HW separation was enforced by FAA back when 787 was in prototype stage.
> The proposed architecture of the 787 allows connection to and access from external sources (the public Internet) and airline operator networks to the previously isolated Aircraft Control Domain and Airline Information Services Domain.
> Capability is proposed for providing electronic transmission of field-loadable software applications and databases to the aircraft. These would subsequently be loaded into systems within the Aircraft Control Domain and Airline Information Services Domain.
[1] http://rgl.faa.gov/Regulatory_and_Guidance_Library%5CrgSC.ns...
I can't find the "work-in-progress" reports for type certification regarding the network, but the special conditions involve:
> The applicant shall ensure system security protection for > the Aircraft Control Domain and Airline Information > Domain from access by unauthorized sources external to > the airplane, including those possibly caused by > maintenance activity. The applicant shall ensure that > security threats are identified and assessed, and that > risk mitigation strategies are implemented to protect the > airplane from all adverse impacts on safety, > functionality, and continued airworthiness.
In reality, how is this separation of critical networks looking like exactly? MAC address filters? Are they air-gapped? I would venture to guess, nobody that isn't bound by an NDA knows.
FAA caught it and forced them to redesign the setup.
As for actual AFDX networks - they have hardcoded forwarding tables and no MAC learning, and separation between networks tends to use data diodes
You burn one lb (unit) of fuel for every three lbs (units) of fuel you carry.
Me: FAA licensed dispatcher
(Also, you'll see a 1:1 rule would imply adding fuel does not increase range, which is absurd.)