论文标题
ISO 21434的安全工程
Security Engineering for ISO 21434
论文作者
论文摘要
ISO 21434是一种新标准,旨在应对汽车网络安全的未来挑战。这份白皮书仔细研究了ISO 21434,帮助工程师了解ISO 21434零件,要进行的关键活动以及应生产的主要人工制品。作为任何认证,获得ISO 21434认证的一见钟情可能令人生畏。工程师必须部署包括几种安全风险评估方法的流程,以提出安全论点和支持项目安全要求的证据。在这份白皮书中,我们提出了一种安全工程方法,该方法可以通过依靠自动化支持的严格安全评估和增量评估维护方法来缓解此过程。我们以示例证明,所提出的方法可以大大提高生产的人工制品的质量,生产它们的效率,并实现持续的安全评估。最后,我们指出了我们正在研究的一些关键研究方向,以完全实现拟议的方法。
The ISO 21434 is a new standard that has been proposed to address the future challenges of automotive cybersecurity. This white paper takes a closer look at the ISO 21434 helping engineers to understand the ISO 21434 parts, the key activities to be carried out and the main artefacts that shall be produced. As any certification, obtaining the ISO 21434 certification can be daunting at first sight. Engineers have to deploy processes that include several security risk assessment methods to produce security arguments and evidence supporting item security claims. In this white paper, we propose a security engineering approach that can ease this process by relying on Rigorous Security Assessments and Incremental Assessment Maintenance methods supported by automation. We demonstrate by example that the proposed approach can greatly increase the quality of the produced artefacts, the efficiency to produce them, as well as enable continuous security assessment. Finally, we point out some key research directions that we are investigating to fully realize the proposed approach.