RESOLUTION OF SAFETY RELEVANT SECURITY THREATS IN THE SYSTEM ARCHITECTURE DESIGN PHASE ON THE EXAMPLE OF AUTOMOTIVE INDUSTRY

Sergej Japs,Harald Anacker
DOI: https://doi.org/10.1017/pds.2021.517
2021-07-27
Proceedings of the Design Society
Abstract:Abstract Cyber-physical systems (CPS), like autonomous vehicles, are intelligent and networked. The development of such systems and its components requires interdisciplinary cooperation between different stakeholders. A lack of system understanding between stakeholders can lead to unidentified and unresolved security threats & safety hazards in early engineering phases, resulting in high costs in product development and potentially compromises compliance with the safety of CPS. Model-based systems engineering (MBSE) improves the system understanding between stakeholders by using models. However, MBSE approaches only partially address security threats & safety hazards. In particular, their integrative consideration is not taken into account. Established security & safety approaches are either only applicable to specific disciplines or only partially consider security threats & safety hazards. In the context of this paper we present a method for the resolution of safety relevant security threats in the system architecture design phase using design patterns. We illustrate our approach with the example of the automotive sector. Finally, we present an evaluation of the method, based on an 8 week project with 67 master students.
What problem does this paper attempt to address?