Multi-Level Security Gateway for Mobile Avionics Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of data and applications from mobile computing platforms into certified avionics systems poses a security risk due to varying levels of integrity and the need for dynamic security management, especially when handling sensitive information across different user classes and operational domains.

Innovation Solution

A multi-level adaptive security structure is implemented in a mobile computing platform to authenticate data and applications, featuring a gateway function that provides a secure interface for different levels of applications and services, ensuring secure integration with certified avionics systems by identifying and managing appropriate security protocols and credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If mobile computing platforms are integrated with certified avionics systems, then functionality and versatility are improved, but security risks increase due to varying levels of data integrity

Engineering Contradiction:
ImprovefunctionalityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a multi-level security architecture that segments the avionics system into different security zones (e.g., unclassified, classified, top secret). Each zone has its own authentication and authorization mechanisms, allowing mobile devices to access appropriate data based on their security clearance level without compromising the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security gateway or broker as an intermediary component between mobile computing platforms and certified avionics systems. This intermediary authenticates mobile devices, authorizes their access rights, and mediates data exchange to ensure that only approved data is transferred between different security domains.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If dynamic security management is implemented for different user classes, then security adaptability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity adaptabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic security management where authentication and authorization parameters are adjusted in real-time based on user identity, data sensitivity level, and operational context. Security policies can be dynamically updated without requiring system reconfiguration, allowing the system to adapt to new threats and requirements.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes security parameters (such as authentication methods, encryption strength, and access controls) based on the specific requirements of different user classes and data types. The system can switch between different security protocols and parameter sets dynamically, providing appropriate security without manual intervention.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If multi-level security authentication is implemented, then data protection is improved, but processing time increases

Engineering Contradiction:
Improvedata protectionVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary authentication actions during device registration and initial login, establishing security credentials and authorization tokens in advance. Once authenticated, users can access protected data without repeating the full authentication process, reducing processing time for subsequent data requests while maintaining strong security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial authentication for low-risk data access and full authentication only for high-sensitivity data. The system can use simplified authentication mechanisms (such as token validation) for routine operations and reserve complex authentication processes for critical data, optimizing the balance between security and processing time.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9092611B1Adaptive, multi-level security for flight deck applications hosted on mobile platforms
Publication Date: 2015.07.28 ROCKWELL COLLINS INC
  • US9092611B1 patent drawing
  • US9092611B1 patent drawing
  • US9092611B1 patent drawing

AI summary

A mobile computing platform for processing data in an environment requiring multiple levels of authentication may include processes to authenticate various applications at each of the multiple levels. The mobile computing platform may integrate with aircraft avionics to provide data from applications to a certified avionics system.