The solution addresses the risk of reduced confidentiality of air missions and the presence of “fake” ADS-B entities by applying cross-domain solution (CDS) techniques and principles of zero trust architectures (ZTA). Both approaches follow a data-centric security model. ZTA is a cybersecurity paradigm that moves defences from static, network-based perimeters to focus on users, assets, and resources, assuming no implicit trust is granted based solely on physical or network location. Current ADS-B broadcasts do not follow this approach, as all data is visible to everyone.
The solution applies ZTA principles, such as data loss prevention, in combination with package-based communication systems to enhance confidentiality. CDS, using security labels (STANAG 4778), controls data flow between different security domains (high and low) at NATO or Eurocontrol atm headquarters.
Key operational steps:
Step 1 – Aircraft authentication:
-
Establishment of trust authority: Ground-based authority manages entity authentication. This may include new authentication services such as Galileo open service navigation message authentication (OSNMA).
-
Establishment of authorised ADS-B receivers: Ground and space-based receivers are registered.
-
Entity confidentiality categories: Entities are classified by confidentiality (military higher than civil).
-
Conditional authorisation: ADS-B transmitters are authorised according to their confidentiality category.
Step 2 – ADS-B segmentation:
-
Public segment: App providers collect and publish ADS-B data.
-
Civil atm segment: Civil aircraft broadcast to authorised ground/space receivers.
-
Military atm segment: Military aircraft broadcast to authorised receivers.
-
Cross-segmentation/domain solutions: Control and transfer between segments use CDS or related services.
Step 3 – ADS-B data conditional authorisation:
-
Authorised reception: ADS-B messages are received by authorised receivers.
-
Valid message tagging/labeling: Valid messages are tagged and labelled for further transmission via the atm network.
-
Invalid message tagging/labeling: Invalid messages are tagged and labelled accordingly.
-
Invalid entity broadcasting: Invalid entities are broadcast (ID) to all receivers in the civil and military segments.
Step 4 – Securing ADS-B data (protected information):
-
Asymmetric key generation: Trust authority generates keys using elliptic curve cryptography (ECC) and pseudorandom generators, distributing them to authorised civil and military entities.
-
Symmetric key generation: Keys for individual flights are generated within ADS-B message size constraints.
-
Symmetric key encryption: Keys are encrypted, split into parts, and transmitted across multiple mode S messages.
-
Symmetric key transfer: Key transfer messages mirror ADS-B structure to ensure compatibility.
-
Encryption of ADS-B data/tags: Specific or all ADS-B messages onboard military aircraft are encrypted using the symmetric key.
Step 5 – ADS-B data analytics:
-
Entity verification: Received data is checked against the entity and trust authority register.
-
Data validation: Integrity of data is verified using machine learning to detect spoofing or ghost ADS-B entities.