Aircraft Software Configuration Management via Digital Signature Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Ad-Hoc networks of vehicles, existing technologies face challenges in reliably identifying the transmitter of data packets due to collisions with other packets, which affects the decoding and transmission quality of alert messages.

Innovation Solution

A method and device for managing software configurations of aircraft equipment, which includes detecting communication links, checking and importing configuration files, storing software updates, and controlling software modifications, ensuring secure and efficient software updates by using digital signatures and addressing tables to authenticate and authorize updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data packets are transmitted in an Ad-Hoc network without enhanced identification mechanisms, then transmission simplicity is maintained, but sender identification reliability deteriorates due to packet collisions

Engineering Contradiction:
Improvesender identification reliabilityVSAvoidpacket structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The identification mechanism is segmented into multiple independent components: a primary identifier field containing the sender's address, and multiple redundant identifier fields distributed throughout the packet. This segmentation ensures that even if the primary identifier is lost due to collision, alternative identifiers remain available for reliable sender identification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The packet is pre-configured with multiple identifier fields before transmission, anticipating potential collisions. The sender embeds its identification information in multiple locations within the packet structure in advance, so that when collisions occur, the receiver can still extract the sender's identity from the remaining intact identifier fields.

Inventive Principle:
Principle #10Preliminary action

2Speed

If quick decoding of warning messages is required, then decoding speed must be improved, but this conflicts with the need for reliable sender identification amidst collisions

Engineering Contradiction:
Improvedecoding speedVSAvoidsender identification reliability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The receiver performs partial decoding by focusing only on extracting the sender's identifier from the available packet fragments, rather than attempting to decode the entire packet. This partial action approach enables quick identification of the sender even when parts of the packet are corrupted or lost due to collisions, maintaining both speed and reliability.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The multiple distributed identifier fields act as intermediaries between the collided packet fragments and the sender identification process. Even when collisions fragment the packet, these intermediary identifier fields remain accessible and enable the receiver to quickly determine the sender's identity without needing to reconstruct the entire original packet.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If automatic software updates are implemented with security checks, then security is improved, but update process complexity and time consumption increase

Engineering Contradiction:
Improvesoftware update securityVSAvoidupdate process time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Configuration files are prepared in advance with pre-computed digital signatures and authentication information. Before the actual software update process begins, the system validates the configuration file's digital signature and checks the software update's authentication credentials. This preliminary security verification prevents unauthorized or corrupted updates from being installed, ensuring security while streamlining the update process by eliminating the need for complex real-time security checks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The software update system performs self-verification through automatic digital signature validation and authentication checks. The configuration file and software update packets contain embedded authentication information that enables the receiving system to automatically verify their legitimacy without requiring manual security audits or complex external verification processes. This self-service approach maintains high security standards while minimizing the time and complexity of the update process.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3891600B1Method and device for managing software configurations of equipment of an aircraft
Publication Date: 2023.05.03 SAFRAN ELECTRONICS & DEFENSE (FR)
  • EP3891600B1 patent drawingFigure 1
  • EP3891600B1 patent drawingFigure 2
  • EP3891600B1 patent drawingFigure 3

AI summary

The invention relates to a method and a device for managing software configurations of equipment of an aircraft comprising a device for managing software configurations of equipment of the aircraft. The device for managing software configurations of equipment of the aircraft: - detects the availability of a communication link between a server on the ground and the aircraft, - checks whether a configuration file is available and imports the configuration file, - imports, from the server on the ground, one or more software updates identified in the configuration file and stores the one or more software updates in a temporary storage space, - determines the time from which each update can be carried out, - controls the modification of the software configuration of the item or items of equipment with the at least one software update corresponding to the item or items of equipment.