DDC-I Announces Modular, Secure DAL-A Boot Solution for Avionics Systems Running Deos Safety-Critical RTOS

DDC-I, a supplier of software and professional services for mission and safety-critical applications, today announced ME-Boot, a modular, portable, Design Assurance Level A (DAL-A) boot solution for the Deos DO-178C, safety-critical real-time operating system. ME-Boot provides a compact, flexible, reusable, phased, embedded boot solution for avionics platforms running Deos that can be readily enhanced with new capabilities, ported and certified on new hardware.

“ME-Boot provides an innovative DAL-A certifiable boot solution for avionics platforms running Deos,” said Gary Gilliland, vice president of marketing at DDC-I. “Like Deos, ME-Boot employs a modular design in which boot components are divided into independently loadable modules.  This modularity enables binary reuse of modules as well as the addition of customized modules, greatly reducing the cost and risk associated with developing, modifying, and maintaining avionics board support packages.”

ME-Boot (Modular Extensible Boot) is a multi-stage DAL-A bootloader that performs hardware initialization and boots the Deos kernel, including pre-OS loading activities (e.g., secure boot) and OS component loading and launch. ME-Boot performs first-stage operations such as configuring the memory controller, SDRAM, CPUs and other I/O devices. It then performs second-stage booting operations such as loading the Deos kernel, system image and related files from a storage device such as flash, SATA drive, or over ethernet.

Most hardware vendors supply a BIOS, slim boot, or U-boot when they deliver a board.  For a certified system, this code must be replaced with new code that can be certified to the required DAL. When dealing with DO-178C-certifiable or other higher integrity production BSPs, the boot code is usually a highly customized, one-off code base developed from the ground-up that is platform specific with a single executable module based on each system use case.

One of the challenges of this highly customized approach is that it becomes very expensive to make changes due to the reverification efforts needed for the entire BSP code base.  As such, reusability is often limited to snippets of source code with little or no reuse of any of the other software life-cycle data (e.g., requirements, tests, etc.).  Additionally, this approach restricts the user’s ability to add or modify the BSP once it has been delivered by the supplier (e.g., PBIT, IO initialization, security, etc.).  

ME-Boot employs a modular approach that streamlines the development, modification, and reuse of DAL-A BSPs by separating the boot functions into independent modules. This modular approach allows capability to be readily added and subtracted without affecting the verification evidence of previous work, thereby allowing binaries to be reused on common architectures. It also makes it easy for developers to add new functionality such as security (authentication, encryption, key storage), I/O configuration, and Power on Built in Testing (PBIT). Custom module testing with unique system testing requirements can also be readily added without perturbing other COTS modules, thus accelerating time to market and significantly reducing labor and costs.