Automotive SPICE, Safety and Cybersecurity Integration

Automotive SPICE, Safety and Cybersecurity Integration
复制标题

汽车 SPICE、安全和网络安全集成

DOI:
--
复制
发表时间:
2017
期刊:
SAFECOMP Workshops
影响因子:
--
通讯作者:
Christian Kreiner
Christian Kreiner
中科院分区:
--
文献类型:
--
作者:
Georg Macher;Alexander Much;A. Riel;R. Messnarz;Christian Kreiner

文献摘要

被引文献

相似文献

目前开发的汽车系统显示出更高的自动化水平,以及与其他车辆、交通基础设施和云服务的更紧密集成。因此,正如安全在世纪后期成为发展的关键部分一样,汽车领域现在必须将网络安全视为现代汽车发展的一个组成部分。先进的驾驶员辅助系统或自动驾驶功能等新功能推动了对内置安全解决方案和网络安全感知系统设计的需求。不幸的是,在安全工程的背景下,特别是在汽车安全部门,仍然缺乏安全问题的经验。一个欧洲伙伴关系在欧盟项目SafEUr的范围内为ISO 26262制定了一套技能、培训材料和最佳做法。该工作组(SoQrates工作组)分享知识和经验,并将汽车SPICE评估模型与功能安全要求相结合,并进一步用于集成汽车SPICE和安全评估。SoQrates工作组的成员在很大程度上是经过认证的汽车SPICE评估员,他们在实践中处理安全相关项目。从2016年起,SoQrates工作组开始分析SAE J3061网络安全指南,并将SAE J3061的附加要求整合到该评估模型中。本文将总结以前的结果和扩展的评估模型和工作组的愿景,如何汽车SPICE评估员也可以支持审计的项目与密切的安全关系。
Currently developed automotive systems exhibit an increased level of automation as well as an ever-tighter integration with other vehicles, traffic infrastructure and cloud services. Thus, just as safety became a critical part of the development in the late 20th century, the automotive domain must now consider cyber-security as an integral part of the development of modern vehicles. Novel features, such as advanced driver assistance systems or automated driving functions drive the need for built-in security solutions and cyber-security aware system design. Unfortunately, there is still a lack of experience with security concerns in the context of safety engineering in general and in the automotive safety departments in particular. A European partnership developed a skill set, training materials and best practices for ISO 26262 in the context of the EU project SafEUr. This working party (SoQrates working group) shares knowledge and experiences and integrated the Automotive SPICE assessment model with functional safety requirements, which was further used in integrated Automotive SPICE and safety assessments. The members of the SoQrates working group are, to a large extent, certified Automotive SPICE assessors dealing with security-related project in practice. From 2016 onwards, the SoQrates working party started to analyse the SAE J3061 cyber-security guidebook and integrated the additional requirements of SAE J3061 into this assessment model. This paper will summarise the previous results and extensions of the assessment model and the working group’s vision, how an Automotive SPICE assessor can support also the auditing of projects with close security relation.