Wind River
Certifiable IP Block Catalog
Accelerate certification, reduce integration risk, and lower total development costs with Certifiable IP
Wind River provides certifiable IP blocks that are prebuilt, pre-documented, and pre-verified software components for safety- and security-critical embedded systems, with DO-178C DAL A certification evidence. These blocks accelerate certification programs while reducing integration risk and program cost. This catalog provides technical specifications and key differentiators for each available block, supporting evaluation by certification engineers, system architects, and program technical leads.
To see how Wind River certifiable IP blocks have accelerated certification for real programs, see the Certifiable IP Blocks Solution Brief.
BLOCKS IN THIS CATALOG:
- Curtiss-Wright VPX3-1708 Reference BSP — Two-level board support package for ARINC 653 systems
- Curtiss-Wright VPX3-1708 Secure Boot Loader — Authenticated boot with hardware-anchored chain of trust
- Information Assurance Foundation (IAF) — Data protection, integrity, and trusted boot services
- RTNET Cert — Deterministic TCP/IP network stack for safety-critical systems
- High Reliability File System (HRFS) — Power-loss-safe transactional file system
DO-178C COMPLIANCE ARTIFACTS
A complete DO-178C DAL A compliance artifact set is available for each block through Wind River Professional Services. Each set contains the data required to meet the objectives of all four DO-178C phases — Planning, Requirements and Design, Verification, and Completion — spanning the full evidence chain from the Plan for Software Aspects of Certification (PSACa) through the Software Accomplishment Summary (SAS) including high- and low-level requirements, compliant source code, review data, and complete test cases, procedures, and results.
CURTISS-WRIGHT VPX3-1708 REFERENCE BSP
Two-Level Board Support Package for ARINC 653 Systems
A complete two-level board support package for ARINC 653 systems on the Curtiss-Wright VPX3-1708 single-board computer: a Module OS BSP supporting the Helix Virtualization Platform hypervisor level, and a Partition OS BSP providing the RTOS and full device driver suite for VxWorks guest partitions. A DO-178C DAL A evidence license is available through Wind River Professional Services.
Key Differentiators
- Complete Two-Level Coverage — Purpose-built BSPs for both the hypervisor (MOS) and partition (POS) levels of an ARINC 653 system
- Comprehensive Driver Suite — Storage, buses, timing, DMA, and discrete I/O drivers for the full VPX3-1708 device complement
- Integrated with Catalog Blocks — RTNET, HRFS, and IAF are pre-integrated — the certifiable stack composes out of the box; production use requires a separate license for each
- Per-Component Evidence — Every component carries dedicated DO-178C artifact documentation, supporting focused delta certification
CURTISS-WRIGHT VPX3-1708 SECURE BOOT LOADER
Hardware-Anchored Authenticated Boot
A certifiable secure boot loader occupying the final user-level stage of the Arm Trusted Firmware boot chain on the NXP LX2160A. Every image is signature verified through the Information Assurance Foundation (IAF) before execution, with boot media accessed through the transactional HRFS file system — extending the chain of trust from silicon to operating system. IAF and HRFS are integrated into the SBL and licensed separately for production use; customers develop their own boot application — the SBL element implementing customer-specific image location, load, and verification. DO-178C DAL A evidence is available through Wind River Professional Services.
Key Differentiators
- Authenticated Boot Path — No image executes without IAF signature validation; encrypted image support included
- Minimal-Footprint Staged Design — A small hardware-initialization loader launches a VxWorks-kernel-based boot application — capability without bloat at the most safety-critical boot stage
- Power-Loss-Safe Media Access — Boot images read through HRFS, eliminating file system corruption as a boot-failure mode
- Boot-Time Health Awareness — Onboard temperature and voltage monitoring with error detection and logging from the first instruction
- Per-Component Evidence — Every component carries dedicated DO-178C artifact documentation
Technical specification:
INFORMATION ASSURANCE FOUNDATION (IAF)
SEC Engine Access
The Information Assurance Foundation (IAF) provides applications the interfaces to securely handle data and verify its integrity using the processor’s on-chip security engine (SEC engine) for cryptographic and hashing operations. A library rather than a standalone application, IAF is pre-integrated into the Curtiss-Wright VPX3-1708 SBL and BSP — binding cryptographic functions to a write-protected Black Key Database (BKDB) in non-volatile memory — and is licensed separately for production use. IAF is operating-system independent and processor specific, with DO-178C compliance artifacts provided through Wind River Professional Services.
Key Differentiators
- Hardware-Backed Crypto — The NXP SEC engine offloads all RSA/ECC operations — zero CPU overhead for key verification
- Tamper-Proof Key Storage — BKDB is hardware write-protected after provisioning; cannot be modified at runtime
- Pre-Kernel Enforcement — Verification runs before the OS loads — no software bypass path exists
- Dual-Image Resilience — Built-in primary/secondary image fallback with independent verification callbacks
- Certifiable Architecture — DO-178C Level A design with full function header block (FHB) traceability and MISRA-C conformance
Technical Specifications
Performance figures measured on CW VPX-1708 with NXP QorIQ ARMv8 processor.
RTNET CERT
Real-Time Network Stack for VxWorks
A deterministic TCP/IP network stack built for safety-critical embedded systems — typical applications include onboard networking between compute nodes, such as a flight control computer communicating with control surfaces. RTNET provides standard socketbased IPv4 networking with DO-178C DAL A certification artifacts provided through Wind River Professional Services.
Key Differentiators
- DO-178C DAL A Certification Artifacts — Each of the stack’s three components carries dedicated certification evidence, integration-ready for program use
- Deterministic by Design — Kernel-resident, pre-allocated buffer pools, static API-based configuration — no runtime surprises
- Standards Conformant — 30+ RFC conformance across TCP, UDP, IPv4, ICMP, and ARP using the standard socket API
- Flexible Deployment — Runs natively on VxWorks 7 or within an ARINC 653 partition on Helix Virtualization Platform — including multiple partitions per system
Technical Specifications
Values reflect the current certifiable configuration of RTNET. The certifiable scope is deliberately bounded; features outside the current scope are listed explicitly below.
HIGH RELIABILITY FILE SYSTEM (HRFS)
Highly Reliable File System for VxWorks
A transactional, power-loss-safe file system for embedded systems where data integrity is non-negotiable. Every write is either fully committed or fully discarded — automatically, with no possibility of corruption reaching the application. HRFS is included in VxWorks; DO-178C compliance artifacts and the corresponding source version are provided through Wind River Professional Services.
Key Differentiators
- Zero Corruption on Power Loss — No logically inconsistent state possible; recovery is automatic with no manual intervention
- Deterministic, Bounded Recovery — Replays at most 7 inode journal entries — milliseconds, not a scan that scales with disk size
- Drop-In POSIX Compatibility — open(), read(), write(), and related APIs work unmodified through the VxWorks VFS layer
- Certifiable CERT Build — Bounded-memory, deterministic build supports DO-178C, IEC 61508, and ISO 26262 programs
Technical Specifications
Values reflect distinct build and block-size configurations — the applicable figure depends on which HRFS configuration is deployed.