IntroductionΒΆ
What is Bunker-Centric Architecture (BCA)?ΒΆ
Bunker-Centric Architecture (BCA) is a multi-domain, hypervisor-based architecture for Embedded Cyber-Physical Systems and Physical AI Systems that require the highest levels of security, safety, and resilience. At its core, it provides a strongly isolated execution environment (βBunkerβ), enforced by a secure hypervisor that combines near-native execution efficiency with innovative security mechanisms. This enables critical and non-critical workloads to safely coexist on the same hardware while maintaining strict isolation of assets, data, memory, peripherals, and execution domains. The architecture is designed for cyber-physical systems, including Industrial IoT (IIoT), automotive Electronic Control Units (ECUs), medical devices, robotics, autonomous systems, and other embedded platforms where protecting critical assets, ensuring operational continuity, and preserving the availability of critical functions are essential even when the system is under attack.
Its innovative architecture provides strong isolation guarantees while minimizing the trusted computing base, enabling secure execution of software inside the Bunker irrespective of the behavior of non-critcal software. Bunker-Centric Architecture supports the development of highly secure embedded platforms aligned with modern cybersecurity, facilitating compliance with regulatory and industry standards such as the Cyber Resilience Act (CRA), IEC 62443, ISO/SAE 21434, and other domain-specific security frameworks.
The architecture is designed for security-critical use cases that demand high levels of assurance beyond what can be provided by lightweight isolation technologies such as containers or application sandboxes. It enforces an on-chip Zero Trust security model by combining a strongly isolated Bunker with an Open World execution environment. The Bunker hosts trusted, security- and safety-critical functions, while the Open World executes non-trusted or lower-assurance software.
The architecture guarantees that the Open World has no direct access to Bunker resources. Even if the Open World is fully compromised, the Bunker continues to preserve the confidentiality, integrity, and availability of protected assets and critical functions through hardware-assisted isolation and hypervisor-enforced separation.
Block diagram of Bunker for Linux, a BCA reference design.ΒΆ
The architecture is designed to be flexible and highly customizable, allowing system integrators to adapt both trusted and non-trusted components to their specific security, functional, and regulatory requirements.
Bunker-Centric Architecture (BCA) is composed of two logical domains:
Open World, one or more non-trusted operating systems executing general-purpose, non-critical workloads defined by the customer. Each Open World instance is sandboxed by the hypervisor and has access only to the virtual devices and interfaces required for its tasks.
Bunker, the trusted computing domain, comprising:
Bunker OS, trusted and hardened operating system hosting security-sensitive applications and security services (e.g., logging, OTA)
Bunker-TEE, Trusted Execution Environment for isolated secure services
Type-1 Hypervisor, hypervisor enforcing strong isolation between domains
Bunker FW, secure firmware providing boot and platform security services
Bunker RTOS, a RTOS running on a MCU / Real-Time Subsystem
In general, BCA does not mandate specific implementations for these components. For example, the Trusted Execution Environment may be implemented using OP-TEE, Trusty TEE, or other TEE technologies, while the Bunker OS and firmware components may be based on Linux, proprietary operating systems, or vendor-specific solutions. Furthermore, Bunker RTOS may be based on Zephyr or FreeRTOS.
Accelerat provides a reference, commercial implementation of BCA for the Armv8-A (aarch64) architecture. Support for RISC-V and x86-64 architectures is currently on the roadmap.
The Acceleratβs implementation maps the BCA components as follows:
Open World: one vanilla Linux image for general-purpose workloads (e.g., the one provided by the hardware vendor)
Bunker OS: security-hardened minimal Linux provided by Accelerat
Bunker-TEE: OP-TEE
Type-1 Hypervisor: Acceleratβs CLARE-Hypervisor
Bunker FW: TF-A (Trusted Firmware-A)
Bunker RTOS: FreeRTOS
The reference implementation is available in multiple flavours, including:
AI Bunker - optimized for deploying the Bunker as a Trusted Inference Environment; without any external exposure, the AI Bunker is conceived to host AI models that need to be protected from theft or unauthorized accesses (model confidentiality and integrity).
Bunker for Linux - general-purpose design optimized for hosting security-realted applications that need the Linux operating system.
The reference implementation also comes with built-in security services for operation and deployment, namely secure update management, anti-tampering logging, and attack-resistant monitoring.