Passenger Authentication and Network Segmentation for Aircraft Cybersecurity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Commercial transports face vulnerabilities in their computer systems due to potential hacking and manipulation, particularly when passengers with access to inflight entertainment systems can inadvertently or intentionally access flight critical systems, necessitating robust passenger authentication and monitoring mechanisms.
Innovation Solution
A system and method for authenticating passengers by matching them to their assigned seats using names or identifiers, employing security questions, biometric recognition, facial recognition, and certificate recognition, while monitoring and controlling access to resources based on predetermined profiles, utilizing a media server, passenger database, and data loss prevention system to ensure authorized use and restrict unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If passengers are given access to inflight entertainment systems, then passenger comfort and entertainment are improved, but security vulnerabilities increase as passengers may access or hack flight critical systems
Solution Approach 1:
The patent segments the network into isolated segments: flight critical systems are separated from passenger entertainment systems through network segmentation. This allows passengers to access entertainment resources while preventing unauthorized access to flight critical systems, resolving the contradiction between ease of operation and security protection.
Solution Approach 2:
The patent introduces an intermediary authentication system that mediates between passengers and resources. The system verifies passenger identities and authorizes access to specific resources, allowing legitimate entertainment access while blocking potential attacks on flight critical systems.
2Device complexity
If multiple computer systems are interconnected in the same physical network to save space, then device complexity is reduced, but security risks increase due to potential hacking and manipulation
Solution Approach 1:
The patent applies network segmentation to divide the physical network into logically isolated segments. Flight critical systems operate in a secure segment while passenger entertainment systems operate in a separate segment, reducing overall security risks while maintaining physical space efficiency.
Solution Approach 2:
The patent implements different security policies and access controls for different network segments. Critical systems receive enhanced security protection while entertainment systems provide open access, allowing the network to maintain low complexity overall while protecting specific vulnerable areas.
3Productivity
If passenger profiles are assigned before flights with predetermined resource access, then resource allocation efficiency is improved, but the ability to detect and measure actual passenger identity and seat assignment is reduced
Solution Approach 1:
The patent performs preliminary actions by pre-assigning passenger profiles and resource access rights before the flight. This enables efficient resource allocation while the system later verifies actual passenger identity and seat assignment through authentication mechanisms, resolving the contradiction between efficiency and verification capability.
Solution Approach 2:
The patent implements feedback mechanisms that verify whether the pre-assigned passenger is actually sitting in the assigned seat and using authorized resources. This feedback loop ensures that preliminary resource allocation matches actual passenger identity, maintaining both efficiency and security.
Data Source
AI summary
A method, system and computer-usable medium are disclosed for authenticating passengers and their activity regarding the use of resources on a transport during a trip or session on a transport. A passenger is matched to a name and/or identifier that corresponds to a seat on a transport for a specific flight. Authentication is performed based on various methods, such as set of security questions, biometric recognition, facial recognition, certificate recognition. Passenger data is exchanged with on board and remote systems that include accessibility of the passenger to a set of onboard resources. Passenger activity is monitored as to acceptable use of the resources during the flight or trip.


