This page was machine-translated and may differ from the original. View original

Connected Cars Require Cybersecurity

Google 우선 소스Published2022.02.24 14:14





28% of cyberattacks in 2021 will involve vehicles.
Semiconductor and automobile manufacturers are collaborating with standards agencies.

Connected cars are expected to grow significantly, accounting for 86% of the global automotive market by 2025, but connectivity across various networks is raising concerns that it could provide attack vectors for hackers.

On the 22nd, E4ds Webinar was held with Infineon's Manager Lee Kyung-soo on the topic of 'The Present and Future of Automotive Cybersecurity and Infineon's Response Plan.'

Connected cars are vulnerable to hacker attacks, including malware, data manipulation, and hardware-level physical attacks. These attacks can threaten the safety of vehicle drivers, lead to personal data loss, and even impact manufacturers' businesses.

Upstream's 2021 Automotive Cybersecurity Report outlines cybersecurity attacks that occurred in 2021.

Attacks targeting vehicle theft and internal control systems accounted for 28.4%, followed by data breaches (30%).

If the internal control system is hijacked, it can malfunction and cause injury to not only the driver but also other people, making it a very serious matter.

To prevent this, data is processed without external exposure.Safe data processing is required so that only data with a structure can be processed.

Additionally, as vehicle architecture evolves into △E/E architecture and △domain architecture, protection is also essential in areas that can be closely connected to the outside world and in gateways that lead communication.

Currently, many standards organizations and automobile and semiconductor manufacturers are collaborating to develop guidelines, standards, and regulations for automotive cybersecurity.

In 2009, the HIS working group included its work on how software should be implemented in the Secure Hardware Extension (SHE) Functional Specification.

The intention is to create a mechanism that can process security activities that were previously performed in software in the hardware domain quickly in real time, and the result includes the need to create a security domain within the MCU to take charge of security by performing the role previously performed by an external dedicated security IC.

SAE and ISO have collaborated to publish a single standard, ISO/SAE 21434: 2021 Road Vehicles – Cybersecurity engineering.

This standard is important because specific comments in various regulations refer to ISO/SAE 21434 for details.

When developing a vehicle system, it is important to consider the vehicle life cycle, including △how to design it △the pre- and post-development stages △the mass production stage △the disposal stage.

△Comprehensive content on how to manage security, △what functions to include, and △how to maintain and repair vulnerabilities when discovered has been compiled into a standard.

The reason this standard is important is that specific comments in various regulations are detailed in ISO/SAE 214Because I recommend you refer to 34.

△UNECE WP.29's UN R No.155 CSMS △No.156 SUMS are the first automotive cybersecurity regulations established in Europe.

CSMS is a regulation for the overall management system of the Cyber Security Management System, and vehicle manufacturers must obtain CSMS certification through an external certification agency.

Only certified vehicles can be sold in Europe, and the certification must be renewed every three years.

Vehicle Type Approval (TA) is an item that must be approved by vehicle type.

To sell a car in Europe, a manufacturer must obtain a type approval (TA) for each vehicle along with CSMS certification.

Adopted in June 2020 and effective in January 2021, all new types of vehicles developed from the effective date of July 2022 must be vehicles that have received TA.

The domestic cybersecurity guideline is the 'Automobile Cybersecurity Guideline' established by the Ministry of Land, Infrastructure and Transport in December 2020.

Based on the current UN Regulation No. 155, recommendations were first presented for matters likely to be established as domestic standards in the future.

It includes recommendations from manufacturers and the roles of security approval/testing agencies.

Infineon is actively engaged in various activities to address security issues, including various hacking threats, and provides cybersecurity solutions.

Infineon is a member of AUTO-ISAC and is actively sharing information about vehicle security incidents both online and offline.

The solution is to have an HSM hardware security module embedded within the MCU. There is a Aurix family of products.

Additionally, for applications requiring a higher level of security, an external security-only IC is provided to meet the requirements.

This product line includes OPTIGA TPM, SLI 97 V2X, etc.

When asked whether the country is adequately prepared for hacker threats, Manager Lee Kyung-soo stated, "I believe many automakers, standards organizations, and the national government are making significant efforts and preparing accordingly." He added, "There is no such thing as perfect security. New threats continually emerge, so analyzing, supplementing, maintaining, and managing them is crucial."
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
성유창 기자
성유창 기자