Security Requirements Engineering in Safety-Critical Railway Signalling Networks

被引:11
|
作者
Heinrich, Markus [1 ]
Vateva-Gurova, Tsvetoslava [1 ]
Arul, Tolga [1 ]
Katzenbeisser, Stefan [1 ]
Suri, Neeraj [1 ]
Birkholz, Henk [2 ]
Fuchs, Andreas [2 ]
Krauss, Christoph [2 ]
Zhdanova, Maria [2 ]
Kuzhiyelil, Don [3 ]
Tverdyshev, Sergey [3 ]
Schlehuber, Christian [4 ]
机构
[1] Tech Univ Darmstadt, Dept Comp Sci, Darmstadt, Germany
[2] Fraunhofer Inst Secure Informat Technol SIT, Darmstadt, Germany
[3] SYSGO AG, Klein Winternheim, Germany
[4] DB Netz AG, Frankfurt, Germany
关键词
Security systems - Cryptography - Network architecture - Architecture - Safety engineering;
D O I
10.1155/2019/8348925
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Securing a safety-critical system is a challenging task, because safety requirements have to be considered alongside security controls. We report on our experience to develop a security architecture for railway signalling systems starting from the bare safety-critical system that requires protection. We use a threat-based approach to determine security risk acceptance criteria and derive security requirements. We discuss the executed process and make suggestions for improvements. Based on the security requirements, we develop a security architecture. The architecture is based on a hardware platform that provides the resources required for safety as well as security applications and is able to run these applications of mixed-criticality (safety-critical applications and other applications run on the same device). To achieve this, we apply the MILS approach, a separation-based high-assurance security architecture to simplify the safety case and security case of our approach. We describe the assurance requirements of the separation kernel subcomponent, which represents the key component of the MILS architecture. We further discuss the security measures of our architecture that are included to protect the safety-critical application from cyberattacks.
引用
收藏
页数:14
相关论文
共 50 条
  • [1] Domain Specific Modelling and Language for Safety-Critical and Security-Critical Requirements Engineering
    Sklyar, Vladimir
    Kharchenko, Vyacheslav
    [J]. 2022 12TH INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS, SERVICES AND TECHNOLOGIES (DESSERT), 2022,
  • [2] Requirements Engineering for Safety-Critical Molecular Programs
    Lutz, Robyn R.
    [J]. 2022 30TH IEEE INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE (RE 2022), 2022, : 302 - 308
  • [3] Implementing a Security Architecture for Safety-Critical Railway Infrastructure
    Eckel, Michael
    Kuzhiyelil, Don
    Krauss, Christoph
    Zhdanova, Maria
    Katzenbeisser, Stefan
    Cosic, Jasmin
    Drodt, Matthias
    Pitrolle, Jean-Jacques
    [J]. 2021 INTERNATIONAL SYMPOSIUM ON SECURE AND PRIVATE EXECUTION ENVIRONMENT DESIGN (SEED 2021), 2021, : 215 - 226
  • [4] Formal Requirements Specification in Safety-critical Railway Signaling System
    Jo, Hyun-Jeong
    Hwang, Jong-Gyu
    Yoon, Yong-Ki
    [J]. T& D ASIA: 2009 TRANSMISSION & DISTRIBUTION CONFERENCE & EXPOSITION: ASIA AND PACIFIC, 2009, : 731 - 734
  • [5] Requirements Engineering for Safety-Critical Systems: Overview and Challenge
    Galvao Martins, Luiz Eduardo
    Gorschek, Tony
    [J]. SBES'18: PROCEEDINGS OF THE XXXII BRAZILIAN SYMPOSIUM ON SOFTWARE ENGINEERING, 2018, : 10 - 10
  • [6] Requirements Engineering for Safety-Critical Systems Overview and Challenges
    Martins, Luiz Eduardo G.
    Gorschek, Tony
    [J]. IEEE SOFTWARE, 2017, 34 (04) : 49 - 55
  • [7] Specifying Software Requirements for Safety-Critical Railway Systems: An Experience Report
    Provenzano, Luciana
    Hanninen, Kaj
    [J]. REQUIREMENTS ENGINEERING: FOUNDATION FOR SOFTWARE QUALITY, REFSQ 2017, 2017, 10153 : 363 - 369
  • [8] Requirements engineering for safety-critical systems: A systematic literature review
    Martins, Luiz Eduardo G.
    Gorschek, Tony
    [J]. INFORMATION AND SOFTWARE TECHNOLOGY, 2016, 75 : 71 - 89
  • [9] SAFETY AND SECURITY PROFILES OF INDUSTRY NETWORKS USED IN SAFETY-CRITICAL APPLICATIONS
    Franekova, Maria
    [J]. TRANSPORT PROBLEMS, 2008, 3 (04) : 25 - 32
  • [10] Requirements Engineering for Safety-Critical Systems: An Interview Study with Industry Practitioners
    Martins, Luiz Eduardo G.
    Gorschek, Tony
    [J]. IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2020, 46 (04) : 346 - 361