Dynamic Certificate Management for Mobile Platforms
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In mobile platforms like aircraft, buses, and ships, existing wireless IP communication systems lack security, particularly in environments where crew members have limited knowledge of computer security, making it difficult to implement and manage security certificates for secure data access.
Innovation Solution
A system and method for remotely and dynamically generating security certificates using a self-signed certificate authority within a public key infrastructure, allowing for automated mutual authentication between onboard and central computer systems, establishing a secure link without manual intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If standard security certificate systems are implemented in mobile platforms, then security is improved, but operational complexity and workload increase significantly
Solution Approach 1:
The mobile platform computer system automatically performs certificate exchange operations without requiring user interaction. The system self-manages the security certificate lifecycle including generation, storage, and exchange with central systems, eliminating the need for crew members to manually handle complex security procedures
Solution Approach 2:
Security certificates are pre-configured and automatically exchanged when computer equipment is installed or replaced on the mobile platform. The system proactively manages certificate validity and renewal before security issues arise, rather than requiring reactive user intervention
2Reliability
If interactive certificate exchange is required for newly installed computer equipment, then security authentication is improved, but implementation becomes infeasible due to limited crew knowledge and short turnaround times
Solution Approach 1:
The computer system automatically conducts certificate exchange operations with central systems without requiring crew member intervention. The system independently manages authentication protocols and certificate validation, making security implementation as easy as simply installing the computer equipment
Solution Approach 2:
A centralized certificate authority system acts as an intermediary between mobile platforms and central systems, automating the certificate exchange process. This intermediary handles the complex authentication procedures remotely, eliminating the need for on-site technical expertise
3Extent of automation
If cryptographic hardware is installed for automated certificate exchange, then security automation is improved, but parking time and labor costs increase
Solution Approach 1:
The patent replaces physical cryptographic hardware installation with software-based automated certificate exchange. The system uses existing communication interfaces and protocols to perform automated security operations, eliminating the need for physical hardware modifications and associated downtime
Solution Approach 2:
The automated certificate exchange system utilizes existing multi-functional computer system components and communication interfaces already present on mobile platforms. Rather than adding dedicated cryptographic hardware, the system leverages universal computing resources for security operations
Data Source
Figure 1
Figure 2
AI summary
A system and method for establishing a mutually authenticated secure link between a mobile platform system and a remote system is provided. An onboard computer system (OCS) generates a dynamic certificate and digitally signs the dynamic certificate with a static certificate. The dynamic certificate is transmitted to a remote central computer system (CCS). The CCS verifies that the dynamic certificate is from a trusted source and sends a return dynamic certificate electronically signed with the static certificate to the OCS. The OCS verifies the return dynamic certificate is from the CCS, thereby establishing a mutually authenticated secure link between the OCS and the CCS.