On-line upgrade (OTA) system and on-line upgrade method for airborne application data

Through the airborne application data online upgrade system, it supports two-way data transmission between the ground and the air, dynamically controls upgrade permissions, and adopts differentiated security verification and breakpoint resumption technology to solve the problem of insufficient timeliness of airborne data upgrades, and realizes full-stage upgrade capabilities and efficient data transmission.

CN120848931APending Publication Date: 2025-10-28COMMERCIAL AIRCRAFT CORP OF CHINA LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510963312.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-11
Publication Date
2025-10-28

AI Technical Summary

Technical Problem

In existing technologies, airborne data upgrades can only be completed on the ground, which is not timely enough to meet emergency needs. It also relies on manual operations, which is inefficient and affects flight scheduling. It is also impossible to retransmit data or install patches in the air.

Method used

An airborne application data online upgrade (OTA) system was designed. It supports two-way data transmission between the ground and the air, and realizes rapid wireless upgrade of information systems through wireless communication links. It includes a network security module and a file server module, dynamically controls upgrade permissions, and adopts differentiated security verification and breakpoint resume technology.

Benefits of technology

It achieves full-stage upgrade capabilities, reduces maintenance time and costs, improves data upgrade efficiency, reduces manual intervention, and ensures system stability and flexibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120848931A_ABST
    Figure CN120848931A_ABST
Patent Text Reader

Abstract

The present application describes an onboard application data online upgrade (OTA) system, the system supporting terrestrial and air bi-directional data transmission and comprising: an OTA terrestrial terminal for generating OTA data associated with loadable software / applications (DLS / DLA) of an information system, and an OTA onboard terminal for generating OTA data associated with the loadable software / applications (DLS / DLA) of the information system; the OTA airborne end is used for receiving, storing and processing the OTA data, the OTA airborne end interacts with the OTA ground end through a wireless communication link, and the OTA airborne end comprises a network security module used for configuring a static strategy file to carry out differential security verification on the OTA data; and a file server module for controlling a function associated with the OTA data. The invention also discloses a method for carrying out online upgrading by using the system, and numerous other aspects.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of avionics and information technology, and more specifically to an over-the-air (OTA) system and method for over-the-air (OTA) updates of airborne application data. Background Technology

[0002] With the increasing intelligence of aircraft information systems, the frequency of upgrades for field-loadable software / applications (DLS / DLA) has significantly increased. Currently, airborne data upgrades can only be completed on the ground, resulting in insufficient timeliness. If an upgrade fails during transit maintenance, the same flight cannot be upgraded again, leaving the flight crew without access to the latest data (e.g., real-time weather information). Furthermore, current upgrade technologies are inefficient, relying on manual operation and centralized loading tools, leading to long maintenance times and impacting flight scheduling efficiency. In-flight data transmission or patch installation is also impossible, limiting flexibility and making it difficult to respond to emergency needs.

[0003] Therefore, there is an urgent need to propose an airborne application data online upgrade (OTA) system, especially a system that enables rapid wireless upgrades of information system field-loadable software based on network security protection and air-to-ground wireless communication links. Summary of the Invention

[0004] The following provides a brief overview of one or more aspects to offer a basic understanding of them. This overview is not an exhaustive summary of all conceived aspects, nor is it intended to identify the key or decisive elements of all aspects, nor to define the scope of any or all aspects. Its sole purpose is to present some concepts of one or more aspects in a simplified form as a prelude to the more detailed descriptions that follow.

[0005] To address the aforementioned issues, this paper proposes an Over-the-Air (OTA) system and method for updating airborne application data.

[0006] In one aspect of this application, an Over-the-Air (OTA) system for airborne application data updates is disclosed. The system supports bidirectional data transmission between the ground and the air and includes: an OTA ground terminal for generating OTA data associated with loadable software / applications (DLS / DLA) of an information system; and an OTA airborne terminal for receiving, storing, and processing the OTA data. The OTA airborne terminal interacts with the OTA ground terminal via a wireless communication link. The OTA airborne terminal includes: a network security module for configuring static policy files to perform differentiated security verification on the OTA data; and a file server module for controlling functions associated with the OTA data. The OTA airborne terminal and the OTA ground terminal interact via a wireless communication link, and the system supports bidirectional data transmission between the ground and the air.

[0007] Preferably, the file server module is further configured to: monitor the status of the wireless communication link and aircraft parameters during the uploading, loading, and upgrading of the OTA data; and dynamically control the operation permissions of the function based at least in part on the status of the wireless communication link and the aircraft parameters.

[0008] Preferably, the status of the wireless communication link indicates whether at least one of airport Wi-Fi, cellular network, air-to-ground communication, or satellite link is connected; the aircraft parameters indicate at least one of the following: whether the front boarding gate is open, whether the aircraft is on the ground, whether the flight altitude is greater than or equal to a first altitude threshold, whether the flight altitude is greater than or equal to a second altitude threshold, or whether the flight altitude is greater than or equal to a third altitude threshold.

[0009] Preferably, the file server module dynamically controls the operation permissions of the function, including one or more of the following: when the aircraft parameters indicate that the aircraft is on the ground and the wireless communication link is connected, the upload of OTA data is allowed; when the aircraft parameters indicate that the aircraft's flight altitude is greater than or equal to a first altitude threshold and the wireless communication link is connected, the upload of OTA data is allowed; when the aircraft parameters indicate that the aircraft is on the ground or the flight altitude is greater than or equal to a second altitude threshold, the loading of OTA data is allowed; and when the aircraft parameters indicate that the aircraft is on the ground or the flight altitude is greater than or equal to a third altitude threshold, the upgrade of OTA data is allowed, wherein the first altitude threshold, the second altitude threshold, and the third altitude threshold may be the same or different.

[0010] Preferably, the function includes resuming interrupted transmission, wherein the file server module is further used to generate a temporary file to record the transmission progress of the OTA data, and to continue transmission based on the location of the interrupted point after the wireless communication link is restored, based on the location of the temporary file.

[0011] Preferably, the network security module is further configured to: perform differentiated security verification on the OTA data according to a pre-set security level using the static policy configuration file.

[0012] Preferably, the security level includes three levels: high security level, medium security level, and low security level, wherein OTA data belonging to the high security level adopts a multi-layer encryption and two-way authentication process; OTA data belonging to the medium security level adopts one-way encryption authentication; and OTA data belonging to the low security level adopts basic verification.

[0013] Preferably, the OTA display interface is used to select one or more DLS / DLAs for upgrade; and / or to display a progress bar and completion status prompts in real time during the loading of the OTA data.

[0014] Preferably, the OTA airborne terminal is further configured to: periodically send a loading success confirmation message to the OTA ground terminal after the OTA data loading is completed; and update the configuration information of the DLS / DLA of the information system.

[0015] In one aspect of this application, a method for online over-the-air (OTA) upgrade of airborne application data is disclosed. This method supports bidirectional data transmission between the ground and the air, and includes: generating OTA data associated with loadable software / applications (DLS / DLA) of an information system via an OTA ground terminal; interacting between the OTA airborne terminal and the OTA ground terminal via a wireless communication link; configuring a static policy file via a network security module of the OTA airborne terminal to perform differentiated security verification on the OTA data; and controlling functions associated with the OTA data via a file server module of the OTA airborne terminal; and interacting between the OTA airborne terminal and the OTA ground terminal via a wireless communication link, wherein the method supports bidirectional data transmission between the ground and the air.

[0016] Preferably, the file server module is further configured to: monitor the status of the wireless communication link and aircraft parameters during the uploading, loading, and upgrading of the OTA data; and dynamically control the operation permissions of the function based at least in part on the status of the wireless communication link and the aircraft parameters.

[0017] Preferably, the operating permissions for dynamically controlling the function include one or more of the following: allowing the uploading of OTA data when the aircraft parameters indicate that the aircraft is on the ground and the wireless communication link is connected; allowing the uploading of OTA data when the aircraft parameters indicate that the aircraft's flight altitude is greater than or equal to a first altitude threshold and the wireless communication link is connected; allowing the loading of OTA data when the aircraft parameters indicate that the aircraft is on the ground or the flight altitude is greater than or equal to a second altitude threshold; and allowing the upgrading of OTA data when the aircraft parameters indicate that the aircraft is on the ground or the flight altitude is greater than or equal to a third altitude threshold, wherein the first altitude threshold, the second altitude threshold, and the third altitude threshold may be the same or different.

[0018] Preferably, the static policy configuration file performs the differentiated security verification on the OTA data according to a pre-set security level.

[0019] Preferably, the security level includes three levels: high security level, medium security level, and low security level, wherein OTA data belonging to the high security level adopts a multi-layer encryption and two-way authentication process; OTA data belonging to the medium security level adopts one-way encryption authentication; and OTA data belonging to the low security level adopts basic verification.

[0020] This synopsis is provided to introduce some concepts in a simplified form, which will be further described in the detailed description below. This synopsis is not intended to identify key or essential features of the claimed subject matter, nor is it intended to limit the scope of the claimed subject matter. Other aspects, features, and / or advantages of the embodiments will be set forth in part in the description which follows, and will be apparent in part from the description, or may be learned by practice of this disclosure. Attached Figure Description

[0021] To gain a detailed understanding of the manner in which the above-described features of the invention are employed, a more specific description of the above-briefly summarized content can be provided with reference to various embodiments, some of which are illustrated in the accompanying drawings. However, it should be noted that the drawings only illustrate certain typical aspects of the invention and should not be considered as limiting its scope, as this description may allow for other equivalent aspects. In the drawings, similar reference numerals are consistently used for similar purposes. It should be noted that the described drawings are merely schematic and non-limiting. In the drawings, the dimensions of some components may be enlarged and are not drawn to scale for illustrative purposes.

[0022] Figure 1 A schematic diagram of an airborne application data OTA system according to an embodiment of the present invention is explained.

[0023] Figure 2A schematic diagram illustrating the process of loading air-to-ground wireless data according to an embodiment of the present invention is provided.

[0024] Figure 3 An example of the process flow for implementing online upgrades of field-loadable software / applications in an information system according to an embodiment of the present invention is explained.

[0025] Figure 4 A block diagram illustrating an apparatus for enabling online upgrades of field-loadable software / applications in an information system, according to an embodiment of the present invention, is provided. Detailed Implementation

[0026] To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to specific embodiments and the accompanying drawings. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the described exemplary embodiments. However, it will be apparent to those skilled in the art that the described embodiments can be practiced without some or all of these specific details. In other exemplary embodiments, well-known structures or processing steps have not been described in detail to avoid unnecessarily obscuring the concepts of this disclosure.

[0027] In this specification, unless otherwise stated, the term "A or B" as used herein refers to "A and B" and "A or B", and does not imply that A and B are exclusive.

[0028] Figure 1 A schematic diagram 100 of an airborne application data OTA loading system according to an embodiment of the present invention is explained.

[0029] In the embodiments of the present application, Figure 1 As shown, the online update (OTA) system for field-loadable software / applications (DLS / DLA) of the information system (hereinafter referred to as the IS system) (also known as the OTA architecture) includes: an OTA ground terminal and an OTA airborne terminal, etc., and the OTA airborne terminal includes a network security module, a file server module, etc. This airborne application data OTA system supports bidirectional data transmission between the ground and the air.

[0030] In embodiments of this application, the OTA ground terminal can generate OTA data associated with the DLS / DLA of the IS system. For example, the OTA ground terminal can provide DLS / DLA update information and update data of the aircraft's IS system and transmit them to the OTA airborne terminal via the IS system's wireless communication link (e.g., Wi-Fi / cellular). Additionally or alternatively, the OTA ground terminal can also receive and store the OTA data associated with the IS system's DLS / DLA from other systems (e.g., external loading tools or systems, etc.). Preferably, the wireless communication link can include at least one of the following: airport Wi-Fi, cellular network, satellite communication, or 5G air-to-ground (ATG) link, etc. Preferably, the wireless communication link between the OTA ground terminal and the OTA airborne terminal dynamically switches priorities according to the flight phase. For example, airport Wi-Fi or cellular network is preferred during the ground phase, while satellite communication or ATG link is preferred during the air phase.

[0031] In the embodiments of this application, the OTA airborne terminal and the OTA ground terminal interact via a wireless communication link, and provide the OTA execution program and OTA display interface for the DLS / DLA within the IS system, such as in Figure 2 The following provides a more detailed explanation. Additionally or alternatively, the OTA airborne unit can receive OTA data from the OTA ground unit, and store and process the OTA data, as described in more detail below.

[0032] In embodiments of this application, the file server module at the network server of the OTA onboard terminal can control functions associated with OTA data, such as data upload, data loading, data upgrade, or resume interrupted download. Preferably, the file server module can set logical judgments for data upload, and during the upload, loading, and upgrade of OTA data, the file server module monitors the status of the wireless communication link and aircraft parameters; and dynamically controls the operation permissions of functions based at least in part on the status of the wireless communication link and aircraft parameters, including: when the status of the wireless communication link indicates that the 5G ATG link status / airport wireless communication link status signal is connected, data upload is allowed. Specifically, when the aircraft parameters indicate that the aircraft is on the ground and the status of the wireless communication link is connected, OTA data upload is allowed; and / or when the aircraft parameters indicate that the aircraft's flight altitude is greater than or equal to a first altitude threshold (e.g., 20,000, 30,000 feet, etc.) and the status of the wireless communication link is connected, OTA data upload is allowed. Preferably, the file server module can be configured with logical judgments for data loading, including: if the aircraft parameter indication indicates that the boarding gate signal is open and the WOW wheel load signal is on the ground / IRS flight altitude is greater than or equal to a second altitude threshold (e.g., 20,000, 30,000 feet, etc.), data loading can proceed. Preferably, the file server module can be configured with logical judgments for data upgrades, including: if the aircraft parameter indication indicates that the boarding gate signal is open and the WOW wheel load signal is on the ground / IRS flight altitude is greater than or equal to a third altitude threshold (e.g., 20,000, 30,000 feet, etc.), data updates can proceed. The status of the wireless communication link can indicate whether at least one of airport Wi-Fi, cellular network, air-to-ground communication, or satellite link is connected; the aircraft parameters can indicate at least one of the following: whether the aircraft is on the ground, whether the flight altitude is greater than or equal to a first altitude threshold, whether the flight altitude is greater than or equal to a second altitude threshold, or whether the flight altitude is greater than or equal to a third altitude threshold, and the first, second, and third altitude thresholds can be the same or different. Preferably, the file server module can be configured with a resume function, including resuming transmission from the point of interruption after data upload is interrupted. Preferably, the resume function is identified and determined by setting temporary files in the data upload folder. For example, the file server module can generate temporary files to record the OTA data transmission progress, and resume transmission based on the identified breakpoint location after the wireless communication link is restored. Preferably, the temporary files can be automatically deleted after the OTA data transmission is completed or can be stored for later verification. Preferably, by configuring the file server module's logic signals, automated management and control of data upload, data loading, data upgrade, and resume transmission can be achieved for different flight phases, reducing the workload of maintenance personnel and improving the efficiency of data upgrades.

[0033] In the embodiments of this application, the network security module of the OTA onboard terminal can be configured with a static policy file to perform differentiated security verification on OTA data. For example, the network security module can configure the communication port for OTA data received from the OTA ground terminal, reducing OTA data authentication and verification authorization, and shortening data upload time. OTA data authentication and verification authorization are achieved through static configuration of the network security policy file. For example, the network security module may include a secure routing module and a secure interface module. On one hand, when the communication port is identified as a security authentication port, the received OTA data can be directly routed and forwarded. On the other hand, when the communication port is identified as a security authentication port, the received OTA data can be directly transmitted. Preferably, different verification and authorization services can be applied to OTA data with different security levels. Preferably, the security levels include three levels: high security level, medium security level, and low security level. For example, OTA data belonging to the high security level can use multiple encryption and two-way authentication processes; OTA data belonging to the medium security level uses one-way encryption authentication; and OTA data belonging to the low security level uses basic verification. Alternatively, different OTA data can be tagged according to their corresponding security levels and pre-configured in the policy configuration file of the network security module on the OTA airborne terminal. Preferably, the policy configuration file can be a static policy file, thereby performing differentiated security verification on OTA data according to pre-set security levels (high, medium, low). For example, the security level can be determined based on the degree to which the data affects flight safety. Therefore, OTA data that can be loaded in the field of the information system can quickly pass through the network security identity authentication process, and data of different security levels can be granted different authorized services, shortening data upload time and reducing the maintenance time costs caused by loading aircraft transit data.

[0034] In the embodiments of this application, after differentiated security verification, the OTA data enters the file server module of the network server on the OTA airborne terminal. The file server module monitors the status of the airport communication link and the air-to-ground link, as well as the aircraft parameters, as described above.

[0035] In one example, based at least in part on the above description, specific embodiments of OTA upgrades in this application may include:

[0036] Step 1: When the wheel-borne WOW signal + cabin door (front boarding gate) signal = on-ground and airport communication link

[0037] =Online, allows for OTA data uploads;

[0038] Step 2: When the flight altitude (distance from the ground) is greater than or equal to the first threshold and the air-to-ground communication link is online, OTA data upload can be performed, where the first threshold can be 3000 feet;

[0039] Step 3: If the data upload is not completed on the ground, the upload will stop and resume when the flight altitude (distance from the ground) is greater than or equal to the first threshold and the air-to-ground communication link is online, until the data upload is completed. The first threshold can be 3000 feet.

[0040] Step 4: Once the data upload is complete, the data can be loaded into the onboard OTA program;

[0041] Step 5: After loading into the OTA program, upgrade services can be provided.

[0042] It should be understood that the above embodiments are only used to illustrate this application and are not intended to limit the scope of this application.

[0043] Figure 2 A schematic diagram illustrating the process of loading air-to-ground wireless data according to an embodiment of the present invention is provided.

[0044] In the embodiments of this application, an OTA data loading platform (1) can be set up at the OTA ground end, residing in the airline server and / or ground system, for providing OTA update data packets (2) of DLS / DLA in the IS system.

[0045] In the embodiments of this application, an OTA execution program (3) and an OTA display interface (4) may be provided on the OTA airborne terminal. Preferably, the OTA execution program (3) resides in both the IS system network server and the Electronic Flight Bag (hereinafter referred to as EFB) and is used to load DLS / DLA data. Preferably, the OTA display interface (4) resides in the EFB and is used to load human-machine interaction operations.

[0046] In the embodiments of this application, after the OTA data loading platform (1) receives and stores the OTA update data packet (2) of DLS / DLA in the IS system, it periodically sends an updateable prompt message (5) to the OTA onboard terminal and automatically uploads the OTA update data to the OTA cache directory (11) of the OTA execution program (3). The OTA display interface (4) pushes the updateable prompt message (5) to the maintenance personnel. Entering the OTA display interface (4) allows browsing the DLS / DLA that can be upgraded in the current IS. The maintenance personnel can complete the individual / batch loading by selecting one or more DLS / DLAs that need to be upgraded.

[0047] In the embodiments of this application, if loading is not completed during transit, automatic resume transmission can be provided after landing (6). A loading progress bar (7) is provided during the loading process, and a loading completion message (8) is provided after loading is completed. Preferably, after loading is completed, the OTA airborne terminal periodically sends a loading success message (9) to the OTA ground terminal. After receiving the loading success message (9), the OTA data airborne platform (1) of the OTA ground terminal updates the local DLS / DLA information. Preferably, after loading is completed, maintenance personnel can access the integrated maintenance service software (hereinafter referred to as IMMS) in the EFB to view the upgraded DLS / DLA configuration information (10).

[0048] In the embodiments of this application, for the upgrade of DLS / DLA residing in the IS system network server, the maintenance personnel perform the loading and update operation by accessing the OTA display interface (4) in the EFB. After entering the OTA display interface (4), the OTA execution program (3) starts, and the maintenance personnel select one or more DLS / DLAs that need to be upgraded for loading and updating. Preferably, after the selection is completed, an OTA configuration file (12) is generated, which is used to call the OTA update data packet (2) under the OTA cache directory (11), and an OTA execution directory (13) is generated. When the maintenance personnel click the OTA load button (14), the OTA update data packet (2) in the execution directory is loaded simultaneously. Preferably, when the loading is completed, the OTA configuration file (12) is automatically sent to the IMMS software in the EFB, which is used to call the OTA update data packet (2) under the OTA cache directory (11), and an OTA execution directory (13) is generated. When the maintenance personnel click the OTA load button (14), the OTA update data packet (2) in the execution directory is loaded simultaneously. Preferably, once loading is complete, the OTA configuration file (12) is automatically sent to the IMMS software within the EFB to update the DLS / DLA configuration information (10). Once the configuration information update is complete, a message indicating successful loading (9) is displayed, and the OTA upgrade is complete.

[0049] In the embodiments of this application, for the upgrade of DLS / DLA residing in the IS system EFB, the operation process of maintenance personnel is the same as that in the IS system server, but the OTA execution program (3) is executed differently. For example, compared with the upgrade of the IS system server, after the DLS / DLA data in the EFB displays the message that the loading was successful (9), it is necessary to exit the DLS / DLA and re-enter before the new data takes effect. Additionally or alternatively, after the loading is completed, the configuration information comparison process is different. The EFB sends configuration information to the IMMS software through BIT message (15) to update the configuration information displayed by the IMMS.

[0050] Figure 3A block diagram illustrating an apparatus according to an embodiment of the present invention for supporting rapid wireless online upgrades of field-loadable software / applications for information systems is provided. It should be noted that... Figure 3 This is intended only to provide a general explanation of the various components, which may be appropriately utilized by any or all of them. Note that in some instances, [the components are...]. Figure 3 The components being explained can be localized into a single physical device and / or distributed among various networked devices, for example, they can be located at different physical locations on an aircraft or other entity.

[0051] Device 300 is shown as including hardware elements that can be electrically coupled (or otherwise communicated) via bus 305. The hardware elements may include processing units 310, which may include, but are not limited to, one or more general-purpose processors, one or more special-purpose processors (such as digital signal processing (DSP) chips, graphics accelerator processors, application-specific integrated circuits (ASICs), etc.), and / or other processing structures or means.

[0052] Device 300 may also include one or more input devices 370, which may include devices related to a user interface (e.g., touchscreen, touchpad, microphone, buttons, dial pad, switch, etc.) and / or devices related to navigation, autonomous driving, etc. Similarly, one or more output devices 315 may relate to devices that interact with the user (e.g., via a display, light-emitting diode (LED), speaker, etc.) and / or devices related to navigation, driving, etc.

[0053] Device 300 may also include a wireless communication interface 330, which may include, but is not limited to, a modem, a network card, an infrared communication device, a wireless communication device, and / or a chipset (such as...). Devices, WiFi devices, WiMax devices, WAN devices, and / or various cellular devices, etc. The wireless communication interface 330 enables device 300 to communicate with other devices. This can include various forms of communication from the previously described embodiments. Thus, it can be capable of transmitting direct communication, broadcasting wireless signals, receiving direct and / or broadcast wireless signals, etc. Accordingly, the wireless communication interface 330 can be capable of transmitting and / or receiving RF signals from various RF channels / bands. Communication using the wireless communication interface 330 can be performed via one or more wireless communication antennas 332 that transmit and / or receive wireless signals 334.

[0054] The device 300 may further include sensors 340. Sensors 340 may include, but are not limited to, one or more inertial sensors and / or other sensors (e.g., lidar, accelerometers, gyroscopes, cameras, magnetometers, altimeters, microphones, proximity sensors, light sensors, barometers, etc.). Sensors 340 may be used, for example, to determine certain real-time characteristics of the aircraft, such as position, velocity, acceleration, altitude, heading, attitude, weather data, etc.

[0055] Device 300 may further include memory 360 and / or be in communication with memory 360. Memory 360 may include, but is not limited to, local and / or network-accessible storage, disk drives, drive arrays, optical storage devices, solid-state storage devices (such as random access memory (RAM) and / or read-only memory (ROM)), which may be programmable, flash-updatable, etc. Such storage devices may be configured to implement any suitable data storage, including but not limited to various file systems, database structures, and / or the like.

[0056] The memory 360 of device 300 may also include software elements ( Figure 3 (Not shown in the document), these software elements include operating systems, device drivers, executable libraries, and / or other code (such as one or more applications). These software elements may include computer programs provided by various embodiments, and / or may be designed to implement the methods described herein, and / or configure the systems described herein. Software applications stored in memory 360 and executed by processing units 310 can be used to implement the functionality of the aircraft as described herein. Furthermore, one or more procedures described with respect to the methods discussed herein can be implemented as code and / or instructions in memory 360 executable by device 300 (and / or processing units 310 or DSP 320 within device 300), including those described below. Figure 4 The functions described in the method. In one respect, such code and / or instructions can be used to configure and / or adapt a general-purpose computer (or other device) to perform one or more operations according to the described method.

[0057] Figure 4 An example of the process flow for enabling rapid wireless online upgrades of field-loadable software / applications of an information system based on network security protection and air-to-ground wireless communication links, according to an embodiment of the present invention, is explained.

[0058] In embodiments of this application, the apparatus (e.g., apparatus 300) for enabling rapid wireless online upgrades of field-loadable software / applications for information systems can be operated jointly by the aircraft and the operator to achieve its function. The method 400 for operating the apparatus is as follows: Figure 4 As shown in the image.

[0059] In embodiments of this application, method 400 may include: step 405, generating OTA data associated with the loadable software / application (DLS / DLA) of the information system. The means for performing the functionality of step 405 may be an OTA ground terminal of an airborne application data OTA system. Additionally or alternatively, the OTA ground terminal may also receive and store OTA data associated with the DLS / DLA of the IS system from other systems. The means for performing the functionality of step 405 may include one or more software and / or hardware components of the device, such as referenced... Figure 3 The bus 305, (various) processing units 310, memory 360, and / or the ... Figure 3 Other software and / or hardware components of the device 300 explained in the text.

[0060] In embodiments of this application, method 400 may include step 410, configuring a static policy file to perform differentiated security verification on OTA data. The functional device for performing step 410 may be a network security module of the OTA airborne terminal of an airborne application data (OTA) system, wherein the OTA airborne terminal and the OTA ground terminal interact via a wireless communication link, and can be used to receive, store, and process OTA data from the OTA ground terminal. Preferably, the method can also support bidirectional data transmission between the ground and the air. Preferably, the network security module is further used to: perform differentiated security verification on OTA data according to a pre-set security level using a static policy configuration file. Preferably, the security level includes three levels: high security level, medium security level, and low security level, wherein OTA data belonging to the high security level uses a multi-layer encryption and two-way authentication process; OTA data belonging to the medium security level uses one-way encryption authentication; and OTA data belonging to the low security level uses basic verification. The functional device for performing step 410 may include one or more software and / or hardware components of the device, such as referenced... Figure 3 The bus 305, (various) processing units 310, memory 360, and / or the ... Figure 3 Other software and / or hardware components of the device 300 explained in the text.

[0061] In embodiments of this application, method 400 may include step 415, controlling functions associated with OTA data. The means for performing the functionality of step 415 may be a file server module of the OTA airborne terminal of an airborne application data (OTA) system. Preferably, the file server module is further configured to: monitor the status of the wireless communication link and aircraft parameters during the uploading of OTA data; and dynamically control the operational permissions of the function based at least in part on the status of the wireless communication link and the aircraft parameters. Preferably, the status of the wireless communication link indicates whether at least one of airport Wi-Fi, cellular network, air-to-ground communication, or satellite link is connected; the aircraft parameters indicate at least one of the following: whether the front boarding gate is open, whether the aircraft is on the ground, whether the flight altitude is greater than or equal to a first altitude threshold, whether the flight altitude is greater than or equal to a second altitude threshold, or whether the flight altitude is greater than or equal to a third altitude threshold. Preferably, the operating permissions of the file server module's dynamic control function include one or more of the following: allowing OTA data upload when aircraft parameters indicate the aircraft is on the ground and the wireless communication link is connected; allowing OTA data upload when aircraft parameters indicate the aircraft's flight altitude is greater than or equal to a first altitude threshold and the wireless communication link is connected; allowing OTA data loading when aircraft parameters indicate the aircraft is on the ground or its flight altitude is greater than or equal to a second altitude threshold; and allowing OTA data upgrade when aircraft parameters indicate the aircraft is on the ground or its flight altitude is greater than or equal to a third altitude threshold, wherein the first altitude threshold, the second altitude threshold, and the third altitude threshold are the same or different. Preferably, the function includes resuming interrupted transmission, wherein the file server module is further used to generate a temporary file to record the transmission progress of the OTA data, and to resume transmission based on the location of the interrupted point after the wireless communication link is restored, based on the location of the interrupted point in the temporary file. The means for performing the functionality of step 415 may include one or more software and / or hardware components of the device, such as reference Figure 3 The bus 305, (various) processing units 310, memory 360, and / or the ... Figure 3 Other software and / or hardware components of the device 300 explained in the text.

[0062] In embodiments of this application, the OTA onboard terminal may further include an OTA execution program and an OTA display interface. Preferably, the OTA display interface is used to select one or more DLS / DLAs for upgrade; and / or to visually display a progress bar and completion status prompts in real time during the OTA data loading process. Preferably, the OTA onboard terminal is further used to: periodically send a loading success confirmation message to the OTA ground terminal after the OTA data loading is completed; and update the configuration information of the information system's DLS / DLAs.

[0063] Furthermore, embodiments of this application also disclose a computer-readable storage medium including computer-executable instructions stored thereon, which, when executed by a processor, cause the processor to perform the methods of the embodiments herein.

[0064] Furthermore, embodiments of this application also disclose an apparatus including a processor and a memory storing computer-executable instructions, which, when executed by the processor, cause the processor to perform the methods of the embodiments herein.

[0065] Furthermore, embodiments of this application also disclose an apparatus for enabling rapid wireless online upgrades of loadable software / applications in an information system, the apparatus including means for implementing the methods of the various embodiments herein. In one aspect, the apparatus includes: means for generating OTA data associated with loadable software / applications (DLS / DLA) of the information system; means for configuring a static policy file to perform differentiated security checks on the OTA data; and means for controlling functions associated with the OTA data.

[0066] Furthermore, embodiments of this application also disclose an aircraft, characterized in that it is equipped with the aforementioned OTA onboard terminal, network security module, file server module, etc.

[0067] The above describes the airborne application data online upgrade (OTA) system and method according to the present invention. Compared with the prior art, the method of the present invention has at least the following advantages:

[0068] (1) Full-stage upgrade capability, supporting data upload, loading and upgrade in both ground and air stages, reducing maintenance time and costs;

[0069] (2) Dynamic safety control: Automatically adjusts operating permissions based on aircraft parameters and wireless link status to ensure system stability;

[0070] (3) Efficient transmission: By using breakpoint resume and differentiated authorization strategies, the data upload time is shortened and the efficiency of data upgrade is improved.

[0071] (4) Automated management reduces manual intervention and lowers the workload of maintenance personnel.

[0072] Throughout this specification, reference has been made to "embodiments," meaning that a particular described feature, structure, or characteristic is included in at least one embodiment. Therefore, the use of these phrases may refer to more than one embodiment. Furthermore, the described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0073] The various steps and modules of the methods and apparatus described above can be implemented in hardware, software, or a combination thereof. If implemented in hardware, the various illustrative steps, modules, and circuits described in connection with this disclosure can be implemented or executed using a general-purpose processor, digital signal processor (DSP), application-specific integrated circuit (ASIC), field-programmable gate array (FPGA), or other programmable logic components, hardware components, or any combination thereof. A general-purpose processor can be a processor, microprocessor, controller, microcontroller, or state machine, etc. If implemented in software, the various illustrative steps and modules described in connection with this disclosure can be stored as one or more instructions or codes on a computer-readable medium or transmitted. Software modules implementing the various operations of this disclosure can reside in a storage medium, such as RAM, flash memory, ROM, EPROM, EEPROM, registers, hard disk, removable disk, CD-ROM, cloud storage, etc. The storage medium can be coupled to a processor so that the processor can read and write information from / to the storage medium and execute corresponding program modules to implement the various steps of this disclosure. Moreover, software-based embodiments can be uploaded, downloaded, or remotely accessed through appropriate communication means. Such appropriate means of communication include, for example, the Internet, the World Wide Web, intranets, software applications, cables (including fiber optic cables), magnetic communication, electromagnetic communication (including RF microwave and infrared communication), electronic communication, or other such means of communication.

[0074] The numerical values ​​given in the various embodiments are merely examples and are not intended to limit the scope of the invention. Furthermore, as a whole, there are other components or steps not listed in the claims or specification of this invention. Moreover, a single name for a component does not preclude other names for that component.

[0075] It should also be noted that these embodiments may be described as processes depicted as flowcharts, flow diagrams, structure diagrams, or block diagrams. Although a flowchart may describe the operations as a sequential process, many of these operations can be executed in parallel or concurrently. Furthermore, the order of these operations can be rearranged.

[0076] The disclosed methods, apparatuses, and systems should not be limited in any way. Rather, this disclosure covers all novel and non-obvious features and aspects of the various disclosed embodiments (individually and in various combinations and sub-combinations of each other). The disclosed methods, apparatuses, and systems are not limited to any particular aspect or feature or combination thereof, and no disclosed embodiment is required to have any one or more specific advantages or to solve any particular or all technical problems.

[0077] This invention is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other modifications based on the teachings of this invention without departing from the spirit and scope of the claims. All of these modifications are within the scope of protection of this invention.

[0078] Those skilled in the art will recognize that these embodiments can be practiced without one or more specific details or using other methods, resources, materials, etc. In other cases, well-known structures, resources, or operations are not shown or described in detail merely for the purpose of observing obscure aspects of the embodiments.

[0079] While embodiments and applications have been described and illustrated, it should be understood that the embodiments are not limited to the precise configurations and resources described above. Various modifications, substitutions, and improvements that will be apparent to those skilled in the art may be made in the arrangement, operation, and details of the methods and systems disclosed herein without departing from the scope of the claimed embodiments.

[0080] As used herein, the terms “and,” “or,” and “and / or” may include a variety of meanings, which are also contemplated, at least in part, depending on the context in which such terms are used. Generally, “or,” when used to relate a list such as A, B, or C, is intended to mean A, B, and C (in the inclusive sense) and A, B, or C (in the exclusive sense). Additionally, the term “one or more” as used herein may be used to describe any feature, structure, or property in its singular form, or to describe multiple features, structures, or characteristics, or some other combination thereof. However, it should be noted that this is merely an illustrative example, and the claimed subject matter is not limited to this example.

[0081] While the features currently considered exemplary have been explained and described, those skilled in the art will understand that various other modifications can be made and equivalents can be substituted without departing from the claimed subject matter. Additionally, numerous modifications can be made to adapt a particular scenario to the teachings of the claimed subject matter without departing from the central concepts described herein.

Claims

1. An airborne application data online upgrade (OTA) system, the system supporting two-way data transmission between ground and air and comprising: OTA ground terminal, used to generate OTA data associated with loadable software / applications (DLS / DLA) of information systems; as well as An OTA airborne terminal is used to receive, store, and process the OTA data, wherein the OTA airborne terminal interacts with the OTA ground terminal via a wireless communication link, and The OTA onboard unit includes: The network security module is used to configure static policy files to perform differentiated security verification on the OTA data; as well as The file server module is used to control functions associated with the OTA data.

2. The system according to claim 1, characterized in that, The file server module controls the functions associated with the OTA data, and the file server module itself is further included in this category. During the uploading, loading, and upgrading of the OTA data, the status of the wireless communication link and aircraft parameters are monitored; and The operational permissions of the function are dynamically controlled, at least in part, based on the state of the wireless communication link and the aircraft parameters.

3. The system according to claim 2, characterized in that, The status of the wireless communication link indicates whether at least one of the airport Wi-Fi, cellular network, air-to-ground communication, or satellite link is connected. The aircraft parameters indicate at least one of the following: whether the aircraft is on the ground, whether the flight altitude is greater than or equal to a first altitude threshold, whether the flight altitude is greater than or equal to a second altitude threshold, or whether the flight altitude is greater than or equal to a third altitude threshold.

4. The system according to claim 2 or 3, characterized in that, The file server module dynamically controls the operation permissions of the function, including one or more of the following: When the aircraft parameters indicate that the aircraft is on the ground and the wireless communication link is in a connected state, the uploading of OTA data is permitted. When the aircraft parameters indicate that the aircraft's flight altitude is greater than or equal to a first altitude threshold and the wireless communication link is in a connected state, the uploading of OTA data is permitted. The loading of OTA data is permitted when the aircraft parameters indicate that the aircraft is on the ground or the flight altitude is greater than or equal to a second altitude threshold. as well as The OTA data upgrade is permitted when the aircraft parameters indicate that the aircraft is on the ground or the flight altitude is greater than or equal to a third altitude threshold. The first height threshold, the second height threshold, and the third height threshold may be the same or different.

5. The system according to claim 3, characterized in that, The functionality includes resuming interrupted downloads, wherein the file server module is further used for... A temporary file is generated to record the transmission progress of the OTA data, and After the wireless communication link is restored, transmission will continue based on the location of the breakpoint in the temporary file.

6. The system according to claim 1, characterized in that, The network security module is further used for: The OTA data is subjected to differentiated security verification according to a pre-set security level using the static policy configuration file.

7. The system according to claim 6, characterized in that, The security levels include three levels: high security, medium security, and low security. OTA data belonging to the aforementioned high security level employs multiple encryption and two-way authentication processes; OTA data belonging to the aforementioned security level employs one-way encryption authentication. OTA data belonging to the aforementioned low security level undergoes basic verification.

8. The system according to claim 1, characterized in that, The OTA onboard terminal further includes an OTA display interface, and the OTA display interface is used for Select one or more DLS / DLA upgrades; and / or The progress and completion status are visually displayed during the loading of the OTA data.

9. The system according to claim 8, characterized in that, The OTA onboard terminal is further used for: After the OTA data is loaded, a successful loading confirmation message is periodically sent to the OTA ground terminal.

10. The system according to claim 8, characterized in that, The OTA onboard unit is further used for: After the OTA data is loaded, the configuration information of the DLS / DLA of the information system is updated in response to the completion of the OTA data loading.

11. A method for online over-the-air (OTA) upgrade of airborne application data, the method supporting bidirectional data transmission between ground and air and comprising: OTA data is generated via OTA ground terminal and associated with loadable software / applications (DLS / DLA) of information system; The OTA airborne terminal interacts with the OTA ground terminal via a wireless communication link; The OTA onboard terminal's network security module configures a static policy file to perform differentiated security verification on the OTA data; as well as The functions associated with the OTA data are controlled via the file server module of the OTA onboard terminal.

12. The method according to claim 11, characterized in that, The file server module is further used for: During the uploading, loading, and upgrading of the OTA data, the status of the wireless communication link and aircraft parameters are monitored; and The operational permissions of the function are dynamically controlled, at least in part, based on the state of the wireless communication link and the aircraft parameters.

13. The method according to claim 12, characterized in that, The operating permissions for dynamically controlling the aforementioned function include one or more of the following: When the aircraft parameters indicate that the aircraft is on the ground and the wireless communication link is in a connected state, the uploading of OTA data is permitted. When the aircraft parameters indicate that the aircraft's flight altitude is greater than or equal to a first altitude threshold and the wireless communication link is in a connected state, the uploading of OTA data is permitted. The loading of OTA data is permitted when the aircraft parameters indicate that the aircraft is on the ground or the flight altitude is greater than or equal to a second altitude threshold. as well as The OTA data upgrade is permitted when the aircraft parameters indicate that the aircraft is on the ground or the flight altitude is greater than or equal to a third altitude threshold, wherein the first altitude threshold, the second altitude threshold, and the third altitude threshold are the same or different.

14. The method according to claim 11, characterized in that, The static policy configuration file performs differentiated security verification on the OTA data according to a pre-set security level.

15. The method according to claim 14, characterized in that, The security levels include three levels: high security, medium security, and low security. OTA data belonging to the aforementioned high security level employs multiple encryption and two-way authentication processes; OTA data belonging to the aforementioned security level employs one-way encryption authentication. OTA data belonging to the aforementioned low security level undergoes basic verification.