2021•Unpublished venueOpen access

FAST-zero'21 Paper Category: Scientific Paper: Safety Management System and Cybersecurity Management System Interfaces for Highly Automated Driving Vehicle

Marzana Khatun, Florence Wagner, Rolf Jung, Michael R. Glass

Open full text 1 citations

Abstract

For a safe operation of highly automated driving (HAD) systems on the road, the overall safety (functional safety (FS) and the safety of the intended functionality (SOTIF)) including cybersecurity must be guaranteed. Within these terms, the application of a Safety Management System (SMS) is becoming essential for HAD systems. Meanwhile, the cybersecurity for HAD systems is handled separately, familiar as Cybersecurity Management System (CSMS). To provide seamless safety and cybersecurity for highly automated vehicles on the road the two Management Systems should be linked with each other and therefore the interfaces from the SMS to cybersecurity must be defined. Furthermore, the communication flow from SMS to CSMS shall be specified to ensure that no information is lost in between. However, the development phases (SMS and CSMS) will also seemingly pomp the interface areas to industrial sectors like IEC TR 63069 [1], with UN Regulation No.155 [2] and others. The research aspects presented in this paper focus on: (1) identifying the management related adaption topics for HAD-Safety and cybersecurity considering ISO 26262 (FS), ISO/PAS 21448 (SOTIF), UL4600 (safety for evaluation), SAE J3061 (cybersecurity guidebook) and upcoming ISO 21434 (cybersecurity) [3], [4] [5], [6] and [7]. (2) the novelty in interfaces of SMS and CSMS in risk management of HAD systems. Moreover, provides a brief systematic approach to sort the collected data during the SMS processes into safety, cybersecurity, or both domains. Safety considers the functional insufficiencies (SOTIF) for hazard analysis and cybersecurity contemplates the threat analysis which can have the potential to occur a hazardous situation for HAD vehicles. Safety considers the SOTIF aspect which deals with environmental and misuse aspects but cybersecurity covers a vast area of consideration. Derived from the proposed approach a general structure for SMS interfaces to cybersecurity is created.

About this research paper

What this paper is about

For a safe operation of highly automated driving (HAD) systems on the road, the overall safety (functional safety (FS) and the safety of the intended functionality (SOTIF)) including cybersecurity must be guaranteed. Within these terms, the application of a Safety Management System (SMS) is becoming essential for HAD systems. Meanwhile, the cybersecurity for HAD systems is handled separately, familiar as Cybersecurity Management System (CSMS). To provide seamless safety and cybersecurity for highly automated vehicles on the road the two Management Systems should be linked with each other and therefore the interfaces from the SMS to cybersecurity must be defined. Furthermore, the communication flow from SMS to CSMS shall be specified to ensure that no information is lost in between. However, the development phases (SMS and CSMS) will also seemingly pomp the interface areas to industrial sectors like IEC TR 63069 [1], with UN Regulation No.155 [2] and others. The research aspects presented in this paper focus on: (1) identifying the management related adaption topics for HAD-Safety and cybersecurity considering ISO 26262 (FS), ISO/PAS 21448 (SOTIF), UL4600 (safety for evaluation), SAE J3061 (cybersecurity guidebook) and upcoming ISO 21434 (cybersecurity) [3], [4] [5], [6] and [7]. (2) the novelty in interfaces of SMS and CSMS in risk management of HAD systems. Moreover, provides a brief systematic approach to sort the collected data during the SMS processes into safety, cybersecurity, or both domains. Safety considers the functional insufficiencies (SOTIF) for hazard analysis and cybersecurity contemplates the threat analysis which can have the potential to occur a hazardous situation for HAD vehicles. Safety considers the SOTIF aspect which deals with environmental and misuse aspects but cybersecurity covers a vast area of consideration. Derived from the proposed approach a general structure for SMS interfaces to cybersecurity is created.

Why it matters

OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

For a safe operation of highly automated driving (HAD) systems on the road, the overall safety (functional safety (FS) and the safety of the intended functionality (SOTIF)) including cybersecurity must be guaranteed. Within these terms, the application of a Safety Management System (SMS) is becoming essential for HAD systems. Meanwhile, the cybersecurity for HAD systems is handled separately, familiar as Cybersecurity Management System (CSMS). To provide seamless safety and cybersecurity for highly automated vehicles on the road the two Management Systems should be linked with each other and therefore the interfaces from the SMS to cybersecurity must be defined. Furthermore, the communication flow from SMS to CSMS shall be specified to ensure that no information is lost in between. However, the development phases (SMS and CSMS) will also seemingly pomp the interface areas to industrial sectors like IEC TR 63069 [1], with UN Regulation No.155 [2] and others. The research aspects presented in this paper focus on: (1) identifying the management related adaption topics for HAD-Safety and cybersecurity considering ISO 26262 (FS), ISO/PAS 21448 (SOTIF), UL4600 (safety for evaluation), SAE J3061 (cybersecurity guidebook) and upcoming ISO 21434 (cybersecurity) [3], [4] [5], [6] and [7]. (2) the novelty in interfaces of SMS and CSMS in risk management of HAD systems. Moreover, provides a brief systematic approach to sort the collected data during the SMS processes into safety, cybersecurity, or both domains. Safety considers the functional insufficiencies (SOTIF) for hazard analysis and cybersecurity contemplates the threat analysis which can have the potential to occur a hazardous situation for HAD vehicles. Safety considers the SOTIF aspect which deals with environmental and misuse aspects but cybersecurity covers a vast area of consideration. Derived from the proposed approach a general structure for SMS interfaces to cybersecurity is created.

Key concepts: Computer security, Safety management systems, Computer science, Management system, Hazard, Incident management, Risk analysis (engineering), Engineering

Related papers

Back to paper searchBrowse research topicsOriginal source
FAST-zero'21 Paper Category: Scientific Paper: Safety Management System and Cybersecurity Management System Interfaces for Highly Automated Driving Vehicle — Research Paper | ScholarLens