Integrating Security into Safe Airborne Software Development

People's safety has always been the utmost priority in civil aviation. Consequently, the avionics industry has developed and is subject to some of the most rigorous safety standards, within airborne software development regulated under DO-178C ""Software Considerations in Airborne Systems and Equipment Certification"". Recently, it became evident that in addition to unintentional safety hazards, avionics were increasingly exposed to intentional malicious attacks. The growing connectivity of aircraft systems created new cyber security risks, which led to the development of dedicated security standards including DO-326B "Airworthiness Security Process Specification" and its guidance DO-356A "Airworthiness Security Methods and Considerations". Rather than replacing DO-178C, they extend the assurance framework by introducing a structured approach to identifying, assessing and mitigating security threats that could compromise aircraft safety.

While DO-178C focuses on airborne software and the prevention of unintended failures through development assurance levels, DO-326B operates at the system level. It addresses security risks arising from all electronic interaction including hardware, software, networks and interfaces, ensuring that intentional unauthorized electronic interactions are systemically considered within the design and development life cycle.

This presentation examines how DO-356A objectives flow down into software development and how they can be integrated into an established DO-178C life cycle. The relationship between the DO-326B and the widely recognized Common Criteria standard is also analyzed. Although both standards rely on structured threat modeling and evidence based assurance, Common Criteria evaluates security against defined assurance levels while DO-326B focuses on the overall safety impact of the aircraft. The presentation clarifies how Common Criteria activities may support DO-356A compliance activities. The presentation highlights areas of overlap, synergy and extension between the standards, demonstrating that safety and security are not competing disciplines but complementary assurance perspectives essential for modern airborne systems.

Using certifiable ARINC 653 RTOS as an example, the presentation also discusses challenges of common security practices within deterministic and certifiable airborne software.

Speaker

Carsten Beck

Partner Management, SYSGO

Carsten Beck is managing partners and alliances within SYSGO. Prior, he was Head of Product Development for PikeOS, where he leads the evolution of the PikeOS RTOS and hypervisor, designed for deployment in safety- and security-critical systems across highly regulated industries. He brings extensive experience in system design as well as product and project management.

Before joining SYSGO in 2022, he led the hardware team at Masabi in London.

Carsten holds degrees in Control Systems of Imperial College London and in Electrical Engineering of Technical University Kaiserslautern.

Sponsored by

Official Media Partners

Aerospace Innovations

Sponsored and Organised by