SlideShare a Scribd company logo
© 2019 Rolls-Royce and Other HICLASS Partners.
© 2019 Rolls-Royce and HICLASS Partners
The information in this document is the property of Rolls-Royce and other HICLASS partners. This information is given in good faith based upon the latest information available to the HICLASS partners, no warranty or representation is given
concerning such information, which must not be taken as establishing any contractual or other commitment binding upon the HICLASS partners.
The information contained in this document is submitted in confidence and is of the kind contemplated by Section[s] [41 and 43] of the Freedom of Information Act 2000. No UK security
classification is applicable to this document. The information contained in this document is not controlled and no export license is required.
1
The HICLASS Research Programme
Enabling Development of Complex and Secure Aerospace Systems
Mike Bennett, Rolls-Royce Control Systems
on behalf of the HICLASS consortium
This work was supported by the HICLASS project,
funded by the Aerospace Technology Institute
and Innovate UK, as project number 113213.
© 2019 Rolls-Royce and Other HICLASS Partners.
2
HICLASS will enable UK
industry to build and
support the most
complex, connected,
cyber-secure avionic
systems in the world
• £32M project over 4 years
• Started July 2019
• Led by Rolls-Royce
• 16 funded partners
• 2 unfunded partners
• Engagement with DSTL
Project Overview
Systems developers, tool suppliers and academics
working together to develop integrated solutions
© 2019 Rolls-Royce and Other HICLASS Partners.
Opportunity
3. Position for
New Markets
4. Ongoing Cost Avoidance
1. Exploit Existing
Markets
Lower-cost assured software and
electronics are key enablers
Aerospace
High-Integrity Tools and Services
2. Secure Existing
Markets
Adjacent Markets
© 2019 Rolls-Royce and Other HICLASS Partners.
0
1
2
3
4
5
6
7
8
9
Integrity
Complexity
Digital Dependence
Connectivity
Security
Safety
4
Increasing Scale and Complexity
The systems we can
practically build today
The systems we’d like to
be able to build
© 2019 Rolls-Royce and Other HICLASS Partners.
5
Continuing the journey….
• Model-Based Development
• Open Toolchains
• Improved Architectures
• Improved / Automated / Formal
Verification
• Pooling niche skills and
build community
• Enhance understanding of
shared problems
• Multi-core
• Security
• Electronic platform
technologies
Technologies
Matured and Expanded
ASSET
© 2019 Rolls-Royce and Other HICLASS Partners.
6
Work Package Overview
WP4
Integration &
Embedding
Integrated
product
demonstrators
WP3
Advanced Verification
Timing Analysis for
complex systems eg.
multi-core and
distributed
Automated,
scalable and model-
based
Early and virtual
integration
WP2
Future Platforms and
Development
Integrated Model-
Based Engineering
Reusable
Components and
Product Lines
Cyber-secure
architectures and
mechanisms
High-Integrity
connectivity, networks
and data distribution
WP1
Domain Exploitation for
HICLASS Systems
Product opportunities
and exploitation for
HICLASS systems
Develop a cross-
industry cyber-
security approach for
avionics and drive
regulation
Themes
Scope requirements, refine
exploitation opportunities and
develop cross-industry security
approach Develop 34 advanced
technologies in 14
complementary work packages
Systems developers
integrate technologies
Advanced hardware
platforms and smart
sensors
Security
Verification
Technologies
© 2019 Rolls-Royce and Other HICLASS Partners.
7
Technologies
Model Based
System
Engineering
Model-Based
Software
Development
Automated
Verification for
Certification
Secure Formal
Code
Executable
Models
Rapid
Integration of
Complex Systems
Next Generation Platform
9 electronic and
software platform
technologies
11 Security
Technologies
4 specification
and modelling
technologies
7 verification and
test technologies
Multi-Core Processing
3 Multi-Core
Technologies
Agile
Find and Fix
© 2019 Rolls-Royce and Other HICLASS Partners.
8
New Areas - Multi-Core Timing Verification
• Online monitoring limits
contention and interference
within predetermined
bounds
• Robust allocation &
scheduling restricts
contention for shared
resources and supports
graceful degradation
• Processor & resource
demands obtained via
measurement-based
analysis
• Micro-benchmarks
quantify sensitivity to
different levels of
interference
• Multi-cores contain HW resources that are shared
between cores causing timing unpredictability
• Regulator provides objectives that must be met for
certification
• How to meet those objectives?
1. Mechanisms
2. Testing and
Analysis
3. Building
Argument
4. Improving Regulation
• FAA/EASA Feedback
© 2019 Rolls-Royce and Other HICLASS Partners.
• Current Status:
- Safety: many years industry experience.
- Security
• Many security process standards.
• Aerospace security standards (ED-202A/DO-326A) only
recently published about to be adopted as Acceptable
Means of Compliance
- Lack of expertise in certification
• Now expressed as customer requirements
- Key Issues:
• Expertise is theoretical rather practical
• Integration of security and safety
• Cost effectiveness
9
New Areas – Security (1/2)
Security Risk
Assessment
related activities
Airworthiness
acceptability matrix
3 – Security Risk
Assessment (3.2)
2 - Security Scope
Definition (3.1)
Certification related activities
1 - Plan for Security Aspects of
Certification (PSecAC)
7 - Communication of evidences
(PSecAC Summary)
Not
Acceptable
Security
Risk
4 - Are
security risks
acceptable
?
Security Development related activities
5 - Security Development (3.4)6 - Security Effectiveness
Assurance (3.3)
Architecture
Modifications
Architecture
under
consideration
© 2019 Rolls-Royce and Other HICLASS Partners.
- Share and Develop Best Practice
• Create some common elements e.g. Threat Model
• Stopping criteria
• Advice covering the interaction of security measures with safety,
- e.g. safety impact of security measure failure modes
- Develop Security Technologies
• Binary vulnerability analysis
• Cyber-hardening (eg. compiler)
• Fuzz testing
• On-board Security Information and Event Management (SIEM)
• Secure Data Communications, Loading and Update
- Engagement with industry working groups
10
New Areas – Security (2/2)
One example of some of the
technology interactions
© 2019 Rolls-Royce and Other HICLASS Partners.
• Dissemination events
• Aerospace Software Systems Engineering & Technology (ASSET) partnership
- Identification of Gaps!
• Work with specific partners on particular topics
- Case studies
- Supply of tools
11
Engaging with HICLASS
© 2019 Rolls-Royce and Other HICLASS Partners.
• The Aerospace Software Systems Engineering &
Technology (ASSET) partnership.
• ‘Club’ open to all organisations undertaking technical
work in aerospace software and systems engineering
in the UK
- Inc. system suppliers, software houses, tool
suppliers, government agencies, academic
research organisations)
- No NDA / Collaboration Agreement
- Publication under Creative Commons Licence
• Constitution developed during the SECT-AIR project
• Starting small - currently run on a volunteer basis as
a pilot with a proposed small subscription fee from
2020 managed through University of York
• Sharing best practice in industry-led working groups
(eg. Agile and CPD)
12
Offer different
perspectives
ASSET
© 2019 Rolls-Royce and Other HICLASS Partners.
• Rolls Royce in on a software transformation journey
• More products, projects and software
• Current approach is difficult to sustain
13
Rolls-Royce Exploitation
© 2019 Rolls-Royce and Other HICLASS Partners.
• HICLASS is key enabler to the UK to build cyber-secure systems of the future
• Important part of enhancing the UK capability in high-integrity systems and
software engineering
• Highly collaborative with an array of technologies being developed
• Main focus in civil aerospace but cross-sector exploitation is expected
• Come and talk to us to find out more!
14
Summary and Conclusions
© 2019 Rolls-Royce and Other HICLASS Partners.
15
Partner leads
Organisation Lead Contact
Rolls-Royce Mike Bennett
Adacore Paul Butcher
Altran Katie Smith
BAE Systems Malcolm Earl
Callen-Lenz Martin Ward
Cobham Paul Moses
Cocotec Philippa Hopcroft
D-RisQ Nick Tudor
GDUK Matt Saint-Gregory
GE Aviation Kevin Grover
Leonardo Donald Taylor
MBDA Lee Jacques
Oxford Daniel Kroening
Rapita Systems Adam Barker
Southampton Colin Snook
Thales Peter Bland
Ultra Aleem Saleh
York Iain Bate
© 2019 Rolls-Royce and Other HICLASS Partners.
16
WP Breakdown
WP1
WP1.1 Future
Products and Impact
(Rolls-Royce)
WP 1.2 Embedded
Cyber-Security
Standards,
Approach and
Process (Thales)
WP2
WP2.1 Ensuring Data Communication
Integrity (Thales)
WP2.2 Technologies for Cyber Hardening
(GDUK)
WP2.3 Full-lifecycle Model-Based
Development Environment (Altran)
WP2.4 Specification Environment for
Complex Systems (Altran)
WP2.5 Flexible, Secure and Segregated
Software Architecture Frameworks
(Rolls-Royce)
WP2.6 Enhanced Software Update and
Maintenance Capability (Rolls-Royce)
WP2.7 Future complex, safety-critical and
modular hardware platform (Rolls-Royce)
WP3
WP3.1 Automatic formal
verification (D-RisQ)
WP3.2 Semi-automatic formal
verification (DRisQ)
WP3.3 Automated Low Level
Verification (Rapita)
WP3.4 Automated verification
tools for event-driven software
(Cocotec)
WP3.5 SPARK for HICLASS
(Adacore)
WP3.6 Integrated Framework for
Managing the Timing of New
Complex Architectures (York)
WP3.7 Automated System-Level
Testing (Altran)
WP4
WP4.1 Future Engine
Controls and Monitoring
Computing Platform (Rolls-
Royce)
WP4.2 Innovative Flight
Control System (Callen-Lenz)
WP4.3 Next Generation
Control System (Rapita)
WP4.4 Safe & Secure
Processing Reference Design
(GDUK)
WP4.5 Future Power Systems
(GE)

More Related Content

PDF
The Future of Aerospace – More Software Please!
AdaCore
 
PDF
Using Tiers of Assurance Evidence to Reduce the Tears! Adopting the “Wheel of...
AdaCore
 
PDF
Securing the Future of Safety and Security of Embedded Software
AdaCore
 
PDF
Spark / Ada for Safe and Secure Firmware Development
AdaCore
 
PDF
Approaches to Cyber Resilience and Supply Chain Assurance
Leonardo
 
PDF
PM Briefing: Autonomy and big data for defence
Defence and Security Accelerator
 
PDF
27 July 2017 Innovation nework event: how to create a great proposal
Defence and Security Accelerator
 
PDF
D pduapi user-manual
linhdoanbro
 
The Future of Aerospace – More Software Please!
AdaCore
 
Using Tiers of Assurance Evidence to Reduce the Tears! Adopting the “Wheel of...
AdaCore
 
Securing the Future of Safety and Security of Embedded Software
AdaCore
 
Spark / Ada for Safe and Secure Firmware Development
AdaCore
 
Approaches to Cyber Resilience and Supply Chain Assurance
Leonardo
 
PM Briefing: Autonomy and big data for defence
Defence and Security Accelerator
 
27 July 2017 Innovation nework event: how to create a great proposal
Defence and Security Accelerator
 
D pduapi user-manual
linhdoanbro
 

What's hot (15)

PPTX
8 July 2015: Agile, immersive mission training themed competition
Defence and Security Accelerator
 
PDF
2017-05-10 Gate4SPICE: "Legacy Software"
Alexander Much
 
PPTX
Accelerator Enduring Challenge Competition Launch Opening Session
Heather-Fiona Egan
 
PDF
Is Linux ready for safety related applications?
Alexander Much
 
PDF
Webinar–2019 Open Source Risk Analysis Report
Synopsys Software Integrity Group
 
PDF
Core analysis:State of SDN-NFV in wireless networks 2014
Patrick Lopez
 
PDF
EB corbos and the L4Re microhypervisor: Open-source automotive safety
Alexander Much
 
PDF
Rotary Wing Platforms: Delivering Information Advantage to the Joint Force
Leonardo
 
PDF
Testing ADAS & Self Driving Cars
Automotive IQ
 
PPTX
TWISummit 2019 - Embracing a Service Mesh
Thoughtworks
 
PDF
MISRA C Chairman - Device Developer Conference 2016
Andrew Banks
 
PDF
Webinar Presentation: "Diagnostic Flash Application with OTX"
KPIT
 
PDF
20140121 cisec-safety criticalsoftwaredevelopment
CISEC
 
PDF
EENA 2018 - Drones and Public Safety
EENA (European Emergency Number Association)
 
PPTX
Software Sustainability: preserving the future of research software
Neil Chue Hong
 
8 July 2015: Agile, immersive mission training themed competition
Defence and Security Accelerator
 
2017-05-10 Gate4SPICE: "Legacy Software"
Alexander Much
 
Accelerator Enduring Challenge Competition Launch Opening Session
Heather-Fiona Egan
 
Is Linux ready for safety related applications?
Alexander Much
 
Webinar–2019 Open Source Risk Analysis Report
Synopsys Software Integrity Group
 
Core analysis:State of SDN-NFV in wireless networks 2014
Patrick Lopez
 
EB corbos and the L4Re microhypervisor: Open-source automotive safety
Alexander Much
 
Rotary Wing Platforms: Delivering Information Advantage to the Joint Force
Leonardo
 
Testing ADAS & Self Driving Cars
Automotive IQ
 
TWISummit 2019 - Embracing a Service Mesh
Thoughtworks
 
MISRA C Chairman - Device Developer Conference 2016
Andrew Banks
 
Webinar Presentation: "Diagnostic Flash Application with OTX"
KPIT
 
20140121 cisec-safety criticalsoftwaredevelopment
CISEC
 
EENA 2018 - Drones and Public Safety
EENA (European Emergency Number Association)
 
Software Sustainability: preserving the future of research software
Neil Chue Hong
 
Ad

Similar to Introducing the HICLASS Research Programme - Enabling Development of Complex and Secure Aerospace Systems (20)

PDF
Developing Future High Integrity Processing Solutions
AdaCore
 
PDF
Profarnborough-airplanes-presentation.pdf
varnitrajatgoel
 
PPTX
TCI 2016 Better technology innovation support for supply chain companies
TCI Network
 
PDF
Bae gta
The Pathway Group
 
PDF
Unified Systems Engineering feasibility
Eric Verhulst
 
PPT
VFB 2013 - Strategic Research and Horizon Scanning - Rolls Royce
Science City Bristol
 
PDF
Driving workforce enablement through it innovation - Digital at Rolls-Royce
Microsoft UK
 
PDF
Rolls-Royce Engineering Infographic
Ali Mayar
 
PPT
Richard Crisp -- predictable development for the IoT
Anatoly Levenchuk
 
PPTX
Curtiss-Wright Controls Avionics & Electronics Corporate Overview
Curtiss-Wright Defense Solutions
 
PPTX
Innovate UK Future Worlds Event - Material World – John Laughlin
Invest Northern Ireland
 
PDF
Remote monitoring & user experience by Iiro Lindborg, Development Project Man...
Ixonos Plc
 
PDF
MRO IT CONFERENCE & SHOWCASE Brochure
Aviation Week
 
PDF
Innovation in Aerospace
Seda Eskiler
 
PDF
Aircraft IT MRO eJournal "eSignatures" How I See IT
Michael Denis
 
PPTX
Splunk at Airbus
Splunk
 
PPTX
ERS Case Study: HCLT develops a next generation in-flight entertainment syst...
HCL Technologies
 
PDF
Product and Systems Engineering at Innovate 2013
IBM Rational software
 
PPTX
The business case for hybrid clouds and mini pods
Janet Brokerage
 
Developing Future High Integrity Processing Solutions
AdaCore
 
Profarnborough-airplanes-presentation.pdf
varnitrajatgoel
 
TCI 2016 Better technology innovation support for supply chain companies
TCI Network
 
Unified Systems Engineering feasibility
Eric Verhulst
 
VFB 2013 - Strategic Research and Horizon Scanning - Rolls Royce
Science City Bristol
 
Driving workforce enablement through it innovation - Digital at Rolls-Royce
Microsoft UK
 
Rolls-Royce Engineering Infographic
Ali Mayar
 
Richard Crisp -- predictable development for the IoT
Anatoly Levenchuk
 
Curtiss-Wright Controls Avionics & Electronics Corporate Overview
Curtiss-Wright Defense Solutions
 
Innovate UK Future Worlds Event - Material World – John Laughlin
Invest Northern Ireland
 
Remote monitoring & user experience by Iiro Lindborg, Development Project Man...
Ixonos Plc
 
MRO IT CONFERENCE & SHOWCASE Brochure
Aviation Week
 
Innovation in Aerospace
Seda Eskiler
 
Aircraft IT MRO eJournal "eSignatures" How I See IT
Michael Denis
 
Splunk at Airbus
Splunk
 
ERS Case Study: HCLT develops a next generation in-flight entertainment syst...
HCL Technologies
 
Product and Systems Engineering at Innovate 2013
IBM Rational software
 
The business case for hybrid clouds and mini pods
Janet Brokerage
 
Ad

More from AdaCore (20)

PDF
RCA OCORA: Safe Computing Platform using open standards
AdaCore
 
PDF
Have we a Human Ecosystem?
AdaCore
 
PDF
Rust and the coming age of high integrity languages
AdaCore
 
PDF
SPARKNaCl: A verified, fast cryptographic library
AdaCore
 
PDF
Taming event-driven software via formal verification
AdaCore
 
PDF
Pushing the Boundary of Mostly Automatic Program Proof
AdaCore
 
PDF
RCA OCORA: Safe Computing Platform using open standards
AdaCore
 
PDF
Product Lines and Ecosystems: from customization to configuration
AdaCore
 
PDF
Adaptive AUTOSAR - The New AUTOSAR Architecture
AdaCore
 
PDF
Software Engineering for Robotics - The RoboStar Technology
AdaCore
 
PDF
MISRA C in an ISO 26262 context
AdaCore
 
PPTX
Application of theorem proving for safety-critical vehicle software
AdaCore
 
PDF
The Application of Formal Methods to Railway Signalling Software
AdaCore
 
PDF
Bounded Model Checking for C Programs in an Enterprise Environment
AdaCore
 
PDF
Multi-Core (MC) Processor Qualification for Safety Critical Systems
AdaCore
 
PDF
Ada 202x A broad overview of relevant news
AdaCore
 
PDF
Verification and Validation of Robotic Assistants
AdaCore
 
PDF
An Alternative Approach to DO-178B
AdaCore
 
PDF
MISRA C – Recent developments and a road map to the future
AdaCore
 
PDF
HIS 2015: Prof. Phil Koopman - A Case Study of Toyota Unintended Acceleration...
AdaCore
 
RCA OCORA: Safe Computing Platform using open standards
AdaCore
 
Have we a Human Ecosystem?
AdaCore
 
Rust and the coming age of high integrity languages
AdaCore
 
SPARKNaCl: A verified, fast cryptographic library
AdaCore
 
Taming event-driven software via formal verification
AdaCore
 
Pushing the Boundary of Mostly Automatic Program Proof
AdaCore
 
RCA OCORA: Safe Computing Platform using open standards
AdaCore
 
Product Lines and Ecosystems: from customization to configuration
AdaCore
 
Adaptive AUTOSAR - The New AUTOSAR Architecture
AdaCore
 
Software Engineering for Robotics - The RoboStar Technology
AdaCore
 
MISRA C in an ISO 26262 context
AdaCore
 
Application of theorem proving for safety-critical vehicle software
AdaCore
 
The Application of Formal Methods to Railway Signalling Software
AdaCore
 
Bounded Model Checking for C Programs in an Enterprise Environment
AdaCore
 
Multi-Core (MC) Processor Qualification for Safety Critical Systems
AdaCore
 
Ada 202x A broad overview of relevant news
AdaCore
 
Verification and Validation of Robotic Assistants
AdaCore
 
An Alternative Approach to DO-178B
AdaCore
 
MISRA C – Recent developments and a road map to the future
AdaCore
 
HIS 2015: Prof. Phil Koopman - A Case Study of Toyota Unintended Acceleration...
AdaCore
 

Recently uploaded (20)

PDF
Event Presentation Google Cloud Next Extended 2025
minhtrietgect
 
PDF
Oracle AI Vector Search- Getting Started and what's new in 2025- AIOUG Yatra ...
Sandesh Rao
 
PDF
Security features in Dell, HP, and Lenovo PC systems: A research-based compar...
Principled Technologies
 
PPTX
IT Runs Better with ThousandEyes AI-driven Assurance
ThousandEyes
 
PDF
Make GenAI investments go further with the Dell AI Factory
Principled Technologies
 
PDF
REPORT: Heating appliances market in Poland 2024
SPIUG
 
PDF
Economic Impact of Data Centres to the Malaysian Economy
flintglobalapac
 
PPTX
AI and Robotics for Human Well-being.pptx
JAYMIN SUTHAR
 
PPTX
OA presentation.pptx OA presentation.pptx
pateldhruv002338
 
PDF
BLW VOCATIONAL TRAINING SUMMER INTERNSHIP REPORT
codernjn73
 
PPTX
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 
PDF
Unlocking the Future- AI Agents Meet Oracle Database 23ai - AIOUG Yatra 2025.pdf
Sandesh Rao
 
PDF
Orbitly Pitch Deck|A Mission-Driven Platform for Side Project Collaboration (...
zz41354899
 
PDF
Responsible AI and AI Ethics - By Sylvester Ebhonu
Sylvester Ebhonu
 
PDF
Get More from Fiori Automation - What’s New, What Works, and What’s Next.pdf
Precisely
 
PDF
Using Anchore and DefectDojo to Stand Up Your DevSecOps Function
Anchore
 
PDF
Accelerating Oracle Database 23ai Troubleshooting with Oracle AHF Fleet Insig...
Sandesh Rao
 
PPTX
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
PPTX
The-Ethical-Hackers-Imperative-Safeguarding-the-Digital-Frontier.pptx
sujalchauhan1305
 
PDF
Trying to figure out MCP by actually building an app from scratch with open s...
Julien SIMON
 
Event Presentation Google Cloud Next Extended 2025
minhtrietgect
 
Oracle AI Vector Search- Getting Started and what's new in 2025- AIOUG Yatra ...
Sandesh Rao
 
Security features in Dell, HP, and Lenovo PC systems: A research-based compar...
Principled Technologies
 
IT Runs Better with ThousandEyes AI-driven Assurance
ThousandEyes
 
Make GenAI investments go further with the Dell AI Factory
Principled Technologies
 
REPORT: Heating appliances market in Poland 2024
SPIUG
 
Economic Impact of Data Centres to the Malaysian Economy
flintglobalapac
 
AI and Robotics for Human Well-being.pptx
JAYMIN SUTHAR
 
OA presentation.pptx OA presentation.pptx
pateldhruv002338
 
BLW VOCATIONAL TRAINING SUMMER INTERNSHIP REPORT
codernjn73
 
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 
Unlocking the Future- AI Agents Meet Oracle Database 23ai - AIOUG Yatra 2025.pdf
Sandesh Rao
 
Orbitly Pitch Deck|A Mission-Driven Platform for Side Project Collaboration (...
zz41354899
 
Responsible AI and AI Ethics - By Sylvester Ebhonu
Sylvester Ebhonu
 
Get More from Fiori Automation - What’s New, What Works, and What’s Next.pdf
Precisely
 
Using Anchore and DefectDojo to Stand Up Your DevSecOps Function
Anchore
 
Accelerating Oracle Database 23ai Troubleshooting with Oracle AHF Fleet Insig...
Sandesh Rao
 
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
The-Ethical-Hackers-Imperative-Safeguarding-the-Digital-Frontier.pptx
sujalchauhan1305
 
Trying to figure out MCP by actually building an app from scratch with open s...
Julien SIMON
 

Introducing the HICLASS Research Programme - Enabling Development of Complex and Secure Aerospace Systems

  • 1. © 2019 Rolls-Royce and Other HICLASS Partners. © 2019 Rolls-Royce and HICLASS Partners The information in this document is the property of Rolls-Royce and other HICLASS partners. This information is given in good faith based upon the latest information available to the HICLASS partners, no warranty or representation is given concerning such information, which must not be taken as establishing any contractual or other commitment binding upon the HICLASS partners. The information contained in this document is submitted in confidence and is of the kind contemplated by Section[s] [41 and 43] of the Freedom of Information Act 2000. No UK security classification is applicable to this document. The information contained in this document is not controlled and no export license is required. 1 The HICLASS Research Programme Enabling Development of Complex and Secure Aerospace Systems Mike Bennett, Rolls-Royce Control Systems on behalf of the HICLASS consortium This work was supported by the HICLASS project, funded by the Aerospace Technology Institute and Innovate UK, as project number 113213.
  • 2. © 2019 Rolls-Royce and Other HICLASS Partners. 2 HICLASS will enable UK industry to build and support the most complex, connected, cyber-secure avionic systems in the world • £32M project over 4 years • Started July 2019 • Led by Rolls-Royce • 16 funded partners • 2 unfunded partners • Engagement with DSTL Project Overview Systems developers, tool suppliers and academics working together to develop integrated solutions
  • 3. © 2019 Rolls-Royce and Other HICLASS Partners. Opportunity 3. Position for New Markets 4. Ongoing Cost Avoidance 1. Exploit Existing Markets Lower-cost assured software and electronics are key enablers Aerospace High-Integrity Tools and Services 2. Secure Existing Markets Adjacent Markets
  • 4. © 2019 Rolls-Royce and Other HICLASS Partners. 0 1 2 3 4 5 6 7 8 9 Integrity Complexity Digital Dependence Connectivity Security Safety 4 Increasing Scale and Complexity The systems we can practically build today The systems we’d like to be able to build
  • 5. © 2019 Rolls-Royce and Other HICLASS Partners. 5 Continuing the journey…. • Model-Based Development • Open Toolchains • Improved Architectures • Improved / Automated / Formal Verification • Pooling niche skills and build community • Enhance understanding of shared problems • Multi-core • Security • Electronic platform technologies Technologies Matured and Expanded ASSET
  • 6. © 2019 Rolls-Royce and Other HICLASS Partners. 6 Work Package Overview WP4 Integration & Embedding Integrated product demonstrators WP3 Advanced Verification Timing Analysis for complex systems eg. multi-core and distributed Automated, scalable and model- based Early and virtual integration WP2 Future Platforms and Development Integrated Model- Based Engineering Reusable Components and Product Lines Cyber-secure architectures and mechanisms High-Integrity connectivity, networks and data distribution WP1 Domain Exploitation for HICLASS Systems Product opportunities and exploitation for HICLASS systems Develop a cross- industry cyber- security approach for avionics and drive regulation Themes Scope requirements, refine exploitation opportunities and develop cross-industry security approach Develop 34 advanced technologies in 14 complementary work packages Systems developers integrate technologies Advanced hardware platforms and smart sensors Security Verification Technologies
  • 7. © 2019 Rolls-Royce and Other HICLASS Partners. 7 Technologies Model Based System Engineering Model-Based Software Development Automated Verification for Certification Secure Formal Code Executable Models Rapid Integration of Complex Systems Next Generation Platform 9 electronic and software platform technologies 11 Security Technologies 4 specification and modelling technologies 7 verification and test technologies Multi-Core Processing 3 Multi-Core Technologies Agile Find and Fix
  • 8. © 2019 Rolls-Royce and Other HICLASS Partners. 8 New Areas - Multi-Core Timing Verification • Online monitoring limits contention and interference within predetermined bounds • Robust allocation & scheduling restricts contention for shared resources and supports graceful degradation • Processor & resource demands obtained via measurement-based analysis • Micro-benchmarks quantify sensitivity to different levels of interference • Multi-cores contain HW resources that are shared between cores causing timing unpredictability • Regulator provides objectives that must be met for certification • How to meet those objectives? 1. Mechanisms 2. Testing and Analysis 3. Building Argument 4. Improving Regulation • FAA/EASA Feedback
  • 9. © 2019 Rolls-Royce and Other HICLASS Partners. • Current Status: - Safety: many years industry experience. - Security • Many security process standards. • Aerospace security standards (ED-202A/DO-326A) only recently published about to be adopted as Acceptable Means of Compliance - Lack of expertise in certification • Now expressed as customer requirements - Key Issues: • Expertise is theoretical rather practical • Integration of security and safety • Cost effectiveness 9 New Areas – Security (1/2) Security Risk Assessment related activities Airworthiness acceptability matrix 3 – Security Risk Assessment (3.2) 2 - Security Scope Definition (3.1) Certification related activities 1 - Plan for Security Aspects of Certification (PSecAC) 7 - Communication of evidences (PSecAC Summary) Not Acceptable Security Risk 4 - Are security risks acceptable ? Security Development related activities 5 - Security Development (3.4)6 - Security Effectiveness Assurance (3.3) Architecture Modifications Architecture under consideration
  • 10. © 2019 Rolls-Royce and Other HICLASS Partners. - Share and Develop Best Practice • Create some common elements e.g. Threat Model • Stopping criteria • Advice covering the interaction of security measures with safety, - e.g. safety impact of security measure failure modes - Develop Security Technologies • Binary vulnerability analysis • Cyber-hardening (eg. compiler) • Fuzz testing • On-board Security Information and Event Management (SIEM) • Secure Data Communications, Loading and Update - Engagement with industry working groups 10 New Areas – Security (2/2) One example of some of the technology interactions
  • 11. © 2019 Rolls-Royce and Other HICLASS Partners. • Dissemination events • Aerospace Software Systems Engineering & Technology (ASSET) partnership - Identification of Gaps! • Work with specific partners on particular topics - Case studies - Supply of tools 11 Engaging with HICLASS
  • 12. © 2019 Rolls-Royce and Other HICLASS Partners. • The Aerospace Software Systems Engineering & Technology (ASSET) partnership. • ‘Club’ open to all organisations undertaking technical work in aerospace software and systems engineering in the UK - Inc. system suppliers, software houses, tool suppliers, government agencies, academic research organisations) - No NDA / Collaboration Agreement - Publication under Creative Commons Licence • Constitution developed during the SECT-AIR project • Starting small - currently run on a volunteer basis as a pilot with a proposed small subscription fee from 2020 managed through University of York • Sharing best practice in industry-led working groups (eg. Agile and CPD) 12 Offer different perspectives ASSET
  • 13. © 2019 Rolls-Royce and Other HICLASS Partners. • Rolls Royce in on a software transformation journey • More products, projects and software • Current approach is difficult to sustain 13 Rolls-Royce Exploitation
  • 14. © 2019 Rolls-Royce and Other HICLASS Partners. • HICLASS is key enabler to the UK to build cyber-secure systems of the future • Important part of enhancing the UK capability in high-integrity systems and software engineering • Highly collaborative with an array of technologies being developed • Main focus in civil aerospace but cross-sector exploitation is expected • Come and talk to us to find out more! 14 Summary and Conclusions
  • 15. © 2019 Rolls-Royce and Other HICLASS Partners. 15 Partner leads Organisation Lead Contact Rolls-Royce Mike Bennett Adacore Paul Butcher Altran Katie Smith BAE Systems Malcolm Earl Callen-Lenz Martin Ward Cobham Paul Moses Cocotec Philippa Hopcroft D-RisQ Nick Tudor GDUK Matt Saint-Gregory GE Aviation Kevin Grover Leonardo Donald Taylor MBDA Lee Jacques Oxford Daniel Kroening Rapita Systems Adam Barker Southampton Colin Snook Thales Peter Bland Ultra Aleem Saleh York Iain Bate
  • 16. © 2019 Rolls-Royce and Other HICLASS Partners. 16 WP Breakdown WP1 WP1.1 Future Products and Impact (Rolls-Royce) WP 1.2 Embedded Cyber-Security Standards, Approach and Process (Thales) WP2 WP2.1 Ensuring Data Communication Integrity (Thales) WP2.2 Technologies for Cyber Hardening (GDUK) WP2.3 Full-lifecycle Model-Based Development Environment (Altran) WP2.4 Specification Environment for Complex Systems (Altran) WP2.5 Flexible, Secure and Segregated Software Architecture Frameworks (Rolls-Royce) WP2.6 Enhanced Software Update and Maintenance Capability (Rolls-Royce) WP2.7 Future complex, safety-critical and modular hardware platform (Rolls-Royce) WP3 WP3.1 Automatic formal verification (D-RisQ) WP3.2 Semi-automatic formal verification (DRisQ) WP3.3 Automated Low Level Verification (Rapita) WP3.4 Automated verification tools for event-driven software (Cocotec) WP3.5 SPARK for HICLASS (Adacore) WP3.6 Integrated Framework for Managing the Timing of New Complex Architectures (York) WP3.7 Automated System-Level Testing (Altran) WP4 WP4.1 Future Engine Controls and Monitoring Computing Platform (Rolls- Royce) WP4.2 Innovative Flight Control System (Callen-Lenz) WP4.3 Next Generation Control System (Rapita) WP4.4 Safe & Secure Processing Reference Design (GDUK) WP4.5 Future Power Systems (GE)