Features

Data transfer security

The SAE succinctly defines the primary purpose of data load as to upload loadable software parts, such as navigation databases and operational programs, to airborne computers. A secondary function of data load is downloading data from airborne computers. This can be achieved by the use of an Airborne Data Loader (ADL) for installation on aircraft to perform onboard loading, or through a Portable Data Loader (PDL) for loading equipment on the ground or carried onto aircraft to perform onboard loading.

These PDLs support loading data from various sources, such as floppy disks, hard drives, USB devices, CDs, DVDs, and wired or wireless network locations.

PDLs, as Donald van Tongeren, a consultant with MBS Electronic Systems, explains, have been in use for a long time.

“Even aircraft such as the DC-10 had onboard components that were “updated” using PDLs, with software distributed via diskettes,” he tells Aerospace Innovations. “Later, PDLs were introduced that connected via networks to servers hosting the software parts, eliminating the need for physical media. However, this introduced security risks—specifically, whether software parts could be altered during transmission over the network.

“At that point, several industry standards were developed and published. When followed, these ensure the integrity of Loadable Software Aircraft Parts (LSAPs). The standard specifically developed for PDLs is ARINC 645, which introduced the commonly used term “ARINC 645-compliant PDL.” The most recent evolution is the Airborne Data Loader (ADL), a device installed in the aircraft that performs tasks traditionally handled by PDLs. Both PDLs and ADLs must comply with increasingly stringent standards to ensure end-to-end security for LSAPs. The introduction of EASA Part-IS has recently brought significant attention to data loading security.”

Part-IS establishes the regulatory framework, regulations enacted between 2022 and 2023, for the oversight and implementation of Information Security Management Systems (ISMS) for EASA-approved organisations.

As the UK CAA notes, Part-IS supports resilience to cyber threats, ensures continuity of aviation services, and aligns with the broader cybersecurity legal framework. As of 2025, authorities and service providers must demonstrate compliance through robust governance, threat identification, incident response, and oversight capabilities.

The use of PDLs, in all their forms, is widespread. The so-called “dematerialisation” (i.e. the elimination of physical media), driven by improvements in operational efficiency, was a key factor behind this, now well established, trend, says van Tongeren.

According to the Civil Aviation Cybersecurity Subcommittee of Aerospace Industries Association of America (AIA), PDL manufacturers have played a major role in continuing to advance PDL technology to strengthen the security mechanisms implemented in the data loader devices.

“These advancements not only provide protection against tampering of the PDL and ADL devices but are also designed to protect software parts that are installed on-board and software at-rest,” they write in a 2023 recommendation paper.

‘Data at rest’ is data currently in storage and contrasts with ‘data in transit’ — also called ‘data in motion’ — which is the state of data as it travels from one place to another. It also contrasts with ‘data in use’ — data loaded into memory and actively in use by a software program.

“ARINC 645-1 establishes security hardening requirements for PDLs and ADLs. It was updated throughout 2020 and issued in August 2021. In addition to making the loading devices more robust from a security standpoint, these devices are also aiming to a help make the verification of digital signatures on-board seamless to minimise and simplify additional steps operators and software loading personnel have to follow,” AAI add.

Digital sign-off
One security feature that provides integrity assurance and software authenticity to users is a digital signature. The AIA advocate for a signature being applied by the software delivery source and validated upon receiving software into a company.

ARINC 835 provides two options for applying a digital signature, following established methodologies already in use within the aviation industry. Secure data loaders are also expected to be capable of verifying ARINC 835 and ARINC 827 signed software parts.

For example, Teledyne’s PMAT XS data loader checks digital signatures upon import and prior to load via ARINC 827 crates – used by its Loadstar Server Enterprise 3 (LSE 3) software module, to protect parts in transit and at rest – and ARINC 835 software part signatures. Launched in 2020, Full access to LSE 3 is entirely under airline control, and only encrypted communications from authenticated clients can gain access to it. The system also tracks the delivery and provides reports for all software parts loaded on aircraft and helps collect and return aircraft downloads from the field.

The MBS Data Loading concept from MBS Electronic Systems is compliant with ARINC 827 and ATA Spec 42 for crate format and long-life digital signature, as well as ARINC 835. Developed from the security benchmark of the mini PDL-Pad, its Secure Maintenance Device (SMD) is a DO-335aED-204, ARINC 827, ATA Spec 42, ARINC 835 and ARINC 645-1 complaint data loader for browser-based data loading and OEM Windows App based data loading.

As the company explains, operators have used, and continue to use, Windows laptops and OEM’s applications to load LRUs in a server client configuration.

These types of devices are open, configurable by the user and have inherent security risks that require significant IT overhead to maintain patches and security updates.

However, with the issue of Boeing Instructions for Continued Airworthiness (ICA) Requirements and industry focus on data security such laptop use is unlikely to be compliant for much longer.

Joining up the COTS
“When referring to general-purpose or Windows-based devices, these may introduce certain challenges,” says van Tongeren. “Such solutions are typically based on commercial off-the-shelf systems (COTS) hardware, requiring the airline to maintain and regularly update these devices. The hardware, operating system, and application must remain aligned, and in practice this combination can introduce integration and maintenance challenges, requiring ongoing attention and effort from the operator.

“From a security perspective, this also increases the complexity of maintaining compliance with standards such as ARINC 645 and related guidance, as the overall system integrity depends on multiple independently managed components. An alternative approach (as applied in our solution) is to provide an integrated combination of purpose-built hardware and dedicated software (comparable to the Apple approach). This allows full control over the platform, ensuring that security mechanisms such as secure boot, certificate validation, and Public Key Infrastructure (PKI)-based processes remain consistently implemented and compliant.

“In this model, device maintenance, updates, and compliance with applicable regulations and standards (e.g. ARINC 645/667 and EASA Part-IS) are managed in a controlled and consistent manner. This significantly reduces operational burden for the airline, while ensuring end-to-end integrity, authenticity, and traceability of LSAPs. We consider this approach to be fully aligned with current security requirements and a significant improvement over both legacy and general-purpose solutions.”

The company’s mini PDL-Pad complements its SMD and supports ARINC 429, ARINC 615, and ARINC 615A. AFDX functionality is coming soon. Compatible with any Airbus and Boeing aircraft, it has PKI functionality, supporting Boeing, Airbus and Carillon ARINC 835 signed software parts and Airbus ARINC 641 formatted media sets.

Towards the end of last year, Avionica and AIT (Avionics Interface Technologies) formed a strategic partnership to develop a fully integrated Secure Airborne Data Loader (ADL) ecosystem.

The agreement will see AIT’s Secure ARINC 615 and 615A data loading capabilities, as well as its ARINC 645-1/2 and 835 compliant technologies, natively hosted on Avionica’s aviONS airborne platform.

Additionally, Avionica’s cloud-based digital distribution service, avSYNC, will enable airlines to remotely deploy loadable software parts (LSAPs) directly to the aircraft. The ecosystem will be further enhanced with the integration of AIT’s Fleet Data Command Center (FDCC-SaaS), creating a closed-loop, end-to-end solution that supports both PDLs and airborne systems.

Speaking at the time of the announcement, which aims to give aircraft operators a scalable, secure, and COTS-ready pathway to digital aircraft modernisation, Edward Gorman, Vice President of Engineering at Avionica commented that, “By integrating AIT’s secure data loader technologies into our aviONS platform and leveraging our avSYNC cloud architecture, we are giving operators a seamless, modern, and cybersecurity-focused pathway to manage loadable software across the entire aircraft lifecycle. Together, Avionica and AIT are raising the bar for efficiency, security, and digital enablement across the industry.”

Troy Troshynski, General Manager of AIT, said customers would now be able to deploy loadable software parts more efficiently and more securely, leveraging its industry-leading cloud-based LSAP distribution system across all data loader form factors.

Moving to 645-1
As the AAI observe, ARINC 645-1 compliant PDLs and ADLs are becoming more readily available to the aviation industry. They write these loaders are designed to the security requirements specified in ARINC 645-1 which help deter tampering with the loading device, contain security-based logs which can be helpful in investigations and cyber forensics efforts, and have capability to validate ARINC 835 based digital signatures of the software parts to be stored in the PDL/ADL and loaded onto the aircraft LRUs. Transitioning from standard data loading solutions to ARINC 645-1 compliant secure data loaders provides additional safety measures in ensuring the correct and desired software part is loaded onto aircraft LRUs. Shop load tools and processes should also ensure that digitally signed parts are used for shop loading of LRUs. Generally, ARINC 645-1 loaders should also be used for shop loading.

At MBS Electronic Systems, van Tongeren says their system is designed to ensure the integrity, authenticity, and traceability of Loadable Software Aircraft Parts (LSAPs), in full compliance with ARINC 645/667, ATA Spec 42, Boeing ICA, and EASA Part-IS guidance material.

“It uses secure communication channels, PKI for validation, and encryption of LSAPs at rest. All our LSAP loading tools are implemented as secure boot platforms based on embedded Linux operating systems. Any unauthorised modification of the system image prevents the device from starting. The devices are fully locked down and restricted to their intended function—software loading operations. Local administrative access is not permitted. Assigned loading tools (e.g. the Mini PDL) initiate communication with FLS-Desk. When new software parts become available, the Mini PDL verifies the crate certificate. If invalid, the software is rejected and logged; if valid, it is stored in the local repository. When a software part is selected for loading, the certificate is verified again. If invalid, loading is prevented. These mechanisms have been independently evaluated and validated by Boeing and GE.”

AIT PDLs data storage system leverage data-at-rest encryption to protect all Field Loadable Software (FLS) on the PDL as well as data retrieved from the aircraft.

AIT says that if an attacker were to open one of its PDLs and remove the storage to examine it with intent to maliciously tamper, the storage media would be unintelligible. The encryption keys are stored securely on the Trusted Platform Module embedded in the motherboard of the PDLs.

In addition to secure storage of PDLs, it is important to maintain traceability of usage (i.e. who uses the device and when) and to regularly analyse log files.

Weakest link
As van Tongeren observes, an often-overlooked risk factor is personnel, including employees and contractors.

They have direct access to safety-critical systems and may unintentionally or deliberately bypass technical controls, he says. “Training and clear procedures are essential to mitigate risks and ensure correct system usage. Awareness is a key objective of EASA Part-IS,” he states.

He adds that in addition to employee awareness training, unsigned or legacy software should be treated as new software parts if these were to be reused. These should be thoroughly validated (e.g. via incoming goods inspection processes) before being introduced into the new secure system. The involved hardware is normally already under strict control, and any remaining software is deleted from the devices before leaving the controlled premisses of the airline.

According to the AAI, to ensure secure software loading devices are the only ones used for aircraft LRUs, it is important for all industry groups to decommission standard PDLs and ADLs once they have completed replacements with secure data loaders. This includes shop loaders. “Operators may wish to convert ADL airplanes to PDL connections if secure PDLs are more available or if this makes sense economically. Each aviation entity with ownership of ADLs and PDLs should incorporate a plan for decommissioning the standard loading devices. As part of the decommissioning process these entities should also include a data purging step that removes all stored software parts, LRU downloaded data, and any other potential data of proprietary nature,” they write.

It is important to ensure software remains protected from its origin to the final step of being loaded onto an LRU or Integrated Modular Avionics (IMA).

MBS Electronic Systems actively participate in industry committees involved in the development of standards and regulatory changes.

“For example, our PDL is already aligned with the upcoming ARINC 645-2 standard,” says van Tongeren says. “Another important topic is the evolution of PKI. SHA-2 (or higher) is currently the recommended standard within the industry and under ATA Spec 42. While there is no immediate indication that SHA-256 is at risk, the potential need to transition to new cryptographic approaches—including post-quantum cryptography—is being actively considered across the industry. We are closely monitoring these developments and preparing accordingly,” he remarks.

A stark warning comes from Dmitrijs Terentjevs, a hardware/software engineer at DTech SIA. “In my experience 95% of operators or users who deal with data loading and PDLs, do not understand threats and risks and have no idea how to avoid them. This starts from airlines (especially smaller ones) and ends [with the] PDL operator. Existing security measures will not work until all elements of chain understand [the] whole process.”

By Alex Preston