Automated Security Credential Delivery for Crew Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing authentication method for crewmembers accessing the administrative functions of an in-flight entertainment and communications (IFEC) system requires physical presence at a crew terminal to generate a one-time password (OTP), which is laborious and creates operational overhead, especially when OTPs need to be relayed across crewmembers.

Innovation Solution

An automated system generates and delivers a security credential, such as a one-time password, to crewmember computing devices at the end of a flight, eliminating the need for physical presence at a crew terminal, using a local security credential generator and remote relay that correlates with crewmember staffing schedules to transmit the credential to designated devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical presence at crew terminal is required to generate OTP, then security authentication is ensured, but operational overhead and laborious process increase

Engineering Contradiction:
Improvesecurity authenticationVSAvoidoperational overhead
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service authentication by automatically generating and delivering OTPs to crewmembers' mobile devices without requiring physical presence at the crew terminal. The mobile device receives and stores the OTP autonomously, allowing crewmembers to authenticate independently.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The mobile device acts as an intermediary between the authentication system and the crewmember. It receives the OTP from the system, stores it securely, and presents it during authentication, eliminating the need for direct interaction with the crew terminal while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If OTP is generated at crew terminal, then secure authentication is provided, but time consumption and efficiency decrease

Engineering Contradiction:
Improveauthentication securityVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The OTP is generated and delivered to the crewmember's mobile device in advance, before the authentication event occurs. This preliminary action eliminates the time required for on-demand OTP generation at the crew terminal, allowing immediate authentication when needed.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If crewmembers must be physically present at crew terminal, then authentication control is maintained, but operational flexibility and convenience are reduced

Engineering Contradiction:
Improveauthentication controlVSAvoidoperational flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The mechanical requirement of physical presence at the crew terminal is replaced with an electronic system that delivers authentication credentials to mobile devices. This substitution maintains control through secure OTP delivery while enabling operational flexibility through remote access capability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10742625B2Automated delivery of security credentials to scheduled crew
Publication Date: 2020.08.11 PANASONIC AVIONICS CORP
  • US10742625B2 patent drawing
  • US10742625B2 patent drawing
  • US10742625B2 patent drawing

AI summary

A system for delivering to one or more crewmember computing devices a security credential for accessing a management interface of an electronics system of a vehicle has a local security credential generator and a remote security credential relay in communication therewith. One or more security credential destinations are identified from a correlation of a vehicle identifier accompanying the security credential transmitted to the remote security credential relay to one or more crewmember computing devices as defined in a crewmember staffing schedule. The security credential is then passed to the crewmember computing devices. A local login controller grants access to the management interface in response to a validation of the security credential transmitted thereto from the crewmember computing device.