liu.seSearch for publications in DiVA
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • oxford
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Enhancing Cybersecurity for LDACS: a Secure and Lightweight Mutual Authentication and Key Agreement Protocol
Linköping University, Department of Computer and Information Science, Database and information techniques. Linköping University, Faculty of Science & Engineering.
Linköping University, Department of Computer and Information Science, Database and information techniques. Linköping University, Faculty of Science & Engineering.
Linköping University, Department of Computer and Information Science, Database and information techniques. Linköping University, Faculty of Science & Engineering.ORCID iD: 0000-0002-9829-9287
German Aerosp Ctr DLR, Germany.
Show others and affiliations
2023 (English)In: 2023 IEEE/AIAA 42ND DIGITAL AVIONICS SYSTEMS CONFERENCE, DASC, IEEE , 2023Conference paper, Published paper (Refereed)
Abstract [en]

The aviation industry faces significant challenges due to rising global air travel demand. Frequency saturation in Air Traffic Management (ATM) leads to communication problems, necessitating the enhancement of traditional systems. The Single European Sky ATM Research (SESAR) initiative, backed by the European Commission, aims to digitize ATM, with the L-band Digital Aeronautical Communications System (LDACS) as a key component. LDACS aims to improve communication, enhance surveillance, and optimize airspace usage for safer, more efficient ATM. Although LDACS is protected against most cyberattacks, a critical security objective, anonymity, is currently overlooked. To strengthen LDACS's security, robust authentication mechanisms, Post-Quantum security, and measures to ensure aircraft anonymity are crucial. Therefore, we propose a comprehensive security framework to enhance LDACS's cybersecurity, focusing on mutual authentication and key agreement. The protocol uses Physical Unclonable Function (PUF) for robust mutual authentication and Bit-flipping Key Encapsulation (BIKE) for secure session key establishment utilizing Post-Quantum Cryptography (PQC). This framework ensures anonymity and secure communication between aircraft and ground stations while minimizing message exchange, latency, and data overhead. An informal security analysis confirms our proposed framework's potential to augment the efficiency and security of ATM operations.

Place, publisher, year, edition, pages
IEEE , 2023.
Series
IEEE-AIAA Digital Avionics Systems Conference, ISSN 2155-7195, E-ISSN 2155-7209
Keywords [en]
Aviation Cybersecurity; BIKE; LDACS; PUF; Mutual Authentication and Key Exchange (MAKE)
National Category
Communication Systems
Identifiers
URN: urn:nbn:se:liu:diva-200533DOI: 10.1109/DASC58513.2023.10311307ISI: 001103267600200ISBN: 9798350333572 (electronic)ISBN: 9798350333589 (print)OAI: oai:DiVA.org:liu-200533DiVA, id: diva2:1832754
Conference
IEEE/AIAA 42nd Digital Avionics Systems Conference (DASC), Barcelona, SPAIN, oct 01-05, 2023
Note

Funding Agencies|Trafikverket and Luftfartsverket under Automation Program II; Autonomous Systems and Software Program (WASP)

Available from: 2024-01-30 Created: 2024-01-30 Last updated: 2026-05-12
In thesis
1. Secure Mobility and Authentication Protocols in Heterogeneous Aviation Data Networks
Open this publication in new window or tab >>Secure Mobility and Authentication Protocols in Heterogeneous Aviation Data Networks
2026 (English)Doctoral thesis, comprehensive summary (Other academic)
Abstract [en]

Civil aviation is undergoing a transition towards digital, IP-based air–ground communication systems in order to accommodate increasing air traffic density, improve operational efficiency, and maintain safety-critical services. Within this evolution, technologies such as Controller–Pilot Data Link Communications (CPDLC), the L-band Digital Aeronautical Communications System (LDACS), and the Future Communication Infrastructure (FCI) have become key to enabling continuous data exchange between aircraft and ground systems. Despite their operational benefits, however, these systems do not yet provide security protection in a unified and consistently deployed manner across communication establishment, operational message exchange, and mobility or handover phases. In particular, guarantees related to mutual authentication, key establishment, integrity, confidentiality, and secure mobility management are not uniformly maintained across current air–ground communication environments. As a result, aviation communication systems remain exposed to replay, impersonation, message injection, man-in-the-middle (MITM), session hijacking, and denial-of-service (DoS) attacks, especially during mobility events and handover transitions, thereby posing significant risks to operational safety.

Motivated by these challenges, we develop lightweight, aviation-compatible, and formally verifiable security frameworks in this thesis to secure communication and handover across CPDLC, LDACS, and heterogeneous FCI environments. For CPDLC, the thesis introduces lightweight security mechanisms that provide mutual authentication, session key establishment, and secure handover by using Elliptic Curve Cryptography (ECC), Elliptic Curve Diffie–Hellman (ECDH), Schnorr signatures, and symmetric protection. For LDACS, the thesis strengthens security through lightweight authentication together with post-quantum-resilient key establishment and handover mechanisms. In this framework, Physically Unclonable Functions (PUFs) enable lightweight hardware-bound authentication, while the Bit-Flipping Key Encapsulation (BIKE) mechanism supports post-quantum-secure key establishment. This design reduces reliance on conventional public key infrastructure and supports secure key continuity across intra- and inter-domain scenarios. At the network level, the thesis further introduces a Host Identity Protocol (HIP)-based framework for the FCI to enable secure multi-homing and seamless mobility across heterogeneous links, including LDACS, the Aeronautical Mobile Airport Communications System (AeroMACS), and Satellite Communications (SATCOM).

To ensure that the proposed mechanisms provide rigorous security guarantees suitable for safety-critical aviation environments, the thesis complements framework design with formal security assurance. Symbolic analysis using Tamarin Prover and ProVerif is employed to establish essential properties, including authentication, key secrecy, forward secrecy, and secure handover, under strong adversary models. Overall, this thesis advances the security and robustness of both legacy and nextgeneration aviation communication systems across operational communication and mobility scenarios.

Place, publisher, year, edition, pages
Linköping: Linköping University Electronic Press, 2026. p. 81
Series
Linköping Studies in Science and Technology. Dissertations, ISSN 0345-7524 ; 2526
National Category
Security, Privacy and Cryptography
Identifiers
urn:nbn:se:liu:diva-223884 (URN)10.3384/9789181185690 (DOI)9789181185683 (ISBN)9789181185690 (ISBN)
Public defence
2026-08-19, Ada Lovelace, B Building, Campus Valla, Linköping, 09:15 (English)
Opponent
Supervisors
Available from: 2026-05-12 Created: 2026-05-12 Last updated: 2026-05-12Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full text

Search in DiVA

By author/editor
Khan, SulemanSingh, GurjotGurtov, Andrei
By organisation
Database and information techniquesFaculty of Science & Engineering
Communication Systems

Search outside of DiVA

GoogleGoogle Scholar

doi
isbn
urn-nbn

Altmetric score

doi
isbn
urn-nbn
Total: 149 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • oxford
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf