UAV Pre-Boot Permission Validation Using a UEFI Shell

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security protocols for unmanned aerial vehicles (UAVs) are vulnerable to data tampering and hacking, particularly at the application level, which can compromise flight permissions and safety regulations such as No-Permission-No-Takeoff (NPNT).

Innovation Solution

Implementing a Unified Extensible Firmware Interface (UEFI) shell that downloads and validates a permission file from a server over a network before booting the operating system, ensuring that operational parameters are securely passed to the operating system and applications, thereby controlling UAV flight within predefined boundaries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security protocols are implemented at the application level, then flight permission control is achieved, but the system becomes vulnerable to data tampering and hacking

Engineering Contradiction:
Improveflight permission securityVSAvoidvulnerability to tampering and hacking
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements permission validation at the UEFI shell level before the operating system boots. The permission file is downloaded and validated in advance during the pre-boot phase, establishing security constraints before any application-level code can execute. This preliminary action ensures that even if applications are compromised, the fundamental flight permission constraints cannot be violated.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces the UEFI shell as an intermediary layer between the hardware and the operating system applications. This intermediary validates permission files and enforces operational parameters before allowing the OS to run, creating a security barrier that protects against application-level tampering while maintaining controlled access to flight functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If permission validation is performed at the UEFI shell level, then security against tampering is improved, but the system complexity increases

Engineering Contradiction:
Improvepermission validation securityVSAvoidboot process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the existing UEFI shell environment, which is a standard component in modern computing systems, to perform permission validation. By utilizing this pre-existing universal platform, the patent avoids creating a completely new security subsystem, thereby reducing overall system complexity while still achieving enhanced security through multi-functional use of the UEFI shell.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12093698B2Dynamic pre-boot configuration for flight systems
Publication Date: 2024.09.17 ARINC INC
  • US12093698B2 patent drawing
  • US12093698B2 patent drawing
  • US12093698B2 patent drawing

AI summary

An unmanned aerial vehicle (UAV) is described. The UAV includes functions such as geo-location-based approvals, targeted system updates and dynamic rule enforcements, authentical, internet protocol (IP) whitelisting, and application control. The functions are controlled from the firmware level. The functions may ensure a highly secure and controlled embedded system on the UAV in the event an application of the UAV is compromised by a third party. UEFI is used to provide a tamper proof way of enforcing permitted flights on authorized equipment.