Significantly Reducing Security Risk Analysis Efforts
— Risk Analysis for the SDV Era Aligned with ISO/SAE 21434
With the enforcement of UN-R155, cybersecurity measures are now mandatory for all new vehicles, prompting automakers and suppliers to fully implement ISO/SAE 21434. In the era of Software Defined Vehicles (SDVs), where vehicles are increasingly connected to cloud services and mobile applications, the attack surface has expanded significantly. As a result, vulnerabilities or insufficient security measures during the design and development phases can directly impact vehicle safety. Given this context, preventing vulnerabilities early in the development process has become more critical than ever. However, challenges such as increased workload for security tasks and a shortage of skilled personnel are becoming more apparent. This presentation introduces VERZEUSE® for TARA, a tool developed to streamline threat and vulnerability analysis as one approach to addressing these challenges. The tool has already been applied to over 120 types of in-vehicle products, achieving up to 90% reduction in threat analysis effort and 63% reduction in vulnerability analysis effort.
- Safety & Security
- Automotive Software Expo