In-line Communication Guard for Aircraft Bus Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing interconnection of aircraft systems requires customized devices and installations to protect integrity, leading to high costs due to the need for unique communication components tailored to specific use cases, especially when legacy systems are integrated with new router class devices of lower design assurance levels.
Innovation Solution
A communication guard device is inserted in-line between low and high integrity devices on a communication bus, equipped with a filter that evaluates data transmissions against predefined rules for rate, size, or content type, preventing unauthorized data from passing to high integrity systems, thus enabling generic interfaces for aggregate data processing and reducing the need for customized components.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If customized devices and installations are used to protect system integrity when interconnecting legacy systems with new router class devices, then system integrity is protected, but implementation cost increases
Solution Approach 1:
The communication guard is designed as a universal device that can be deployed across multiple aircraft types and communication bus standards (CAN, LIN, Ethernet). The filter rules are configurable to adapt to different data transmission requirements, allowing a single device design to serve multiple functions and applications, thereby reducing per-implementation cost while maintaining integrity protection
Solution Approach 2:
The communication guard acts as an intermediary device inserted in-line between low integrity devices and high integrity devices on the communication bus. It mediates data transmissions by evaluating packets against filter rules, blocking malicious or non-compliant traffic while allowing legitimate communication, thus protecting system integrity without requiring customization of the endpoint systems
2Reliability
If customized communication components are tailored to specific use cases to ensure data integrity, then data integrity is maintained, but device complexity increases
Solution Approach 1:
The communication guard's functionality is segmented into distinct modular components: a packet receiver, a filter rules engine, an evaluator, and a packet transmitter. Each component has a specific function, making the overall system easier to design, implement, and maintain. The filter rules themselves are segmented into individual criteria (rate, size, content type) that can be independently configured and evaluated
Solution Approach 2:
The communication guard is designed with universal interfaces that support multiple communication bus standards (CAN, LIN, Ethernet). This multi-functionality allows a single device architecture to handle different protocols and applications without requiring separate customized components for each use case, thereby reducing device complexity while maintaining data integrity
3Reliability
If in-line communication guards with filter rules are deployed to evaluate and block non-compliant data transmissions, then data integrity is protected, but device complexity increases
Solution Approach 1:
The communication guard's functionality is segmented into distinct modular components: a packet receiver, a filter rules engine, an evaluator, and a packet transmitter. Each component has a specific function, making the overall system easier to design, implement, and maintain. The filter rules themselves are segmented into individual criteria (rate, size, content type) that can be independently configured and evaluated
Solution Approach 2:
The communication guard autonomously evaluates incoming packets against stored filter rules and automatically blocks non-compliant transmissions without requiring external intervention. The device self-manages the filtering process, making real-time decisions based on configurable criteria, which simplifies deployment and operation while maintaining data integrity
Data Source
AI summary
A communication network includes a low integrity device, a high integrity device, a communication bus communicably coupling the low integrity device and the high integrity device together, and a communication guard inserted in-line along the communication bus. The communication guard includes a filter configured to store one or more rules defining at least one of a rate, a size, or a content type that is permissible for data transmissions from the low integrity device to the high integrity device; receive a respective data transmission from the low integrity device; evaluate characteristics of the respective data transmission relative to the one or more rules; and prevent the respective data transmission from passing through the communication guard to the high integrity device in response to the characteristics of the respective data transmission failing to comply with at least one of the one or more rules.


