Trusted-Untrusted Domain Filter Architecture for Low-Latency Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing firewall and gateway solutions for aircraft communication lack flexibility and simplicity while failing to meet High-Security Assurance Level requirements for secure communication between trusted and untrusted domains.

Innovation Solution

A filter device utilizing a combination of hardware programmable devices, such as FPGAs, and general-purpose CPUs, with modular filter channels comprising hardware and software chains, enabling flexible and scalable data filtering and translation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If software-based firewalls and gateway functions are used, then widespread use and ease of implementation are improved, but security assurance level and detailed evidence for correctness are insufficient

Engineering Contradiction:
Improveease of implementationVSAvoidsecurity assurance level
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The filter device is segmented into distinct hardware filter chains and software filter chains, with hardware components handling high-speed packet filtering and software components handling complex packet inspection and stateful firewall rules. This segmentation allows each component to be optimized for its specific function, achieving both high security assurance and implementability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges hardware-based filtering (for performance and security assurance) with software-based filtering (for flexibility and ease of implementation) into a unified filter device. The hardware programmable device and CPU work together to process packets, combining the advantages of both hardware speed and software flexibility.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If hardware-based filtering is implemented, then security assurance and filtering performance are improved, but device complexity increases

Engineering Contradiction:
Improvesecurity assuranceVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hardware filter chains are further segmented into multiple independent chains that can be configured differently for different traffic types. This allows the hardware complexity to be distributed across multiple simpler, parallel structures rather than one complex monolithic filter.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The filter device incorporates dynamic reconfiguration capabilities where the hardware filter chains can be programmed with different packet filtering rules without physical reconfiguration. This dynamic programming approach reduces the need for complex hardware designs by using programmability to adapt to different security requirements.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If detailed packet inspection is performed, then security filtering accuracy is improved, but processing latency increases

Engineering Contradiction:
Improvefiltering accuracyVSAvoidprocessing latency
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

Packet inspection is segmented into two stages: hardware-based first-stage filtering that performs quick checks and stateful firewall rules at high speed, and software-based second-stage inspection that performs detailed packet analysis. This segmentation allows detailed inspection without overwhelming latency by filtering out the majority of packets at the hardware stage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The hardware filter chains perform partial packet inspection sufficient for high-speed filtering and stateful firewall protection, while leaving detailed inspection to the software stage only when necessary. This partial action approach maintains low latency for most packets while preserving the capability for detailed inspection when needed.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP4564739B1Filter device and method for communication between a trusted domain and an untrusted domain, and computer system
Publication Date: 2026.05.20 AIRBUS OPERATIONS GMBH
  • EP4564739B1 patent drawingFigure 1
  • EP4564739B1 patent drawingFigure 2
  • EP4564739B1 patent drawingFigure 3

AI summary

The present invention provides a filter device (1) for communication between a trusted domain (4) and an untrusted domain (5), comprising: a central processing unit, CPU (2), and a hardware programmable device (3) connected to the CPU (3), the hardware programmable device (3) comprising: a first input/output, I/O, interface (6a) connected to the untrusted domain (5) and a second I/O interface (6b) connected to the trusted domain (4), wherein the first and second I/O interfaces (6a, 6b) are configured to receive and transmit data frames from and to the respective untrusted and trusted domain (4, 5), a first filter channel (7a) configured to filter a first data frame received from the first I/O interface (6a) and provide a first filtered data frame to the second I/O interface (6b), and a second filter channel (7b) configured to filter a second data frame received from the second I/O interface (6b) and provide a second filtered data frame to the first I/O interface (6a); wherein each of the first and second filter channels (7a, 7b) comprises: a hardware filter chain (8) and a software filter chain (9), wherein the hardware filter chain (8) and the software filter chain (9) comprise hardware filter circuitry (10) and the software filter chain (9) comprises software circuitry (11) connected to the CPU (2), a demultiplexer (12) configured to receive the respective first and second data frames from the respective first and second I/O interfaces (6a, 6b), classify data streams of the respective first and second data frames according to at least one attribute, and input the data streams into the hardware filter chain (8) and the software filter chain (9) according to their classification to provide filtered data streams, a multiplexer (13) configured to combine the filtered data streams from the hardware filter chain chain (8) and the software filter chain (9) to provide respective first and second filtered data frames and transmit the first and second filtered data frames to the respective second and first I/O interfaces (6a, 6b). Further the present invention provides a corresponding method for communication between a trusted domain (4) and an untrusted domain (5) and a computer system for an airplane comprising the filter device.