Finally, using the security architecture in a real
airborne environment cannot be done without a
certification procedure: software considerations in
airborne systems and equipment certification are
described in the Radio Technical Commission for
Aeronautics (RTCA) and EUROCONTROL DO-
178B document [27]. Thus, we are considering the
use of a high-assurance design technique called
MILS (Multiple Independent Layer Security and
Safety) [28] to implement the SecMan module.