Dynamic Onboard Firewall Exceptions for Airline Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Passengers on flights often refrain from using Internet-based applications due to the cost-benefit calculus of limited Internet access, and existing firewall solutions like whitelists are cumbersome and costly to maintain, lacking precise application-specific control.

Innovation Solution

A system that dynamically implements firewall exceptions, allowing remote application providers to authorize and subsidize Internet connectivity for specific applications, enabling seamless access without passengers needing to purchase separate access, using a connectivity manager and BLE beacons for proactive alerts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a whitelist-based firewall approach is used to control Internet access, then network security is improved, but maintenance complexity and costs increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidfirewall maintenance complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables application providers to self-manage their own firewall exceptions through automated registration and authorization processes. The connectivity manager automatically evaluates requests, checks presence states, and updates firewall rules without requiring manual whitelist maintenance, allowing the system to serve itself

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The connectivity manager acts as an intermediary between application providers and the firewall system. It receives connection requests, evaluates them against presence states and airline policies, then dynamically updates firewall exceptions accordingly, eliminating the need for manual whitelist management while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of energy

If passengers are required to purchase Internet access for application usage, then airline revenue is improved, but passenger convenience deteriorates

Engineering Contradiction:
Improveairline revenueVSAvoidpassenger convenience
Core Design Contradiction:
Loss of energyVSEase of operation

Solution Approach 1:

The system applies different access models to different applications based on their individual presence states and authorization levels. Some applications can operate with provider-subsidized access while others require passenger payment, allowing localized optimization of both revenue and convenience for each application context

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically changes the access parameter (paid vs. free) based on the application's presence state, authorization status, and airline policy. This allows the same infrastructure to support both revenue-generating paid access and convenience-oriented free access scenarios

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If application providers subsidize Internet connectivity costs, then passenger convenience is improved, but bandwidth cost management becomes more complex

Engineering Contradiction:
Improvepassenger convenienceVSAvoidbandwidth cost management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system implements feedback loops where the connectivity manager continuously monitors application usage, presence states, and bandwidth consumption. This feedback enables automated decision-making about which applications receive subsidized access and at what cost levels, managing complexity through continuous adaptation rather than static rules

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The firewall exception system is highly dynamic, automatically creating, modifying, and removing exceptions based on real-time presence states and authorization status. This dynamic approach allows the system to adapt to changing conditions without manual intervention, managing bandwidth cost complexity through automated real-time adjustments

Inventive Principle:
Principle #15Dynamics

4Measurement precision

If firewall exceptions are dynamically created and removed based on presence states, then application-specific control precision is improved, but system complexity increases

Engineering Contradiction:
Improveapplication-specific control precisionVSAvoidfirewall management system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-registering application providers and establishing authorization frameworks before actual connectivity needs arise. Presence states are established in advance, allowing the firewall system to quickly evaluate and execute exceptions without complex real-time decision-making, reducing operational complexity while maintaining precision

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3166278B1System for dynamically implementing firewall exceptions
Publication Date: 2020.05.06 PANASONIC AVIONICS CORP
  • EP3166278B1 patent drawingFigure 1
  • EP3166278B1 patent drawingFigure 2
  • EP3166278B1 patent drawingFigure 3A

AI summary

A system for dynamically implementing exceptions in an onboard network firewall has a client application interface receptive to a data link request from a client device. An onboard connectivity manager includes a firewall interface connected to the onboard network firewall to request the exceptions in response to a connection authorization, and a client presence manager receptive to the data link request relayed by the client application interface from the client device. A presence state for the client devices is activated and maintained following the data link request. A remote connectivity manager is connected to a remote application service and is in communication with the onboard connectivity manager. The remote connectivity manager generates a connection authorization based upon an evaluation of the presence state for the client device against the conditions set by the remote application service.