https://www.mdu.se/

mdu.sePublikationer
Ändra sökning
Länk till posten
Permanent länk

Direktlänk
Publikationer (10 of 151) Visa alla publikationer
Luis de la Vara, J. & Gallina, B. (2026). 12th International Workshop on Next Generation of System Assurance Approaches for Critical Systems (SASSUR 2025). In: Torngren, M Gallina, B Schoitsch, E Troubitsyna, E Bitsch, F (Ed.), COMPUTER SAFETY, RELIABILITY, AND SECURITY. SAFECOMP 2025 WORKSHOPS, COC3CPS, DECSOS, SASSUR, SENSEI, SRTOITS, AND WAISE: . Paper presented at 44th International Conference on Computer Safety Reliability and Security-SAFECOMP-Annual, SEP 10-12, 2025, Stockholm, SWEDEN (pp. 180-182). SPRINGER INTERNATIONAL PUBLISHING AG, 15955
Öppna denna publikation i ny flik eller fönster >>12th International Workshop on Next Generation of System Assurance Approaches for Critical Systems (SASSUR 2025)
2026 (Engelska)Ingår i: COMPUTER SAFETY, RELIABILITY, AND SECURITY. SAFECOMP 2025 WORKSHOPS, COC3CPS, DECSOS, SASSUR, SENSEI, SRTOITS, AND WAISE / [ed] Torngren, M Gallina, B Schoitsch, E Troubitsyna, E Bitsch, F, SPRINGER INTERNATIONAL PUBLISHING AG , 2026, Vol. 15955, s. 180-182Konferensbidrag, Publicerat paper (Refereegranskat)
Ort, förlag, år, upplaga, sidor
SPRINGER INTERNATIONAL PUBLISHING AG, 2026
Serie
Lecture Notes in Computer Science, ISSN 0302-9743
Nationell ämneskategori
Datorsystem
Identifikatorer
urn:nbn:se:mdh:diva-74751 (URN)001579298700015 ()978-3-032-02017-8 (ISBN)978-3-032-02018-5 (ISBN)
Konferens
44th International Conference on Computer Safety Reliability and Security-SAFECOMP-Annual, SEP 10-12, 2025, Stockholm, SWEDEN
Tillgänglig från: 2025-12-03 Skapad: 2025-12-03 Senast uppdaterad: 2025-12-03Bibliografiskt granskad
Sahoo, S. S., Gallina, B. & Sheikh Bahaei, S. (2026). An HMI Personalization Concept for Increasing Safety of the Intended Functionality. In: 2026 21st European Dependable Computing Conference Companion Proceedings (EDCC-C): . Paper presented at 2026 21st European Dependable Computing Conference Companion Proceedings (EDCC-C), 7-10 April, 2026, Canterbury, United Kingdom (pp. 36-39). Institute of Electrical and Electronics Engineers (IEEE)
Öppna denna publikation i ny flik eller fönster >>An HMI Personalization Concept for Increasing Safety of the Intended Functionality
2026 (Engelska)Ingår i: 2026 21st European Dependable Computing Conference Companion Proceedings (EDCC-C), Institute of Electrical and Electronics Engineers (IEEE) , 2026, s. 36-39Konferensbidrag, Publicerat paper (Refereegranskat)
Abstract [en]

Many safety-relevant vehicle functions, both ADAS (Advanced Driver Assistance Systems) and non-ADAS, depend on timely and correct driver responses to system information or warnings. When Human Machine Interface (HMI) assumptions are underspecified, Safety Of The Intended Functionality (SOTIF) may be undermined by delayed reactions, nuisance-driven, mistrust, or misuse. We use the Moving Off Information System (MOIS, UN R159) as a case study and we propose a guardrailed HMI personalisation concept that adapts presentation, not function, to driver variability across users and over time. We define a practical, measurable notion of non-intrusive optical information and map it to evaluation hooks and evidence artifacts. The concept is coupled with attention-aware safeguards and functional safety timing budgets consistent with ISO 26262:2018 and ISO 21448:2022. We outline evaluation hooks and evidence mapping that link SOTIF claims to measurable HMI outcomes without processing personal data. Although developed for MOIS, the concept is intended to extend to other driver-in-the-loop functions beyond ADAS.

Ort, förlag, år, upplaga, sidor
Institute of Electrical and Electronics Engineers (IEEE), 2026
Nationell ämneskategori
Människa-datorinteraktion (interaktionsdesign)
Identifikatorer
urn:nbn:se:mdh:diva-78940 (URN)10.23919/edccccps00002.2026.00031 (DOI)978-1-971299-06-8 (ISBN)
Konferens
2026 21st European Dependable Computing Conference Companion Proceedings (EDCC-C), 7-10 April, 2026, Canterbury, United Kingdom
Tillgänglig från: 2026-09-04 Skapad: 2026-09-04 Senast uppdaterad: 2026-09-04Bibliografiskt granskad
Gallina, B., Törngren, M. & Bitsch, F. (Eds.). (2026). Computer Safety, Reliability, and Security. Paper presented at 44th International Conference, SAFECOMP 2025, Stockholm, Sweden, September 10–12, 2025. Springer
Öppna denna publikation i ny flik eller fönster >>Computer Safety, Reliability, and Security
2026 (Engelska)Proceedings (redaktörskap) (Övrigt vetenskapligt)
Ort, förlag, år, upplaga, sidor
Springer, 2026
Serie
Lecture Notes in Computer Science, ISSN 0302-9743, E-ISSN 1611-3349
Nationell ämneskategori
Elektroteknik och elektronik
Identifikatorer
urn:nbn:se:mdh:diva-75142 (URN)978-3-032-01241-8 (ISBN)
Konferens
44th International Conference, SAFECOMP 2025, Stockholm, Sweden, September 10–12, 2025
Tillgänglig från: 2025-12-15 Skapad: 2025-12-15 Senast uppdaterad: 2025-12-15Bibliografiskt granskad
Törngren, M., Gallina, B., Schoitsch, E., Troubitsyna, E. & Bitsch, F. (Eds.). (2026). Computer Safety, Reliability, and Security: SAFECOMP 2025 Workshops. Paper presented at CoC3CPS, DECSoS, SASSUR, SENSEI, SRToITS, and WAISE, Stockholm, Sweden, September 9, 2025. Springer
Öppna denna publikation i ny flik eller fönster >>Computer Safety, Reliability, and Security: SAFECOMP 2025 Workshops
Visa övriga...
2026 (Engelska)Proceedings (redaktörskap) (Övrigt vetenskapligt)
Ort, förlag, år, upplaga, sidor
Springer, 2026
Serie
Lecture Notes in Computer Science, ISSN 0302-9743 ; 15955
Nationell ämneskategori
Elektroteknik och elektronik
Identifikatorer
urn:nbn:se:mdh:diva-75143 (URN)978-3-032-02017-8 (ISBN)
Konferens
CoC3CPS, DECSoS, SASSUR, SENSEI, SRToITS, and WAISE, Stockholm, Sweden, September 9, 2025
Tillgänglig från: 2025-12-15 Skapad: 2025-12-15 Senast uppdaterad: 2025-12-15Bibliografiskt granskad
Fayollas, C., Gallina, B., Palanque, P., Rodriguez-Hernando, D. & Steere, S. (2026). Human-Variability-Aware Safety Analysis Framework for Interactive Technologies of Critical Command and Control Systems. In: Systems, Software and Services Process Improvement and Innovation, Cairo, Egypt, September 8–10, 2026, Proceedings, Part I: . Paper presented at Systems, Software and Services Process Improvement and Innovation, Cairo, Egypt, September 8–10, 2026, Proceedings, Part I (pp. 271-289). Springer Nature
Öppna denna publikation i ny flik eller fönster >>Human-Variability-Aware Safety Analysis Framework for Interactive Technologies of Critical Command and Control Systems
Visa övriga...
2026 (Engelska)Ingår i: Systems, Software and Services Process Improvement and Innovation, Cairo, Egypt, September 8–10, 2026, Proceedings, Part I, Springer Nature , 2026, s. 271-289Konferensbidrag, Publicerat paper (Refereegranskat)
Abstract [en]

Command and Control Systems (CCS) are dependability-critical socio-technical systems, which encompass organizations, trained operator(s), and interactive technology designed to support the operator(s) in command and monitoring tasks. For instance, the CCS for Flight Safety Operations at the Europe’s Spaceport in Kourou supports the operator(s) in the monitoring of the trajectory and flight parameters of a launcher, and in commanding the eventual destruction of the launcher if the trajectory deviates outside of the pre-defined safety envelope. To ensure dependability, the congruence between the interactive technology and the operator is key. Indeed, the interactive technology must tolerate human-variability in terms of faults which may occur at perceptive, motor, and cognitive levels and which may lead to human errors. To assess dependability of new interaction technologies, we propose a systematic human-variability-aware safety analysis framework, called P-VASA. The framework takes into account the input and output devices, their associated interaction techniques and the operator’s task and is applicable to any CCS involving interactive technologies.

Ort, förlag, år, upplaga, sidor
Springer Nature, 2026
Serie
Communications in Computer and Information Science, ISSN 1865-0929, E-ISSN 1865-0937
Nationell ämneskategori
Datavetenskap (datalogi)
Identifikatorer
urn:nbn:se:mdh:diva-78937 (URN)10.1007/978-3-032-36813-3_17 (DOI)978-3-032-36812-6 (ISBN)
Konferens
Systems, Software and Services Process Improvement and Innovation, Cairo, Egypt, September 8–10, 2026, Proceedings, Part I
Tillgänglig från: 2026-09-04 Skapad: 2026-09-04 Senast uppdaterad: 2026-09-04Bibliografiskt granskad
Grechi, V., de Oliveira, A., Gallina, B., Montecchi, L. & Braga, R. (2026). Model-based Safety and Security Co-Analysis usingComponent Attack Fault Trees in the Automotive Domain. In: 2026: Proceedings of the 26th Brazilian Symposium on Cybersecurity. Paper presented at 26º Simpósio Brasileiro de Cibersegurança (SBSeg 2026), (pp. 754-769).
Öppna denna publikation i ny flik eller fönster >>Model-based Safety and Security Co-Analysis usingComponent Attack Fault Trees in the Automotive Domain
Visa övriga...
2026 (Engelska)Ingår i: 2026: Proceedings of the 26th Brazilian Symposium on Cybersecurity, 2026, s. 754-769Konferensbidrag, Publicerat paper (Refereegranskat)
Abstract [en]

Cyber-physical systems (CPSs) in critical domains such as self-driven cars and unmanned aerial vehicles involve complex interactions between safety and security concerns. Failures in CPSs such as self-driven cars are caused either by hardware/software component faults or attacks. The identification of hazards, their risks, and root causes is addressed by Safety Engineering, e.g., using Fault Tree Analysis. On the other hand, Security Engineering addresses the identification of asset vulnerabilities, their associated external threats, risks, and causes, using Attack Tree Analysis. Although both disciplines use separate terminology, processes, and tools, they rely on a common system architecture and in the use models such as Component Fault Trees and Attack Trees to support their analyses. In the automotive domain, such analyses should be performed in alignment with guidance defined in assurance standards, e.g., ISO 26262 for functional safety, and ISO 21434 for cybersecurity. However, existing techniques that integrate safety and security models are not fully aligned with the ISO 21434. In this paper, we introduce a novel Component Attack Fault Trees (CAFT) modelling language, built upon Component Fault Trees and ISO 21434 concepts, for integrating safety and security analysis models. Since CAFT was built in alignment with traditional safety and security analysis formalisms and standards, it has the potential to guide engineers in the development of multi-concern analysis model-driven engineering tools. We illustrate the use of our CAFT language to support safety and security co-analysis of an automotive headlamp system. 

Nationell ämneskategori
Datorsystem
Identifikatorer
urn:nbn:se:mdh:diva-78939 (URN)10.5753/sbseg.2026.27039 (DOI)
Konferens
26º Simpósio Brasileiro de Cibersegurança (SBSeg 2026),
Tillgänglig från: 2026-09-04 Skapad: 2026-09-04 Senast uppdaterad: 2026-09-04Bibliografiskt granskad
Gallina, B. & Olesen, T. Y. (2026). Ontology-Based SBOM (Software Bill of Materials) Cross-Jurisdiction Compliance. In: Systems, Software and Services Process Improvement and Innovation: 33rd European Conference, EuroSPI 2026, Cairo, Egypt, September 8–10, 2026, Proceedings, Part I. Paper presented at 33rd European Conference, EuroSPI 2026, Cairo, Egypt, September 8–10, 2026 (pp. 50-67). Springer Nature
Öppna denna publikation i ny flik eller fönster >>Ontology-Based SBOM (Software Bill of Materials) Cross-Jurisdiction Compliance
2026 (Engelska)Ingår i: Systems, Software and Services Process Improvement and Innovation: 33rd European Conference, EuroSPI 2026, Cairo, Egypt, September 8–10, 2026, Proceedings, Part I, Springer Nature , 2026, s. 50-67Konferensbidrag, Publicerat paper (Refereegranskat)
Abstract [en]

A Software Bill of Materials (SBOM) has become mandatory in different jurisdictions. If well-conceived and understood, an SBOM is a starting point for risk identification and assessment. In various jurisdictions, the provision of an SBOM is mandatory. The format for SBOM creation and the process for its generation and maintenance are jurisdiction-dependent. Hence, to ensure cross-jurisdiction compliance, vendors selling their products to different jurisdictions need to systematize and manage the SBOM commonalities and variabilities. As far as the literature reveals, no automatable methodological approach guides SBOM cross-jurisdiction compliance. In this paper, we focus on the SBOM format, and we reuse and customize our previously proposed ontology-based methodological approach. First, we represent the systematization of the existing commonality and variability among a subset of relevant SBOM formats adopted by different jurisdictions. Then, we reuse the reusable constraints for checking instance-validity. Finally, we provide an argumentation pattern for SBOM-cross-jurisdiction compliance.

Ort, förlag, år, upplaga, sidor
Springer Nature, 2026
Serie
Communications in Computer and Information Science, ISSN 1865-0929, E-ISSN 1865-0937
Nationell ämneskategori
Programvaruteknik
Identifikatorer
urn:nbn:se:mdh:diva-78938 (URN)10.1007/978-3-032-36813-3_4 (DOI)978-3-032-36812-6 (ISBN)
Konferens
33rd European Conference, EuroSPI 2026, Cairo, Egypt, September 8–10, 2026
Tillgänglig från: 2026-09-04 Skapad: 2026-09-04 Senast uppdaterad: 2026-09-04Bibliografiskt granskad
Törngren, M., Asplund, F. & Gallina, B. (2026). Preface. Paper presented at 44th International Conference on Computer Safety, Reliability and Security, SAFECOMP 2025, Stockholm, Sweden, 10-12 September, 2025. Lecture Notes in Computer Science, 15954 LNCS, v-vi
Öppna denna publikation i ny flik eller fönster >>Preface
2026 (Engelska)Ingår i: Lecture Notes in Computer Science, ISSN 0302-9743, E-ISSN 1611-3349, Vol. 15954 LNCS, s. v-viArtikel i tidskrift, Editorial material (Refereegranskat) Published
Ort, förlag, år, upplaga, sidor
Springer Science and Business Media Deutschland GmbH, 2026
Nationell ämneskategori
Datavetenskap (datalogi)
Identifikatorer
urn:nbn:se:mdh:diva-73215 (URN)2-s2.0-105014389284 (Scopus ID)
Konferens
44th International Conference on Computer Safety, Reliability and Security, SAFECOMP 2025, Stockholm, Sweden, 10-12 September, 2025
Tillgänglig från: 2025-09-10 Skapad: 2025-09-10 Senast uppdaterad: 2025-10-10Bibliografiskt granskad
Okada, M. & Gallina, B. (2026). STPA-WA: A Safe System-Oriented Extension of STPA forDependability in Automated Driving. In: : . Paper presented at 13th European Congress of Embedded Real Time Systems (ERTS), Feb 2026, Toulouse, France.. HAL
Öppna denna publikation i ny flik eller fönster >>STPA-WA: A Safe System-Oriented Extension of STPA forDependability in Automated Driving
2026 (Engelska)Konferensbidrag, Publicerat paper (Refereegranskat)
Abstract [en]

To nearly achieve vision zero, the United Nations have intro-duced the safe system approach. This approach aims at accom-modating human factors by incorporating redundancy withinthe different identified safety pillars (safe speed linked to reg-ulations, safe vehicles, safe roads, safe emergency care). Tocontribute to vision zero, ADSs (Automated Driving Systems)need to contribute to road safety, in addition to ensuring safetyof the intended functionality. Achieving safe and harmoniousADSs necessitates a comprehensive safety approach beyondthe vehicle-centric / ADS-centric perspective. It also calls forroadmanship which is a concept that centers on whether thevehicle plays well with others.System Theoretic Process Analysis (STPA) is a process forconducting hazards analysis. STPA has been recently includedwithin the automotive safety standards and regulations as sug-gested process to be adopted. However, its application has beenconsidered challenging and proposals for adaptations have beenprovided. In this paper, we provide yet another novel adaptation,called STPA-WA1, which embraces roadmanship and the differ-ent perspectives represented by the different pillars. STPA-WAdeepens safety/dependability understanding.

Ort, förlag, år, upplaga, sidor
HAL, 2026
Serie
European Congress of Embedded Real Time Systems, ISSN 2680-0918
Nationell ämneskategori
Farkost och rymdteknik
Identifikatorer
urn:nbn:se:mdh:diva-78967 (URN)10.82331/ERTS.2026.41 (DOI)
Konferens
13th European Congress of Embedded Real Time Systems (ERTS), Feb 2026, Toulouse, France.
Tillgänglig från: 2026-09-08 Skapad: 2026-09-08 Senast uppdaterad: 2026-09-08Bibliografiskt granskad
Grechi, V. L., Luiz de Oliveira, A., Gallina, B., Montecchi, L. & Vaccare Braga, R. T. (2025). Integrating Attack-Fault Trees in the ODE Metamodel to Support Safety and Security Co-Analysis in the Automotive Domain. In: Proceedings - 2025 IEEE 49th Annual Computers, Software, and Applications Conference, COMPSAC 2025: . Paper presented at 49th IEEE Annual Computers, Software, and Applications Conference, COMPSAC 2025, Toronto, Canada, 8-11 July, 2025 (pp. 63-72). Institute of Electrical and Electronics Engineers (IEEE)
Öppna denna publikation i ny flik eller fönster >>Integrating Attack-Fault Trees in the ODE Metamodel to Support Safety and Security Co-Analysis in the Automotive Domain
Visa övriga...
2025 (Engelska)Ingår i: Proceedings - 2025 IEEE 49th Annual Computers, Software, and Applications Conference, COMPSAC 2025, Institute of Electrical and Electronics Engineers (IEEE) , 2025, s. 63-72Konferensbidrag, Publicerat paper (Refereegranskat)
Abstract [en]

Integrating safety and security in automotive cyber-physical systems (CPS) domains (e.g. autonomous vehicles), is challenging for two main reasons. First, it is still difficult to represent the potential consequences of system failures or malicious attacks. Secondly, these systems must ensure safety and security despite unknowns and uncertainties. A Digital Dependability Identity (DDI) can facilitate this by encapsulating all dependability characteristics (e.g., design, requirements, safety, and security analysis models) of CPS's components. The Open Dependability Exchange (ODE) metamodel is an implementation of the DDI concept, but has limitations in the interplay between safety and security. ODE is aligned with with ISO 26262 but lacks certain security concepts to be aligned with ISO 21434. Also, ODE supports modeling fault trees, but modeling attack trees and attack-fault trees still not. This paper proposes an extension to the ODE metamodel, aiming to increase coverage of ISO 21434 concepts and allowing the modeling of attack-fault trees. We built these metamodel extensions based on an analysis of the ODE metamodel, industry standards, Microsoft STRIDE model, and HEAVENS security analysis methodologies. We evaluated the proposed extensions in an illustrative example of an autonomous vehicle.

Ort, förlag, år, upplaga, sidor
Institute of Electrical and Electronics Engineers (IEEE), 2025
Serie
IEEE Annual Computer Software and Applications Conference Workshops, ISSN 2836-3795
Nyckelord
Attack-fault Trees, Open Dependability Exchange (ODE), Safety and Security Co-analysis, Threat Analysis and Risk Assessment
Nationell ämneskategori
Programvaruteknik
Identifikatorer
urn:nbn:se:mdh:diva-73427 (URN)10.1109/compsac65507.2025.00017 (DOI)001575960000009 ()2-s2.0-105016132191 (Scopus ID)979-8-3315-7434-5 (ISBN)
Konferens
49th IEEE Annual Computers, Software, and Applications Conference, COMPSAC 2025, Toronto, Canada, 8-11 July, 2025
Tillgänglig från: 2025-09-24 Skapad: 2025-09-24 Senast uppdaterad: 2026-07-06Bibliografiskt granskad
Organisationer
Identifikatorer
ORCID-id: ORCID iD iconorcid.org/0000-0002-6952-1053

Sök vidare i DiVA

Visa alla publikationer