Composite AMI Identity Management for Airplane LRUs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern airplanes face cybersecurity vulnerabilities due to their complex, interconnected software and firmware systems, which can lead to potential attacks on flight critical systems and compromise airworthiness, especially with the use of non-aviation standard TCP/IP protocols and lack of proper key management in line-replaceable units (LRUs).
Innovation Solution
A method for provisioning a second line replacement unit (LRU) using a first LRU in an airplane involves generating a public-private key pair, requesting a certificate signing request (CSR), obtaining and revoking certificates through a certificate authority, and providing composite airline modifiable information (AMI) with multiple public key certificates for secure identity management and communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If e-enabled airplane capability to reprogram flight critical avionics components wirelessly is implemented, then efficiency of flight and business operations is improved, but cybersecurity vulnerabilities and risks to airworthiness increase
Solution Approach 1:
The patent implements preliminary security measures by establishing a certificate authority (CA) infrastructure and digital certificate system before wireless reprogramming operations begin. The CA issues digital certificates to authorized entities, and these certificates are verified before allowing any software updates or reprogramming actions. This preliminary authentication framework prevents unauthorized access and ensures that only verified software updates can be installed, thus addressing cybersecurity vulnerabilities while maintaining the efficiency benefits of wireless reprogramming capability.
2Ease of operation
If multiple public key certificates are stored in a single composite AMI file, then management of airplane identities is simplified and number of software parts is reduced, but security management complexity increases
Solution Approach 1:
The patent merges multiple public key certificates into a single composite Airplane Modifiable Information (AMI) file. Instead of managing separate certificate files for each identity, the system combines all necessary certificates into one unified structure. This consolidation simplifies the management of airplane identities by reducing the number of software parts that need to be tracked and distributed, while the internal structure of the composite file maintains organized security management through standardized certificate formats and hierarchical arrangement.
3Reliability
If LRU replacement is allowed during flight operations, then operational availability is improved, but risk of introducing compromised software increases
Solution Approach 1:
The patent implements a feedback mechanism where the certificate authority infrastructure provides continuous verification capability. When an LRU is replaced during flight operations, the new LRU must present valid digital certificates that are verified against the CA infrastructure. This feedback loop ensures that only authenticated, non-compromised software can be installed, even during operational replacements. The system continuously monitors and validates the authenticity of software updates, preventing compromised software from being introduced while maintaining operational availability.
Data Source
AI summary
The present disclosure generally relates to one or more line replacement units (“LRUs”) for an airplane including a method for provisioning a second line replacement unit (“LRU”) using a first LRU in an airplane. The method includes providing, by the first LRU, a communication to the second LRU to request a certificate signing request (“CSR”) based on a public-private key pair generated by the second LRU; obtaining the CSR from the first LRU; providing the CSR and a certificate revocation request for a replaced LRU to a certificate authority (“CA”); obtaining a composite airline modifiable information (“AMI”) comprising a public key certificate associated with a private key generated by the first LRU; and providing the composite AMI to the first LRU.


