Aircraft Network Access Control via Segmented Operating Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems fail to effectively control access to aircraft network data processing systems, as they are not suited for mobile environments and cannot validate the correct configuration of devices connected, leading to potential risks from unapproved software and unauthorized access.

Innovation Solution

A data processing device with separate operating environments is used, where a first operating environment controls access to the aircraft network data processing system based on predefined rules, isolating unapproved software and ensuring only trusted devices and software can access the system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current network access control systems are applied to aircraft, then network security may be improved, but the systems are not suited for mobile environments and cannot validate device configuration

Engineering Contradiction:
Improvenetwork securityVSAvoidsuitability for mobile environment
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the data processing device into multiple operating environments (first and second operating environments) with distinct security contexts. The first operating environment is configured to access the aircraft network data processing system, while the second operating environment is isolated. This segmentation allows the system to maintain security controls appropriate for aircraft operations while enabling flexibility for different operational modes and device configurations.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If access control is relaxed to allow maintenance devices, then ease of operation is improved, but unapproved software may affect system operation

Engineering Contradiction:
Improvemaintenance device accessVSAvoidunapproved software impact
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a network access controller as an intermediary component within the first operating environment. This controller mediates all access requests from the second operating environment to the aircraft network data processing system by validating device configuration and enforcing access control rules. This intermediary mechanism enables maintenance devices to access the system for operational convenience while preventing unapproved software from affecting system integrity through rigorous validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If device configuration validation is implemented, then system integrity is improved, but device complexity increases

Engineering Contradiction:
Improvesystem integrityVSAvoidaccess control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network access controller is designed to perform multiple functions: validating device configuration, controlling network access, and enforcing security policies. By consolidating these functions into a single multi-functional component within the first operating environment, the system achieves comprehensive configuration validation and security control without proportionally increasing overall device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8806579B1Secure partitioning of devices connected to aircraft network data processing systems
Publication Date: 2014.08.12 THE BOEING CO
  • US8806579B1 patent drawing
  • US8806579B1 patent drawing
  • US8806579B1 patent drawing

AI summary

A system and method for controlling access to an aircraft network data processing system on an aircraft. A first operating environment on a data processing device is configured to access the aircraft network data processing system. A second operating environment on the data processing device is configured to request access to the aircraft network data processing system. A network access controller on the first operating environment is configured to control the access to the aircraft network data processing system by the second operating environment based on rules defining the access to the aircraft network data processing system.