DIY перевірка безпеки

Статті, гайди й товари, позначені тегом «DIY перевірка безпеки» — об'єднаний перелік усіх матеріалів каталогу за цією темою.

Гайд користувача

Інженерія кібербезпеки електросамоката: ETSI EN 303 645 V3.2.0:2024-12 baseline (13 provisions для consumer IoT — no default password, vulnerability disclosure RFC 9116, secure update, secure storage, secure communication), ISO/SAE 21434:2021 road-vehicle cybersecurity engineering (TARA threat analysis + risk assessment), ISO/SAE 24089:2023 software update engineering, UNECE R155 CSMS (Cybersecurity Management System) обов'язковий для type-approval нових типів з 07-2022, UNECE R156 SUMS (Software Update Management System), EU Cyber Resilience Act 2024/2847 (Regulation 2024-10-23, applicability 2027-12-11 + reporting obligations 2026-09-11), NIST SP 800-193:2018 Platform Firmware Resilience Guidelines (Protection-Detection-Recovery RoT), NIST SP 800-183 IoT Networks of Things, IEC 62443-4-1/-4-2 secure product development lifecycle, Bluetooth Core 5.4 LE Secure Connections з ECDH P-256 (заміна Just Works як baseline), IEEE 802.11i WPA3-Personal SAE Dragonfly key exchange, RFC 9116 security.txt responsible-disclosure, attack surface (BLE pairing Just Works/Numeric Comparison/Passkey Entry/OOB, Bluetooth protocol attacks KNOB CVE-2019-9506 + BIAS CVE-2020-10135 + BLURtooth CVE-2020-15802 + BLESA CVE-2020-9770, firmware via JTAG/SWD/USB DFU, motor controller CAN bus, mobile app↔cloud TLS, OTA update channel signing, GPS spoofing, smart-battery BMS handshake, hardware UART debug eFuse), mitigation (LE Secure Connections ECDH P-256 + mutual TLS certificate pinning + secure boot signed bootloader + signed firmware AES-256 + anti-rollback monotonic counter + HSM/secure element ATECC608B/NXP A1006/SE050 + SBOM SPDX CycloneDX + RFC 9116 security.txt + Coordinated Vulnerability Disclosure ISO/IEC 29147:2018 + penetration testing ISTQB), incidents (Xiaomi M365 BLE anti-lock bypass 2019 Zimperium Rani Idan, Lime BLE replay attack 2019, Bird/Lime API IDOR 2020, Ninebot ES1/ES2/ES4 BLE pwd 888888 vulnerability, Tier/Voi unauthorized unlock 2022, hoverboard CVE catalogue 2018)

Інженерний deep-dive у кібербезпеку електросамоката як четверта cross-cutting infrastructure axis — паралельна до [інженерії різьбових з'єднань як joining-axis](@/guide/fastener-and-bolted-joint-engineering.md), [термоменеджменту як heat-dissipation axis](@/guide/thermal-management-engineering.md) і [EMC/EMI як interference-mitigation axis](@/guide/emc-emi-engineering.md). Покриває: 10-row standards matrix (ETSI EN 303 645 V3.2.0:2024-12 consumer IoT baseline, ISO/SAE 21434:2021 road-vehicle TARA, ISO/SAE 24089:2023 SW update engineering, UNECE R155 CSMS, UNECE R156 SUMS, EU CRA 2024/2847, NIST SP 800-193 firmware RoT, IEC 62443-4-1 secure SDLC, Bluetooth Core 5.4 LE Secure Connections, IEEE 802.11i WPA3-SAE); 7-row attack-surface matrix (BLE pairing методи + KNOB/BIAS/BLURtooth/BLESA + firmware JTAG/SWD/DFU + mobile↔cloud TLS + OTA signing + GPS spoofing + smart-battery handshake); 6-row mitigation matrix (LE Secure Connections + mutual TLS + secure boot + signed firmware + anti-rollback + HSM/SE); 6-row real-incident matrix (Xiaomi M365 2019 + Lime BLE 2019 + Bird IDOR 2020 + Ninebot pwd 888888 + Tier/Voi 2022 + hoverboard catalogue); 8-step DIY security check; 6-step DIY remediation; EU Cyber Resilience Act timeline (2024-12-10 entry into force, 2026-09-11 reporting obligations, 2027-12-11 full applicability); 16 нумерованих розділів.

17 хв читання

Гайд користувача

Функціональна безпека електросамоката: безпекова цілісність як шоста cross-cutting infrastructure axis — IEC 61508:2010 (E/E/PE безпеково-пов'язані системи, SIL 1-4) + ISO 26262:2018 (автомобільна FuSa, ASIL A-D) + ISO 13849-1:2023 (безпекові частини машин, PLr a-e, категорії B/1/2/3/4) + IEC 62061:2021 (SIL CL для машинних E/E/PES) + EN 17128:2020 Annex G (PLEV functional safety requirements) + IEC 60812:2018 FMEA + IEC 61025:2006 FTA + IEC 61709:2017 reliability data + MISRA C:2023 software safety subset + ISO/PAS 21448:2022 SOTIF + IEC 61511 process industry + IEC 60730-1:2024 controls + UL 991 + UL 1998 + DO-178C analogy

Інженерний deep-dive у функціональну безпеку електросамоката як шоста cross-cutting infrastructure axis — паралельна до [інженерії різьбових з'єднань як joining-axis](@/guide/fastener-and-bolted-joint-engineering.md), [термоменеджменту як heat-dissipation axis](@/guide/thermal-management-engineering.md), [EMC/EMI як interference-mitigation axis](@/guide/emc-emi-engineering.md), [кібербезпеки як interconnect-trust axis](@/guide/cybersecurity-engineering.md) та [NVH як acoustic-vibration-emission axis](@/guide/nvh-engineering.md). Покриває: 10-row standards matrix (IEC 61508, ISO 26262, ISO 13849-1, IEC 62061, EN 17128 Annex G, IEC 60812 FMEA, IEC 61025 FTA, IEC 61709, MISRA C, ISO/PAS 21448 SOTIF); SIL/ASIL/PL/SIL CL cross-mapping; 6-row hazard-by-subsystem matrix (motor controller throttle-stuck, brake actuator loss, throttle position drift, BMS thermal runaway, display HMI critical info, lighting fail-dark); FMEA worked example для BLE throttle injection scenario; FTA worked example для wheel lock at speed; FMEDA з PFD/PFH calculation, Safe Failure Fraction, Hardware Fault Tolerance; risk reduction equation R_residual = R_unmitigated × (1 - RRF); 6-row mitigation matrix; ALARP принцип; software safety V-model + MISRA C:2023 + formal methods; SOTIF (ISO/PAS 21448) як extension до IEC 61508; HIL testing + fault injection; 8-row real-incidents timeline (Lime brake recall 2019, Ninebot ES2 throttle creep 2020, Apollo Pro firmware bug, Boosted board fire, Bird scooter rear-wheel hub crack, Tier scooter motor-stuck); 8-step DIY safety check; 6-step DIY remediation; industry shift 2020→2026; 16 нумерованих розділів.

17 хв читання