NFC Tagged PED Access Control for Aircraft Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Aircraft wireless networks are frequently shut down due to misplaced, lost, or stolen portable electronic devices (PEDs) used as electronic flight bags, requiring labor-intensive Certificate Revocation List updates and disrupting crew and maintenance access.

Innovation Solution

Implementing a Near Field Communication (NFC)-type Radio Frequency Identification (RFID) system to dynamically manage an Airline Approved Devices List by tagging authorized PEDs with unique identifiers and access levels, allowing only authorized devices to access the network upon proximity to an NFC reader, eliminating the need for Certificate Revocation Lists and network deactivation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital certificates are used to secure wireless network access, then network security is improved, but administrative complexity and response time to device loss increase

Engineering Contradiction:
Improvenetwork securityVSAvoidadministrative complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the authorization process into two independent components: NFC tags attached to devices for identification, and a centralized database for authorization management. This segmentation allows the NFC reader to quickly identify devices without complex certificate verification, while security decisions are handled separately by the authorization database, reducing administrative complexity while maintaining security

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The NFC tag acts as an intermediary carrier that holds device identification information. Instead of directly implementing complex digital certificate verification, the system uses NFC tags as an intermediate layer to store and transmit device identifiers, which are then verified against the authorization database, simplifying the overall authentication process

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If Certificate Revocation Lists are updated to prevent unauthorized access, then network security is improved, but network availability and operational efficiency deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary authorization by maintaining a pre-configured authorization database containing all approved device identifiers before devices attempt to connect. The NFC reader quickly checks incoming devices against this pre-prepared list, eliminating the need for reactive certificate revocation updates and network shutdowns when devices are lost or stolen

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authorization database is designed to be dynamically updateable without requiring network-wide certificate revocation. The system can add or remove authorized device identifiers in the database in real-time, allowing rapid response to device loss while maintaining continuous network availability for authorized devices

Inventive Principle:
Principle #15Dynamics

3Reliability

If wireless networks are deactivated when authorized devices are lost, then network security is improved, but access availability and user convenience worsen

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system extracts the authorization verification process from the network access control itself. Instead of using digital certificates that require network-wide revocation, the device identification information is extracted into separate NFC tags. This allows the network to remain active and accessible while authorization decisions are made independently based on NFC tag verification against the authorization database

Inventive Principle:
Principle #2Taking out (Extraction)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution reduces administrative overhead, prevents unnecessary network shutdowns, and ensures secure access by dynamically updating the list of authorized devices onboard, enhancing operational efficiency and minimizing disruptions.

Implementation Method 1

uses Near Field Communication (NFC)-type Radio Frequency Identification (RFID) technology to tag each PED which is authorized to use the wireless network

Methodology Applied
Scientific EffectNear Field Communication (NFC): Electromagnetic Induction

Implementation Method 2

Near Field Communication (NFC)-type Radio Frequency Identification (RFID) system

Methodology Applied
Scientific EffectRadio Frequency Identification (RFID): Electromagnetic Induction

Data Source

PatentEP3142328B1System and method for providing secure access to a wireless network
Publication Date: 2020.02.12 THE BOEING CO
  • EP3142328B1 patent drawingFigure 1
  • EP3142328B1 patent drawingFigure 2
  • EP3142328B1 patent drawingFigure 3

AI summary

A system and method are disclosed for controlling access by a portable electronic device (PED) to a wireless network. A near field communications (NFC) tag is affixed to each authorized PED. Each NFC tag is programmed to include an identification code for the associated portable electronic device. An NFC reader has an antenna that receives an information signal when the NFC tag on a PED is placed in close proximity to the antenna. The NFC reader also has an output for outputting the information contained within the information signal. An authorization module is coupled to the output of the NFC reader and to a router which controls access to the wireless network. The authorization module receives the information from the NFC reader and, if the information contains an identification code for a PED, configures the router to allow the PED having that identification code to access the wireless network.