Secured Maintenance Gateway for Avionics Ethernet Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Ethernet-based interfaces in avionics systems pose security risks due to bi-directional communication, allowing low integrity systems to interact with high integrity systems, potentially leading to security failures during operations or maintenance procedures.

Innovation Solution

A system comprising a first and second processing circuit, and a network interface device with a filtering engine that separates data pathways and inspects data packets to ensure only compliant packets are transmitted from low integrity to high integrity systems, using a physically separated network pathway and implemented on a field programmable gate array (FPGA) for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If Ethernet bi-directional interface is used for high-speed communication, then communication speed is improved, but security risks increase due to potential communication from low integrity systems to high integrity systems

Engineering Contradiction:
Improvecommunication speedVSAvoidsystem security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The network interface device is segmented into multiple communication interfaces (first communications interface for low integrity systems, second communications interface for high integrity systems) with physically separated network pathways. This segmentation allows high-speed Ethernet communication while preventing unauthorized access between integrity zones through dedicated, isolated communication channels.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The filtering engine acts as an intermediary component that inspects data packets traveling between low integrity and high integrity systems. It enforces inspection criteria to block malicious or non-compliant packets while allowing legitimate high-speed communication to pass through, thus mediating security concerns without sacrificing communication performance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If physical separation of network pathways is implemented, then security is improved, but device complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoidnetwork interface complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple communication interfaces and physically separated network pathways are merged into a single integrated network interface device. This consolidation provides the security benefits of physical separation while managing complexity through unified device architecture, allowing high-speed Ethernet communication with built-in security enforcement.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The network interface device performs multiple functions within a single device: it provides high-speed Ethernet communication, enforces security policies through the filtering engine, and maintains physically separated network pathways. This multi-functionality reduces overall system complexity compared to using separate devices for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10911403B1Systems and methods for secured maintenance gateway
Publication Date: 2021.02.02 ROCKWELL COLLINS INC
  • US10911403B1 patent drawing
  • US10911403B1 patent drawing
  • US10911403B1 patent drawing

AI summary

A system includes a first processing circuit, a second processing circuit, and a network interface device. The network interface device includes a first communications interface, a second communications interface, and a filtering engine. The first communications interface is configured to receive first data packets from the first processing circuit and communicate the first data packets for transmission to the second processing circuit via a first network pathway. The second communications interface is configured to receive second data packets from the second processing circuit and communicate the second data packets to the first processing circuit via a second network pathway physically separated from the first network pathway. The filtering engine is configured to determine whether the first data packets satisfy an inspection criteria, and transmit the first data packets to the second processing circuit responsive to determining that the first data packets satisfy the inspection criteria.