IP Library › Granted Patent US 12,652,160
Granted Patent B2
US 12,652,160 · App. 18/011,725 · Granted Jun 9, 2026

Anonymous, authenticated and private satellite tasking system

Inventors: Gerardo Gabriel Richarte (Caba, AR); Emiliano Kargieman (Buenos Aires, AR)
Assignee: Urugus S.A.
H04L9/0819H04B7/18513H04B7/18593H04L9/0861H04L9/321
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,652,160
App. No.
18/011,725
Granted
Jun 9, 2026
Kind
B2
Abstract

Systems, methods and devices for implementing cryptographic and security-in-depth techniques on-board spacecrafts or satellites are provided, to allow users to task activities or retrieve satellite data from the satellite system in an anonymous, secure, safe, and private manner, such that no other user sharing the satellite system resources can know what has been tasked or transmitted to the ground. Considerable advantages can be realized by providing spacecraft or satellite systems with a substantial capacity of applying security-in-depth and cryptographic techniques and protocols to data and requests, based on autonomous tasking, allowing a secure, safe and private use of spacecraft or satellite resources.

Claims (64)

1 . A private satellite tasking system comprising:

a satellite comprising computer-readable media, one or more sensors, and one or more on-board computers;

one or more application programming interfaces on-board the satellite configured to expose satellite resources to the one or more on-board computers; and

a programming interface broker on-board the satellite configured to authenticate and authorize the one or more application programming interfaces;

the computer-readable media including one or more instructions, that when executed by the one or more on-board computers, cause the one or more on-board computers to perform acts comprising:

determining, by the programming interface broker, permissions granted to a user of one or more users;

assigning, based at least in part on the permissions, a user on-board computer of the one or more on-board computers to each of the one or more users or each user profile associated with each of the one or more users;

determining, based at least in part on the permissions, one or more satellite resources of the satellite to assign to the user on-board computer; and

assigning, based at least in part on the permissions, at least one application programming interface of the one or more application programming interfaces to the user on-board computer to expose the one or more satellite resources of the satellite to the user on-board computer to provide an exclusive operative control of the one or more satellite resources of the satellite to the user on-board computer, for an extent of an operating window assigned to each of the one or more users;

wherein the at least one application programming interface of the one or more application programming interfaces is configured to implement cryptographic and security-in-depth techniques with respect to one or more messages received from and/or transmitted to one or more users while the satellite is in orbit.

2 . The system of claim 1 , wherein the acts further comprise determining, based at least in part on the one or more messages, the operating window for the user, and assigning the one or more satellite resources to the user based at least in part on the operating window, wherein the operating window is further determined by defining one or more of a period of time, a geographical area, an extent in space, a number of satellites, a resource allotment, or any combination of these.

3 . The system of claim 2 , wherein the one or more messages comprise signed and/or encrypted request and implementing the cryptographic and security-in-depth techniques comprises the steps executed by at least one of the one or more on-board computers of:

verifying an integrity of the one or more messages;

authenticating an identity of the one or more users; and/or

decrypting the encrypted request as a decrypted request;

and the acts further comprise:

determining, based at least in part on the decrypted request, one or more tasks to perform; and

performing, based at least in part on the permissions and on the operating window, the one or more tasks.

4 . The system of claim 3 , wherein the one or more tasks comprises:

capturing payload data;

encrypting and/or signing the payload data as encrypted and/or signed payload data; and

transmitting the encrypted and/or signed payload data to the user.

5 . The system of claim 4 , wherein the acts further comprise:

analyzing the payload data to generate analysis results;

encrypting and/or signing the analysis results as encrypted and/or signed analysis results; and

transmitting the encrypted and/or signed analysis results to the user;

wherein the payload data comprises satellite data captured by the satellite or by one or more satellites of a constellation of satellites.

6 . The system of claim 1 , wherein the user on-board computer is at least one of a physical machine, a virtual machine, a full virtual machine, a lightweight virtual machine, an operating system user profile, a capabilities configuration setting, or an application container.

7 . The system of claim 1 , wherein the user on-board computer is a first user onboard computer configured to persist its state and save or discard its status to be carried from execution to execution before handing in the one or more satellite resources to a second user on-board computer, or is configured to be stateless and rely on an external mechanism to load configurations and parameters before handing in the one or more satellite resources to a second user on-board computer.

8 . The system of claim 1 , wherein the one or more satellite resources comprise hardware and software resources including at least one of payload systems, application containers, virtual on-board computers, physical on-board computers, satellite modules, operating windows, satellite tasks, requests, tasking requests, data requests, storage, the one or more sensors, supplies used by a space-based manufacturing facility, data or information that is stored, collected or processed, upload or download bandwidth capacity, or cryptographic operations.

9 . The system of claim 1 , wherein the acts further comprise:

implementing obfuscation processes by setting a global satellite state or a satellite resource state in a configuration configured to impede collecting or accessing data or metadata derived or generated from the use of the satellite or the one or more satellite resources by the user on-board computer before releasing the satellite or the one or more satellite resources from the user on-board computer to a second user on-board computer.

10 . The system of claim 1 , wherein the acts further comprise:

implementing remote attestation protocols by showing that software on board the satellite has not been changed, by any user on-board computer, to a state different from a known and accepted state.

11 . The system of claim 1 , wherein implementing the cryptographic and security-in-depth techniques comprises:

generating, by the satellite, a cryptographic key; and

distributing the cryptographic key to the one or more users.

12 . The system of claim 11 , wherein the cryptographic key comprises a public portion and a private portion; and wherein the private portion of the cryptographic key is stored in the satellite and the public portion of the cryptographic key is distributed to the one or more users.

13 . The system of claim 1 , wherein the cryptographic and security-in-depth techniques comprise at least one of encrypting the one or more messages, decrypting the one or more messages, sealing the one or more messages, unsealing the one or more messages, verifying an integrity of the one or more messages, authenticating an identity of the one or more users, virtualization, software or hardware isolation, compartmentalization, access control, resource allocation, or generation, use and verification of authentication data; wherein the one or more messages comprise at least one of cryptographic keys, requests, tasks, instructions, metadata, or satellite data.

14 . The system of claim 1 , wherein the permissions are included in the one or more messages, and comprise a set of permissions assigned to the user, and the acts further comprise:

assigning, based at least in part on the set of permissions, at least one of the one or more satellite resources, one or more satellites of a constellation of satellites, or one or more additional satellite resources of the one or more satellites, to the user on-board computer, and/or storing the set of permissions to be used at a later time.

15 . A method under control of one or more processors in a satellite, the method comprising:

receiving and/or transmitting one or more messages from and/or to one or more users while the satellite is in orbit;

implementing, by a first application programming interface, cryptographic and security-in-depth techniques with respect to the one or more messages received from and/or transmitted to the one or more users while the satellite is in orbit;

generating by a programming interface broker, based on received and/or stored permissions, a description of permissions and privileges associated with each of the one or more users;

assigning, based at least in part on the description, a user onboard computer to each of the one or more users or user profiles associated with each of the one or more users;

determining, based at least in part on the description, one or more satellite resources of the satellite to assign to a user on-board computer; and

assigning, based at least in part on the description, one or more second application programming interfaces to the user on-board computer to expose the one or more satellite resources of the satellite to the user on-board computer to provide an exclusive operative control of the one or more satellite resources of the satellite to the user on-board computer, for an extent of an operating window assigned to each of the one or more users.

16 . The method of claim 15 , further comprising determining, based at least in part on the one or more messages, the operating window for the user on-board computer, and further assigning the one or more satellite resources to the user on-board computer based at least in part on the operating window, wherein the operating window is further determined by defining one or more of a period of time, a geographical area, an extent in space, a number of satellites, a resource allotment, or any combination of these.

17 . The method of claim 16 , wherein implementing the cryptographic and security-in-depth techniques comprises:

verifying an integrity of the one or more messages;

authenticating an identity of the one or more users; and

the method further comprises:

determining the operating window for the user on-board computer based at least in part on the one or more messages.

18 . The method of claim 15 , wherein the one or more messages are encrypted, wherein the permissions are included in the one or more messages and comprise a set of permissions, and implementing the cryptographic and security-in-depth techniques comprises:

decrypting the one or more messages; and

determining, based at least in part on the set of permissions, the one or more satellite resources to be assigned to the one or more users or one or more tasks to be performed by the satellite.

19 . The method of claim 18 , further comprising:

encrypting and/or signing one or more additional messages comprising at least one of raw satellite data, processed satellite data, analysis results or metadata to generate encrypted and/or signed one or more messages; and

transmitting the encrypted and/or signed one or more messages to the one or more users.

20 . The method of claim 15 , wherein implementing the cryptographic and security-in-depth techniques comprises:

generating a cryptographic key;

distributing the cryptographic key to the one or more users; and

receiving an encrypted message sent by the one or more users, wherein the encrypted message is encrypted with the cryptographic key.

Assignments (2)
SECURITY INTEREST Recorded Apr 12, 2024
From: URUGUS S.A.
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 067085/0242 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2022
From: RICHARTE, GERARDO GABRIEL; KARGIEMAN, EMILIANO
To: URUGUS S.A.
Reel/Frame 062161/0599 →
Continuity (2)
Provisional Application 63044892 · Jun 26, 2020
Related Publication 20230231699A1 · Jul 20, 2023
References Cited (9)
US 20150365824A1 · Gustafson · 2015 [cited by examiner]
US 20160056957A1 · Clarke · 2016 [cited by examiner]
US 20190028394A1 · Coleman · 2019 [cited by examiner]
An Architecture for Advanced Networking Technology for Integrating Communications in Space (Year: 2020). [cited by examiner]
Invitation to Pay Fees dtd Sep. 9, 2021 for PCT App No. PCT/US21/38535. [cited by applicant]
The International Search Report and Written Opinion for PCT Application No. PCT/US21/38535, dtd Nov. 17, 2021. [cited by applicant]
Birrane, et al., “An Architecture for Advanced Networking Technology for Integrating Communications in Space,” Published in: 2020 IEEE Aerospace Conference, Aug. 21, 2020, 7 pages. [cited by applicant]
The European Search Report, mailed on Jul. 16, 2024, for European Application No. 21829537.6, a counterpart foreign application of the U.S. Appl. No. 18/011,725, 9 pages. [cited by applicant]
Yuan, et al., “A survey on secure routing protocols for satellite network,” Journal of Network and Computer Applications, ScienceDirect, Jul. 31, 2019, 17 pages. [cited by applicant]