汽车移动接入系统通用多级风险评估方法

Thomas Termin, D. Lichte, K. Wolf
{"title":"汽车移动接入系统通用多级风险评估方法","authors":"Thomas Termin, D. Lichte, K. Wolf","doi":"10.3850/978-981-14-8593-0_5778-CD","DOIUrl":null,"url":null,"abstract":"Nowadays mobility companies have to deal with the digitization of analog products and services. A central scope of interest is the design of mobile access systems, intended to replace the physical key. However, these systems do not only involve new use cases but also risks that place safety and security issues in the foreground of the system design. To ensure protection against safety and security risks, a procedure that allows multilevel system evaluation is necessary. Practical experience in risk assessment (SRA) shows field-specific approaches widely used. In order to facilitate an embedded safe and secure system design, this paper introduces a generic assessment method, which considers different system configurations and multilevel safety and security risks. Within this procedure, previously identified technical requirements are mapped in a Morphological Box (MB) to describe the configuration space (CS) of the system. In order to evaluate the system, use cases and sequences as well as misuse cases are mapped using UML. Identified threats and attack paths are transferred into fault and attack trees. The results of the fault tree analysis (FTA) and attack tree analysis (ATA) allows the definition of security requirements. Additionally, the process reveals non-standard scenarios that demand further detailed analysis. The proposed approach is applied to the example of an automotive mobile access system.","PeriodicalId":201963,"journal":{"name":"Proceedings of the 30th European Safety and Reliability Conference and 15th Probabilistic Safety Assessment and Management Conference","volume":"52 8","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"Approach to Generic Multilevel Risk Assessment of Automotive Mobile Access Systems\",\"authors\":\"Thomas Termin, D. Lichte, K. Wolf\",\"doi\":\"10.3850/978-981-14-8593-0_5778-CD\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Nowadays mobility companies have to deal with the digitization of analog products and services. A central scope of interest is the design of mobile access systems, intended to replace the physical key. However, these systems do not only involve new use cases but also risks that place safety and security issues in the foreground of the system design. To ensure protection against safety and security risks, a procedure that allows multilevel system evaluation is necessary. Practical experience in risk assessment (SRA) shows field-specific approaches widely used. In order to facilitate an embedded safe and secure system design, this paper introduces a generic assessment method, which considers different system configurations and multilevel safety and security risks. Within this procedure, previously identified technical requirements are mapped in a Morphological Box (MB) to describe the configuration space (CS) of the system. In order to evaluate the system, use cases and sequences as well as misuse cases are mapped using UML. Identified threats and attack paths are transferred into fault and attack trees. The results of the fault tree analysis (FTA) and attack tree analysis (ATA) allows the definition of security requirements. Additionally, the process reveals non-standard scenarios that demand further detailed analysis. The proposed approach is applied to the example of an automotive mobile access system.\",\"PeriodicalId\":201963,\"journal\":{\"name\":\"Proceedings of the 30th European Safety and Reliability Conference and 15th Probabilistic Safety Assessment and Management Conference\",\"volume\":\"52 8\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"1900-01-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Proceedings of the 30th European Safety and Reliability Conference and 15th Probabilistic Safety Assessment and Management Conference\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.3850/978-981-14-8593-0_5778-CD\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 30th European Safety and Reliability Conference and 15th Probabilistic Safety Assessment and Management Conference","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.3850/978-981-14-8593-0_5778-CD","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

摘要

如今,移动公司不得不应对模拟产品和服务的数字化。感兴趣的一个中心范围是移动访问系统的设计,旨在取代物理密钥。然而,这些系统不仅涉及新的用例,而且还存在将安全和安保问题置于系统设计前景的风险。为了确保防范安全和保安风险,需要一个允许多级系统评估的程序。风险评估(SRA)的实践经验表明,特定领域的方法被广泛使用。为了方便嵌入式系统的安全设计,本文介绍了一种考虑不同系统配置和多级安全风险的通用评估方法。在此过程中,先前确定的技术需求被映射到形态学盒(MB)中,以描述系统的配置空间(CS)。为了评估系统,用例和序列以及误用用例使用UML进行映射。识别出的威胁和攻击路径被转换成故障树和攻击树。故障树分析(FTA)和攻击树分析(ATA)的结果可以用于定义安全需求。此外,该过程还揭示了需要进一步详细分析的非标准场景。将所提出的方法应用于汽车移动接入系统的实例。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Approach to Generic Multilevel Risk Assessment of Automotive Mobile Access Systems
Nowadays mobility companies have to deal with the digitization of analog products and services. A central scope of interest is the design of mobile access systems, intended to replace the physical key. However, these systems do not only involve new use cases but also risks that place safety and security issues in the foreground of the system design. To ensure protection against safety and security risks, a procedure that allows multilevel system evaluation is necessary. Practical experience in risk assessment (SRA) shows field-specific approaches widely used. In order to facilitate an embedded safe and secure system design, this paper introduces a generic assessment method, which considers different system configurations and multilevel safety and security risks. Within this procedure, previously identified technical requirements are mapped in a Morphological Box (MB) to describe the configuration space (CS) of the system. In order to evaluate the system, use cases and sequences as well as misuse cases are mapped using UML. Identified threats and attack paths are transferred into fault and attack trees. The results of the fault tree analysis (FTA) and attack tree analysis (ATA) allows the definition of security requirements. Additionally, the process reveals non-standard scenarios that demand further detailed analysis. The proposed approach is applied to the example of an automotive mobile access system.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信