Router VPN for Airplane On-Board Network Connectivity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current aircraft on-board computer systems face limitations in network connectivity due to non-routable TCP/IP addresses and limited physical Ethernet ports, preventing scalable network designs and communication between maintenance control units and secure internal networks.
Innovation Solution
A system and method utilizing a router to establish a virtual private network (VPN) between an off-board client device and an airplane's on-board computer network, maintaining source TCP/IP addresses and enabling communication with both internal and external networks while supporting Network Address Translation (NAT).
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If private re-usable TCP/IP addresses are used for on-board networks, then network connectivity is established, but the addresses are not routable in enterprise computing networks
Solution Approach 1:
A network address translator (NAT) device is introduced as an intermediary between the on-board network using private TCP/IP addresses and the enterprise computing network requiring routable addresses. The NAT device translates private addresses to public routable addresses, enabling communication between the two networks while maintaining the integrity of both addressing schemes.
2Adaptability or versatility
If NAT is implemented for address translation, then address routability is improved, but the source TCP/IP address cannot be retained throughout the network connectivity session
Solution Approach 1:
The network communication path is segmented into distinct translation stages. The NAT device performs address translation only for outbound traffic from the on-board network to external networks, while allowing inbound traffic to maintain the original source address. This segmentation enables selective address translation based on traffic direction, preserving source addresses where required while providing routability where needed.
3Device complexity
If physical Ethernet ports are limited in number, then device complexity is reduced, but scalability to multiple airplanes is prevented
Solution Approach 1:
The NAT device is configured to serve multiple airplanes through a single physical Ethernet connection. By implementing virtualization and multi-tenancy capabilities, the device can simultaneously manage network addresses and connections for multiple aircraft, allowing each airplane to maintain its own private address space while sharing the same physical network infrastructure.
4Ease of operation
If maintenance control units connect to on-board servers, then maintenance functions are enabled, but connectivity to secure internal networks is lost
Solution Approach 1:
The NAT device acts as a mediator that enables the maintenance control unit to simultaneously maintain connections to both the on-board maintenance server and the secure internal enterprise network. By implementing intelligent routing and address translation, the device allows the maintenance unit to access external resources while preserving its connection to the secure internal network infrastructure.
Data Source
AI summary
A system and method for establishing connectivity between a client device and an on-board computer network of an airplane are provided. The client device is connected for establishing communication with a network such as an enterprise intranet associated with the airplane. A virtual private network is created for establishing communication between a router and the client device. The client device is connected with an on-board server of the airplane via the router while maintaining connectivity between the personal computer and the network.


