Electronic processing device, avionics computer, communication infrastructure and associated processing method

The electronic processing device verifies the integrity of decryption algorithms in avionics systems by comparing encrypted and decrypted messages, addressing the need for continuous operation and cyber-attack detection without recertification.

FR3164589A1Pending Publication Date: 2026-01-16THALES SA
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
FR2024007601
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-11
Publication Date
2026-01-16

AI Technical Summary

Technical Problem

Existing avionics systems require recertification with every change in decryption algorithms, and there's a need for real-time integrity verification and cyber-attack detection in aeronautical telecommunications.

Method used

An electronic processing device on board the aircraft with a verification module to compare encrypted and decrypted messages, ensuring integrity and detecting cyber-attacks without recertification, using certified processing devices.

Benefits of technology

Ensures continuous operation and rapid detection of cyber-attacks without requiring recertification of the avionics system, maintaining communication integrity and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Electronic processing device, avionics computer, communication infrastructure and associated processing method. The present invention relates to an electronic processing device (44) intended to be carried on board an aircraft (30) and comprising: a first receiving module (50) configured to receive an encrypted message, a second receiving module (52) configured to receive an associated decrypted message, the decrypted message having been calculated via a decryption algorithm applied to the encrypted message by a decryption device (42), external to the processing device (44), and characterized in that it further comprises a verification module (54) configured to verify the behavior of the decryption device (42) via a comparison between the encrypted message and the associated decrypted message according to a set of comparison criteria. Figure for the abstract: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Electronic processing device, avionics computer, communication infrastructure and associated processing method

[0001] The present invention relates to a processing device intended to be carried on board an aircraft.

[0002] The invention also relates to an avionics computer intended to be carried on board an aircraft, the computer comprising a flow management device, a decoding device and such a processing device.

[0003] The invention also relates to a communication infrastructure comprising a ground computer intended to be installed on the ground and such an avionics computer.

[0004] The invention also relates to a processing method implemented by such a processing device; and to a computer program comprising software instructions which, when executed by a computer, implement such a processing method.

[0005] The invention relates to the field of communications in the context of the needs of the ATN / IPS (from the English Aeronautical Telecommunication Network using the Internet Protocol Suite) designating aeronautical telecommunication networks based on the Internet connection protocol.

[0006] In the context of ATN / IPS, computer security during communications is paramount to ensure the safety of aircraft in the event of a computer attack or failure of telecommunications systems.

[0007] More specifically, the invention relates to computer security during communications between ground equipment and certified equipment on board an aircraft.

[0008] In the world of aeronautical telecommunications, it is common practice to enable an aircraft to communicate with ground equipment using an avionics system configured to allow such communication. Generally, the messages exchanged during these communications are encrypted, and the avionics system then includes one or more decryption / encryption algorithms to decrypt encrypted messages received from the ground equipment, or even to encrypt any messages destined for the ground equipment.

[0009] In addition, such an avionics system must be certified to meet aeronautical requirements, for example according to SAL (Security Assurance Level) certification or DAL (Design Assurance Level) certification.

[0010] However, the list of decryption algorithm(s) required to decrypt encrypted messages received from ground equipment is likely to evolve, and a new certification of such an avionics system is then potentially required with each evolution of this list.

[0011] The aim of the invention is then to propose an electronic processing device and an associated method, making it possible to remedy this problem.

[0012] To this end, the invention relates to a processing device intended to be carried on board an aircraft and comprising:

[0013] - a first receiving module configured to receive an encrypted message,

[0014] - a second receiving module configured to receive a decrypted message associated, the decrypted message having been calculated via a decryption algorithm applied to the encrypted message by a decryption device, external to the processing device;

[0015] the processing device further comprising a verification module configured to verify a behavior of the decryption device via a comparison between the encrypted message and the associated decrypted message according to a set of comparison criterion(a).

[0016] The onboard processing device of the aircraft according to the invention then makes it possible to verify the behavior of the decryption device, external processing device, which has decrypted the received encrypted message, that is to say to verify the integrity of the decryption device via regular monitoring of the decrypted messages, these being compared to each respective encrypted message.

[0017] Thus, the processing device is certified, but the decryption device is not certified, and a possible change in the decryption algorithm does not then require new certification.

[0018] In addition, the processing device also allows, via this integrity check, the rapid detection of a possible computer attack, or cyber-attack, against the decryption device.

[0019] According to other advantageous aspects of the invention, the treatment device comprises one or more of the following features, taken individually or in all technically possible combinations:

[0020] - the decryption algorithm conforms to the Data Transport Layer protocol Security (DTLS);

[0021] - the set of comparison criteria includes a first criterion of comparison depending on the size of the encrypted message and the size of the decrypted message;

[0022] - the set of comparison criteria includes a second criterion of comparison depending on a time instant of reception of the encrypted message and a time instant of reception of the decrypted message;

[0023] - the second comparison criterion is that a time gap between the instant the time of reception of the encrypted message and the time of reception of the decrypted message is less than a predefined duration, such as 100 ms;

[0024] - the verification module is configured to compare the encrypted message and the decrypted message associated according to the set of comparison criteria, in the absence of implementation of the decryption algorithm within the processing device.

[0025] The invention also relates to an avionics computer intended to be installed on board an aircraft and comprising:

[0026] - a decryption device configured to receive an encrypted message and calculate a decrypted message associated via a decryption algorithm,

[0027] - a processing device configured to process the decrypted message,

[0028] - a flow management device configured to receive a data stream and extract the encrypted message, then transmit the encrypted message to both the processing device and the decryption device, the processing device being as defined above,

[0029] According to other advantageous aspects of the invention, the avionics computer comprises one or more of the following features, taken individually or in all technically possible combinations:

[0030] - the processing device is configured to command a restart of the decryption device if the set of comparison criteria is not met,

[0031] - the processing device is configured to control the implementation of a a new decryption device will be used if the set of comparison criteria is not met again following a restart of the decryption device.

[0032] - the processing device is configured to receive, during a first exchange, a verification data from a ground computer through a secure communication channel and verify the establishment of such a first exchange via a state machine.

[0033] Furthermore, the invention relates to a communication infrastructure comprising: - an avionics computer intended to be installed on board an aircraft and configured to receive and process a data stream,

[0034] - a ground calculator intended to be installed on the ground and configured to generate and transmit the data stream to the avionics computer, and

[0035] the avionics computer being as defined above.

[0036] Furthermore, the invention relates to a processing method implemented by an electronic processing device and comprising the following steps:

[0037] - reception of an encrypted message,

[0038] - reception of an associated decrypted message, the decrypted message having been calculated via a decryption algorithm applied to the encrypted message by a decryption device external to the processing device, and

[0039] - verification of the behavior of the decryption device via a comparison between the encrypted message and the associated decrypted message according to a set of comparison criteria.

[0040] According to other advantageous aspects of the invention, the treatment process comprises the following step:

[0041] - prior to the reception stage, an initial exchange of unencrypted data and including:

[0042] - generation of a private client key and a public client key by a ground computer,

[0043] - generation of a private server key and a public server key by the device deciphering,

[0044] - transmission of a recognition message, from the ground computer, towards the decryption device via a secure communication channel between the ground computer and the decryption device, said acknowledgment message including at least one random client signature data, a list of supported encryption algorithms, the public client key and a list of supported cryptography services,

[0045] - reception of the recognition message by the decryption device,

[0046] - selection of an encryption algorithm and a cryptography service from among the lists received,

[0047] - transmission of a second recognition message, from the device decryption, towards the ground computer via the communication channel, said second acknowledgment message including at least the selected encryption algorithm, the public server key and the selected cryptography service,

[0048] - calculation of a first verification data by the decryption device from of the public client key and the private server key,

[0049] - calculation of a second verification data point by the ground computer from the key public server and private client key,

[0050] - establishment of encrypted communication between the ground computer and the computer avionics, said communication being authorized only if the first check data is equal to the second check data.

[0051] Finally, the invention also relates to a computer program comprising software instructions which, when executed by a computer, implement a processing method as defined above.

[0052] The invention will become clearer upon reading the following description, given solely by way of non-limiting example, and made with reference to the drawings in which:

[0053] [Fig-1] [Fig.1] is a schematic representation of an infrastructure of communication, according to the invention, the communication infrastructure comprising a ground computer intended to be installed on the ground and an avionics computer intended to be installed on board an aircraft, the avionics computer comprising a flow management device, a decoding device and a processing device according to the invention; and

[0054] [Fig.2] [Fig.2] is a flowchart of a treatment process according to the invention, the process being implemented by the processing device of [Fig.1].

[0055] In [Fig.1], a communication infrastructure 10 includes a ground computer 20 intended to be installed on the ground and an avionics computer 22 intended to be carried on board an aircraft 30.

[0056] For example, the ground computer 20 is configured to generate and transmit a data stream 21 to the avionics computer 22 via a data link. The data stream 21 includes at least one encrypted message. Typically, the data stream 21 also includes MAC, IP, and UDP addresses, a source, and a destination. The data link is known per se and is typically a radio link.

[0057] The avionics computer 22 is configured to receive and process said data stream 21.

[0058] The avionics computer 22 includes an electronic flow management device 40, an electronic decoding device 42 and an electronic processing device 44.

[0059] Typically, the flow management device 40, the decoding device 42 and the processing device 44 are connected to each other.

[0060] For example, the flow management device 40, the decryption device 42 and the processing device 44 run on the same processor.

[0061] Alternatively, only the decryption device 42 and the processing device 44 run on the same processor.

[0062] Alternatively, the stream management device 40, the decryption device 42, and the processing device 44 each run on their respective separate processors. According to this alternative, the stream management device 40, the decryption device 42, and the processing device 44 then run in total on three separate processors.

[0063] The flow management device 40 is configured to receive the data flow 21. In addition, the flow management device 40 is configured to process only the Legitimate data streams. For example, legitimate data streams contain consistent MAC, IP, and UDP addresses, as well as a consistent source and destination.

[0064] In addition, the flow management device 40 is configured to extract the encrypted message from the data stream 21.

[0065] The decryption device 42, also called the decryption device, is configured to receive the encrypted message and calculate an associated decrypted message via a decryption algorithm.

[0066] Advantageously, the decryption device 42 does not require any avionics certification.

[0067] By way of example, the decryption algorithm conforms to a communication protocol, such as the DTLS (Data Transport Layer Security) protocol.

[0068] Alternatively, the communication protocol to which the decryption algorithm conforms is chosen from the group consisting of: the TCP protocol (Transport Control Protocol), the IPv6 protocol, the Packet Firewall protocol, the ICMP protocol (Internet Control Message Protocol) and the TLS protocol (Transport Layer Security).

[0069] The decryption algorithm is for example chosen from the group consisting of: a SHA algorithm (from the English Secure Hash Algorithm), an AES algorithm (from the English Advanced Encryption Standard), a CCM algorithm (from the English Counter mode with Cipher block chaining Message) and a GCM algorithm (from the English Galois Counter Mode)

[0070] When the decryption algorithm is of the SHA type, it uses for example a cryptography service chosen from the group of cryptography services comprising: TLS_AES_128_GCM_SHA256, TLS_AES_128_CCM_SHA256, TLS_AES_256_GCM_SHA384.

[0071] As an optional complement, the decryption algorithm is coded in Linux, and the decryption device 42 is configured to include only a predefined list of libraries necessary for the operation of said decryption algorithm.

[0072] The processing device 44 comprises a first receiving module 50, a second receiving module 52 and a verification module 54.

[0073] Unlike the decryption device 42, the processing device 44 is advantageously certified, for example according to the SAL certification or according to the DAL certification.

[0074] In the example of [Fig.1], the processing device 44 includes an information processing unit 60 formed, for example, of a processor 62 and a memory 64 associated with the processor 62.

[0075] Continuing with the example in [Fig. 1], the first receiving module 50, the second receiving module 52, and the verification module 54 are each implemented as a software program, or a software component, executable by the processor 62. The memory 64 of the processing device 44 is then capable of storing a first receiving software program, a second receiving software program, and a verification software program. The processor 62 is then capable of executing each of the following software programs: the first receiving software program, the second receiving software program, and the verification software program.

[0076] In an alternative not shown, the first receiving module 50, the second receiving module 52 and the verification module 54 are each implemented as a programmable logic component, such as an FPGA (Field Programmable Gate Array), or as a dedicated integrated circuit, such as an ASIC (Application-Specific Integrated Circuit).

[0077] When the processing device 44 is implemented in the form of one or more software programs, i.e., in the form of a computer program, it is also capable of being stored on a computer-readable medium (not shown). A computer-readable medium is, for example, a medium capable of storing electronic instructions and being connected to a bus of a computer system. For example, a readable medium is an optical disc, a magneto-optical disc, a ROM, a RAM, any type of non-volatile memory (e.g., EPROM, EEPROM, FLASH, NVRAM), a magnetic card, or an optical card. A computer program comprising software instructions is then stored on the readable medium.

[0078] For example, the processing device 44 is in an IMA (Integrated Module Avionics). An IMA is a computer network avionics system comprising a plurality of computer modules capable of supporting numerous applications of varying levels of criticality.

[0079] The first receiving module 50 is configured to receive the encrypted message from the flow management device 40.

[0080] The second receiving module 52 is configured to receive the decrypted message from the decryption device 42.

[0081] The verification module 54 is configured to verify a behavior of the decryption device 42 via a comparison between the encrypted message and the associated decrypted message according to a set of comparison criterion(a).

[0082] The set of comparison criteria includes a first comparison criterion depending on a size of the encrypted message and a size of the decrypted message.

[0083] For example, if the size of the encrypted message is equal to the size of the decrypted message, the processing device 44 validates the behavior of the decryption device 42 as normal, and the decryption device 42 is considered compliant, i.e., intact. Conversely, if the size of the encrypted message differs from the size of the decrypted message, the processing device 44 does not validate the behavior of the decryption device 42, and the decryption device 42 is considered non-compliant, i.e., not intact. Indeed, a size difference between the encrypted and decrypted messages can mean that the decryption device 42 is defective or the victim of a cyberattack.

[0084] In addition, the set of comparison criteria includes a second comparison criterion depending on the time of reception of the encrypted message and the time of reception of the message decrypted by the processing device 44.

[0085] For example, if the decryption device 42 is defective or the victim of a computer attack, message processing is typically slowed down, causing an increased time gap between the times when the processing device 44 receives the encrypted message and the decrypted message.

[0086] For example, the second comparison criterion is that the time difference between the time of reception of the encrypted message and the time of reception of the decrypted message is less than a predefined duration, such as 100 ms. Such a time difference value is slightly greater than the normal computation time of the decryption device 42.

[0087] Advantageously, the verification module 54 is configured to compare the encrypted message and the associated decrypted message according to the set of comparison criteria, in the absence of an implementation of the decryption algorithm within the processing device 44.

[0088] As an optional addition, the processing device 44 is configured to trigger a restart of the decryption device 42 if the set of comparison criteria is not met. Those skilled in the art will recognize that the ability of the processing device 44 to restart such a decryption device 42 without affecting other partitions of the same system is a property of the IMA's operating systems.

[0089] In addition, the processing device 44 is configured to command the implementation of a new decryption device 42 if the set of comparison criteria is not met again following the restart of the decryption device 42.

[0090] In addition, the processing device 44 is configured to verify the integrity of a first data exchange between the decryption device 42 and the ground computer 20 via a state machine, said first data exchange being carried out through a secure communication channel 23.

[0091] The operation of the avionics computer 22 according to the invention, and in particular of the electronic processing device 44, is now explained with the aid of [Fig.2] representing a flowchart of the processing method according to the invention.

[0092] Initially, the first data exchange is not encrypted and is divided into a plurality of successive actions.

[0093] During the first generation action, the solenoid computer 20 generates a private client key and a public client key. In parallel, the decryption device 42 generates a private server key and a public server key. Typically, the generated private keys are encoded on 32 bytes and therefore have values ​​between 0 and 2^-1. Advantageously, such key sizes improve security in the event of a cyberattack, such as a brute-force attack.

[0094] During a second reconnaissance action, the ground computer 20 sends a reconnaissance message to the decryption device 42 via the secure communication channel 23. The reconnaissance message includes at least one random client signature, a list of supported encryption algorithms, the public client key, and a list of supported cryptographic services. Optionally, the list of encryption algorithms and the list of cryptographic services are ordered according to a preference order.

[0095] When the decryption device 42 receives said acknowledgment message, said decryption device 42 sends back a second acknowledgment message to the ground computer 20 via the secure communication channel 23. The second acknowledgment message includes at least one encryption algorithm selected from the list received from the ground computer 20, the public server key and a cryptography service selected from the list received from the ground computer 20. If the received lists are ordered in order of preference, the decryption device 42 selects the first encryption algorithm and the first cryptography service that the latter is capable of supporting in said lists.

[0096] Next, the decryption device 42 calculates a first verification data point from the public client key and the private server key. For example, the verification data point is the result of applying the curve25519() algorithm to the public client key and the private server key.

[0097] In parallel, the sol calculator 20 calculates a second verification data point by applying the curve25519() algorithm to the public server key and the private client key. Advantageously, the calculations performed by the calculator 20 and the decryption device 42 have the same result thanks to the properties of elliptic curve multiplication of the curve25519() algorithm.

[0098] The first verification data transmitted by the decoding device 42, and respectively the second verification data transmitted by the ground computer 20, during such exchanges, allows verification that data communication is authorized between the two devices.

[0099] During such exchanges, a communication received by the decryption device 42, or respectively by the ground computer 20, which does not contain the corresponding verification data is interrupted.

[0100] In addition, to allow the reception of encrypted messages from the ground computer 20, the decryption device 42 first checks that the first calculated verification data is equal to the second received verification data; and conversely, to allow the reception of encrypted messages from the decryption device 42, the ground computer 20 first checks that the second calculated verification data is equal to the first received verification data.

[0101] Once these actions have been performed, communications between the ground computer 20 and the avionics computer 22 are encrypted. Since the encryption algorithm and the cryptography service used during these communications are known to the ground computer 20 and the decryption device 42, each computer is capable of reading encrypted data received by the other computer or transmitting encrypted data to the other computer.

[0102] At each communication, the sol 20 computer and the decryption device provide the corresponding verification data without which said communication is interrupted.

[0103] In addition, the state machine checks the integrity of the random customer signature data and whether any of the preceding actions have been properly implemented. If said integrity is not verified, the avionics computer 22 refuses all communication.

[0104] During a step 100, the electronic processing device 44 receives, via its first receiving module 50, a respective encrypted message from the flow management device 40.

[0105] Advantageously, the electronic processing device 44 receives the encrypted message once the first exchange has been established and the verification data has been validated.

[0106] After this first reception step 100, the processing device 44 receives, in a subsequent step 200 and via its second reception module 52, a respective decrypted message from the decryption device 42.

[0107] A person skilled in the art will understand that the calculation time, i.e. implementation time, of the decryption device 42 implies a time gap between the time of reception of the encrypted message and the time of reception of the message decrypted by the processing device 44, that is to say between the time associated with the first reception step 100 and the time associated with the second reception step 200.

[0108] For example, the decrypted message corresponds to the useful part of data extracted from the data stream 21.

[0109] The decrypted message is calculated from the encrypted message via the application of the decryption algorithm to the encrypted message.

[0110] The decryption algorithm is applied by the decryption device 42, which is external to the processing device 44. For example, the decryption algorithm is applied by the decryption device 42 of the avionics computer 22.

[0111] Next, the processing device 44 checks, in a subsequent step 300 and via its verification module 54, the behavior of the decryption device 42.

[0112] This behavior check is then aimed at verifying the integrity of the decryption device 42, and in particular that it has not been the subject of an attack.

[0113] The verification is implemented via a comparison between the encrypted message and the associated decrypted message according to the set of comparison criteria.

[0114] Advantageously, if the set of comparison criteria is not met, the processing device 44 commands the restart of the decoding device 42.

[0115] As an optional addition, if the set of comparison criteria is not met again following the restart of the decryption device 42, the processing device 44 commands the implementation of a new decryption device 42.

[0116] It is then understood that the electronic processing device 44 according to the invention makes it possible to verify the integrity and availability of the decryption device 42 which is external to the processing device 44 and therefore distinct from the processing device 44. The decryption device 42 is for example in the form of COTS software embedded on board the aircraft 30.

[0117] In particular, such an invention makes it possible to monitor in real time the integrity of the decryption device 42 running COTS software in the specific context of ATN / IPS.

[0118] In addition, the invention makes it possible to quickly detect a possible computer attack, or cyber-attack, against the decryption device 42.

[0119] Finally, the capabilities of the processing device 44 to restart the decryption device 42 and to implement a new decryption device in the event of a detected problem make it possible to guarantee the availability of the decryption device 42, for example in the form of COTS software, in the context of the ATN / IPS.

Claims

Demands

1. Electronic processing device (44) intended to be carried on board an aircraft (30) and comprising: - a first receiving module (50) configured to receive an encrypted message, - a second receiving module (52) configured to receive an associated decrypted message, the decrypted message having been calculated via a decryption algorithm applied to the encrypted message by a decryption device (42), external to the processing device (44), and characterized in that it further comprises a verification module (54) configured to verify a behavior of the decryption device (42) via a comparison between the encrypted message and the associated decrypted message according to a set of comparison criterion(a).

2. Processing device (44) according to claim 1, wherein the decryption algorithm conforms to the Data Transport Layer Security (DTLS) protocol.

3. Processing device (44) according to any one of the preceding claims, wherein the set of comparison criteria includes a first comparison criterion depending on a size of the encrypted message and a size of the decrypted message.

4. Processing device (44) according to any one of the preceding claims, wherein the set of comparison criteria includes a second comparison criterion dependent on a time instant of reception of the encrypted message and a time instant of reception of the decrypted message.

5. Processing device (44) according to claim 4, wherein the second comparison criterion is that a time gap between the time of receipt of the encrypted message and the time of receipt of the decrypted message is less than a predefined duration.

6. A processing device (44) according to any one of the preceding claims, wherein the verification module (54) is configured to compare the encrypted message and the associated decrypted message according to the set of comparison criteria, in the absence of implementation of the decryption algorithm within the processing device (44).

7. Avionics computer (22) intended to be carried on board an aircraft (30) and comprising: - a decryption device (42) configured to receive an encrypted message and calculate an associated decrypted message via a decryption algorithm, - a processing device (44) configured to process the decrypted message, - a flow management device (40) configured to receive a data stream (21) and extract the encrypted message therefrom, then to transmit the encrypted message to both the processing device (44) and the decryption device (42), and characterized in that the processing device (44) is according to any one of the preceding claims.

8. Avionics computer (22) according to the preceding claim, wherein the processing device (44) is configured to command a restart of the decryption device (42) if the set of comparison criterion(a) is not met.

9. Avionics computer (22) according to claim 8, wherein the processing device (44) is configured to command an implementation of a new decryption device (42) if the set of comparison criteria is not met again following the restart of the decryption device (42).

10. Avionics computer (22) according to any one of claims 7 to 9, wherein the processing device (44) is configured to receive, during a first exchange, a verification data from a ground computer (20) through a secure communication channel (23) and to verify the establishment of such a first exchange via a state machine.

11. Communication infrastructure (10) comprising: - an avionics computer (22) intended to be carried on board an aircraft (30) and configured to receive and process a data stream (21), - a ground computer (20) intended to be installed on the ground and configured to generate and transmit the data stream (21) to the avionics computer (22), and characterized in that the avionics computer (22) is according to any one of claims 7 to 9.

12. A processing method implemented by an electronic processing device (44) and comprising the following steps: - reception (100) of an encrypted message, - reception (200) of an associated decrypted message, the the decrypted message having been calculated via a decryption algorithm applied to the encrypted message by a decryption device (42), external to the processing device (44), and - verification (300) of a behavior of the decryption device (42) via a comparison between the encrypted message and the associated decrypted message according to a set of comparison criterion(a).

13. A processing method according to the preceding claim, wherein said method further comprises, prior to the reception step (100), an initial unencrypted data exchange comprising: - generation of a private client key and a public client key by a ground computer (20), - generation of a private server key and a public server key by the decryption device (42), - transmission of an acknowledgment message from the ground computer (20) to the decryption device (42) via a secure communication channel (23) between the ground computer (20) and the decryption device (42), said acknowledgment message including at least one random client signature data, a list of supported encryption algorithms, the public client key and a list of supported cryptographic services, - reception of the recognition message by the decryption device (42), selection of an encryption algorithm and a cryptography service from the lists received, transmission of a second acknowledgment message from the decryption device (42) to the ground computer (20) via the communication channel (23), said second acknowledgment message including at least the selected encryption algorithm, the public server key and the selected cryptography service, calculation of a first verification data by the decryption device (42) from the public client key and the private server key, calculation of a second verification data by the ground computer (20) from the public server key and the private client key, establishment of an encrypted communication between the ground computer (20) and the avionics computer (22), said communication being authorized only if the first verification data is equal to the second verification data.

14. Computer program comprising software instructions which, when executed by a computer, implement a processing method according to claim 12 or 13.

Citation Information

Patent Citations

  • Handling of machine-to-machine secure sessions

    US20220353060A1