Data Server Gateway for Avionics Security and Adaptability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems restrict the integration of non-critical data into critical systems, limiting their functionality due to security constraints, which hampers the utilization of critical systems in complex environments like avionics, where data exchange between 'closed world' and 'open world' systems is restricted.

Innovation Solution

A computer assembly with a data server that includes digital and physical interfaces for bidirectional data transmission and transformation, ensuring secure data exchange between critical and non-critical systems, utilizing unique identifiers and specific protocols like URI, REST, NMEA, and wireless interfaces to enable secure data sharing and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If critical systems are isolated as closed worlds to maintain security, then security level is improved, but adaptability deteriorates

Engineering Contradiction:
Improvesecurity levelVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a gateway as an intermediary component between the critical closed-world system and non-critical open-world systems. This gateway acts as a controlled interface that enables data exchange while maintaining security boundaries. The gateway validates and translates data between different worlds, allowing the critical system to access external data sources without direct exposure to untrusted environments, thus resolving the contradiction between security isolation and adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is segmented into distinct functional zones: the critical closed-world core system, the gateway interface layer, and external open-world data sources. This segmentation allows each component to operate with appropriate security levels - the critical core remains isolated while the gateway handles external communications. By dividing the system architecture, the patent enables selective data exchange without compromising the security integrity of the critical components.

Inventive Principle:
Principle #1Segmentation

2Reliability

If data exchange between critical and non-critical systems is restricted, then security is maintained, but functionality deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidfunctionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The gateway serves as a mediator that enables controlled data exchange between critical and non-critical systems. It implements security policies that allow necessary data flows while blocking unauthorized access. The gateway can translate data formats, validate data integrity, and enforce access control rules, thus enabling enhanced functionality through external data sources without compromising security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically adjusts data exchange parameters based on security context and data type. The gateway can modify data formats, apply transformation rules, and control transmission parameters to ensure that only authorized and validated data enters the critical system. This parameter control enables flexible functionality while maintaining security boundaries through adaptive data processing.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If consumer computing devices are integrated into critical systems, then adaptability is improved, but security deteriorates

Engineering Contradiction:
ImproveusabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The gateway acts as a protective intermediary between consumer computing devices and the critical system core. It provides a controlled interface that allows usability benefits from consumer devices (such as tablets, smartphones, or external computers) while preventing direct access to critical components. The gateway validates all interactions, ensuring that consumer devices can enhance system functionality without introducing security vulnerabilities to the critical infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3340565B1Unit for the identification, sharing and management of data comprising critical and non-critical data
Publication Date: 2022.11.02 THALES SA
  • EP3340565B1 patent drawingFigure 1

AI summary

The general field of the invention is that of computer systems for identification and data management, said computer system comprising a server (11) including software ensuring a determined function transforming input data into output data.The computer system according to the invention comprises: - A first system (20) and a second system (30, 40), the first system being a critical system; - A first digital interface (14) ensuring the control of the data identifier and the bidirectional transmission of data between the server and the critical system; - A first physical interface (15) ensuring the physical link between the first digital interface and the critical system; - A second digital interface (12, 16, 17) ensuring the control and bidirectional transmission of data between the server and the second system; - A second physical interface (13, 18) ensuring the physical link between the second digital interface and the second system.