Secure Enclave for Satellite Hosted Payload Command Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current payload operations in satellite systems lack resource allocation privacy, with all switching and control managed by a single satellite controller without secure separation of host and hosted user data processing.

Innovation Solution

Implementing a secure enclave within a host satellite operation center to encrypt and decrypt commands and telemetry using respective communication security varieties for host and hosted users, allowing private reconfiguration of payloads and secure data transmission across different frequency bands.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single satellite controller manages all payload switching and control, then device complexity is reduced, but resource allocation privacy and data security are compromised

Engineering Contradiction:
Improvecontroller structureVSAvoidresource allocation privacy
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The patent divides the single satellite controller into multiple independent controllers (host controller and hosted controllers). Each controller has its own secure processing space, allowing resource allocation and control operations to be segmented and isolated. This segmentation enables privacy protection for resource allocation while maintaining overall system functionality through coordinated control among multiple controllers.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If multiple independent controllers are implemented for resource allocation privacy, then data security and privacy are improved, but device complexity increases

Engineering Contradiction:
Improvedata privacyVSAvoidcontroller structure
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent merges multiple independent controllers into a unified payload system where host and hosted controllers operate together. The controllers share common interfaces and coordination mechanisms, allowing them to function as an integrated system while maintaining individual privacy boundaries. This merging approach enables multiple controllers to work together without proportionally increasing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If encryption is applied to all commands and telemetry, then security is improved, but processing time and operational complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies encryption selectively rather than uniformly across all data streams. Different encryption schemes are applied to different types of data (host commands, hosted commands, telemetry) based on their security requirements. This local quality approach ensures that security is strengthened where needed while minimizing the processing overhead and time loss associated with encryption operations.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11290176B2Facilitating satellite operations with secure enclave for hosted payload operations
Publication Date: 2022.03.29 THE BOEING CO
  • US11290176B2 patent drawing
  • US11290176B2 patent drawing
  • US11290176B2 patent drawing

AI summary

Systems, methods, and apparatus for commercial satellite operations with secure enclave for payload operations are disclosed. In one or more embodiments, the disclosed method comprises generating, by a secure enclave of a host satellite operation center (SOC), hosted commands according to service specifications for at least one hosted user. The method further comprises generating, by a SOC operation portion of the host SOC, host commands according to service specifications for a host user. Also, the method comprises transmitting, by the host SOC, the host commands and the hosted commands to a vehicle. In addition, the method comprises reconfiguring a host/hosted payload on the vehicle according to the host commands and the hosted commands. Additionally, the method comprises generating, by the host/hosted payload, host telemetry and hosted telemetry. Also, the method comprises transmitting, by the vehicle, the host telemetry and the hosted telemetry to the host SOC.