Distributed Ledger Authentication for Aerospace Control Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Aerospace control systems in aircraft are vulnerable to cyber threats due to potential weaknesses in third-party components and software configurations, which can compromise the security of engine networks and control systems.

Innovation Solution

A method utilizing a braided ring network with distributed ledgers, including unit, system, and device level ledgers, to securely authenticate and validate control nodes and peripheral devices, employing encryption and hashing to ensure the integrity and authenticity of components and software configurations before operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If distributed ledgers and authentication protocols are implemented in aerospace control systems, then system security and component authenticity are improved, but device complexity and computational overhead increase

Engineering Contradiction:
Improvesystem securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into multiple hierarchical levels: device-level ledgers for individual component authentication, unit-level ledgers for subsystem verification, and system-level ledgers for overall control system validation. This segmentation distributes the computational burden across multiple independent authentication layers, improving security without overwhelming any single component with excessive complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Authentication and validation of control nodes and peripheral devices are performed in advance before the aerospace control system begins operation. The distributed ledgers pre-establish cryptographic proofs of authenticity and integrity for all components during system initialization or component installation, eliminating the need for continuous complex verification during critical flight operations.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple levels of distributed ledgers are maintained for authentication, then authenticity verification is improved, but loss of time and computational resources increase

Engineering Contradiction:
Improveauthenticity verificationVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs authentication and validation of control nodes and peripheral devices in advance during system initialization or component installation. The distributed ledgers pre-establish cryptographic proofs of authenticity, eliminating the need for time-consuming verification processes during critical real-time flight operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent combines multiple authentication functions into a unified distributed ledger system that simultaneously handles device identity verification, software configuration validation, and component integrity checking. This merging consolidates what would otherwise be separate time-consuming verification processes into a single efficient authentication operation.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11456891B2Apparatus and methods for authenticating cyber secure control system configurations using distributed ledgers
Publication Date: 2022.09.27 ROLLS ROYCE CORP
  • US11456891B2 patent drawing
  • US11456891B2 patent drawing
  • US11456891B2 patent drawing

AI summary

Control systems and methods for securely authenticating and validating a control system. The control system may include a plurality of dependent control nodes and master control nodes. Each dependent control node is communicatively coupled to one or more peripheral devices. Each control node maintains a unit level distributed ledger, where each unit level distributed ledger includes information from corresponding peripheral devices. Each control node may transmit a portion of the unit level distributed ledger to a master control node. Each master control node may maintain a system level distributed ledger that includes information from the corresponding unit level distributed ledgers. Each master node may transmit a portion of the system level distributed ledger to a central node that maintains a separate secure distributed ledger. The master node may authenticate the control system based on the received portion of the system level distributed ledgers and the secure distributed ledgers.