Wireless On-Board Network Segmentation via Distinct Standards
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current on-board aircraft networks rely on wired links, which are cumbersome, weight-intensive, and difficult to maintain, and do not support wireless connections while maintaining segregation between secure and non-secure sub-networks.
Innovation Solution
Implementing a partitioned on-board network with adjacent sub-networks connected via wireless links using distinct communication standards or separate sets of transmission resources, ensuring segregation through security elements, and managed by access controllers to maintain segregation constraints.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If wired links are used to connect terminals to the on-board network, then network segregation between secure and non-secure sub-networks is maintained, but the weight of cables and connection technology increases and installation complexity increases
Solution Approach 1:
The patent replaces wired mechanical connections with wireless communication systems. Access points are installed in the aircraft cabin to provide wireless connectivity to terminals, eliminating the need for extensive cable routing and physical connectors while maintaining network segmentation through logical separation and security protocols
2Reliability
If wired links are used to connect terminals to the on-board network, then network segregation between secure and non-secure sub-networks is maintained, but installation constraints increase due to cable path requirements
Solution Approach 1:
The patent replaces wired mechanical connections with wireless communication systems. Access points are installed in the aircraft cabin to provide wireless connectivity to terminals, eliminating the need for extensive cable routing and physical connectors while maintaining network segmentation through logical separation and security protocols
3Reliability
If wired links are used to connect terminals to the on-board network, then network segregation between secure and non-secure sub-networks is maintained, but maintenance difficulty increases when equipment is remote from maintenance servers
Solution Approach 1:
The patent replaces wired mechanical connections with wireless communication systems. Access points are installed in the aircraft cabin to provide wireless connectivity to terminals, eliminating the need for extensive cable routing and physical connectors while maintaining network segmentation through logical separation and security protocols
4Weight of moving object
If wireless links are used to connect terminals to the on-board network, then weight and installation complexity are reduced, but network segregation between sub-networks may be compromised
Solution Approach 1:
The patent applies network segmentation by dividing the wireless network into distinct virtual sub-networks or VLANs corresponding to different security zones (secure avionic sub-network and non-secure open sub-network). Access points are configured to enforce segmentation policies, ensuring that wireless terminals in the open sub-network cannot access resources in the secure sub-network, thereby maintaining logical segregation without physical barriers
Solution Approach 2:
The patent introduces security elements such as firewalls, access control lists, and authentication mechanisms as intermediaries between the open and secure sub-networks. These intermediaries control and filter wireless traffic, allowing legitimate communications while blocking unauthorized access attempts, thus preserving network segregation in the wireless environment
5Weight of moving object
If wireless links are used to connect terminals to the on-board network, then weight and installation complexity are reduced, but security against unauthorized access becomes more challenging
Solution Approach 1:
The patent introduces security elements such as firewalls, access control lists, and authentication mechanisms as intermediaries between the open and secure sub-networks. These intermediaries control and filter wireless traffic, allowing legitimate communications while blocking unauthorized access attempts, thus preserving network segregation in the wireless environment
Solution Approach 2:
The patent implements preliminary security measures including wireless authentication protocols, encryption, and access control policies that prevent unauthorized access before it can occur. Security elements are configured in advance to recognize and reject malicious or unauthorized connection attempts, proactively defending against potential threats rather than reacting to them
Data Source
AI summary
The subject matter disclosed herein relates an on-board network with nodes linked by wired links, the on-board network being partitioned into adjacent sub-networks, mutually segregated by security elements. Each sub-network can be equipped with access points allowing mobile terminals to connect to the sub-network by wireless links. The access points of adjacent sub-networks use different communication standards or distinct sets of transmission resources in such a way that the segregation between adjacent sub-networks is preserved.


