Network Switch Auditing Deterministic Communications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Deterministic networks face challenges in ensuring secure and precise communication by controlling data packets between electronic devices, particularly in aviation and industrial control systems, where unauthorized data transmission and data integrity are critical but existing solutions lack comprehensive auditing mechanisms.

Innovation Solution

A network switch equipped with computing devices that receive data packets, verify source and destination addresses, and compare actual values against reference values defined by a protocol to ensure only authorized and formatted data is transmitted, rejecting or modifying packets that do not meet these criteria, thereby maintaining network security and integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive auditing mechanisms are implemented to ensure secure and precise communication, then network security and data integrity are improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidauditing mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary auditing mechanism that acts as a mediator between data packets and the deterministic network. The auditing switch intercepts packets, validates them against protocol rules, and either forwards or rejects them. This intermediary layer enhances security without requiring modification of existing network devices, resolving the contradiction by adding functionality through a dedicated intermediate component rather than complicating existing devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The auditing mechanism is segmented into distinct functional components: packet reception, source address validation, destination address validation, protocol rule checking, and packet forwarding/rejection. This segmentation allows each component to perform its specific function independently, making the overall auditing system more manageable and less complex while maintaining comprehensive security validation.

Inventive Principle:
Principle #1Segmentation

2Reliability

If protocol rules are strictly enforced to control data packet characteristics, then data integrity is improved, but communication flexibility deteriorates

Engineering Contradiction:
Improvedata integrityVSAvoidcommunication flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by validating data packets against protocol rules before they are transmitted through the network. The auditing switch checks source addresses, destination addresses, and packet characteristics in advance, rejecting non-compliant packets before they can cause integrity issues. This preliminary validation ensures data integrity while maintaining flexibility because compliant packets are transmitted without further restriction.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The auditing mechanism provides feedback by comparing actual packet characteristics against protocol-defined reference values and making acceptance or rejection decisions based on this comparison. This feedback loop ensures that only packets meeting protocol requirements are transmitted, maintaining data integrity while allowing full flexibility for all packets that satisfy the established protocol rules.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3429161B1A network switch for auditing communications on a deterministic network
Publication Date: 2022.09.21 GE AVIATION SYST LTD
  • EP3429161B1 patent drawingFigure 1
  • EP3429161B1 patent drawingFigure 2
  • EP3429161B1 patent drawingFigure 3

AI summary

A network switch 310 for auditing communications on a deterministic network 240 includes one or more computing device(s) 312 configured to receive a data packet (D) comprising at least a source address 406 and a destination address 408. The computing device(s) 312 can determine whether the source address 406 corresponds to a first electronic device 330 on the deterministic network 240. In addition, the computing device(s) 312 can determine whether the destination address 408 corresponds to a second electronic device 340 on the deterministic network 240. When the source address 406 corresponds to the first electronic device 330 and the destination address 408 corresponds to the second electronic device 340, the computing device(s) 312 can compare an actual value for a characteristic of the data packet (D) against a reference value for the characteristic. When the actual value for the characteristic corresponds to the reference value for the characteristic, the computing device(s) 312 can transmit the data packet (D) to the destination address 408.