End-to-End Integrity Check for Time-Sensitive Ethernet Streams

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current time-sensitive Ethernet networks fail to meet the robustness requirements of the ARINC 664 P7 standard, particularly in terms of network equipment malfunctions, and are not optimally implemented in commercial off-the-shelf products, which are less expensive and more bandwidth-efficient.

Innovation Solution

A method for checking the end-to-end integrity of communication streams in a time-sensitive network using a virtual identifier and a transmission aggregate, calculated using a hash function, to ensure message integrity and authenticity, which is not transmitted and thus not interceptable, reducing the risk of reconstitution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If ARINC 664 P7 standard is implemented within AFDX network, then network robustness against equipment malfunctions is improved, but device complexity and cost increase due to proprietary IT equipment requirements

Engineering Contradiction:
Improvenetwork robustnessVSAvoidequipment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies the copying principle by creating a virtual identifier that replicates the security function of proprietary AFDX equipment without requiring actual proprietary hardware. The virtual identifier is computed locally at each endpoint using the same algorithm as the proprietary system, enabling COTS devices to achieve AFDX-like robustness through software-based replication rather than hardware emulation.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical/properitary hardware system with a software-based solution. Instead of requiring specialized AFDX equipment with built-in security mechanisms, the invention substitutes these with standard Ethernet devices running software that computes virtual identifiers and performs integrity checks, thereby eliminating the need for complex proprietary hardware while maintaining security functions.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If ARINC 664 P7 standard is implemented within AFDX network, then message integrity and authenticity are ensured, but bandwidth efficiency deteriorates due to proprietary protocol overhead

Engineering Contradiction:
Improvemessage integrityVSAvoidbandwidth efficiency
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts the essential security function from the proprietary AFDX protocol envelope. By separating the integrity check mechanism (virtual identifier computation) from the physical AFDX frame structure, the solution enables use of standard Ethernet framing, thereby eliminating redundant proprietary headers and improving bandwidth efficiency while maintaining message integrity through the extracted security function.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the protocol parameters by using standard Ethernet frame formats instead of proprietary AFDX frames. The virtual identifier is computed using the same mathematical principles as AFDX but applied to standard Ethernet packets, achieving AFDX-level integrity with Ethernet-level bandwidth efficiency by changing the framing parameters rather than the underlying security algorithm.

Inventive Principle:
Principle #35Parameter changes

3Ease of manufacture

If standard COTS products are used, then cost and bandwidth efficiency are improved, but network robustness against malfunctions deteriorates due to inability to guarantee frame transmission without alteration

Engineering Contradiction:
Improvecost efficiencyVSAvoidnetwork robustness
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent enables COTS products to achieve AFDX-level robustness by copying the security function through virtual identifiers. Each endpoint independently computes the virtual identifier using the same algorithm, creating a distributed verification system that doesn't rely on proprietary hardware but provides equivalent guarantees against frame alteration and equipment malfunction.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent implements feedback through the verification process where the receiving endpoint computes the expected virtual identifier and compares it with the received value. This feedback mechanism enables detection of frame alterations and transmission errors, providing robustness verification without requiring proprietary equipment, thereby achieving both cost efficiency and network reliability.

Inventive Principle:
Principle #23Feedback

4Adaptability or versatility

If CRC calculation function is implemented in COTS products, then protocol support capability is improved, but reliability deteriorates due to ability to reconstruct Ethernet frames

Engineering Contradiction:
Improveprotocol supportVSAvoidframe transmission integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent addresses this contradiction by copying the security function at the application layer through virtual identifiers rather than relying on data link layer CRC mechanisms. This allows COTS Ethernet devices to maintain their universal protocol support while achieving superior integrity guarantees, as the virtual identifier verification occurs after frame reconstruction and cannot be bypassed by standard Ethernet processing.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20240205123A1End-to-end integrity check of a communication stream
Publication Date: 2024.06.20 THALES SA
  • US20240205123A1 patent drawing
  • US20240205123A1 patent drawing

AI summary

A method of integrity control, an allocation of virtual identifier, to each stream, only known to each transmitter or receiver, located at one end of the stream, a transmission by a transmitter at the end of a stream, of a message including the payload, the value of a counter of transmitted messages, and a transmission aggregate determined from the virtual identifier known to the transmitter, the value, the payload, the reception by a receiver, at the other end of the stream, of the message, and determination of a reception aggregate from the virtual identifier known to the receiver, the value received, the payload received, the end-to-end integrity check by comparing transmission and reception aggregates.