Aircraft Information System Access Control via Location-Based Authenticators

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing aircraft information system access methods are vulnerable to unauthorized access, particularly in public zones, and require frequent database updates, removable media management, and are not compatible with harsh environmental conditions or high-security threats.

Innovation Solution

A method that uses authenticators generated in restricted access zones, combining location-based security with time-limited tickets, eliminating the need for user account databases and removable media, and allowing access based on possession and action knowledge, ensuring strong authentication under various environmental conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If jacks are made available in public zones to facilitate maintenance operations, then accessibility and ease of operation are improved, but security and vulnerability to unauthorized access worsen

Engineering Contradiction:
Improveaccessibility of maintenance connectorsVSAvoidsecurity of information system
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication by verifying the connector's location in a restricted zone and the terminal's possession of a valid authenticator before granting access. This preliminary check prevents unauthorized access while maintaining ease of operation for authorized personnel.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authenticator as an intermediary element that mediates between the terminal and the information system. The authenticator, generated in restricted zones and validated by the system, acts as a trusted intermediary that enables secure access in public zones without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If user account databases are kept up to date in the airplane or maintenance computer, then authentication accuracy is improved, but device complexity and loss of time worsen due to frequent updates

Engineering Contradiction:
Improveauthentication accuracyVSAvoiddatabase update management
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts the authentication data from the airplane's information system and places it in portable terminals in the form of authenticators. This extraction eliminates the need for maintaining user account databases in the airplane, reducing device complexity while preserving authentication accuracy through the validated authenticator system.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system uses the authenticator itself as the authentication credential, eliminating the need for separate database queries. The authenticator contains all necessary authentication information, allowing the system to verify credentials without external database updates, thus reducing complexity and update requirements.

Inventive Principle:
Principle #25Self-service

3Reliability

If removable media such as USB keys or smart cards are used for authentication, then strong authentication is improved, but device complexity and ease of manufacture worsen due to complicated lifecycle management

Engineering Contradiction:
Improvestrength of authenticationVSAvoidlifecycle management of authentication media
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the terminal itself multi-functional by integrating authenticator storage and presentation capabilities directly into the terminal's memory and communication interfaces. This eliminates the need for separate removable authentication media, reducing device complexity while maintaining strong authentication through the terminal's inherent capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authenticator is designed as a temporary, disposable credential that is generated for a specific session or period and then invalidated. This approach replaces expensive, long-lived removable media with inexpensive, short-lived digital credentials that are automatically managed by the system, reducing both cost and complexity.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

4Reliability

If authentication methods require physical presence in restricted zones, then security is improved, but ease of operation worsens due to environmental constraints such as dirty conditions or remote locations

Engineering Contradiction:
Improvesecurity of access controlVSAvoidaccessibility under environmental constraints
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication in restricted zones where the terminal receives and stores the authenticator. Once authenticated, the terminal can operate in public or environmentally constrained zones without requiring continuous physical presence in restricted areas, thus maintaining security while improving ease of operation under environmental constraints.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authenticator serves as an intermediary that transfers the security credential from the restricted zone to the terminal. This allows the terminal to access the information system in public or environmentally constrained zones without requiring the user to physically return to restricted zones, maintaining security while accommodating environmental constraints.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8819775B2Secure method of accessing an information system of an aircraft
Publication Date: 2014.08.26 AIRBUS OPERATIONS (SAS)
  • US8819775B2 patent drawing
  • US8819775B2 patent drawing
  • US8819775B2 patent drawing

AI summary

In the method of accessing an information system of an aircraft the system receives an authenticator request from a connector of the aircraft; the system determines whether the connector presents a predetermined characteristic; and in the event that the system determines that the connector does indeed present the predetermined characteristic, the system sends an authenticator to the connector. Provision is also made for: the system receives an authenticator the system determines whether the authenticator is valid; and in the event that the system determines that the authenticator is indeed valid, the system authorizes access to the system from a connector of the aircraft from which the authenticator was sent.