Flight Management System Cyber Security Failover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Aircraft systems face potential flight risks due to the vulnerability of their networked domains to cyber security threats, allowing hackers to access and compromise critical flight, weapons, and communications systems.

Innovation Solution

The implementation of a flight management system comprising a primary and mirror system with configuration lockdowns, firewalls, and a monitoring system that continuously verifies and locks down file counts, sizes, and system states, enabling failover to a mirrored domain in case of detected threats and ensuring only trusted data is disseminated to the domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If domains are networked together to enable bi-directional communication, then system connectivity and data sharing are improved, but vulnerability to cyber security threats increases

Engineering Contradiction:
Improvesystem connectivityVSAvoidcyber security vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system divides the aircraft's technical domains into separate virtualized environments running on isolated servers. Each domain (flight, weapons, communications) operates in its own virtualized space with controlled access, preventing lateral movement of cyber threats while maintaining necessary data sharing through secure interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A security monitoring and management system acts as an intermediary layer between networked domains. This intermediary continuously monitors communications, detects anomalies, and enforces security policies, allowing domains to remain connected while protecting against cyber threats through active intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If external network access is enabled for data reception, then information gathering capability is improved, but exposure to external cyber threats increases

Engineering Contradiction:
Improveinformation gathering capabilityVSAvoidexternal cyber threat exposure
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security assessments and validations on all incoming external data before it reaches internal domains. Data packets are scanned, authenticated, and verified against security policies in advance, allowing the system to maintain external connectivity while blocking malicious content before it can cause harm.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Incoming external data is first copied to a isolated sandbox environment for analysis and validation. The original data path remains protected while the copy undergoes security checking, allowing the system to evaluate external information safely before deciding whether to accept it into the main system.

Inventive Principle:
Principle #26Copying

3Reliability

If configuration lockdown is implemented on domains, then system security and integrity are improved, but system flexibility and update capability deteriorate

Engineering Contradiction:
Improvesystem integrityVSAvoidsystem flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The configuration lockdown system implements dynamic access controls that adapt based on operational context. Security restrictions are not static but change according to flight phase, threat level, and data sensitivity, allowing the system to maintain strict security when needed while permitting necessary updates and configurations under controlled conditions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system continuously monitors configuration changes and system state, providing feedback to the security management layer. This feedback loop enables automated responses to security events while allowing legitimate configuration updates, balancing the need for lockdown with the need for system adaptability through intelligent, context-aware control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11394782B2Flight management systems and methods
Publication Date: 2022.07.19 DONAHUE DANIEL
  • US11394782B2 patent drawing
  • US11394782B2 patent drawing
  • US11394782B2 patent drawing

AI summary

A flight management system of the present disclosure has an internal network that uses an open architecture concept with no single point of failure of critical system and which is cyber secure for aviation assets. A flight management system of the present disclosure comprises an internal network operating on an aircraft, and the internal network communicatively coupled to an external network via a firewall. The flight management system further has a primary system installed on the aircraft, which is initially active, and the primary system has a first weapons domain communicatively coupled to the internal network, a first flight domain communicatively coupled to the internal network, and a first communications domain communicatively coupled to the internal network. The flight management system also has a mirror system installed on the aircraft, which is initially inactive, and the mirror system has a second weapons domain communicatively coupled to the internal network, a second flight domain communicatively coupled to the internal network, and a second communications domain communicatively coupled to the internal network. Furthermore, the flight management system has a monitoring system separate from the primary system and the mirror system and communicatively coupled to the internal network, and the monitoring system has a processor. The processor monitors, over the internal network, the first weapons domain, the first flight domain, and the first communications domain while active. The processor reboots, over the internal network, the first weapons domain, the first flight domain, or the first communications domain if the first weapons domain, the first flight domain, or the first communications domain change state and the processor activates the second weapons domain if the first weapons domain is rebooted, activates the second flight domain if the first flight domain is rebooted, or activates the second communications domain if the first communication domain is rebooted.