Why this environment matters
An electronic flight bag can place charts, documents and performance tools in the crew’s hands. Its security problem includes a subtle failure: an application may open normally while showing authentic information that is stale or intended for a different operation. This concept concentrates on the provenance and availability of that information.
The security challenge
In a proposed implementation, a chart viewer would read only an approved content set identified by version and effective period. It would not share update credentials with the process that downloads new material. A visible content status would remain available when the aircraft is disconnected, so the crew would not have to infer freshness from a successful login.
How the capsule model could help
A NØNOS content broker could admit a signed package, check its declared scope and expose a read-only view to a compatible application capsule. A performance-calculation tool would receive its specific reference data separately from general documents. Correct software isolation would not make a wrong input or an incorrect calculation model safe. Flight preparation may occur before a period with no useful network connection. The evaluation would identify which approved information must remain available and how it is recovered after an application failure. Credentials and transient viewing state could be disposable, while approved packages and relevant handover records need a deliberately managed store. The fallback must be understandable to a busy crew. If an update fails halfway through, the interface should identify the last complete content set rather than mixing pages from different releases. An operator would need to assess device power, environmental limits, application usability and alternative access to required information.
Deployment requirements
Aviation approval and flight-critical capability have not been established. A deployment would require compatible applications and an operator-led assessment of applicable aviation requirements. The concept should be evaluated outside operational flight use until that work is complete. Evaluation requirements: Load a signed but expired content set and verify that its status is visible before operational use. Interrupt package installation and confirm that the reader exposes one coherent release. Perform a disconnected restart and document exactly which approved information and operational records remain available.
Current public-beta limitations, hardware support and application availability must be assessed before any pilot. Neither this use case nor an industry source establishes NONOS certification or a current customer deployment.
Separate the reader from the update authority
In a proposed implementation, a chart viewer would read only an approved content set identified by version and effective period. It would not share update credentials with the process that downloads new material. A visible content status would remain available when the aircraft is disconnected, so the crew would not have to infer freshness from a successful login.
A NØNOS content broker could admit a signed package, check its declared scope and expose a read-only view to a compatible application capsule. A performance-calculation tool would receive its specific reference data separately from general documents. Correct software isolation would not make a wrong input or an incorrect calculation model safe.
A restart must not erase the operational record
Flight preparation may occur before a period with no useful network connection. The evaluation would identify which approved information must remain available and how it is recovered after an application failure. Credentials and transient viewing state could be disposable, while approved packages and relevant handover records need a deliberately managed store.
The fallback must be understandable to a busy crew. If an update fails halfway through, the interface should identify the last complete content set rather than mixing pages from different releases. An operator would need to assess device power, environmental limits, application usability and alternative access to required information.
Who could buy or integrate it?
- Airlines procuring managed electronic flight bags
- EFB vendors integrating cockpit applications and devices
- Business aviation operators standardising crew devices
Industry examples: Honeywell, Collins Aerospace. Organisations shown illustrate the industry. No NONOS customer, partner or endorsement relationship is implied.