Satellite Secured Channel Key Management With Rollback Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The SDLS standard for securing satellite communications lacks detailed management of keys and security parameters, leading to potential communication failures and loss of connectivity due to inconsistent key configurations, especially in simpler satellites without redundant channels.

Innovation Solution

A method involving concatenation and verification of Extended Procedures, with rollback safeguards, to manage secured channels, ensuring successful execution and synchronization across initiator and receiver.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If key management procedures are implemented according to SDLS-EP standard, then security parameter management capability is improved, but system complexity increases due to lack of detailed implementation guidance

Engineering Contradiction:
Improvesecurity parameter management capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The key management process is divided into distinct phases: preparation phase (generating and storing rollback data), execution phase (applying Extended Procedures), and verification phase (checking success and applying result data). This segmentation transforms the complex, undifferentiated key management process into manageable, sequential steps with clear boundaries and responsibilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Rollback data representing the initial state of security parameters is generated and stored before the actual key management operations are executed. This preliminary action creates a safety net that allows the system to recover if operations fail, enabling more aggressive security parameter changes without permanent risk.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If Extended Procedures are executed to replace keys and reconfigure secured communication channel, then key rotation capability is improved, but risk of communication failure increases due to potential inconsistencies

Engineering Contradiction:
Improvekey rotation capabilityVSAvoidcommunication reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

Rollback data is prepared in advance as a protective measure against potential execution failures. This cushioning mechanism ensures that even if key replacement operations fail or create inconsistencies, the system can restore the previous secure state and maintain communication reliability.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

The system verifies whether Extended Procedures executed successfully and based on this feedback, either applies result data to complete the key rotation or restores rollback data to prevent communication failure. This feedback loop ensures that key rotation only completes when verification confirms success.

Inventive Principle:
Principle #23Feedback

3Reliability

If verification and validation of concatenated Extended Procedures is performed, then execution reliability is improved, but processing time increases

Engineering Contradiction:
Improveexecution reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Verification and validation of the concatenated Extended Procedures are performed before actual execution. This preliminary checking ensures that only valid, consistent operation sequences are executed, preventing wasted time on failed operations and enabling faster overall key rotation by avoiding retry cycles.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4607817A1Method for managing a secured channel in a satellite communication
Publication Date: 2025.08.27 CYSEC SA
  • EP4607817A1 patent drawingFigure 1
  • EP4607817A1 patent drawingFigure 2
  • EP4607817A1 patent drawing

AI summary

1. A method for managing a secured channel (16) in a satellite communication between an initiator (12) and a receiver (14) exchanging data according to the SDLS standards, the method comprising the steps of: - requiring (102), from the initiator (12) or the receiver (14), the application of Extended Procedures of said SDLS standards; - grouping (104) together such Extended Procedures by means of a concatenating operation; - executing (108) such concatenated Extended Procedures respectively at the initiator (12) or at the receiver (14), - verifying if the execution of the Extended Procedures succeeded and, in positive case, obtaining result data to be transmitted to the receiver (14) or to the initiator (12), respectively.