Aerospace and Electronic Systems Magazine November 2017 - 30

Datalink Security in LDACS for Air Traffic Management

Figure 7.

Impact of fate sharing. The graph displays the probability of the security
verification to fail due to residual bit errors. The security verification
fails if there is one or more bit errors in the data covered by the security
data. The smallest proposed security coverage spans DLS fragments;
the largest security coverage spans the entire multiframe. Slot-based
and resource allocation-based security lie between these extremes. Error
recovery is performed by the DLS by retransmitting DLS fragments.
The shaded area identifies the worst-case increase in failure probability
due to fate sharing.

QUANTIFYING SECURITY OVERHEAD
Security in the DLS does not suffer from bit errors, because those
errors are corrected prior to security validation. However, DLS
overhead increases with the bit error rate, because finer fragmentation is required to achieve the desired fragment error rate of 5%
or lower. The subnetwork-based approach adds security overhead
only once to each packet. It is therefore instructive to investigate
security overhead in the datalink level-based approach against
overhead in the subnetwork-based approach.
Figure 8 displays the increase of security overhead under an
increasing residual bit error rate, assuming s = 128 bits of security
data per fragment or packet (shaded area in Figure 8). For bit error rates worse than 5 × 10−6, the security overhead of the datalink
layer-based approach increases significantly due to the smaller
fragment sizes and more frequent retransmissions.

QUALITATIVE ANALYSIS
Making LDACS more robust in the physical layer requires additional infrastructure: multiple ground stations, directed antennas,
or secondary datalinks. Having secondary datalinks as fallbacks
is the approach foreseen in the aeronautical telecommunications
network by SESAR. However, additional security functionality in
the datalink layer is still desirable to build additional layers of defense in depth.
Security at the multiframe level is problematic when it comes
to error recovery, latency requirements, and trust relationships in
the forward link. The theoretically good overhead ratio does not
compensate for these drawbacks. In addition, the reverse link cannot be protected by this approach, because multiple aircraft are
30

Figure 8.

Security overhead of subnetwork (SNDCP)-based security vs. DLSbased security. The shaded area identifies the increase of security
overhead due to DLS fragmentation and retransmissions. Nonsecurity
overhead is not displayed. For details on nonsecurity overhead, see [42].

consecutively contributing data to the multiframe structure, making it impossible for a single aircraft to secure all data prior to
its transmission. The same drawbacks hold for the slot-level approach.
Resource allocations are assigned to each aircraft separately.
Security at the resource allocation level would therefore circumvent the limited trust relationship problem. However, like the multiframe-based approach and the slot-based approach, this is not attractive due to large security validation failure probabilities caused
by residual bit errors.
Of the two remaining options, security in the DLS and security
in the subnetwork layer, the latter is more attractive due to its lower
overhead. A minor drawback of this approach is the comparably
high placement in the LDACS protocol stack. Security validation
can only happen when the subnetwork packet has been completely
received. In consequence, security violations are detected later
compared to implementation options lower in the protocol stack.
However, this does not decrease the level of security. Both approaches support per-application trust relationships as authentication, confidentiality, and integrity are applied on the packet level.
A summary of our findings for all implementation options
is displayed in Table 2. Each implementation option is matched
against the security objectives derived from the security requirements identified above.

PROPOSED INTEGRATION OF SECURITY FUNCTIONS INTO
THE PROTOCOL STACK
The LME sees to the configuration, resource management, and
mobility management of aircraft connected to a LDACS ground
station. Therefore, we claim that it is the appropriate place in the
protocol stack to place the security management functions (F_SecFunc). The LME has access to all sublayers of the system; therefore, it is natural to add the auditing function (F_Audit) here. The

IEEE A&E SYSTEMS MAGAZINE

NOVEMBER 2017



Table of Contents for the Digital Edition of Aerospace and Electronic Systems Magazine November 2017

No label
Aerospace and Electronic Systems Magazine November 2017 - No label
Aerospace and Electronic Systems Magazine November 2017 - Cover2
Aerospace and Electronic Systems Magazine November 2017 - 1
Aerospace and Electronic Systems Magazine November 2017 - 2
Aerospace and Electronic Systems Magazine November 2017 - 3
Aerospace and Electronic Systems Magazine November 2017 - 4
Aerospace and Electronic Systems Magazine November 2017 - 5
Aerospace and Electronic Systems Magazine November 2017 - 6
Aerospace and Electronic Systems Magazine November 2017 - 7
Aerospace and Electronic Systems Magazine November 2017 - 8
Aerospace and Electronic Systems Magazine November 2017 - 9
Aerospace and Electronic Systems Magazine November 2017 - 10
Aerospace and Electronic Systems Magazine November 2017 - 11
Aerospace and Electronic Systems Magazine November 2017 - 12
Aerospace and Electronic Systems Magazine November 2017 - 13
Aerospace and Electronic Systems Magazine November 2017 - 14
Aerospace and Electronic Systems Magazine November 2017 - 15
Aerospace and Electronic Systems Magazine November 2017 - 16
Aerospace and Electronic Systems Magazine November 2017 - 17
Aerospace and Electronic Systems Magazine November 2017 - 18
Aerospace and Electronic Systems Magazine November 2017 - 19
Aerospace and Electronic Systems Magazine November 2017 - 20
Aerospace and Electronic Systems Magazine November 2017 - 21
Aerospace and Electronic Systems Magazine November 2017 - 22
Aerospace and Electronic Systems Magazine November 2017 - 23
Aerospace and Electronic Systems Magazine November 2017 - 24
Aerospace and Electronic Systems Magazine November 2017 - 25
Aerospace and Electronic Systems Magazine November 2017 - 26
Aerospace and Electronic Systems Magazine November 2017 - 27
Aerospace and Electronic Systems Magazine November 2017 - 28
Aerospace and Electronic Systems Magazine November 2017 - 29
Aerospace and Electronic Systems Magazine November 2017 - 30
Aerospace and Electronic Systems Magazine November 2017 - 31
Aerospace and Electronic Systems Magazine November 2017 - 32
Aerospace and Electronic Systems Magazine November 2017 - 33
Aerospace and Electronic Systems Magazine November 2017 - 34
Aerospace and Electronic Systems Magazine November 2017 - 35
Aerospace and Electronic Systems Magazine November 2017 - 36
Aerospace and Electronic Systems Magazine November 2017 - 37
Aerospace and Electronic Systems Magazine November 2017 - 38
Aerospace and Electronic Systems Magazine November 2017 - 39
Aerospace and Electronic Systems Magazine November 2017 - 40
Aerospace and Electronic Systems Magazine November 2017 - 41
Aerospace and Electronic Systems Magazine November 2017 - 42
Aerospace and Electronic Systems Magazine November 2017 - 43
Aerospace and Electronic Systems Magazine November 2017 - 44
Aerospace and Electronic Systems Magazine November 2017 - 45
Aerospace and Electronic Systems Magazine November 2017 - 46
Aerospace and Electronic Systems Magazine November 2017 - 47
Aerospace and Electronic Systems Magazine November 2017 - 48
Aerospace and Electronic Systems Magazine November 2017 - 49
Aerospace and Electronic Systems Magazine November 2017 - 50
Aerospace and Electronic Systems Magazine November 2017 - 51
Aerospace and Electronic Systems Magazine November 2017 - 52
Aerospace and Electronic Systems Magazine November 2017 - 53
Aerospace and Electronic Systems Magazine November 2017 - 54
Aerospace and Electronic Systems Magazine November 2017 - 55
Aerospace and Electronic Systems Magazine November 2017 - 56
Aerospace and Electronic Systems Magazine November 2017 - 57
Aerospace and Electronic Systems Magazine November 2017 - 58
Aerospace and Electronic Systems Magazine November 2017 - 59
Aerospace and Electronic Systems Magazine November 2017 - 60
Aerospace and Electronic Systems Magazine November 2017 - 61
Aerospace and Electronic Systems Magazine November 2017 - 62
Aerospace and Electronic Systems Magazine November 2017 - 63
Aerospace and Electronic Systems Magazine November 2017 - 64
Aerospace and Electronic Systems Magazine November 2017 - Cover3
Aerospace and Electronic Systems Magazine November 2017 - Cover4
http://www.brightcopy.net/allen/aesm/34-2s
http://www.brightcopy.net/allen/aesm/34-2
http://www.brightcopy.net/allen/aesm/34-1
http://www.brightcopy.net/allen/aesm/33-12
http://www.brightcopy.net/allen/aesm/33-11
http://www.brightcopy.net/allen/aesm/33-10
http://www.brightcopy.net/allen/aesm/33-09
http://www.brightcopy.net/allen/aesm/33-8
http://www.brightcopy.net/allen/aesm/33-7
http://www.brightcopy.net/allen/aesm/33-5
http://www.brightcopy.net/allen/aesm/33-4
http://www.brightcopy.net/allen/aesm/33-3
http://www.brightcopy.net/allen/aesm/33-2
http://www.brightcopy.net/allen/aesm/33-1
http://www.brightcopy.net/allen/aesm/32-10
http://www.brightcopy.net/allen/aesm/32-12
http://www.brightcopy.net/allen/aesm/32-9
http://www.brightcopy.net/allen/aesm/32-11
http://www.brightcopy.net/allen/aesm/32-8
http://www.brightcopy.net/allen/aesm/32-7s
http://www.brightcopy.net/allen/aesm/32-7
http://www.brightcopy.net/allen/aesm/32-6
http://www.brightcopy.net/allen/aesm/32-5
http://www.brightcopy.net/allen/aesm/32-4
http://www.brightcopy.net/allen/aesm/32-3
http://www.brightcopy.net/allen/aesm/32-2
http://www.brightcopy.net/allen/aesm/32-1
http://www.brightcopy.net/allen/aesm/31-12
http://www.brightcopy.net/allen/aesm/31-11s
http://www.brightcopy.net/allen/aesm/31-11
http://www.brightcopy.net/allen/aesm/31-10
http://www.brightcopy.net/allen/aesm/31-9
http://www.brightcopy.net/allen/aesm/31-8
http://www.brightcopy.net/allen/aesm/31-7
https://www.nxtbookmedia.com