Multi-dimensional security fusion risk assessment method and related equipment

Through a multi-dimensional safety fusion risk assessment method, the functional safety, expected functional safety and information security of the autonomous driving system are comprehensively analyzed, and a dynamic scenario model and risk matrix are constructed. This solves the problem of dimensional separation in risk assessment in the autonomous driving system and improves the system's safety and user experience.

CN120688056APending Publication Date: 2025-09-23VOYAH AUTOMOBILE TECH CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510750696.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-09-23

AI Technical Summary

Technical Problem

In existing technologies, the safety risk assessment of autonomous driving systems is fragmented, making it difficult to comprehensively quantify cross-domain risks and respond to them in real-time, resulting in waste of resources and decision-making delays, and making it impossible to establish a unified risk analysis standard.

Method used

A multi-dimensional safety fusion risk assessment method is proposed. By acquiring the data set of the target system, functional safety, expected functional safety and information security risk analysis is performed, a dynamic scenario model is established, a multi-dimensional risk matrix is ​​constructed, the risk value of the hazardous event is obtained and the risk level is divided.

Benefits of technology

It has achieved a comprehensive risk assessment of the autonomous driving system, improved safety, reliability and user experience, optimized resource allocation, promoted real-time coordinated response to cross-domain threats, and enhanced the system's robustness and user trust.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120688056A_ABST
    Figure CN120688056A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-dimensional safety fusion risk assessment method and related equipment, and relates to the technical field of automatic driving, and the method comprises the steps: obtaining a first data set and a second data set of a target system; performing functional security risk analysis, expected functional security risk analysis and information security risk analysis on the first data set to identify a hazardous event of the target system; based on the second data set, establishing a dynamic scene model, and obtaining a threat level of the hazard event through the dynamic scene model; constructing a multi-dimensional risk matrix according to the hazard event, the dynamic scene model and the threat level; and obtaining a risk value of the hazard event based on the multi-dimensional risk matrix, and performing risk grade division according to the risk value to obtain a multi-dimensional security risk assessment result of the target system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of autonomous driving technology, and in particular to a risk assessment method and related equipment for multi-dimensional safety fusion. Background Art

[0002] Related safety risk assessment methods commonly suffer from a core problem of fragmented assessment dimensions. In complex systems such as autonomous driving or the Industrial Internet of Things, functional safety, functional safety, and information security are often assessed independently: functional safety relies on failure mode analysis (such as Hazard Analysis and Risk Assessment (HARA)) to quantify hardware failure risks, information security uses vulnerability scanning (such as Threat Analysis and Risk Assessment (TARA)) to determine attack path threats, and safety of the intended functionality (SOTIF) focuses on scenarios with insufficient system performance or environmental misuse.

[0003] However, this fragmented assessment makes it difficult to comprehensively quantify cross-domain risks. For example, if a sensor hardware failure (functional safety risk) is superimposed on a communication link hijack (information security risk), it may cause a more serious system out of control, but the relevant technology cannot capture such compound risks. More importantly, the independent assessment framework requires repeated data collection and model building, resulting in resource waste and decision-making delays. Although some technologies have attempted to introduce dynamic parameters (such as environmental visibility, network attack frequency) or optimize risk quantification models (such as single-dimensional risk values), their underlying logic is still limited to specific security fields. It is impossible to build a unified risk analysis standard, and it is difficult to achieve real-time coordinated response to cross-domain threats. With the increase in system complexity and security requirements, there is an urgent need to break the barriers of traditional assessment dimensions and build a dynamic analysis framework that integrates multi-dimensional security parameters to fundamentally solve the problem of risk assessment fragmentation.

[0004] Therefore, how to provide a multi-dimensional security integrated risk assessment method has become a technical problem that needs to be solved urgently. Summary of the Invention

[0005] The Summary of the Invention introduces a series of simplified concepts that will be further described in the Detailed Description of the Invention. The Summary of the Invention of this application is not intended to limit the key features and essential technical features of the claimed technical solution, nor is it intended to determine the scope of protection of the claimed technical solution.

[0006] This application specifically includes the following aspects:

[0007] First, this application proposes a multi-dimensional security fusion risk assessment method, including:

[0008] Acquire a first data set and a second data set of a target system;

[0009] Performing a functional safety risk analysis, an expected functional safety risk analysis, and an information security risk analysis on the first data set to identify hazardous events of the target system;

[0010] establishing a dynamic scenario model based on the second data set, and obtaining a threat level of the hazardous event through the dynamic scenario model;

[0011] Constructing a multi-dimensional risk matrix based on the hazardous event, the dynamic scenario model, and the threat level;

[0012] Based on the multi-dimensional risk matrix, the risk value of the hazardous event is obtained, and risk levels are divided according to the risk value to obtain a multi-dimensional security risk assessment result of the target system.

[0013] In a feasible embodiment, the first data set includes functional safety parameters, expected functional safety parameters and information security parameters, and the second data set includes vehicle status information, network environment information, visibility information, weather brightness information, ground humidity information, ground slope information, obstacle information and pedestrian information.

[0014] In a feasible implementation, the multi-dimensional security fusion risk assessment method further includes:

[0015] Obtain the functional safety parameters through hazard and operability analysis;

[0016] Obtaining the expected functional safety parameters through an expected functional safety analysis method;

[0017] The information security parameters are obtained through threat and risk assessment analysis methods.

[0018] In a feasible implementation manner, the functional safety parameters include the failure mode of the target system and the risk value corresponding to the failure mode; the expected functional safety parameters include the performance limitation data and false triggering scenario information of the target system; and the information security parameters include the vulnerability information of the target system and the threat level corresponding to the external attack path.

[0019] In a feasible implementation, the multi-dimensional risk matrix includes a preset severity level, a preset controllability level, a preset economic impact level, a preset privacy impact level, and a preset exposure rate level, wherein:

[0020] The preset severity level is used to represent the threat level of the hazardous event to the function of the target system or to the personal safety of the user;

[0021] The preset controllability level is used to characterize the response and mitigation capabilities of the target system to the hazardous event;

[0022] The preset economic impact level is used to characterize the direct or indirect economic losses caused by the hazardous event;

[0023] The preset privacy impact level is used to characterize the risk of leakage of user privacy data caused by the harmful event;

[0024] The preset exposure rate level is used to characterize the probability or frequency of the hazardous event occurring in a dynamic scenario.

[0025] In a feasible implementation manner, the risk value of the hazardous event is calculated using the following formula:

[0026] Y = (A + B + C) × D × E;

[0027] Among them, Y is the risk value of the hazardous event, A is the preset severity level, B is the preset economic impact level, C is the preset privacy impact level, D is the preset exposure rate level, and E is the preset controllability level.

[0028] In a feasible implementation manner, the risk level classification is performed according to the risk value to obtain a multi-dimensional security risk assessment result of the target system, including:

[0029] Classify the risk value according to the preset security level to obtain the functional safety level and the information security level corresponding to the risk value;

[0030] When the functional safety level corresponding to the risk value is within a first threshold range and the information security level corresponding to the risk value is within a second threshold range, determining that the multi-dimensional security risk assessment result of the target system is the highest risk level;

[0031] When the functional safety level corresponding to the risk value is within the third threshold range and the information security level corresponding to the risk value is within the fourth threshold range, the multi-dimensional security risk assessment result of the target system is determined to be the lowest risk level; wherein, the lower limit value of the first threshold range is greater than the upper limit value of the second threshold range, the lower limit value of the second threshold range is greater than the upper limit value of the third threshold range, and the lower limit value of the third threshold range is greater than the upper limit value of the fourth threshold range.

[0032] In a second aspect, the present application proposes a multi-dimensional security fusion risk assessment system, which is applied to the multi-dimensional security fusion risk assessment method described in any one of the above embodiments, including:

[0033] A data acquisition module, configured to acquire a first data set and a second data set of a target system;

[0034] a risk analysis module, configured to perform functional safety risk analysis, expected functional safety risk analysis, and information security risk analysis on the first data set to identify hazardous events of the target system;

[0035] a data processing module, configured to establish a dynamic scenario model based on the second data set, and obtain a threat level of the hazardous event through the dynamic scenario model;

[0036] A matrix construction module, configured to construct a multi-dimensional risk matrix based on the hazardous event, the dynamic scenario model, and the threat level;

[0037] The risk assessment module is used to obtain the risk value of the hazardous event based on the multi-dimensional risk matrix, and to classify the risk levels according to the risk value to obtain a multi-dimensional security risk assessment result of the target system.

[0038] In a third aspect, an electronic device comprises: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor is configured to implement the steps of the multi-dimensional security fusion risk assessment method as described in any one of the first aspects above when executing the computer program stored in the memory.

[0039] In a fourth aspect, the present application further proposes a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the multi-dimensional security fusion risk assessment method of any one of the first aspects.

[0040] In summary, the multi-dimensional safety fusion risk assessment method proposed in this application integrates the risk analysis methods of functional safety, expected functional safety, and information security, and can build a comprehensive and systematic risk assessment system to significantly improve the safety, reliability, and user experience of autonomous driving systems. Functional safety focuses on the risks caused by failures in autonomous driving systems, expected functional safety focuses on problems caused by insufficient performance or misuse of autonomous driving systems, and information security focuses on threats posed by external attacks or internal vulnerabilities in autonomous driving systems. By integrating these three analysis methods, it is possible to comprehensively cover the various risk types that may be faced during vehicle operation, avoiding the omission of potential hidden dangers due to the limitations of a single method.

[0041] The multi-dimensional safety fusion risk assessment method proposed in this application can assess risks more accurately, and comprehensively evaluate the safety of autonomous driving systems in complex scenarios by comprehensively considering functional safety, expected functional safety, and information security. For example, in an autonomous driving system, not only hardware failures (functional safety) are considered, but also software decision errors (expected functional safety) and external attacks (information security) are concerned, so as to more accurately identify and quantify risks. In addition, this application helps to optimize resource allocation and risk management, and through unified assessment and ranking of risks, rationally allocate resources, and promote the collaborative work of functional safety, expected functional safety, and information security teams to avoid duplication of work and waste of resources.

[0042] The multi-dimensional safety fusion risk assessment method proposed in this application can also enhance the robustness and reliability of autonomous driving systems. By identifying weak links and designing effective redundancy and fault-tolerance mechanisms, autonomous driving systems can better adapt to dynamic environments. For example, in severe weather conditions, autonomous driving systems can dynamically adjust sensor performance and communication encryption strategies based on risk assessment results to ensure safe operation. Furthermore, this application can enhance user experience and trust. By making risk assessment results transparent, users can gain a clearer understanding of the safety of autonomous driving systems and strengthen their trust in autonomous driving technology.

[0043] Finally, this application meets regulatory and standard requirements, ensuring legal and compliant vehicle operation, while also supporting the development and verification of complex systems and providing a solid foundation for the widespread adoption of autonomous driving technology. In short, this application not only improves the safety of autonomous driving systems but also lays the foundation for the continuous improvement and market promotion of the technology.

[0044] The multi-dimensional security fusion risk assessment method proposed in this application, and other advantages, objectives and features of this application will be reflected in part through the following description, and in part will also be understood by technical personnel in this field through research and practice of this application. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Various other advantages and benefits will become apparent to those skilled in the art upon reading the detailed description of the preferred embodiment below. The accompanying drawings are for illustration purposes only and are not to be considered as limiting the present description. The same reference symbols are used throughout the drawings to represent the same components. In the drawings:

[0046] Figure 1 A schematic diagram of a multi-dimensional security fusion risk assessment method provided in an embodiment of the present application;

[0047] Figure 2 A schematic diagram of the functional modules of a multi-dimensional security fusion risk assessment system provided in an embodiment of the present application;

[0048] Figure 3 A schematic diagram of the structure of a multi-dimensional security fusion risk assessment electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0049] In order to better understand the technical solutions provided by the embodiments of this specification, the technical solutions of the embodiments of this specification are described in detail below through the accompanying drawings and specific embodiments. It should be understood that the embodiments of this specification and the specific features in the embodiments are detailed descriptions of the technical solutions of the embodiments of this specification, rather than limitations on the technical solutions of this specification. In the absence of conflict, the embodiments of this specification and the technical features in the embodiments can be combined with each other.

[0050] In this article, relational terms such as first and second are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or equipment comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also include elements inherent to such process, method, article or equipment. In the absence of further restrictions, the elements defined by the statement "comprising a ..." do not exclude the presence of other identical elements in the process, method, article or equipment comprising the elements. The term "two or more" includes two or more than two cases.

[0051] See also Figure 1 , which is a process diagram of a multi-dimensional security fusion risk assessment method provided in an embodiment of the present application, which may specifically include:

[0052] S110: Acquire a first data set and a second data set of a target system.

[0053] Exemplarily, first, a first data set and a second data set of a target system (eg, an autonomous driving system) are acquired. These two data sets are the basis for subsequent risk assessment.

[0054] S120 . Perform functional safety risk analysis, expected functional safety risk analysis, and information security risk analysis on the first data set to identify hazardous events of the target system.

[0055] Exemplarily, the first data set is used to perform functional safety risk analysis, expected functional safety risk analysis, and information security risk analysis, and these analyses are used to identify hazardous events that may occur in the target system.

[0056] In some examples, performing functional safety risk analysis, expected functional safety risk analysis, and information security risk analysis on the first data set to identify hazardous events of the target system specifically includes:

[0057] S121. Process functional safety parameters through hazard and operability analysis to identify the functional failure modes of the target system and their corresponding safety integrity levels.

[0058] For example, functional safety parameters usually include data related to the functional implementation of the target system during normal operation. The hazard and operability analysis method can deeply explore the functional failure modes that may occur in the target system. For example, in an autonomous driving system, sensor failure, brake system failure, etc. are all functional failure modes. At the same time, this method can also determine the Automotive Safety Integrity Level (ASIL) corresponding to these failure modes. The ASIL level reflects the impact of the failure mode on the safety of the autonomous driving system and helps to manage different functional failure situations in a hierarchical manner.

[0059] S122. Process the expected functional safety parameters through the expected functional safety analysis method to identify the performance limitation data and false triggering scenario information of the target system under the preset scenario.

[0060] For example, the intended functional safety parameters focus on risk scenarios arising from insufficient design performance or environmental misjudgment during normal operation of the target system. This intended functional safety analysis method can identify the performance limitations of the target system under pre-defined scenarios, such as the reduced detection accuracy of sensors in an autonomous driving system under certain weather conditions. Furthermore, it can identify false triggering scenarios, such as the possibility that the autonomous driving system may erroneously trigger certain functions in complex traffic environments.

[0061] S123. Process information security parameters through threat and risk assessment analysis to identify security vulnerabilities of the target system and corresponding attack paths.

[0062] For example, information security parameters primarily involve security-related data during the target system's information exchange and storage processes. Threat and risk assessment analysis can identify security vulnerabilities in the target system, such as software vulnerabilities and communication protocol vulnerabilities, as well as corresponding attack paths. For example, hackers could hijack communication links and steal cloud data from autonomous driving systems through cyberattacks.

[0063] S124. Determine the harmful events of the target system based on the correlation between functional failure modes, performance limitation data, false triggering scenario information, security vulnerabilities and attack paths.

[0064] For example, after identifying functional failure modes, performance limitation data, false trigger scenarios, security vulnerabilities, and attack paths, it's necessary to analyze their interrelationships. These factors often don't exist in isolation; the emergence of one can trigger a chain reaction of others. By analyzing these interrelationships, we can identify the combined impact of a target system's hazards, leading to a more comprehensive assessment of the risks facing the target system.

[0065] S130: Based on the second data set, a dynamic scenario model is established, and the threat level of the hazardous event is obtained through the dynamic scenario model.

[0066] Exemplarily, the second data set is used to establish a dynamic scenario model, which can simulate the operation of the target system in different scenarios, thereby obtaining the threat level of the hazardous event.

[0067] In some examples, establishing a dynamic scenario model based on the second data set and obtaining the threat level of the hazard event through the dynamic scenario model specifically includes:

[0068] S131: Input the second data set into a preset scene model to construct a dynamic scene model.

[0069] For example, the preset scenario model can construct a dynamic scenario model containing multiple elements based on the input second data set. These elements include vehicle operating state parameters, such as real-time vehicle speed, acceleration, and steering angle, which reflect the vehicle's current motion state; environmental perception parameters, such as visibility, ground humidity, and obstacle distribution, which describe the vehicle's external environment; and network security state parameters, such as attack frequency and vulnerability activity, i.e., communication link quality, which reflect the target system's network security status.

[0070] S132. Calculate the exposure rate index of each hazardous event in real time through a dynamic scenario model. The exposure rate index is dynamically adjusted based on the following factors: the frequency of occurrence of hazardous events in historical data; the triggering probability of hazardous events under current environmental conditions; and the correlation between the real-time monitored attack behavior and the target system anomaly.

[0071] For example, the exposure rate metric reflects the likelihood of a hazardous event occurring in the current scenario. It is dynamically adjusted based on multiple factors. The first is the frequency of the hazardous event in historical data. If a hazardous event has occurred frequently in the past, then its likelihood of occurring in the current scenario is relatively high. The second is the triggering probability of the hazardous event under current environmental conditions. For example, the triggering probability of certain hazardous events increases in severe weather conditions. Finally, the correlation between the real-time detected supply behavior and the target system anomaly is considered. If the monitored aggressiveness is highly correlated with the target system anomaly, the likelihood of the hazardous event occurring is also increased.

[0072] Furthermore, after the dynamic scenario model is constructed, the system calculates the exposure rate index of each hazard event by integrating vehicle operating status parameters (including speed and acceleration), environmental perception data (such as visibility and road adhesion coefficient) and network security status (such as attack frequency and vulnerability activity) in real time. This index is first dynamically weighted based on the matching degree between the current scenario and the preset hazard trigger conditions. Among them, sudden environmental changes (such as low visibility caused by heavy rain) and high-frequency network attacks will significantly increase the matching coefficient; secondly, it combines the occurrence frequency of similar events in the historical database and dynamically corrects it based on the real-time vehicle speed or acceleration status (for example, the frequency weight is increased by 50% when the vehicle speed exceeds 100km / h); at the same time, it continuously monitors the time correlation between network attack behavior and system function abnormalities (such as sensor failure within 300ms after the attack) and quantifies the instantaneous risk through the threat activity model. Ultimately, the system integrates the matching coefficient, corrected historical frequency, and real-time threat activity according to preset weights to generate an exposure rate indicator in the range of 0-1, and maps it to exposure rate levels of 0-4 (Level 0: negligible probability; Level 4: extremely high probability of occurrence), providing a dynamic probability basis for the subsequent multi-dimensional quantification of the risk matrix.

[0073] S133: Determine the real-time threat level of the hazard event based on the exposure rate index and a preset threat level mapping table.

[0074] For example, the threat level mapping table maps different exposure rate indicator ranges to different threat levels. In this way, the threat level of the hazard event to the target system can be assessed in real time and accurately, providing a basis for subsequent risk response measures.

[0075] S140. Construct a multi-dimensional risk matrix based on hazardous events, dynamic scenario models and threat levels.

[0076] For example, a multi-dimensional risk matrix is ​​constructed based on hazardous events, dynamic scenario models and threat levels. This matrix comprehensively considers factors from multiple aspects and reflects the characteristics of risks more comprehensively.

[0077] S150. Based on the multi-dimensional risk matrix, the risk value of the hazardous event is obtained, and the risk level is divided according to the risk value to obtain a multi-dimensional security risk assessment result of the target system.

[0078] For example, the risk value of the hazardous event is obtained based on the multi-dimensional risk matrix, and the risk level is divided according to the risk value, and finally the multi-dimensional security risk assessment result of the target system is obtained.

[0079] In summary, the multi-dimensional safety-integrated risk assessment method proposed in this application transcends the limitations of traditional single-dimensional assessments and can cover cross-domain risks in long-tail scenarios. By integrating functional safety, expected functional safety, and information security analyses, it comprehensively covers the various types of risks a vehicle may face during operation, avoiding potential hazards that could be missed due to the limitations of a single approach, and significantly improving the safety, reliability, and user experience of autonomous driving systems.

[0080] In some examples, the first data set includes functional safety parameters, expected functional safety parameters, and information safety parameters, and the second data set includes vehicle status information, network environment information, visibility information, weather brightness information, ground humidity information, ground slope information, obstacle information, and pedestrian information.

[0081] Exemplarily, the first data set includes functional safety parameters (used to analyze hazards caused by target system failures), expected functional safety parameters (used to analyze risks caused by design deficiencies during normal operation), and information security parameters (used to analyze threats caused by external attacks or vulnerabilities). The second data set includes vehicle status information: for example, vehicle speed, direction of travel, and the operating status of vehicle components; network environment information: for example, real-time network attack events, communication link status, and the active status of information security vulnerabilities; visibility information: for example, sunny days, sandstorms, rain, snow, and fog; pedestrian information: for example, pedestrian height and movement speed; weather brightness information, ground humidity information, ground slope information, obstacle information, and external interference factors such as environmental changes in complex traffic scenarios or severe weather conditions. This information can construct more realistic dynamic scenarios and provide rich data support for the establishment of dynamic scenario models. By integrating multiple data aspects, risk assessment is more accurate and comprehensive. The inclusion of information such as vehicle status and network environment can reflect changes in safety risks in complex traffic scenarios or severe weather conditions in real time, enhancing the adaptability of the assessment method to dynamic environments.

[0082] In some examples, the multi-dimensional security fusion risk assessment method also includes:

[0083] Obtain functional safety parameters through hazard and operability analysis;

[0084] Obtain expected functional safety parameters through expected functional safety analysis method;

[0085] Obtain information security parameters through threat and risk assessment analysis.

[0086] For example, functional safety parameters are obtained through the Hazard Analysis and Risk Assessment (HARA) method, which can systematically identify the functional failure hazards of the target system; the intended functional safety parameters are obtained through the Safety of the Intended Functionality (SOTIF) method, which can analyze the risk scenarios caused by insufficient design performance or environmental misjudgment under normal operation of the target system; and information security parameters are obtained through the Threat Analysis and Risk Assessment (TARA) method, which can identify network attack paths and vulnerability exploitation scenarios. It can be seen that the use of specific analysis methods to obtain different parameters ensures the accuracy and reliability of the parameters. These professional analysis methods help to more accurately identify different types of risks and provide a solid foundation for subsequent risk assessments.

[0087] In some examples, functional safety parameters include failure modes of the target system and risk values ​​corresponding to the failure modes; expected functional safety parameters include performance limitation data and false triggering scenario information of the target system; and information security parameters include vulnerability information of the target system and threat levels corresponding to external attack paths.

[0088] For example, first, the functional safety parameters include the failure modes of the target system and the risk values ​​corresponding to the failure modes, which clearly define the possible failure conditions of the target system and the corresponding risk levels. Secondly, the expected functional safety parameters include the performance limitation data of the target system (i.e., the inherent capability limitation parameters of the target system, including sensor detection range or accuracy data, algorithm decision accuracy data, and system response delay data) and false triggering scenario information (such as the scenario characteristics that may cause the target system to produce incorrect responses, including: misidentification of obstacles, false triggering of emergency braking, and incorrect lane keeping decisions. It can be seen that false triggering scenario information helps to understand the performance deficiencies of the target system and the scenarios where misoperation may occur. Finally, the information security parameters include the vulnerability information of the target system and the threat level corresponding to the external attack path, so as to clearly grasp the weak links in the information security of the target system and the degree of threat it faces.

[0089] It can be seen that the refinement of parameter content makes risk assessment more specific and in-depth. It can more accurately identify and quantify different types of risks, helping to take targeted measures to reduce risks and improve the security of the target system.

[0090] In some examples, the multidimensional risk matrix includes a preset severity level, a preset controllability level, a preset economic impact level, a preset privacy impact level, and a preset exposure rate level, where:

[0091] The preset severity level is used to represent the threat level of the hazard event to the function of the target system or to the personal safety of the user;

[0092] The preset controllability level is used to characterize the target system's response and mitigation capabilities to hazardous events;

[0093] The preset economic impact level is used to characterize the direct or indirect economic losses caused by the hazardous event;

[0094] The preset privacy impact level is used to characterize the risk of leakage of user privacy data due to a harmful event;

[0095] The preset exposure rate level is used to characterize the probability or frequency of hazardous events occurring in dynamic scenarios.

[0096] For example, the preset severity level is used to characterize the threat level of a hazardous event to the function of the target system or to the personal safety of users, reflecting the severity of the hazardous event; the preset controllability level is used to characterize the target system's response and mitigation capabilities to the hazardous event, reflecting the target system's ability to cope with risks; the preset economic impact level is used to characterize the direct or indirect economic losses caused by the hazardous event, taking into account the impact of the risk on the economy; the preset privacy impact level is used to characterize the risk of leakage of user privacy data due to the hazardous event, focusing on user privacy protection; the preset exposure rate level is used to characterize the probability or frequency of the occurrence of the hazardous event in a dynamic scenario, reflecting the possibility of the risk occurring. It can be seen that the multi-dimensional risk matrix comprehensively considers multiple factors, making risk assessment more comprehensive and objective. It can more accurately assess the characteristics and impact of risks and provide a more scientific basis for risk management.

[0097] In some examples, the risk value of a hazardous event is calculated using the following formula:

[0098] Y = (A + B + C) × D × E;

[0099] Among them, Y is the risk value of the harmful event, A is the preset severity level, B is the preset economic impact level, C is the preset privacy impact level, D is the preset exposure rate level, and E is the preset controllability level.

[0100] The exemplary and clear calculation formula makes the calculation of risk value more accurate and standardized. By quantifying the risk value, the risk level of different hazard events can be more intuitively compared, facilitating risk ranking and management.

[0101] In some examples, risk levels are divided according to risk values ​​to obtain multi-dimensional security risk assessment results for the target system, including:

[0102] The risk value is divided into risk levels according to the preset security level to obtain the functional safety level and information security level corresponding to the risk value;

[0103] When the functional safety level corresponding to the risk value is within the first threshold range and the information security level corresponding to the risk value is within the second threshold range, determining that the multi-dimensional security risk assessment result of the target system is the highest risk level;

[0104] When the functional safety level corresponding to the risk value is within the third threshold range and the information security level corresponding to the risk value is within the fourth threshold range, the multi-dimensional security risk assessment result of the target system is determined to be the lowest risk level; the lower limit value of the first threshold range is greater than the upper limit value of the second threshold range, the lower limit value of the second threshold range is greater than the upper limit value of the third threshold range, and the lower limit value of the third threshold range is greater than the upper limit value of the fourth threshold range.

[0105] For example, the first threshold range is the highest risk level interval of the functional safety level, the second threshold range is the highest risk level interval of the information security level, the third threshold range is the lowest risk level interval of the functional safety level, and the fourth threshold range is the lowest risk level interval of the information security level. Further, the risk levels can be divided into the highest risk level, high risk level, medium risk level, and lowest risk level. The highest risk level corresponds to scenarios with dual high risks of functional safety and information security (such as brake failure + network hijacking), the high risk level corresponds to scenarios such as steering failure + data tampering, the medium risk level corresponds to scenarios such as sensor deviation + communication delay, and the lowest risk level corresponds to scenarios such as headlight failure + log alarm.

[0106] For example, when the frequency of cyber attacks in the target system increases or visibility decreases, the threshold range will be dynamically adjusted. For example, if the exposure rate level increases by 1 level, the risk value interval boundary will increase by 10%; when the controllability level decreases by 1 level, the risk value interval boundary will increase by 15%.

[0107] In summary, clear risk classification standards make risk assessment results clearer and easier to understand. They provide decision-makers with clear risk information, enabling them to take appropriate measures to address different risk levels and optimize resource allocation and risk management. For example, if the assessment result is the highest risk level, the system will be immediately shut down and the target system will be tested. If the assessment result is the medium risk level, the system will be operated at a limited speed and communication encryption will be enhanced. If the assessment result is the low risk level, logs will be recorded and periodic inspections will be conducted.

[0108] In a specific embodiment, the risk value can be divided into more levels. For example, when the risk value is 0, the risk level is no risk; when the risk value is between 1 and 10, the risk level is very low; when the risk value is between 11 and 40, the risk level is low; when the risk value is between 41 and 60, the risk value is medium; when the risk value is between 61 and 80, the risk level is high; when the risk value is greater than 80, the risk level is very high.

[0109] It should be noted that the above embodiments are only the best examples and are not intended to limit the implementation of the present application.

[0110] Furthermore, the present application also proposes a multi-dimensional security fusion risk assessment system, which is applied to any of the above multi-dimensional security fusion risk assessment methods, specifically as follows: Figure 2 The figure shows a functional module diagram of a multi-dimensional security fusion risk assessment system proposed in this application, including:

[0111] A data acquisition module 21 is used to acquire a first data set and a second data set of a target system;

[0112] a risk analysis module 22 for performing functional safety risk analysis, expected functional safety risk analysis, and information security risk analysis on the first data set to identify hazardous events of the target system;

[0113] A data processing module 23 is configured to establish a dynamic scenario model based on the second data set, and obtain a threat level of the hazard event through the dynamic scenario model;

[0114] A matrix construction module 24 is used to construct a multi-dimensional risk matrix based on hazardous events, dynamic scenario models and threat levels;

[0115] The risk assessment module 25 is used to obtain the risk value of the hazardous event based on the multi-dimensional risk matrix, and classify the risk levels according to the risk value to obtain the multi-dimensional security risk assessment result of the target system.

[0116] Exemplarily, the first data set and the second data set of the target system are acquired through the data acquisition module 21; the functional safety risk analysis, expected functional safety risk analysis and information security risk analysis are performed on the first data set through the risk analysis module 22 to identify hazardous events of the target system; the dynamic scenario model is established based on the second data set through the data processing module 23, and the threat level of the hazardous event is obtained through the dynamic scenario model; the multidimensional risk matrix is ​​constructed according to the hazardous event, the dynamic scenario model and the threat level through the matrix construction module 24; the risk value of the hazardous event is obtained based on the multidimensional risk matrix through the risk assessment module 25, and the risk level is divided according to the risk value to obtain a multidimensional safety risk assessment result of the target system.

[0117] like Figure 3 As shown, an embodiment of the present application also provides an electronic device 300, including a processor 310, a memory 320, and a computer program 321 stored on the memory 320 and executable on the processor. When the processor 310 executes the computer program 321, the steps of any of the above-mentioned multi-dimensional security fusion risk assessment methods are implemented.

[0118] Since the electronic device introduced in this embodiment is a device used to implement a multi-dimensional security fusion risk assessment method in the embodiment of this application, based on the method introduced in the embodiment of this application, technical personnel in this field can understand the specific implementation method of the electronic device of this embodiment and its various variations. Therefore, how the electronic device implements the method in the embodiment of this application will not be introduced in detail here. As long as the equipment used by technical personnel in this field to implement the method in the embodiment of this application falls within the scope of protection to be protected by this application.

[0119] In the specific implementation process, the computer program 321 can be implemented when executed by the processor Figure 1 Any implementation manner in the corresponding embodiments.

[0120] It should be noted that, in the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.

[0121] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-readable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-readable program code.

[0122] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded computer, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0123] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0124] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0125] An embodiment of the present application also provides a computer program product, which includes computer software instructions. When the computer software instructions are executed on a processing device, the processing device executes the process of the risk assessment method of multi-dimensional security fusion.

[0126] A computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function according to the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that a computer can store or a data storage device such as a server or data center that includes one or more available media integrated. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid state drive (SSD)).

[0127] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0128] In the several embodiments provided in this application, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interface, device or unit, which can be electrical, mechanical or other forms.

[0129] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0130] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0131] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0132] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.

[0133] Although the preferred embodiments of this specification have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concepts. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of this specification.

[0134] Obviously, those skilled in the art may make various changes and modifications to this specification without departing from the spirit and scope of this specification. Thus, if such changes and modifications fall within the scope of the claims of this specification and their equivalents, this specification is intended to include such changes and modifications.

Claims

1. A multi-dimensional security fusion risk assessment method, characterized in that: include: Acquire a first data set and a second data set of a target system; Performing a functional safety risk analysis, an expected functional safety risk analysis, and an information security risk analysis on the first data set to identify hazardous events of the target system; establishing a dynamic scenario model based on the second data set, and obtaining a threat level of the hazardous event through the dynamic scenario model; Constructing a multi-dimensional risk matrix based on the hazardous event, the dynamic scenario model, and the threat level; Based on the multi-dimensional risk matrix, the risk value of the hazardous event is obtained, and risk levels are divided according to the risk value to obtain a multi-dimensional security risk assessment result of the target system.

2. The multi-dimensional security fusion risk assessment method according to claim 1 is characterized in that: The first data set includes functional safety parameters, expected functional safety parameters and information security parameters, and the second data set includes vehicle status information, network environment information, visibility information, weather brightness information, ground humidity information, ground slope information, obstacle information and pedestrian information.

3. The multi-dimensional security fusion risk assessment method according to claim 2 is characterized in that: Also includes: Obtain the functional safety parameters through hazard and operability analysis; Obtaining the expected functional safety parameters through an expected functional safety analysis method; The information security parameters are obtained through threat and risk assessment analysis methods.

4. The multi-dimensional security fusion risk assessment method according to claim 2 is characterized in that: The functional safety parameters include the failure modes of the target system and the risk values ​​corresponding to the failure modes; the expected functional safety parameters include the performance limitation data and false triggering scenario information of the target system; the information security parameters include the vulnerability information of the target system and the threat level corresponding to the external attack path.

5. The multi-dimensional security fusion risk assessment method according to claim 1 is characterized in that: The multi-dimensional risk matrix includes a preset severity level, a preset controllability level, a preset economic impact level, a preset privacy impact level, and a preset exposure rate level, wherein: The preset severity level is used to represent the threat level of the hazardous event to the function of the target system or to the personal safety of the user; The preset controllability level is used to characterize the response and mitigation capabilities of the target system to the hazardous event; The preset economic impact level is used to characterize the direct or indirect economic losses caused by the hazardous event; The preset privacy impact level is used to characterize the risk of leakage of user privacy data caused by the harmful event; The preset exposure rate level is used to characterize the probability or frequency of the hazardous event occurring in a dynamic scenario.

6. The multi-dimensional security fusion risk assessment method according to claim 5 is characterized in that: The risk value of the hazard event is calculated using the following formula: Y = (A + B + C) × D × E; Among them, Y is the risk value of the hazardous event, A is the preset severity level, B is the preset economic impact level, C is the preset privacy impact level, D is the preset exposure rate level, and E is the preset controllability level.

7. The multi-dimensional security fusion risk assessment method according to claim 1 is characterized in that: The risk level classification is performed according to the risk value to obtain a multi-dimensional security risk assessment result of the target system, including: Classify the risk value according to the preset security level to obtain the functional safety level and the information security level corresponding to the risk value; When the functional safety level corresponding to the risk value is within a first threshold range and the information security level corresponding to the risk value is within a second threshold range, determining that the multi-dimensional security risk assessment result of the target system is the highest risk level; When the functional safety level corresponding to the risk value is within the third threshold range and the information security level corresponding to the risk value is within the fourth threshold range, the multi-dimensional security risk assessment result of the target system is determined to be the lowest risk level; wherein, the lower limit value of the first threshold range is greater than the upper limit value of the second threshold range, the lower limit value of the second threshold range is greater than the upper limit value of the third threshold range, and the lower limit value of the third threshold range is greater than the upper limit value of the fourth threshold range.

8. A multi-dimensional security fusion risk assessment system, applied to the multi-dimensional security fusion risk assessment method according to any one of claims 1 to 7, characterized in that: include: A data acquisition module, configured to acquire a first data set and a second data set of a target system; a risk analysis module, configured to perform functional safety risk analysis, expected functional safety risk analysis, and information security risk analysis on the first data set to identify hazardous events of the target system; a data processing module, configured to establish a dynamic scenario model based on the second data set, and obtain a threat level of the hazardous event through the dynamic scenario model; A matrix construction module, configured to construct a multi-dimensional risk matrix based on the hazardous event, the dynamic scenario model, and the threat level; The risk assessment module is used to obtain the risk value of the hazardous event based on the multi-dimensional risk matrix, and to classify the risk levels according to the risk value to obtain a multi-dimensional security risk assessment result of the target system.

9. An electronic device comprising: A memory and a processor, wherein the processor is configured to implement the steps of the multi-dimensional security fusion risk assessment method according to any one of claims 1 to 7 when executing a computer program stored in the memory.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the multi-dimensional security fusion risk assessment method according to any one of claims 1 to 7 are implemented.

Citation Information

Cited By

  • Vehicle stability control multi-domain safety fusion method and system based on double neural networks

    CN122034952A

  • Vehicle stability control multi-domain safety fusion method and system based on double neural networks

    CN122034952B