The computers that fly European aircraft and spacecraft are moving from single-core to multicore processors, and the move changes what has to be proved before a safety-critical function can be trusted. On a single core, the time an application needs depends mainly on the application itself. On a multicore processor, applications running on different cores compete for the same caches, memory, interconnects and interfaces, so the timing of one function can depend on what another function, hosted on a different core and perhaps supplied by a different company, happens to be doing. The evidence that a function will always finish in time therefore stops being a property of the function alone and becomes a property of the whole configuration: the processor, its settings, the hypervisor or operating system that partitions it, and every application it hosts. That evidence is expensive to produce, and it is produced by several parties at different moments. A defence integrator who later needs to update an application, retune a configuration, replace a hypervisor or move to a new processor, possibly because a supplier has exited or a component has become obsolete, faces a practical question that is rarely answered in public: when one part of a multicore platform changes, which part of the existing assurance evidence remains usable, who produced it, and on what terms can the integrator and the authority still rely on it?
© 2026 Defence Finance Monitor · Privacy ∙ Terms ∙ Collection notice
Substack is the home for great culture


