Skip to article frontmatterSkip to article content
Site not loading correctly?

This may be due to an incorrect BASE_URL configuration. See the MyST Documentation for reference.

This section presents a hypothetical security architecture for the SkyLink Connected Aircraft Platform, comprising a set of data flow diagrams and associated security controls.

Document Information

AttributeValue
Document OwnerSkyLink Platform Team
ClassificationInternal
Document Version1.0
Last Review DateDecember 2025
Next Review DateJune 2026
Related Documentstbd

Overview

Purpose

This document describes the security architecture of the SkyLink platform using Data Flow Diagrams (DFD) to illustrate:

Scope

This architecture covers:

Audience


System Context (Level 0)

Context Diagram

Example context diagram

External Actors

ActorDescriptionAuthenticationData Exchanged
Aircraft SystemsOnboard avionics and telemetry systemsmTLS + JWT RS256Telemetry data, weather requests
WeatherAPIThird-party weather data providerAPI Key (outbound)Weather conditions, air quality
Google People APIGoogle contact synchronizationOAuth 2.0 (outbound)Contact names, emails
Admin OperatorsPlatform administratorsTBD (future)Configuration, monitoring

Trust Boundaries

Boundary Definitions

IDBoundaryFromToRisk Level
TB1Internet → GatewayUntrusted (Internet)DMZ (Gateway)CRITICAL
TB2Gateway → ServicesDMZInternal ServicesMEDIUM
TB3Services → External APIsInternalExternal (Vendors)HIGH
TB4Services → DatabaseInternalData LayerHIGH

Security Controls per Boundary

TB1: Internet → Gateway (CRITICAL)

TRUST BOUNDARY: Internet → API Gateway

ThreatControl
Spoofing→ mTLS (X.509 client certs)
Man-in-the-Middle→ TLS 1.2+ with strong ciphers
Replay attacks→ JWT expiry (15 min)
DDoS / Flooding→ Rate limiting (60 req/min)
Injection→ Pydantic validation (extra=forbid)
Information disclosure→ Security headers (OWASP)
Large payloads→ 64 KB request limit

AUTHENTICATION FLOW:

  1. TLS handshake (mutual authentication)

  2. Client certificate validation (CA-signed)

  3. CN extraction from certificate

  4. JWT token issuance (sub = CN)

  5. Cross-validation on subsequent requests (CN == sub)

TB2: Gateway → Services (MEDIUM)

TRUST BOUNDARY 2 : Gateway → Internal Services

ASSUMPTION:

CONTROLS:

DATA FLOW:

NOTE:

TB3: Services → External APIs (HIGH)

SectionConnection / ItemDetails / Configuration
Outbound ConnectionsWeather Service ──[HTTPS]──► WeatherAPI• API key in request header
• Geohash/coordinates (no raw GPS)
• Demo mode fallback (fixtures)
Contacts Service ──[HTTPS]──► Google People API• OAuth 2.0 bearer token
• Minimal scope (contacts.readonly)
• Token refresh handling
ControlsSecurity & Network• HTTPS enforced (TLS 1.2+)
• API keys not logged
• Response validation
• Timeout configuration

TB4: Services → Database (HIGH)

SectionItemDetails / Configuration
ConnectionContacts Service ──[TCP:5432]──► PostgreSQL• Direct TCP connection
ControlsSecurity & Architecture• Network isolation (Docker bridge)
• Credential-based authentication
• Connection pooling (SQLAlchemy)
• Parameterized queries (no SQL injection)
Data StoredStored Records• OAuth tokens (AES-256-GCM encrypted)
• User identifiers
• Token expiration metadata
Data ProtectionPrivacy & Encryption• Encryption at rest (application-level)
• No plaintext secrets in database

Data Flow Diagrams (Level 1)

Flow 1: Aircraft Authentication

Data Flow diagram

Security Controls Applied:

Flow 2: Telemetry Ingestion

Data Flow2 diagram

HTTP Response Codes:

CodeMeaningScenario
201CreatedNew event stored
200OKDuplicate event (idempotent)
409ConflictSame event_id, different payload
400Bad RequestValidation error
401UnauthorizedInvalid/expired JWT
403ForbiddenCN ≠ JWT.sub
429Too Many RequestsRate limit exceeded

Flow 3: Weather Query

Data Flow3 diagram

Data Protection:

Flow 4: Contacts OAuth

Data Flow OATH

OAuth Security:


Security Controls by Layer

Control Matrix

LayerControlImplementation
TransportTLS 1.2+mTLS with strong ciphers
TransportCertificate validationX.509, CA-signed
NetworkService isolationDocker bridge network
ApplicationAuthenticationJWT RS256
ApplicationAuthorizationRBAC (5 roles, 7 permissions)
ApplicationCross-validationCN == JWT sub
ApplicationRate limiting60 req/min per identity
ApplicationInput validationPydantic extra=forbid
ApplicationIdempotencyUnique constraint
ApplicationSecurity headersOWASP set
DataPII minimizationGPS rounding (4 dec)
DataToken encryptionAES-256-GCM
DataNo PII in logsStructured logging
ContainerNon-root userUID 1000
Supply ChainDependency scanningpip-audit, Trivy
Supply ChainImage signingCosign (keyless)
Supply ChainSBOMCycloneDX
Supply ChainSecret detectionGitleaks

Defense in Depth Visualization

Defense in Depth

Data Classification

Classification Matrix

Data TypeClassificationAt RestIn TransitIn LogsRetention
Aircraft UUIDInternalPlaintextTLSAllowedUnlimited
Telemetry (speed, alt)ConfidentialPlaintextTLStrace_id only90 days
GPS PositionPIIRounded (4 dec)TLSNever90 days
Google ContactsPIINot storedTLSNeverSession only
OAuth TokensRestrictedAES-256-GCMTLSNeverUntil revoked
JWT TokensRestrictedN/A (memory)TLSNever15 min
mTLS CertificatesRestrictedFile (0600)TLSNever1 year
API KeysRestrictedEnv varTLSNeverUntil rotated

Data Handling Rules

Data ClassificationExamplesLoggingStorageTransmissionOther Rules
INTERNAL DATAAircraft UUID, trace_id✓ Can be logged✓ Can be stored plaintext✓ Can be transmitted—
CONFIDENTIAL DATATelemetry✗ Cannot be logged (only trace_id)✓ Can be stored✓ Must be encrypted in transit (TLS)—
PII DATAGPS, Contacts✗ Never logged⚠ GPS must be rounded (4 decimals = ~11m accuracy)
⚠ Contacts are read-only, not persisted
✓ Must be encrypted in transit (TLS)—
RESTRICTED DATATokens, Keys, Certs✗ Never logged✓ Must be encrypted at rest (AES-256-GCM)✓ Must be encrypted in transit (TLS)✗ Never in source code
✓ Environment variables or secrets manager

Attack Surface Analysis

Attack Surface Map

SurfaceExposureRisk LevelAttack VectorsMitigations
API Gateway :8000InternetCRITICALDDoS, injection, auth bypassmTLS, JWT, rate limit, validation
Internal ServicesDocker networkMEDIUMLateral movementNetwork isolation, no auth needed
PostgreSQL :5432Docker networkHIGHSQL injection, data theftCredentials, parameterized queries
Container RegistryInternetHIGHImage tamperingCosign signing, Trivy scanning
CI/CD PipelineGitHub/GitLabHIGHSecret theft, code injectionGitleaks, protected branches
External APIsOutboundMEDIUMData leakageHTTPS, minimal data sharing

Exposed Endpoints

EndpointAuthenticationRate LimitedInput ValidationRisk
GET /healthNoneNoN/ALOW
GET /metricsNoneNoN/ALOW
POST /auth/tokenmTLSYesPydanticMEDIUM
POST /telemetry/ingestmTLS + JWTYesPydantic strictHIGH
GET /weather/currentJWTYesQuery paramsMEDIUM
GET /contacts/JWTYesQuery paramsMEDIUM

Cryptographic Inventory

Algorithms and Key Sizes

PurposeAlgorithmKey SizeRotation PeriodStorage
JWT SigningRS256 (RSA-SHA256)2048-bit90 daysEnv var (PRIVATE_KEY_PEM)
JWT VerificationRS2562048-bit90 daysEnv var (PUBLIC_KEY_PEM)
Token EncryptionAES-256-GCM256-bit90 daysEnv var (ENCRYPTION_KEY)
mTLS CARSA/X.5092048-bit1 yearFile (certs/ca/ca.crt)
mTLS ServerRSA/X.5092048-bit1 yearFile (certs/server/)
mTLS ClientRSA/X.5092048-bit1 yearFile (certs/clients/)
Image SigningECDSA (Sigstore)P-256Keyless (per-build)GitHub OIDC

Key Management

Key Management

Network Security

Network Topology

Network Topology

Network Policies

ServiceAllowed InboundAllowed Outbound
gatewayInternet:8000telemetry, weather, contacts
telemetrygatewayNone
weathergatewayWeatherAPI (HTTPS)
contactsgatewayGoogle APIs (HTTPS), db:5432
dbcontactsNone

Kubernetes Network Policies

For production Kubernetes deployments, network policies enforce zero-trust networking:

# Default: deny all traffic
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: skylink-default-deny
spec:
  podSelector: {}
  policyTypes:
    - Ingress
    - Egress

Kubernetes Network Policy Matrix:

PolicyFromToPortsPurpose
gateway-ingressingress-nginxgateway8000External access
gateway-egressgatewayinternal services8001-8003Service routing
internal-ingressgatewaytelemetry/weather/contacts8001-8003Internal traffic
internal-egressinternal servicesexternal APIs443API calls
prometheus-scrapemonitoring namespaceall pods8000-8003Metrics collection

Security Headers

X-Content-Type-Options: nosniff
X-Frame-Options: DENY
Cache-Control: no-store, no-cache, must-revalidate, max-age=0
Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Embedder-Policy: require-corp
Referrer-Policy: no-referrer
Permissions-Policy: geolocation=(), microphone=(), camera=()

JWT Claims

{
  "sub": "aircraft_id (from mTLS CN)",
  "aud": "skylink",
  "iat": 1734600000,
  "exp": 1734600900,
  "role": "aircraft_standard"
}

RBAC Roles

RoleDescriptionKey Permissions
aircraft_standardDefault aircraftweather:read, telemetry:write
aircraft_premiumPremium aircraft+ contacts:read
ground_controlGround controlweather:read, contacts:read, telemetry:read
maintenanceMaintenancetelemetry:read/write, config:read
adminAdministratorAll permissions

Rate Limits

ScopeLimitWindow
Per aircraft_id60 requests1 minute
Global10 requests1 second