View Full Version : Technical study on ACARS "encryption"

6th Apr 2017, 22:58
Interesting study for those who are interested!

"Abstract. Recent research has shown that a number of existing wireless avionic systems lack encryption and are thus vulnerable to eavesdropping
and message injection attacks. The Aircraft Communications Addressing and Reporting System (ACARS) is no exception to this rule with 99%
of the trac being sent in plaintext. However, a small portion of the trac coming mainly from privately-owned and government aircraft is
encrypted, indicating a stronger requirement for security and privacy by those users. In this paper, we take a closer look at this protected
communication and analyze the cryptographic solution being used. Our results show that the cipher used for this encryption is a mono-alphabetic
substitution cipher, broken with little effort. We assess the impact on privacy and security to its unassuming users by characterizing months
of real-world data, decrypted by breaking the cipher and recovering the keys. Our results show that the decrypted data leaks privacy sensitive
information including existence, intent and status of aircraft owners."


6th Apr 2017, 23:59
I recall having discussions several years ago with Rockwell-Collins about data-mining based on transmissions from client airlines using their ACARS network. The consensus was that there was/is no imminent prospect of air carriers encrypting their ACARS transmissions. Obviously the situation with corporate and government aviation is different.

7th Apr 2017, 05:11
Not too dissimilar to the outcry from some "professional" pilots about the invasion of privacy when it was revealed ACARS transmissions were being published on the interweb in this Prune thread (http://www.pprune.org/australia-new-zealand-pacific/406630-acars-warning-all.html).

Most aviation-related communication is unsecure, and has always been. Probably always will be too, unfortunately, given the difficulty of replacing such widespread existing technology.

7th Apr 2017, 07:35
I dont think interception is the issue, the issue is far more interjection.

I just depends on how much airlines or other systems want to broadcast and/or rely on ACARS to send/relay information.