Avionics Data Loading Device with Sealed Decryption Unit

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for secure data transfer to avionics devices in vehicles lack sufficient security, as data is often transmitted unencrypted, and existing encryption methods do not adequately prevent manipulation or hacking, especially in mobile data loading scenarios where physical access and monitoring are limited.

Innovation Solution

A mobile data loading device with a decryption unit and digital signature certification unit, where encrypted and signed data can only be decrypted after verification of authenticity, and the software and operating system are stored in encrypted form within a sealed security housing to prevent unauthorized access and manipulation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is transmitted unencrypted through mobile data loading devices, then ease of operation and compatibility are improved, but security and reliability deteriorate due to manipulation risks

Engineering Contradiction:
Improveease of data transferVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by encrypting data before transmission and verifying digital signatures before decryption. The encryption is performed in advance on the data source, and the signature verification occurs before the decryption unit processes the data, preventing manipulation during transfer without requiring changes to the transmission process itself

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary decryption unit with a sealed housing that acts as a trusted mediator between the data source and the target system. This intermediary contains the decryption functionality and signature verification in a physically protected environment, preventing direct access to decryption keys and ensuring data integrity without requiring the end system to handle unencrypted data

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption and digital signatures are implemented, then security and reliability are improved, but device complexity increases due to additional security components

Engineering Contradiction:
Improvedata securityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the decryption unit and signature verification functionality into a single integrated device with a unified sealed housing. This combination consolidates multiple security functions into one component, reducing the overall number of separate security devices needed and simplifying the system architecture while maintaining comprehensive security

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent applies the nested doll principle by placing the decryption unit inside a sealed housing that contains the signature verification functionality. The decryption unit is nested within the broader security context of the sealed housing and verification mechanisms, creating layers of protection where each layer encapsulates specific functions

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If a sealed security housing is used for the decryption unit, then security against physical access and manipulation is improved, but ease of repair and maintenance deteriorate

Engineering Contradiction:
Improveprotection against manipulationVSAvoidmaintenance accessibility
Core Design Contradiction:
ReliabilityVSEase of repair

Solution Approach 1:

The patent applies segmentation by designing the sealed housing as a discrete, self-contained module that can be replaced as a unit. The decryption unit and verification components are segmented into this separate sealed package, allowing the sealed housing to be replaced without disassembling or repairing internal components, thus maintaining security while enabling maintenance

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2642421B1Data loading device
Publication Date: 2015.05.20 TECHSAT
  • EP2642421B1 patent drawingFigure 1a~1d
  • EP2642421B1 patent drawingFigure 2a~2b
  • EP2642421B1 patent drawingFigure 3~4

AI summary

The device has a decryption unit (9) that is arranged in a secured and sealed housing (10). The housing is provided with an input (4) for input of encrypted data, and an output for loading decrypted data to a line-replaceable unit (LRU) in a data line provided between the input and output decryption processors (7) storing the decryption program for decrypting the encrypted data using a notebook computer. The decrypted data is stored in a data memory of the decryption processors and loaded into the LRU.