Trust Without Boundaries: An Architectural Analysis of Satellite Flight Software

πŸ“… 2026-08-14
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
This study addresses the insufficient security isolation caused by absent internal trust boundaries in satellite flight software. Focusing on NASA’s cFS architecture and leveraging NOS3 simulation alongside cross-framework comparisons, this work systematically exposes latent attack surfaces arising from shared authority within modular systems. Experimental results demonstrate that a single compromised component can masquerade as legitimate behavior to abuse privileges. Accordingly, this project proposes an architecture-level trust boundary reinforcement mechanism that effectively enhances onboard software security. By clarifying future improvement directions for flight software security architectures, this research fills a critical gap in systematic defense strategies for this domain.
πŸ“ Abstract
As spacecraft become more software-driven and interconnected, onboard flight software is an increasingly important security boundary. Popular flight software architectures often treat onboard components as trusted peers, simplifying integration while limiting internal isolation and access control. We analyze NASA's Core Flight Software (cFS) to examine how authority, identity, communication, observability, and persistence are distributed across onboard components. Using NASA's flight-representative NOS3 simulator, we validate these weaknesses through five experiments implemented with a malicious onboard component that abuses legitimate architectural privileges. We then compare cFS with other modular flight software frameworks to identify recurring trust assumptions and architectural weaknesses. Our results show that a single compromised component can exploit broadly shared authority in ways that are difficult to distinguish from legitimate behavior. We conclude with architectural implications and discuss mechanisms for strengthening internal trust boundaries in future flight software systems.
Problem

Research questions and friction points this paper is trying to address.

Satellite Flight Software
Trust Boundaries
Security Architecture
Access Control
Component Isolation
Innovation

Methods, ideas, or system contributions that make the work stand out.

Flight Software Security
Trust Boundary Analysis
NASA cFS
Architectural Vulnerability
NOS3 Simulator
J
Jack Vanlyssel
Department of Computer Science, University of New Mexico, Albuquerque, NM, USA
G
Gruia-Catalin Roman
Department of Computer Science, University of New Mexico, Albuquerque, NM, USA
K
Kendra Cook
Science Applications International Corporation (SAIC)
Sazzadur Rahaman
Sazzadur Rahaman
Assistant Professor of Computer Science at The University of Arizona
SecurityPrivacyProgram AnalysisApplied CryptographyInternet Measurement
Afsah Anwar
Afsah Anwar
University of New Mexico
MalwareThreat IntelligenceVulnerability Management