Dynamic Onboard Firewall Exceptions for Airline Bandwidth Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Passengers on flights often do not utilize Internet-based applications on their portable electronic devices due to the need to purchase and manage Internet access, which is costly and requires passengers to balance access costs with application benefits, leading to underutilization of these services. Current whitelist-based solutions are cumbersome and costly to maintain, and do not allow for precise application-specific control over onboard firewalls.

Innovation Solution

A system that dynamically implements exceptions in onboard network firewalls to allow Internet connectivity for specific applications, enabling application providers to subsidize costs and manage access without passenger intervention, using a remote application service to authorize connectivity based on network conditions and application provider agreements, and incorporating a Bluetooth Low Energy beacon notification system to alert devices of available connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If whitelist-based solutions are used to control firewall access, then Internet connectivity can be provided to multiple applications, but the system becomes cumbersome and costly to maintain with imprecise control

Engineering Contradiction:
Improvefirewall access controlVSAvoidwhitelist maintenance
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the firewall control mechanism from the application layer, creating a separate connectivity manager service that handles authorization. This separates the complex whitelist maintenance tasks from the firewall itself, allowing precise application-specific control without burdening the firewall configuration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The connectivity manager acts as an intermediary between applications and the firewall. It receives authorization requests from applications, evaluates them against policy, and dynamically implements firewall exceptions. This mediator handles the complexity of access control logic centrally rather than through cumbersome whitelist maintenance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of energy

If passengers purchase Internet access subscriptions, then bandwidth costs are covered, but usage is limited and passengers must balance access costs with application benefits

Engineering Contradiction:
Improvebandwidth costVSAvoidaccess management
Core Design Contradiction:
Loss of energyVSEase of operation

Solution Approach 1:

The system enables applications to self-authorize for connectivity by presenting their own identity and policy credentials to the connectivity manager. Applications autonomously manage their access rights without requiring passenger intervention or complex subscription management, making the system easier to operate while maintaining cost recovery.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The firewall exceptions are dynamically implemented based on real-time authorization decisions rather than static whitelist configurations. This allows the system to adapt connectivity permissions flexibly according to application needs and policy conditions, improving ease of operation while maintaining cost control.

Inventive Principle:
Principle #15Dynamics

3Productivity

If Internet access is provided during peak times, then application usage increases, but service quality degrades for paying customers

Engineering Contradiction:
Improveapplication usageVSAvoidservice quality
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system changes the parameter of firewall exception duration dynamically. Authorization grants are time-limited and can be revoked or adjusted based on current network conditions. This allows the system to permit higher usage during off-peak times while maintaining service quality for paying customers during peak periods by controlling the duration and scope of exceptions.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The connectivity manager monitors network conditions and uses this feedback to make real-time decisions about authorization requests. When network congestion is detected, the system can deny or limit new authorization grants, thereby protecting service quality for paying customers while still allowing application usage to increase during favorable conditions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3220599B1System for demand -based regulation of dynamically implemented firewall exceptions
Publication Date: 2019.06.19 PANASONIC AVIONICS CORP
  • EP3220599B1 patent drawingFigure 1
  • EP3220599B1 patent drawingFigure 2
  • EP3220599B1 patent drawingFigure 3A

AI summary

A system for regulating dynamic implementation of exceptions in an onboard network firewall includes a client application interface receptive to a data link request from a client device. An onboard connectivity manager includes a firewall interface connected to the onboard network firewall to request the exceptions in response to a connection authorization, a client presence manager receptive to the data link request relayed by the client application interface from the client device, and a network load manager in communication with the firewall interface and the client presence manager. A remote connectivity manager is connected to a remote application service and is in communication with the onboard connectivity manager. The network load manager generates the connection authorization to the firewall interface in response to the connection authorization request and an evaluation of one or more access grant conditions.