Advanced RTOS Security for Safety-Critical Embedded Systems
The Enhanced Security Module (ESM), a cybersecurity extension for SAFERTOS®, provides the security foundations and building blocks needed to help developers build secure embedded software, even when the final deployment context is not yet known.
Designed for connected and safety-critical embedded applications, the ESM enables secure-by-design development through capabilities including task isolation, access control, memory protection and threat detection. These features help protect critical resources, contain compromised software components and improve overall system resilience.
The ESM is developed using established cybersecurity engineering practices, including Threat Analysis and Risk Assessment (TARA), security verification, penetration testing and fuzz testing. This provides greater transparency, traceability and assurance, helping organisations support cybersecurity objectives alongside functional safety requirements and evolving regulatory expectations.
Ask Us a Question
For pricing, licensing, or any other sales or product related questions, please contact us.
Why the Enhanced Security Module (ESM)?
A Real Time Operating System is foundational software. While it may not be directly exposed to external threats, it plays a critical role in determining how securely the wider application behaves.
The SAFERTOS® ESM was developed through a comprehensive TARA process. The ESM applies multiple layers of protection designed to:
- Support secure-by-design development practices
- Build traceability into the development lifecycle
- Restrict unauthorised access to system resources
- Isolate software components from one another
- Prevent attacks from spreading throughout the application
- Detect security violations at runtime
- Protect critical application data and system services
- Improve resilience against both accidental faults and malicious activity
Rather than enforcing a fixed security architecture, the ESM gives developers the mechanisms needed to build security into their own systems.
Enhanced Security Module Benefits
Runtime security
- Detects unauthorized access attempts.
- Provides threat containment at task level.
- Protects critical application data from unauthorized access.
- Delivers security mechanisms that can be applied before the final deployment context is known.
Threat containment
- Isolates user-mode tasks from one another.
- Restricts access to kernel resources and RTOS objects.
- Limits the impact of compromised software components.
- Supports secure-by-design development through built-in protection and monitoring capabilities.
Software assurance
- Developed using cybersecurity engineering practices.
- Supports security-focused development and verification practices.
- Supplied with a Design Assurance Pack (DAP) containing design, verification, security documentation and traceability artefacts.
- Provides lifecycle evidence to support safety, security and compliance activities throughout the product lifecycle.
Integration
- Extends SAFERTOS® without changing the existing API.
- Uses the same familiar development lifecycle as SAFERTOS®
- Allows developers to retain processor, toolchain and architectural flexibility.
- For further information on SAFERTOS® and ESM licensing, please contact us.
Suitable Applications
- Automotive systems
- Industrial automation
- Medical devices
- Edge computing devices
- Connected IoT products
- Robotics
Ask Us a Question
For pricing, licensing, or any other sales or product related questions, please contact us.
Security Features
- Access Control Policy (ACP) enables developers to control which SAFERTOS® API functions each task can access.
- Object Control Policy (OCP) restricts access to RTOS objects, including timers, queues, mutexes, semaphores, event groups, event polls, and other tasks.
- Memory isolation builds on SAFERTOS® spatial separation mechanisms using MPU/MMU memory regions to limit task access and trigger exceptions on violations.
- Task context data isolation stores task context data within the Task Control Block (TCB) rather than the task stack, helping protect inactive tasks from exploitation and data leakage.
- Data obfuscation uses indirect references for key data structures rather than exposing direct memory pointers.
- Secure portable layer provides enhanced enforcement of kernel and user-space partitioning.
- Penetration detection monitor triggers exceptions when tasks attempt to access unauthorized memory, APIs, or data objects, providing early warning of potential attacks.
- Attack containment strategy designed to prevent compromised tasks from accessing data from other tasks or gaining broader system control.
Supporting Security and Compliance Activities
Organisations developing connected products need to demonstrate that cybersecurity has been considered throughout design, development, verification and maintenance activities.
The SAFERTOS® ESM supports these efforts through:
- Security-focused architecture
- Security verification activities
- Design traceability
- Development artefacts
- Security documentation
- Long-term maintenance support
The ESM is developed in accordance with ISO 21434 cybersecurity engineering principles and can support organisations operating in regulated and security-conscious industries, including those addressing emerging requirements such as the Cyber Resilience Act (CRA).

Enhanced Security Module Specifications
| Item | Details |
|---|---|
| Platform | SAFERTOS® |
| API Compatibility | Existing SAFERTOS® API retained |
| Memory Protection | MPU/MMU-based task isolation |
| Access Controls | Task-level API and RTOS object permissions |
| Deliverables |
|
| Documentation | Safety, security and user manuals included |
| Additional Materials | Test harness and demonstration application |
| Maintenance | Annual support, incident reports, errata, updates and patches available |
Development Process
The ESM follows the SAFERTOS® development lifecycle with additional cybersecurity activities, including:
- Threat Analysis and Risk Assessment (TARA)
- Cybersecurity Analysis Report (CAR)
- Security and functional and safety requirements
- Additional penetration testing and fuzz testing
- Development to the highest possible Safety Integrity Level requirements where applicable
Support and Evaluation
- Annual support and maintenance options available
- Access to product updates, security patches and errata
- Access to incident reporting
- Evaluation source code packages available on request through the sales team.
