VWAY

Newsroom
Technical Resources


STPASTPA + STPA-Sec (Safety & Security)

Previously, STPA analysis has been widely used to identify interaction issues between users and various components, as well as to identify failures in components and potential accidents due to emergent behavior. However, today I'd like to go beyond this safety perspective and introduce the concept of STPA-Sec (Security) to demonstrate an example of STPA analysis with added security considerations. Below, we'll add L-5, the loss of user's personal information exposure, to the existing safety-related losses identified from L-1 to L-4. This means that users will now analyze STPA not only from a safety perspective but also considering security aspects.


STPA-Sec losses table L-1 to L-5 for a vehicle, with the security-related loss 'driver's personal information exposed' highlighted

We identify UCA (Unsafe Control Action) according to the STPA steps. The CA (Control Action) we will analyze is the "Enable AH" control command issued by the driver to the Autohold Module

STPA control structure excerpt — driver and Auto Hold Module with the control actions Enable AH, Disable AH and brake pedal on/off, and feedback such as AH enabled/disabled and dashboard indicators

The possible UCAs are as follows:
UCA - 17: The driver activates the Autohold module while driving, but the 'Enable AH' command is not provided.

STPA step 3 unsafe control action table for the Enable AH control action from the driver to the Auto Hold Module — UCA-17 'Driver activated Autohold while driving but not Enable AH provided' in the 'not providing causes hazard' column, linked to hazards H-1, H-2 and H-3
Next is the step of identifying loss scenarios. The loss scenario below is a scenario that could occur due to UCA - 17. The green shading represents the analysis from the perspective of misuse or safety in STPA, while the yellow shading represents the results from the perspective of security in STPA-Sec analysis.


STPA step 4 loss scenario table for UCA-17 — LS-13 driver mistakenly presses button, LS-14 Auto Hold Module fails to receive user signals due to obsolescence, LS-15 driver sends malicious disruptive commands to the Autohold system, LS-16 sensor lacks driver attention to the Autohold system status, LS-16-1 sensor fails to recognize system warnings
It's a simple example, but through STPA analysis, we were able to perform both safety and security analyses of the target system.


Concept art of a hand holding a padlock icon inside a security interface — STPA-Sec integrated safety and security analysis