Aircraft Maintenance Wireless Access Control via Intermediary Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems for mobile devices in secured areas, such as aircraft maintenance, face challenges in securely transmitting authentication information and ensuring access restrictions, as traditional methods like WPA2 and Radius standards are not effective in preventing unauthorized access when using wireless local communication.
Innovation Solution
A communication system with a first wireless communication device and a second wireless communication device, where the second device is located in a secure, smaller area and provides authentication information only to devices physically present, enhancing security through a two-factor authentication process using a terminal device with a PIN or identification card.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If wireless local communication (WLAN, ZigBee) is used to simplify connection of external maintenance devices, then ease of operation is improved, but security against unauthorized access deteriorates
Solution Approach 1:
The patent introduces a second wireless communication device as an intermediary that stands between the mobile computer device and the first communication device. This intermediary verifies authentication information before allowing communication, thus maintaining ease of wireless connection while adding a security layer that prevents unauthorized access
Solution Approach 2:
The patent creates different communication areas with different security requirements. The second communication device operates in a restricted area where authentication information is distributed, while the first communication device operates in a broader area. This local differentiation allows wireless convenience in authorized zones while maintaining security through geographic-based access control
2Ease of operation
If authentication information is transmitted to mobile computer devices outside secured areas, then ease of operation is improved, but security against unauthorized access deteriorates
Solution Approach 1:
The patent segments the authentication process into two distinct phases: authentication information distribution (handled by the second communication device in the secured area) and authentication verification (handled by the first communication device). This segmentation allows authentication information to be transmitted securely within the restricted area while still enabling mobile devices to access the system legally
3Reliability
If a smaller second communication area is created for authentication information transmission, then security against unauthorized access is improved, but ease of operation deteriorates
Solution Approach 1:
The patent makes the communication areas dynamic rather than fixed. The second communication device can move authentication information to different locations within the secured area, and the system adapts to the mobile nature of the devices. This dynamic approach maintains security through restricted area enforcement while preserving operational flexibility
Data Source
Figure 1
Figure 2~3
AI summary
A communication system (10) comprises a first wireless communication device (12) for providing communication access to a mobile computing device (18, 20) in a first communication area (16). The first wireless communication device (12) includes an access control device for granting access based on authentication information known to the mobile computing device (18, 20). A second communication device (24) is provided for providing the authentication information to the mobile computing device (18, 20). Furthermore, the invention relates to a method for granting access that can be carried out with the aforementioned communication system (10), as well as a maintenance system and/or an aircraft with such a communication system (10).