Hierarchical Trust Assessment for Avionics Subsystems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional centralized trust assessment modules in avionics systems limit system robustness by requiring subsystems to rely on outputs from other subsystems without the ability to make trust assessments, leading to vulnerabilities when a parent subsystem fails or is compromised.
Innovation Solution
A hierarchical integrated trust assessment system (HITAS) that locally assesses aircraft subsystem inputs, outputs, and state, verifying data authenticity and processing within expected bounds, allowing for override of faulty subsystems and certification of individual subsystems rather than the entire aircraft.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a centralized trust assessment module is used to assess trust for the entire avionics system, then system integration is simplified, but system robustness and reliability deteriorate because subsystems cannot independently assess trust when parent subsystems fail or are compromised
Solution Approach 1:
The patent divides the centralized trust assessment module into multiple distributed trust assessment modules, with each module responsible for assessing trust within its own subsystem. This segmentation allows independent trust evaluation at the subsystem level, preventing single points of failure and improving system robustness while maintaining manageable complexity through modular architecture
Solution Approach 2:
The patent introduces a hierarchical dimension to trust assessment, operating at two levels: subsystem-level distributed assessment and system-level centralized coordination. This multi-dimensional approach enables local autonomy for reliability while maintaining global integration, resolving the contradiction between centralized simplicity and distributed robustness
2Device complexity
If a centralized trust assessment module is used to assess trust for the entire avionics system, then single-point assessment is achieved, but adaptability and ease of subsystem replacement deteriorate because entire aircraft recertification is required for subsystem changes
Solution Approach 1:
The patent segments the certification and trust assessment scope to the subsystem level rather than requiring system-wide certification. Each distributed trust assessment module independently evaluates its subsystem, allowing individual subsystems to be replaced or upgraded without affecting other subsystems' certifications, thereby improving adaptability while maintaining manageable assessment complexity
Solution Approach 2:
The patent enables subsystems to perform self-assessment of trust through distributed trust modules, allowing autonomous verification of subsystem integrity and functionality. This self-service capability eliminates the need for external system-wide recertification when subsystems are replaced, enhancing adaptability and versatility
3Device complexity
If subsystems rely on outputs from other subsystems without local trust assessment capability, then system integration is simplified, but vulnerability to parental subsystem failures increases
Solution Approach 1:
The patent implements preliminary trust assessment at the source within each subsystem before data is exchanged or used by other subsystems. Each distributed trust module evaluates the trustworthiness of its own subsystem's outputs and inputs in advance, preventing propagation of compromised data and reducing vulnerability to parental subsystem failures while maintaining straightforward integration protocols
Data Source
AI summary
A hierarchical integrated trust assessment system features nested subsystems. Each subsystem utilizes a trust module for validating input data to the subsystem, validating output data from the subsystem, and validating the operation of the subsystem itself. The trust module verifies the format, the authenticity, the content of the inputs to the subsystem. The scope of each trust module is minimized to the associated subsystem. Minimizing the scope of the trust module results in increased reliability of the trust module's decisions.


