IP Library Granted Patent US 12688305
Granted Patent B2
US 12688305 · App. 18/848,312 · Granted Jul 21, 2026

Risk analysis of a distributed test object

Inventors: Marcel Lotze (Braunschweig, DE); Jörn Eichler (Berlin, DE); Alexander Tschache (Wolfsburg, DE)
Assignee: VOLKSWAGEN AKTIENGESELLSCHAFT
G06F21/577G06F21/552G06F21/554G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12688305
App. No.
18/848,312
Granted
Jul 21, 2026
Kind
B2
Abstract

A method, a computer program with instructions, and a system for the risk analysis of a distributed test object. The disclosed embodiment also relates to devices for use in such a system. According to the invention, a risk analysis for a part of the test object located in a first context is carried out. In addition, a risk analysis for a part of the test object located in a second context is carried out. If a protection requirement is determined in the case of one of the risk analyses, information relating to this determined protection requirement is exchanged between the risk analyses. The determined protection requirement can then be taken into account in that a risk-enhancing measure is determined. In this case, information relating to the determined risk-enhancing measure can be exchanged between the risk analyses.

Claims (31)

1 . A method for performing cyber security risk analysis of a distributed test object that includes a plurality of distributed test object parts, the method comprising:

performing a semi-automated, or fully automated, first risk analysis for a first one of the plurality of distributed test object parts located in a first context in a first analysis context, the first analysis context being delineated from other analysis contexts of a plurality of analysis contexts by a first distinct assessment model or a first distinct analysis method and a first distinct specification for modelling the test object, wherein the first context relates to a transport, a mobile device or an embedded system;

performing a semi-automated, or fully automated, second risk analysis for a second one of the plurality of distributed test object parts located in a second context in a second analysis context, the second analysis context being delineated by a second distinct assessment model or a second distinct analysis method and a second distinct specification for modelling the test object, wherein the second context relates to a backend or information technology system;

exchanging information relating to an ascertained protection requirement between the first and second risk analyses; and

automatically performing further risk analyses while the ascertained protection requirement is to be taken into account based on a transmission path of a datum for the ascertained protection requirement,

wherein the further cyber security risk analyses are performed in the first and second contexts by interchanging data between the first and second contexts,

wherein respective data origins are annotated during analysis to provide uniform identification of transmitted data by way of either alignment or association independently of analysis context and modelling specification such that modelling of the test object part in the transport and the backend is completed in a single operation,

wherein a threat to the protection requirement identified during the risk analysis in one of the first and second contexts is taken into account during the risk analysis in the other of the first and second contexts to provide reciprocal linking of the risk analyses in the different contexts that enables threats to a protection requirement that have been identified in and taken into consideration across contexts reciprocally,

wherein in response to identification of the threat to the protection requirement during the one of the first and second risk analyses is taken into account during the other of the first and second risk analyses, and

wherein an ascertained protection requirement is taken into account during a third risk analysis for a part of the test object that is located in a third context.

2 . The method of claim 1 , wherein the ascertained protection requirement is taken into account by stipulating a risk-mitigating measure.

3 . The method of claim 2 , wherein information relating to the stipulated risk-mitigating measure is exchanged between risk analyses.

4 . The method of claim 3 , wherein the risk-mitigating measure is stipulated in an automated manner or by way of a manual intervention.

5 . A non-transitory computer readable medium including computer program containing instructions that, when executed by a computer, cause the computer to perform the risk analysis method of claim 1 .

6 . A system for performing cyber security risk analysis of a distributed test object that includes a plurality of distributed test object parts, having:

first analysis circuitry for performing a semi-automated or fully automated risk analysis for a first one of the plurality of distributed test object parts located in a first context in a first analysis context, the first analysis context being delineated from other analysis contexts of a plurality of analysis contexts by a first distinct assessment model or a first distinct analysis method and a first distinct specification for modelling the test object, wherein the first context relates to a transport, a mobile device or an embedded system; and

second analysis circuitry for performing a semi-automated or fully automated risk analysis for a second one of the plurality of distributed test object parts located in a second context in a second analysis context, the second analysis context being delineated by a second distinct assessment model or a second distinct analysis method and a second distinct specification for modelling the test object, wherein the second context relates to a backend or information technology system,

wherein the first analysis circuitry and the second analysis circuitry being configured to exchange information relating to an ascertained protection requirement,

wherein automatic performance of further risk analyses while the ascertained protection requirement is to be taken into account is based on a transmission path of a datum for the ascertained protection requirement,

wherein the further cyber security risk analyses are performed in the first and second contexts by interchanging data between the first and second contexts,

wherein respective data origins are annotated during analysis to provide uniform identification of transmitted data by way of either alignment or association independently of analysis context and modelling specification such that modelling of the test object part in the transport and the backend is completed in a single operation,

wherein a threat to the protection requirement identified during the risk analysis in one of the first and second contexts is taken into account during the risk analysis in the other of the first and second contexts to provide reciprocal linking of the risk analyses in the different contexts that enables threats to a protection requirement that have been identified in and taken into consideration across contexts reciprocally,

wherein in response to identification of the threat to the protection requirement during the one of the first and second risk analyses is taken into account during the other of the first and second risk analyses, and

wherein an ascertained protection requirement is taken into account during a third risk analysis for a part of the test object that is located in a third context.

7 . The system of claim 6 , wherein the first analysis circuitry is further configured to relay information relating to the ascertained protection requirement to the second analysis circuitry for carrying out risk analysis for the part of the test object that is located in the second context.

8 . The system of claim 6 , wherein the second analysis circuitry is further configured to take into account the protection requirement ascertained by the first analysis circuitry in the second context.

9 . The system of claim 6 , wherein the first analysis circuitry is part of a first analysis device and the second analysis circuitry is part of a second analysis device both included in the system and communicating to perform risk analysis of a distributed test object, wherein the system further comprises first and second interfaces for the respective first and second devices for communication with one another, wherein the first analysis circuitry and the second analysis circuitry are configured to use the first and second device interfaces to exchange information relating to an ascertained protection requirement.

10 . The system of claim 9 , wherein the transmission path of the datum for the ascertained protection requirement is used to perform further risk analysis while the ascertained protection requirement is to be taken into account.

11 . The system of claim 9 , wherein the ascertained protection requirement is taken into account by the first and second analysis circuitry stipulating a risk-mitigating measure in an automated manner or by manual intervention.

12 . The system of claim 9 , wherein each of the first and second analysis devices further comprise a controller configured to control operation of the first and second analysis circuitry.

13 . The system of claim 12 , wherein settings of the first and second analysis circuitry are changeable by the user interfaces or the controllers for the first and second analysis devices.