Method and apparatus for an advanced security system for power line connections
By adopting a multi-factor authentication system on the aircraft, using biometrics, tokens and password data combined with power line broadband communication, the security problems in aircraft data transmission are solved and secure access control for critical systems is achieved.
Patent Information
- Application Number
- CN202010379838.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-05-08
- Filing Date
- 2020-05-08
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2040-05-08
AI Technical Summary
In the prior art, aircraft data transmission poses security risks, especially in critical systems where wireless communication is not applicable, it is difficult to ensure that only authorized personnel access to aircraft networks and internal data to prevent potential threats or attacks.
A multi-factor authentication system is adopted, combining biometric data, token data and password data, and authentication information is transmitted between the aircraft and the ground system through power line broadband communication (BPL), ensuring the security of access rights.
Improves the security and reliability of aircraft data transmission, ensures that only multi-authorized users can access critical systems, and enhances protection against potential threats.
Smart Images

Figure CN111914227B_ABST
Abstract
Description
Technical Field
[0001] The field of the present disclosure generally relates to methods and systems for secure data communication, and more particularly, to methods and systems for increasing data security of communication across a three-phase power system. Background Art
[0002] Vehicles such as commercial aircraft, military aircraft, unmanned aerial vehicles, and various systems thereon generate and consume large amounts of data. For example, the engine is monitored at each stage of operation, which results in the generation of a large amount of data. Such engine monitoring data includes, for example but not limited to, compression ratio, revolutions per minute (RPM), temperature, and vibration data. In addition, fuel-related data, maintenance, aircraft health monitoring (AHM), operation information, catering data, in-flight entertainment equipment (IFE) updates, and passenger data such as duty-free shopping are typically routinely generated on the aircraft.
[0003] At least some of these systems are wirelessly connected to a ground system via a central aircraft server and a central transceiver for data transmission and reception. However, for some critical systems, critical data is not configured for wireless data transmission. Thus, when the aircraft arrives at the gate, much of the data is manually downloaded from the aircraft. Specifically, a data recording device is manually coupled to an interface on the aircraft and data is collected from various data generators or logbooks for forwarding and processing at the logistics department. In addition, the logistics department function transfers updated data sets (such as data related to the next flight(s) of the aircraft) to the aircraft.
[0004] The need for additional communication channels and data transmission is driving rapid changes related to such communication. This increased need is due to, for example, the increased dependence of ground systems on data from the aircraft and the increased communication needs of flight crews, cabin crews, and passengers. In addition, it is critical that only authorized personnel have access to the aircraft network and internal data to prevent the possibility of serious threats or attacks on the aircraft systems. These may include, but are not limited to, unauthorized access to the aircraft network, aircraft control, aircraft data, theft or destruction of such data, and / or any other form of improper or malicious behavior associated with threats to the aircraft and its network, its systems, control, or data. Summary of the Invention
[0005] On the one hand, a multi-factor authentication system on a vehicle is provided. The system includes at least one on-board processor; a first on-board database that stores a first plurality of authentication data associated with a first factor for authentication; and a second on-board database that stores a second plurality of authentication data associated with a second factor for authentication. The at least one on-board processor communicates with the first on-board database, the second on-board database, and one or more on-board protected computer systems. The at least one processor is programmed to receive a request from a user to access one or more protected computer systems. The request contains authentication data that includes a first authentication factor and a second authentication factor. The at least one processor is further programmed to retrieve from the first on-board database the first factor authentication data associated with the user. The at least one processor is further programmed to compare the first factor authentication data with the received first authentication factor to determine if there is a match. Additionally, the at least one processor is programmed to retrieve from the second on-board database the second factor authentication data associated with the user. Furthermore, the at least one processor is programmed to compare the second factor authentication data with the received second authentication factor to determine if there is a match. Moreover, the at least one processor is programmed to grant access to one or more on-board protected computer systems if all comparisons match.
[0006] On the other hand, a multi-factor authentication computer device on a vehicle is provided. The multi-factor authentication computer device includes at least one processor that communicates with a first on-board database, a second on-board database, and one or more on-board protected computer systems. The first on-board database stores a first plurality of authentication data associated with a first factor for authentication. The second on-board database stores a second plurality of authentication data associated with a second factor for authentication. The at least one on-board processor is programmed to receive a request from a user to access one or more protected computer systems. The request contains authentication data that includes a first authentication factor and a second authentication factor. The at least one processor is further programmed to retrieve from the first on-board database the first factor authentication data associated with the user. The at least one processor is further programmed to compare the first factor authentication data with the received first authentication factor to determine if there is a match. Additionally, the at least one processor is programmed to retrieve from the second on-board database the second factor authentication data associated with the user. Furthermore, the at least one processor is programmed to compare the second factor authentication data with the received second authentication factor to determine if there is a match. Moreover, the at least one processor is programmed to grant access to one or more on-board protected computer systems if all comparisons match.
[0007] In yet another aspect, a method for authenticating a user is provided. The method is performed by at least one processor on a vehicle, the at least one processor communicating with at least one memory device. The method includes receiving a request from the user to access one or more protected computer systems. The request includes authentication data that includes a first authentication factor and a second authentication factor. The method also includes retrieving first factor authentication data associated with the user from a first on-board database that stores a first plurality of authentication data associated with the first factor for authentication. The method further includes comparing the first factor authentication data with the received first authentication factor to determine if a match exists. Additionally, the method includes retrieving second factor authentication data associated with the user from a second on-board database that stores a second plurality of authentication data associated with the second factor for authentication. Further, the method includes comparing the second factor authentication data with the received second authentication factor to determine if a match exists. Moreover, the method includes granting access to one or more on-board protected computer systems if all comparisons match. Additionally, the method also includes denying access to one or more on-board protected computer systems if a match does not exist for all comparisons.
[0008] The features, functions, and advantages that have been discussed can be implemented independently in various embodiments or can be combined in other embodiments, and further details thereof can be seen with reference to the following description and the drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] Figure 1 A block diagram of a power and digital communication transmission system is shown.
[0010] Figure 2 Shows Figure 1 A block diagram of a main control system in the power and digital communication transmission system shown.
[0011] Figure 3 Shows Figure 1 A block diagram of a slave system in the power and digital communication transmission system shown.
[0012] Figure 4 Shows the Figure 1 Simplified flowchart of a multi-factor authentication system in the power and digital communication transmission system shown.
[0013] Figure 5 Shows Figure 4 A block diagram of the multi-factor authentication system shown.
[0014] Figure 6 Shows an example configuration of a Figure 1 client system according to an embodiment of the present disclosure.
[0015] Figure 7 shows an example configuration of a server system as shown in Figure 1 , Figure 4 and Figure 5 accordance with an embodiment of the present disclosure.
[0016] Figure 8 is a flowchart of a process for authenticating a user using a Figure 4 and Figure 5 multi - factor authentication system as shown.
[0017] Unless otherwise noted, the figures provided herein are intended to illustrate features of embodiments of the present disclosure. These features are considered applicable to a variety of systems including one or more embodiments of the present disclosure. As such, the figures are not intended to include all conventional features known to those of ordinary skill in the art that are required to practice the embodiments disclosed herein. Detailed Description
[0018] The described embodiments enable secure vehicle broadband communication with a data network. More specifically, the present disclosure relates to using multi - factor authentication in conjunction with power - line broadband (BPL) communication to enable secure aircraft information exchange. Power - line communication technology can be used to improve data transmission and enhance data security from an aircraft to an airline's logistics department and vice versa.
[0019] Described herein are computer systems such as BPL master computer devices and slave computer devices and related computer systems. As described herein, all such computer systems include a processor and a memory. However, any processor in the computer devices referred to herein can also refer to one or more processors, where the processors can be in one computing device or in multiple computing devices acting in parallel. Additionally, any memory in the computer devices referred to herein can also refer to one or more memories, where the memories can be in one computing device or in multiple computing devices acting in parallel.
[0020] Furthermore, although the terms "master" and "slave" are used herein to describe different computer devices, in some embodiments, such different devices can be considered more as parallel devices rather than a master device controlling a slave device. In some embodiments, the master device can be controlled by the slave device. For the purposes of the present disclosure, the slave device is a device on a vehicle, and the master device is a device on the ground or at the location where the vehicle is currently docked or stationary.
[0021] As used herein, a processor may include any programmable system including systems using microcontrollers, reduced instruction set circuits (RISC), application specific integrated circuits (ASIC), logic circuits, and any other circuit or processor capable of performing the functions described herein. The above examples are not intended to limit the definition and / or meaning of the term "processor" in any way.
[0022] As used herein, the term "database" may refer to a data repository, a relational database management system (RDBMS), or both. As used herein, a database may include any collection of data, including hierarchical databases, relational databases, flat file databases, object-relational databases, object-oriented databases, and any other structured or unstructured collection of records or data stored in a computer system. The above examples are not intended to limit the definition and / or meaning of the term database in any way. Examples of RDBMSs include, but are not limited to Database, MySQL, DB2, SQL Server, and PostgreSQL. However, any database capable of implementing the systems and methods described herein may be used. (Oracle is a registered trademark of Oracle Corporation of Redwood Shores, California; IBM is a registered trademark of International Business Machines Corporation of Armonk, New York; Microsoft is a registered trademark of Microsoft Corporation of Redmond, Washington; and Sybase is a registered trademark of Sybase of Dublin, California.)
[0023] In one embodiment, a computer program is provided and the program is embodied on a computer-readable medium. In an example embodiment, the system is executed on a single computer system without the need to be connected to a server computer. In another embodiment, the system operates in an environment (Windows is a registered trademark of Microsoft Corporation of Redmond, Washington). In yet another embodiment, the system operates in a mainframe environment and Run on a server environment (UNIX is a registered trademark of X / Open Company Limited, Reading, Berkshire, UK). The application is flexible and is designed to run in a variety of different environments without compromising any of its major functions. In some embodiments, the system includes multiple components distributed among multiple computing devices. One or more components may be in the form of computer-executable instructions embodied in a computer-readable medium.
[0024] As used herein, an element or step recited in the singular and preceded by the word "a" or "an" should be understood as not excluding a plurality of elements or steps, unless expressly stated to the contrary. Furthermore, references to "example embodiments" or "one embodiment" of the present disclosure are not intended to be construed as excluding the existence of additional embodiments that also incorporate the recited features.
[0025] As used herein, the terms "software" and "firmware" are interchangeable and include any computer program stored in a memory (including RAM memory, ROM memory, EPROM memory, EEPROM memory, and non-volatile RAM (NVRAM) memory) for execution by a processor. The above memory types are merely examples and, therefore, there is no limitation as to the types of memory that may be used to store a computer program.
[0026] Furthermore, as used herein, the term "real-time" refers to at least one of the time of occurrence of an associated event, the time of measurement and collection of predetermined data, the time of processing data, and the time of response of the system to the event and the environment. In the embodiments described herein, these activities and events occur substantially instantaneously.
[0027] As used herein, the term "multi-factor authentication" refers to the requirement of at least two forms of identification before allowing a user to access at least one of, for example, a user account, a computer system, a computer network, and / or data stored in a memory device. The three types of identification used in multi-factor authentication include, but are not limited to, something the user knows (such as a password), something the user has (such as a smart card or other physical token), and something the user is (such as a fingerprint or other biometric identifier).
[0028] The systems and processes are not limited to the specific embodiments described herein. Additionally, the components of each system and each process may be practiced independently of and separated from the other components and processes described herein. Each component and process may also be used in combination with other assembly packages and processes.
[0029] Figure 1FIG. 0 is a block diagram of a power and digital communication transmission system 100 according to an exemplary embodiment of the present disclosure. In this exemplary embodiment, the power and digital communication transmission system 100 includes an electronic aircraft umbilical cable 102 that includes a supply end 104, a plug end 106, and electrical conductors 108 extending therebetween. The plug end 106 is configured to mate with a vehicle such as an aircraft 110 such that power is supplied from the supply end 104 to the aircraft 110 through the electrical conductors 108. The electrical energy for powering a commercial aircraft on the ground is 115 Vac, 400 Hz, three-phase power and includes a neutral line. In the exemplary embodiment, the supply end 104 is coupled to a ground power system 112 at an airport terminal boarding gate 114. The ground power system 112 is configured to receive power from a power source through a power conduit 115. In other embodiments, the ground power system 112 is located at a dock to couple to a ship, barge, or steamer (not shown). In other embodiments, the ground power system 112 is located at a garage or service facility and is configured to couple to a wheeled vehicle such as, but not limited to, a car, a recreational vehicle (RV), or a train. Additionally, the ground power system 112 may include another vehicle such as a space vehicle, a subsea or surface vehicle, where one or both vehicles are moving relative to each other and / or their surroundings when coupled through the umbilical cable 102.
[0030] The power and digital communication transmission system 100 also includes a first interface device 116 electrically coupled to the supply end 104. In the exemplary embodiment, the interface device 116 is electrically coupled to the supply end 104 through the power conduit 115 and the ground power system 112, where the interface device 116 is electrically coupled to the power conduit 115 and the ground power system 112 receives power through the power conduit 115. In an alternative embodiment, the interface device 116 is electrically coupled to the supply end 104 downstream of the ground power system 112. In one embodiment, the ground power system 112 is a distributed power system operating at a voltage incompatible with the aircraft 110. In such an embodiment, a point-of-use power system 117 is used to step the voltage to a level compatible with the aircraft 110. In another alternative embodiment, the interface device 116 is electrically coupled to the electrical conductors 108 inside the ground power system 112. The interface device 116 is also coupled to a network 118 through a wired network access point 120 or a wireless communication link 122.
[0031] The power and digital communication transmission system 100 also includes a second interface device 124 that is electrically coupled to the plug end 106 when the umbilical cable 102 is coupled to the aircraft 110. In an exemplary embodiment, the interface device 124 is electrically coupled to the on-board power bus 125 through the umbilical cable plug 126 through the plug end 106, and the umbilical cable plug 126 passes through the wall of the fuselage 128 of the aircraft 110. The interface device 124 is also coupled to the on-board network 129 through the on-board wired network access point 130 or the on-board wireless communication link 132. In some cases, due to attenuation from the vehicle itself, the on-board wireless link 132 may not be able to transmit from the vehicle to the outside of the vehicle. Examples of the on-board wireless link 132 may include, but are not limited to, 60 GHz or low data rate wireless, such as IoT applications via BLE, Zigbee, Wi-Fi, and Bluetooth.
[0032] The first interface device 116 is configured to transmit and receive data carrier signals through the electrical conductor 108 when powering the aircraft 110 through the electrical conductor 108. The first interface device 116 is also configured to convert a predetermined data format on the network into a data carrier signal and convert the data carrier signal into a predetermined data format on the network. When the umbilical cable 102 is coupled to the aircraft 110, the second interface device 124 is electrically coupled to the plug end 106. The second interface device 124 (e.g., a receiver and transmitter, an on-board transceiver) is configured to transmit and receive data carrier signals between the first interface device 116 and the on-board network 129 via the umbilical cable 102 when powering the aircraft 110 through the electrical conductor 108. In an exemplary embodiment, each of the first interface device 116 and the second interface device 124 is configured to detect a communication link established through the electrical conductor and report the link to the system 100. The interface device 116 and the interface device 124 are electrically matched with the characteristics of the umbilical cable 102, including but not limited to wire size, shielding, length, voltage, load, frequency, and grounding.
[0033] In an exemplary embodiment, the predetermined data format is compatible with various network protocols, including but not limited to Internet network protocol, gateway link network protocol, Aeronautical Telecommunication Network (ATN) protocol, and Aircraft Communication Addressing and Reporting System (ACARS) network protocol.
[0034] In an exemplary embodiment, when the aircraft 110 is parked at a service location such as an airport terminal gate, high-speed network services are provided to the aircraft 110 through the conductors of the aircraft ground power umbilical cable using, for example but not limited to, power line broadband (BPL), X10, or similar technologies. Using such technologies allows airports and airlines to add a simple interface to the aircraft umbilical cable at the gate and allows aircraft manufacturers to provide a matching interface within the aircraft to allow broadband Internet services to be provided to the aircraft through the aircraft power link in the umbilical cable.
[0035] Power line broadband (BPL) is a technology that allows Internet data to be transmitted over power lines. (BPL is sometimes also referred to as power line communication or PLC.) A modulated radio frequency signal including digital signals from the Internet is injected / added / modulated onto the power line using, for example, inductive or capacitive coupling. These radio frequency signals are injected or superimposed onto the alternating current power waveform, which is transmitted via the power conductor at one or more specific points. The radio frequency signals propagate along the power conductor to the point of use. Transmitting BPL is allowed with little (if any) modification to the umbilical cable. Frequency separation in the umbilical cable substantially minimizes crosstalk and / or interference between the BPL signal and other wireless services. Compared with wireless methods, BPL allows for higher speeds and more reliable Internet and data network services for the aircraft. Using BPL also eliminates the need to couple additional separate cables to the aircraft 110 because it combines aircraft power and Internet / data services on the same wire. System 100 uses frequencies in the range of, for example, approximately 2.0 MHz to approximately 80.0 MHz or an X10-like range, with an exact frequency range defined and designed by the characteristics and shielding of the umbilical cable 102 and the allowed RFI / EMI levels in that particular environment.
[0036] In an embodiment, symmetric high-bandwidth BPL is used in the umbilical cable 102 to transmit data communication signals at a communication speed with the aircraft 110 at a rate of tens or hundreds of megabits per second (Mbps). Since the BPL link is dedicated to only one aircraft 110 and is not shared like wireless, the actual throughput can be two to ten times that of wireless throughput in the same environment. In addition, the throughput is stable and reliable in the airport environment, while existing wireless gateway link services vary with RF interference and congestion at each airport.
[0037] Figure 2 is shown Figure 1 A block diagram of the main control system 200 in the illustrated power and digital communication transmission system 100 is shown. In an exemplary embodiment, the main control system 200 includes a main control unit 202. In an exemplary embodiment, the main control unit 202 is coupled to the power conduit 115 and serves as a first interface device 116 ( Figure 1as shown).
[0038] The main control unit 202 includes a central processing unit (CPU) 204 that communicates with a power line circuit board 206 (also referred to as a power line transceiver). The power line circuit board 206 allows the CPU 204 to communicate with other devices via a power line and a BPL connection 208. The BPL connection 208 uses a power line similar to the electronic aircraft umbilical cable 102 ( Figure 1 as shown).
[0039] The main control unit 202 also includes a Wi-Fi card 210 (also referred to as a Wi-Fi transceiver) for communicating with a remote device via a first wireless connection 212. The main control unit 202 also includes a cell modem card 214 (also referred to as a cellular modem) for communicating with a remote device via a second wireless connection 216. In some embodiments, the main control unit 202 includes a removable memory 218. The removable memory 218 includes any memory card and device that can be removably attached to the main control unit, including but not limited to a universal serial bus (USB) flash drive, an external hard drive, and a non-magnetic medium. The CPU 204 communicates with and controls the power line circuit board 206, the Wi-Fi card 210, the cell modem card 214, and the removable memory 218. Although the Wi-Fi and cellular connection cards 210 and 214 are described above, wireless connection can also be achieved by other methods, including but not limited to 60Ghz, AeroMACS, WiMAX, Whitespace, and Bluetooth.
[0040] In an exemplary embodiment, the CPU 204 detects that a connection has been established with another device via the BPL connection 208, such as to a second interface device 124 ( Figure 1 as shown). The CPU 204 receives a plurality of data via the BPL connection 208 and the power line transceiver 206. The CPU 204 determines the destination of the plurality of data. In some embodiments, the destination is another computer. In other embodiments, the destination is multiple computers or a computer network. In some embodiments, the destination is one or more computer systems associated with an airline, an airport, and / or an operations logistics department. The main control unit 202 is remote from the destination. In an exemplary embodiment, the main control unit 202 is capable of remotely connecting to the destination via one or more wireless networks. In these embodiments, the CPU 204 determines whether to route the plurality of data through the first wireless transceiver (i.e., the Wi-Fi card 210) or the second wireless transceiver (i.e., the cell modem card 214). The first wireless transceiver and the second wireless transceiver can also be connected using 60GHz, AeroMACS, WiMAX, Whitespace, and Bluetooth.
[0041] In an exemplary embodiment, the main control unit 202 further includes a user authentication system 220. The user authentication system 220 includes one or more devices that allow the system 100 to authenticate a user. The user authentication device 220 may include, but is not limited to, a keyboard or keypad, a card reader, a radio frequency identifier (RFID) reader, a biometric scanner, and any other device that can be used to identify and authenticate a user. In an exemplary embodiment, the user authentication device 220 provides multi-factor authentication, which requires the user to provide a biometric identifier and at least one of a password and a token identifier. In an exemplary embodiment, the authentication information is received by the CPU 204 of the main control unit 202 and transmitted to the authentication system via the electronic aircraft umbilical cable 102( Figure 1 as shown) to an authentication system such as the dynamic multi-factor authentication system 410( Figure 1 as shown) on the aircraft 110( Figure 4 as shown).
[0042] In some embodiments, the CPU 204 tests the signal strengths of the first wireless connection 212 and the second wireless connection 216. The CPU 204 compares the signal strengths of the first wireless connection 212 and the second wireless connection 216 to determine which connection to use to transmit a plurality of data to a destination. Then, the CPU 204 routes the plurality of data to the destination using the determined wireless connection. In some other embodiments, the main control unit 202 also considers the reliability of the first wireless connection 212 and the second wireless connection 216 when determining which wireless connection to use.
[0043] In some embodiments, if the signal strengths of both the first wireless connection 212 and the second wireless connection 216 are below respective predetermined thresholds, the CPU 204 stores the plurality of data on the removable memory 218. In some other embodiments, the CPU 204 transmits the plurality of data to the destination at a subsequent time when the signal strength of one of the first wireless connection 212 and the second wireless connection 216 exceeds the respective predetermined threshold.
[0044] In some other embodiments, the CPU 204 audits the voltage, current, and phase of the BPL connection 208 to determine whether the connection is within parameters. The CPU 204 may determine whether to transmit a plurality of data based on the audit. Additionally, if the CPU 204 determines that the connection is not within parameters, the CPU 204 may determine whether to receive data via the BPL connection 208. This ensures that the BPL connection 208 is properly connected before transmitting a plurality of data, thereby ensuring the security of the connection and the integrity of the data received by the main control unit 202.
[0045] In some other embodiments, the master control unit 202 transmits data regarding future aircraft operations to the slave unit via the BPL connection 208, such as but not limited to software updates for one or more systems, additional movies and / or other entertainment options, flight paths, and weather information. In these embodiments, the master control unit 202 may have received data for uploading to the slave unit from an airport, an airline, or an operations logistics department.
[0046] In some additional embodiments, the master control unit 202 is stored on the aircraft 110. When the aircraft 110 lands at an airport that does not have an existing BPL system, the master control unit 202 is deployed to connect to one or more wireless networks at that airport. In some other embodiments, the master control unit 202 is password protected to ensure access by authorized users.
[0047] Figure 3 is shown Figure 1 A block diagram of the slave system 300 in the power and digital communication transmission system 100 shown. In an exemplary embodiment, the slave system 300 includes a slave unit 302 that may be on a vehicle. In an exemplary embodiment, the slave unit 302 is similar to the second interface device 124 ( Figure 1 shown).
[0048] The slave unit 302 includes a processor or central processing unit (CPU) 304 that communicates with a power line circuit board 306 (also referred to as a power line transceiver). The power line circuit board 306 allows the CPU 304 to communicate with other devices via the BPL connection 308. The BPL connection 308 uses a power line similar to the electrical aircraft umbilical cable 102 ( Figure 1 shown).
[0049] In some embodiments, the slave unit 302 includes a removable memory 310. The removable memory 310 includes any memory card and device that can be removably attached to the master control unit, including but not limited to a universal serial bus (USB) flash drive, an external hard drive, and a non-magnetic medium. The processor or CPU 304 communicates with and controls the power line circuit board 306 and the removable memory 310. In some embodiments, the slave unit 302 is on the aircraft 110 and has connections 312 to multiple systems on the aircraft. In these embodiments, the slave unit 302 receives data regarding the operation of the aircraft from the multiple systems.
[0050] In an exemplary embodiment, the on-board slave unit 302 including the processor or CPU 304 has a connection 312 that connects to the aircraft network 412 (both shown in Figure 4as shown), wherein the dynamic multi-factor authentication system 410. In an exemplary embodiment, the dynamic multi-factor authentication system 410 authenticates a user before providing access to the aircraft network 412.
[0051] In an exemplary embodiment, the CPU 304 receives multiple data from multiple systems via the connection 312. The CPU 304 determines whether a connection has been established with another device via the BPL connection 308, such as to the main control unit 202 ( Figure 2 as shown). If a connection has been established, the CPU 304 transmits the multiple data to the BPL main control unit 202 via the power line transceiver 306. If no connection exists, the CPU 304 stores the multiple data in the removable memory 310.
[0052] In an exemplary embodiment, the processor or CPU 304 of the slave unit 302 on the aircraft determines whether the aircraft 110 is on the ground before determining whether the power line transceiver 306 is connected to the main control unit 202. In some embodiments, the CPU 304 continuously receives data from multiple systems. The CPU 304 stores this data in the removable memory 310. When the CPU 304 determines that the aircraft is on the ground and connected to the main control unit 202, the CPU 304 transmits the data from the removable memory 310 to the main control unit 202 via the BPL connection 308.
[0053] In some other embodiments, the CPU 304 audits the voltage, current, and phase of the BPL connection 308 to determine whether the connection is within parameters. The CPU 304 can determine whether to transmit the multiple data based on the audit. Additionally, if the CPU 304 determines that the connection is not within parameters, the CPU 304 can determine whether to receive data via the BPL connection 308. This ensures that the BPL connection 308 is properly established before transmitting the multiple data, thereby ensuring the security of the connection and the integrity of the data transmitted and received by the main control unit 202.
[0054] In some other embodiments, the main control unit 202 transmits data regarding future aircraft operations to the slave unit 302 via the BPL connection 308, such as but not limited to software updates for one or more systems, additional movies and / or other entertainment options, flight paths, and weather information. In some embodiments, the slave unit 302 routes the data to the appropriate systems on the vehicle. In other embodiments, the slave unit 302 acts as a pass-through for the network of the vehicle.
[0055] In some other embodiments, the slave unit 302 is password protected to ensure access by authorized users.
[0056] Figure 4 is shown usingFigure 1 The power and digital communication transmission system 100 shown, and Figure 3 A simplified flowchart of the multi-factor authentication system 400 of the slave unit 302 shown, where the multi-factor authentication system 400 is implemented by a processor or CPU 304 of the slave unit 302 on an aircraft. In an exemplary embodiment, when a user desires to access the aircraft network 412, the multi-factor authentication system 400 performs an authentication check on the user to confirm the user's identity. In an exemplary embodiment, the aircraft network 412 includes a core system 414 for the operation of the aircraft 110 ( Figure 1 shown). In addition to the core system 414, the aircraft network 412 may include, but is not limited to, a flight system 416, a fuel system 418, an entertainment system 420, and other systems 422 required to operate the aircraft 110. In some embodiments, the aircraft network 412 is similar to the on-board network 129 ( Figure 1 shown).
[0057] In an exemplary embodiment, the aircraft network 412 is protected by a dynamic multi-factor authentication system 410. The dynamic multi-factor authentication system 410 serves as a gateway for controlling access to the systems included in the aircraft network 412. When a computer device (such as the master control unit 202) ( Figure 2 shown) attempts to access the aircraft network 412, the dynamic multi-factor authentication system 410 requests authentication information 402 from a requester computer device such as the master control unit 202. In other embodiments, the requester computer device may include crew member devices, passenger devices (such as smartphones and tablets), maintenance devices, and any other device that attempts to access the aircraft network 412.
[0058] In an exemplary embodiment, the authentication information 402 includes biometric data 404, token data 406, and password data 408. The biometric data 404 includes biometric information that can be used to identify a user. The biometric data 404 may include, but is not limited to, retina scans, iris scans, fingerprint data, facial recognition data, facial recognition, ear recognition, profile recognition, speaker recognition, device motion pattern recognition, and contact pattern recognition. The token data 406 represents data from a physical device owned by the user, where the token includes data read and / or received by the multi-factor authentication system 410. This data can come from a disconnected key fob that generates an access code, a device connected to the requesting computer device (such as a USB token or inserted access card), an RFID tag, or other physical tokens of broadcast signals, or a software token stored on the requester's computer device. The password data 408 represents any password, passphrase, personal identification number (PIN), challenge question, or any other information that the user should know to be authenticated by the system 400. In an exemplary embodiment, the authentication data 402 also includes a user identifier (such as a username) to uniquely identify the user and allow the system to determine which entries are associated with that user.
[0059] In an exemplary embodiment, the dynamic multi-factor authentication system 410 requires at least two-factor authentication. In this embodiment, this includes the biometric data 404, and one of the token data 406 and the password data 408. In other embodiments, all three types of authentication information 402 may be required. In additional embodiments, multiple data of each type may be required. For example, two forms of biometric data 404 may be required. In some embodiments, the type of authentication data 402 provided is based on the capabilities of the requesting device and the user authentication device 220 ( Figure 2 as shown).
[0060] In some embodiments, the dynamic multi-factor authentication system 410 may operate in a sandbox. The dynamic multi-factor authentication system 410 serves as a security gate in front of critical systems. In some embodiments, the dynamic multi-factor authentication system 410 resides in the core system 414. In other embodiments, the dynamic multi-factor authentication system 410 is a stand-alone device or program.
[0061] Figure 5 is shown Figure 4Block diagram of the multi-factor authentication system 410 shown, which system can be on a vehicle or aircraft. In an exemplary embodiment, the multi-factor authentication system 410 includes: a multi-factor authentication server 502; a session token server 504; a biometric template server 506 having a database for storing data associated with authentication factors including biometric data; and a token server 508 having a database for storing data associated with authentication factors including token data. In some embodiments, the server 502, the server 504, the server 506, and the server 508 are separate physical devices on a vehicle or aircraft. In other embodiments, the server 502, the server 504, the server 506, and the server 508 are virtual devices that can be executed on one or more computer devices associated with the aircraft network 412( Figure 4 shown).
[0062] In an exemplary embodiment, the biometric template server 506 stores multiple biometric templates from multiple users. For example, the biometric template server 506 can store fingerprint data for multiple registered users. In an exemplary embodiment, the biometric template server 506 stores the biometric templates as encrypted data. For example, the biometric template server 506 can store the hash code of previously provided biometric data. Although the examples described herein use hash codes to store encrypted biometric data, those of ordinary skill in the art will understand that the systems described herein can use a variety of encryption methods. In an exemplary embodiment, the stored biometric template data has been previously provided by the user and stored in the biometric template server 506, such as when the user registers or updates his or her profile.
[0063] In an exemplary embodiment, the token server 508 stores encrypted token data or password data. As described above, this data is provided when the user registers or updates his or her profile with the system they wish to access. As described above with respect to biometric templates, the token or password data is similarly encrypted.
[0064] In an exemplary embodiment, the biometric data in the biometric template server 506 and the token data in the token server 508 are encrypted to ensure the security of the system 400. For example, if an attacker were able to access the biometric data or the token data contained in one of these servers 506 and 508, the encrypted nature of the data would make it more difficult for the attacker to use it to attempt to access the aircraft network 412 or other protected systems. If the data were not encrypted, the attacker could simply send the stored authentication data 402 to the multi-factor authentication system 410 to request access. However, since the data is encrypted, as described below, the multi-factor authentication system 410 will not be able to recognize the data. Additionally, the biometric data and the token data are divided between two separate servers 506 and 508 such that a compromise of one of the servers will not allow an attacker to obtain both the biometric data and the token data to access the system because each server 506 and 508 stores only half of the required biometric data and token data.
[0065] In an exemplary embodiment, when a user attempts to access the aircraft network 412, the user transmits the authentication data 402 to the multi-factor authentication system 410. The authentication information 402 is routed to the multi-factor authentication server 502. In some embodiments, the authentication data 402 is encrypted using a first encryption method before being transmitted to the multi-factor authentication server 502. The first encryption method is different from the encryption method used to store the data in the biometric template server 506 and the token server 508. The purpose of this encryption is to protect the data during transmission. For example, the encrypted authentication data 402 can be transmitted in the payload of one or more data packets transmitted to the multi-factor authentication system 400 via the electronic aircraft umbilical 102.
[0066] In an exemplary embodiment, the multi-factor authentication system 410 receives the authentication data 402. The authentication data 402 is routed to the multi-factor authentication server 502. If the authentication data 402 is encrypted, the multi-factor authentication server 502 decrypts the data using a first encryption / decryption method that is different from the encryption / decryption method used to encrypt the data stored in the biometric template server 506 and the token server 508. The multi-factor authentication server 502 transmits the authentication data 402 to the session token server 504. The session token server 504 parses the authentication data 402. The session token server 504 transmits the biometric data 404 to the biometric template server 506.
[0067] In an exemplary embodiment, the session token server 504 also transmits an identifier associated with the user, which may be the identifier included in the authentication data 402. In other embodiments, the identifier is an identifier that the session token server 504 looks up based on the user identifier in the authentication data 402. In an exemplary embodiment, the encrypted data is stored with a user identifier different from the user identifier used by the user to access the system. This requires a separate database that correlates the provided user identifier to the stored identifier. Additionally, the biometric template and the token data are stored with different identifiers. In this example, the user provides a user identifier in the authentication data 402. The session token server 504 uses the provided user identifier to look up the user identifier for the biometric template and the user identifier for the token. The session token server 504 transmits the appropriate user identifiers to the biometric template server 506 and the token server 508, respectively.
[0068] In some embodiments, the session token server 504 encrypts the biometric data 404 before transmitting it to the biometric template server 506. This encryption uses the same method as the method used for storing the biometric template. In these embodiments, the biometric template server 506 compares the received encrypted biometric data 404 with the stored biometric template and reports back whether a match exists. In other embodiments, the biometric template server 506 receives the unencrypted biometric data 404, encrypts the biometric data 404, and compares it with the corresponding stored biometric template. Then, the biometric template server 506 reports back whether a match exists.
[0069] In some embodiments, the session token server 504 encrypts the token data 406 or the password data 408 before transmitting it to the token server 508. This encryption uses the same method as the method used for storing the token / password data. In these embodiments, the token server 508 compares the received encrypted data 406 or 408 with the stored token / password data and reports back to the session token server 504 whether a match exists. In other embodiments, the token server 508 receives the unencrypted token data 406 or password data 408, encrypts the token data 406 or password data 408, and compares it with the corresponding stored token / password data. Then, the token server 508 reports back to the session token server 504 whether a match exists.
[0070] In an exemplary embodiment, the session token server 504 retrieves a biometric template or token / password data from the biometric template server 506 and the token server 508, respectively. The session token server 504 compares the retrieved biometric template and token / password data with the received authentication data 402 to determine if a match exists. In some embodiments, the session token server 504 encrypts the authentication data 502 prior to comparison. In other embodiments, the session token server 504 decrypts the retrieved biometric template or token / password data prior to comparison.
[0071] In other embodiments, the biometric template server 506 receives the received biometric data 404. The biometric template server 506 retrieves the corresponding biometric template and decrypts the retrieved template. The biometric template server 506 then compares the received biometric data 404 with the decrypted biometric template to determine if a match exists. The biometric template server 506 then reports back whether a match exists.
[0072] In other embodiments, the token server 508 receives the received token data 406 / password data 408. The token server 508 retrieves the corresponding stored token data / password data and decrypts the retrieved data. The token server 508 then compares the received token data 406 / password data 408 with the decrypted token data / password data to determine if a match exists. The token server 508 then reports back whether a match exists.
[0073] In an exemplary embodiment, the session token server 504 reports back to the multi-factor authentication server 502 whether authentication was successful, where the session token server 504 reports pass or fail. In an exemplary embodiment, the session token server 504 reports back which authentication check failed. If the authentication check is successful, the multi-factor authentication server 502 allows the requester computer device to access the aircraft network 412. If the authentication check fails, the multi-factor authentication server 502 blocks access to the aircraft network 412. When the requester computer device has failed the authentication check multiple times, the multi-factor authentication server 502 will impede the requester computer device from attempting again and filter the IP address to prevent any further attempts to access the aircraft network 412. In some other embodiments, the multi-factor authentication server 502 may report the IP address of the requester computer device as well as any biometric information provided to the core system 414 ( Figure 4 as shown), such that this information can be sent to one or more computer systems on the ground. This information can be sent via an off-aircraft link between the aircraft and the ground computer system. This may occur when the aircraft is on the ground or in the air.
[0074] In some embodiments, the multi-factor authentication server 502 performs the actions of the session token server 504 and communicates with the biometric template server 506 and the token server 508.
[0075] In some embodiments, each passenger has a biometric template stored in the biometric template server 506. This may occur when the passenger boards the aircraft. Additionally, each seat may have been assigned its own IP address. Further, each area of the aircraft can have its own separate router. These three sets of data allow the dynamic multi-factor authentication system 410 to determine whether a passenger is authenticated based on the passenger's attributes. For example, the dynamic multi-factor authentication system 410 can analyze the IP address and area from which it received the authentication request and confirm that the passenger who has submitted the biometric data 404 matches that seat and area.
[0076] In one example, the multi-factor authentication server 502 receives authentication data 402 that includes a username, biometric data 404, and token data 406. The multi-factor authentication server 502 transmits the authentication data 402 to the session token server 504. The session token server 504 accesses the user identifier database and uses the username in the authentication data 402 to retrieve a different user identifier for the user. The session token server 504 transmits the retrieved user identifier and the biometric data 404 to the biometric template server 506. The biometric template server 506 uses the retrieved user identifier to retrieve the biometric template associated with the user. The biometric template server 506 compares the retrieved biometric template with the received biometric data 404 to determine whether a match exists. The biometric template server 506 returns the result of the comparison. The session token server 504 transmits the retrieved user identifier and the token data 406 to the token server 508. The token server 508 uses the retrieved user identifier to retrieve the token data associated with the user. The token server 508 compares the retrieved token data with the received token data 406 to determine whether a match exists. The token server 508 returns the result of the comparison. The session token server 504 reports the results of the two comparisons, and if all comparisons match, the multi-factor authentication server 502 authenticates the user.
[0077] Figure 6 An example configuration of a Figure 1 client system shown in accordance with one embodiment of the present disclosure is shown.
[0078] The user computer device 602 is operated by the user 601. The user computer device 602 can include a first interface device 116, a second interface device 124 (both shown in Figure 1 ), and a main control unit 202 ( Figure 2as shown) and from unit 302( Figure 3 as shown). The user computer device 602 includes a processor 605 for executing instructions. In some embodiments, the executable instructions are stored in the memory area 610. The processor 605 may include one or more processing units (e.g., in a multi-core configuration). The memory area 610 is any device that allows information such as executable instructions and / or transaction data to be stored and retrieved. The memory area 610 may include one or more computer-readable media.
[0079] The user computer device 602 also includes at least one media output component 615 for presenting information to the user 601. The media output component 615 is any component capable of communicating information to the user 601. In some embodiments, the media output component 615 includes an output adapter (not shown), such as a video adapter and / or an audio adapter. The output adapter is operatively coupled to the processor 605 and is operatively coupleable to an output device, such as a display device (e.g., a cathode ray tube (CRT), a liquid crystal display (LCD), a light-emitting diode (LED) display, or an "electronic ink" display) or an audio output device (e.g., speakers or headphones). In some embodiments, the media output component 615 is configured to present a graphical user interface (e.g., a web browser and / or a client application) to the user 601. The graphical user interface may include, for example, one or more settings for connecting to another device via a power cable and / or receiving authentication information. In some embodiments, the user computer device 602 includes an input device 620 for receiving input from the user 601. The user 601 may use the input device 620 to (but is not limited to) select and / or input settings for the network. The input device 620 may include, for example, a keyboard, a pointing device, a mouse, a stylus, a touch-sensitive panel (e.g., a touchpad or a touchscreen), a gyroscope, an accelerometer, a position detector, a biometric input device, and / or an audio input device. A single component, such as a touchscreen, may serve as both the output device of the media output component 615 and the input device 620. In some embodiments, the input device 620 may also include the ability to receive authentication information from the user 601. In these embodiments, the input device 620 may include one or more of a keyboard or keypad, a card reader, a radio frequency identifier (RFID) reader, a biometric scanner, and any other device that can be used to identify and authenticate the user 601.
[0080] The user computer device 602 may also include a communication interface 625 communicatively coupled to a remote device such as the main control unit 202. The communication interface 625 may include, for example, a wired or wireless network adapter and / or a wireless data transceiver for use with a mobile telecommunications network.
[0081] Stored in the storage area 610 are, for example, computer-readable instructions for providing a user interface to the user 601 via the media output component 615 and, optionally, receiving and processing input from the input device 620. Among other possibilities, the user interface can also include a web browser and / or a client application. The web browser enables a user (such as user 601) to display media and other information (usually embedded in a web page or website from the main control unit 202) and interact with the media and other information. The client application allows the user 601 to interact with, for example, the main control unit 202. For example, the instructions can be stored by a cloud service, and the output of the instruction execution is sent to the media output component 615.
[0082] Figure 7 Illustrated is an example configuration of a Figure 1 , Figure 4 and Figure 5 server system as shown. The server computer device 701 can include, but is not limited to, a first interface device 116, a second interface device 124 (both shown in Figure 1 ), a main control unit 202 ( Figure 2 shown), a slave unit 302 ( Figure 3 shown), a dynamic multi-factor authentication system 410, a core system 414, a flight system 416, a fuel system 418, an entertainment system 420, other systems 422 ( Figure 4 shown), a multi-factor authentication server 502, a session token server 504, a biometric template server 506, and a token server 508 ( Figure 5 shown). The server computer device 701 also includes a processor 705 for executing instructions. The instructions can be stored in the memory area 710. The processor 705 can include one or more processing units (e.g., in a multi-core configuration).
[0083] The processor 705 is operatively coupled to the communication interface 715 such that the server computer device 701 can communicate with remote devices such as another server computer device 701, the slave unit 302, and the multi-factor authentication server 502. For example, the communication interface 715 can receive weather information from a computer device connected to the main control unit 202 via the Internet.
[0084] The processor 705 may also be operatively coupled to a storage device 734. The storage device 734 is any computer-operable hardware suitable for storing and / or retrieving data, such as but not limited to data associated with a database. In some embodiments, the storage device 734 is integrated within the server computer device 701. For example, the server computer device 701 may include one or more hard disk drives as the storage device 734. In other embodiments, the storage device 734 is external to the server computer device 701 and may be accessed by multiple server computer devices 701. For example, the storage device 734 may include a storage area network (SAN), a network attached storage (NAS) system, and / or multiple storage units, such as hard disks and / or solid state disks in a redundant array of inexpensive disks (RAID) configuration.
[0085] In some embodiments, the processor 705 is operatively coupled to the storage device 734 via a storage interface 720. The storage interface 720 is any component capable of providing the processor 605 access to the storage device 734. The storage interface 720 may include, for example, an advanced technology attachment (ATA) adapter, a serial ATA (SATA) adapter, a small computer system interface (SCSI) adapter, a RAID controller, a SAN adapter, a network adapter, and / or any component that provides the processor 705 access to the storage device 734.
[0086] The processor 705 executes computer-executable instructions for implementing aspects of the present disclosure. In some embodiments, by executing the computer-executable instructions or by being otherwise programmed, the processor 705 is transformed into a dedicated microprocessor. For example, the processor 705 is programmed with instructions such as those shown below.
[0087] Figure 8 is a flowchart of a process for authenticating a user using Figure 4 and Figure 5 the multi-factor authentication system 410 shown. In other embodiments, the process 800 is performed by a dynamic multi-factor authentication system 410 ( Figure 4 shown). In some embodiments, the steps of the process 800 may be performed by one or more of a multi-factor authentication server 502, a session token server 504, a biometric template server 506, and a token server 508 (all shown in Figure 5 ).
[0088] In an exemplary embodiment, the dynamic multi-factor authentication system 410 receives 805 from a user 601 ( Figure 6 shown) access to one or more protected computer systems, such as an aircraft network 412 ( Figure 4a request for a computer system (as shown). The request includes authentication information 402, which includes a first authentication factor such as biometric data 404 and a second authentication factor such as token data 406 or password data 408. In some embodiments, the dynamic multi-factor authentication system 410 and the aircraft network 412 are on the aircraft 110.
[0089] In an exemplary embodiment, the dynamic multi-factor authentication system 410 retrieves 810 first-factor authentication data associated with the user 601 from a first database that stores a first plurality of authentication data associated with the first factor for authentication. In an exemplary embodiment, the first database is associated with the biometric template server 506. In some embodiments, the first plurality of authentication data stored in the first database is encrypted using a first encryption method. In some embodiments, the dynamic multi-factor authentication system 410 encrypts the received first authentication factor using the first encryption method before comparison. In other embodiments, the dynamic multi-factor authentication system 410 decrypts the first-factor authentication data before comparison.
[0090] In some embodiments, the dynamic multi-factor authentication system 410 includes a first authentication computer device associated with the first database. In some embodiments, the first authentication computer device is similar to the biometric template server 506. The dynamic multi-factor authentication system 410 compares 815 the first-factor authentication data with the received first authentication factor 404 to determine if there is a match. In these embodiments, the biometric template server 506 performs the comparison of the first authentication factor with the first-factor authentication data. The biometric template server 506 transmits the result of the comparison to the multi-factor authentication server 502. In some other embodiments, the result only includes pass or fail.
[0091] The dynamic multi-factor authentication system 410 retrieves 820 second-factor authentication data associated with the user 601 from a second database that stores a second plurality of authentication data associated with the second factor for authentication. In an exemplary embodiment, the second database is associated with the token server 508. In some embodiments, the second plurality of authentication data stored in the second database is encrypted using a second encryption method. In some embodiments, the dynamic multi-factor authentication system 410 encrypts the received second authentication factor using the second encryption method before comparison. In other embodiments, the dynamic multi-factor authentication system 410 decrypts the second-factor authentication data before comparison.
[0092] The dynamic multi-factor authentication system 410 compares 825 the second-factor authentication data with the received second authentication factor to determine if a match exists. In these embodiments, the token server 508 performs the comparison of the second authentication factor with the second-factor authentication data. The token server 508 transmits the result of the comparison to the multi-factor authentication server 502. In some other embodiments, the result only includes pass or fail.
[0093] If all comparisons match, the dynamic multi-factor authentication system 410 grants 830 access to one or more protected computer systems.
[0094] If a match does not exist for all comparisons, the dynamic multi-factor authentication system 410 denies 835 access to one or more protected computer systems.
[0095] In some embodiments, the request is received via a broadband power line (BPL) connection 208 ( Figure 2 as shown). In some other embodiments, the request originates from a ground-based modem, such as the master control unit 202 ( Figure 2 as shown).
[0096] In some embodiments, the dynamic multi-factor authentication system 410 further includes a third database that stores multiple user identifier information. In these embodiments, the request includes a first user identifier. The first database stores a first plurality of authentication data based on a second user identifier. The dynamic multi-factor authentication system 410 retrieves the second user identifier from the third database based on the first user identifier. The first user identifier and the second user identifier are different. The dynamic multi-factor authentication system 410 retrieves the first-factor authentication data associated with the user based on the second user identifier.
[0097] In some other embodiments, a third encryption method is used to encrypt the first authentication factor and the second authentication factor in the request. The dynamic multi-factor authentication system 410 extracts the first authentication factor and the second authentication factor from the request. Then, the dynamic multi-factor authentication system 410 decrypts the first authentication factor and the second authentication factor before transmitting them to the biometric template server 506 or the token server 508.
[0098] At least one technical solution to the technical problems provided for the system may include: (i) an improved security system; (ii) a simplified process for authenticating users; (iii) increased difficulty for external attackers due to the encryption and separation of biometric data and token data; (iv) tracking attackers and preventing them from accessing the system; (v) improving the security of the aircraft system.
[0099] The methods and systems described herein can be implemented using computer programming or engineering techniques including computer software, firmware, hardware, or any combination or subset thereof, where the technical effects can be achieved by performing at least one of the following steps: (a) receiving, from a user, a request to access one or more protected computer systems, where the request includes authentication information including a first authentication factor and a second authentication factor; (b) retrieving, from a first database, first-factor authentication data associated with the user; (c) comparing the first-factor authentication data with the received first authentication factor to determine if a match exists; (d) retrieving, from a second database, second-factor authentication data associated with the user; (e) comparing the second-factor authentication data with the received second authentication factor to determine if a match exists; and (f) granting access to the one or more protected computer systems if all comparisons match.
[0100] Although described with respect to aircraft broadband power line applications, embodiments of the present disclosure are also applicable to other transportation vehicles such as ships, barges, and boats docked at ports or marinas and wheeled vehicles parked in service areas.
[0101] The above methods and systems for transmitting power and digital communications at the aircraft gate to directly provide high-speed Internet service support to an aircraft are cost-effective, secure, and highly reliable. The methods and systems include integrating BPL or X10-like technologies into the aircraft and airport infrastructure to provide broadband Internet and data services to the aircraft with minimal infrastructure impact and cost. Integrating BPL, X10, or similar technologies into the airport and aircraft allows for the use of existing aircraft gate umbilicals to provide high-speed and highly reliable Internet and data services from the airport gate to the aircraft. Thus, these methods and systems facilitate the transmission of power and digital communications in a safe, cost-effective, and reliable manner.
[0102] The computer-implemented methods discussed herein can include additional, fewer, or alternative actions, including actions discussed elsewhere herein. The methods can be implemented via one or more local or remote processors, transceivers, servers, and / or sensors (such as processors, transceivers, servers, and / or sensors mounted on a transportation vehicle or mobile device or associated with smart infrastructure or a remote server) and / or via computer-executable instructions stored on a (one or more) non-transitory computer-readable medium. Additionally, the computer systems discussed herein can include additional, fewer, or alternative functions, including functions discussed elsewhere herein. The computer systems discussed herein can include computer-executable instructions stored on a (one or more) non-transitory computer-readable medium or be implemented via computer-executable instructions stored on a (one or more) non-transitory computer-readable medium.
[0103] As used herein, the term "non-transitory computer-readable medium" is intended to represent any tangible computer-based device implemented in any method or technology for short-term and long-term storage of information such as computer-readable instructions, data structures, program modules and sub-modules, or other data in any device. Thus, the methods described herein may be encoded as executable instructions embodied in a tangible non-transitory computer-readable medium, including but not limited to storage devices and / or memory devices. When executed by a processor, such instructions cause the processor to perform at least a portion of the methods described herein. Additionally, as used herein, the term "non-transitory computer-readable medium" includes all tangible computer-readable media, including but not limited to non-transitory computer storage devices, including but not limited to volatile and non-volatile media, and removable and non-removable media (such as firmware, physical and virtual storage, CD-ROM, DVD, and any other digital source, such as a network or the Internet) and digital devices not yet developed, with the sole exception being transitory propagating signals.
[0104] As described above, the described embodiments enable secure vehicle broadband communication with a data network. More specifically, the present disclosure is directed to using powerline broadband (BPL) communication to enable aircraft information exchange to occur at increased speeds and where conventional data exchange services may not be available. More specifically, a master control unit on the ground and a slave unit on the aircraft establish a two-way communication channel via one or more powerlines and ensure the security and integrity of data transmitted via the powerlines. The master control unit also ensures that data is transmitted to its intended destination via the most efficient wireless network.
[0105] The above-described methods and systems for BPL communication are cost-effective, secure, and highly reliable. The method and system include: detecting a connection of a slave unit via a BPL connection; receiving a plurality of data from the slave unit via the BPL connection; determining a destination for the plurality of data; comparing two or more transmission methods for transmitting the plurality of data to the destination; and transmitting the plurality of data to the destination via one of the two or more transmission methods based on the comparison. Thus, these methods and systems contribute to improving the use and efficiency of BPL communication by enhancing the ability of the BPL communication system to communicate with external systems that are not compatible with a 115Vac, 400Hz, three-phase power system.
[0106] The methods and systems described herein can be implemented using computer programming or engineering techniques that include computer software, firmware, hardware, or any combination or subset thereof. As described above, at least one technical problem with existing systems is the need for a system for cost-effective and reliable BPL communication. The systems and methods described herein solve this technical problem. The technical effects of the systems and processes described herein are achieved by performing at least one of the following steps: (a) detecting a connection of a slave unit via a BPL connection; (b) receiving a plurality of data from the slave unit via the BPL connection; (c) determining a destination for the plurality of data; (d) comparing two or more transmission methods for transmitting the plurality of data to the destination; and (e) based on the comparison, transmitting the plurality of data to the destination via one of the two or more transmission methods. The resulting technical effect is communication between a BPL system based on a wireless communication bridge and other computer systems.
[0107] In addition, the present disclosure includes embodiments according to the following clauses:
[0108] Clause 1. A multi-factor authentication system (410) on a vehicle (110), comprising:
[0109] At least one on-board processor (705);
[0110] A first on-board database that stores a first plurality of authentication data (402) associated with a first factor for authentication; and
[0111] A second on-board database that stores a second plurality of authentication data (402) associated with a second factor for authentication,
[0112] wherein the at least one processor (705) communicates with the first on-board database, the second on-board database, and one or more on-board protected computer systems (414), and wherein the at least one processor (705) is programmed to:
[0113] Receive a request from a user (601) to access the one or more on-board protected computer systems (414), wherein the request contains authentication data (402) that includes a first authentication factor (402) and a second authentication factor (402);
[0114] Retrieve first factor authentication data associated with the user (601) from the first on-board database;
[0115] Compare the first factor authentication data with the received first authentication factor (402) to determine if a match exists;
[0116] Retrieve the second factor authentication data associated with the user (601) from the second on-board database;
[0117] Compare the second factor authentication data with the received second authentication factor (402) to determine if there is a match; and
[0118] If all comparisons match, grant access to the one or more airborne protected computer systems (414).
[0119] Clause 2. The system according to claim 1, wherein the at least one processor (705) is further programmed to: if there is no match for all comparisons, deny access to the one or more protected computer systems (414).
[0120] Clause 3. The system according to claim 1, wherein the first plurality of authentication data (402) stored in the first database is encrypted using a first encryption method, and wherein the processor (705) is further programmed to encrypt the received first authentication factor using the first encryption method before comparison.
[0121] Clause 4. The system according to claim 3, further comprising a first authentication computer device associated with the first database, wherein the first authentication computer device is programmed to:
[0122] Perform a comparison of the first authentication factor (402) with the first factor authentication data; and
[0123] Transmit the result of the comparison to the at least one processor (705).
[0124] Clause 5. The system according to claim 4, wherein the second plurality of authentication data (402) stored in the second database is encrypted using a second encryption method, and wherein the processor (705) is further programmed to encrypt the received second authentication factor using the second encryption method before comparison.
[0125] Clause 6. The system according to claim 5, further comprising a second authentication computer device associated with the second database, wherein the second authentication computer device is programmed to:
[0126] Perform a comparison of the second authentication factor (402) and the second factor authentication data; and
[0127] Transmit the result of the comparison to the at least one processor (705).
[0128] Clause 7. The system according to claim 6, wherein the first on-board database resides on a first on-board server, and the first plurality of authentication data (402) associated with the first factor for authentication includes token data (406), and the second on-board database resides on a second on-board server, and the second plurality of authentication data (402) associated with the second factor for authentication includes biometric data (404), wherein the token data (406) and the biometric data (404) are divided between the first on-board server (506) and the second on-board server (508) such that a breach of one on-board server will enable access to both the token data (406) and the biometric data (404).
[0129] Clause 8. The system according to claim 1, wherein the request from the user (601) is received from a device not on the vehicle (110).
[0130] Clause 9. The system according to claim 8, wherein the request is received via a broadband power line connection, i.e., a BPL connection (208), and wherein the request originates from a ground-based modem.
[0131] Clause 10. The system according to claim 1, wherein the multi-factor authentication system (410) and the one or more protected computer systems (414) are on an aircraft (110).
[0132] Clause 11. The system according to claim 1, further comprising a third database that stores a plurality of user identifier information, wherein the request includes a first user identifier, wherein the first database stores the first plurality of authentication data (402) based on a second user identifier, and wherein the processor (705) is further programmed to:
[0133] retrieve the second user identifier from the third database based on the first user identifier, wherein the first user identifier and the second user identifier are different; and
[0134] retrieve the first factor authentication data (402) associated with the user (601) based on the second user identifier.
[0135] Clause 12. The system according to claim 1, wherein a third encryption method is used to encrypt the first authentication factor and the second authentication factor in the request, and wherein the at least one processor (705) is further programmed to:
[0136] extract the first authentication factor (402) and the second authentication factor (402) from the request; and
[0137] Decrypt the first authentication factor (402) and the second authentication factor (402).
[0138] Clause 13. A multi-factor authentication computer device (410) on a vehicle (110), comprising at least one processor (705) communicating with a first on-board database, a second on-board database, and one or more on-board protected computer systems (414), wherein the first on-board database stores a first plurality of authentication data (402) associated with a first factor for authentication, wherein the second on-board database stores a second plurality of authentication data (402) associated with a second factor for authentication, and wherein the at least one processor (705) is programmed to:
[0139] Receive, from a user (601) not on the vehicle (110), a request to access the one or more protected computer systems (414), wherein the request includes authentication information, the authentication information including a first authentication factor (402) and a second authentication factor (402);
[0140] Retrieve, from the first on-board database, first-factor authentication data associated with the user (601);
[0141] Compare the first-factor authentication data with the received first authentication factor (402) to determine if a match exists;
[0142] Retrieve, from the second on-board database, the second-factor authentication data associated with the user (601);
[0143] Compare the second-factor authentication data with the received second authentication factor (402) to determine if a match exists; and
[0144] If all comparisons match, grant access to the one or more on-board protected computer systems (414).
[0145] Clause 14. The computer device (410) according to claim 13, wherein the at least one processor (705) is further programmed to: if a match does not exist for all comparisons, deny access to the one or more on-board protected computer systems (414).
[0146] Clause 15. The computer device (410) according to claim 13, wherein the first plurality of authentication data (402) stored in the first database is encrypted using a first encryption method, and wherein the processor (705) is further programmed to encrypt the received first authentication factor (402) using the first encryption method before comparison.
[0147] Clause 16. The computer device (410) according to claim 15, wherein the computer device (410) communicates with a first authentication computer device (506), the first authentication computer device (506) being associated with the first on-board database, wherein the first authentication computer device (506) is programmed to:
[0148] perform a comparison of the first authentication factor (402) with the first factor authentication data; and
[0149] transmit the result of the comparison to the at least one processor (705), wherein the result includes only pass or fail.
[0150] Clause 17. The computer device (410) according to claim 13, wherein the second plurality of authentication data (402) stored in the second on-board database is encrypted using a second encryption method, and wherein the processor (705) is further programmed to encrypt the received second authentication factor using the second encryption method before comparison.
[0151] Clause 18. The computer device (410) according to claim 17, wherein the computer device (410) communicates with a second authentication computer device (508), the second authentication computer device (508) being associated with the second database, wherein the second authentication computer device (508) is programmed to:
[0152] perform a comparison of the second authentication factor (402) with the second factor authentication data; and
[0153] transmit the result of the comparison to the at least one processor (705), wherein the result includes only pass or fail.
[0154] Clause 19. The computer device (410) according to claim 13, wherein the request is received via a broadband power line (BPL) connection (208), wherein the request originates from a ground-based modem, and wherein the multi-factor authentication computer device (410) and the one or more protected computer systems (414) are on an aircraft (110).
[0155] Clause 20. A method for authenticating a user (601), the method being executed by at least one processor (705) on a vehicle (110), the at least one processor (705) communicating with at least one memory device, the method comprising:
[0156] Receiving (805) from the user (601) a request to access one or more protected computer systems, wherein the request contains authentication information, the authentication information including a first authentication factor (402) and a second authentication factor (402);
[0157] Retrieving (810) from a first on-board database first factor authentication data associated with the user (601), the first on-board database storing a first plurality of authentication data (402) associated with a first factor for authentication;
[0158] Comparing (815) the first factor authentication data (402) with the received first authentication factor (402) via an on-board multi-factor authentication system (410) to determine if a match exists;
[0159] Retrieving (820) from a second on-board database second factor authentication data associated with the user (601), the second on-board database storing a second plurality of authentication data associated with a second authentication factor;
[0160] Comparing (825) the second factor authentication data with the received second authentication factor (402) via an on-board multi-factor authentication system (410) to determine if a match exists;
[0161] If all comparisons match, granting (830) access to the one or more on-board protected computer systems (414); and
[0162] If a match does not exist for all comparisons, denying (835) access to the one or more on-board protected computer systems (414).
[0163] This written description uses examples to disclose various embodiments including the best mode, and also enables those skilled in the art to practice various embodiments, including making and using any device or system and performing any combined method. The patentable scope of this disclosure is defined by the claims, and may include other examples that occur to those skilled in the art. If such other examples have structural elements that are not different from the literal language of the claims, or if they include equivalent structural elements that are not substantially different from the literal language of the claims, then they are intended to be within the scope of the claims.
Claims
1. A multi-factor authentication system (410) on a vehicle (110), comprising: At least one on-board processor (705); A first encrypted on-board database storing a first plurality of authentication data (402) associated with a first factor for authentication and encrypted using a first encryption method; And A second encrypted on-board database storing a second plurality of authentication data (402) associated with a second factor for authentication and encrypted using a second encryption method different from the first encryption method, wherein the first encrypted on-board database and the second encrypted on-board database are stored separately, wherein the first factor for authentication is different from the second factor for authentication, and wherein the first plurality of authentication data is different from the second plurality of authentication data, Wherein the at least one processor (705) communicates with the first encrypted on-board database, the second encrypted on-board database, and one or more on-board protected computer systems (414), and wherein the at least one processor (705) is programmed to: Receive from a user (601) a request to access the one or more on-board protected computer systems (414), the request including a first authentication factor (402), a second authentication factor (402), and an identifier associated with the user, wherein the identifier is different from the first authentication factor and the second authentication factor; Based on the identifier, retrieve from the first encrypted on-board database the first factor authentication data associated with the user (601); Compare the first factor authentication data with the received first authentication factor (402) to determine whether a first match exists; Based on the identifier, retrieve from the second encrypted on-board database the second factor authentication data associated with the user (601); Compare the second factor authentication data with the received second authentication factor (402) to determine whether a second match exists; And If all comparisons match, grant access to the one or more on-board protected computer systems (414).
2. The system according to claim 1, wherein the at least one processor (705) is further programmed to: if a match does not exist for all comparisons, deny access to the one or more protected computer systems (414).
3. The system according to claim 1, wherein the processor (705) is further programmed to: Receive encrypted first factor authentication data encrypted using the first encryption method; Before the comparison, encrypt the received first authentication factor using the first encryption method; and Compare the encrypted received first authentication factor and the encrypted first factor authentication data.
4. The system according to claim 3, further comprising a first authentication computer device associated with the first encrypted on-board database, wherein the first authentication computer device is programmed to: Perform the comparison of the encrypted first authentication factor (402) and the encrypted first factor authentication data; and Transmit the result of the comparison to the at least one processor (705).
5. The system according to claim 4, wherein the processor (705) is further programmed to: Receive encrypted second-factor authentication data encrypted using the second encryption method; Before the comparison, encrypt the received second authentication factor using the second encryption method; and Compare the encrypted received second authentication factor and the encrypted second-factor authentication data.
6. The system according to claim 5, further comprising a second authentication computer device associated with the second encrypted on-board database, wherein the second authentication computer device is programmed to: Perform the comparison of the encrypted second authentication factor (402) and the encrypted second-factor authentication data; and Transmit the result of the comparison to the at least one processor (705).
7. The system according to claim 6, wherein the first encrypted on-board database resides on a first on-board server, and the first plurality of authentication data (402) associated with the first factor for authentication includes encrypted token data (406), and the second encrypted on-board database resides on a second on-board server, and the second plurality of authentication data (402) associated with the second factor for authentication includes encrypted biometric data (404), wherein the encrypted token data (406) and the encrypted biometric data (404) are divided between the first on-board server (506) and the second on-board server (508) such that a leak of one on-board server will render it impossible to access both the encrypted token data (406) and the encrypted biometric data (404).
8. The system according to claim 1, wherein the request of the user (601) is received from a device not on the vehicle (110).
9. The system according to claim 8, wherein the request is received via a broadband power line connection, i.e., a BPL connection (208), and wherein the request originates from a ground-based modem.
10. The system according to claim 1, wherein the multi-factor authentication system (410) and the one or more protected computer systems (414) are on an aircraft (110).
11. The system according to claim 1, further comprising: A third database that stores a plurality of user identifier information, wherein the identifier is a first user identifier, wherein the first encrypted on-board database stores the first plurality of authentication data (402) based on a second user identifier, and wherein the processor (705) is further programmed to: Retrieve the second user identifier from the third database based on the first user identifier, wherein the first user identifier and the second user identifier are different; and Retrieve the first-factor authentication data (402) associated with the user (601) based on the second user identifier.
12. The system according to claim 1, wherein a third encryption method different from the first encryption method and the second encryption method is used to encrypt the first authentication factor and the second authentication factor in the request, and wherein the at least one processor (705) is further programmed to: Extract the first authentication factor (402) and the second authentication factor (402) from the request; and Decrypt the first authentication factor (402) and the second authentication factor (402).
13. A method for authenticating a user (601), the method being executed by at least one processor (705) on a vehicle (110), the at least one processor (705) communicating with at least one memory device, the method comprising: Receiving (805) from a user (601) a request to access one or more protected computer systems, the request including a first authentication factor (402), a second authentication factor (402), and an identifier associated with the user, wherein the identifier is different from the first authentication factor and the second authentication factor; Based on the identifier, retrieving (810) first factor authentication data associated with the user (601) from a first encrypted on-board database, the first encrypted on-board database storing a first plurality of authentication data (402) associated with a first factor for authentication and encrypted using a first encryption method; Comparing (815) the first factor authentication data (402) with the received first authentication factor (402) via an on-board multi-factor authentication system (410) to determine if a first match exists; Based on the identifier, retrieving (820) second factor authentication data associated with the user (601) from a second encrypted on-board database, the second encrypted on-board database storing a second plurality of authentication data associated with a second factor for authentication and encrypted using a second encryption method different from the first encryption method, wherein the first encrypted on-board database and the second encrypted on-board database are stored separately, and wherein the first factor for authentication is different from the second factor for authentication; Comparing (825) the second factor authentication data with the received second authentication factor (402) via the on-board multi-factor authentication system (410) to determine if a second match exists, wherein the first plurality of authentication data is different from the second plurality of authentication data; If all comparisons match, granting (830) access to the one or more on-board protected computer systems (414); And If a match does not exist for all comparisons, denying (835) access to the one or more on-board protected computer systems (414).
Citation Information
Patent Citations
Secure aircraft data channel communication for aircraft operations
US20120177198A1
Access system for a vehicle and method for managing access to a vehicle
US20160148449A1
Data protection and security for in-vehicle systems
US20190058728A1