Presentation is loading. Please wait.

Presentation is loading. Please wait.

Feb 2009 Introducing ARTIST - Airbus Deutschland GmbH - TBCEI33 Introducing ARTIST Trust and Identification Aircraft Security Presented by Michel Messerschmidt.

Similar presentations


Presentation on theme: "Feb 2009 Introducing ARTIST - Airbus Deutschland GmbH - TBCEI33 Introducing ARTIST Trust and Identification Aircraft Security Presented by Michel Messerschmidt."— Presentation transcript:

1 Feb 2009 Introducing ARTIST - Airbus Deutschland GmbH - TBCEI33 Introducing ARTIST Trust and Identification Aircraft Security Presented by Michel Messerschmidt Aircraft Information System Security Engineer

2 © AIRBUS DEUTSCHLAND GMBH. All rights reserved. Confidential and proprietary document. Feb 2009Introducing ARTIST - Airbus Deutschland GmbH - TBCEI33Page 2 Introducing... ARTIST A unique, electronic Vehicle Identification Number (VIN) for the lifetime of the aircraft An onboard Certificate Authority (CA) providing digital certificates and PKI services Onboard validation of all certificates against Certipath (without the need for ground communication) Provide services for all aircraft systems and applications ARTIST consists of two modules... to keep the critical part small and simple, while providing full services in a flexible way ARTIST = Aircraft Root of Trust and Identification System ARTIST

3 © AIRBUS DEUTSCHLAND GMBH. All rights reserved. Confidential and proprietary document. Feb 2009Introducing ARTIST - Airbus Deutschland GmbH - TBCEI33Page 3 Introducing... TIM ARTIST TIM Private Storage - VIN - Aircraft root private key Trusted Storage - Trusted public certificates Trusted Service - Processor - OS / Firmware - RNG - Algorithms API I/F TIM = Trusted Identity Module Non-modifiable and non-removable (without destruction) for the lifetime of the aircraft Contains the VIN An aircraft root certificate (i.e. a CA certificate) and private key as the root of trust for all aircraft purposes. signed by a ground CA that is cross-certified by Certipath. Trusted public information to validate the aircraft root certificate (e.g. the signing certificates of the ground CA and Certipath) Hardware and Firmware to facilitate all sensitive cryptographic operations (i.e. involving the private key) within TIM No access to Private Storage from outside of TIM

4 © AIRBUS DEUTSCHLAND GMBH. All rights reserved. Confidential and proprietary document. Feb 2009Introducing ARTIST - Airbus Deutschland GmbH - TBCEI33Page 4 Introducing... SARCASM SARCASM = Secure Aircraft Root Certificate Authority Services Module A centralized onboard certificate authority providing digital certificates and PKI services A non-volatile CA storage for public keys and certificates Separate, but identical services for all aircraft domains to ensure domain separation An isolated Secure TRUsted Power & Programming Interface (STRUPPI) for maintenance access to all services that require authentication ARTIST SARCASM ACD CA Service - Processing - Algorithms CA Storage - Certificates - Certificate Revocation Lists AISD CA Service - Processing - Algorithms PIESD CA Service - Processing - Algorithms TIM API I/F API I/F API I/F API I/F STRUPPI

5 © AIRBUS DEUTSCHLAND GMBH. All rights reserved. Confidential and proprietary document. Feb 2009Introducing ARTIST - Airbus Deutschland GmbH - TBCEI33Page 5...putting it all together... ARTIST SARCASM ACD CA Service - Processing - Algorithms CA Storage - Certificates - Certificate Revocation Lists AISD CA Service - Processing - Algorithms PIESD CA Service - Processing - Algorithms TIM Private Storage - VIN - Aircraft root private key Trusted Storage - Trusted public certificates Trusted Service - Processor - OS / Firmware - RNG - Algorithms API I/F API I/F STRUPPI API I/F API I/F

6 © AIRBUS DEUTSCHLAND GMBH. All rights reserved. Confidential and proprietary document. Feb 2009Introducing ARTIST - Airbus Deutschland GmbH - TBCEI33Page 6 Finally... services SARCASM public API services include: Aircraft identification (using VIN) Validation of certificates (from onboard systems and external entities) Verification of signatures Generation of keys for aircraft systems and applications (TBC) Data signatures (TBC, requires a second key pair and certificate in TIM) SARCASM maintenance STRUPPI services include: Issuance of certificates for aircraft systems and applications Processing of certificate requests Revocation of certificates Generation and publication of certificate revocation lists for onboard certificates Storage and management of certificates and certificates revocation lists from external entities (.e.g. airline ground services, airport services)

7 © AIRBUS DEUTSCHLAND GMBH. All rights reserved. Confidential and proprietary document. Feb 2009Introducing ARTIST - Airbus Deutschland GmbH - TBCEI33Page 7 © AIRBUS DEUTSCHLAND GMBH. All rights reserved. Confidential and proprietary document. This document and all information contained herein is the sole property of AIRBUS DEUTSCHLAND GMBH. No intellectual property rights are granted by the delivery of this document or the disclosure of its content. This document shall not be reproduced or disclosed to a third party without the express written consent of AIRBUS DEUTSCHLAND GMBH. This document and its content shall not be used for any purpose other than that for which it is supplied. The statements made herein do not constitute an offer. They are based on the mentioned assumptions and are expressed in good faith. Where the supporting grounds for these statements are not shown, AIRBUS DEUTSCHLAND GMBH will be pleased to explain the basis thereof. AIRBUS, its logo, A300, A310, A318, A319, A320, A321, A330, A340, A350, A380, A400M are registered trademarks.


Download ppt "Feb 2009 Introducing ARTIST - Airbus Deutschland GmbH - TBCEI33 Introducing ARTIST Trust and Identification Aircraft Security Presented by Michel Messerschmidt."

Similar presentations


Ads by Google