Cabin Virtual Router for Aircraft Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Onboard network systems in passenger aircraft face security challenges due to shared access by multiple users, including passengers and flight crew, which can lead to potential security threats that compromise the integrity of the network, especially when handling critical operations.
Innovation Solution
Implementing a cabin virtual router that receives and analyzes requests from passenger devices, determines security threats, and performs appropriate security operations such as disabling the router, switching to a more secure operating system, or modifying requests to mitigate risks, while maintaining a security log for updates and fleet-wide security enhancements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the onboard network system allows shared access by multiple passenger devices, then network usability and convenience are improved, but security risk increases
Solution Approach 1:
The network system is segmented into multiple Virtual Routing Instances (VRIs), each handling specific traffic types (passenger devices, flight crew devices, critical systems). This segmentation isolates security threats to specific segments while maintaining overall network functionality and usability.
Solution Approach 2:
The virtual router acts as an intermediary between passenger devices and the critical flight systems. It monitors, analyzes, and controls all traffic passing through it, blocking malicious traffic before it can reach critical systems while allowing legitimate traffic to pass through seamlessly.
2Object-affected harmful factors
If the virtual router disables operation to block high security threats, then security protection is improved, but network functionality deteriorates
Solution Approach 1:
The virtual router dynamically adjusts its security operations based on real-time threat assessment. When a high-severity threat is detected, it disables only the affected VRI while maintaining other VRIs operational, providing dynamic security response without complete network shutdown.
Solution Approach 2:
By segmenting network traffic into multiple VRIs, the system can isolate and disable only the specific VRI affected by a security threat, rather than disabling the entire network. This maintains network functionality for unaffected traffic segments.
3Measurement precision
If the system performs comprehensive security analysis on each request, then security detection accuracy is improved, but processing time increases
Solution Approach 1:
Different levels of security analysis are applied to different traffic types and sources. Passenger devices receive standard security scanning, while flight crew devices and critical systems receive enhanced security verification. This localized quality approach optimizes detection accuracy without uniformly increasing processing time for all traffic.
Data Source
AI summary
Disclosed are onboard network systems for passenger aircrafts and methods of operating thereof. Specifically, an onboard network system is configured to handle various requests (e.g., communication, entertainment) from passenger devices during aircraft operation. Each request is first received at a cabin virtual router, which determines the security threat associated with this request and, if the security threat exceeds a security threshold, performs a corresponding security operation. In some examples, the cabin virtual router is configured to disable its operation entirely, e.g., if the security threat is high. In other examples, the cabin virtual router switches to a new operating system and/or throttles its operation. The cabin virtual router effectively isolates other components of the onboard network system (e.g., a flight deck) from potential threats associated with the passenger devices using this system. Security threats are analyzed to reconfigure the cabin virtual router on the aircraft and/or entire fleet.


