Avionics Securing Engine Widget Integrity Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Client-server systems in avionics face challenges in implementing integrity checks for critical functions, particularly in ensuring that user interactions are processed correctly and consistently, and preventing accidental or untimely triggering of functions.

Innovation Solution

A securing engine is implemented, utilizing mathematical signatures and guard mechanisms to verify the integrity of widgets and their interactions, ensuring that commands are validated before execution and that the state of secured widgets is confirmed by the client before changing, thereby preventing unintended modifications or activations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a client-server system is implemented in avionics with standard architecture, then system functionality and interactivity are improved, but system integrity and safety are compromised due to lack of validation mechanisms

Engineering Contradiction:
Improvesystem functionalityVSAvoidsystem integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary validation actions by computing cryptographic signatures of widget models and comparing them against expected values before executing any user interactions or commands. This pre-validation mechanism ensures that only authorized and unmodified widgets can receive and process user inputs, preventing integrity violations before they occur

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary validation layer between the client-server communication and widget execution. This intermediary computes and verifies cryptographic signatures, acting as a mediator that filters and validates all interactions before they reach the widget model, thus maintaining system integrity while preserving full client-server functionality

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If integrity check mechanisms are added to validate user interactions, then system safety is improved, but system complexity increases due to additional validation layers

Engineering Contradiction:
Improvesystem safetyVSAvoidvalidation mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms the integrity validation problem from a complex structural verification task into a simple parameter comparison task. By computing a cryptographic signature (a numerical parameter) from the widget model and comparing it against an expected value, the system reduces complex integrity checking to a straightforward parameter validation operation

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces traditional mechanical or procedural integrity checking mechanisms with cryptographic validation. Instead of using complex rule-based validation systems, the patent uses mathematical cryptographic functions to generate and verify signatures, substituting elaborate validation logic with elegant mathematical operations

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If cryptographic validation is performed on all widget interactions, then prevention of accidental triggering is improved, but processing time increases due to signature computation and verification

Engineering Contradiction:
Improveprevention of accidental triggeringVSAvoidvalidation processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs the computationally intensive signature computation in advance, during widget model initialization or modification, rather than during each user interaction. The pre-computed signatures are stored and quickly verified during runtime interactions, shifting the time cost from frequent small operations to less frequent larger operations

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8812865B2Secured client-server computer system for interactive applications
Publication Date: 2014.08.19 THALES SA
  • US8812865B2 patent drawing
  • US8812865B2 patent drawing
  • US8812865B2 patent drawing

AI summary

A client-server type computer system for graphical applications is provided, that is to say, for displaying data in the form of software units called “widgets” on display screens called “display units”, said system being intended to control the operation of a machine, the machine including at least one human-machine interface allowing interaction with the widgets, said system managing critical data or functions. The computer system includes a securing engine controlling the integrity of the display of the critical widgets, the sending of commands which is performed by means of the human-machine interface, the input and display of the critical data. The main provisions of this securing engine are the use of computer “signatures”, the provision of “feedback” circuits and the use of guard mechanisms or dedicated confirmation dialog boxes. Preferably, the machine is an aircraft, the computer system is the avionics on board said aircraft and the display screens are the cockpit display systems.