Distributed Engine Control Loop Encryption for Real-Time Aircraft Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Aerospace control systems face challenges in balancing real-time control requirements with security protocols, as existing systems often employ encryption methods that are resource-intensive and costly, particularly in distributed control networks where both inner and outer control loops require secure data communication.

Innovation Solution

Implementing a distributed control system where the inner control loop operates with unencrypted or weakly encrypted data for faster communication, while the outer control loop uses encrypted data to ensure security, optimizing encryption functionality by locating it in the slower outer control loop and utilizing commercial off-the-shelf electronics for reduced weight, cost, and enhanced processor capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is applied to both inner and outer control loops, then security is improved, but system cost and processing complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidencryption processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The control network is segmented into two distinct loops: an inner control loop for real-time control signals and an outer control loop for less time-critical data. Encryption is selectively applied only to the outer control loop, while the inner control loop operates without encryption or with minimal encryption. This segmentation allows the system to maintain security for non-critical communications while preserving real-time performance for critical control signals.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different encryption strategies are applied to different parts of the control system based on their specific requirements. The inner control loop, which requires real-time response, uses no encryption or weak encryption, while the outer control loop uses strong encryption. This local differentiation of encryption quality optimizes both security and performance across the system.

Inventive Principle:
Principle #3Local quality

2Reliability

If strong encryption is used in the inner control loop, then security is improved, but real-time control performance deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidreal-time control speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The control system is divided into two separate communication channels: an unencrypted inner control loop for real-time actuator control and an encrypted outer control loop for supervisory control and monitoring. This segmentation ensures that real-time control signals are not burdened by encryption overhead, maintaining fast response times while still providing security for less time-critical communications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of applying full encryption to all control communications, the system applies encryption partially—only to the outer control loop where security is needed but real-time performance is less critical. This partial application of encryption achieves adequate security protection without sacrificing the real-time control performance required for safe aircraft operation.

Inventive Principle:
Principle #16Partial or excessive action

3Weight of moving object

If commercial off-the-shelf electronics are used, then system weight and cost are reduced, but processing capabilities for encryption may be limited

Engineering Contradiction:
Improvesystem weightVSAvoidprocessor capability
Core Design Contradiction:
Weight of moving objectVSPower

Solution Approach 1:

The system segments encryption requirements by control loop, placing less demanding encryption (or no encryption) in the inner loop and stronger encryption only in the outer loop. This reduces the overall computational burden on COTS processors, allowing the use of lighter, lower-cost electronics that would be insufficient if full encryption were required across all control communications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The encryption parameters are adjusted based on the control loop requirements—using weaker encryption algorithms or reduced encryption strength in the inner control loop compared to the outer control loop. This parameter differentiation reduces the processing power needed, enabling the use of COTS electronics with limited processing capabilities while still providing adequate security for the system.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11155338B2Encryption and security in a distributed control network
Publication Date: 2021.10.26 ROLLS ROYCE NORTH AMERICAN TECHNOLOGIES INC
  • US11155338B2 patent drawing
  • US11155338B2 patent drawing

AI summary

Methods and systems are provided for controlling a component of an aircraft engine by communicating data over an inner control loop portion of a distributed engine control network for an aircraft; and controlling an operation of the aircraft engine by communicating encrypted data over an outer control loop portion of the distributed engine control network, wherein the data communicated over the inner control loop portion is unencrypted or encrypted with weaker encryption than the data communicated over the outer control loop portion.