Skip to main content

2020 | OriginalPaper | Buchkapitel

ISO/SAE DIS 21434 Automotive Cybersecurity Standard - In a Nutshell

verfasst von : Georg Macher, Christoph Schmittner, Omar Veledar, Eugen Brenner

Erschienen in: Computer Safety, Reliability, and Security. SAFECOMP 2020 Workshops

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

A range of connected and automated vehicles is already available, which is intensifying the usage of connectivity features and information sharing for vehicle maintenance and traffic safety features. The resulting highly connected networking amplifies the attractiveness level for attacks on vehicles and connected infrastructure by hackers with different motivations. Hence, the newly introduced cybersecurity risks are attracting a range of mitigating strategies across the automotive field. The industry’s target is to design and deliver safe and secure connected and automated vehicles. Therefore, efforts are being poured into developing an industry standard capable of tackling automotive cybersecurity issues and protecting assets. The joint working group of the standardization organizations ISO and SAE have recently established and published a draft international specification of the “ISO/SAE DIS 21434 Road Vehicles - Cybersecurity Engineering” standard.
This document delivers a review of the available draft. This work provides a position statement for discussion of available analysis methods and recommendations given in the standard. The aim is to provide a basis for industry experts and researchers for an initial review of the standard and consequently trigger discussions and suggestions of best practices and methods for application in the context of the standard.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat IEC 62443: Industrial communication networks - network and system security IEC 62443: Industrial communication networks - network and system security
2.
Zurück zum Zitat ISO 27000 series, information technology - security techniques ISO 27000 series, information technology - security techniques
3.
Zurück zum Zitat Caltagirone, S., Pendergast, A., Betz, C.: The diamond model of intrusion analysis. Technical report, Center for Cyber Intelligence Analysis and Threat Research Hanover Md (2013) Caltagirone, S., Pendergast, A., Betz, C.: The diamond model of intrusion analysis. Technical report, Center for Cyber Intelligence Analysis and Threat Research Hanover Md (2013)
4.
Zurück zum Zitat Dobaj, J., Schmittner, C., Krisper, M., Macher, G.: Towards integrated quantitative security and safety risk assessment. In: Romanovsky, A., Troubitsyna, E., Gashi, I., Schoitsch, E., Bitsch, F. (eds.) Computer Safety. Reliability, and Security, pp. 102–116. Springer, Cham (2019). https://doi.org/10.1007/978-3-030-26250-1_8CrossRef Dobaj, J., Schmittner, C., Krisper, M., Macher, G.: Towards integrated quantitative security and safety risk assessment. In: Romanovsky, A., Troubitsyna, E., Gashi, I., Schoitsch, E., Bitsch, F. (eds.) Computer Safety. Reliability, and Security, pp. 102–116. Springer, Cham (2019). https://​doi.​org/​10.​1007/​978-3-030-26250-1_​8CrossRef
6.
Zurück zum Zitat Henniger, O., Ruddle, A., Seudié, H., Weyl, B., Wolf, M., Wollinger, T.: Securing vehicular on-board IT systems: The EVITA project. In: VDI/VW Automotive Security Conference, p. 41 (2009) Henniger, O., Ruddle, A., Seudié, H., Weyl, B., Wolf, M., Wollinger, T.: Securing vehicular on-board IT systems: The EVITA project. In: VDI/VW Automotive Security Conference, p. 41 (2009)
7.
Zurück zum Zitat ISO - International Organization for Standardization. IEC 61508 Functional safety of electrical/electronic/programmable electronic safety-related systems ISO - International Organization for Standardization. IEC 61508 Functional safety of electrical/electronic/programmable electronic safety-related systems
8.
Zurück zum Zitat ISO - International Organization for Standardization. IEC 60812 Analysis techniques for system reliability - Procedure for failure mode and effects analysis (FMEA) (2006) ISO - International Organization for Standardization. IEC 60812 Analysis techniques for system reliability - Procedure for failure mode and effects analysis (FMEA) (2006)
9.
Zurück zum Zitat ISO - International Organization for Standardization. IEC 61025 Fault tree analysis (FTA), December 2006 ISO - International Organization for Standardization. IEC 61025 Fault tree analysis (FTA), December 2006
10.
Zurück zum Zitat ISO - International Organization for Standardization. ISO 26262 Road vehicles Functional Safety Part 1–10 (2011) ISO - International Organization for Standardization. ISO 26262 Road vehicles Functional Safety Part 1–10 (2011)
11.
Zurück zum Zitat ISO - International Organization for Standardization. ISO/SAE DIS 21434 Road Vehicles - Cybersecurity engineering (2020) ISO - International Organization for Standardization. ISO/SAE DIS 21434 Road Vehicles - Cybersecurity engineering (2020)
14.
Zurück zum Zitat Macher, G., Messnarz, R., Armengaud, A., Eric, A., Riel, A., Brenner, E., Kreiner, C.: Integrated safety and security development in the automotive domain. In: SAE Technical Paper. SAE International (2017) Macher, G., Messnarz, R., Armengaud, A., Eric, A., Riel, A., Brenner, E., Kreiner, C.: Integrated safety and security development in the automotive domain. In: SAE Technical Paper. SAE International (2017)
15.
Zurück zum Zitat Macher, G., Schmittner, C., Dobaj, J., Armengaud, E., Messnarz, R.: An integrated view on automotive spice, functional safety and cyber-security. In: SAE Technical Paper. SAE International, April 2020 Macher, G., Schmittner, C., Dobaj, J., Armengaud, E., Messnarz, R.: An integrated view on automotive spice, functional safety and cyber-security. In: SAE Technical Paper. SAE International, April 2020
16.
Zurück zum Zitat Macher, G., Sporer, H., Berlach, R., Armengaud, E., Kreiner, C.: SAHARA: a security-aware hazard and risk analysis method. In: Design, Automation Test in Europe Conference Exhibition (DATE), pp. 621–624, March 2015 Macher, G., Sporer, H., Berlach, R., Armengaud, E., Kreiner, C.: SAHARA: a security-aware hazard and risk analysis method. In: Design, Automation Test in Europe Conference Exhibition (DATE), pp. 621–624, March 2015
17.
Zurück zum Zitat Macher, G., Sporer, H., Brenner, E., Kreiner, C., An automotive signal-layer security and trust-boundary identification approach. Procedia Comput. Sci. 109, 490–497 (2017). 8th International Conference on Ambient Systems, Networks and Technologies, ANT-2017 and the 7th International Conference on Sustainable Energy Information Technology, SEIT 2017, 16–19 May 2017. Madeira, Portugal (2017) Macher, G., Sporer, H., Brenner, E., Kreiner, C., An automotive signal-layer security and trust-boundary identification approach. Procedia Comput. Sci. 109, 490–497 (2017). 8th International Conference on Ambient Systems, Networks and Technologies, ANT-2017 and the 7th International Conference on Sustainable Energy Information Technology, SEIT 2017, 16–19 May 2017. Madeira, Portugal (2017)
18.
Zurück zum Zitat Schmittner, C., Griessnig, G., Ma, Z.: Status of the development of ISO/SAE 21434. In: Larrucea, X., Santamaria, I., O’Connor, R.V., Messnarz, R. (eds.) Systems, Software and Services Process Improvement, vol. 896, pp. 504–513. Springer, Heidelberg (2018). https://doi.org/10.1007/978-3-319-97925-0_43 Schmittner, C., Griessnig, G., Ma, Z.: Status of the development of ISO/SAE 21434. In: Larrucea, X., Santamaria, I., O’Connor, R.V., Messnarz, R. (eds.) Systems, Software and Services Process Improvement, vol. 896, pp. 504–513. Springer, Heidelberg (2018). https://​doi.​org/​10.​1007/​978-3-319-97925-0_​43
22.
Zurück zum Zitat Vehicle Electrical System Security Committee. SAE J3061 Cybersecurity Guidebook for Cyber-Physical Automotive Systems Vehicle Electrical System Security Committee. SAE J3061 Cybersecurity Guidebook for Cyber-Physical Automotive Systems
Metadaten
Titel
ISO/SAE DIS 21434 Automotive Cybersecurity Standard - In a Nutshell
verfasst von
Georg Macher
Christoph Schmittner
Omar Veledar
Eugen Brenner
Copyright-Jahr
2020
DOI
https://doi.org/10.1007/978-3-030-55583-2_9