arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.14532cs.CR

无边界信任:卫星飞行软件的架构分析

Trust Without Boundaries: An Architectural Analysis of Satellite Flight Software

Jack Vanlyssel, Gruia-Catalin Roman, Kendra Cook, Sazzadur Rahaman, Afsah Anwar

首次发表
浏览论文内容

中文总结 AI 辅助

该研究分析NASA的cFS架构弱点,通过实验验证单组件入侵可利用共享权限,提出未来飞行软件需强化内部信任边界的改进方向。

中文摘要 AI 辅助

随着航天器越来越依赖软件驱动且互联互通,星载飞行软件成为愈发重要的安全边界。流行的飞行软件架构常将星载组件视为可信对等体,简化集成的同时限制了内部隔离与访问控制。我们分析美国国家航空航天局(NASA)的核心飞行软件(Core Flight Software,cFS),研究权限、身份、通信、可观测性和持久性在星载组件间的分布情况。利用NASA的飞行代表性NOS3模拟器,我们通过5项实验验证这些弱点,实验采用滥用合法架构权限的恶意星载组件。随后我们将cFS与其他模块化飞行软件框架对比,识别反复出现的信任假设与架构弱点。结果显示,单个受感染组件可利用广泛共享的权限,其行为难以与合法行为区分。最后我们探讨架构影响,并讨论未来飞行软件系统中强化内部信任边界的机制。

英文摘要

As spacecraft become more software-driven and interconnected, onboard flight software is an increasingly important security boundary. Popular flight software architectures often treat onboard components as trusted peers, simplifying integration while limiting internal isolation and access control. We analyze NASA's Core Flight Software (cFS) to examine how authority, identity, communication, observability, and persistence are distributed across onboard components. Using NASA's flight-representative NOS3 simulator, we validate these weaknesses through five experiments implemented with a malicious onboard component that abuses legitimate architectural privileges. We then compare cFS with other modular flight software frameworks to identify recurring trust assumptions and architectural weaknesses. Our results show that a single compromised component can exploit broadly shared authority in ways that are difficult to distinguish from legitimate behavior. We conclude with architectural implications and discuss mechanisms for strengthening internal trust boundaries in future flight software systems.

补充信息

↑