FMS Config File Security via EFB Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need to enhance cybersecurity in aviation systems by securely managing configuration files that are externally connected to onboard avionic systems, particularly during the loading and updating processes, to prevent unauthorized access and ensure secure flight planning data deployment.
Innovation Solution
The implementation of a method and system that configures aircraft configuration files using a permission validation process, allowing access to flight management systems (FMS) to validate user and client requests through encryption and decryption procedures based on public and private keys, and enabling a direct setup mode for updating the config file content using a digital signature authentication process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If configuration files are externally connected to onboard avionic systems for flight operations, then access to flight planning data is enabled, but cybersecurity vulnerabilities increase due to unauthorized access risks
Solution Approach 1:
The patent introduces an encryption layer as an intermediary between the external configuration file access and the onboard avionic systems. Public key encryption acts as a mediator that allows data to be transmitted and accessed while maintaining security, as the encrypted data cannot be read without the corresponding private key.
Solution Approach 2:
The patent transforms the configuration data by encrypting it before transmission to the onboard systems. This parameter change (from plaintext to ciphertext) ensures that even if unauthorized access occurs, the data remains unreadable and secure.
2Adaptability or versatility
If configuration files are updated during flight operations, then system adaptability is improved, but security validation complexity increases
Solution Approach 1:
The patent implements preliminary validation of the configuration file's digital signature before allowing any updates to be applied. The system verifies the signature in advance, ensuring the update's authenticity and integrity before it modifies the system state, thus preventing unauthorized or corrupted updates.
Solution Approach 2:
The patent replaces manual security validation processes with automated cryptographic verification. Instead of relying on manual checks or simple authentication, the system uses digital signature verification algorithms to automatically validate the authenticity and integrity of configuration updates.
3Reliability
If encryption is implemented for all data transmissions, then cybersecurity is enhanced, but processing time increases
Solution Approach 1:
The patent applies encryption selectively rather than uniformly to all data. Configuration data and sensitive flight planning information are encrypted, while other non-sensitive operational data may be transmitted without encryption. This localized approach maintains security for critical data while minimizing the overall processing overhead.
Data Source
AI summary
Methods, systems, and apparatuses are provided for flight management to configure an aircraft configuration (config) file accessible by the avionic system wherein an avionic service is implemented by a flight management system (FMS) for corroborating allowance of access using one of a set of validation procedures for corroboration prior to execution of a request for content to the config file including validating that a user request for a session is authorized based on user identification data, that a client request by an Electronic Flight Bag (EFB) application for a session is authorized based on client identification data, and in response to the client request, determining that an EFB application request is encrypted and performing a decrypt procedure of the EFB application request based on private key data of a private key; and encrypting an EFB application response based on public key data of a public key from the config file.


