Powered by OpenAIRE graph
Found an issue? Give us feedback
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/ ZENODOarrow_drop_down
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/
ZENODO
Preprint . 2026
License: CC BY
Data sources: ZENODO
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/
ZENODO
Preprint . 2026
License: CC BY
Data sources: ZENODO
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/
ZENODO
Preprint . 2026
License: CC BY
Data sources: ZENODO
ZENODO
Preprint . 2026
License: CC BY
Data sources: Datacite
ZENODO
Preprint . 2026
License: CC BY
Data sources: Datacite
ZENODO
Preprint . 2026
License: CC BY
Data sources: Datacite
ZENODO
Preprint . 2026
License: CC BY
Data sources: Datacite
versions View all 3 versions
addClaim

Security Governance Filters

Authors: Bolignano, Dominique;

Security Governance Filters

Abstract

Modern digital infrastructures are becoming increasingly complex and interconnected. Cloud platforms, artificial intelligence infrastructures, connected vehicles and large-scale cyber-physical systems combine numerous software layers, protocol stacks and operational interfaces. In such environments, attempting to secure every component of the infrastructure is unrealistic. Large software stacks inevitably contain vulnerabilities, making traditional perimeter security mechanisms increasingly fragile. A more robust architectural approach consists in introducing strongly verifiable control points capable of mediating interactions between security domains and governing critical operations. This paper revisits the concept of security filters, originally introduced for protecting critical IoT and cyber-physical infrastructures. Unlike traditional firewalls that operate on low-level protocol elements and rely on large trusted computing bases, security filters enforce explicit high-level policies on commands and data flows. When implemented on top of formally verified microkernels and minimal trusted components, such filters drastically reduce the attack surface and provide strong assurance guarantees. We argue that formally verified security filters constitute the simplest form of programmable security governance anchors and can therefore be considered minimal instances of Trusted Security Governance Platforms (TSGP). Beyond this conceptual role, security filters also represent one of the most practical governance anchors for constructing security architectures based on Trusted Security Governance Platforms. The paper also analyzes the robustness advantages of this architecture compared to traditional firewall-based approaches. By minimizing the trusted computing base to a formally verified microkernel and a small filtering application, the architecture eliminates large classes of vulnerabilities inherent to traditional network security devices. Finally, we present emerging industrial deployments of these mechanisms within the security core of next-generation Software Defined Vehicles (SDV) and discuss ongoing work exploring similar architectures for avionics systems where critical information exchanges between onboard subsystems must be strictly governed. These deployments illustrate how governance-based security architectures can move from research concepts to large-scale cyber-physical infrastructures.

Keywords

trusted computing base, microkernel security, domain isolation, programmable trust anchors, formally verified systems, security filters, trusted security governance platforms, software defined vehicles, trusted security governance, secure communication mediation, avionics security, cyber-physical security

  • BIP!
    Impact byBIP!
    selected citations
    These citations are derived from selected sources.
    This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    0
    popularity
    This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
    Average
    influence
    This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    Average
    impulse
    This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
    Average
Powered by OpenAIRE graph
Found an issue? Give us feedback
selected citations
These citations are derived from selected sources.
This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Citations provided by BIP!
popularity
This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
BIP!Popularity provided by BIP!
influence
This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Influence provided by BIP!
impulse
This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
BIP!Impulse provided by BIP!
0
Average
Average
Average