{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T03:55:13Z","timestamp":1784865313570,"version":"3.55.0"},"reference-count":54,"publisher":"MDPI AG","issue":"6","license":[{"start":{"date-parts":[[2024,3,13]],"date-time":"2024-03-13T00:00:00Z","timestamp":1710288000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Henan Science and Technology Major Project","award":["221100240100"],"award-info":[{"award-number":["221100240100"]}]},{"name":"Henan Science and Technology Major Project","award":["23PJ1403000"],"award-info":[{"award-number":["23PJ1403000"]}]},{"name":"Henan Science and Technology Major Project","award":["2023YFB2504800"],"award-info":[{"award-number":["2023YFB2504800"]}]},{"name":"Henan Science and Technology Major Project","award":["YYJC042022016"],"award-info":[{"award-number":["YYJC042022016"]}]},{"name":"Shanghai Pujiang Program","award":["221100240100"],"award-info":[{"award-number":["221100240100"]}]},{"name":"Shanghai Pujiang Program","award":["23PJ1403000"],"award-info":[{"award-number":["23PJ1403000"]}]},{"name":"Shanghai Pujiang Program","award":["2023YFB2504800"],"award-info":[{"award-number":["2023YFB2504800"]}]},{"name":"Shanghai Pujiang Program","award":["YYJC042022016"],"award-info":[{"award-number":["YYJC042022016"]}]},{"name":"National Key Research and Development Program","award":["221100240100"],"award-info":[{"award-number":["221100240100"]}]},{"name":"National Key Research and Development Program","award":["23PJ1403000"],"award-info":[{"award-number":["23PJ1403000"]}]},{"name":"National Key Research and Development Program","award":["2023YFB2504800"],"award-info":[{"award-number":["2023YFB2504800"]}]},{"name":"National Key Research and Development Program","award":["YYJC042022016"],"award-info":[{"award-number":["YYJC042022016"]}]},{"name":"SongShan Laboratory Pre-Research Project","award":["221100240100"],"award-info":[{"award-number":["221100240100"]}]},{"name":"SongShan Laboratory Pre-Research Project","award":["23PJ1403000"],"award-info":[{"award-number":["23PJ1403000"]}]},{"name":"SongShan Laboratory Pre-Research Project","award":["2023YFB2504800"],"award-info":[{"award-number":["2023YFB2504800"]}]},{"name":"SongShan Laboratory Pre-Research Project","award":["YYJC042022016"],"award-info":[{"award-number":["YYJC042022016"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>A cyber-physical system (CPS) integrates communication and automation technologies into the operational processes of physical systems. Nowadays, as a complex CPS, an intelligent connected vehicle (ICV) may be exposed to accidental functional failures and malicious attacks. Therefore, ensuring the ICV\u2019s safety and security is crucial. Traditional safety\/security analysis methods, such as failure mode and effect analysis and attack tree analysis, cannot provide a comprehensive analysis for the interactions between the system components of the ICV. In this work, we merge system-theoretic process analysis (STPA) with the concept phase of ISO 26262 and ISO\/SAE 21434. We focus on the interactions between components while analyzing the safety and security of ICVs to reduce redundant efforts and inconsistencies in determining safety and security requirements. To conquer STPA\u2019s abstraction in describing causal scenarios, we improved the physical component diagram of STPA-SafeSec by adding interface elements. In addition, we proposed the loss scenario tree to describe specific scenarios that lead to unsafe\/unsecure control actions. After hazard\/threat analysis, a unified risk assessment process is proposed to ensure consistency in assessment criteria and to streamline the process. A case study is implemented on the autonomous emergency braking system to demonstrate the validation of the proposed method.<\/jats:p>","DOI":"10.3390\/s24061848","type":"journal-article","created":{"date-parts":[[2024,3,13]],"date-time":"2024-03-13T13:08:43Z","timestamp":1710335323000},"page":"1848","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":27,"title":["Complying with ISO 26262 and ISO\/SAE 21434: A Safety and Security Co-Analysis Method for Intelligent Connected Vehicle"],"prefix":"10.3390","volume":"24","author":[{"given":"Yufeng","family":"Li","sequence":"first","affiliation":[{"name":"School of Computer Engineering and Science, Shanghai University, Shanghai 200444, China"},{"name":"The Purple Mountain Laboratories, Nanjing 211111, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wenqi","family":"Liu","sequence":"additional","affiliation":[{"name":"School of Computer Engineering and Science, Shanghai University, Shanghai 200444, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qi","family":"Liu","sequence":"additional","affiliation":[{"name":"School of Computer Engineering and Science, Shanghai University, Shanghai 200444, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiangyu","family":"Zheng","sequence":"additional","affiliation":[{"name":"School of Computer Engineering and Science, Shanghai University, Shanghai 200444, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3893-7731","authenticated-orcid":false,"given":"Ke","family":"Sun","sequence":"additional","affiliation":[{"name":"School of Computer Engineering and Science, Shanghai University, Shanghai 200444, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chengjian","family":"Huang","sequence":"additional","affiliation":[{"name":"School of Computer Engineering and Science, Shanghai University, Shanghai 200444, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2024,3,13]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"189","DOI":"10.1002\/sys.21509","article-title":"Conceptualizing the key features of cyber-physical systems in a multi-layered representation for safety and security analysis","volume":"23","author":"Wied","year":"2020","journal-title":"Syst. Eng."},{"key":"ref_2","first-page":"90","article-title":"Cyber security attacks to modern vehicular systems","volume":"36","author":"Pan","year":"2017","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"102150","DOI":"10.1016\/j.cose.2020.102150","article-title":"Cybersecurity for autonomous vehicles: Review of attacks and defense","volume":"103","author":"Kim","year":"2021","journal-title":"Comput. Secur."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"104461","DOI":"10.1016\/j.micpro.2022.104461","article-title":"ThreatSurf: A method for automated threat surface assessment in automotive cybersecurity engineering","volume":"90","author":"Zelle","year":"2022","journal-title":"Microprocess. Microsys."},{"key":"ref_5","unstructured":"Auto, U. (2023, March 23). Upstream Security\u2019s 2023 Global Automotive Cybersecurity Report. Available online: https:\/\/upstream.auto\/reports\/2023report\/."},{"key":"ref_6","first-page":"6","article-title":"0-days & mitigations: Roadways to exploit and secure connected BMW cars","volume":"2019","author":"Cai","year":"2019","journal-title":"Black Hat USA"},{"key":"ref_7","unstructured":"Bohara, R., Ross, M., Rahlfs, S., and Ghatta, S. (2023). Proceedings of the Software Engineering 2023 Workshops, Gesellschaft f\u00fcr Informatik."},{"key":"ref_8","unstructured":"Mader, R., Winkler, G., Reindl, T., and Pandya, N. (2021, January 29\u201330). The Car\u2019s Electronic Architecture in Motion: The Coming Transformation. Proceedings of the 42nd International Vienna Motor Symposium, Vienna, Austria."},{"key":"ref_9","first-page":"16","article-title":"Free-fall: Hacking tesla from wireless to can bus","volume":"25","author":"Nie","year":"2017","journal-title":"Black Hat USA"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"7169720","DOI":"10.1155\/2020\/7169720","article-title":"A systematic approach for cybersecurity design of in-vehicle network systems with trade-off considerations","volume":"2020","author":"Yu","year":"2020","journal-title":"Secur. Commun. Netw."},{"key":"ref_11","first-page":"5456","article-title":"eUF: A framework for detecting over-the-air malicious updates in autonomous vehicles","volume":"34","author":"Qureshi","year":"2022","journal-title":"J. King Saud-Univ. Comput. Inf. Sci."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Kumar, R., and Stoelinga, M. (2017, January 12\u201314). Quantitative security and safety analysis with attack-fault trees. Proceedings of the 2017 IEEE 18th International Symposium on High Assurance Systems Engineering (HASE), Singapore.","DOI":"10.1109\/HASE.2017.12"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Macher, G., Sporer, H., Berlach, R., Armengaud, E., and Kreiner, C. (2015, January 9\u201313). SAHARA: A security-aware hazard and risk analysis method. Proceedings of the 2015 Design, Automation & Test in Europe Conference & Exhibition (DATE), Grenoble, France.","DOI":"10.7873\/DATE.2015.0622"},{"key":"ref_14","first-page":"183","article-title":"STPA-SafeSec: Safety and security analysis for cyber-physical systems","volume":"34","author":"Friedberg","year":"2017","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_15","unstructured":"Leveson, N.G., and Thomas, J.P. (2018). STPA Handbook, McMaster University."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Young, W., and Leveson, N. (2013, January 9\u201313). Systems thinking for safety and security. Proceedings of the 29th Annual Computer Security Applications Conference, New Orleans, LA, USA.","DOI":"10.1145\/2523649.2530277"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Schmittner, C., and Macher, G. (2019, January 10). Automotive cybersecurity standards-relation and overview. Proceedings of the Computer Safety, Reliability, and Security: SAFECOMP 2019 Workshops, ASSURE, DECSoS, SASSUR, STRIVE, and WAISE, Turku, Finland.","DOI":"10.1007\/978-3-030-26250-1_12"},{"key":"ref_18","unstructured":"Kelechava, B. (2019). Road Vehicles Functional Safety Standards (Standard No. ISO 26262:2018)."},{"key":"ref_19","unstructured":"(2021). Road Vehicles: Cybersecurity Engineering (Standard No. ISO\/SAE 21434)."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"505","DOI":"10.1016\/j.jsse.2023.09.001","article-title":"Triad concurrent approach among functional safety, cybersecurity and SOTIF","volume":"10","author":"Kaneko","year":"2023","journal-title":"J. Space Saf. Eng."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"91","DOI":"10.4271\/11-01-02-0005","article-title":"Enhancement of automotive penetration testing with threat analyses results","volume":"1","author":"Braun","year":"2018","journal-title":"SAE Int. J. Transp. Cybersecur. Priv."},{"key":"ref_22","first-page":"83","article-title":"Threat\/Hazard Analysis and Risk Assessment: A Framework to Align the Functional Safety and Security Process in Automotive Domain","volume":"4","author":"Agrawal","year":"2021","journal-title":"SAE Int. J. Transp. Cybersecur. Priv."},{"key":"ref_23","unstructured":"United Nations Economic Commission for Europe (2022, January 30). Uniform Provisions Concerning the Approval of Vehicles with Regards to Cyber Security and Cyber Security Management System. Regulation Addendum 154-UN Regulation No. 155. Available online: https:\/\/unece.org\/sites\/default\/files\/2021-03\/R155e.pdf."},{"key":"ref_24","unstructured":"United Nations Economic Commission for Europe (2022, January 30). Uniform Provisions Concerning the Approval of Vehicles with Regards to Software Update and Software Updates Management System. Regulation Addendum 155-UN Regulation No. 156. Available online: https:\/\/unece.org\/sites\/default\/files\/2021-03\/R156e.pdf."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"100205","DOI":"10.1016\/j.treng.2023.100205","article-title":"Analyses on standards and regulations for connected and automated vehicles: Identifying the certifications roadmap","volume":"14","author":"Benyahya","year":"2023","journal-title":"Transp. Eng."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Chen, L., Jiao, J., and Zhao, T. (2020). A novel hazard analysis and risk assessment approach for road vehicle functional safety through integrating STPA with FMEA. Appl. Sci., 10.","DOI":"10.3390\/app10217400"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"10494","DOI":"10.1109\/TVT.2020.3009165","article-title":"VeRA: A simplified security risk analysis method for autonomous vehicles","volume":"69","author":"Cui","year":"2020","journal-title":"IEEE Trans. Veh. Technol."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Cui, J., and Sabaliauskaite, G. (2018, January 13\u201314). US 2: An unified safety and security analysis method for autonomous vehicles. Proceedings of the 2018 Future of Information and Communication Conference, Vancouver, Canada.","DOI":"10.1007\/978-3-030-03402-3_42"},{"key":"ref_29","first-page":"160","article-title":"Integrating autonomous vehicle safety and security analysis using STPA method and the six-step model","volume":"11","author":"Sabaliauskaite","year":"2018","journal-title":"Int. J. Adv. Secur."},{"key":"ref_30","unstructured":"Triginer, J.C., Martin, H., Winkler, B., and Marko, N. (2020, January 29\u201331). Integration of safety and cybersecurity analysis through combination of systems and reliability theory methods. Proceedings of the Embedded Real-Time Systems, Toulouse, France."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"8","DOI":"10.1108\/02656719610118151","article-title":"Failure mode and effects analysis: An integrated approach for product design and process control","volume":"13","author":"Teng","year":"1996","journal-title":"Int. J. Qual. Reliab. Manag."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"194","DOI":"10.1109\/TR.1985.5222114","article-title":"Fault tree analysis, methods, and applications\u2014A review","volume":"34","author":"Lee","year":"1985","journal-title":"IEEE Trans. Reliab."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"103981","DOI":"10.1016\/j.jlp.2019.103981","article-title":"The integration of HAZOP study with risk-matrix and the analytical-hierarchy process for identifying critical control-points and prioritizing risks in industry\u2014A case study","volume":"62","author":"Marhavilas","year":"2019","journal-title":"J. Loss Prev. Process Ind."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"179","DOI":"10.1016\/j.ress.2018.09.004","article-title":"Vulnerabilities and safety assurance methods in Cyber-Physical Systems: A comprehensive review","volume":"182","author":"Bolbot","year":"2019","journal-title":"Reliab. Eng. Syst. Saf."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"177","DOI":"10.1016\/j.ress.2017.05.037","article-title":"Application of systems theoretic process analysis to a lane keeping assist system","volume":"167","author":"Mahajan","year":"2017","journal-title":"Reliab. Eng. Syst. Saf."},{"key":"ref_36","unstructured":"Abdulkhaleq, A., and Wagner, S. (2013, January 26\u201328). Experiences with applying STPA to software-intensive systems in the automotive domain. Proceedings of the 2013 STAMP Conference at MIT, Boston, MA, USA."},{"key":"ref_37","unstructured":"Sharma, S., Flores, A., Hobbs, C., Stafford, J., and Fischmeister, S. (2019, January 29). Safety and security analysis of AEB for L4 autonomous vehicle using STPA. Proceedings of the Workshop on Autonomous Systems Design (ASD 2019), Florence, Italy."},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Ten, C.W., Liu, C.C., and Govindarasu, M. (2007, January 24\u201328). Vulnerability assessment of cybersecurity for SCADA systems using attack trees. Proceedings of the 2007 IEEE Power Engineering Society General Meeting, Tampa, FL, USA.","DOI":"10.1109\/PES.2007.385876"},{"key":"ref_39","unstructured":"Karray, K., Danger, J.L., Guilley, S., and Abdelaziz Elaabid, M. (2018). Cyber-Physical Systems Security, Springer."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Henniger, O., Apvrille, L., Fuchs, A., Roudier, Y., Ruddle, A., and Weyl, B. (2009, January 20\u201322). Security requirements for automotive on-board networks. Proceedings of the 2009 9th International Conference on Intelligent Transport Systems Telecommunications, Lille, France.","DOI":"10.1109\/ITST.2009.5399279"},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Boudguiga, A., Boulanger, A., Chiron, P., Klaudel, W., Labiod, H., and Seguy, J.C. (2015, January 27\u201329). RACE: Risk analysis for cooperative engines. Proceedings of the 2015 7th International Conference on New Technologies, Mobility and Security (NTMS), Paris, France.","DOI":"10.1109\/NTMS.2015.7266516"},{"key":"ref_42","unstructured":"Monteuuis, J.P., Boudguiga, A., Zhang, J., Labiod, H., Servel, A., and Urien, P. (2018, January 4\u20138). Sara: Security automotive risk analysis method. Proceedings of the 4th ACM Workshop on Cyber-Physical System Security, Incheon, Republic of Korea."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Sheik, A.T., Maple, C., Epiphaniou, G., and Dianati, M. (2023). Securing Cloud-Assisted Connected and Autonomous Vehicles: An In-Depth Threat Analysis and Risk Assessment. Sensors, 24.","DOI":"10.3390\/s24010241"},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"14752","DOI":"10.1109\/ACCESS.2023.3243906","article-title":"An Integrated Approach of Threat Analysis for Autonomous Vehicles Perception System","volume":"11","author":"Ghosh","year":"2023","journal-title":"IEEE Access"},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"103179","DOI":"10.1016\/j.cose.2023.103179","article-title":"A comparative risk analysis on CyberShip system with STPA-Sec, STRIDE and CORAS","volume":"128","author":"Sahay","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"89","DOI":"10.1109\/MVT.2023.3263334","article-title":"Dynamic Heterogeneous Redundancy-Based Joint Safety and Security for Connected Automated Vehicles: Preliminary Simulation and Field Test Results","volume":"18","author":"Li","year":"2023","journal-title":"IEEE Veh. Technol. Mag."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"148672","DOI":"10.1109\/ACCESS.2019.2946632","article-title":"Collaborative analysis framework of safety and security for autonomous vehicles","volume":"7","author":"Cui","year":"2019","journal-title":"IEEE Access"},{"key":"ref_48","first-page":"102620","article-title":"Extending STPA with STRIDE to identify cybersecurity loss scenarios","volume":"55","author":"Hirata","year":"2020","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_49","unstructured":"SAE International (2016). 3061: Cybersecurity Guidebook for Cyber-Physical Vehicle Systems, Society for Automotive Engineers."},{"key":"ref_50","unstructured":"Cui, J., and Sabaliauskaite, G. (2017). On the Alignment of Safety and Security for Autonomous Vehicles, IARIA CYBER."},{"key":"ref_51","first-page":"031104","article-title":"Comparison of the HAZOP, FMEA, FRAM, and STPA methods for the hazard analysis of automatic emergency brake systems","volume":"8","author":"Sun","year":"2022","journal-title":"ASCE-ASME J. Risk Uncertain. Eng. Syst. Part Mech. Eng."},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Bolovinou, A., Atmaca, U.I., Ur-Rehman, O., Wallraf, G., and Amditis, A. (2019, January 9\u201312). Tara+: Controllability-aware threat analysis and risk assessment for l3 automated driving systems. Proceedings of the 2019 IEEE Intelligent Vehicles Symposium (IV), Paris, France.","DOI":"10.1109\/IVS.2019.8813999"},{"key":"ref_53","unstructured":"France, M.E. (2017). Engineering for Humans: A New Extension to STPA. [Ph.D. Thesis, Massachusetts Institute of Technology]."},{"key":"ref_54","first-page":"995","article-title":"Remote attacks on automated vehicles sensors: Experiments on camera and lidar","volume":"11","author":"Petit","year":"2015","journal-title":"Black Hat Eur."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/24\/6\/1848\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T14:13:07Z","timestamp":1760105587000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/24\/6\/1848"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,3,13]]},"references-count":54,"journal-issue":{"issue":"6","published-online":{"date-parts":[[2024,3]]}},"alternative-id":["s24061848"],"URL":"https:\/\/doi.org\/10.3390\/s24061848","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,3,13]]}}}