Systems and methods for secure communications over broadband datalinks

US10819418B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10819418-B2
Application numberUS-201715498415-A
CountryUS
Kind codeB2
Filing dateApr 26, 2017
Priority dateApr 29, 2016
Publication dateOct 27, 2020
Grant dateOct 27, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems and methods for secure communications over broadband datalinks are provided. In certain implementations, a system for providing secure communications through a communication link includes a first communication unit that includes a processing unit that is configured to execute code that causes the first communication unit to verify messages with a firewall as they are received by the first communication unit; remove encapsulation data that encapsulates a message received from a second communication unit; check a digital signature appended to the message received from a second communication unit through a non-secure communication link; perform an integrity check on the message; and when the message is verified through the digital signature and the integrity check, process the message; wherein removal of the encapsulation data and implementation of the firewall is in a first partition and performance of the integrity check and verification of the digital signature is in a second partition.

First claim

Opening claim text (preview).

The invention claimed is: 1. A system for providing secure communications through an Internet Protocol (IP) communication link, the system comprising: a first communication unit, the first communication unit comprising at least one hardware processing unit that is configured to execute code that causes the first communication unit to: verify avionics messages with a firewall to filter received avionics messages as they are received by the first communication unit from a second communication unit; remove IP information with an IP network stack; remove encapsulation data that encapsulates the avionics messages; check a digital signature appended to the avionics messages; perform an integrity check on the avionics messages; and when the avionics messages are verified through the digital signature and the integrity check, process the avionics messages; wherein removal of the encapsulation data and implementation of the firewall and IP network stack are performed using resources associated with a first avionic partition on the at least one processing unit and performance of the integrity check and verification of the digital signature are performed using resources associated with a second avionic partition on the at least one processing unit, wherein the resources associated with the first avionic partition are separated from the resources associated with the second avionic partition. 2. The system of claim 1 , wherein the first communication unit is avionics on an aircraft. 3. The system of claim 2 , wherein the first communication unit receives the avionics messages from a ground server, wherein the ground server receives the avionics messages from the second communication unit. 4. The system of claim 2 , wherein the second communication system is an operations center. 5. The system of claim 1 , wherein the hardware processing unit is further configured to execute code that scans a format of the avionics messages. 6. The system of claim 5 , wherein the hardware processing unit is further configured to scan a format of an address of the avionics messages to determine what application processes the avionics messages. 7. The system of claim 1 , wherein one or more applications are restricted from executing on one of the first avionic partition on the at least one hardware processing unit and the second avionic partition on the at least one hardware processing unit. 8. The system of claim 1 , wherein the firewall filters out the avionics messages when the avionics messages are not associated with communications initiated by the first communication unit. 9. A method for receiving secure communications through an Internet Protocol (IP) communication link on a first communication unit comprising at least one hardware processing unit, the method comprising: on the first communication unit, verifying an avionics message with a firewall as the avionics message is received by the first communication unit from a second communication unit via the IP communication link, wherein the firewall is configured to filter the receive avionics message; on the first communication unit, removing IP information with an IP network stack; on the first communication unit, removing encapsulation data that encapsulates the avionics message; on the first communication unit, checking a digital signature appended to the avionics message; on the first communication unit, performing an integrity check on the avionics message; and on the first communication unit, when the avionics message is verified through the digital signature and the integrity check, processing the avionics message; wherein removal of the encapsulation data and implementation of the firewall and the IP network stack are processed using resources associated with a first avionic partition on the at least one hardware processing unit and performance of a verification of the digital signature and the integrity check is processed using resources associated with a second avionic partition on the at least one processing unit, wherein the resources associated with the first avionic partition are separated from the resources associated with the second avionic partition. 10. The method of claim 9 , wherein a format of the avionics message is scanned, and a message validation check is performed. 11. The method of claim 9 , wherein the integrity check comprises verifying a cyclical redundancy check appended to the avionics message. 12. The method of claim 9 , further comprising: appending a cyclical redundancy check to a second avionics message; encapsulating the second avionics message for transmission according to a transmission protocol; appending information to the second avionics message according to the transmission protocol; and transmitting the second avionics message through the communication link; wherein the second avionics message is encapsulated in the second avionic partition, and the cyclical redundancy check is appended to the second avionics message in the first avionic partition. 13. The method of claim 12 , wherein transmitting the second avionics message through the communication link comprises transmitting the second avionics message through a ground server, wherein the ground server provides the avionics message to the second communication unit. 14. The method of claim 9 , wherein the second communication unit is an operations center. 15. The method of claim 9 , wherein one or more applications are restricted from executing on one of the first and second avionic partitions. 16. A system for providing secure communications through an Internet Protocol (IP) communication link, the system comprising: a first communication unit, the first communication unit comprising at least one first hardware processing unit that is configured to execute code that causes the first communication unit to: append a cyclical redundancy check to an avionics message; encapsulate the avionics message with encapsulation data for transmission according to a transmission protocol; append IP information to the avionics message; append a digital signature to the avionics message; and transmit the avionics message through the IP communication link; wherein the encapsulation data and IP information are appended using resources associated with a second avionic partition for the at least one first hardware processing unit and the cyclical redundancy check and digital signature are appended to the message using resources associated with a first avionic partition for the at least one first hardware processing unit and the first avionic partition and the second avionic partition are associated with different levels, wherein the resources associated with the first avionic partition on the at least one first hardware processing unit are separated from the resources associated with the second avionic partition on the at least one first hardware processing unit; and a second communication unit, the second communication unit comprising at least one second hardware processing unit that is configured to execute code that causes the second communication unit to: remove the IP information with an IP network stack; remove encapsulation data that encapsulates the avionics message received from the first communication unit; scan a format of the avionics message; perform an integrity check on the avionics message; verify the digital signature appended to the avionics message, wherein the removal of the encapsulation data and the IP information is performed using resources associated with a first avionic partition on the at least one second hardware processing unit and

Assignees

Inventors

Classifications

  • Transmission of traffic-related information between aircraft and ground stations · CPC title

  • Packet or message integrity · CPC title

  • using filters or firewalls · CPC title

  • H04L63/123Primary

    received data contents, e.g. message integrity · CPC title

  • Airborne or Satellite Networks (space-based or airborne stations H04B7/185) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10819418B2 cover?
Systems and methods for secure communications over broadband datalinks are provided. In certain implementations, a system for providing secure communications through a communication link includes a first communication unit that includes a processing unit that is configured to execute code that causes the first communication unit to verify messages with a firewall as they are received by the fir…
Who is the assignee on this patent?
Honeywell Int Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/123. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Oct 27 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).