Microcontroller Memory Access Monitoring for Avionics Safety
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current avionics systems require complex and costly ASIC components for AFDX interfaces, which pose safety risks due to potential undetected erroneous information, and there is a need for a simpler and less expensive solution that ensures safety.
Innovation Solution
Embedding a processor, memory, and communication module within a microcontroller, with a shared memory access monitoring module to detect unauthorized access and trigger interrupts or resets, and using a checksum for data frames to prevent transmission of erroneous data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a specific electronic component of the ASIC type is developed to fulfill the function of an AFDX interface, then the interface function is provided, but the device complexity and cost increase significantly
Solution Approach 1:
The patent merges the processor and communication module into a single microcontroller unit, eliminating the need for separate ASIC components. The microcontroller integrates the AFDX interface functionality directly within its architecture, reducing overall system complexity while maintaining the required design assurance levels through unified hardware-software co-design.
Solution Approach 2:
The microcontroller serves multiple functions simultaneously - it acts as both the processor for critical flight control functions and the communication module for AFDX interface operations. This multi-functional approach replaces the need for dedicated ASIC components, reducing device complexity while ensuring reliability through a single validated platform.
2Reliability
If a specific electronic component of the ASIC type is developed to fulfill the function of an AFDX interface, then the interface function is provided, but the manufacturing cost increases
Solution Approach 1:
By combining the processor and communication module into a single microcontroller, the patent eliminates the need for separate ASIC development, fabrication, and assembly processes. This integration significantly reduces manufacturing costs while maintaining design assurance through a single component validation approach.
Solution Approach 2:
The patent replaces expensive, custom-developed ASIC components with commercially available microcontrollers that offer comparable functionality at lower cost. This substitution leverages the economies of scale in commercial microcontroller production to reduce manufacturing expenses while maintaining required reliability levels.
3Device complexity
If the processor and communication module share a common memory through a common bus, then the device complexity is reduced, but the risk of unauthorized access and safety risks increase
Solution Approach 1:
The patent implements memory access monitoring before potential unauthorized access can occur. The monitoring module continuously tracks memory access patterns and proactively detects attempts by the communication module to access unauthorized address areas, triggering interrupts or resets to prevent safety-critical errors before they can propagate.
Solution Approach 2:
The patent introduces a memory access monitoring module as an intermediary between the communication module and the shared memory. This mediator monitors and controls memory access requests, allowing legitimate communication operations while blocking unauthorized access to processor-controlled memory areas, thus enabling shared memory architecture without compromising safety.
Data Source
AI summary
This invention relates, according to a first aspect, to electronic equipment comprising a processor (2), a memory (11) and a communication module (3) ensuring an interface with an avionics data network. The communication module (3) and the processor (2) are embedded within a microcontroller (1) so that the memory (11) is shared between the processor and the communication module. The electronic equipment also includes a module for monitoring the accesses to the memory (17) which are configured so as to detect an access of the communication module (3) into an unauthorized address area (12) of the memory (11). According to a second aspect, the invention relates to a method of making a processor secure against the failures of a complex peripheral.


