인피니언 8월20일부터
This page was machine-translated and may differ from the original. View original

[Planning - Autonomous Vehicles⑧] Cybersecurity is the key to preventing autonomous vehicles from becoming "running weapons."

Google 우선 소스Published2017.07.17 06:33
Self-driving car security requires a "whitelist," not a "blacklist."
Hardware needs key management, software needs certificates, and physical security needs to be considered.


If there's one technology that best exemplifies the phrase "dreams become reality," it's the self-driving car. When summoned, it drives itself to its destination. Autonomous vehicles recognize and avoid obstacles while driving, providing owners with various conveniences and information. While the commercialization of fully autonomous vehicles will take some time, so-called "semi-autonomous vehicle" technology is steadily advancing. Advertisements for cars with autonomous driving capabilities are now commonplace, demonstrating their deep-seated presence in our lives. This magazine will present a series on self-driving cars over the next 11 installments. Beginning with trends in the autonomous vehicle industry, we'll explore semiconductor components like radar, lidar, and camera sensors, communications, precision mapping, software platforms, artificial intelligence, security, and K-City services. We ask for your continued support. <Editor's Note>

Photo source: Penta Security

To achieve autonomous driving technology level 4 or higher, which transfers control from the driver to the vehicle, more powerful security technology is required. This is because drivers must be confident that autonomous vehicles are safe even when exposed to threats such as vehicle system errors or hacker access.

Automotive semiconductor companies like Renesas, Infineon, NXP, and Maxim have already adopted hardware security modules (HSMs). HSMs support key management by centrally storing and encrypting keys for transmission.

HSM is a module that was stipulated by EVITA (E-safety Vehicle Intrusion ProTected Applications), which operated from 2008 to 2011, regarding the security of vulnerable ECUs as smart cars and connected cars developed. It is divided into three levels: level 1 security for ECUs, level 2 security for communication between ECUs in the vehicle, and level 3 security for external communication.

Toursec, a security company owned by Harman and acquired by Samsung last year, also released a solution that installs a software defense shield directly on the telecommunication control unit (TCU) that supports telemetrics.

Photo source: Penta Security

While vehicle ECU hacking is unprecedented, cybersecurity has already been compromised. While the Tesla S received an over-the-air (OTA) patch, Fiat Chrysler and GM were forced to issue recalls due to security threats.

NXP and Hyundai Mobis joined Auto-ISAC (Automotive Information Sharing and Analysis Center) in February of this year to strengthen cybersecurity. Bosch, LG Electronics, and Honeywell are members and active members of Auto-ISAC, a consultative body of automotive OEMs.

Computerization of automobiles, automotive security ultimately comes down to cybersecurity.

SAE J3061 is the internationally accepted standard for cybersecurity. While solutions vary by OEM and security vendor, among domestic companies, Penta Security offers a three-tiered security solution. These include: a firewall installed on the in-vehicle gateway, which identifies and blocks threats based on their appearance and attributes; a Key Management System (KMS) used for inter-ECU communication; and AutoCrypt, a certificate management technology (PKI) that ensures privacy while securing external communications.

In particular, autonomous vehicles raise serious privacy concerns because they "broadcast" their locations to the surrounding area while driving. This is prevented by using PKI certificates, which randomly generate 20 certificates every five minutes. These 20 certificates are rotated weekly, resulting in approximately 1,000 certificates used annually. This certificate management technology meets the U.S. CAMP VSC and SCMS (Security Credential Management System) standards. V2X communication security follows the global standard defined by IEEE1609.2.

■ Interview
Sim Sang-gyu, Ph.D. , Director of Penta Security's IoT Convergence Security Research Lab

"Complete security costs tens of millions of won, but the actual possible cost is a few thousand won…
"It will be built as a self-driving car security whitelist."

Q. If a vehicle company strengthens security at the ECU level and supports cybersecurity, can security be considered safe?

"Previously, we focused solely on locking doors. We need additional physical security. If we were to drill holes in unseen locations and install hacking systems into the vehicle network, we would be helpless.

If a gateway firewall is a technology that blocks security threats from entering the vehicle from external communications, it is necessary to consider security technologies that ensure internal communications are secure. For example, there are technologies that encrypt in-vehicle networks or detect unauthorized devices joining the network."

Q. How much security is needed to ensure safety?

"To meet both hardware and software security requirements for each vehicle, it would cost tens of millions of won per vehicle. The National Highway Traffic Safety Administration (NHTSA)'s NPRM document mandates V2X communication at a cost of $135 to $301 per vehicle, with security accounting for at most 10%. Unit costs are estimated at a few thousand won. Ultimately, it is expected that a whitelist-based security approach, allowing only protocols within a permitted list, will be widely adopted."

Q. To reduce the cost burden on drivers, wouldn't it be better to promote V2X infotainment and related industries to encourage corporate investment?

"The related industries utilizing V2X communication are endless. Many are already emerging. In foreign countries, secure storage is being promoted, which stores driver patterns and transmits them to online insurance companies to reduce insurance premiums. In addition, vehicle OEMs are considering the OTA method when releasing the initial first-generation products. V2X communication can be activated as a means to prevent recalls by checking for bugs in real time."

Q. How is the government promoting autonomous driving security?

Currently, automotive security is at the discretion of vehicle manufacturers. The Ministry of Land, Infrastructure and Transport is building smart roads, but it isn't involved in internal communications. Rather, the Ministry of Trade, Industry and Energy may intervene through manufacturers. Once smart roads are built, the government is expected to push for mandatory security measures when considering the vehicles that will drive on them.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
김자영 기자