RIDI-Hypothesis: A Foundational Theory for Cybersecurity Risk Assessment in Cyber-Physical Systems

Ramakrishna Ramadugu · 2025

This paper introduces the RIDI-Hypothesis, a theoretical framework designed to address cybersecurity vulnerabilities within Cyber-Physical Systems (CPS). By examining the functional block that generates nonces, we identify potential weaknesses such as replace, insert, delete, and inject, which can compromise nonce freshness. We extend our analysis to broader security considerations, proposing two hypotheses: System Security Design, which defines a system by a unique specification, and System Insecurity Design, where non-unique designs quantitatively represent insecurity. Our methodology utilizes UML diagrams to construct ABF-graphs, representing system specifications as logical structures. Using the Z3 SMT solver, we identify all potential insecure configurations. We also introduce an open-source cybersecurity risk assessment tool that quantifies risks and suggests mitigations. A case study involving a water level reader sensor demonstrates our approach, highlighting 16,777,216 potential scenarios of specification divergence. Our findings underscore the importance of precise design processes in mitigating cybersecurity risks. Future work will focus on verification and test-case generation to further enhance system security.

Read the paper · More papers on PaperTik