Satellite Secure Enclave for Hosted Payload Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current satellite payload operations lack resource allocation privacy, as all switching and control are managed by a single satellite controller without secure resource allocation.

Innovation Solution

Implementing a secure enclave within the satellite operations center that uses encrypted commands and telemetry to allow private and dynamic resource allocation, separating host and hosted payload operations using inband communications and secure terrestrial links.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single satellite controller manages all payload switching and control, then the control system is simple and easy to operate, but resource allocation privacy is lost and security is compromised

Engineering Contradiction:
Improveresource allocation privacyVSAvoidcontrol system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the satellite controller into two distinct components: a host controller that manages overall satellite operations and a secure enclave that handles hosted payload operations. This segmentation allows resource allocation privacy for hosted payloads while maintaining a relatively simple overall control structure. The secure enclave acts as an isolated compartment that processes commands independently, preventing the host controller from accessing hosted payload resource allocations.

Inventive Principle:
Principle #1Segmentation

2Reliability

If encrypted commands and telemetry are used for secure communication, then security and privacy are enhanced, but communication system complexity increases

Engineering Contradiction:
Improvecommunication securityVSAvoidcommunication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces encryption modules as intermediary components between the host controller, secure enclave, and external communication systems. These modules handle the encryption and decryption of commands and telemetry data, providing security without requiring the core control systems to implement complex cryptographic functions directly. The encryption modules act as buffers that protect sensitive information while maintaining straightforward control logic in the host controller and secure enclave.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If inband communications are used for payload operations, then communication efficiency is improved, but security risks increase compared to out-of-band communications

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidcommunication security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the communication channels into distinct inband and out-of-band paths with different security requirements. Hosted payload commands and telemetry use encrypted inband communications for efficiency, while host controller communications can use more secure out-of-band channels when needed. This segmentation allows the system to optimize communication efficiency for time-critical payload operations while maintaining security through encryption and selective use of secure channels.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12191977B2Satellite operations with secure enclave for secure inband hosted payload operations
Publication Date: 2025.01.07 THE BOEING CO
  • US12191977B2 patent drawing
  • US12191977B2 patent drawing
  • US12191977B2 patent drawing

AI summary

Systems, methods, and apparatus for satellite operations with secure enclave for secure inband hosted payload operations are disclosed. In one or more embodiments, a method for payload operations comprises receiving, by a vehicle, host commands from a satellite operation portion of a host spacecraft operations center (SOC). The method further comprises reconfiguring a payload and at least bus component on the vehicle according to the host commands. Also, the method comprises transmitting, by the vehicle, host telemetry to the satellite operation portion of the host SOC. In addition, the method comprises receiving, by the vehicle, hosted commands from a secure enclave of the host SOC. Additionally, the method comprises reconfiguring the payload on the vehicle according to the hosted commands. Further, the method comprises transmitting, by a payload antenna on the vehicle, host payload data, hosted payload data, and the encrypted hosted telemetry to the secure enclave.