Flight Management System Cyber Security Failover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Aircraft systems face potential flight risks due to the vulnerability of their networked domains to cyber security threats, allowing hackers to access and compromise critical flight, weapons, and communications systems.
Innovation Solution
The implementation of a flight management system comprising a primary and mirror system with configuration lockdowns, firewalls, and a monitoring system that continuously verifies and locks down file counts, sizes, and system states, enabling failover to a mirrored domain in case of detected threats and ensuring only trusted data is disseminated to the domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If domains are networked together to enable bi-directional communication, then system connectivity and data sharing are improved, but vulnerability to cyber security threats increases
Solution Approach 1:
The system divides the aircraft's technical domains into separate virtualized environments running on isolated servers. Each domain (flight, weapons, communications) operates in its own virtualized space with controlled access, preventing lateral movement of cyber threats while maintaining necessary data sharing through secure interfaces.
Solution Approach 2:
A security monitoring and management system acts as an intermediary layer between networked domains. This intermediary continuously monitors communications, detects anomalies, and enforces security policies, allowing domains to remain connected while protecting against cyber threats through active intervention.
2Adaptability or versatility
If external network access is enabled for data reception, then information gathering capability is improved, but exposure to external cyber threats increases
Solution Approach 1:
The system performs preliminary security assessments and validations on all incoming external data before it reaches internal domains. Data packets are scanned, authenticated, and verified against security policies in advance, allowing the system to maintain external connectivity while blocking malicious content before it can cause harm.
Solution Approach 2:
Incoming external data is first copied to a isolated sandbox environment for analysis and validation. The original data path remains protected while the copy undergoes security checking, allowing the system to evaluate external information safely before deciding whether to accept it into the main system.
3Reliability
If configuration lockdown is implemented on domains, then system security and integrity are improved, but system flexibility and update capability deteriorate
Solution Approach 1:
The configuration lockdown system implements dynamic access controls that adapt based on operational context. Security restrictions are not static but change according to flight phase, threat level, and data sensitivity, allowing the system to maintain strict security when needed while permitting necessary updates and configurations under controlled conditions.
Solution Approach 2:
The system continuously monitors configuration changes and system state, providing feedback to the security management layer. This feedback loop enables automated responses to security events while allowing legitimate configuration updates, balancing the need for lockdown with the need for system adaptability through intelligent, context-aware control.
Data Source
AI summary
A flight management system of the present disclosure has an internal network that uses an open architecture concept with no single point of failure of critical system and which is cyber secure for aviation assets. A flight management system of the present disclosure comprises an internal network operating on an aircraft, and the internal network communicatively coupled to an external network via a firewall. The flight management system further has a primary system installed on the aircraft, which is initially active, and the primary system has a first weapons domain communicatively coupled to the internal network, a first flight domain communicatively coupled to the internal network, and a first communications domain communicatively coupled to the internal network. The flight management system also has a mirror system installed on the aircraft, which is initially inactive, and the mirror system has a second weapons domain communicatively coupled to the internal network, a second flight domain communicatively coupled to the internal network, and a second communications domain communicatively coupled to the internal network. Furthermore, the flight management system has a monitoring system separate from the primary system and the mirror system and communicatively coupled to the internal network, and the monitoring system has a processor. The processor monitors, over the internal network, the first weapons domain, the first flight domain, and the first communications domain while active. The processor reboots, over the internal network, the first weapons domain, the first flight domain, or the first communications domain if the first weapons domain, the first flight domain, or the first communications domain change state and the processor activates the second weapons domain if the first weapons domain is rebooted, activates the second flight domain if the first flight domain is rebooted, or activates the second communications domain if the first communication domain is rebooted.


