Trust Without Boundaries: An Architectural Analysis of Satellite Flight Software
This study addresses the insufficient security isolation caused by absent internal trust boundaries in satellite flight software. Focusing on NASA’s cFS architecture and leveraging NOS3 simulation alongside cross-framework comparisons, this work systematically exposes latent attack surfaces arising from shared authority within modular systems. Experimental results demonstrate that a single compromised component can masquerade as legitimate behavior to abuse privileges. Accordingly, this project proposes an architecture-level trust boundary reinforcement mechanism that effectively enhances onboard software security. By clarifying future improvement directions for flight software security architectures, this research fills a critical gap in systematic defense strategies for this domain.