DocumentCode :
2536106
Title :
Mils-based information flow control in the avionic domain: A case study on compositional architecture and verification
Author :
Muller, Klaus-Robert ; Paulitsch, M. ; Schwarz, R. ; Tverdyshev, S. ; Blasum, H.
Author_Institution :
EADS Innovation Works, Munich, Germany
fYear :
2012
fDate :
14-18 Oct. 2012
Abstract :
Software architectures in the aerospace domain are becoming more and more integrated and interconnected for functional and architectural reasons (Integrated Modular Avionics, IMA), which exacerbates potential security problems of avionic software. As a consequence, security considerations are gaining importance for the general ≫airworthiness≪ of modern aircrafts, and proper security assurance requires increasing effort. In this paper, we report on-going work in the SeSaM research project. We propose to leverage modularity as a key to obtain more secure software and higher assurance of this claimed security with reasonable effort. Using Multiple Independent Levels of Security (MILS), we present a case study on how an application can be systematically designed, secured, and proven secure by adopting a composite evaluation approach reflecting the modular system architecture. More specifically, we employ a separation kernel as the foundation for a security-critical application, and we investigate how a security evaluation can be achieved systematically and with reduced effort if we evaluate underlying kernel and dependent application independently before joining these partial results to obtain an overall evaluation verdict. Thus, we illustrate how a compositional approach may ease security design and security assurance of IMA architectures.
Keywords :
aerospace computing; aerospace safety; avionics; software architecture; MILS-based information flow control; SeSaM research project; aerospace domain; avionic domain; avionic software; compositional architecture; compositional verification; integrated modular avionics; leverage modularity; multiple independent levels of security; potential security problems; proper security assurance; security-critical application; separation kernel; software architectures; Aerospace electronics; Certification; Computer architecture; Kernel; Logic gates; Safety; Security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Digital Avionics Systems Conference (DASC), 2012 IEEE/AIAA 31st
Conference_Location :
Williamsburg, VA
ISSN :
2155-7195
Print_ISBN :
978-1-4673-1699-6
Type :
conf
DOI :
10.1109/DASC.2012.6382411
Filename :
6382411
Link To Document :
بازگشت