AegisKernel
A QNX RTOS-based secure operating environment for automotive systems — safety architecture, TARA and threat modeling across 120+ critical operations.
- Role
- Safety Lead (co-lead, 4-member team) · BitArmora Technologies
- Timeline
- Jan 2026 – May 2026
- Domain
- automotiveembeddedsafety
- Stack
- QNX RTOSTARAISO/SAE 21434ISO 26262ISO 21448
Problem
Modern vehicles run safety-critical software where a security flaw can become a safety hazard. A secure operating environment for this space has to prove — not just claim — that every critical operation is analysed for threats, bounded in time, and able to fall back to a safe state, in line with ISO 26262, ISO/SAE 21434 and ISO 21448.
Approach
As Safety Lead, I owned the system's safety architecture end to end within a 4-member engineering team.
- Threat Analysis and Risk Assessment (TARA) and threat modeling to identify attack paths and rate their risk
- WCET validation so critical operations stay within their timing budgets
- Safe-state analysis defining how the system degrades safely when something goes wrong
What I built
The analysis covered 120+ critical operations, translating safety and security requirements into structured, traceable engineering artifacts:
- Software Requirements Specification (SRS)
- Safety Envelope Specifications
- Architecture diagrams
- A Critical Operations Taxonomy — the structured data backbone that made the system auditable and traceable end to end
Results
A QNX-based secure operating environment whose safety and security decisions can be traced from requirement to artifact, documented in compliance with ISO 26262, ISO/SAE 21434 and ISO 21448.