A Comparative Analysis of UNECE WP.29 R155 and ISO/SAE 21434

Gianpiero Costantino, M. Vincenzi, I. Matteucci
{"title":"A Comparative Analysis of UNECE WP.29 R155 and ISO/SAE 21434","authors":"Gianpiero Costantino, M. Vincenzi, I. Matteucci","doi":"10.1109/eurospw55150.2022.00041","DOIUrl":null,"url":null,"abstract":"In the last years, the increasing number of cyber-attacks on vehicles has shown the importance to implement security solutions within the automotive domain. To reduce the risk that a vehicle or its components get attacked and compromised, two cybersecurity references have been released: UNECE WP.29 R155 and ISO/SAE 21434. In March 2021, the United Nations Economic Commission for Europe (UNECE) published the WP.29 R155 regulation, mandatory in some countries from July 2022 to homologate vehicles' cybersecurity. Officially released in August 2021, ISO/SAE 21434 is a cybersecurity standard which aims to be widely accepted and applied in the engineering of electrical and electronic (E/E) systems for road vehicles. In this work, we describe and analyze the two norms, comparing them to show their points of contact and differences. From our analysis, the two documents, spanned both along the entire life-cycle of a vehicle, can be considered overlapped in some processes, but also complementary to increase the cybersecurity of the vehicle. Finally, we provide a use case of application of the regulation and the standard on an E/E system, reporting the possible limits and implementations.","PeriodicalId":275840,"journal":{"name":"2022 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)","volume":"25 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/eurospw55150.2022.00041","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

In the last years, the increasing number of cyber-attacks on vehicles has shown the importance to implement security solutions within the automotive domain. To reduce the risk that a vehicle or its components get attacked and compromised, two cybersecurity references have been released: UNECE WP.29 R155 and ISO/SAE 21434. In March 2021, the United Nations Economic Commission for Europe (UNECE) published the WP.29 R155 regulation, mandatory in some countries from July 2022 to homologate vehicles' cybersecurity. Officially released in August 2021, ISO/SAE 21434 is a cybersecurity standard which aims to be widely accepted and applied in the engineering of electrical and electronic (E/E) systems for road vehicles. In this work, we describe and analyze the two norms, comparing them to show their points of contact and differences. From our analysis, the two documents, spanned both along the entire life-cycle of a vehicle, can be considered overlapped in some processes, but also complementary to increase the cybersecurity of the vehicle. Finally, we provide a use case of application of the regulation and the standard on an E/E system, reporting the possible limits and implementations.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
UNECE WP.29 R155与ISO/SAE 21434的比较分析
在过去的几年里,越来越多的车辆网络攻击表明了在汽车领域实施安全解决方案的重要性。为了降低车辆或其组件受到攻击和损害的风险,发布了两个网络安全参考标准:UNECE WP.29 R155和ISO/SAE 21434。2021年3月,联合国欧洲经济委员会(UNECE)发布了WP.29 R155法规,该法规从2022年7月起在一些国家强制执行,以统一车辆的网络安全。ISO/SAE 21434于2021年8月正式发布,是一项网络安全标准,旨在被广泛接受并应用于道路车辆的电气和电子(E/E)系统工程。在这项工作中,我们对这两种规范进行了描述和分析,并对它们进行了比较,以显示它们的联系点和差异。从我们的分析来看,这两个文件跨越了车辆的整个生命周期,在某些过程中可以被认为是重叠的,但在提高车辆的网络安全方面也是互补的。最后,我们提供了在E/E系统上应用法规和标准的用例,报告了可能的限制和实现。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Reliability of IP Geolocation Services for Assessing the Compliance of International Data Transfers GNPassGAN: Improved Generative Adversarial Networks For Trawling Offline Password Guessing Towards an Operations-Aware Experimentation Methodology Two de-anonymization attacks on real-world location data based on a hidden Markov model Reviewing Estimates of Cybercrime Victimisation and Cyber Risk Likelihood
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1