzes application-layer protocols such as HTTP, FTP, UDP, IGMP, and DDS to detect network asset information. The sequence is as follows: active detection is performed first, primarily for proactively scanning and acquiring assets within unknown avionics system networks. After active detection is complete, passive detection is performed, mainly for continuously monitoring undiscovered assets within known networks. This continuous information acquisition completes the attributes of detected assets and enables continuous monitoring and deep scanning of undiscovered assets, ultimately achieving the discovery and full lifecycle management of all assets within the avionics network.
[0031] The verification process control module controls the test verification process according to the user-configured test plan. It calls the compliance verification module and the security verification module respectively, performing protocol compliance testing and security verification testing on each verification target listed in the verification target list, and generating security test result data and a compliance report. The basic order is to first call the security verification module to perform security testing, and then call the compliance verification module to perform FACE protocol compliance verification testing. The test plan typically includes the content to be tested, the test scope, the test order, and the estimation criteria.
[0032] The security verification module will undergo security testing according to the following standards:
[0033] Operating system security testing standards: Test whether known operating system vulnerabilities within the avionics system have been patched; test whether the operating system within the avionics system can prevent unauthorized system privilege acquisition; test whether the operating system within the avionics system can prevent sensitive port services from being exposed to the outside.
[0034] Network security testing standards: Test whether the firewall of the network system within the avionics system has a reasonable security policy, and test whether the network system within the avionics system can prevent common network attacks;
[0035] Component / Service / Remote Procedure Call Security Testing Standards: Test whether the components within the avionics system comply with the component security policy, test whether the avionics system can prevent sensitive services from being exposed to the outside, and test whether the remote procedure calls within the avionics system can reject illegal requests;
[0036] Communication security testing standards: Test whether the communication system within the avionics system can block risky communication protocols and disable relevant ports; test whether the communication system within the avionics system can reject unauthorized login requests.
[0037] Password / Authentication Security Testing Standards: Test whether the authentication and access control system within the avionics system can correctly identify legitimate and illegitimate identities and permissions, and test and evaluate the password encryption strength of the password management system within the avionics system.
[0038] The compliance verification module tests the software, platform components, and middleware under test against the FACE protocol according to preset standards to determine whether they comply with the corresponding FACE standard and the corresponding security level of the FACE standard, namely confidentiality level, security level, and general level. The requirements for each level of the software, platform components, and middleware under test are as follows:
[0039] Confidentiality level:
[0040] Regarding spatiotemporal partitioning:
[0041] Spatiotemporal partitioning must be supported;
[0042] Regarding the use of operating system interfaces:
[0043] a) It should support ARINC 653 and POSIX interfaces.
[0044] b) External operations should only support memory block operations.
[0045] c) Confidential components should use only a subset of POSIX APIs tailored for the SE profile in the POSIX operating environment (see Appendix A of the FACE 3.0 protocol for details).
[0046] d) SE-level profile OSS UoC for POSIX operating environments should support mutex operations with a priority protection protocol (_POSIX_THREAD_PRIO_PROTECT) (e.g., pthread_mutexattr_setprotocol() API).
[0047] e) SE-level profile OSS UoC for POSIX operating environments should support memory mapping operations (e.g., mmap() API) with shared memory objects (_POSIX_SHARED_MEMORY_OBJECTS).
[0048] f) Security-grade components used in POSIX operating environments should include support for inter-area communication using ARINC 653 sampling and queued ports.
[0049] g) Confidential components used in POSIX operating environments should include support for the set of health monitoring APIs defined in ARINC 653 in order to communicate with ARINC 653 health monitoring programs.
[0050] Security level:
[0051] Regarding spatiotemporal partitioning:
[0052] Spacetime partitioning should be supported. If the component depends on the ARINC653 operating environment, spacetime partitioning must be provided.
[0053] Regarding the use of operating system interfaces:
[0054] a) ARINC 653 and POSIX should be supported.
[0055] b) External operations should only support memory block operations, file system operations, sampling port expansion, and multi-module scheduling.
[0056] c) Security-grade components used in POSIX operating environments should support mutex operations with a priority protection protocol (_POSIX_THREAD_PRIO_PROTECT) (e.g., pthread_mutexattr_setprotocol() API).
[0057] d) Security-grade components used in POSIX operating environments should support memory mapping operations (e.g., mmap() API) with shared memory objects (_POSIX_SHARED_MEMORY_OBJECTS).
[0058] e) Security-grade components for POSIX operating environments should include support for inter-area communication using ARINC 653 sampling and queued ports.
[0059] f) Security-grade components used in POSIX operating environments should include support for the set of health monitoring APIs defined in ARINC 653 in order to communicate with ARINC 653 health monitoring programs.
[0060] General grade:
[0061] Regarding spatiotemporal partitioning:
[0062] Spatial partitioning should be supported, with time partitioning as an option;
[0063] Regarding the use of operating system interfaces:
[0064] a) General-purpose components should provide a subset of POSIX APIs tailored for GP-level profiles (see Appendix A of the FACE3.0 protocol).
[0065] b) General-purpose components should provide a set of APIs for sockets: FD_CLR(), FD_ISSET(), FD_SET(), FD_ZERO(), and select().
[0066] c) There are no special restrictions on external operations.
[0067] d) If ARINC 653 is supported, general-purpose components should include support for inter-area communication using ARINC 653 sampling and queue ports.
[0068] e) If ARINC 653 is supported, general-purpose components should include support for the set of health monitoring APIs defined in ARINC 653 in order to communicate with ARINC 653 health monitoring programs.
[0069] The data collection and audit record module is used to collect safety test results data and compliance reports generated during the testing and verification of various terminals in the avionics system, and to record them for audit purposes. These records can be accessed by other modules.
[0070] The report generation and conclusion evaluation module generates a verification report based on the security test results and compliance reports generated during the testing and verification process. The verification report includes the test results for all the aforementioned test items and, according to preset rules, provides an evaluation conclusion using a scoring system and veto criteria. The scoring system is as follows: FACE protocol compliance verification accounts for 50% of the score, software environment security verification accounts for 30%, and others account for 20%. Furthermore, non-compliance with the FACE protocol, and failures in network security, communication security, and password / authentication security during security testing are veto criteria.
[0071] The data backup and push module is used to back up and push all test, verification and evaluation deliverables, including security test results data, compliance reports, verification reports, evaluation conclusions, etc., to a specified location on a specified server. In addition, users can configure the specific backup location, backup time and backup frequency.
[0072] Referring to Figure 2, the verification and evaluation method of the avionics system safety verification and evaluation system includes the following steps:
[0073] Step 1: The asset scanning module first actively probes and then continuously performs passive probes to collect information on various hardware devices, software components and current running processes in the avionics network, and then classifies and organizes them to form a verification target list.
[0074] Step 2: The verification process control module, based on the test plan configured by the user, controls the test verification process, calls the compliance verification module and the security verification module respectively, performs protocol compliance testing and security verification testing for each verification target listed in the verification target list, and generates security test result data and compliance report;
[0075] The security verification module will be tested according to the following standards: operating system security testing standard, network security testing standard, component / service / remote procedure call security testing standard, communication security testing standard, and password / authentication security testing standard.
[0076] The compliance verification module tests the software, platform components, and middleware under test against the FACE protocol according to preset standards to determine whether they comply with the corresponding FACE standard and the corresponding security level of the FACE standard.
[0077] Step 3: The data collection and audit record module collects the safety test results data and compliance reports generated during the testing and verification of various terminals in the avionics system, and records the audit results for use by other modules.
[0078] Step 4: The report generation and conclusion evaluation module generates a verification report based on the security test results data and compliance reports generated during the testing and verification process. The verification report includes the test results of all the above test items and, in addition, provides an evaluation conclusion based on preset rules, using a scoring system and veto items.
[0079] Step 5: The data backup and push module backs up and pushes all test, verification, and evaluation deliverables, including security test results data, compliance reports, verification reports, evaluation conclusions, etc., according to the server location, backup time, and backup frequency specified by the user.
[0080] It is understood that those skilled in the art can make equivalent substitutions or modifications to the technical solution and inventive concept of the present invention, and all such substitutions or modifications should fall within the protection scope of the appended claims.
Claims
1. An avionics system safety verification and evaluation system, comprising an asset scanning module, a verification process control module, a safety verification module, and a compliance verification module, characterized in that: The asset scanning module is used to collect information on various hardware devices, software components, and current operating processes in the avionics system, and then classify and organize them to form a verification target list. The verification process control module is used to call the compliance verification module and the security verification module respectively according to the test verification process, and perform protocol compliance testing and security verification testing on each verification target listed in the verification target list, and generate security test result data and compliance report.
2. The avionics system safety verification and evaluation system according to claim 1, characterized in that... The asset scanning module first uses tools to detect network hosts and scanning ports, and detects hardware characteristics and version information. It actively scans and acquires assets within unknown avionics system networks. Then, it collects traffic from the target network, analyzes the protocols in the traffic, continuously monitors undiscovered assets in known networks, and continuously acquires information to complete the attributes of detected assets and continuously monitor and deeply scan undiscovered assets. Ultimately, it achieves the discovery and full lifecycle management of all assets within the avionics network.
3. The avionics system safety verification and evaluation system according to claim 1, characterized in that... For each verification target, the verification process control module first calls the security verification module to perform security testing, and then calls the compliance verification module to perform FACE protocol compliance verification testing.
4. The avionics system safety verification and evaluation system according to claim 1, characterized in that... The security verification module performs security testing according to the following standards: Operating System Security Testing Standards: Testing whether known operating system vulnerabilities within the avionics system have been patched; testing whether the operating system within the avionics system can prevent unauthorized system privilege acquisition; testing whether the operating system within the avionics system can prevent sensitive port services from being exposed to the outside world; Network Security Testing Standards: Testing whether the firewall of the network system within the avionics system has reasonable security policies; testing whether the network system within the avionics system can prevent common network attacks; Component / Service / Remote Procedure Call Security Testing Standards: Testing whether components within the avionics system comply with component security policies; testing whether the avionics system can prevent sensitive services from being exposed to the outside world; testing whether remote procedure calls within the avionics system can reject unauthorized requests. Communication security testing standards: Test whether the communication system within the avionics system can block risky communication protocols and disable relevant ports, and test whether the communication system within the avionics system can reject unauthorized login requests; Password / authentication security testing standards: Test whether the authentication and access control system within the avionics system can correctly identify legitimate and illegitimate identities and permissions, and test and evaluate the password encryption strength of the password management system within the avionics system.
5. The avionics system safety verification and evaluation system according to claim 1, characterized in that... The compliance verification module tests the software, platform components, and middleware under test against the FACE protocol according to preset standards to determine whether they comply with the corresponding FACE standard and the corresponding security level of the FACE standard.
6. The avionics system safety verification and evaluation system according to claim 1, characterized in that... It also includes a data collection and audit log module, which is used to collect safety test results data and compliance reports generated during the testing and verification of various terminals in the avionics system, and to audit and log them for use by other modules.
7. The avionics system safety verification and evaluation system according to claim 1, characterized in that... It also includes a report generation and conclusion evaluation module, which is used to generate verification reports based on the security test results data and compliance reports generated during the testing and verification process.
8. The avionics system safety verification and evaluation system according to claim 7, characterized in that, The verification report includes the test results of all test items, and in addition, provides an evaluation conclusion based on preset rules, using a scoring system and veto items.
9. The avionics system safety verification and evaluation system according to claim 1, characterized in that... It also includes a data backup and push module for backing up and pushing all test, verification, and evaluation deliverables.
10. The avionics system safety verification and evaluation system according to claim 9, characterized in that... The data backup and push module performs backups according to the backup location, backup time, and backup frequency configured by the user, and pushes all test, verification, and evaluation products to the specified location on the specified server.