Partitioned Computing Device for Airborne Safety and Security Reconciliation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Reconciling safety-critical and high assurance security functional requirements between safety and security domains in airborne systems is challenging due to platform size, weight, and power constraints, making it difficult to simultaneously perform flight-critical safety functions and robust security functions.
Innovation Solution
A system with a computing device partitioned into safety and security modules, utilizing time and space partitioning to isolate resources, and a predefined communication interface to restrict information sharing between the modules, allowing each to be certified independently and minimizing duplication of functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physically separate federated systems are used to handle safety and security functions, then safety and security functions can be independently implemented, but platform size, weight, and power constraints are violated
Solution Approach 1:
The system is segmented into distinct safety and security domains through time and space partitioning. The safety domain operates during first time intervals and the security domain operates during second time intervals, with each domain having isolated resource access. This segmentation allows independent certification and implementation of safety and security functions while sharing the same physical platform, thereby reducing overall platform size, weight, and power requirements.
2Weight of moving object
If the same physical device is used for both safety and security functions, then platform size, weight, and power are reduced, but reconciling allocation of operational requirements between safety and security domains becomes difficult
Solution Approach 1:
The computational resources of the shared physical device are segmented into time-based partitions. The safety domain is allocated specific time intervals (first time intervals) and the security domain is allocated other time intervals (second time intervals). This temporal segmentation simplifies the allocation of operational requirements by providing clear, non-overlapping resource access patterns, making it easier to reconcile safety and security requirements on the same device.
Solution Approach 2:
A communication interface serves as an intermediary between the safety and security domains. This interface controls and mediates all information exchange between domains, ensuring that safety-critical communications are prioritized and that security domain activities do not interfere with safety domain operations. The intermediary simplifies requirement reconciliation by providing a structured, controlled mechanism for inter-domain communication.
3Productivity
If safety and security modules share the same physical device, then resource utilization is improved, but information sharing between modules becomes uncontrolled
Solution Approach 1:
The communication interface acts as an intermediary that controls all information sharing between safety and security modules. It implements a structured protocol that allows necessary information exchange while preventing unauthorized or harmful communications. This intermediary mechanism enables safe resource sharing and improved utilization while maintaining controlled, auditible information flow between domains with different security requirements.
Data Source
AI summary
Systems and methods for providing safety and security functions are disclosed. The system includes a computing device that provides at least a first partition and a second partition. The computing device implements time and space partitioning to isolate resources available to the first partition and the second partition. The system also includes a safety module that operates in the first partition for providing safety functions for the system. The system further includes a security module that operates in the second partition for providing security functions for the system. A predefined communication interface is utilized to facilitate communications between the safety module and the security module. The communication interface defines a set of communications allowable between the safety module and the security module, wherein information sharing between the safety module and the security module is restricted to only the set of communications allowed through the communication interface.


