Virtual Machine Segmentation for Multi-Level Security Data Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Aircraft data processing systems face challenges in integrating security functions with commercial hardware and software while maintaining confidentiality, integrity, and availability, especially in coexisting with sensitive data and functionalities that require various levels of security or responsibility.

Innovation Solution

A software component utilizing multiple virtual machines and a hypervisor to manage security levels, allowing for the implementation of various security functions on a single machine, independent of hardware platforms, with authentication and data transfer filtering to ensure security and integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple functions with different security levels are integrated into a single data processing system, then system versatility and resource utilization improve, but security risk and system complexity increase

Engineering Contradiction:
Improvesystem versatilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system is segmented into multiple virtual machines, each isolated and dedicated to specific functions with defined security levels. This segmentation allows versatile functionality while maintaining security boundaries, as each virtual machine operates independently with controlled access to resources and data.

Inventive Principle:
Principle #1Segmentation

2Ease of manufacture

If commercial hardware and software are used to reduce costs and improve compatibility, then ease of manufacture and adaptability improve, but security control and system reliability deteriorate

Engineering Contradiction:
ImprovecompatibilityVSAvoidsecurity control
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

A hypervisor layer is introduced as an intermediary between the commercial hardware/software infrastructure and the security-critical functions. This hypervisor provides standardized interfaces and security management, enabling the use of commercial products while maintaining controlled security boundaries and isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If security functions are integrated into operational processes, then operational efficiency improves, but system complexity and maintenance requirements increase

Engineering Contradiction:
Improveoperational efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

Security functions are merged with operational processes within the virtualized environment, allowing both to coexist in the same physical infrastructure. The virtual machines provide logical separation while sharing physical resources, reducing overall system complexity compared to completely separate security and operational systems.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9804875B2Software component and device for the automated processing of multi-purpose data, employing functions requiring different security levels or responsibility limits
Publication Date: 2017.10.31 AIRBUS (SAS)
  • US9804875B2 patent drawing
  • US9804875B2 patent drawing
  • US9804875B2 patent drawing

AI summary

A software component for automated processing of multi-usage data, implementing functions requiring various levels of security or limits of responsibility. The software component includes a plurality of virtual machines, each virtual machine being adapted for executing at least one function requiring a level of security or a limit of responsibility which is predetermined and a hypervisor adapted for controlling execution of the plurality of virtual machines.