End-to-End Integrity Check for Time-Sensitive Ethernet Streams
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current time-sensitive Ethernet networks fail to meet the robustness requirements of the ARINC 664 P7 standard, particularly in terms of network equipment malfunctions, and are not optimally implemented in commercial off-the-shelf products, which are less expensive and more bandwidth-efficient.
Innovation Solution
A method for checking the end-to-end integrity of communication streams in a time-sensitive network using a virtual identifier and a transmission aggregate, calculated using a hash function, to ensure message integrity and authenticity, which is not transmitted and thus not interceptable, reducing the risk of reconstitution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If ARINC 664 P7 standard is implemented within AFDX network, then network robustness against equipment malfunctions is improved, but device complexity and cost increase due to proprietary IT equipment requirements
Solution Approach 1:
The patent applies the copying principle by creating a virtual identifier that replicates the security function of proprietary AFDX equipment without requiring actual proprietary hardware. The virtual identifier is computed locally at each endpoint using the same algorithm as the proprietary system, enabling COTS devices to achieve AFDX-like robustness through software-based replication rather than hardware emulation.
Solution Approach 2:
The patent replaces the mechanical/properitary hardware system with a software-based solution. Instead of requiring specialized AFDX equipment with built-in security mechanisms, the invention substitutes these with standard Ethernet devices running software that computes virtual identifiers and performs integrity checks, thereby eliminating the need for complex proprietary hardware while maintaining security functions.
2Reliability
If ARINC 664 P7 standard is implemented within AFDX network, then message integrity and authenticity are ensured, but bandwidth efficiency deteriorates due to proprietary protocol overhead
Solution Approach 1:
The patent extracts the essential security function from the proprietary AFDX protocol envelope. By separating the integrity check mechanism (virtual identifier computation) from the physical AFDX frame structure, the solution enables use of standard Ethernet framing, thereby eliminating redundant proprietary headers and improving bandwidth efficiency while maintaining message integrity through the extracted security function.
Solution Approach 2:
The patent changes the protocol parameters by using standard Ethernet frame formats instead of proprietary AFDX frames. The virtual identifier is computed using the same mathematical principles as AFDX but applied to standard Ethernet packets, achieving AFDX-level integrity with Ethernet-level bandwidth efficiency by changing the framing parameters rather than the underlying security algorithm.
3Ease of manufacture
If standard COTS products are used, then cost and bandwidth efficiency are improved, but network robustness against malfunctions deteriorates due to inability to guarantee frame transmission without alteration
Solution Approach 1:
The patent enables COTS products to achieve AFDX-level robustness by copying the security function through virtual identifiers. Each endpoint independently computes the virtual identifier using the same algorithm, creating a distributed verification system that doesn't rely on proprietary hardware but provides equivalent guarantees against frame alteration and equipment malfunction.
Solution Approach 2:
The patent implements feedback through the verification process where the receiving endpoint computes the expected virtual identifier and compares it with the received value. This feedback mechanism enables detection of frame alterations and transmission errors, providing robustness verification without requiring proprietary equipment, thereby achieving both cost efficiency and network reliability.
4Adaptability or versatility
If CRC calculation function is implemented in COTS products, then protocol support capability is improved, but reliability deteriorates due to ability to reconstruct Ethernet frames
Solution Approach 1:
The patent addresses this contradiction by copying the security function at the application layer through virtual identifiers rather than relying on data link layer CRC mechanisms. This allows COTS Ethernet devices to maintain their universal protocol support while achieving superior integrity guarantees, as the virtual identifier verification occurs after frame reconstruction and cannot be bypassed by standard Ethernet processing.
Data Source
AI summary
A method of integrity control, an allocation of virtual identifier, to each stream, only known to each transmitter or receiver, located at one end of the stream, a transmission by a transmitter at the end of a stream, of a message including the payload, the value of a counter of transmitted messages, and a transmission aggregate determined from the virtual identifier known to the transmitter, the value, the payload, the reception by a receiver, at the other end of the stream, of the message, and determination of a reception aggregate from the virtual identifier known to the receiver, the value received, the payload received, the end-to-end integrity check by comparing transmission and reception aggregates.

