method of establishing a secure connection between an aircraft and a ground-based assistance center

The method addresses the insecurity of aircraft-ground communication by implementing strong authentication and hybrid encryption, creating a secure channel for emergency communications and enhancing flight safety.

FR3151730B1Active Publication Date: 2025-06-20SAFRAN ELECTRONICS & DEFENSE (FR)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2023007987
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-07-25
Publication Date
2025-06-20
Estimated Expiration
2043-07-25

AI Technical Summary

Technical Problem

Current solutions for securing communication links between aircraft and ground-based assistance centers are inadequate, particularly in emergency situations, due to the lack of guaranteed confidentiality, discretion, and service quality.

Method used

A method for establishing a secure end-to-end connection between an aircraft and a ground-based assistance center, involving strong mutual authentication, hybrid encryption using public and private keys, and multi-factor authentication, to ensure secure transmission of emergency commands.

Benefits of technology

The method provides a secure, reliable, and independent communication channel for emergency situations, enhancing flight safety by ensuring confidentiality and integrity of communications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000020_0000
    Figure 00000020_0000
  • Figure 00000020_0001
    Figure 00000020_0001
  • Figure 00000021_0000
    Figure 00000021_0000
Patent Text Reader

Abstract

One aspect of the invention relates to a method for establishing a secure end-to-end connection between an on-board environment of an aircraft and a ground environment of a ground assistance center. The secure connection is dedicated exclusively to managing an emergency situation. The method notably comprises the exchange of several ACARS “aircraft communication addressing and reporting system” messages and the implementation of an MPLS “multiprotocol label switching” cloud. Finally, the method comprises establishing a secure connection between the on-board environment and the ground environment via hybrid encryption using a public key accessible by the ground environment and the on-board environment and using a private key accessible exclusively by the ground environment. Figure to be published with the abstract: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: method for establishing a secure connection between an aircraft and a ground-based assistance center TECHNICAL FIELD OF THE INVENTION

[0001] The technical field of the invention is that of communications security and in particular the security of communications between an aircraft and a ground-based assistance center.

[0002] The present invention relates to a method for establishing a secure connection between an aircraft and a ground-based assistance center. TECHNOLOGICAL BACKGROUND OF THE INVENTION

[0003] When an aircraft is faced with a set of significant failures, the pilot(s) must execute a set of procedures to decide whether the aircraft can remain in a stabilized flight condition and sufficiently navigable to continue the current flight / mission, or whether it is necessary to divert to land as quickly as possible.

[0004] In the future, it is envisaged to have only one pilot per aircraft, it will therefore be necessary to be able to deal with all crisis situations, while maintaining the requirement for flight safety. Several solutions are envisaged: one of them being to allow one or more people, located in a ground environment, to provide support to the pilot in the aircraft or to take control of the aircraft's cockpit.

[0005] Remote control of a cockpit requires the implementation of a secure connectivity link between the onboard environment of the aircraft cockpit and the ground environment. However, in the face of increasingly sophisticated cyber-attacks, securing such a link is a complex task to achieve.

[0006] Currently, most latest generation aircraft carry connectivity solutions allowing exchanges of operational data between the cockpits of said aircraft and the operational centers on the ground. The implemented solutions are based on technologies from the world of information systems and Internet Protocol networks, noted IP for "Internet Protocol" in English, with for example the use of 4G / 5G cellular modems. In order to ensure the security of this connection, it is for example known to use security libraries such as the Internet security protocol, "Internet Protocol Security" in English, used in particular for the implementation of Virtual Private Network, noted VPN for "Virtual Private Network" in English.

[0007] Even though certification authorities have established rules and guidelines for To frame the implementation of secure connectivity solutions, there is no requirement for confidentiality, discretion and service guarantee. As a result, the behavior of secure aircraft connectivity is based on the notion of "best effort" which does not allow to demonstrate the level of quality expected for a connectivity link in an emergency situation.

[0008] There is therefore a need for a method allowing the secure transmission of messages between an on-board environment of an aircraft and a ground environment of a ground assistance center, in particular when the aircraft is in an emergency situation. Summary of the invention

[0009] The invention provides a solution to the problems mentioned above, by proposing a method for establishing a secure end-to-end connection between an on-board environment of an aircraft and a ground environment of a support center located on the ground. Thus, communication between the aircraft and the ground is achieved by a set of solutions allowing a secure connection. A first level of the secure solution concerns securing the communication media. For the sake of simplicity, this level is not described in the invention because it is the responsibility of the communication media access provider. A second level of the solution concerns establishing a secure link between the remote access manager of the on-board environment and the ground environment. The connection is only established after strong mutual authentication between the aircraft and the user on the ground.A third level of the solution concerns the systematic encryption and signing of all emergency interactive command exchanges.

[0010] One aspect of the invention relates to a method for establishing a secure end-to-end connection between an on-board environment of an aircraft and a ground environment of a ground-based assistance center, the secure connection being dedicated exclusively to managing an emergency situation with: • The embedded environment comprising a remote access manager and an IP connectivity system dedicated to managing the emergency situation, the remote access manager comprising a first multi-network hardware filtering module and the IP connectivity system being linked to the remote access manager via the multi-network hardware filtering module, and • The ground environment comprising an emergency connection manager dedicated to managing the emergency situation, the emergency connection manager comprising a second multi-network hardware filtering module, The method comprising: • Send a first ACARS “Aircraft Communication Addressing and Reporting System” message via an ACARS network, the first ACARS message being sent by the on-board environment to the ground environment when an emergency situation concerning the aircraft is detected, • Receive and decode the first ACARS message through the ground environment of the assistance center, • When the first ACARS message is considered to describe an emergency situation, activate a confidential environment dedicated to the management of the emergency situation, the activation of the environment comprising: • Sending a second ACARS message via the ACARS network, the second ACARS message being sent by the ground environment to the on-board environment and the second ACARS message containing a confirmation of the acknowledgement of the emergency situation, • Implement an MPLS “MultiProtocol Label Switching” cloud between the IP connectivity system and the connection system to IP network access service providers, • Establish a connection to the MPLS cloud through the first and second multi-network hardware filtering modules, and • Establish a secure connection between the on-board environment and the ground environment via hybrid encryption using a public key and a private key, the public key being accessible by the ground environment and the on-board environment and the private key being accessible exclusively by the ground environment, the establishment of a secure connection including the encryption of messages allowing the establishment of the secure link using the public key, the encrypted messages being sent within the MPLS cloud and at least one of the encrypted messages allowing the sharing of the private key.

[0011] The term "environment" designates all the systems on which the method according to the invention is executed. In addition, the term "environment" may further designate system software, including the operating system, on which the method according to the invention is executed.

[0012] Thanks to the invention, the transmission of messages between an on-board environment of an aircraft and a ground environment of a ground assistance center is secure. Indeed, security is ensured by the different security levels. In addition, this transmission system is totally independent of the other transmission systems of the aircraft and the assistance center, thus making it possible to further increase process safety.

[0013] In addition to the characteristics which have just been mentioned in the preceding paragraph, the method according to one aspect of the invention may have one or more complementary characteristics among the following, considered individually or according to all technically possible combinations: • The method further comprises multi-factor authentication in order to access a remote display of a cockpit of the aircraft in an emergency situation, the remote display being carried out at the ground environment level, • Multi-factor authentication includes: • Generate a random password by the remote access manager, • Sending a third ACARS message including the password generated via the ACARS network to the ground environment, • Receipt of the third message by the ground environment and entry of the password by a user, and • When the password entered by the user is authenticated, the remote display of the aircraft cockpit in an emergency situation is activated, • The remote display of the aircraft cockpit in an emergency situation further comprises a user interface, the method further comprising: • Reception by the user interface of an interaction initiated by the user, the interaction corresponding to a command from the aircraft cockpit, • Sending a signed message, the signed message including the order and an additional field filled in randomly, • Reception of the signed message by the embedded environment, • When the signed message is authenticated by the embedded environment: • Sending by the on-board environment of a fourth ACARS message and an IP message to the ground environment, • Execution of the order included in the signed message, the order being carried out in the cockpit, and • Update of the remote display of the aircraft cockpit in emergency situations, • The method further comprises a declaration of end of emergency situation when the aircraft has landed, the declaration of end of emergency comprising: • Restart the remote access manager and the IP connectivity system dedicated to managing the emergency situation at the on-board environment level, • Remove the secure connection at the ground environment level, and • Update the public key and private key.

[0014] A second aspect of the invention relates to an on-board environment of an aircraft comprising a remote access manager and an IP connectivity system dedicated to the management of the emergency situation, the remote access manager comprising a multi-network hardware filtering module and the IP connectivity system being linked to the remote access manager via the multi-network hardware filtering module, the on-board environment being configured to implement a method according to the invention.

[0015] A third aspect of the invention relates to an aircraft comprising an on-board environment according to the invention.

[0016] A fourth aspect of the invention relates to a ground environment of a ground-based assistance center comprising an emergency connection manager, the emergency connection manager comprising a second multi-network hardware filtering module, the ground environment being configured to implement a method according to the invention.

[0017] A fifth aspect of the invention relates to a computer program comprising instructions which, when the program is executed by a computer, cause the on-board environment and the ground environment to execute at least one of the steps of the method according to the invention. For example, a first computer program comprising instructions which, when the program is executed by a first computer, cause the first computer to implement the steps of the method according to the invention carried out at the ground environment. In another example, a second computer program comprising instructions which, when the program is executed by a second computer, cause the second computer to implement the steps of the method according to the invention carried out at the on-board environment.

[0018] A sixth aspect of the invention relates to a computer-readable medium, on which the computer program according to the invention is recorded.

[0019] The invention and its various applications will be better understood upon reading the following description and examining the accompanying figures. BRIEF DESCRIPTION OF THE FIGURES

[0020] The figures are presented for information purposes only and in no way limit the invention.

[0021] [Fig.l] shows a schematic representation of an example of the method according to the invention.

[0022] Figures 2, 3 and 4 show a schematic representation of an example of a step of the method according to the invention.

[0023] [Fig.5] shows a schematic representation of an example of an on-board environment according to the invention.

[0024] [Fig.6] shows a schematic representation of an example of a ground environment according to the invention. DETAILED DESCRIPTION

[0025] The figures are presented for information purposes only and in no way limit the invention.

[0026] A first aspect of the invention illustrated in [Fig.l] relates to a method 100 for establishing a secure end-to-end connection between an on-board environment of an aircraft and a ground environment of a ground-based assistance center. The steps of the example of the method 100 are indicated by a rectangle with solid lines and the optional steps are indicated by a rectangle with dotted lines.

[0027] The method 100 is implemented using an on-board environment of the aircraft. An example of an on-board environment 500 suitable for implementing the method 100 is illustrated in [Fig.5]. The on-board environment 500 comprises a system page manager 510, NNC execution (for Non-Normal Checklist) and RCCP control (for Remote Centralized Control Panel), a cyber module 550, a remote access manager 580 and an IP connectivity system 620. The remote access manager 580 and the IP connectivity system 620 are dedicated to managing an emergency situation, i.e. are not involved in any other method. The system page manager 510, NNC execution and RCCP control is a high DAL (Design Assurance Level) environment. The 550 cyber module is SAL level, for “Security Assurance Level” in English, 3.The cyber module 550 is connected with the system page manager 510, NNC execution and RCCP control, in particular via a first broadcast stream 530 dedicated to the emergency situation and via a first emergency interactive command link 540. The first broadcast stream 530 dedicated to the emergency situation originates from the system page manager 510, NNC execution and RCCP control and is destined for the cyber module 550. The first emergency interactive command link 540 is bidirectional. The remote access manager 580 comprises a first processor 582, a security element 583, or "secure element" in English, and a first multi-network hardware filtering module 581. The remote access manager 580 is connected to the cyber module 550 via a . second broadcast stream 560 dedicated to the emergency situation and a second link 570 of emergency interactive commands. The second broadcast stream 560 dedicated to the emergency situation originates from the cyber module 550 and is destined for the remote access manager 580. The second link 570 of emergency interactive commands is bidirectional. The IP connectivity system 620 is connected to the remote access manager 580 via the first multi-network hardware filtering module 581. The IP connectivity system 620 is dedicated to the management of emergency situations at the cockpit level. The first processor 582 performs several functions dedicated to the management of an emergency situation. For example, the first processor 582 is in charge of monitoring an emergency situation detection in order to activate the necessary devices and initiate the establishment of a secure connection.The first processor 582 is also responsible for receiving the interactive command messages 750 coming from the ground environment and translating them into commands that can be understood by the cyber module 550 but especially by the system page manager, NNC execution and RCCP piloting. To carry out this operation, the processor will use the secrets recorded, i.e. elements kept secret such as keys and / or certificates, in the security element in order to be able to decrypt the messages and to be able to verify the identity of the source of the messages. In one example, the IP connectivity system 620 can be equipped with an internal gyroscopic inertial system and 3-axis accelerometer, also dedicated to emergency situation management. The inertial system makes it possible in particular to know the position and attitude of the aircraft.This information is used to determine in real time what type of communication media will be the most reliable and available to ensure the mission, for example, an Inmarsat ® SB-S satcom modem, an Iridium Certus ® satcom modem, an “air-ground” modem based on cellular technology such as 5G technology, or any other means of connecting the aircraft to the ground that meets the performance, availability, and quality of service constraints required by the device. Other examples of means that can be used to connect the aircraft to the ground are Internet access systems via satellite constellations such as One Web, Starlink, or Kuiper. The information sent by the ground environment, such as the interactive commands 610, passes through the IP connectivity system 620 and is then transmitted to the first multi-network hardware filtering module 581.Similarly, the information sent to the ground environment, such as the broadcast stream 600 dedicated to the emergency situation and the interactive commands 610, by the onboard environment 500 are transmitted by the first multi-network hardware filtering module 581 to the IP connectivity system 620. In one example, the first multi-network hardware filtering module 581 may be an integrated circuit of the FPGA type, for "field-programmable gate array" in English. In one example, compatible with the previous example, the . first multi-network hardware filtering module 581 allows the implementation of several independent Ethernet networks and provides physical segregation between each established network. This first multi-network hardware filtering module 581 is for example based on EPEX technology, for “Ethernet Port EXpander” in English, described in patent EP2652628B1 dated 2010-12-17 entitled “Device for multiple ethemet connection to a computer unit and computer unit assembly and equipment linked together”. EPEX technology provides the possibility of performing flow filtering at the OSI layer level, for “Open Systems Interconnection” in English, of level 1, 2 and / or 3 and also makes it possible to manage the bandwidth allocable to each port to protect against flooding attacks or denial of service. In another example, compatible with the previous example, the remote access manager 580 is of level S AL 3.

[0028] The method 100 is also implemented using a ground environment of a ground assistance center. An example of a ground environment 700 suitable for implementing the method 100 is illustrated in [Fig.6]. The ground environment 700 comprises an emergency connection manager 710 and a system 720 for connecting to IP network access service providers. The emergency connection manager 710 and the connection system 720 are dedicated to managing emergency situations. The emergency connection manager 710 comprises a second processor 712, a second security element 713 and a second multi-network hardware filtering module 711, different from the first multi-network hardware filtering module 581. In one example, the second multi-network hardware filtering module 711 may be an FPGA-type integrated circuit. The emergency connection manager 710 sends the broadcast stream 790 to the operational control center 760 dedicated to emergencies.In addition, the emergency connection manager 710 sends and receives interactive command messages 780. The information sent by the onboard environment 500, such as the broadcast stream 740 and the interactive command messages 750, passes through the system 720 for connecting to the IP network access service providers dedicated to emergency management and is then transmitted to the second multi-network hardware filtering module. Similarly, the information sent to the onboard environment 500, such as the interactive command messages 750, by the ground environment is transmitted by the second multi-network hardware filtering module 711 to the system 720 for connecting to the IP network access service providers dedicated to emergency management. The method 100 then makes it possible to send these interactive command messages to the remote access manager 580 of the onboard environment 500 via a secure connection.The method 100 also allows the emergency connection manager 710 to receive the broadcast stream 740 which was sent by the remote access manager 580. the 500 on-board environment via the secure connection.

[0029] The secure connection established according to the method 100 is an end-to-end secure connection between the onboard environment 500 of the aircraft and the ground environment 700 of the assistance center. This secure connection is dedicated exclusively to the management of an emergency situation for an aircraft. Thus, in one example, compatible with the previous examples, the connection is created when an emergency situation is detected and terminated when the emergency situation is resolved. When there is no emergency situation, the devices presented previously and used to implement the method 100 are not accessible from the outside, that is to say outside the onboard environment 500 and outside the ground environment 700. Thus, the connection duration is minimal and this makes it possible to increase the discretion of this connection and therefore its security.It is even possible in one example to isolate the remote access manager 580 from the cyber module 550 by deactivating the data flows between these two entities. In order to ensure their proper functioning, a test of the proper functioning of the connection between the remote access manager 580 and the cockpit connectivity system 620 can be carried out at regular intervals. This test can be carried out by a function equivalent to a 'ping' type command in order to ensure the functional availability of the link. In the same way, the cockpit connectivity system 620 carries out a test of the proper functioning of its link with the ground. These two tests can be carried out separately so as not to establish a direct connection between the remote access manager 580 in an emergency situation and the ground environment 700.

[0030] An emergency situation is a situation that may jeopardize the safety of the flight of the aircraft and therefore possibly the physical integrity of the persons on board the aircraft. In order to manage this situation, it is necessary to activate and / or deactivate certain controls of the aircraft. The method according to the present invention aims to assist the pilot of the aircraft in this task. The detection of an emergency situation may be due to a detection of loss of capacity of the pilot of the aircraft. The detection of an emergency situation may also be due to a crisis in the aircraft, for example a cascade of system failures, requiring the help or assistance of one or more persons removed to the ground. The device 520 for detecting an emergency situation may therefore take into account 2 input sources: • The result of monitoring the pilot's capability level, and • The activation of an emergency situation declaration element.

[0031] A first step 110 of the method 100 consists of sending an ACARS message via an ACARS network. The acronym ACARS stands for “Addressing Communication And Reporting System” and designates a digital data link system for the transmission of short messages between aircraft and stations at ground by airband radio or by satellite. The ACARS message is sent by the onboard environment 500 to the ground environment 700 when an emergency situation concerning the aircraft is detected. This message informs the assistance center that an emergency situation has been detected in the aircraft and that the pilot of the aircraft needs assistance. The ACARS message can be opaque, that is to say that the data contained in this message is obfuscated. Data obfuscation is a form of data masking in which the data is deliberately scrambled. Optionally, the device 520 in charge of detecting and alerting in the event of an emergency situation generates an internal signal to the onboard environment 500. This internal signal informs in particular the system page manager 510, NNC execution and RCCP piloting and the cyber module 550 of the activation of the emergency mode.These modules then activate a configuration giving priority to the processing of data flows associated with the emergency situation. The ACARS network can be implemented with a connectivity router 630 on the side of the on-board environment 500 and a module 730 for connection to the ACARS network access service providers.

[0032] In a second step 120, the ACARS message is received and decoded by the ground environment 700 of the assistance center located on the ground.

[0033] In a third step 130, a test is performed to verify whether the message concerns an emergency situation by the assistance center. When the ACARS message is considered to describe an emergency situation by the assistance center, a confidential environment dedicated to the management of the emergency situation is set up. Confidentiality is the characteristic of information being accessible only to those who are authorized. This activation 130 of the confidential environment comprises three sub-steps 131 to 134. [Fig. 2] shows a schematic representation of an example of the third step 130 of the method 100.

[0034] The first sub-step 131 of step 130 is the sending of an ACARS message via the ACARS network. The message is sent by the ground environment to the on-board environment. In addition, the ACARS message contains a confirmation of the situation being taken into account by the assistance center. For example, the ground user, pilot or other personnel, who can assist an aircraft in an emergency situation and who has authorization to physically enter the confidential environment sends a confirmation message of the situation being taken into account via the ACARS network.

[0035] The second sub-step 132 of step 130 is the establishment of a cloud 630 MPLS, for “multiprotocol label switching” in English, between the system 620 of IP connectivity and the system 720 of connection to the providers of access to the IP network service. The main role of the MPLS network technique is to combine the concepts of IP routing of level 3, and the mechanisms of switching of level 2. In addition, the technique MPLS network handles connected mode switching, based on labels, the switching tables being calculated from information coming from IP routing protocols as well as control protocols. The MPLS network technique can be considered as an interface bringing the internet protocol, denoted IP, the connected mode and which uses the services of layer 2. Finally, it should be noted that the MPLS network technique is in no way restricted to a specific layer 2 and can operate on all types of media allowing the routing of layer 3 packets. A 630 MPLS cloud, for "Multiprotocol Label Switching" in English is more precisely an infrastructure of an access provider operating by switching labels. This technology is chosen for its characteristics which allow to ensure a good level of flow routing performance.Indeed, this MPLS routing technology is considered an intermediate OSI layer, commonly referred to as "OSI 2.5", between the Ethernet OSI 2 layer and the IP OSI 3 layer. Thus, this technology makes it possible to route IP packets without having to decapsulate them because it uses one or more labels that are added to the frame and which make it possible to quickly route a packet from one element of the 630 MPLS cloud to another. In addition, this technology makes it possible to allocate a class of service in order to ensure quality of service and bandwidth allocation.

[0036] The third sub-step 133 of step 130 is the connection of the on-board environment 500 to the MPLS cloud 630 by the first multi-network hardware filtering module 581 as well as the connection of the ground environment 700 to the MPLS cloud 630 by the second multi-network hardware filtering module 711. The connection 590 is the connection of the on-board environment 500 to the MPLS cloud 630 managed by the first module 581. The connection 800 is the connection of the ground environment 700 to the MPLS cloud 630 managed by the second module 711. This sub-step 133 allows the establishment of a secure aircraft-ground communication at the level of the communication means. For example, this establishment may include, initially, establishing a connection by the IP connectivity system 620 with the ground environment 700 via the media which presents the best quality of service.All the security attributes of this link are activated to establish a first level of protection of the exchanges. This link is represented by a first tunnel 640 in FIGS. 5 and 6. Concerning the ground environment 700, the system 720 for connection to the IP network access service providers dedicated to emergency situations ensures the termination of the secure link. The establishment of this first level of security involves the IP network access service providers who will contribute to the overall quality of service of the emergency link. The third sub-step 133 of step 130 can be carried out before or after the second sub-step 132 of step 130.

[0037] The fourth sub-step 134 of step 130 is the establishment of a secure connection between the onboard environment 500 and the ground environment 700. The connection is secured in particular via hybrid encryption using the two main families of encryption: asymmetric encryption and symmetric encryption. The hybrid encryption is carried out using a public key and a private key. In one example, the public key may be part of a public key infrastructure. In addition, these keys may also be electronic certificates. The public key is accessible by the onboard environment 500 and the ground environment 700. The public key may for example be stored at the ground environment 700. Preferably, the public key is known only to the organization that operates the aircraft and must be stored and managed in a secure environment.As soon as a suspicion that a key is disclosed arises, the entire fleet and the confidential ground environment may, or in some cases must, be updated as quickly as possible. The asymmetric private key is accessible only by the ground environment 700. The establishment 134 of a confidential connection includes the encryption of messages allowing the establishment of the secure link using the public key. In addition, the encrypted messages are sent within the MPLS cloud 630 and at least one of the encrypted messages sent includes the symmetric private key and therefore allows it to be shared with the onboard environment 500. The symmetric private key can then be used to encrypt and decrypt the exchanges between the ground environment 700 and the onboard environment 500. The implementation of the fourth sub-step 134 can be carried out by the processor 582 and the security element 583 of the remote access manager 580 in an emergency situation.In one example, this sub-step is achieved by using secrets, in addition to the previously mentioned keys, that are strong enough to be quantum-safe, for example by choosing libraries or programs that meet the requirements established by the National Institute of Standards and Technology (NIST) in the standard "Post-Quantum Cryptography Standardization." Quantum-safe cryptography refers to efforts to identify algorithms that are resistant to attacks from both classical and quantum computers, in order to preserve the security of information, even after the construction of a large-scale quantum computer. At the end of these exchanges, the onboard environment has authenticated the ground environment.It should also be noted that an identical process with another set of keys is carried out so that the ground environment authenticates the onboard environment. This double authentication is commonly a mutual authentication. At the end of this sub-step 134, the tunnel 650 is set up. This tunnel 650 is at OSI level 3 or Layer 3 Virtual Private Network, noted L3VPN. This tunnel then allows the messages transported and exchanged to be encrypted.

[0038] In one example, compatible with the preceding examples, the method 100 comprises an optional fourth step 140 of multi-factor authentication in order to access a remote display of a cockpit of the aircraft in an emergency situation. Multi-factor authentication is authentication requiring the user to provide several proofs of identity, also called factors. The factors are commonly separated into four types: • Knowledge factors: password, confidential code, etc. • Physical factors: smartphone, badge, USB key, etc. • Biological factors: fingerprint, facial or voice recognition, etc. • Location factors: network connection, geographic position, etc.

[0039] In one example, consistent with the previous examples, access to the area for managing an emergency situation is subject to “physical” access authorization; this step acts as a first level of validation and authenticates the user located on the ground as being capable of assuming responsibility for any action with respect to the aircraft.

[0040] Multi-factor authentication allows access at the environment level to the remote display of the aircraft cockpit in an emergency situation. A remote display here consists of offering a display of the aircraft cockpit for a user located in the assistance center. This remote display therefore allows a user, who is not physically in the aircraft, to see the state of the cockpit in real time in order, for example, to advise the pilot located in the aircraft.

[0041] In one example, compatible with the previous example, the multi-factor authentication 140 comprises 4 sub-steps 141 to 144. [Fig. 3] shows a schematic representation of an example of step 140 of the method 100. The first sub-step 141 of step 140 consists of generating a random password by the remote access manager 580. A second sub-step 142 of step 140 consists of sending an ACARS message, comprising the generated password, via the ACARS network to the ground environment 700. A third sub-step 143 of step 140 consists of receiving the message by the ground environment 700 and entering the password. The password entry is for example carried out by a user. Additionally, in one example, the processor 582 may wait a limited time, for example 30 seconds, to allow the remote pilot to enter the password on a screen in the ground environment 700.If the ground pilot enters the wrong password or responds beyond the time limit, the processor 582 generates a new password which is sent to the ground environment 700 via the ACARS network. When the password entered by the user is authenticated, the fourth . sub-step 144 of step 140 consists of activating the broadcast streams allowing remote viewing of the aircraft cockpit in an emergency situation.

[0042] In another example, multi-factor authentication is performed based on a time-based one-time password mechanism, "One-Time Password" in English or on a "Google au-thenticator" authentication mechanism.

[0043] In one example, compatible with the preceding examples, the method 100 further comprises 7 optional steps 150 to 210. In this example, the remote display of the cockpit of the aircraft in an emergency situation further comprises a user interface. The user interface notably allows the user to interact with the cockpit via an interaction applied to the remote display such as a click on a button. Steps 150 to 210 are for example implemented for each action requested by the pilot on the ground.

[0044] The optional step 150 of the method 100 consists of receiving by the user interface an interaction initiated by the user located on the ground. In addition, the interaction corresponds to a command from the cockpit of the aircraft, such as stopping, restarting or modifying operating parameters of a system of the aircraft.

[0045] The optional step 160 of the method 100 consists of sending a signed message from the ground environment 700 to the onboard environment 500. The signed message comprises the command, or information allowing the onboard environment 500 to identify the command, and an additional field filled in randomly. In one example, the signature of the message also uses asymmetric keys and / or certificates. These asymmetric keys and / or certificates are different from the keys and / or certificates used to set up the secure communication link.

[0046] The optional step 170 of the method 100 consists of receiving the signed message. The reception is carried out by the embedded environment 500.

[0047] Optional step 180 of method 100 is to authenticate the signed message. For example, the processor receives the message, decrypts and verifies the signature containing the command and the random field.

[0048] When the signed message is authenticated 180, the on-board environment 500 sends in a step 190 an ACARS message and an IP message to the ground environment 700. In the previous example, the processor takes the content of the random field and returns it to the ground environment 700 via an ACARS message and via an IP message.

[0049] The optional step 200 of the method 100 consists of carrying out the command included in the signed message. The command is carried out at the aircraft level in the cockpit. In the previous example, the processor translates the emergency interactive command message into a command intelligible by the module 510, system page manager, NNC execution and RCCP piloting. This command is then carried out at the level of the embedded environment 500.

[0050] The optional step 210 of the method 100 consists of updating the remote display of the cockpit of the aircraft in an emergency situation. Thus, once the action has been carried out at the aircraft level, the result is available via the broadcast stream. The ground environment 700 is thus continuously supplied with data generated by the aircraft to supply the remote display and help the ground crew to have the vision and follow the developments in the cockpit.

[0051] In one example, consistent with the preceding examples, the method 100 further comprises an optional step 220 of declaring the end of the emergency situation when the aircraft has landed. The step 220 of declaring the end of the emergency comprises three sub-steps 221 to 223. [Fig. 4] shows a schematic representation of an example of the step 220 of the method 100.

[0052] The first sub-step 221 of step 220 consists of restarting the remote access manager 580 and the IP connectivity system 620 dedicated to managing the emergency situation at the level of the on-board environment 500. For example, the power supply of the remote access manager 580 and the IP connectivity system 620 dedicated to managing the emergency situation can be stopped and then restarted.

[0053] The second sub-step 222 of step 220 consists of deleting the secure connection at the ground environment 700. Deleting the secure connection at the environment level may consist of refuting it.

[0054] The third sub-step 223 of step 220 consists of updating the public key and the private key. This step 223 can be carried out before the aircraft resumes its service.

[0055] In one example, from the moment an aircraft activates emergency situation management, this operating mode will be active until the mission is considered to be fully accomplished, namely when the aircraft is stopped, engines off and positioned at a gateway. Once these conditions are met, a ground maintenance operator will be able to perform an operation allowing the aircraft to return to a normal situation. An example of an operation allowing the aircraft to return to a normal situation is to cut off all electrical power sources to turn off all systems and components of the aircraft, wait a few minutes then repower the systems and components and finally check that the aircraft restarts correctly in a “non-emergency” mode.

[0056] Unless otherwise specified, the same element appearing in different figures presents a unique reference.

Claims

Claims

1. Method (100) for establishing a secure end-to-end connection between an on-board environment (500) of an aircraft and a ground environment (700) of a ground-based assistance center, the secure connection being dedicated exclusively to managing an emergency situation with: - The embedded environment (500) comprising a remote access manager (580) and an IP connectivity system (620) dedicated to managing the emergency situation, the remote access manager (580) comprising a first multi-network hardware filtering module (581) and the IP connectivity system (620) being linked to the remote access manager (580) via the multi-network hardware filtering module (581), and - The ground environment (700) comprising an emergency connection manager (710) dedicated to managing the emergency situation, the emergency connection manager (710) comprising a second multi-network hardware filtering module (711), The method comprising: - Sending (110) a first “Aircraft Communication Addressing and Reporting System” ACARS message via an ACARS network, the first ACARS message being sent by the onboard environment (500) to the ground environment (700) when an emergency situation concerning the aircraft is detected, - Receive and decode (120) the first ACARS message via the ground environment (700) of the assistance center, - When the first ACARS message is considered to describe an emergency situation, activating (130) a confidential environment dedicated to the management of the emergency situation, the activation of the environment comprising: • Sending (131) a second ACARS message via the ACARS network, the second ACARS message being sent by the ground environment (700) to the onboard environment (500) and the second ACARS message containing a confirmation of the consideration of the emergency situation • Set up (132) an MPLS “multiprotocol label switching” cloud (630) between the IP connectivity system (620) and the system (720) for connection to the IP network access service providers, • Establish (133) a connection (590, 800) to the MPLS cloud (630) by the first and second multi-network hardware filtering modules (581, 711), and • Establish (134) a secure connection between the onboard environment (500) and the ground environment (700) via hybrid encryption using a public key and a private key, the public key being accessible by the ground environment (700) and the onboard environment (500) and the private key being accessible exclusively by the ground environment (700),establishing a secure connection including message encryption enabling the secure connection to be established using the public key, the encrypted messages being sent within the MPLS cloud (630) and at least one of the encrypted messages enabling the sharing of the private key.,

2. The method (100) of claim 1 further comprising multi-factor authentication to access a remote display of a cockpit of the aircraft in an emergency situation, the remote display being performed at the ground environment.

3. Method according to claim 2 in which the multi-factor authentication (140) comprises: - Generating (141) a random password by the remote access manager (580), - Sending (142) a third ACARS message comprising the generated password via the ACARS network to the ground environment (700), - Reception (143) of the third message by the ground environment (700) and entry of the password by a user, and - When the password entered by the user is authenticated, the remote display of the cockpit of the aircraft in an emergency situation is activated (144).

4. Method (100) according to claim 2 or 3 wherein the remote display of the cockpit of the aircraft in an emergency situation further comprises a user interface, the method (100) further comprising: - Reception (150) by the user interface of an interaction initiated by the user, the interaction corresponding to a command from the cockpit of the aircraft, - Sending (160) of a signed message, the signed message comprising the command and an additional field filled in randomly, - Reception (170) of the signed message by the on-board environment (500), - When the signed message is authenticated (180) by the on-board environment (500): • Sending (190) by the on-board environment (500) of a fourth ACARS message and an IP message to the ground environment (700), • Carrying out (200) the command included in the signed message, the command being carried out in the cockpit,and • Update (210) of the remote display of the aircraft cockpit in an emergency situation.,

5. Method (100) according to any one of the preceding claims further comprising a declaration (220) of end of emergency situation when the aircraft has landed, the declaration of end of emergency comprising: - Restarting (221) the remote access manager (580) and the IP connectivity system (620) dedicated to the management of the emergency situation at the level of the on-board environment (500), - Delete (222) the secure connection at the ground environment level (700), and - Update (223) the public key and the private key.

6. On-board environment (500) of an aircraft comprising a remote access manager (580) and an IP connectivity system (620) dedicated to managing the emergency situation, the remote access manager (580) comprising a multi-network hardware filtering module (511) and the IP connectivity system (620) being linked to the remote access manager (580) via the multi-network hardware filtering module, the on-board environment (500) being configured to implement a method according to one of the preceding claims.

7. Aircraft comprising an on-board environment (500) according to the preceding claim.

8. Ground environment (700) of a ground-based assistance center comprising an emergency connection manager (710), the emergency connection manager (710) comprising a second multi-network hardware filtering module (711), the ground environment (700) being configured to implement a method according to one of claims 1 to 5.

9. A computer program comprising instructions which, when the program is executed by a computer, cause the on-board environment and the ground environment according to claims 6 and 8 to execute at least one of the steps of the method according to one of claims 1 to 5.

10. Computer-readable medium, on which the computer program according to the preceding claim is recorded.