Dear all,
I am happy to announce that our journal paper "Automating Safety and
Security Co-Design through Semantically-Rich Architecture Patterns" has
been accepted at Transactions on Cyber-Physical Systems (TCPS) in the
special issue on Automotive Safety and Security.
Journal:
Transactions on Cyber-Physical Systems (TCPS) in the special issue on
Automotive Safety and Security
Title:
Automating Safety and Security Co-Design through Semantically-Rich
Architecture Patterns
Authors:
Yuri Gil Dantas and Vivek Nigam
Abstract:
During the design of safety-critical systems, safety and security
engineers make use of architecture patterns,
such as Watchdog and Firewall, to address identified failures and
threats. Often, however, the deployment
of safety patterns has consequences on security, e.g., the deployment of
a safety pattern may lead to new
threats. The other way around may also be possible, i.e., the deployment
of a security pattern may lead to new
failures. Safety and security co-design is, therefore, required to
understand such consequences and trade-offs,
in order to reach appropriate system designs. Currently, pattern
descriptions, including their consequences,
are described using natural language. Therefore, their deployment in
system design is carried out manually,
thus time-consuming and prone to human-error, especially given the high
system complexity. We propose the
use of semantically-rich architecture patterns to enable automated
support for safety and security co-design
by using Knowledge Representation and Reasoning (KRR) methods. Based on
our domain-specific language,
we specify reasoning principles as logic specifications written as
answer-set programs. KRR engines enable
the automation of safety and security co-engineering activities,
including the automated recommendation of
which architecture patterns can address failures or threats and
consequences of deploying such patterns. We
demonstrate our approach on an example taken from the ISO 21434 standard.
Cheers,
Yuri Gil Dantas
--
Yuri Gil Dantas
Research assistant
fortiss GmbH
Landesforschungsinstitut des Freistaats Bayern
für softwareintensive Systeme
An-Institut Technische Universität München
Guerickestraße 25, 80805 München, Germany
T: +49 (89) 3603522 193
F: +49 (89) 3603522 50
dantas(a)fortiss.org
www.fortiss.org
Amtsgericht München: HRB: 176633
USt-IdNr.: DE263907002, Steuer-Nr.: 143/237/25900
Rechtsform: gemeinnützige GmbH
Sitz der Gesellschaft: München
Geschäftsführer: Dr. Harald Rueß, Thomas Vallon
Vorsitzender des Aufsichtsrats: Dr. Manfred Wolter