Data confidentiality management process, IT system, and associated infrastructure
A computer system with segregated servers and uniform confidentiality rules simplifies data management by ensuring authorized access and easy rule updates, addressing inefficiencies in complex privacy processes.
Patent Information
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- THALES SA
- Filing Date
- 2024-10-21
- Publication Date
- 2026-04-24
AI Technical Summary
The increasing complexity of data privacy management processes due to multiple and changing confidentiality rules, coupled with the need for robust cybersecurity, leads to inefficiencies and reduced performance in digital services, particularly when anonymizing data prevents user access.
A computer system with segregated servers, each equipped with a processing module, verification module, and management module, applies uniform confidentiality rules to stored data, simplifying authorization and execution of requests while allowing easy rule updates.
Simplifies data confidentiality management by ensuring all data adhere to a single set of rules, facilitating authorized access and easy rule modifications, thereby maintaining security and performance.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Data confidentiality management method, computer system, and associated infrastructure
[0001] The present invention relates to a method for managing data confidentiality, as well as an associated computer system and infrastructure.
[0002] The widespread implementation of digital technology and computer services in everyday life generates a significant increase in the flow of data exchanged and stored by IT service providers.
[0003] The increasing storage of data, which may be personal and sensitive, raises the stakes for securing this data, in other words, cybersecurity, in order to ensure data confidentiality. Furthermore, in order to protect data against attacks that are becoming increasingly complex and sophisticated over time, it is also necessary to implement sophisticated and robust security processes.
[0004] However, this often leads to increased complexity in data privacy management processes, with multiple, complex privacy rules that may apply only to a portion of user data and may be subject to change. Anonymizing data is also known to prevent the identification of the users to whom the data belongs, thereby limiting the risks in case of data loss or theft. However, the use of anonymized data reduces the performance of certain digital services, and in particular, prevents a user from accessing their own data, since it is not possible to associate anonymized data with a specific user.
[0005] The aim of the invention is therefore to offer an improved data confidentiality management system that is simple to implement and secure.
[0006] To this end, the invention relates to a method for managing data confidentiality, for a computer system comprising a plurality of servers, each server comprising a processing module having a memory configured to store data; a verification module configured to store a set of confidentiality rules; and a management module, connected to the verification module belonging to the same server as the management module, and configured to be connected to a client electronic device;
[0007] the process being implemented by the computer system.
[0008] According to the invention, the process comprises the following steps: - reception, by the management module of each server, of a request from the client electronic device; - each server checks that the received request is authorized; and - If the request is authorized by a respective server, the request will be executed. by said server.
[0009] Thanks to the invention, each server determines whether the request it receives is authorized or not. This simplifies the management of confidentiality rules, since all data stored in the processing module of said server is subject to the same set of confidentiality rules stored in the server's verification module. For example, a server corresponds to a specific level of confidentiality, associated with a specific security level and therefore with a specific set of confidentiality rules. Furthermore, this avoids the need to generate requests based on the server in question, which also facilitates queries across all available data while respecting confidentiality: only authorized requests, and therefore those that comply with the confidentiality rules, can be executed and access the data.
[0010] Moreover, it is easy to modify the set of privacy rules to ensure that data confidentiality is maintained over time, without changing the data or its storage method.
[0011] According to other advantageous aspects of the invention, the method comprises one or more of the following features, taken individually or in all technically possible combinations: - The query includes a plurality of attributes, and the control step includes the following sub-steps: - verification by the verification module of each server, that each attribute of the request conforms to the set of confidentiality rules stored in the verification module; - if each attribute of the request conforms to said set of confidentiality rules, determination by the respective server's verification module that the request is authorized; and - if the request is authorized, an authorization is recorded in the verification module of said server. - Each processing module is configured to process requests transmitted by the verification module belonging to the same server, and the execution step includes the following sub-steps: - transmission of the request by the verification module of the respective server to the processing module belonging to said server; and - processing of the request by the processing module of said server. - The control stage also includes the following sub-stages: - if the request is pre-authorized by the verification module of a respective server, determination by the management module of said server that the request is authorized and recording of an authorization in the management module,
[0012] and in which the sub-steps of verification, determination by the verification module that the request is authorized and recording of the authorization in the verification module of said server are carried out if the request is not pre-authorized by the verification module of said server. - Each processing module is configured to process requests transmitted by the management module belonging to the same server,
[0013] and in which, if the request is pre-authorized, the execution step further includes the following sub-step: - transmission of the request by the respective server's management module to the processing module belonging to said server,
[0014] the processing step being carried out following the step of transmitting the request by the management module of said server. - The computer system also includes a replication system configured to store predefined data,
[0015] the execution step further comprising the following sub-steps: - if each server determines that the request is not authorized, the request is received by the replication system; and - processing of the request by the replication system based on predefined data.
[0016] The invention also relates to a computer system comprising a plurality of servers, each server comprising: - a processing module, including a memory configured to store data; - a verification module configured to store a set of privacy rules; and - a management module, connected to the verification module belonging to the same server as the management module, the management module being configured to be connected to a client electronic device,
[0017] the computer system being configured to implement the process.
[0018] According to other advantageous aspects of the invention, the computer system comprises one or more of the following features, taken individually or in all technically possible combinations: - the set of privacy rules stored in each verification module is distinct from one server to another; - The management modules of each server are configured to implement identical processes from one management module to another so that the management modules operate with performance greater than or equal to a minimum performance level.
[0019] the minimum performance being preferably identical for all management modules. - The computer system also includes a replication system, configured to replicate the operation of the management modules.
[0020] The invention also relates to an infrastructure comprising a client electronic device, and a computer system, the client electronic device being connected to each management module.
[0021] According to another advantageous aspect of the invention, the infrastructure is configured to be embedded in an aircraft, and the computer system is configured to be external to the aircraft.
[0022] The invention will become clearer upon reading the following description, given solely by way of non-limiting example, and made with reference to the drawings in which:
[0023] [Fig-1] [Fig.1] is a diagram of an infrastructure according to the invention;
[0024] [Fig.2] [Fig.2] is a general flowchart of a process according to the invention;
[0025] [Fig.3] [Fig.3] is a flowchart showing a first detailed part of the method according to the invention; and
[0026] [Fig.4] [Fig.4] is a flowchart showing a second detailed part of the process according to the invention.
[0027] Fig. 1 represents an infrastructure 10 comprising a client electronic device 12 and a computer system 14, connected to the client electronic device 12.
[0028] The electronic client device 12 is also called the client service. The electronic client device 12 is, for example, implemented as one or more software programs, i.e., as a computer program, also called a computer program product. In this case, the electronic client device 12 is also capable of being stored on a computer-readable medium (not shown). The computer-readable medium is, for example, a medium capable of storing electronic instructions and being connected to a bus of a computer system. By way of example, the readable medium is an optical disc, a magneto-optical disc, ROM, RAM, any type of non-volatile memory (e.g., FLASH or NVRAM), or a magnetic card. A computer program comprising software instructions is then stored on the readable medium.
[0029] The electronic client device 12 is advantageously configured to communicate with external terminals, which are for example electronic devices belonging to users.
[0030] The computer system 14 comprises a plurality of interconnected servers 20. Advantageously, they form a cloud. In the example in [Fig. 1], four servers 20 are shown. Alternatively, the computer system 14 comprises more than four servers 20, as represented by the dotted lines between two of the four servers 20. Alternatively still, the computer system 14 comprises fewer than four servers 20.
[0031] Each server 20 comprises a processing module 22, a verification module 24, and a management module 26, each management module 26 being connected to the verification module 24 belonging to the same server 20. Each management module 26 is configured to be connected to the client electronic device 12, this connection being potentially intermittent.
[0032] The processing module 22 includes a memory 28, configured for storing data. Advantageously, the processing module 22 further includes data processing means, for example, computing means.
[0033] Advantageously, the processing modules 22 of each server 20 are configured so that a structure of the data stored in each processing module 22 is similar.
[0034] The data are, for example, images and / or data measured by sensors. The images are, for example, medical images or photographs taken by users. The sensor data are, for example, data measured by connected sensors located in homes, or physiological data of users, such as heart rate or body temperature.
[0035] The verification module 24 is also called the compliance manager. The verification module 24 is configured to store a set of confidentiality rules. For this purpose, the verification module 24 includes, for example, a memory, not shown.
[0036] The confidentiality rules set comprises a set of rules that define an authorized use of the data. For example, the rules relate to the type of use, for example use for technical or security purposes, the encryption methods used to transmit the data, the location of the use, etc.
[0037] Advantageously, each set of privacy rules is distinct from one server 20 to another. For example, each set of privacy rules corresponds to a degree of User data confidentiality. Thus, each server 20 is associated with a set of confidentiality rules, and therefore with a specific level of security.
[0038] In cases where the data is medical data, such as data relating to medical examinations, medical imaging images are secured to ensure a high degree of confidentiality, while data relating, for example, to physical activity, which the user chooses to share publicly, is secured to ensure a lower degree of confidentiality than for medical imaging images. The confidentiality rules are advantageously predefined, for example by an infrastructure developer 10, according to the type of data to be stored in the processing modules 22 and the desired degree of confidentiality for the data.
[0039] The verification module 24 is advantageously configured to communicate with the processing module 22 and with the management module 26, i.e. configured to exchange information directly with the processing module 22 and with the management module 26. Alternatively, the verification module 24 is configured to communicate only with the management module 26.
[0040] The management module 26 is also called the interface manager, or "interface manager" in English.
[0041] The verification module 24 and the management module 26 are, for example, each implemented in the form of software, executable by one or more processors of the server 12.
[0042] When the verification modules 24 and management modules 26 are implemented as one or more software programs, i.e., as a computer program, also called a computer program product, they are also capable of being stored on a computer-readable medium, not shown, or possibly on multiple media. A computer-readable medium is, for example, a medium capable of storing electronic instructions and being connected to a bus of a computer system. For example, a readable medium is an optical disc, a magneto-optical disc, ROM, RAM, any type of non-volatile memory (e.g., FLASH or NVRAM), or a magnetic card. A computer program comprising software instructions is then stored on the readable medium.
[0043] Alternatively, the verification module 24 and the management module 26 are each implemented as a programmable logic component, such as an FPGA (Field Programmable Gate Array) or an integrated circuit, such as an ASIC (Application Specified Integrated Circuit).
[0044] Each management module 26 is advantageously configured to implement processes identical to those of the other management modules 26, in order to function identically to the other management modules 26, or in order to function with a similar performance for all management modules 26. Performance is for example a service rate, or a quality of service, also noted QoS (from the English Quality of Service).
[0045] The servers 20 are not connected to each other, and in particular, the management modules 26 of different servers 20 are not connected to each other. The same applies to the processing modules 22 and the verification modules 24. In other words, the servers 20 are segregated from each other.
[0046] Advantageously, the computer system 14 further comprises a replication system 30, also called an "interface cloning system." The replication system 30 advantageously includes a memory 32 configured to store predefined data. The predefined data are, for example, generic data that has been created without actually belonging to any users. Alternatively, or in addition, the predefined data are anonymized data that cannot be associated with any specific user.
[0047] Alternatively or in addition, memory 32 is configured to store computer models, for example pre-trained machine learning models, which allow user data to be anonymized. In this case, the user data are input variables for the model, and the anonymized data are output variables for the model.
[0048] Advantageously, the replication system 30 further includes a replication module 34, the operation of which will be explained in more detail later in the description.
[0049] Infrastructure 10 is configured to be distributed among several different locations, in other words, infrastructure 10 is decentralized.
[0050] For example, the client electronic device 12 is configured to be as close as possible to the infrastructure users. The client electronic device 12 is, for example, connected at the network edge. The computer system 14 is remote from the client electronic device 12 and is, for example, distributed across different geographical locations.
[0051] According to one example, infrastructure 10 allows for the generation of recommendations to passengers in an aircraft 40, for example, a civil aircraft. Alternatively, infrastructure 10 allows for the personalization of a display for passengers, in order to improve their comfort, for example, by customizing a graphical interface according to their habits. In the first two cases, the users are the aircraft passengers. Alternatively, infrastructure 10 allows for the issuance of an alert to aircraft personnel, who are then the users of infrastructure 10, for example, regarding potential health risks or allergies present among passengers, in order to improve passenger safety during the flight.
[0052] The customer electronic device 12 is then configured to be on board the aircraft 40. In particular, the customer electronic device 12 is for example integrated into the electronic systems on board the aircraft 40. The computer system 14 is typically configured to be external to the aircraft 40, and is located for example on the ground, or possibly distributed between several geographical areas, for example several countries or continents.
[0053] Alternatively, the servers 20 of the computer system are external to the aircraft 40, distributed across several geographical areas, and together form a cloud, and the replication system 30 is connected at the network edge. In this case, the replication system 30 is also installed on board the aircraft 40.
[0054] According to another example, the infrastructure 10 assists medical personnel in the medical monitoring and / or diagnosis of patients. The client electronic device 12 is, for example, located in a hospital or clinic, and the computer system 14 is, for example, distributed across several geographical areas, remote from the hospital. The sets of confidentiality rules, for example, prevent the theft or corruption of users' personal data and ensure optimized medical monitoring by limiting diagnostic errors related to incomplete or corrupted data.
[0055] A data confidentiality management method is now described with reference to Figures 2 to 4. The method is implemented by the computer system 14. The method includes a reception step S10, by the management module 26 of each server 20, of a request from the client electronic device 12. The request received by each management module 26 is identical for all management modules 26. The request includes a plurality of attributes, which correspond to the characteristics of the request, for example the sender of the request, their nationality, the type of data use that is intended by the request, the duration of data use, etc.
[0056] The query is a read query, that is to say an access to the data, without modifying it; or a write query, that is to say a modification of the data, for example an addition, a deletion, or a modification of the data.
[0057] According to examples, requests are issued by the client electronic device 12 following a request from a user via a personal electronic device, such as a tablet or computer. Alternatively, requests are issued by the client electronic device 12 without resulting from a user request. In this case, the requests allow, for example, the organization and / or optimization of data.
[0058] Following receipt of the request, each server 20 checks that the received request is authorized during an S20 control step.
[0059] Advantageously, the control step S20 comprises substeps S202 to S210.
[0060] When each of the management modules 26 receives a request, each management module 26 determines whether the request is pre-authorized. To do this, each management module 26 compares the request to one or more pre-authorizations stored by the management modules 26. A pre-authorization includes, for example, a number of conditions that must be met for a request to be considered pre-authorized by the management module 26. An example of a pre-authorization is: all requests originating from a specific user are pre-authorized.
[0061] Pre-authorizations are predefined, for example, by a developer of infrastructure 10.
[0062] If the management module 26 of a server 20 determines that the request is pre-authorized, the management module 26 of said server 20 then determines during the authorization substep S202 that the request is authorized and records an authorization in the management module 26 during a registration substep S204.
[0063] If the management module 26 determines that the request is not pre-authorized, for example if the request does not fulfill one of the conditions included in the pre-authorization, then the verification module 24 belonging to said server 20 checks during a verification step S205 that each attribute of the request complies with the set of confidentiality rules stored in the verification module 24. In other words, during the verification step S205, the verification module 24 checks that each attribute of the request fulfills the conditions defined by the set of confidentiality rules.
[0064] If each attribute of the request conforms to the set of confidentiality rules, then the verification module 24 belonging to said server 20 determines that the request is authorized during an S206 step and records an authorization in the verification module 24 during an S208 registration step.
[0065] The permissions stored in the management module 26 at substep S202 and in the verification module 24 at substep S208 allow for tracking the authorization of the request. Advantageously, the permissions include the request attributes and a timestamp, in order to record the date and time of the authorizations, as well as a key from the verification module 24. The recorded permissions are also called leases.
[0066] Since each server 20 has a set of confidentiality rules that, advantageously, is unique to it, that is to say, specific, for example, the same request will be allowed by some servers 20 and not allowed by others. In other words, according to this advantageous aspect, each set of confidentiality rules is specific to the respective server 20 in which said set is stored.
[0067] If the request is authorized by the verification module 24 of one of the servers 20, an execution step S30 is carried out by the server 20.
[0068] The execution step S30 advantageously comprises substeps S301 to S308.
[0069] Substep S301 is a substep for transmitting the S301 request. It is performed following substeps S202 and S204, that is, if the request has been pre-authorized. During substep S301, the management module 26 transmits the request from the server 20 that authorized the request to the processing module 22 belonging to said server 20.
[0070] In the event that the request has not been pre-authorized, a transmission substep S302 is performed following substeps S206 and S208. During the transmission substep S302, the request is transmitted by the verification module 24 of the server 20 that authorized the request to the processing module 22 belonging to said server 20.
[0071] Advantageously, the execution step S30 further includes a request processing substep S304. The processing substep S304 is performed by the processing module 22 after the request has been transmitted during one of the transmission substeps S301 or S302. If the request is a write request, during the processing substep S304, the data stored in the memory 28 of the processing module 22 is modified and / or new data is added to memory 28. If the request is a read request, during the processing substep S304, data is read and / or aggregated or processed by the processing module 22 to form a response to the request. The response is then sent to the management module 26, which transmits it to the client electronic device 12.
[0072] Alternatively, in particular where it is the verification module 24 which transmitted the request during the S302 step, the response is sent to the verification module 24 which transmits it to the electronic client device 12, either directly or via the management module 26.
[0073] If one of the attributes of the request does not conform to the set of confidentiality rules, then the verification module 24 determines that the request is not allowed during an S210 step.
[0074] Optionally, if the request is not authorized, the management module 26 sends a disauthorization message to the client electronic device 12 to indicate to the client electronic device 12 that the request is not authorized by the server 20.
[0075] According to one example, the request is not allowed by any of the servers 20.
[0076] Advantageously, if the request is not authorized by any of the servers 20, the replication system 30 sends a no-response message to the client device 12 after a waiting period has elapsed. This automatic sending of a no-response message to the client device 12 after this waiting period, which acts as a timeout, prevents the client device 12 from waiting indefinitely for a response.
[0077] Following the receipt of the no response message by the client device 12, if the request is a read request, then the execution step S30 is carried out, in particular, the request is received by the replication system 30 during a reception substep S306, as seen in [Fig.4].
[0078] Alternatively, if during the waiting period the client electronic device 12 does not receive any response from the servers 20, or receives only non-authorization messages during the waiting period, and the request is a read request, then the request is received by the replication system 30 during the reception substep S306, without it being necessary for the client electronic device 12 to receive the no response message.
[0079] Once the request is received by the replication system 30 during the reception substep S306, the replication system 30 generates a response to the request from the predefined data stored in the memory 32 of the replication system 30 during a processing substep S308, also called the degraded processing substep.
[0080] The degraded processing substep S308 allows a response to be formed from data whose use is not subject to special confidentiality rules.
[0081] Thus, the replication system 30 is configured to operate similarly to a server 20, in order to process the request when none of the servers 20 do so.
[0082] However, the response formed during the degraded processing substep S308 is generally less relevant, or less accurate than a response obtained from data stored in the servers 20, because the predefined data is generic and / or anonymized data.
[0083] The waiting time is advantageously measured from the moment the request is received by the servers 20. In other words, the timeout is triggered from the moment the request is received by the servers 20.
[0084] Alternatively, the lack of response is due to a connection problem between the client electronic device 12 and the servers 20.
[0085] In the case where the replication system 30 is connected at the network edge, the connection between the replication system 30 and the client electronic device 12 is faster and more reliable than that between the servers 20 and the client electronic device 12. Thus, the degraded processing substep S306 is executed more reliably than the processing substep S304, and compensates for a possible connection problem between the client electronic device 12 and the servers 20.
[0086] Advantageously, the replication system 30, more specifically the replication module 34, replicates the operation of the management modules 26. For this purpose, for example, the replication module 34 synchronizes the updates of the modules The management module performs tests on the 26 management modules to verify that their operation achieves a performance level greater than or equal to a minimum performance level, advantageously the minimum performance level being identical for all management modules. The performance level is, for example, a service level or a quality of service; and the minimum performance level is, for example, a minimum service level or a minimum quality of service. As another example, if the operation of one of the 26 management modules is unsatisfactory, the replication module 34 performs maintenance operations on the faulty management module 26 to correct the failures.
[0087] For example, the tests consist of sending predefined data to the management module 26, for example, generic data, and verifying that the same test request sent to all management modules 26, and whose response is formed from the generic data, does indeed give an identical response for all management modules 26, in similar times. The tests are advantageously carried out when no request sent by the client electronic device 12 is received by the management modules 26.
[0088] Optionally, the verification module 24 directly transmits read and / or write requests to the processing module 22. This is the case, for example, in the case of requests that are not subject to authorization.
[0089] The infrastructure 10 thus allows data to be managed according to the degree of confidentiality, and therefore the level of security to be ensured for the data. In particular, the client electronic device 12 is independent of the confidentiality rules, which are managed locally by each server 20, via the verification module 24. It is therefore easy to add data subject to new confidentiality rules, and to update the sets of confidentiality rules. The architecture and operation of the infrastructure 10 are thus simplified, while maintaining data confidentiality.
Claims
Demands
1. A method for managing data confidentiality, for a computer system (14) comprising a plurality of servers (20), each server (20) comprising a processing module (22) having a memory (28) configured to store data; a verification module (24) configured to store a set of confidentiality rules; and a management module (26), connected to the verification module (24) belonging to the same server (20) as the management module (26), and configured to be connected to a client electronic device (12); the method being implemented by the computer system (14) and characterized in that it comprises the following steps: - reception (S10), by the management module (26) of each server (20), of a request from the client electronic device (12); - control (S20) by each server (20) that the received request is authorized;and - if the request is authorized by a respective server (20), execution (S30) of the request by said server (20).;
2. A method according to claim 1, wherein the request comprises a plurality of attributes and the control step (S20) comprises the following substeps: - verification (S205) by the verification module of each server (20), that each attribute of the request conforms to the set of confidentiality rules stored in the verification module (24); - if each attribute of the request conforms to said set of confidentiality rules, determination (S206) by the verification module (24) of the respective server (20) that the request is authorized; and - if the request is authorized, recording (S208) of an authorization in the verification module (24) of said server (20).
3. A method according to claim 1 or 2, wherein each processing module (22) is configured to process requests transmitted by the verification module (24) belonging to the same server (20), and the execution step (S30) includes the following substeps: - transmission (S302) of the request by the verification module (24) of the respective server (20) to the processing module (22) belonging to said server (20); and - processing (S304) of the request by the processing module (22) of said server (20).
4. A method according to claim 2 or 3, wherein the control step (S20) further comprises the following substeps: - if the request is pre-authorized by the verification module (24) of a respective server (20), determination (S202) by the management module (26) of said server (20) that the request is authorized and recording (S204) of an authorization in the management module (26), and wherein the substeps of verification (S205), determination by the verification module (24) that the request is authorized (S206) and recording (S208) of the authorization in the verification module (24) of said server (20) are carried out if the request is not pre-authorized by the verification module (24) of said server.
5. A method according to claim 4, wherein each processing module (22) is configured to process requests transmitted by the management module (26) belonging to the same server (20), and wherein, if the request is pre-authorized, the execution step (S30) further comprises the following substep: - transmission (S302) of the request by the management module (26) of the respective server (20) to the processing module belonging to said server (20), the processing step (S304) being carried out following the transmission step (S302) of the request by the management module (26) of said server (20).
6. A method according to any one of claims 1 to 5, wherein the computer system (14) further comprises a replication system (30) configured to store predefined data, the execution step further comprising the following substeps: - if each server (20) determines that the request is not allowed, reception (S306) of the request by the replication system (30); and - processing of the request (S308) by the replication system (30) from the predefined data.
7. Computer assembly (14) comprising a plurality of servers (20), each server (20) comprising: - a processing module (22), having a memory (28) configured to store data; - a verification module (24) configured to store a set of confidentiality rules; and - a management module (26), connected to the verification module (24) belonging to the same server (20) as the management module (26), the management module (26) being configured to be connected to a client electronic device (12), the computer assembly (14) being configured to implement the method according to any one of claims 1 to 6.
8. Computer assembly (14) according to claim 7, wherein the set of confidentiality rules stored in each verification module (24) is distinct from one server (20) to another.
9. Computer assembly (14) according to claim 7 or 8, wherein the management modules (26) of each server (20) are configured to implement identical processes from one management module (26) to another so that the management modules (26) operate with a performance greater than or equal to a minimum performance, the minimum performance preferably being identical for all management modules (26).
10. Computer assembly (14) according to claim 9, further comprising a replication system (30), configured to replicate the operation of the management modules (26).
11. Infrastructure (10) comprising a client electronic device (12), and a computer system (14) according to any one of claims 7 to 10, the client electronic device (12) being connected to each management module (26). 16
12. Infrastructure (10) according to claim 11, wherein the customer electronic device (12) is configured to be embedded in an aircraft (40), and the computer assembly (14) is configured to be external to the aircraft (40).
Citation Information
Patent Citations
Methods and systems for providing access control to secured data
US20090100268A1
Multi-Level Secure Information Retrieval System
US20100146618A1
Secure key and transaction management for multi-party computation systems
US20240296445A1