Avionic Security Gateway Dynamic Policy Adaptation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Avionic security gateways face challenges in reducing resource consumption, particularly computing power and memory, due to the need to execute extensive security algorithms continuously, which is not suited for the constrained environment of on-board aircraft systems, and the increasing interactions between critical avionic equipment and other systems.

Innovation Solution

The avionic security gateway dynamically adapts its security policy and resource allocation based on the aircraft's operational state, utilizing predefined communication channel characteristics to implement appropriate security algorithms and allocate resources accordingly, thereby optimizing resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a set of security algorithms is executed continuously to guard against all computer attacks, then security coverage is improved, but resource consumption (computing power and memory) increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidcomputing power and memory consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements dynamic adaptation of security algorithms based on the aircraft's operational state. The security gateway executes different sets of security algorithms depending on whether the aircraft is in flight, on ground, or in maintenance mode. This dynamic approach ensures comprehensive security coverage when needed while reducing resource consumption during normal operations, directly resolving the contradiction between security coverage and resource usage.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters of security algorithm execution based on operational conditions. By adjusting which algorithms are active and their execution intensity according to the aircraft state, the system optimizes the balance between security protection and resource consumption. This parameter-based adaptation allows the gateway to maintain security effectiveness while minimizing computing power and memory requirements during normal flight operations.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If critical avionic equipment is physically isolated to ensure safety, then system reliability is improved, but adaptability to increasing interactions between systems deteriorates

Engineering Contradiction:
Improvesafety of critical equipmentVSAvoidinteractions between systems
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security gateway acts as an intermediary device between critical avionic equipment and other systems. It implements security algorithms that filter and monitor data traffic, allowing controlled interactions while maintaining the isolation of critical systems. This mediator approach enables the aircraft to increase system interoperability and adaptability without compromising the safety and reliability of critical avionic equipment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3402158B1Improved avionics security gateway and aircraft comprising such a gateway
Publication Date: 2020.04.08 THALES SA
  • EP3402158B1 patent drawingFigure 1
  • EP3402158B1 patent drawingFigure 2

AI summary

This gateway (10) is designed to establish an interconnection between the first and second communication networks (11, 12) of an onboard computer system on an aircraft and to monitor at least one communication channel (C1) between a first transmitting device (13) on the first network and a second receiving device (14) on the second network. The gateway is characterized in that it is designed to implement, at any given time, a security policy for said communication channel that depends on a current operating mode (M) of the gateway, the current operating mode being a function of a current state (E) of the aircraft. The gateway includes a configuration table (30) that indicates, for each possible current operating mode (M) and for each communication channel to be monitored, a value for at least one configuration parameter defining the security policy.