Secure Avionics File Loading via Encoded Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for loading files to servers on air transport means, such as avionics servers, are inefficient and insecure, particularly when using non-dedicated protocols and formats, leading to compatibility issues and security concerns when transferring files to standard servers in the 'open world' context.
Innovation Solution
A method and device for loading files from a client to a target server that involves encoding data, requesting authenticity checks, and loading files in a predetermined format using a standard protocol like HTTPS, ensuring secure and authenticated file transfers while maintaining compatibility with avionics tools by using the ARINC 665 format.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If ARINC 615A protocol and TFTP are used for file transfer, then compatibility with avionics servers is maintained, but transfer speed is slow and security is insufficient
Solution Approach 1:
The patent changes the transfer protocol parameter from TFTP to HTTPS, and changes the data format parameter to ARINC 665 with encoded authentication data. This allows using a more secure and faster standard protocol while maintaining compatibility through format encoding.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism where the server validates encoded authentication data before accepting file transfers. This intermediary step enables secure communication between standard servers and avionics tools without requiring dedicated avionics protocols.
2Adaptability or versatility
If ARINC 615A protocol is used, then avionics server compatibility is ensured, but the protocol is designed for small file transfers in secure environments which does not suit open world contexts
Solution Approach 1:
The patent makes the loading tool universal by enabling it to work with both dedicated avionics servers and standard servers. The tool uses ARINC 665 format with encoded authentication data that can be validated by any server supporting the authentication mechanism, not just avionics servers.
Solution Approach 2:
Instead of making servers adapt to specialized avionics protocols, the patent inverts the approach by making standard servers capable of handling authenticated file transfers through validation of encoded authentication data. This allows standard servers to serve dual purposes.
3Adaptability or versatility
If standard servers are used without dedicated avionics protocols, then versatility is improved, but security and file authenticity cannot be guaranteed
Solution Approach 1:
The patent applies preliminary authentication by encoding authentication data with the file data before transfer. The server validates this encoded authentication data before accepting the files, ensuring authenticity is established in advance rather than requiring specialized protocols.
Solution Approach 2:
The encoded authentication data acts as an intermediary mechanism that bridges standard servers and security requirements. It provides a simple validation method that standard servers can implement without adopting complex avionics protocols.
4Ease of operation
If TFTP protocol is used for transfer, then simplicity is maintained, but transfer speed becomes relatively slow
Solution Approach 1:
The patent changes the transfer protocol parameter from TFTP to HTTPS. HTTPS provides better transfer efficiency and speed while maintaining reasonable simplicity through standard web infrastructure that is already widely deployed and understood.
Data Source
AI summary
A method is provided for loading files from a client to at least one target server. The method involves transmitting, from the client to the target server, a set of data obtained from the files to be loaded, at least some of the data of the set being encoded; requesting, from the client, an authenticity check, by the target server, on the data of the set using at least some of the encoded data; and when the authenticity of the data of the set has been checked successfully by the target server, loading the files, according to a predetermined format, from the client to the target server.


