Trusted Mobile Communications for Offline Aviation Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current aviation systems face challenges in establishing the integrity of data from resource-constrained client devices, especially in offline modes where connectivity to the airline back-office system is not available, leading to security vulnerabilities and difficulties in maintaining compliance with rigorous procedural processes.

Innovation Solution

A method and system for trusted mobile communications that provision mobile client systems with security parameters on a per application and per device basis, using a digital notary to establish a chain of trust, allowing access to airplane systems even when offline, and ensuring data integrity through cryptographic verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If custom client devices are used to connect to onboard airplane systems, then functionality and connectivity are improved, but security integrity and compliance verification become difficult to establish

Engineering Contradiction:
Improveconnectivity capabilityVSAvoidsecurity integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary security assessments and provisions security parameters to client devices before they connect to airplane systems. This includes evaluating device security posture, provisioning appropriate security parameters, and establishing trust relationships in advance, so that when devices connect offline, their integrity has already been verified and documented.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention introduces an intermediary security assessment system that acts as a mediator between client devices and airplane systems. This intermediary evaluates device security, provisions parameters, and creates verifiable trust records that the airplane system can validate without needing continuous network connectivity to the back-office system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If manual data entry processes are used by flight crews and maintenance workers, then system complexity is reduced, but time consumption and error rates increase

Engineering Contradiction:
Improvesystem complexityVSAvoiddata entry efficiency
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The system enables client devices to automatically perform data entry and interaction with airplane systems without requiring manual input from flight crews or maintenance workers. Devices can autonomously access system data, perform transactions, and complete tasks, dramatically improving productivity while the system maintains security through automated parameter verification.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If COTS mobile devices are allowed for user familiarity and cost reduction, then ease of operation and cost are improved, but cyber security vulnerabilities increase

Engineering Contradiction:
Improveuser familiarityVSAvoidcyber security risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system dynamically changes security parameters based on device type, user role, and operational context. COTS devices receive provisioned security parameters tailored to their specific use case, transforming them from vulnerable generic devices into securely configured access points. The system adjusts encryption keys, access permissions, and verification requirements according to the specific device and operational needs.

Inventive Principle:
Principle #35Parameter changes

4Measurement precision

If security parameters are provisioned on a per application and per device basis, then security precision is improved, but device complexity and provisioning overhead increase

Engineering Contradiction:
Improvesecurity verification precisionVSAvoidprovisioning complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments security parameters into discrete, manageable units that can be independently provisioned and verified for each device and application combination. This segmentation allows the system to maintain high security precision by tailoring parameters to specific needs while reducing overall complexity through modular, reusable security configurations that can be automatically managed.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3565216B1System and method for trusted mobile communications
Publication Date: 2023.08.02 THE BOEING CO
  • EP3565216B1 patent drawingFigure 1
  • EP3565216B1 patent drawingFigure 2
  • EP3565216B1 patent drawingFigure 3A

AI summary

Systems and methods for trusted mobile communications are described. A network system provisions a mobile client system with a collection of security parameters on a per application basis and a per device basis. The airplane system provides access to the mobile client system based on the established chain of trust without previously having information about the mobile client system even when the mobile client system and the airplane system are offline with respect to the network system.