Non-Internet Protocol Data Sync for Aircraft Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security measures, such as firewalls and air gap networking, are inadequate for ensuring secure data transfer and isolation between computing devices and networks on mobile platforms like aircraft, as they can be circumvented and are labor-intensive and costly for information transfer.
Innovation Solution
An apparatus comprising first and second memories configured for data communication and a controller that detects changes in data and synchronizes it in real-time using non-Internet protocols like ATAoE, FCoE, Infiniband, SATA, PATA, and USB, providing secure data transfer between computing devices and networks without direct Internet protocol interaction.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If air gap networking is used to physically isolate secure networks from insecure networks, then network security is improved, but information transfer becomes labor intensive and expensive
Solution Approach 1:
The patent introduces an intermediary system consisting of a secure computing device and an unsecured computing device that act as mediators between the secure network and insecure network. These intermediary devices enable automated information transfer across the air gap through physical media exchange (such as portable storage devices), eliminating the need for manual labor while maintaining security isolation. The intermediary devices handle the complexity of secure data exfiltration and importation, making the process efficient and scalable.
2Device complexity
If traditional firewalls are used to control network traffic, then basic security is provided, but they can be circumvented and do not provide adequate security for critical applications
Solution Approach 1:
The patent applies segmentation by dividing the network into strictly isolated secure and unsecured segments with no direct communication paths. Instead of relying on a single firewall layer, the system segments data transfer into multiple independent steps: data is exported from the secure network to physical media, the media is physically moved to an unsecured device, and then imported into the insecure network. This multi-stage segmentation eliminates the possibility of circumvention through traditional firewall vulnerabilities.
Solution Approach 2:
The patent introduces intermediary computing devices that act as secure buffers between the secure network and insecure network. These intermediary devices run specialized software that enforces security policies and manages data transfer without requiring direct network connectivity between secure and unsecured systems. The intermediary architecture provides defense-in-depth, making circumvention extremely difficult as attackers would need to compromise multiple isolated systems simultaneously.
3Ease of operation
If direct Internet protocol communication is used between computing devices, then data transfer is simple, but security vulnerabilities and unauthorized access risks increase
Solution Approach 1:
The patent introduces non-Internet communication protocols as intermediary mechanisms that completely bypass the TCP/IP stack and associated security vulnerabilities. The system uses specialized protocols for data export from secure devices to physical media, and for data import into unsecured networks. These intermediary protocols operate in isolated security domains, preventing Internet-based attacks while maintaining efficient data transfer capabilities.
Solution Approach 2:
The patent replaces electronic network protocol communication with physical media exchange mechanisms. Instead of relying on vulnerable Internet protocols for data transfer across security boundaries, the system uses physical portable storage devices that are exported from the secure network, physically transported, and then imported into the unsecured network. This mechanical/physical substitution eliminates digital attack vectors while maintaining data transfer functionality.
Data Source
AI summary
The disclosure describes components, apparatus and methods for providing network security between computing devices and/or networks on mobile platforms such as aircraft. One such apparatus may comprise: a first memory configured for data communication with a first computing device of the mobile platform; a second memory configured for data communication with a second computing device of the mobile platform; and a controller. The controller may be configured to detect a change in data stored In the first memory and cause the change in data stored in the first memory to be reflected in the second memory by causing data transfer from the first memory to the second memory. Data transfer between the first memory and the second memory may be conducted using a non-internet protocol.


