Usage data management process, associated electronic device and computer system

A method for managing usage data in avionics systems through secure transmission to a database addresses data management complexity and cybersecurity issues, ensuring efficient and compliant data access.

FR3167729A1Pending Publication Date: 2026-04-24THALES SA
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
THALES SA
Filing Date
2024-10-21
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

The increasing complexity in managing and securing usage data, particularly in avionics systems, due to new regulatory standards and cybersecurity threats, leads to inefficient data management and access issues, especially when anonymization reduces service performance and user access.

Method used

A method for managing usage data through a computer system with a server and electronic device, involving session opening, address association, and secure transmission of data to a database, ensuring confidentiality and compliance with regulatory standards.

Benefits of technology

The method provides simple, secure, and efficient data management, allowing users to access their usage data while maintaining confidentiality and adhering to regulatory requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Usage Data Management Method, Electronic Device, and Associated Computer System. The present invention relates to a usage data management method for a computer system comprising, on the one hand, a server equipped with a database and, on the other hand, an electronic device connected to said server, the database storing at least one address associated with a user of the electronic device; the method being implemented by the electronic device (14) and comprising the following steps: opening (S11) a session with said at least one address; associating (S12) with said at least one address usage data relating to the use of the electronic device by a user of the electronic device; and transmitting (S14) said usage data over a data link to at least one address to the database. Figure for the abstract: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method for managing usage data, associated electronic device and computer system

[0001] The present invention relates to a method for managing usage data, as well as an associated electronic device and computer system.

[0002] The widespread implementation of digital technology and computer services in everyday life generates a significant increase in the flow of data exchanged and stored by IT service providers.

[0003] Among this data, certain data referred to as "usage data" relate to the use of an electronic device by a user. Such data relates to or is associated with the user through the use of the electronic device, although it does not correspond to the user's personal data because the user is not necessarily identified on the electronic device. During a user session, the electronic device temporarily stores a certain amount of this usage data.

[0004] However, new regulatory standards now require that all or part of this usage data be retained for security purposes, or to facilitate its reuse in other functionalities or services, which may even be offered by third parties. This applies particularly when such an electronic device is intended to be installed on board an aircraft. The usage data thus stored must then be exchangeable and / or accessible by the user of the electronic device. In such a use case related to the field of avionics, the electronic device is typically a flight management system, specifically configured to define the aircraft's flight plan and to monitor its trajectory. The user of the electronic device is then a natural person (for example, an aircraft pilot) or a legal entity (for example, the company chartering or owning the aircraft).

[0005] Furthermore, the increasing storage of generic digital data, which may be personal and sensitive, raises the stakes for securing this data, in other words, cybersecurity, in order to ensure data confidentiality. Moreover, in order to protect data against attacks that are becoming increasingly complex and sophisticated over time, it is also necessary to implement sophisticated and robust security processes.

[0006] However, this often leads to increased complexity in data management processes, with complex confidentiality rules that may only apply to a portion of user data, and which may be These practices are subject to change. It is also known to anonymize data to prevent the identification of the users to whom the data belongs, thus limiting the risks in case of data loss or theft. However, the use of anonymized data reduces the performance of some digital services, and in particular, prevents a user from accessing their own data, since it is not possible to associate anonymized data with a specific user.

[0007] The aim of the invention is therefore to offer improved management of usage data, in particular from the point of view of its storage and confidentiality, and which is simple to implement and secure.

[0008] To this end, the invention relates to a method for managing usage data, for a computer system comprising on the one hand a server equipped with a database and on the other hand an electronic device connected to said server via a data link, the database storing at least one address associated with a user of the electronic device, the electronic device comprising a session opening module, a management module connected to the session opening module; and a transmission module connected to the management module and configured to transmit usage data over the data link;

[0009] the process being implemented by the electronic device and comprising the following steps: - opening, by the login module, of a session with said at least one address; - association to said address, by the management module, of usage data relating to the use of the electronic device by a user of the electronic device; and - transmission, by the transmission module, of said usage data over the data link to at least one address towards the database.

[0010] Thanks to the invention, usage data relating to the use of the electronic device by a user of that device is associated in the device with at least one address used for logging in, and then transmitted by the device to at least one address in the database when connectivity with the data link is established. Thus, the method according to the invention offers the user of the electronic device a simple and efficient service for storing and managing their usage data, preserving the confidentiality of the usage data (because the electronic device does not know the user but only the address) and / or allowing the reuse of usage data during a subsequent session (allowing, for example, simplified configuration during such a subsequent session). Such a service for storing and managing usage data is remote from the device. electronic, via the transmission of usage data to the database, which can then store the latter.

[0011] In addition, the method according to the invention offers improved security, via controlled access to the database storing usage data.

[0012] Finally, thanks to the process according to the invention, the user of the electronic device can securely access his usage data via the database, which makes it possible to comply with the new regulatory standards.

[0013] Usage data means any data generated, or whose generation is triggered, by an action of the user of an electronic device, through their use of the device. Such usage data originates from the user's activity and, more specifically, from their interaction with content on the electronic device. Examples of usage data include: personal or profile data (name, address, identifier, etc.); transaction data (payment method, date, amount, financial institution); data on areas of interest (favorite content, subscriptions); behavioral data (selection, search, viewing, purchase, sharing, etc.); data collected by mobile phones, computers, and connected objects (calls, activation, location); browsing data, etc.

[0014] A usage data management policy also refers to a set of rules for access, protection, or use / reuse that define authorized management of usage data. Such a usage data management policy is responsible for the governance of usage data.

[0015] According to other advantageous aspects of the invention, the method comprises one or more of the following features, taken individually or in all technically possible combinations:

[0016] - the data link is a point-to-point link, and the transmission step consists of an individual transmission of usage data to at least one address towards the database;

[0017] - during the transmission step, the transmission of usage data is carried out regularly to at least one address to the database;

[0018] - the process further includes a reuse step, by the electronic device, usage data stored in the database and relating to the use of the electronic device by said user;

[0019] - the session opening step includes a substep of adding one or several predefined parameter(s), and the step of reusing usage data stored in the database is carried out under condition(s), and if and only if said parameter(s) added during the session opening step satisfy said condition(s);

[0020] - the electronic device further includes an authentication module connected to the login module, and the process further includes a step of authentication of the user of the electronic device, said authentication step being implemented by the authentication module;

[0021] - the electronic device further comprises a smart card reader connected to the authentication module, and the user authentication step of the electronic device is performed by reading a smart card relating to the user, when the smart card is inserted into said smart card reader;

[0022] - said address associated with a user of the electronic device is an address rotating, encrypted using an encryption key;

[0023] - during the step of transmitting usage data over the data link to the minus an address to the database, a time countdown is performed by the electronic device in relation to a predefined duration, and, if said address is not reached in the database at the end of said predefined duration, the process further includes a step of erasure, by the electronic device, of said usage data;

[0024] - The management module is configured to store a data management policy of use, said usage data management policy containing said at least one address, and the login step is performed with the usage data management policy containing said at least one address;

[0025] - the usage data management policy contains several addresses for a same user of the electronic device;

[0026] - said usage data management policy further contains at least one electronic certificate associated with the user of the electronic device, the electronic device further includes a verification module configured to verify the validity of an electronic certificate, said verification module being connected to the management module and the transmission module, and the process further includes a verification step, by said verification module, of the validity of said at least one electronic certificate associated with the user of the electronic device, the data transmission step being carried out if and only if said at least one electronic certificate is valid; and

[0027] - the usage data management policy is encrypted.

[0028] The invention also relates to an electronic device capable of being connected to a server via a data link, the electronic device comprising: - a login module; - a management module connected to the login module; and - a transmission module connected to the management module and configured to transmit usage data over the data link, the device electronic being configured to implement the process as defined above.

[0029] The invention also relates to a computer system comprising on the one hand a server equipped with a database and on the other hand an electronic device as defined above, the electronic device being connected to said server via a data link, the database storing said at least one address which is associated with a user of the electronic device.

[0030] According to other advantageous aspects of the invention, the computer system comprises one or more of the following features, taken individually or in all technically possible combinations:

[0031] - the electronic device is configured to be carried on board an aircraft, and the The server is configured to be external to the aircraft;

[0032] - The management module is configured to store a data management policy of use, the said usage data management policy containing at least one address, the user of the electronic device is a pilot of the aircraft, and the usage data management policy is a policy specific to a particular pilot of the aircraft, or alternatively a policy common to all pilots of the company that charters or owns the aircraft.

[0033] The invention will become clearer upon reading the following description, given solely by way of non-limiting example, and made with reference to the drawings in which:

[0034] [Fig-1] [Fig.1] is a diagram of a computer assembly according to the invention;

[0035] [Fig.2] [Fig.2] is a general flowchart of a process according to the invention; and

[0036] [Fig.3] [Fig.3] is a flowchart showing a detailed part of the process according to the invention.

[0037] Figure 1 represents a computer system 10 comprising a server 12 and an electronic device 14, the latter being connected to the server 12 via a data link 16. The data link 16 is conventionally a wireless data link. Advantageously, the data link 16 is a point-to-point link.

[0038] The server 12 stores a database 18. The database 18 stores at least one address A1, A2, A3 associated with a user of the electronic device 14. In the example in [Fig. 1], the database 18 stores three addresses A1, A2, A3, each address A1, A2, A3 being associated with a distinct user of the electronic device 14. When the electronic device 14 is intended to be carried in an aircraft 40, as will be described later, the users of the electronic device 14 are typically pilots of the aircraft 40. In an alternative not shown, several addresses stored within the database 18 may be associated with the same user of the electronic device 14. Addresses A1, A2, A3 are logical addresses.

[0039] Database 18 is a logical database. Advantageously, such a logical database is stored on a dedicated physical medium within server 12. Alternatively or in addition, database 18 is, for example, hosted in one or more Internet "cloud" servers.

[0040] The electronic device 14 comprises a logon module 20, a management module 22 connected to the logon module 20, and a transmission module 24 connected to the management module 22. Advantageously, as illustrated in [Fig. 1], the electronic device 14 also comprises an authentication module 26 connected to the logon module 20, a smart card reader 28 connected to the authentication module 26, and a verification module 30 connected to the management module 22 and the transmission module 24. Advantageously, the electronic device 14 is associated with a unique identifier.

[0041] The session opening module 20 is capable of opening a session on the electronic device 14. Advantageously, the session opening module 20 is configured to add one or more predefined parameter(s) when opening a session on the electronic device 14, such parameters being for example a maximum retention period for usage data, whether or not to allow subsequent reuse of usage data, whether or not to anonymize usage data, etc.

[0042] In the particular embodiment illustrated in [Fig. 1], the management module 22 is advantageously configured to store a usage data management policy 32. The usage data management policy 32 contains at least one address. In the example in [Fig. 1], the usage data management policy 32 contains the three addresses A1, A2, and A3. In an alternative not shown, the usage data management policy 32 contains several addresses for the same user of the electronic device 14. These different addresses then advantageously allow for data structuring within the database 18. The usage data can thus be structured according to several addresses, for example, one address per data category (packets), or one address per country.Data management policy 32 advantageously contains other data, such as, for example, a maximum retention period for usage data, whether or not subsequent reuse of usage data is permitted, whether or not usage data is anonymized, etc. Advantageously, data management policy 32 is encrypted. Advantageously still, data management policy 32 also contains at least one electronic certificate (not shown on the . figures for clarity), such an electronic certificate being associated with a user of the electronic device 14.

[0043] The transmission module 24 is configured to transmit usage data over the data link 16.

[0044] The verification module 30 is configured to verify the validity of an electronic certificate.

[0045] In the example of [Fig.1], the electronic device 14 includes an information processing unit 45 formed for example of a memory 46 and a processor 48 associated with the memory 46.

[0046] The memory 46 of the electronic device 14 is then capable of storing a login program, a management program, a transmission program, and optionally, an authentication program and a verification program. The processor 48 is then capable of executing each of the following programs: the login program, the management program, the transmission program, and optionally, the authentication program and the verification program.

[0047] When the session opening module 20, management module 22, and transmission module 24, as well as the optional authentication module 26 and verification module 30, are implemented as one or more software programs, i.e., as a computer program, also called a computer program product, they are also capable of being stored on a computer-readable medium, not shown, or possibly on multiple media. A computer-readable medium is, for example, a medium capable of storing electronic instructions and being connected to a bus of a computer system. For example, a readable medium is an optical disc, a magneto-optical disc, a ROM, a RAM, any type of non-volatile memory (e.g., FLASH or NVRAM), or a magnetic card. A computer program comprising software instructions is then stored on the readable medium.

[0048] Alternatively, the session opening module 20, the management module 22 and the transmission module 24, as well as optionally the authentication module 26 and the verification module 30, are each implemented as a programmable logic component, such as an FPGA (Field Programmable Gate Array) or an integrated circuit, such as an ASIC (Application Specified Integrated Circuit).

[0049] According to an example illustrated in [Fig. 1], the electronic device 14 is configured to be carried on board an aircraft 40. In particular, the electronic device 14 is, for example, integrated into the electronic systems carried on board the aircraft 40. The server 12 is then typically configured to be external to the aircraft 40, and is located, for example, on the ground. According to a particular embodiment, the Electronic device 14 is a Flight Management System (FMS), specifically configured to define the flight plan of an aircraft 40 and to monitor its trajectory. As illustrated in [Fig. 1], the user of electronic device 14 is either a natural person (e.g., a pilot of the aircraft) or a legal entity (e.g., the company chartering or owning the aircraft). Usage data management policy 32 is then, for example, a policy specific to a particular pilot of aircraft 40. This allows for a structured approach to usage data by pilot within database 18. Alternatively, usage data management policy 32 is a policy common to all pilots of the company chartering or owning aircraft 40. This allows that company to have direct access to all its usage data in database 18.

[0050] According to another example, the computer system 10 assists medical personnel in the medical monitoring and / or diagnosis of patients. The electronic device 14 is, for example, located in a hospital or clinic, and the server 12 is, for example, installed in a dedicated room, remote from the hospital. In particular, the electronic device 14 is, for example, integrated into a medical device, typically a radiological device. The user of the electronic device 14 is then a natural person, typically a patient.

[0051] According to another example, the electronic device 14 is configured to be carried on a drone. In particular, the electronic device 14 is, for example, integrated into the electronic systems on board the drone. The server 12 is then typically configured to be external to the drone and is located, for example, on the ground. The user of the electronic device 14 is then a natural person, typically a drone pilot.

[0052] A method for managing usage data is now described with reference to Figures 2 and 3. The method is implemented by the electronic device 14.

[0053] When the electronic device 14 includes an authentication module 26, the method advantageously includes an initial step S10 of authenticating a user of the electronic device 14, implemented by this module 26. The authentication of the user of the electronic device 14 is, for example, performed by reading a smart card (not shown) relating to the user, when the smart card is inserted into the smart card reader 28. According to a particular embodiment, the smart card stores a usage data management policy that contains at least one address.

[0054] The method includes a subsequent step SI 1 of opening a session, by the session opening module 20. During this step SI 1, the session is opened on the electronic device 14, with at least one of the addresses A1, A2, A3. According to In one particular embodiment, the session is opened on the electronic device 14 with the usage data management policy stored in the user's smart card, which contains at least one address A1, A2, A3. Alternatively, the session is opened on the electronic device 14 with at least one of the addresses A1, A2, A3 entered (manually or via the use of a QR code, for example) by the user on the electronic device 14. Alternatively, when the management module 22 stores the usage data management policy 32, the session is opened on the electronic device 14, during the opening step SI 1, with the usage data management policy 32 containing the addresses A1, A2, A3. Advantageously, as illustrated in [Fig. 3], the session opening step SU includes a substep SI 12 for adding one or more predefined parameter(s).The predefined parameter(s) include, for example, specific data formatting or a mask applied to certain data. This could, for instance, correspond to a restrictive agreement on data usage stipulated in a contract with the company or according to local law.

[0055] Following the opening of the session, the management module 22 associates usage data relating to the use of the electronic device 14 by the user of the electronic device 14 with at least one of the addresses A1, A2, A3, during an association step S12. To do this, in the particular embodiment illustrated in [Fig. 1], the management module 22 retrieves the address(es) in question A1, A2, A3 from the usage data management policy 32. In the example of [Fig. 1], the management module 22 retrieves a single address A1, A2, A3 from the usage data management policy 32 in order to associate it with the usage data of a particular user of the electronic device 14. According to a particular embodiment, the address in question A1, A2, A3 is a rotating address, encrypted using an encryption key.

[0056] Once the association is made between the usage data and at least one of the addresses A1, A2, A3, the transmission module 24 transmits this usage data over the data link 16 to at least one address A1, A2, A3 to the database 18, during a transmission step S14. Advantageously, this transmission step S14 consists of an individual transmission of the usage data to at least one address A1, A2, A3 to the database 18, over a point-to-point data link 16. Advantageously still, this transmission of the usage data is carried out regularly to at least one address A1, A2, A3 to the database 18.When connectivity with server 12 is not operational on data link 16, the transmission module 24 is able to retain usage data for a time period necessary for the re-establishment of the connection with server 12, and then transmit the usage data on the data link. 16, to at least one address A1, A2, A3 in the database. According to a particular embodiment, during this transmission step 14, a time countdown is performed by the electronic device 14 against a predefined duration. At the end of the predefined duration, if the address(es) in question A1, A2, A3 is / are not reached in the database 18, the process further includes a deletion step S16, by the electronic device 14, of the usage data that was to be transmitted.

[0057] If the transmission of usage data has been successfully carried out to database 18 during the transmission step S14, the user of the electronic device 14 can then subsequently access his usage data, via a query made to database 18. Advantageously, the user of the electronic device 14 can only access his usage data if he first provides database 18 with identification keys (typically public / private encryption keys) used for example for the encryption of the rotating address A1, A2, A3 used to associate his usage data.

[0058] When the usage data management policy 32 contains at least one electronic certificate associated with a user of the electronic device 14, and the electronic device 14 includes a verification module 30, the process further includes an intermediate step S13 of verification, by the verification module 30, of the validity of this electronic certificate. This verification step S13 is performed before the transmission step S14, and the transmission step S14 is then performed if and only if the electronic certificate is valid.

[0059] Advantageously, the method includes a final step S18 of reusing, by the electronic device 14, the usage data stored in the database 18 and relating to the user's use of the electronic device 14. This then allows, in particular, simplified configuration (pre-configuration) when a subsequent session is opened on the electronic device 14 by the session opening module 20.

[0060] It is thus understood that the process according to the invention allows for improved management of usage data, in particular from the point of view of its storage and confidentiality, which is simple to implement and secure, and also allows a user of the electronic device to securely access his usage data, which makes it possible to comply with the new regulatory standards.

Claims

Demands

1. A method for managing usage data, for a computer system (10) comprising on the one hand a server (12) equipped with a database (18) and on the other hand an electronic device (14) connected to said server (12) via a data link (16), the database (18) storing at least one address (A1, A2, A3) associated with a user of the electronic device (14), the electronic device (14) comprising a logon module (20), a management module (22) connected to the logon module (20); and a transmission module (24) connected to the management module (22) and configured to transmit usage data over the data link (16); the process being implemented by the electronic device (14) and characterized in that it comprises the following steps: - opening (SI 1), by the session opening module (20), of a session with said at least one address (A1, A2, A3);- association (S12) to said at least one address (A1, A2, A3), by the management module (22), of usage data relating to the use of the electronic device (14) by a user of the electronic device (14); and - transmission (S14), by the transmission module (24), of said usage data over the data link (16) to at least one address (A1, A2, A3) to the database (18).

2. A method according to claim 1, wherein the data link (16) is a point-to-point link, and the transmission step (S 14) consists of an individual transmission of the usage data to at least one address (A1, A2, A3) to the database (18).

3. A method according to claim 1 or 2, wherein, during the transmission step (S 14), the transmission of usage data is carried out regularly to at least one address (A1, A2, A3) to the database (18).

4. A method according to any one of the preceding claims, wherein the method further comprises a step (S 18) of reusing, by the electronic device (14), the usage data stored in the database (18) and relating to the use of the electronic device (14) by said user.

5. A method according to claim 4, wherein the session opening step (SU) includes a substep (SI 12) of adding one or more predefined parameter(s), and the step (S 18) of reusing usage data stored in the database (18) is carried out under condition(s), and if and only if said parameter(s) added during the session opening step (SU) satisfy said condition(s).

6. A method according to any one of the preceding claims, wherein the electronic device (14) further comprises an authentication module (26) connected to the session opening module (20), and the method further comprises a step (S 10) for authenticating the user of the electronic device (14), said authentication step (S 10) being implemented by the authentication module (26).

7. A method according to claim 6, wherein the electronic device (14) further comprises a smart card reader (28) connected to the authentication module (26), and the step (S10) of authenticating the user of the electronic device (14) is carried out by reading a smart card relating to the user, when the smart card is inserted into said smart card reader (28).

8. A method according to any one of the preceding claims, wherein said address (A1, A2, A3) associated with a user of the electronic device (14) is a rotating address, encrypted using an encryption key.

9. A method according to any one of the preceding claims, wherein, during the step (S 14) of transmitting usage data over the data link (16) to at least one address (A1, A2, A3) to the database (18), a time countdown is performed by the electronic device (14) against a predefined time, and, if said address (A1, A2, A3) is not reached in the database (18) at the end of said predefined time, the method further comprises a step of erasure (S16), by the electronic device (14), of said usage data.

10. A method according to the preceding claim, wherein the management module (22) is configured to store a management policy (32) of usage data, said usage data management policy (32) containing said at least one address (A1, A2, A3), and in which the session opening step (SU) is performed with the usage data management policy (32) containing said at least one address (A1, A2, A3).

11. Method according to the preceding claim, wherein the usage data management policy (32) contains several addresses for the same user of the electronic device (14).

12. A method according to claim 10 or 11, wherein said usage data management policy (32) further contains at least one electronic certificate associated with the user of the electronic device (14), wherein the electronic device (14) further comprises a verification module (30) configured to verify the validity of an electronic certificate, said verification module (30) being connected to the management module (22) and the transmission module (24), and wherein the method further comprises a step (S 13) of verification, by said verification module (30), of the validity of said at least one electronic certificate associated with the user of the electronic device (14), the step (S 14) of transmitting usage data being carried out if and only if said at least one electronic certificate is valid.

13. Electronic device (14) capable of being connected to a server (12) via a data link (16), the electronic device (14) comprising: - a session opening module (20); - a management module (22) connected to the session opening module (20); and - a transmission module (24) connected to the management module (22) and configured to transmit usage data over the data link (16), the electronic device (14) being configured to implement the method according to any one of the preceding claims.

14. A computer system (10) comprising, on the one hand, a server (12) equipped with a database (18) and, on the other hand, an electronic device (14) according to the preceding claim, the electronic device (14) being connected to said server (12) via a data link (16), the database (18) storing said at least one address (A1, A2, A3) which is associated with a user of the electronic device (14).

15. Computer assembly (10) according to the preceding claim, wherein the electronic device (14) is configured to be embedded in an aircraft (40), and the server (12) is configured to be external to the aircraft (40).

16. Computer assembly (10) according to the preceding claim, wherein the management module (22) is configured to store a usage data management policy (32), said usage data management policy (32) containing at least one address (A1, A2, A3), wherein the user of the electronic device (14) is a pilot of the aircraft (40), and wherein the usage data management policy (32) is a policy specific to a particular pilot of the aircraft (40), or alternatively a policy common to all pilots of the company that charters or owns the aircraft (40).

Citation Information

Patent Citations

  • User behavior analysis system and method, storage medium and computing equipment

    CN117149597A

  • Distinguishing user-initiated activity from application-initiated activity

    US20230254330A1

  • System and method for monitoring user interaction with web pages

    US7523191B1