Selective Satellite Data Encryption via XOR Key Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Satellites shared among multiple operators face conflicts in command processing and security concerns, as existing systems lack effective mechanisms to manage and encrypt data, leading to potential undesired operations and data exposure.

Innovation Solution

A satellite system with a communications system and computers configured to identify and encrypt information blocks using generated keys, performing exclusive OR operations to form encrypted information, ensuring secure transmission and processing of commands and telemetry data, thereby reducing conflicts and maintaining operator-specific security levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple operators share satellite resources, then resource utilization and revenue increase, but security risks and data exposure increase

Engineering Contradiction:
Improvesatellite resource sharingVSAvoiddata exposure risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments satellite resources by creating separate virtualized environments for different operators. Each operator receives encrypted command sets tailored to their specific needs, with encryption keys distributed selectively. This segmentation allows multiple operators to share the same physical satellite infrastructure while maintaining isolated, secure data channels for each operator, thus enabling resource sharing without compromising security.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If encryption is applied to all data transmissions, then security is improved, but processing time and system complexity increase

Engineering Contradiction:
Improvedata securityVSAvoidprocessing time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent implements selective encryption where only specific command sets and telemetry data requiring security are encrypted, rather than all data transmissions. The system identifies which operators need encryption for which resources and applies encryption only to those specific data streams. This partial application of encryption maintains security for sensitive operations while reducing overall processing overhead and system complexity compared to universal encryption.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If separate controllers are provided for each customer, then operational control is improved, but satellite weight and cost increase

Engineering Contradiction:
Improvecustomer control capabilityVSAvoidsatellite weight
Core Design Contradiction:
Ease of operationVSWeight of moving object

Solution Approach 1:

The patent implements a universal controller architecture that can serve multiple operators simultaneously through virtualization and selective command processing. A single controller unit is designed to handle commands from multiple operators, process telemetry data for different resources, and apply appropriate encryption selectively. This multi-functional controller eliminates the need for separate dedicated controllers for each operator, significantly reducing satellite weight and cost while maintaining full operational control capabilities for each customer.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9001642B2Selective downlink data encryption system for satellites
Publication Date: 2015.04.07 THE BOEING CO
  • US9001642B2 patent drawing
  • US9001642B2 patent drawing
  • US9001642B2 patent drawing

AI summary

A method and apparatus for a satellite system. A satellite system is comprised of a communications system in a satellite and a number of computers associated with the satellite. The communications system is configured to receive first information and transmit second information from the satellite to a remote platform over a number of communications links. The number of computers is configured to identify a block of information for encryption from instructions in the first information. The number of computers is further configured to generate a key from a portion of the block of information based on the instructions. The number of computers is further configured to perform an exclusive OR operation on the block of information using the key to form a block of encrypted information. The number of computers is further configured to transmit the block of encrypted information.