Avionics Ethernet Security via Layered COTS Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Commercial Off-The-Shelf (COTS) networking systems in avionics pose security risks due to their open architecture, leading to increased costs and operational limitations when securing interfaces, necessitating a robust and cost-effective solution for network security within critical systems.
Innovation Solution
A method for identifying and responding to unauthorized transmissions in networked critical systems by analyzing pre-defined parameters associated with trusted sources and destinations, including physical and logical sources, payload integrity, and application levels, using system level checks and safety monitors to enable secure access and immediate responses to threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If COTS networking systems are used in avionics, then cost and availability are improved, but security risks increase
Solution Approach 1:
The patent segments security functionality into multiple independent layers including physical layer authentication, data link layer filtering, network layer validation, and application layer monitoring. Each layer operates independently to provide comprehensive security coverage while maintaining COTS cost-effectiveness
Solution Approach 2:
The patent introduces intermediary security devices and protocols between COTS networking components and critical avionics systems. These intermediaries authenticate transmissions, filter malicious traffic, and monitor network activity without requiring expensive proprietary avionics security hardware
2Object-affected harmful factors
If traditional avionics interfaces are used to increase security, then security level is improved, but cost increases
Solution Approach 1:
The patent employs inexpensive, easily replaceable security monitoring devices and software-based security functions that can be deployed across multiple COTS network nodes. These lightweight security elements provide adequate protection without the high cost of traditional avionics security interfaces
Solution Approach 2:
The patent creates universal security protocols and authentication mechanisms that can be applied across multiple COTS networking interfaces and protocols simultaneously, eliminating the need for dedicated expensive security hardware for each interface type
3Object-affected harmful factors
If COTS interfaces are provisioned with security measures, then security is improved, but operational limitations increase
Solution Approach 1:
The patent implements dynamic security monitoring that adapts to operational conditions in real-time. Security parameters such as authentication requirements and traffic filtering rules are adjusted dynamically based on system state, threat level, and operational mode, maintaining security while minimizing operational constraints
Data Source
AI summary
A system and method is disclosed for identification and response to an unauthorized transmission to a networked critical system. The invention employs a pre-defined parameter which matches trusted sources with defined destinations to enable secure access to the networked critical system. Once the method receives a transmission to the destination, it filters the transmissions based on specific architecture constraints. Should the transmission survive, the method continues with a plurality of layers of system level checks to verify the source matches the pre-defined parameter of a trusted source. Should the transmission fail any of the layers of system level checks, the method provides an appropriate response. Once the transmission survives, the method continuously monitors the data stream for possible threats and allows access the transmission to reach the destination and the networked critical system.


