Aircraft Data Verification Using Digital Certificate Quorum

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for verifying the authenticity and integrity of software and data on aircraft are ineffective due to the unique operational environment of mobile systems, which makes it difficult to apply ground-based validation methods.

Innovation Solution

A method and apparatus using a plurality of digital certificates from multiple certificate authorities, where a processor unit selects a quorum rule in response to a compromised certificate authority and verifies data by determining if a specified number of valid certificates meet the quorum rule, ensuring data authenticity and integrity on aircraft.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If ground-based digital certificate verification systems are applied to aircraft, then data authenticity can be verified, but the system cannot adapt to mobile operational environments and potential certificate authority compromises

Engineering Contradiction:
Improvedata authenticity verificationVSAvoidadaptability to mobile environment and compromised CA
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the trust verification process by dividing the single certificate authority validation into multiple independent certificate authority validations. Instead of relying on one CA, the system uses multiple CAs (at least two) to sign the software, allowing the aircraft system to verify authenticity through distributed trust rather than centralized trust, thus adapting to mobile environments where a single CA might be compromised or unavailable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent prepares for potential CA compromise in advance by implementing a quorum-based verification system. Before any compromise occurs, the system is configured with multiple CAs and quorum rules that define how many valid certificates are needed for verification. This beforehand cushioning ensures that if one or more CAs are later compromised, the system can still maintain security by requiring a quorum that excludes compromised CAs, thus adapting to the compromised environment without complete system failure.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

2Adaptability or versatility

If multiple digital certificates from multiple certificate authorities are used, then adaptability to compromised CAs is improved, but the verification process complexity increases

Engineering Contradiction:
Improveadaptability to compromised CAVSAvoidverification process complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic quorum rule selection that adapts to the verification context. The system can adjust the quorum requirements based on the specific software being verified, the trust relationships established, and the operational environment. This dynamic approach allows the system to maintain adaptability to compromised CAs while optimizing the verification process complexity for each specific case, rather than using a fixed complex quorum requirement for all scenarios.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces an intermediary trust model where multiple CAs act as intermediaries between the software provider and the aircraft system. Instead of directly verifying a single CA's certificate, the system uses multiple CA intermediaries, each providing independent validation. This intermediary structure distributes the verification complexity across multiple trusted entities, making the overall process more manageable and adaptable compared to a single-point verification system.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a quorum rule is implemented to verify data with multiple certificates, then security against compromised CAs is improved, but the verification time increases

Engineering Contradiction:
Improvesecurity against compromised CAVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-configuring the aircraft system with multiple certificate authority certificates and establishing quorum rules before flight operations begin. The system prepares the trust infrastructure in advance, so that during actual software verification, the system only needs to check against pre-loaded certificates rather than establishing trust relationships in real-time. This preliminary setup reduces verification time while maintaining the security benefits of multiple CA validation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a quorum system where only a specified number (quorum) of certificates need to be valid for verification to succeed, rather than requiring all possible certificates to be validated. For example, if three CAs are used, the system might only require two to be valid (2 out of 3 quorum). This partial validation approach provides sufficient security against compromised CAs while avoiding the time cost of validating every single certificate, thus balancing security and verification time.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2801926B1Use of multiple digital signatures and quorum rules to verify aircraft information
Publication Date: 2020.12.30 THE BOEING CO
  • EP2801926B1 patent drawingFigure 1
  • EP2801926B1 patent drawingFigure 2~3
  • EP2801926B1 patent drawingFigure 4

AI summary

A method and apparatus for verifying data for use on an aircraft. A plurality of digital certificates associated with the data is received by a processor unit. The processor unit verifies the data for use on the aircraft using a selected number of the plurality of digital certificates.