TY - JOUR
T1 - VeRA
T2 - A Simplified Security Risk Analysis Method for Autonomous Vehicles
AU - Cui, Jin
AU - Zhang, Biao
N1 - Publisher Copyright:
© 1967-2012 IEEE.
PY - 2020/10
Y1 - 2020/10
N2 - Risk analysis/assessment is an indispensable process during the design and development of Autonomous Vehicles (AVs), which is in charge of evaluating whether the risk of an attack is critical or minor. However, current risk analysis methods either are time-consuming or not suitable for Connected and Autonomous Vehicles (CAVs). In this paper, an efficient security risk analysis method, Vehicles Risk Analysis (VeRA), is proposed, fitting for evaluating the risks of attacks in the context of AV and CAVs. VeRA firstly considers the human capabilities and vehicle automation level to conduct a security risk analysis. Meanwhile, compared to the benchmark (i.e., SAE J3061), VeRA uses a simplified analysis process and fewer factors, significantly reducing the required analysis time without affecting analysis accuracy. Moreover, based on VeRA, a simple but efficient mathematical model is established to assess the risk value by considering the attack probability, severity and human control, avoiding the tedious process of looking up tables in previous methods. A case study on a general AV model shows that VeRA not only captures the critical attacks as accurate as other methods, but also analyzes the changes of human controllability with the vehicle's automation level. The performance compared to other available methods shows that VeRA can obtain the same analysis results by using around 43\% less time than the benchmark.
AB - Risk analysis/assessment is an indispensable process during the design and development of Autonomous Vehicles (AVs), which is in charge of evaluating whether the risk of an attack is critical or minor. However, current risk analysis methods either are time-consuming or not suitable for Connected and Autonomous Vehicles (CAVs). In this paper, an efficient security risk analysis method, Vehicles Risk Analysis (VeRA), is proposed, fitting for evaluating the risks of attacks in the context of AV and CAVs. VeRA firstly considers the human capabilities and vehicle automation level to conduct a security risk analysis. Meanwhile, compared to the benchmark (i.e., SAE J3061), VeRA uses a simplified analysis process and fewer factors, significantly reducing the required analysis time without affecting analysis accuracy. Moreover, based on VeRA, a simple but efficient mathematical model is established to assess the risk value by considering the attack probability, severity and human control, avoiding the tedious process of looking up tables in previous methods. A case study on a general AV model shows that VeRA not only captures the critical attacks as accurate as other methods, but also analyzes the changes of human controllability with the vehicle's automation level. The performance compared to other available methods shows that VeRA can obtain the same analysis results by using around 43\% less time than the benchmark.
KW - autonomous vehicle
KW - connected and autonomous vehicle
KW - Risk analysis
KW - SAE J3061
KW - security attacks
UR - http://www.scopus.com/inward/record.url?scp=85095688625&partnerID=8YFLogxK
U2 - 10.1109/TVT.2020.3009165
DO - 10.1109/TVT.2020.3009165
M3 - 文章
AN - SCOPUS:85095688625
SN - 0018-9545
VL - 69
SP - 10494
EP - 10505
JO - IEEE Transactions on Vehicular Technology
JF - IEEE Transactions on Vehicular Technology
IS - 10
M1 - 9140383
ER -