On the security of aeronautical datalink communications: Problems and solutions
Bibliographic record
Abstract
Numerous protocols allow modern aircraft to communicate with ground entities over wireless networks, including the so-called Datalink digital communications protocols such as ACARS and FANS-1/A. Among other benefits, they greatly enhance automation and allow communication between embedded avionics and aircraft components with ground infrastructure. Unfortunately, none of these protocols incorporate any form of message authentication or confidentiality. To date, no security counter-measures have been proposed to address this with the exception of the ARINC 823 ACARS Message Security (AMS) standard currently employed by the US Air Force to communicate with the Federal Aviation Authority (FAA) air traffic controllers. In this paper, we present a threat analysis of the security flaws in the context of modern usage Datalink communications in aviation. To do so, we first describe how Software Defined Radios (SDR) have made easy to mount impersonation and message spoofing attack on both ACARS and FANS1/A datalink protocols. We then evaluate the potential impact of such attacks on both aircraft safety and air traffic management. To lend credence to our analysis, we describe a proof-of-concept implementation of this attack with a Universal Software Radio Project (USRP) SDR. Finally, we studied the viability of widely adopting AMS as an authentication solution by analyzing its real-world impact in terms of frequency congestion. We show that the widespread adoption of AMS, or an equivalent solution, by all commercial aircrafts would be sustainable.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame machine prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.
Distilled classifier scores by category (both heads)
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.005 | 0.012 |
| Meta-epidemiology (narrow) | 0.001 | 0.001 |
| Meta-epidemiology (broad) | 0.001 | 0.001 |
| Bibliometrics | 0.003 | 0.002 |
| Science and technology studies | 0.003 | 0.007 |
| Scholarly communication | 0.007 | 0.018 |
| Open science | 0.002 | 0.004 |
| Research integrity | 0.007 | 0.007 |
| Insufficient payload (model declined to judge) | 0.003 | 0.001 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".