industry news
Subscribe Now

LDRA Helps Ensure Automotive Cybersecurity with Support for SAE J3061

LDRA tool suite® for Automotive Provides Integrated ISO 26262–Compliant Cybersecurity Process Under J3061 for Safety- and Security-Critical Automotive Applications

Wirral, U.K. – February 27, 2018 – LDRA, the leader in standards compliance, automated software verification, software code analysis, and test tools, today announced support within the LDRA tool suite® for SAE International’s Surface Vehicle Recommended Practice J3061. The tool suite now provides an ISO 26262–compliant cybersecurity development process for critical automotive applications that must be secure to ensure safety, including advanced driver assistance systems (ADAS), autonomous vehicles, infotainment, steering and braking, adaptive cruise control, lane departure warning systems, and more.

Connected vehicles are increasingly becoming targets for cybersecurity attacks, making security a critical aspect of vehicle safety. While ISO 26262 addresses functional safety in the development of automotive systems, cybersecurity must also be designed and built into automotive applications throughout the development lifecycle to provide defense in depth. SAE J3061 provides an engineering process framework that integrates with other development processes for the comprehensive and systematic design of cybersecurity into vehicle systems. With the LDRA tool suite, developers can now map security goals to particular software assets and cross-reference those to appropriate safety goals and requirements.

“With the many complex electronic systems in every new automobile—often mixed and matched from different tiered suppliers—carmakers have an increasingly difficult challenge securing vehicles from myriad cyberattack vectors,” said Steve Hoffenberg, Industry Analyst and Director, VDC Research. “Vehicle electronics now must be designed from the ground up with cybersecurity as a core principle, including the ability to develop and test software in a rigorous manner for safety and security. The framework laid out by SAE J3061 is a significant step in helping automotive developers along that path.”

“We continue to demonstrate our commitment and leadership in the areas of cybersecurity and functional safety in life-critical systems such as automotive applications,” said IanHennell, Operations Director, LDRA. “By integrating the process framework of SAE J3061 into our tool suite, we enable automotive suppliers and OEMs to mitigate risk and increase their confidence that their software is safe and secure by construction.”

The LDRA tool suite supports the following J3061 processes and requirements related to ISO 26262, among others, for automotive applications:

  • SAE J3061 section 8.6.2: Methods for verification of the architectural design accomplished through control flow and data flow analysis. LDRA static analysis tools provide a view into the hierarchical structure of software components, cohesion within the components, coupling among the software components, and data and control flow analysis for ASIL A through ASIL D.
  • SAE J3061 section 8.6.5: Software unit design to ensure the objective of specifying software units in accordance with software architectural design. The LDRA tool suite supports the use of coding guidelines such as MISRA, CERT, and CWE for more secure, reliable, and maintainable code, identifying coding errors and security vulnerabilities so that they can be addressed immediately. The tool suite’s static analysis capabilities ensure that the architectural design and unit implementation principles required by ISO 26262-6:2011 can be checked automatically.
  • SAE J3061 Section 8.6.6: Code reviews throughout software design and implementation. The LDRA tool suite automates the code review process to increase efficiency and reduce opportunity for human error in comparison to peer code reviews. Static analysis can identify vulnerabilities in code that may meet the syntactic requirements of the language while still containing unpredictable or undefined behaviors.
  • SAE J3061 Section 8.6.7: Software unit testing and SAE J3061 Section 8.6.8: Software integration testing. Safety-related units must be run on the target and the test results must comply with the safety and security requirements. The LDRA tool suite supports testing on both development and target platforms using the same test cases, and also supports robustness testing, which is complementary to fuzz testing (recommended by J3061). Boundary value analysis, conditional value analysis, error guessing, and error seeding tests are supported.
  • SAE J3061 Section 8.6.9: Verification/validation of software cybersecurity requirements. During implementation, the LDRA tool suite conducts cybersecurity tests covering all software cybersecurity requirements to verify that the actual results match the requirement results. The tool suite’s bidirectional traceability mechanism ensures that these requirements are fulfilled. LDRA tools have been certified by TÜV SÜD and TÜV Saar in safety-critical environments under ISO 26262

The LDRA tool suite for Automotive with support for SAE J3061 is available now. An in-depth white paper on Applying SAE J3061 to ISO 26262 processes with the LDRA tool suite is available for download at www.ldra.com/SAEJ3061.

About LDRA

For more than 40 years, LDRA has developed and driven the market for software that automates code analysis and software testing for safety-, mission-, security-, and business-critical markets. Working with clients to achieve early error identification and full compliance with industry standards, LDRA traces requirements through static and dynamic analysis to unit testing and verification for a wide variety of hardware and software platforms. Boasting a worldwide presence, LDRA is headquartered in the United Kingdom with subsidiaries in the United States and India coupled with an extensive distributor network. For more information on the LDRA tool suite, please visit www.ldra.com.

Leave a Reply

featured blogs
Apr 18, 2024
Analog Behavioral Modeling involves creating models that mimic a desired external circuit behavior at a block level rather than simply reproducing individual transistor characteristics. One of the significant benefits of using models is that they reduce the simulation time. V...
Apr 16, 2024
Learn what IR Drop is, explore the chip design tools and techniques involved in power network analysis, and see how it accelerates the IC design flow.The post Leveraging Early Power Network Analysis to Accelerate Chip Design appeared first on Chip Design....
Mar 30, 2024
Join me on a brief stream-of-consciousness tour to see what it's like to live inside (what I laughingly call) my mind...

featured video

MaxLinear Integrates Analog & Digital Design in One Chip with Cadence 3D Solvers

Sponsored by Cadence Design Systems

MaxLinear has the unique capability of integrating analog and digital design on the same chip. Because of this, the team developed some interesting technology in the communication space. In the optical infrastructure domain, they created the first fully integrated 5nm CMOS PAM4 DSP. All their products solve critical communication and high-frequency analysis challenges.

Learn more about how MaxLinear is using Cadence’s Clarity 3D Solver and EMX Planar 3D Solver in their design process.

featured chalk talk

The Future of Intelligent Devices is Here
Sponsored by Alif Semiconductor
In this episode of Chalk Talk, Amelia Dalton and Henrik Flodell from Alif Semiconductor explore the what, where, and how of Alif’s Ensemble 32-bit microcontrollers and fusion processors. They examine the autonomous intelligent power management, high on-chip integration and isolated security subsystem aspects of these 32-bit microcontrollers and fusion processors, the role that scalability plays in this processor family, and how you can utilize them for your next embedded design.
Aug 9, 2023
29,790 views