Cryptographic Protocols for Satellite Software Update Delivery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for delivering software updates to satellites and remote locations face challenges due to power, bandwidth, and radio frequency (RF) limitations, particularly in space-based communication systems where traditional security protocols increase the RF footprint and data transfer costs, and existing solutions do not adequately address authentication and minimization of RF signatures.

Innovation Solution

The implementation of three cryptographic protocols: Back-haul Authenticated Control (BAC) for initial transmission and confirmation, Constrained Communication Synchronization-Request (COCO-SYNC-R) for inter-unit distribution using a pull method, and Constrained Communication Synchronization-Provide (COCO-SYNC-P) for inter-unit distribution using a push method, which prioritize authentication and minimize the RF footprint by optimizing data transfer and reducing unnecessary transmissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security protocols are used for software update delivery, then authentication and security are improved, but RF footprint and data transfer costs increase

Engineering Contradiction:
ImproveauthenticationVSAvoidRF footprint
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the authentication function from the data transfer protocol, implementing security at the application layer through separate cryptographic protocols (BAC for back-end authentication, COCO-SYNC-R for receiver-to-receiver authentication). This separation allows security to be maintained while minimizing RF footprint during actual data transfer, as authentication occurs independently rather than requiring continuous secure channel maintenance.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary authentication actions before bulk data transfer. The BAC protocol establishes authentication and authorization in advance, allowing subsequent data transfers to proceed with minimal RF communication. Receivers authenticate themselves and each other beforehand, enabling efficient data distribution without repeated authentication overhead during the transfer process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional file transfer protocols are used, then data delivery is ensured, but power consumption and bandwidth usage increase

Engineering Contradiction:
Improvedata deliveryVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by stationary object

Solution Approach 1:

The patent segments the file transfer process into distinct phases: initialization phase (BAC protocol for authentication and parameter exchange), data transfer phase (efficient bulk transfer with minimal protocol overhead), and confirmation phase (asymmetric confirmation where only the initiating receiver needs to acknowledge). This segmentation allows each phase to be optimized independently, reducing overall power consumption while maintaining reliable delivery.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements partial confirmation action where not all receivers need to send confirmation messages back to the back-end. Instead, the initiating receiver confirms receipt, and other receivers can obtain data through peer-to-peer transfer without individual confirmations. This reduces the total number of RF transmissions and associated power consumption while still ensuring reliable delivery to all receivers.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If security protocols require interaction between devices, then authentication is improved, but device complexity and protocol overhead increase

Engineering Contradiction:
ImproveauthenticationVSAvoidprotocol overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces cryptographic intermediaries (authentication tokens, session keys, and digital signatures) that mediate the authentication process. Rather than requiring complex direct device-to-device verification, receivers use pre-shared keys and cryptographic tokens to authenticate themselves to the back-end and to each other. This intermediary cryptographic layer simplifies the interaction model while maintaining strong authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If complete message transmission is performed to all receivers, then data completeness is improved, but data transfer costs and time increase

Engineering Contradiction:
Improvedata completenessVSAvoiddata transfer time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a self-service data distribution model where receivers that have successfully obtained complete data can automatically share it with other receivers in the network. The COCO-SYNC-R protocol enables receivers to discover each other and transfer data directly without back-end involvement. This peer-to-peer self-service approach reduces the total time required for complete distribution compared to sequential back-end-to-all transfers.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240107304A1Reduced file transfer protocol methods and systems
Publication Date: 2024.03.28 THE GOVERNMENT OF THE UNITED STATES OF AMERICA AS REPRESENTED BY THE SECRETARY DEPARTMENT OF HEALTH & HUMAN SERVICES
  • US20240107304A1 patent drawing
  • US20240107304A1 patent drawing
  • US20240107304A1 patent drawing

AI summary

Methods and systems for reduced file transfer protocols are disclosed, Provided are methods and systems for implementation for securing software updates to satellites and remote locations under power, bandwidth, or frequency limitations, using cryptographic protocols for different components of a delivery architecture for a large data payload, such as for a software update, from a trusted, back-end (terrestrial) source to receivers: a low-response protocol for initial transmission and confirmation (BAC protocol), and two possible inter-unit distribution protocols (COCO-SYNC-R protocol (Pull) or COCO-SYNC-P (PUSH)) with differing optimizations based on connectivity scenarios. These protocols introduce a means for accounting for both security (authentication) and efficacy (minimized RF footprint) in the delivery of critical data payloads to remote receivers.