Cabin Virtual Router for Aircraft Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Onboard network systems in passenger aircraft face security challenges due to shared access by multiple users, including passengers and flight crew, which can lead to potential security threats that compromise the integrity of the network, especially when handling critical operations.

Innovation Solution

Implementing a cabin virtual router that receives and analyzes requests from passenger devices, determines security threats, and performs appropriate security operations such as disabling the router, switching to a more secure operating system, or modifying requests to mitigate risks, while maintaining a security log for updates and fleet-wide security enhancements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the onboard network system allows shared access by multiple passenger devices, then network usability and convenience are improved, but security risk increases

Engineering Contradiction:
Improvenetwork usabilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The network system is segmented into multiple Virtual Routing Instances (VRIs), each handling specific traffic types (passenger devices, flight crew devices, critical systems). This segmentation isolates security threats to specific segments while maintaining overall network functionality and usability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtual router acts as an intermediary between passenger devices and the critical flight systems. It monitors, analyzes, and controls all traffic passing through it, blocking malicious traffic before it can reach critical systems while allowing legitimate traffic to pass through seamlessly.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If the virtual router disables operation to block high security threats, then security protection is improved, but network functionality deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidnetwork functionality
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The virtual router dynamically adjusts its security operations based on real-time threat assessment. When a high-severity threat is detected, it disables only the affected VRI while maintaining other VRIs operational, providing dynamic security response without complete network shutdown.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

By segmenting network traffic into multiple VRIs, the system can isolate and disable only the specific VRI affected by a security threat, rather than disabling the entire network. This maintains network functionality for unaffected traffic segments.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If the system performs comprehensive security analysis on each request, then security detection accuracy is improved, but processing time increases

Engineering Contradiction:
Improvesecurity detection accuracyVSAvoidrequest processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

Different levels of security analysis are applied to different traffic types and sources. Passenger devices receive standard security scanning, while flight crew devices and critical systems receive enhanced security verification. This localized quality approach optimizes detection accuracy without uniformly increasing processing time for all traffic.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10820196B2Onboard network systems for passenger aircraft and methods of operating thereof
Publication Date: 2020.10.27 THE BOEING CO
  • US10820196B2 patent drawing
  • US10820196B2 patent drawing
  • US10820196B2 patent drawing

AI summary

Disclosed are onboard network systems for passenger aircrafts and methods of operating thereof. Specifically, an onboard network system is configured to handle various requests (e.g., communication, entertainment) from passenger devices during aircraft operation. Each request is first received at a cabin virtual router, which determines the security threat associated with this request and, if the security threat exceeds a security threshold, performs a corresponding security operation. In some examples, the cabin virtual router is configured to disable its operation entirely, e.g., if the security threat is high. In other examples, the cabin virtual router switches to a new operating system and/or throttles its operation. The cabin virtual router effectively isolates other components of the onboard network system (e.g., a flight deck) from potential threats associated with the passenger devices using this system. Security threats are analyzed to reconfigure the cabin virtual router on the aircraft and/or entire fleet.