IP Air Traffic Control Network Monitoring System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current air traffic control networks lack effective mechanisms to reliably detect unwanted data traffic, which compromises security due to limited analysis of communication within closed IP networks.

Innovation Solution

An air traffic control system with an Internet protocol-based network monitoring system that includes a monitoring unit with sensor and evaluation modules to analyze and evaluate data traffic, using deep packet inspection to identify unwanted data traffic by examining content, protocols, sources, sinks, and metadata, and providing real-time alerts and graphical reports.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If protocol-level analysis is used in closed IP networks, then network security is maintained through limited access control, but unwanted data traffic cannot be reliably detected

Engineering Contradiction:
Improvedetection reliabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A network monitoring system is introduced as an intermediary component between the closed IP network and the external environment. This monitoring system includes sensors that capture data packets flowing through the network, converters that transform captured data into analysis-ready formats, and evaluators that assess security risks. This intermediary structure enables deep packet inspection and content analysis without disrupting the closed network architecture or access control mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The monitoring system is segmented into distinct functional modules: sensors for data capture, converters for data transformation, and evaluators for security assessment. This segmentation allows each component to perform its specific function efficiently while working together to achieve comprehensive traffic analysis. The modular structure reduces overall system complexity by dividing the monitoring task into manageable, specialized units.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If deep packet inspection is implemented to analyze data content, then unwanted traffic detection capability is improved, but system complexity and resource requirements increase

Engineering Contradiction:
Improvetraffic analysis precisionVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

Converters act as intermediaries between the captured data and the evaluation process. These converters transform raw data packets into standardized formats that are easier to analyze, extracting relevant features and metadata while filtering out unnecessary information. This preprocessing step enables the evaluator to perform deep packet inspection with reduced complexity by working with structured, normalized data rather than raw packets.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The analysis process is segmented into multiple stages: initial data capture by sensors, preprocessing and transformation by converters, and final evaluation by evaluators. Each segment handles specific aspects of traffic analysis, allowing for precise measurement of unwanted traffic while distributing computational complexity across multiple specialized components rather than concentrating it in a single complex system.

Inventive Principle:
Principle #1Segmentation

3Reliability

If continuous monitoring of all data traffic is performed, then network security is enhanced, but data processing time and computational resources increase

Engineering Contradiction:
Improvenetwork securityVSAvoiddata processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The monitoring system applies partial action by focusing analysis on specific aspects of data traffic rather than examining every byte of every packet in depth. Sensors capture all traffic, but converters selectively transform and extract only the most relevant features and metadata for security assessment. Evaluators then concentrate on assessing these extracted features for security risks, rather than performing exhaustive analysis on all data. This selective approach maintains high security reliability while reducing overall processing time and computational resource requirements.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The converter component extracts essential information from captured data packets, separating critical security-relevant features from the rest of the data stream. By taking out only the necessary metadata and key characteristics for security evaluation, the system reduces the volume of data that requires intensive processing, thereby maintaining continuous monitoring capability while minimizing data processing time and computational resource consumption.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3848832B1Flight traffic control system and method for monitoring a flight traffic control network
Publication Date: 2024.05.08 ROHDE & SCHWARZ GMBH & CO KG
  • EP3848832B1 patent drawingFigure 1

AI summary

An air traffic control system for air traffic control comprises at least one controller workstation (18), at least one radio device (20), an air traffic control network (12) configured as an Internet Protocol air traffic control network, and a network monitoring system (22) associated with the air traffic control network (12). The air traffic control network (12) comprises a local network (14) connected to a wide area network (16). The controller workstation (18) is integrated into the local network (16) and connected to the radio device (20), which is integrated into the local network (16) and/or an external network. The network monitoring system (22) includes a monitoring unit (24) integrated into the local network (14). Furthermore, a method for monitoring an air traffic control network (14) of an air traffic control system (10) for air traffic control is described.