Method for controlling communication between a high-security critical part and a low-security non-critical part of a computer and controller for the implementation of such a method
The method and controller within the computer manage data flow between critical and non-critical parts using integrity checks and dual-key sequences, addressing cybersecurity vulnerabilities and reducing bulkiness in aeronautical systems.
Patent Information
- Application Number
- FR2024006855
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-26
- Publication Date
- 2026-01-02
AI Technical Summary
Existing communication methods between critical and non-critical computer parts in the aeronautical field are inadequate in ensuring robust cybersecurity, particularly against attacks, and often result in bulky solutions due to the need for external enclosures and disconnects.
A method and controller are implemented within the computer to control data flow between high-safety critical and low-safety non-critical parts, using a programmable circuit (FPGA) to self-check integrity, validate keys, and manage data flow opening and closing based on integrity checks and dual-key sequences.
Ensures secure communication by protecting critical parts from non-critical parts, maintaining system integrity, and reducing size through integrated implementation, achieving high cybersecurity assurance (SAL3) without external enclosures.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Method for controlling communication between a high-security critical part and a low-security non-critical part of a computer and controller for implementing such a method. Technical field
[0001] The invention relates to a method of communication between equipment in different security zones. It also relates to a device configured to implement such a method. STATE OF THE ART
[0002] In the aeronautical field, computers carrying critical and non-critical functions coexist and must be able to communicate with each other.
[0003] However, it is necessary to ensure that the computer carrying critical functions cannot be corrupted by attacks or erratic operations originating from the non-critical computer.
[0004] In the aeronautical field where critical computers (for example DAL - Design Assurance Level A or B according to the classification indicating a level of reliability required for electronic systems on board aircraft) incorporate non-critical functions (DAL D or E) this guarantee must be very strong or even absolute, particularly with regard to cybersecurity attacks where the protection of critical functions related to flight safety is paramount.
[0005] This is particularly necessary for critical computers linking aircraft control devices which must offer a very high level of safety, especially during flight phases.
[0006] Document FR3015830 discloses a device for controlling communication between two pieces of equipment located in different security zones. Such a device is unsatisfactory because it requires implementation in an external enclosure and a disconnect between the two pieces of equipment to be separated. This leads to a bulky solution. Description of the invention
[0007] The invention proposes a solution for controlling and therefore cutting off communications between different security zones within the same computer.
[0008] To this end, the invention proposes, according to a first aspect, a method of communication between a high-safety critical part of a computer and a low-safety non-critical part of the computer, the method comprising the following steps, implemented within a controller interposed in the computer between the part critical and non-critical parts, the computer being configured to open or close a data flow on a critical link between the critical and non-critical parts:
[0009] - receiving a request to open the data stream from the critical part in order to allow a flow of data between the critical part and the non-critical part;
[0010] - self-checking the integrity of the controller; and whether the controller is intact;
[0011] - opening of the data flow on the critical link;
[0012] - receiving a request to close the data flow on the critical link from the critical part;
[0013] - closing the data stream.
[0014] The invention is advantageously complemented by the following features, taken alone or in any technically possible combination thereof.
[0015] The request to open a flow and / or the request to close a flow includes a key, the method including a validation of the request to open and / or close a flow, the key preferably being double.
[0016] The validation of the request to open and / or close the flow includes a comparison of the received key with a local key stored in a memory of the controller; the request to open and / or close the flow is validated if the local key is identical to the received key.
[0017] If the controller is not intact, the data flow on the critical link remains closed.
[0018] If the controller is not intact, the process includes a step of issuing a alert message to the critical section.
[0019] The controller integrity self-check includes calculating a fingerprint from a controller configuration file stored at controller initialization and comparing the calculated fingerprint with a test fingerprint stored in controller memory.
[0020] The fingerprint is a hash function of the controller configuration file, the controller integrity self-check comprising a comparison of the calculated hash function to a hash function of the same configuration file calculated and stored in a memory of the controller.
[0021] The hash function is a non-reverse SHA-256 hash function.
[0022] The controller is a programmable circuit, preferably an FPGA.
[0023] The non-critical part is a computer qualified DAL D or E and in which the critical part is a computer qualified DAL A, DAL B or DAL C.
[0024] The invention proposes, according to a second aspect, a controller for communication between a critical part of a computer and a non-critical part of the computer, the controller comprising at least one processor configured to implement a method according to the first aspect of the invention.
[0025] The method allows the controller to either interrupt or allow the data flow from the critical part to the non-critical part. The invention therefore makes it possible to protect the critical part from potential attacks originating from the non-critical part.
[0026] Advantageously, the controller thus implements a secure communication method between parts of a computer with different security levels, ensuring that the controller itself is secure by efficiently and securely controlling the opening and closing of the data flow from the non-critical part. The controller integrated into the computer facilitates its integration within the aircraft. In this way, the size is reduced.
[0027] The critical part, deemed healthy because it is properly protected, therefore decides whether to allow the data flow from the non-critical part in accordance with its environment. The critical part is the sole master of the communication link between the critical and non-critical parts. Only the critical part can initiate a transaction on the communication link.
[0028] Advantageously, the controller is activated and deactivated securely via a preferably double-key writing sequence. If an incorrect key is written or a sequence is incomplete, the controller remains secure (no communication is possible from the non-critical part to the critical part). Since the countermeasure implemented in the controller relies on signals provided by the critical part, the invention ensures the integrity of the critical part to guarantee its operation.
[0029] This is particularly advantageous in a critical multi-DAL system, where an isolation function independent of the other systems is required. PRESENTATION OF FIGURES
[0030] Other features, objectives and advantages of the invention will become apparent from the following description, which is purely illustrative and not limiting, and which should be read in conjunction with the accompanying drawings on which:
[0031] - Fig. 1 illustrates a calculator, according to one embodiment, comprising two parts of different security levels between which a controller is inserted to control communications between the two parts;
[0032] - Figure 2 illustrates a method of controlling communications implemented in a control unit according to an embodiment.
[0033] In all figures, similar elements bear identical references. DETAILED DESCRIPTION
[0034] Figure 1 illustrates a computer 1 comprising two parts 11, 12. A part 11 of high safety level or critical part and a part 12 of low safety level or non-critical part. It is specified here that there is only one computer 1.
[0035] The security level is understood to be a set of rules and operating constraints imposed on the party to ensure that only authorized data flows can pass through the party in question.
[0036] A computer is understood to be a component comprising several processors or several microcontrollers enabling the execution of instructions and comprising one or more volatile or non-volatile memories.
[0037] Critical or non-critical parts of the computer are understood to be independent parts of the computer intended to operate with different levels of safety, these parts being allocated in the computer.
[0038] Preferably, and according to levels of operational safety, the parts are qualified according to the DAL EUROCAE ED-12 (Europe) or RTCA DO-178C standard according to several criticality levels (from most critical to least critical):
[0039] - DAL A: This is the strictest criticality level. A failure of a part DAL A can have catastrophic consequences for aircraft safety;
[0040] - DAL B: a failure of a part of DAL B can lead to consequences serious risks to aircraft safety but not necessarily catastrophic;
[0041] - DAL C: a failure of a DAL C part can have consequences on the aircraft safety, but these consequences are limited;
[0042] - DAL D: a failure of a part DAL D is not likely to have a significant impact on aircraft safety;
[0043] - DAL E: this level is used for functions that do not contribute to the safety of the aircraft.
[0044] These DAL criticality levels allow for the assessment of the potential impact of failures in avionics systems. DAL levels A, B, and C are the most commonly used in flight safety-critical systems such as piloting, navigation, and flight control systems.
[0045] The critical part is for example qualified DAL A or B or C and the non-critical part is for example qualified DAL D (or E), the computer thus being a multi-DAL computer to operate with systems where different levels of safety are required.
[0046] Between the critical part 11 and the non-critical part 12 is interposed a controller 2 configured to control communications between the critical part 11 and the non-critical part 12. In particular, the controller 2 allows to cut off or not a flow of data coming from the non-critical part to the critical part.
[0047] Advantageously, the data flow passes through a non-critical link 21 for data coming from the critical part to the non-critical part, and through a critical link 22 for data coming from the non-critical part to the critical part. A communication link is, for example, defined on a communication bus connecting the critical part 11 to the non-critical part 12.
[0048] It will be noted that the non-critical link 21 always allows a data flow to pass through, while the critical link 22 is managed by the controller 2 to close the data flow or not according to a communication process between a high-safety critical part 11 of a computer 1 and a low-safety non-critical part 12 of the computer 1 described in relation to [Fig.2] (see below).
[0049] The controller 2 is preferably a programmable circuit such as an FPGA (Field Gate Programmable Array). The use of an FPGA to implement the control method makes it possible to achieve an extremely high level of cybersecurity (SAL 3, for Security Assurance Level - 3 according to Anglo-Saxon terminology).
[0050] It is specified that the level of security assurance is defined according to the EUROCAE ED-203A / RTCA DO-356A standard and proposes four levels ranging from SAL0 (lowest) to SAL3 (highest). - SAL0: No protective effect. This level is limited to the initial assessment of protection needs and applies to systems and articles to which no higher SAL is assigned. - SALI: Minimum security assurance for security measures: Suitable for additional protection or reinforcement / resilience. It provides a minimum level of confidence in the security measures implemented. - SAL2: Essential confidence in the secure development and operation of security measures: This level ensures that security measures are developed and operated securely, providing essential confidence in their effectiveness. - SAL3: Enhanced confidence in the secure development and operation of security measures. This level provides enhanced confidence in the secure development and operation of security measures, thus ensuring more rigorous protection against threats.
[0051] These SAL levels make it possible to categorize and differentiate the safety requirements according to the importance and criticality of the avionics systems, thus ensuring that the appropriate safety measures are applied according to the specific needs.
[0052] The computer 1 is preferably equivalent to 2 MCUs (379 mm x 436 mm x 60.80 mm). The controller 2 is also small in size and is a component of the computer measuring 30 mm x 30 mm.
[0053] In relation to [Fig.2], at the start-up (step E0) of the controller 2, it initializes and closes by default the data flow between the non-critical part 12 and the critical part 11 (step El). The critical link 22 is then cut.
[0054] Furthermore, at the start-up (step E0) of controller 2, during its initialization, a controller integrity calculation is performed by a module of this controller. This calculation includes calculating a hash of a configuration file, preferably binary, loaded at the initialization of controller 2, and comparing the resulting hash to a test hash that is previously loaded into non-volatile memory of controller 2 during its factory loading. The hash is, for example, a hash function (for example, a non-inverse SHA-256 hash function) of the configuration file. Such a configuration file contains all the instructions for controller 1 to implement the process described herein.
[0055] If the calculated footprint is not identical to the test footprint, calculator 2 does not start.
[0056] When the controller is an FPGA, for example, it calculates a hash function (for example, a non-inverse SHA-256 hash function) of the FPGA configuration file (bitstream) loaded during FPGA initialization. The calculated hash function is then compared to the hash function of the configuration file stored in dedicated non-volatile memory of the FPGA during factory configuration. The hash function is calculated specifically by an FPGA IP address designed for this purpose.
[0057] Next, controller 2 is waiting for a request to open the data flow (step E2) from critical part 11.
[0058] A request to open the data stream on the critical link 22 is sent from the critical part 11 to the controller 2 (step E3). This open request is, for example, a dual-key write sequence (i.e., a message sent by the critical part 11 and read by the controller 2). This key received by the controller 2 is compared to a dual-key sequence 13 stored in the controller's memory (step E4). The key size depends on the system and the expected security level. The higher the security level, the larger the key size. For example, for a SAL0 security level, a key with a minimum length of 8 bits is required, whereas for a SAL3 security level, a key with a minimum length of 512 bits is more suitable.
[0059] If the comparison shows that the received key is identical bit by bit to the stored key, then controller 2 validates the request to open the data stream (step E5).
[0060] An integrity check of controller 2 is then performed (step E6) by carrying out an integrity calculation (step E7). This calculation is similar to the one performed at the start-up of controller 2 described above. If the calculated fingerprint is identical to the test fingerprint, then an integrity alert is raised and manifests itself by sending a Integrity flag (in English, flag) positioned at 0, otherwise the integrity flag is positioned at 1 (step E8).
[0061] When the integrity flag is set to 1, the controller / FPGA sends an alert message to the critical part (step E9). Critical part 11 then receives this alert message (step E10). Upon receiving this alert, critical part 11 can decide to apply sanctions (step E15) which vary depending on its safety and cybersecurity level. For example, if the aircraft is in flight or on the ground, the data flow remains closed to ensure safety and cybersecurity (returning to step E1). However, other possible sanctions may be applied depending on the aircraft's safety and cybersecurity level and situation.
[0062] When the integrity flag is set to 0 then the controller / FPGA commands the opening of the data flow (Eli step) to allow a data flow from the non-critical part 12 to the critical part 11 on the critical link 22.
[0063] Controller 2 is then waiting for a request to close the data stream (step E12). When it receives a request to close the data stream (step E13) from the critical part 11, it terminates the process, which resets by closing the data stream and returning to step E1. As with the open request, the close request consists of the transmission (step E13) of a double-key write sequence. This key received by controller 2 is compared to a double-key sequence 14 stored in the controller's memory (step E14).
Claims
Demands
1. A method for communication between a high-security critical part (11) of a computer (1) and a low-security non-critical part (12) of the computer (1), the method comprising the following steps, implemented within a controller (2) interposed in the computer (1) between the critical part (11) and the non-critical part (12), the computer (2) being configured to open or close a data flow on a critical link (22) between the critical part (11) and the non-critical part (12): - receiving (E2) a request to open the data flow (E3) from the critical part (11) so as to authorize a data flow between the critical part and the non-critical part; - self-checking (E6) the integrity of the controller; and if the controller is intact; - opening (E1) the data flow on the critical link (21);- reception (El2) of a request to close the data flow (El3) on the critical link (21) from the critical part (11); - closure (El) of the data flow.;
2. A method according to claim 1, wherein the request (E3) to open a flow and / or the request (E13) to close a flow includes a key, the method comprising a validation (E2, El2) of the request to open and / or close a flow, the key preferably being double.
3. A method according to claim 2, wherein the validation (E2, El2) of the request to open and / or close the flow includes a comparison (E4, El4) of the received key with a local key stored in a memory of the controller (2); the request to open and / or close the flow being validated if the local key is identical to the received key.
4. A method according to any one of the preceding claims, wherein if the controller (2) is not intact, the data flow on the critical link remains closed (El).
5. A method according to any one of the preceding claims, wherein if the controller (2) is not intact, the method includes a step of emitting (E9) an alert message to the critical part (11).
6. A method according to any one of the preceding claims, wherein the self-check (E6) of the integrity of the controller (2) comprises a calculation (E7) of a fingerprint from a controller configuration file (2) stored at controller initialization (2) and a comparison of the calculated fingerprint with a test fingerprint stored in a controller memory (2).
7. A method according to claim 6, wherein the fingerprint is a hash function of the controller configuration file (2), the controller integrity self-check comprising a comparison of the calculated hash function to a hash function of the same configuration file calculated and stored in a memory of the controller.
8. A method according to claim 7, wherein the hash function is a non-reverse SHA-256 hash function.
9. A method according to any one of the preceding claims, wherein the controller (2) is a programmable circuit, preferably an FPGA.
10. A method according to any one of the preceding claims, wherein the non-critical part (12) is a DAL D or E qualified computer and wherein the critical part (11) is a DAL A, DAL B or DAL C qualified computer.
11. Controller (2) of a communication between a critical part (11) of a computer (1) and a non-critical part (12) of the computer (1), the controller (2) comprising at least one processor configured to implement a method according to one of the preceding claims.
Citation Information
Patent Citations
Device for interconnecting communication networks with controlled security
FR3015830A1
System and method for information sharing between non-secure devices
US20100192217A1
Configurable cross-domain information assurance
US20170098094A1
Multi-level security domain separation using soft-core processor embedded in an FPGA
WO2016118224A1