Non-Internet Protocol Data Sync for Aircraft Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security measures, such as firewalls and air gap networking, are inadequate for ensuring secure data transfer and isolation between computing devices and networks on mobile platforms like aircraft, as they can be circumvented and are labor-intensive and costly for information transfer.

Innovation Solution

An apparatus comprising first and second memories configured for data communication and a controller that detects changes in data and synchronizes it in real-time using non-Internet protocols like ATAoE, FCoE, Infiniband, SATA, PATA, and USB, providing secure data transfer between computing devices and networks without direct Internet protocol interaction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If air gap networking is used to physically isolate secure networks from insecure networks, then network security is improved, but information transfer becomes labor intensive and expensive

Engineering Contradiction:
Improvenetwork securityVSAvoidinformation transfer
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary system consisting of a secure computing device and an unsecured computing device that act as mediators between the secure network and insecure network. These intermediary devices enable automated information transfer across the air gap through physical media exchange (such as portable storage devices), eliminating the need for manual labor while maintaining security isolation. The intermediary devices handle the complexity of secure data exfiltration and importation, making the process efficient and scalable.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If traditional firewalls are used to control network traffic, then basic security is provided, but they can be circumvented and do not provide adequate security for critical applications

Engineering Contradiction:
Improvesecurity systemVSAvoidsecurity effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies segmentation by dividing the network into strictly isolated secure and unsecured segments with no direct communication paths. Instead of relying on a single firewall layer, the system segments data transfer into multiple independent steps: data is exported from the secure network to physical media, the media is physically moved to an unsecured device, and then imported into the insecure network. This multi-stage segmentation eliminates the possibility of circumvention through traditional firewall vulnerabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary computing devices that act as secure buffers between the secure network and insecure network. These intermediary devices run specialized software that enforces security policies and manages data transfer without requiring direct network connectivity between secure and unsecured systems. The intermediary architecture provides defense-in-depth, making circumvention extremely difficult as attackers would need to compromise multiple isolated systems simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If direct Internet protocol communication is used between computing devices, then data transfer is simple, but security vulnerabilities and unauthorized access risks increase

Engineering Contradiction:
Improvedata transferVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces non-Internet communication protocols as intermediary mechanisms that completely bypass the TCP/IP stack and associated security vulnerabilities. The system uses specialized protocols for data export from secure devices to physical media, and for data import into unsecured networks. These intermediary protocols operate in isolated security domains, preventing Internet-based attacks while maintaining efficient data transfer capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces electronic network protocol communication with physical media exchange mechanisms. Instead of relying on vulnerable Internet protocols for data transfer across security boundaries, the system uses physical portable storage devices that are exported from the secure network, physically transported, and then imported into the unsecured network. This mechanical/physical substitution eliminates digital attack vectors while maintaining data transfer functionality.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10587684B2Apparatus and methods for providing network security on a mobile platform
Publication Date: 2020.03.10 AIRBUS CANADA LLP
  • US10587684B2 patent drawing
  • US10587684B2 patent drawing
  • US10587684B2 patent drawing

AI summary

The disclosure describes components, apparatus and methods for providing network security between computing devices and/or networks on mobile platforms such as aircraft. One such apparatus may comprise: a first memory configured for data communication with a first computing device of the mobile platform; a second memory configured for data communication with a second computing device of the mobile platform; and a controller. The controller may be configured to detect a change in data stored In the first memory and cause the change in data stored in the first memory to be reflected in the second memory by causing data transfer from the first memory to the second memory. Data transfer between the first memory and the second memory may be conducted using a non-internet protocol.