SANCTUARY, in collaboration with Airbus Defence & Space and Testonica Lab Ltd., has successfully secured a highly competitive European Space Agency (ESA) tender to develop an innovative “End-to-End Supply Chain Protection Architecture” for spacecraft. The main objective of the proposed solution is to guarantee the integrity, authenticity, and transparency of software artefacts throughout the entire spacecraft supply chain, from their creation at the supplier up to their deployment and update on a spacecraft.
In contemporary space missions, software-based systems are becoming increasingly critical, simultaneously driving higher complexity and vulnerability within associated supply chains. Particularly, the planned use of (re-)programmable and (re-)configurable software and firmware components in spacecraft, as well as the involvement of numerous subcontractors and third-party suppliers, necessitate heightened transparency, integrity, and security throughout every stage of development. Recognizing these challenges, a consortium led by Airbus Defence & Space, together with SANCTUARY and Testonica Lab Ltd., has been commissioned in collaboration with the European Space Agency (ESA) to develop an innovative solution designed to comprehensively protect the end-to-end software supply chain for spacecraft. The primary objective of this proposed solution is to safeguard all phases of software and firmware creation, integration, validation, and deployment against potential manipulations.
Additionally, the project approach includes the systematic containerization of all critical development and integration processes. Digitally signed containers will ensure isolation, integrity, and authenticity of the software tools and components employed. Particular emphasis will be placed on comprehensive validation procedures for integrating third-party components—such as open-source software—including automated and manual testing alongside dynamic and static code analyses, before these components are accepted as trustworthy within the supply chain.