Command Authentication Codes for Unsecured Remote Control Links

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In remotely controlled transport systems, the failure of uplink connections leads to increased risk of accidents due to the inability to authenticate and verify command data, potentially allowing third-party interference and incorrect command execution, which overburdens air traffic control units without proper training.

Innovation Solution

An apparatus comprising a receiving unit, processor unit, and memory unit with a code generator, cryptography module, and comparison module that generates and verifies authentication codes using a private key, allowing secure command data transmission over unsecured data connections, ensuring only authorized commands are executed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If command data is transmitted via an unsecured data connection in the event of uplink failure, then the means of transport can still receive commands, but the system becomes vulnerable to third-party interference and falsified commands

Engineering Contradiction:
Improvecommand transmission capabilityVSAvoidcommand authenticity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary actions by generating and transmitting a transaction code via the unsecured connection before the actual command transmission. This transaction code serves as a preliminary authentication mechanism that enables subsequent verification of command authenticity without requiring a secured connection

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism using transaction codes and authentication codes. These codes act as mediators between the unsecured data connection and the command execution system, enabling verification of command authenticity without requiring direct security measures on the communication channel

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If air traffic control units assume the role of remote operator to forward commands, then command transmission is maintained, but the workload increases and accident risk rises due to lack of training

Engineering Contradiction:
Improvecommand transmission continuityVSAvoidoperator competence
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The system enables self-service operation by equipping the means of transport with autonomous authentication capabilities. The apparatus on the means of transport independently verifies command authenticity using the authentication code and private key, eliminating the need for air traffic control personnel to perform complex authentication tasks or assume remote operator roles

Inventive Principle:
Principle #25Self-service

3Speed

If no authentication mechanism is used on unsecured connections, then transmission speed is maintained, but incorrect command execution occurs due to interference or falsification

Engineering Contradiction:
Improvecommand transmission speedVSAvoidcommand correctness
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system performs preliminary authentication setup by transmitting the transaction code before command execution. This preliminary action establishes the authentication framework in advance, enabling rapid verification of command correctness without slowing down the overall transmission process

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces complex mechanical or procedural authentication systems with a cryptographic substitution mechanism. Using authentication codes generated through cryptographic functions allows for rapid, automated verification of command correctness, maintaining transmission speed while ensuring reliability

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11757631B2Apparatus, system, and method for releasing received command data
Publication Date: 2023.09.12 AIRBUS DEFENCE & SPACE GMBH
  • US11757631B2 patent drawing
  • US11757631B2 patent drawing
  • US11757631B2 patent drawing

AI summary

An apparatus for releasing received command data includes a processor unit with a code generator, a cryptography module, and a comparison module. The code generator generates a transaction code. The apparatus has a transmitting unit which provides the transaction code via an unsecured data connection, a receiving unit which receives an external authentication code and command data via the unsecured data connection, and a memory unit which stores data of a predefined private key. Also disclosed is a transmission apparatus for command data. The transmission apparatus has a basic receiving unit which receives the transaction code, an input unit which receives the command data, a basic memory unit which stores the data of the predefined private key, a basic processor unit which has a basic cryptography module, and a basic transmitting unit which provides the external authentication code and the command data via the unsecured data connection.