Microcontroller Memory Access Monitoring for Avionics Safety

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current avionics systems require complex and costly ASIC components for AFDX interfaces, which pose safety risks due to potential undetected erroneous information, and there is a need for a simpler and less expensive solution that ensures safety.

Innovation Solution

Embedding a processor, memory, and communication module within a microcontroller, with a shared memory access monitoring module to detect unauthorized access and trigger interrupts or resets, and using a checksum for data frames to prevent transmission of erroneous data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a specific electronic component of the ASIC type is developed to fulfill the function of an AFDX interface, then the interface function is provided, but the device complexity and cost increase significantly

Engineering Contradiction:
Improvedesign assurance levelVSAvoidASIC component complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the processor and communication module into a single microcontroller unit, eliminating the need for separate ASIC components. The microcontroller integrates the AFDX interface functionality directly within its architecture, reducing overall system complexity while maintaining the required design assurance levels through unified hardware-software co-design.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The microcontroller serves multiple functions simultaneously - it acts as both the processor for critical flight control functions and the communication module for AFDX interface operations. This multi-functional approach replaces the need for dedicated ASIC components, reducing device complexity while ensuring reliability through a single validated platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a specific electronic component of the ASIC type is developed to fulfill the function of an AFDX interface, then the interface function is provided, but the manufacturing cost increases

Engineering Contradiction:
Improvedesign assurance levelVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

By combining the processor and communication module into a single microcontroller, the patent eliminates the need for separate ASIC development, fabrication, and assembly processes. This integration significantly reduces manufacturing costs while maintaining design assurance through a single component validation approach.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent replaces expensive, custom-developed ASIC components with commercially available microcontrollers that offer comparable functionality at lower cost. This substitution leverages the economies of scale in commercial microcontroller production to reduce manufacturing expenses while maintaining required reliability levels.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Device complexity

If the processor and communication module share a common memory through a common bus, then the device complexity is reduced, but the risk of unauthorized access and safety risks increase

Engineering Contradiction:
Improvesystem integrationVSAvoidunauthorized memory access risk
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent implements memory access monitoring before potential unauthorized access can occur. The monitoring module continuously tracks memory access patterns and proactively detects attempts by the communication module to access unauthorized address areas, triggering interrupts or resets to prevent safety-critical errors before they can propagate.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a memory access monitoring module as an intermediary between the communication module and the shared memory. This mediator monitors and controls memory access requests, allowing legitimate communication operations while blocking unauthorized access to processor-controlled memory areas, thus enabling shared memory architecture without compromising safety.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8527714B2Secure avionics equipment and associated method of making secure
Publication Date: 2013.09.03 SAFRAN ELECTRONICS & DEFENSE (FR)
  • US8527714B2 patent drawing
  • US8527714B2 patent drawing
  • US8527714B2 patent drawing

AI summary

This invention relates, according to a first aspect, to electronic equipment comprising a processor (2), a memory (11) and a communication module (3) ensuring an interface with an avionics data network. The communication module (3) and the processor (2) are embedded within a microcontroller (1) so that the memory (11) is shared between the processor and the communication module. The electronic equipment also includes a module for monitoring the accesses to the memory (17) which are configured so as to detect an access of the communication module (3) into an unauthorized address area (12) of the memory (11). According to a second aspect, the invention relates to a method of making a processor secure against the failures of a complex peripheral.