On Security Risk Management for Teleoperated Driving Systems
Identifikátory výsledku
Kód výsledku v IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216305%3A26220%2F26%3A0198585" target="_blank" >RIV/00216305:26220/26:0198585 - isvavai.cz</a>
Výsledek na webu
<a href="https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=11136163" target="_blank" >https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=11136163</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1109/ACCESS.2025.3602202" target="_blank" >10.1109/ACCESS.2025.3602202</a>
Alternativní jazyky
Jazyk výsledku
angličtina
Název v původním jazyce
On Security Risk Management for Teleoperated Driving Systems
Popis výsledku v původním jazyce
Teleoperated driving technology enables human operators to control vehicles remotely, thereby reducing the need for the driver’s physical presence within the vehicle. Although this innovation enhances operational flexibility, it introduces security challenges that, if unaddressed, could undermine the reliability and safety of Teleoperated Driving Systems (TDS). This paper presents a comprehensive security risk analysis and architectural framework for TDS, emphasizing the system architecture. Our study combines an in-depth review of the existing literature with a structured risk management assessment to analyze TDS assets and data flows. By detailing the system and business assets, their interconnections, and the unique vulnerabilities inherent to TDS, we define critical security threats – ranging from unauthorized control and data manipulation to vulnerabilities in session management protocols and network configurations. The selected security risk management approach guides our risk analysis, maps security threats and vulnerabilities to the corresponding security requirements and controls, and provides a prioritized strategy for risk treatment. Validation results show that our risk analysis achieves strong coverage, with a third-party threat analysis tool confirming eighteen (18) of the thirty-two (32) identified security threats and highlighting three (3) additional scenarios, while missing fourteen (14) threats mainly due to tool limitations. Our results offer practitioners a practical blueprint for identifying and managing security risks in TDS.
Název v anglickém jazyce
On Security Risk Management for Teleoperated Driving Systems
Popis výsledku anglicky
Teleoperated driving technology enables human operators to control vehicles remotely, thereby reducing the need for the driver’s physical presence within the vehicle. Although this innovation enhances operational flexibility, it introduces security challenges that, if unaddressed, could undermine the reliability and safety of Teleoperated Driving Systems (TDS). This paper presents a comprehensive security risk analysis and architectural framework for TDS, emphasizing the system architecture. Our study combines an in-depth review of the existing literature with a structured risk management assessment to analyze TDS assets and data flows. By detailing the system and business assets, their interconnections, and the unique vulnerabilities inherent to TDS, we define critical security threats – ranging from unauthorized control and data manipulation to vulnerabilities in session management protocols and network configurations. The selected security risk management approach guides our risk analysis, maps security threats and vulnerabilities to the corresponding security requirements and controls, and provides a prioritized strategy for risk treatment. Validation results show that our risk analysis achieves strong coverage, with a third-party threat analysis tool confirming eighteen (18) of the thirty-two (32) identified security threats and highlighting three (3) additional scenarios, while missing fourteen (14) threats mainly due to tool limitations. Our results offer practitioners a practical blueprint for identifying and managing security risks in TDS.
Klasifikace
Druh
J<sub>imp</sub> - Článek v periodiku v databázi Web of Science
CEP obor
—
OECD FORD obor
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Návaznosti výsledku
Projekt
—
Návaznosti
R - Projekt Ramcoveho programu EK
Ostatní
Rok uplatnění
2025
Kód důvěrnosti údajů
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Údaje specifické pro druh výsledku
Název periodika
IEEE Access
ISSN
2169-3536
e-ISSN
—
Svazek periodika
13
Číslo periodika v rámci svazku
2025
Stát vydavatele periodika
US - Spojené státy americké
Počet stran výsledku
17
Strana od-do
151153-151169
Kód UT WoS článku
001562596000009
EID výsledku v databázi Scopus
—