IP Library Granted Patent US 10,409,991
Granted Patent B2
US 10,409,991 · App. 15/382,947 · Granted Sep 10, 2019

Technique for secure data loading to a system component

Inventors: Maxim Salomon (Hamburg, DE); Timo Warns (Hamburg, DE)
Assignee: AIRBUS CYBERSECURITY GMBH
G06F21/572G06F9/4406G06F13/385G06F13/4022G06F21/51G06F21/57G06F21/64G06F21/74G06F21/79G06F21/85H04L9/3247G06F2221/031G06F2221/2105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,409,991
App. No.
15/382,947
Granted
Sep 10, 2019
Kind
B2
Abstract

A USB device for secure data loading to a system component, such as of an aircraft. The USB device is operable in a mass storage mode and in a non-mass storage mode. The USB device initially operates in the non-mass storage mode upon startup and comprises a storage for storing data to be loaded to the system component, a processor and a memory, wherein the memory contains instructions executable by the processor such that the USB device is operable to perform a security check on the data to be loaded to the system component, and switch, upon the security check, from the non-mass storage mode to the mass storage mode to provide the data for loading to the system component.

Claims (41)

1. A USB device for secure data loading to a system component, the USB device being configured to operate in a mass storage mode wherein the USB device is detectable by the system component as a USB mass storage device and in a non-mass storage mode wherein the USB device is not yet detectable by the system component as a mass storage device, the USB device initially operating in the non-mass storage mode upon startup and comprising:

a storage for storing data to be loaded to the system component via the mass storage mode:

a processor and a memory, the memory containing instructions executable by the processor such that the USB device is configured to:

perform, independently of the system component, a security check on the data to be loaded from the USB device as a USB mass storage device to the system component; and

switch, upon the security check, from the non-mass storage mode to the mass storage mode to provide the data for loading to the system component by the system component mounting to a file system of the USB device in the mass storage mode;

wherein performing the security check on the data is automatic on startup of the USB device when the USB device is plugged into the system component, and includes at least one of:

checking the data for malicious software,

applying a cryptographic signature check on the data,

verifying a correct version of the data, and

deleting files having non-allowed file properties from the data.

2. The USB device of claim 1 , wherein the USB device is a USB stick.

3. The USB device of claim 1 , wherein the memory further contains instructions executable by the processor such that the USB device is operable to:

switch from the non-mass storage mode to the mass storage mode only if the security check has been successful.

4. The USB device of claim 1 , wherein the USB device comprises a visual indicator, and wherein the memory further contains instructions executable by the processor such that the USB device is configured to:

provide a visual indication using the visual indicator indicating a result of the security check.

5. The USB device of claim 1 , wherein the memory further contains instructions executable by the processor such that the USB device is configured to:

provide a web interface via a host computer separate from the system component for advance configuration of the security check.

6. The USB device of claim 1 , wherein the memory further contains instructions executable by the processor such that the USB device is configured to:

retrieve the data from a data loading repository via a secure connection; and

store the retrieved data in the storage.

7. The USB device of claim 1 , wherein the memory further contains instructions executable by the processor such that the USB device is configured to:

retrieve information for verifying the correct version of the data from a configuration database via a secure connection.

8. The USB device of claim 6 , wherein the USB device comprises an I/O interface and wherein the secure connection is established via the I/O interface.

9. The USB device of claim 8 , wherein the I/O interface is a general-purpose input/output (GPIO) interface, wherein the GPIO interface is connected to a Wi-Fi module via a daughter board, and wherein the secure connection is established via the Wi-Fi module.

10. The USB device of claim 6 , wherein the USB device is connected to a host computer and wherein the secure connection is established via the host computer.

11. A method for secure data loading to a system component using a USB device for storing data to be loaded to the system component, the USB device being operable in a mass storage mode wherein the USB device is detectable by the system component as a USB mass storage device and in a non-mass storage mode wherein the USB device is not yet detectable by the system component as a mass storage device, the USB device initially operating in the non-mass storage mode upon startup, the method comprising:

performing, by the USB device and independently of the system component, a security check on the data stored on the USB device and to be loaded from the USB device as a USB mass storage device to the system component; and

switching, by the USB device, upon the security check, from the non-mass storage mode to the mass storage mode to provide the data for loading to the system component by the system component mounting to a file system of the USB device in the mass storage mode;

wherein performing the security check on the data is automatic on startup of the USB device when the USB device is plugged into the system component, and includes at least one of:

checking the data for malicious software,

applying a cryptographic signature check on the data,

verifying a correct version of the data, and

deleting files having non-allowed file properties from the data.

12. A non-transitory computer-readable medium comprising executable instructions stored thereon which, when executed on a USB device, configures the USB device to carry out a method for secure data loading to a system component using a USB device for storing data to be loaded to the system component, the USB device being operable in a mass storage mode wherein the USB device is detectable by the system component as a USB mass storage device and in a non-mass storage mode wherein the USB device is not vet detectable by the system component as a mass storage device, the USB device initially operating in the non-mass storage mode upon startup, the method comprising:

performing, by the USB device and independently of the system component, a security check on the data to be loaded from the USB device as a USB mass storage device to the system component; and

switching, by the USB device, upon the security check, from the non-mass storage mode to the mass storage mode to provide the data for loading to the system component by the system component mounting to a file system of the USB device in the mass storage mode;

wherein performing the security check on the data is automatic on startup of the USB device when the USB device is plugged into the system component, and includes at least one of:

checking the data for malicious software,

applying a cryptographic signature check on the data,

verifying a correct version of the data, and

deleting files having non-allowed file properties from the data.

Assignments (3)
CHANGE OF NAME Recorded Jun 13, 2019
From: CASSIDIAN CYBERSECURITY GMBH
To: AIRBUS CYBERSECURITY GMBH
Reel/Frame 049457/0831 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2017
From: WARNS, TIMO
To: AIRBUS OPERATIONS GMBH
Reel/Frame 041203/0939 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2017
From: SALOMON, MAXIM
To: CASSIDIAN CYBERSECURITY GMBH
Reel/Frame 041661/0045 →
Priority Claims (1)
EP 15201028 · Dec 18, 2015 · regional
Continuity (1)
Related Publication 20170177871A1 · Jun 22, 2017