• 您的位置:网站首页
  • >
  • 最新刊出
  • >
  • 2026年
  • >
  • 2026年第8期
  • 基于ISO/SAE 21434标准的智能网联电动自行车网络安全研究

    DOI:10.3969/j.issn.2097-857X.2026.08.002

    作者:张兴辉;刘建建;黄志晨;王豪;郑兢;陈良

    关键词:TARA;智能网联电动自行车;网络安全;威胁分析;风险评估

    Research on Cybersecurity of Intelligent Connected Electric Bicycles Based on ISO/SAE 21434 Standard

    Author:ZHANG Xinghui;LIU Jianjian;HUANG Zhichen;WANG Hao;ZHENG Jing;CHEN Liang

    Keywords:TARA; intelligent connected electric bicycles; cybersecurity; threat analysis; risk assessment

    摘要:

    【目的】针对智能网联电动自行车(ICEB)面临的网络安全新挑战,依据ISO/SAE 21434等标准,开展网络安全研究,为该类产品的网络安全开发与全生命周期防护提供支撑。【方法】首次将威胁分析与风险评估(TARA)方法论系统应用于ICEB领域。在识别软硬件等5类核心资产及安全属性基础上,采用STRIDE法挖掘典型威胁场景,并多维度开展影响评级;运用攻击树解析攻击路径,结合CVSS量化攻击可行性,构建风险矩阵并划定风险等级;依据分级处置原则提出对应技术防护方案。【结果】形成完整的ICEB网络安全分析框架;识别出远程劫持、数据泄露、信道不可用等典型威胁,评定出风险等级;提出多因素认证等针对性防护措施。【结论】本研究兼顾产业成本敏感的特性,可为产品网络安全开发、全生命周期安全防护及产业链协同安全建设提供理论与实践支撑。

    Abstract:

    [Objective] To address emerging cybersecurity challenges for intelligent connected electric bicycles (ICEBs), this study conducts cybersecurity research based on standards such as ISO/SAE 21434 to support cybersecurity development and full lifecycle protection for such products. [Methods] This study pioneers the systematic application of the Threat Analysis and Risk Assessment (TARA) methodology within the ICEB domain. Following the identification of five core asset categories (including software and hardware) and their security attributes, the STRIDE method was employed to uncover typical threat scenarios, with impact ratings conducted across multiple dimensions. Attack trees were utilized to analyse attack paths, combined with CVSS to quantify attack feasibility, thereby constructing a risk matrix and defining risk levels. Corresponding technical protection measures were proposed based on graded response principles. [Results] A comprehensive cybersecurity analysis framework for ICEB was established. Typical threats such as remote hijacking, data leakage, and channel unavailability were identified and risk levels were assessed. Targeted protective measures, including multi-factor authentication, were proposed. [Conclusion] This study, accounting for the industry’s cost-sensitive nature, provides theoretical and practical support for product cybersecurity development, full lifecycle security protection, and collaborative security construction across the industrial chain.

    引用格式:张兴辉,刘建建,黄志晨,等. 基于ISO/SAE 21434标准的智能网联电动自行车网络安全研究[J]. 标准化学报,2026(8):16-25.

    基金项目:本文受2024年度国家市场监督管理总局科技计划项目“基于AI模型的智能可穿戴设备信息安全检测技术研究”(项目编号:2024MK148);2025年福建省工业和信息化厅软件业技术创新重点攻关及产业化项目“基于DeepSeek的智能交通车载信息交互系统”(闽工信函软件〔2025〕587号)资助。

    作者简介:张兴辉,硕士,高级工程师,研究方向为物联网、车联网、自动驾驶、车路协同和信息安全等。陈良,通信作者,博士,高级工程师,研究方向为汽车及电动自行车的检验方法及标准、机电类仪器设备开发等。

    主管单位:

    国家市场监督管理总局

    主办单位:

    中国标准化研究院

    中国标准化协会

    国内刊号:

    CN 10-2082/T

    国际刊号:

    ISSN 2097-857X

    创刊时间:

    1964年

    出版周期:

    月刊

    指导单位
    合作伙伴