Complying with ISO 26262 and ISO/SAE 21434: A Safety and Security Co-Analysis Method for Intelligent Connected Vehicle

Yufeng Li,Wenqi Liu,Qi Liu,Xiangyu Zheng,Ke Sun,Chengjian Huang
DOI: https://doi.org/10.3390/s24061848
IF: 3.9
2024-03-14
Sensors
Abstract:A cyber-physical system (CPS) integrates communication and automation technologies into the operational processes of physical systems. Nowadays, as a complex CPS, an intelligent connected vehicle (ICV) may be exposed to accidental functional failures and malicious attacks. Therefore, ensuring the ICV's safety and security is crucial. Traditional safety/security analysis methods, such as failure mode and effect analysis and attack tree analysis, cannot provide a comprehensive analysis for the interactions between the system components of the ICV. In this work, we merge system-theoretic process analysis (STPA) with the concept phase of ISO 26262 and ISO/SAE 21434. We focus on the interactions between components while analyzing the safety and security of ICVs to reduce redundant efforts and inconsistencies in determining safety and security requirements. To conquer STPA's abstraction in describing causal scenarios, we improved the physical component diagram of STPA-SafeSec by adding interface elements. In addition, we proposed the loss scenario tree to describe specific scenarios that lead to unsafe/unsecure control actions. After hazard/threat analysis, a unified risk assessment process is proposed to ensure consistency in assessment criteria and to streamline the process. A case study is implemented on the autonomous emergency braking system to demonstrate the validation of the proposed method.
engineering, electrical & electronic,chemistry, analytical,instruments & instrumentation
What problem does this paper attempt to address?
The problem this paper attempts to address is the comprehensive analysis of functional safety and cybersecurity in Intelligent Connected Vehicles (ICV). With the development of vehicle intelligence and networking technology, ICVs not only face traditional functional failure risks but also potential cyber-attacks, which can similarly lead to safety incidents. Therefore, ensuring the safety and cybersecurity of ICVs has become crucial. Existing safety or security analysis methods, such as Failure Mode and Effects Analysis (FMEA) and Attack Tree Analysis (ATA), cannot comprehensively analyze the interactions between ICV system components, making it difficult to effectively identify and assess safety and cybersecurity risks. Additionally, traditional functional safety engineering methods and cybersecurity methods are usually conducted by different teams, which may lead to insufficient information sharing, differences in analysis methods, and a lack of comprehensive consideration of the interrelationship between safety and cybersecurity. To address these issues, the paper proposes a co-analysis method for safety and cybersecurity that complies with ISO 26262 and ISO/SAE 21434 standards. This method combines System-Theoretic Process Analysis (STPA) with the concept phase of ISO 26262 and the concept phase of ISO/SAE 21434, focusing on analyzing the interactions between system components to reduce redundant work and inconsistencies when determining safety and cybersecurity requirements. Specifically, the paper improves the physical component diagram of STPA by adding interface elements and proposes a loss scenario tree to describe specific scenarios leading to unsafe or insecure control actions. Additionally, the paper proposes a unified risk assessment process to ensure consistency in assessment standards and simplify the process. The effectiveness of the proposed method is validated through a case study, specifically the application of an autonomous emergency braking system. Overall, the paper aims to provide a method that can comprehensively identify and assess loss scenarios in ICV systems, thereby supporting the concept phase of the vehicle development process.