Secure Broadband Datalink Firewall and Partitioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Broadband IP-based datalink systems used for aircraft communication lack security protection and isolation between different aircraft domains, making them vulnerable to security threats, especially when accessing the internet protocol/baseband satellite communication network.

Innovation Solution

Implementing a system with a first communication unit that verifies messages using a firewall and performs digital signature checks, with encapsulation data removal and integrity checks conducted in separate software partitions to ensure secure communication over broadband datalinks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If broadband IP-based datalink systems are used for aircraft communication, then communication bandwidth and cost-effectiveness are improved, but security protection and isolation between aircraft domains are worsened

Engineering Contradiction:
Improvecommunication bandwidthVSAvoidsecurity protection
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system is divided into separate security domains (aircraft domain and passenger domain) with dedicated security boundaries. The communication management unit implements domain separation through virtualization, creating isolated execution environments that prevent cross-domain attacks while maintaining broadband IP connectivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A communication management unit acts as an intermediary between the aircraft domain and broadband IP network. This intermediary implements security policies, filters traffic, and provides isolation mechanisms that allow high-speed communication while protecting against security threats from the open internet protocol network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If Ethernet is used to access the IP/BB SATCOM network and IP ground network, then connectivity and bandwidth are improved, but accessibility to security threats is worsened

Engineering Contradiction:
Improvenetwork connectivityVSAvoidsecurity threats
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary security measures by implementing firewalls, intrusion detection systems, and security policies before malicious traffic can penetrate the aircraft domain. Security checks are performed at multiple layers (network, transport, application) to prevent threats from reaching critical systems.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

Virtualization technologies create flexible security boundaries (virtual firewalls, software-defined networking) that can dynamically adapt to different security requirements while maintaining Ethernet connectivity. These virtual security layers provide protection without physically isolating the system from the broadband network.

Inventive Principle:
Principle #30Flexible shells and thin films

Data Source

PatentUS10819418B2Systems and methods for secure communications over broadband datalinks
Publication Date: 2020.10.27 HONEYWELL INTERNATIONAL INC
  • US10819418B2 patent drawing
  • US10819418B2 patent drawing
  • US10819418B2 patent drawing

AI summary

Systems and methods for secure communications over broadband datalinks are provided. In certain implementations, a system for providing secure communications through a communication link includes a first communication unit that includes a processing unit that is configured to execute code that causes the first communication unit to verify messages with a firewall as they are received by the first communication unit; remove encapsulation data that encapsulates a message received from a second communication unit; check a digital signature appended to the message received from a second communication unit through a non-secure communication link; perform an integrity check on the message; and when the message is verified through the digital signature and the integrity check, process the message; wherein removal of the encapsulation data and implementation of the firewall is in a first partition and performance of the integrity check and verification of the digital signature is in a second partition.