Creating a safer, more secure future.

SAFERTOS® Enhanced Security Module

Advanced RTOS Security for Safety-Critical Embedded Systems

The Enhanced Security Module (ESM), a cybersecurity extension for SAFERTOS®, provides the security foundations and building blocks needed to help developers build secure embedded software, even when the final deployment context is not yet known.

Designed for connected and safety-critical embedded applications, the ESM enables secure-by-design development through capabilities including task isolation, access control, memory protection and threat detection. These features help protect critical resources, contain compromised software components and improve overall system resilience.

The ESM is developed using established cybersecurity engineering practices, including Threat Analysis and Risk Assessment (TARA), security verification, penetration testing and fuzz testing. This provides greater transparency, traceability and assurance, helping organisations support cybersecurity objectives alongside functional safety requirements and evolving regulatory expectations.

Advanced RTOS Security for Safety-Critical Embedded Systems

Ask Us a Question

For pricing, licensing, or any other sales or product related questions, please contact us.

Ask us a question

Why the Enhanced Security Module (ESM)?

A Real Time Operating System is foundational software. While it may not be directly exposed to external threats, it plays a critical role in determining how securely the wider application behaves.

The SAFERTOS® ESM was developed through a comprehensive TARA process. The ESM applies multiple layers of protection designed to:

  • Support secure-by-design development practices
  • Build traceability into the development lifecycle
  • Restrict unauthorised access to system resources
  • Isolate software components from one another
  • Prevent attacks from spreading throughout the application
  • Detect security violations at runtime
  • Protect critical application data and system services
  • Improve resilience against both accidental faults and malicious activity

Rather than enforcing a fixed security architecture, the ESM gives developers the mechanisms needed to build security into their own systems.

Performing the Threat Analysis and Risk Assessment (TARA) Analysis Out Of Context

How do you design for security when the final deployment context is unknown?

As cybersecurity expectations evolve, developers are required to demonstrate security before knowing exactly how or where software will be deployed.

This paper explores how Threat Analysis and Risk Assessment (TARA) can be applied out of context, using ISO 21434 principles to identify risks, define security controls and support secure-by-design development. It also shares insights and lessons learned from performing TARA on SAFERTOS®, alongside the practical outcome: the SAFERTOS® ESM.

This paper was created for, and presented at, Embedded World 2024.

Performing the TARA Analysis white paper image

Enhanced Security Module Benefits

Runtime security

  • Detects unauthorized access attempts.
  • Provides threat containment at task level.
  • Protects critical application data from unauthorized access.
  • Delivers security mechanisms that can be applied before the final deployment context is known.

Threat containment

  • Isolates user-mode tasks from one another.
  • Restricts access to kernel resources and RTOS objects.
  • Limits the impact of compromised software components.
  • Supports secure-by-design development through built-in protection and monitoring capabilities.

Software assurance

  • Developed using cybersecurity engineering practices.
  • Supports security-focused development and verification practices.
  • Supplied with a Design Assurance Pack (DAP) containing design, verification, security documentation and traceability artefacts.
  • Provides lifecycle evidence to support safety, security and compliance activities throughout the product lifecycle.

Integration

  • Extends SAFERTOS® without changing the existing API.
  • Uses the same familiar development lifecycle as SAFERTOS®
  • Allows developers to retain processor, toolchain and architectural flexibility.
  • For further information on SAFERTOS® and ESM licensing, please contact us.

Suitable Applications

Ask Us a Question

For pricing, licensing, or any other sales or product related questions, please contact us.

Ask us a question

Security Features

Every embedded application has different security requirements and deployment environments. Rather than enforcing a fixed security model, ESM provides a set of security building blocks that developers can combine to support their own security architecture.
  • Access Control Policy (ACP) enables developers to control which SAFERTOS® API functions each task can access.
  • Object Control Policy (OCP) restricts access to RTOS objects, including timers, queues, mutexes, semaphores, event groups, event polls, and other tasks.
  • Memory isolation builds on SAFERTOS® spatial separation mechanisms using MPU/MMU memory regions to limit task access and trigger exceptions on violations.
  • Task context data isolation stores task context data within the Task Control Block (TCB) rather than the task stack, helping protect inactive tasks from exploitation and data leakage.
  • Data obfuscation uses indirect references for key data structures rather than exposing direct memory pointers.
  • Secure portable layer provides enhanced enforcement of kernel and user-space partitioning.
  • Penetration detection monitor triggers exceptions when tasks attempt to access unauthorized memory, APIs, or data objects, providing early warning of potential attacks.
  • Attack containment strategy designed to prevent compromised tasks from accessing data from other tasks or gaining broader system control.

The ESM Demonstration

See how the ESM helps developers build secure embedded applications by providing the security foundations needed to protect critical resources, contain threats and improve system resilience.

In this video, we take you through:

  • A clear introduction to what the ESM is
  • How it provides a hardened, protected execution environment
  • A real demonstration of the module running in action

Supporting Security and Compliance Activities

Organisations developing connected products need to demonstrate that cybersecurity has been considered throughout design, development, verification and maintenance activities.

The SAFERTOS® ESM supports these efforts through:

  • Security-focused architecture
  • Security verification activities
  • Design traceability
  • Development artefacts
  • Security documentation
  • Long-term maintenance support

The ESM is developed in accordance with ISO 21434 cybersecurity engineering principles and can support organisations operating in regulated and security-conscious industries, including those addressing emerging requirements such as the Cyber Resilience Act (CRA).

V-Model development process for software that includes extra steps for security

 

Enhanced Security Module Specifications

Item Details
Platform SAFERTOS®
API Compatibility Existing SAFERTOS® API retained
Memory Protection MPU/MMU-based task isolation
Access Controls Task-level API and RTOS object permissions
Deliverables
  • Full SAFERTOS® ESM source code
  • Demonstration application
  • Test harness
  • Design Assurance Pack (DAP)
  • Design and verification artefacts
  • Security manuals
  • Safety manuals
  • User manuals
Documentation Safety, security and user manuals included
Additional Materials Test harness and demonstration application
Maintenance Annual support, incident reports, errata, updates and patches available

Development Process

The ESM follows the SAFERTOS® development lifecycle with additional cybersecurity activities, including:

  • Threat Analysis and Risk Assessment (TARA)
  • Cybersecurity Analysis Report (CAR)
  • Security and functional and safety requirements
  • Additional penetration testing and fuzz testing
  • Development to the highest possible Safety Integrity Level requirements where applicable

Support and Evaluation

  • Annual support and maintenance options available
  • Access to product updates, security patches and errata
  • Access to incident reporting
  • Evaluation source code packages available on request through the sales team.

30 Day Evaluation Packages

Ready to try the ESM yourself? Request your evaluation package today. Evaluation Packages are available free of charge, or visit our download centre for the Enhanced Security Module datasheet.