Towards the development of the cybersecurity concept according to ISO/SAE 21434 using model-based systems engineering *

Sergej Japs
{"title":"Towards the development of the cybersecurity concept according to ISO/SAE 21434 using model-based systems engineering *","authors":"Sergej Japs","doi":"10.1109/RE51729.2021.00073","DOIUrl":null,"url":null,"abstract":"Cyber-physical systems (CPS), such as autonomous vehicles, are intelligent and networked. Close collaboration between stakeholders from different disciplines is necessary right from the start of development. In the automotive sector in particular, the collaboration of the car manufacturer extends to several suppliers. The increasing complexity in the design of such CPSs makes interdisciplinary and cross-company collaboration more difficult. Here, requirements specifications serve as a support for communication. A lack of overall understanding of such CPSs and their numerous interfaces jeopardizes the assurance of safety-relevant security. ISO/SAE 21434, which applies to the automotive industry, requires the creation of a cybersecurity concept at the beginning of the product development process. The problem is that ISO/SAE 21434 only prescribes WHAT must be done, but does not define HOW this is supposed to be done methodically.Existing methods are not applicable to the concept phase without extensive tailoring, according to the challenges I identified in this paper and the literature review I conducted. Furthermore, I present four papers I have written and four papers I plan to write, which serve as building blocks for the required overall method. Finally, I explain how I plan to evaluate my approach.","PeriodicalId":440285,"journal":{"name":"2021 IEEE 29th International Requirements Engineering Conference (RE)","volume":"60 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 IEEE 29th International Requirements Engineering Conference (RE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/RE51729.2021.00073","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

Cyber-physical systems (CPS), such as autonomous vehicles, are intelligent and networked. Close collaboration between stakeholders from different disciplines is necessary right from the start of development. In the automotive sector in particular, the collaboration of the car manufacturer extends to several suppliers. The increasing complexity in the design of such CPSs makes interdisciplinary and cross-company collaboration more difficult. Here, requirements specifications serve as a support for communication. A lack of overall understanding of such CPSs and their numerous interfaces jeopardizes the assurance of safety-relevant security. ISO/SAE 21434, which applies to the automotive industry, requires the creation of a cybersecurity concept at the beginning of the product development process. The problem is that ISO/SAE 21434 only prescribes WHAT must be done, but does not define HOW this is supposed to be done methodically.Existing methods are not applicable to the concept phase without extensive tailoring, according to the challenges I identified in this paper and the literature review I conducted. Furthermore, I present four papers I have written and four papers I plan to write, which serve as building blocks for the required overall method. Finally, I explain how I plan to evaluate my approach.
使用基于模型的系统工程*,根据ISO/SAE 21434开发网络安全概念
网络物理系统(CPS),如自动驾驶汽车,是智能和网络化的。来自不同学科的利益相关者之间的密切合作从开发开始就很有必要。特别是在汽车领域,汽车制造商的合作扩展到几个供应商。这种cps设计的复杂性日益增加,使得跨学科和跨公司的协作更加困难。在这里,需求规范作为通信的支持。缺乏对这类cps及其众多接口的全面了解会危及与安全有关的保安的保证。适用于汽车行业的ISO/SAE 21434要求在产品开发过程的开始就建立网络安全概念。问题是ISO/SAE 21434只规定了必须做什么,但没有规定应该如何有条不紊地完成。根据我在本文中发现的挑战和我进行的文献综述,如果没有广泛的剪裁,现有的方法不适用于概念阶段。此外,我将提交我已经写的四篇论文和我计划写的四篇论文,作为所需的整体方法的基石。最后,我解释了我计划如何评估我的方法。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信