Resource Center

STPA + STPA-Sec (Safety & Security)

Author
VWAY
Date
2023-08-10 11:27
Views
125
Previously, STPA analysis has been widely used to identify interaction issues between users and various components, as well as to identify failures in components and potential accidents due to emergent behavior. However, today I'd like to go beyond this safety perspective and introduce the concept of STPA-Sec (Security) to demonstrate an example of STPA analysis with added security considerations. Below, we'll add L-5, the loss of user's personal information exposure, to the existing safety-related losses identified from L-1 to L-4. This means that users will now analyze STPA not only from a safety perspective but also considering security aspects.

 



 

We identify UCA (Unsafe Control Action) according to the STPA steps. The CA (Control Action) we will analyze is the "Enable AH" control command issued by the driver to the Autohold Module



 

The possible UCAs are as follows:

UCA - 17: The driver activates the Autohold module while driving, but the 'Enable AH' command is not provided.



 

Next is the step of identifying loss scenarios. The loss scenario below is a scenario that could occur due to UCA - 17. The green shading represents the analysis from the perspective of misuse or safety in STPA, while the yellow shading represents the results from the perspective of security in STPA-Sec analysis.

 



 

It's a simple example, but through STPA analysis, we were able to perform both safety and security analyses of the target system.
Total 12
Number Title Author Date Votes Views
12
STPA + STPA-Sec (Safety & Security)
VWAY | 2023.08.10 | Votes 0 | Views 125
VWAY 2023.08.10 0 125
11
STPA + ODD(Operational Design Domain)
VWAY | 2023.06.21 | Votes 0 | Views 180
VWAY 2023.06.21 0 180
10
STPA in Industry Standards (2023)
VWAY | 2023.06.12 | Votes 0 | Views 152
VWAY 2023.06.12 0 152
9
FMEA-MSR (Vehicle Braking System Application)
VWAY | 2023.04.12 | Votes 0 | Views 146
VWAY 2023.04.12 0 146
8
STPA analysis(Autonomous Vehicle) for deriving Misuse
VWAY | 2023.04.07 | Votes 0 | Views 437
VWAY 2023.04.07 0 437
7
FMEA-MSR?
VWAY | 2023.04.07 | Votes 0 | Views 343
VWAY 2023.04.07 0 343
6
STPA Application (Workplace Safety) - Aircraft Assembly Process
VWAY | 2022.11.18 | Votes 0 | Views 695
VWAY 2022.11.18 0 695
5
Example of applying STPA-Sec analysis(Industrial Cyber-security ) - Chiller
VWAY | 2022.11.03 | Votes 0 | Views 909
VWAY 2022.11.03 0 909
4
Example of applying STPA analysis(Medical Science) - COVID-19
VWAY | 2022.10.28 | Votes 0 | Views 581
VWAY 2022.10.28 0 581
3
Example of applying STPA analysis(Aviation) - UAM(eVTOL)
VWAY | 2022.08.11 | Votes 0 | Views 498
VWAY 2022.08.11 0 498