Suppr超能文献

符合ISO 26262和ISO/SAE 21434:一种用于智能网联汽车的安全与安保协同分析方法。

Complying with ISO 26262 and ISO/SAE 21434: A Safety and Security Co-Analysis Method for Intelligent Connected Vehicle.

作者信息

Li Yufeng, Liu Wenqi, Liu Qi, Zheng Xiangyu, Sun Ke, Huang Chengjian

机构信息

School of Computer Engineering and Science, Shanghai University, Shanghai 200444, China.

The Purple Mountain Laboratories, Nanjing 211111, China.

出版信息

Sensors (Basel). 2024 Mar 13;24(6):1848. doi: 10.3390/s24061848.

Abstract

A cyber-physical system (CPS) integrates communication and automation technologies into the operational processes of physical systems. Nowadays, as a complex CPS, an intelligent connected vehicle (ICV) may be exposed to accidental functional failures and malicious attacks. Therefore, ensuring the ICV's safety and security is crucial. Traditional safety/security analysis methods, such as failure mode and effect analysis and attack tree analysis, cannot provide a comprehensive analysis for the interactions between the system components of the ICV. In this work, we merge system-theoretic process analysis (STPA) with the concept phase of ISO 26262 and ISO/SAE 21434. We focus on the interactions between components while analyzing the safety and security of ICVs to reduce redundant efforts and inconsistencies in determining safety and security requirements. To conquer STPA's abstraction in describing causal scenarios, we improved the physical component diagram of STPA-SafeSec by adding interface elements. In addition, we proposed the loss scenario tree to describe specific scenarios that lead to unsafe/unsecure control actions. After hazard/threat analysis, a unified risk assessment process is proposed to ensure consistency in assessment criteria and to streamline the process. A case study is implemented on the autonomous emergency braking system to demonstrate the validation of the proposed method.

摘要

网络物理系统(CPS)将通信和自动化技术集成到物理系统的运行过程中。如今,作为一个复杂的CPS,智能网联汽车(ICV)可能会面临意外的功能故障和恶意攻击。因此,确保ICV的安全性至关重要。传统的安全分析方法,如故障模式和影响分析以及攻击树分析,无法对ICV系统组件之间的交互进行全面分析。在这项工作中,我们将系统理论过程分析(STPA)与ISO 26262和ISO/SAE 21434的概念阶段相结合。在分析ICV的安全性时,我们关注组件之间的交互,以减少在确定安全要求时的冗余工作和不一致性。为了克服STPA在描述因果场景时的抽象性,我们通过添加接口元素改进了STPA-SafeSec的物理组件图。此外,我们提出了损失场景树来描述导致不安全/无安全保障控制行动的具体场景。在进行危险/威胁分析后,提出了一个统一的风险评估过程,以确保评估标准的一致性并简化流程。在自动紧急制动系统上进行了案例研究,以证明所提方法的有效性。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/6e60/10975927/89a119508276/sensors-24-01848-g001.jpg

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验