This page was machine-translated and may differ from the original. View original

[Interview] Lee Kyung-soo, Manager at Infineon: "AURIX™ Automotive Security: Safe and Rapid Implementation"

Google 우선 소스Published2022.01.24 14:53

AURIX™ Vehicle Security: Safe and Fast Implementation

Equipped with HSM, independent safety protection for all operations
Secure Debug, ECU debugger safety protection

[Editor's Note] With the advent of autonomous driving and electric vehicles, over-the-air (OTA) software updates for automotive software are emerging as a key trend. Accordingly, 54 countries, including the US and the EU, have mandated automotive cybersecurity, and South Korea has also discussed and finalized guidelines for establishing a certification management system and a cybersecurity system for autonomous vehicles. Consequently, in-vehicle cybersecurity has gone beyond a trend to a necessity, and fierce competition to dominate the market is expected in the future. In the midst of this, we met with Manager Lee Kyeong-su of Infineon Korea, a global company supporting a variety of security product groups applicable to automotive and industrial IoT applications, to hear about the automotive cybersecurity solutions provided by Infineon.


▲Lee Gyeong-su, Manager of Infineon


I'm curious about why cybersecurity threats to automobiles are on the rise. Could you also explain the types of automotive cyberattacks?

As automobiles gradually evolve into connected cars, new businesses utilizing automobiles are emerging. Accordingly, new valuable information is being stored in cars.

For example, automobiles are prime targets for hackers because they contain drivers' personal information, payment information, and automakers' software-related intellectual property, and cybersecurity threats to automobiles that seek to exploit this information are increasing.

Automotive cyberattacks can be divided into passive attacks and active attacks.

Passive attacks include intercepting and eavesdropping on data in communication, through which the identity of the sender and receiver, and the time and cycle of communication can be observed.

This can be seen as an attack on trustworthiness because it is an illegal method of access by an unauthorized person.

Active attacks go beyond illegal access and can cause system malfunctions and degrade performance by altering, forging, and retransmitting data intercepted in communication.

In other words, it is an attack method that can destroy the system in the way the hacker wants.

■ Self-driving cars are known to be more exposed to cybersecurity threats. I wonder why that is.

Implementing autonomous vehicles fundamentally requires interconnection with external infrastructure and numerous communication networks.

While this increases the convenience of being able to access your vehicle from anywhere, it also increases its vulnerability as these communication points can become easy attack vectors for hackers.

Additionally, self-driving cars are a collection of cutting-edge technologies, making them attractive targets for hackers and a means of demonstrating their hacking capabilities. there is.

■ I am curious about how to strengthen the cyber security of automobiles.

There are generally ways to strengthen hardware, software, and automotive systems, but in my personal opinion, I think the most fundamental and effective way is to change the perception of developers and manufacturers, that is, people working in the automotive industry.

While significant efforts are being made to develop various standards, regulations, and guidelines across the automotive industry, security awareness in the field still needs improvement.

I believe that raising awareness is of utmost importance, as most security threats ultimately originate from people, most frequently and fatally.

■ Infineon's automotive MCU product, AURIX™, supports an integrated security module, HSM (Hardware Security Module), and is known to be used for cryptographic operations to implement secure data storage and security functions. Please introduce AURIX™.

AURIX™, Infineon's automotive microcontroller (MCU) product line, offers outstanding performance and a wide range of functions that can be used in any system throughout the vehicle.

Among them, it is equipped with a Hardware Security Module (HSM) that provides hardware functions to strengthen the security of the automobile system.

A HSM can be viewed as a small MCU embedded within the automotive MCU that is dedicated to security.

The functions of HSM include supporting cryptographic operations such as symmetric key-based algorithms, asymmetric key-based algorithms, and hash algorithms that generate encrypted values without a key, and also supporting the function of generating random numbers using external noise.

Since the operations of these HSMs are performed through dedicated cores, dedicated memory, and dedicated RAM in a securely protected area within the MCU, all operations are performed independently and securely in an environment.

■ I would like to hear about real-world application cases using AURIX™.

Representative examples of practical cybersecurity features utilizing AURIX™ include Secure Boot, Secure Communication, and Secure Debug.

Secure Boot is a function that verifies the integrity of the software before the vehicle system software runs.

This allows us to verify the authenticity of the software and ensure that it operates correctly as designed before actual operation.

In case of Secure Communication, it is safe between the sender and receiver. A security feature that can be applied to communication systems to enable data exchange.

For example, when transmitting data, the data and its corresponding MAC (Message Authentication Code) value are transmitted together, and the receiver calculates the MAC using the transmitted data.

It can be implemented as a method to check for falsification of data by verifying that the calculated MAC is identical to the MAC transmitted through communication.

For Secure Debug, this is a function that safely protects the debugger interface of the vehicle ECU.

Because the debugger interface is a critical part of analyzing and updating the system's software, it must be protected to prevent unauthorized access.

In general, when accessing in a password-based format, if the password matches, access is temporarily permitted, and if the password does not match, access is blocked.

■ I understand that countries around the world have already enacted laws to strengthen automotive cybersecurity, and that Korea has also announced guidelines. I wonder if Infineon's AURIX™ complies with these regulations and national guidelines.

To comply with cybersecurity-related laws and domestic guidelines, automobile and automotive system manufacturers must continuously maintain and manage automotive cybersecurity.

Training and securing security personnel, establishing processes, applying security features, managing vulnerabilities in security features, and establishing follow-up measures when vulnerabilities are discovered must all be considered from a holistic perspective throughout the entire process of automobile design, development, mass production, and post-mass production.

Infineon's AURIX™ enables automotive manufacturers to implement security features in vehicle systems quickly and easily in a more secure environment.

■ Lastly, please say a word to the readers.

The webinar, "The Present and Future of Automotive Cybersecurity and Infineon's Response," to be held on February 22nd, will cover the current state and future of automotive cybersecurity, as well as Infineon's powerful security solutions and practical application cases.

We have prepared diligently to provide practical assistance in the field, so please participate actively.

thank you
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
배종인 기자
배종인 기자