μ½˜ν…μΈ λ‘œ 이동

Automotive Cybersecurity μš©μ–΄μ§‘

이 νŽ˜μ΄μ§€λŠ” Automotive Cybersecurity μ½”μŠ€μ˜ 핡심 μš©μ–΄ λͺ¨μŒμž…λ‹ˆλ‹€. 각 ν•­λͺ©μ€ ISO 11179 ν˜•μ‹(Definition / Source / Related / Example / See also)을 λ”°λ¦…λ‹ˆλ‹€.

검색 ν™œμš©

상단 검색창에 μš©μ–΄λ₯Ό μž…λ ₯ν•˜λ©΄ λ³Έλ¬Έμ—μ„œμ˜ μ‚¬μš©μ²˜λ„ ν•¨κ»˜ 찾을 수 μžˆμŠ΅λ‹ˆλ‹€.


A

AUTOSAR

  • Definition. μ°¨λŸ‰ ECU μ†Œν”„νŠΈμ›¨μ–΄ μ•„ν‚€ν…μ²˜ ν‘œμ€€μœΌλ‘œ, Classic Platform(MCU 기반 μ‹€μ‹œκ°„)κ³Ό Adaptive Platform(POSIX 기반 κ³ μ„±λŠ₯) 두 갈래의 사양을 μ •μ˜ν•œλ‹€.
  • Source. AUTOSAR Consortium specification.
  • Related. Classic Platform, Adaptive Platform, SecOC, BSW.
  • Example. Classic AUTOSAR 의 SecOC λͺ¨λ“ˆμ€ CAN λ©”μ‹œμ§€μ— MAC 을 λΆ€μ°©ν•˜μ—¬ μΈμ¦ν•œλ‹€.
  • See also. Module 02 β€” Automotive SoC Security.

C

CAN (Controller Area Network)

  • Definition. μ°¨λŸ‰ ECU κ°„ 톡신을 μœ„ν•΄ μ„€κ³„λœ λ©€ν‹°λ§ˆμŠ€ν„° 직렬 λΈŒλ‘œλ“œμΊμŠ€νŠΈ λ²„μŠ€λ‘œ, 11/29-bit ID 기반 λΉ„νŒŒκ΄΄μ  μš°μ„ μˆœμœ„ μ€‘μž¬(arbitration) 방식을 μ‚¬μš©ν•œλ‹€.
  • Source. ISO 11898-1.
  • Related. Arbitration, OBD-II, CAN-FD.
  • Example. ID 0x100 λ©”μ‹œμ§€κ°€ ID 0x200 보닀 μš°μ„ ν•˜μ—¬ λ²„μŠ€ 점유.
  • See also. Module 01 β€” CAN Bus Fundamentals.

CAN-FD

  • Definition. CAN 의 ν™•μž₯ ν”„λ‘œν† μ½œλ‘œ, 데이터 νŽ˜μ΄λ‘œλ“œλ₯Ό μ΅œλŒ€ 64λ°”μ΄νŠΈλ‘œ 늘리고 데이터 phase 의 λΉ„νŠΈλ ˆμ΄νŠΈλ₯Ό 더 λ†’κ²Œ μ„€μ •ν•  수 있게 ν•œ 것.
  • Source. ISO 11898-1:2015.
  • Related. CAN, SecOC, MAC truncation.
  • Example. 64λ°”μ΄νŠΈ payload 덕에 16λ°”μ΄νŠΈ MAC 을 동봉할 μ—¬μœ κ°€ 생긴닀.
  • See also. Module 01, Module 02.

CSMS (Cyber Security Management System)

  • Definition. UN R155 κ°€ OEM 에 μš”κ΅¬ν•˜λŠ” 쑰직 μ°¨μ›μ˜ μ‚¬μ΄λ²„λ³΄μ•ˆ 관리 μ²΄κ³„λ‘œ, μœ„ν—˜ μ‹λ³„Β·ν†΅μ œΒ·λͺ¨λ‹ˆν„°λ§Β·μ‚¬κ³  λŒ€μ‘μ˜ 라이프사이클을 μ •μ˜ν•œλ‹€.
  • Source. UN ECE R155.
  • Related. SUMS, TARA, ISO/SAE 21434.
  • Example. OEM 은 CSMS 인증을 λ°›μ•„μ•Ό μ‹ μ°¨ ν˜•μ‹ μŠΉμΈμ„ 받을 수 μžˆλ‹€.
  • See also. Module 04.

D

Defense in Depth

  • Definition. 단일 λ³΄μ•ˆ ν†΅μ œμ— μ˜μ‘΄ν•˜μ§€ μ•Šκ³  μ—¬λŸ¬ 독립적 계측(물리·톡신·OSΒ·μ•±Β·ν΄λΌμš°λ“œ) 의 ν†΅μ œκ°€ 직렬둜 μž‘μš©ν•˜λ„λ‘ μ„€κ³„ν•˜λŠ” λ³΄μ•ˆ 원칙.
  • Source. Common security architecture principle.
  • Related. Layered Security, Threat Modeling.
  • Example. Secure Boot(L1) β†’ SecOC(L2) β†’ Gateway(L3) β†’ IDS(L4) 의 4계측 μŠ€νƒ.
  • See also. Module 04.

F

Freshness Value

  • Definition. SecOC λ©”μ‹œμ§€μ— ν¬ν•¨λ˜λŠ” 단쑰 증가 μΉ΄μš΄ν„°/νƒ€μž„μŠ€νƒ¬ν”„λ‘œ, λ™μΌν•œ λ©”μ‹œμ§€μ˜ μž¬μ „μ†‘(replay) 을 μˆ˜μ‹ μΈ‘μ΄ κ±°λΆ€ν•  수 있게 ν•΄ μ£ΌλŠ” κ°’.
  • Source. AUTOSAR SecOC specification.
  • Related. SecOC, MAC, Replay Attack.
  • Example. μΉ΄μš΄ν„°κ°€ 이전 값보닀 μž‘κ±°λ‚˜ 같은 λ©”μ‹œμ§€λŠ” 폐기.
  • See also. Module 02.

H

HSM (Hardware Security Module)

  • Definition. ν‚€ 생성·저μž₯Β·μ•”ν˜Έ 연산을 μœ„ν•΄ 메인 CPU 와 격리된 λ³΄μ•ˆ μ½”ν”„λ‘œμ„Έμ„œλ‘œ, ν‚€κ°€ 평문 μƒνƒœλ‘œ 외뢀에 λ…ΈμΆœλ˜μ§€ μ•Šλ„λ‘ ν•˜λ“œμ›¨μ–΄λ‘œ λ³΄ν˜Έν•œλ‹€.
  • Source. EVITA / SHE specifications.
  • Related. Root of Trust, Secure Boot, SecOC.
  • Example. SecOC MAC 연산은 HSM λ‚΄λΆ€μ—μ„œ μˆ˜ν–‰λ˜μ–΄ μ„Έμ…˜ ν‚€κ°€ μ™ΈλΆ€λ‘œ λ‚˜κ°€μ§€ μ•ŠλŠ”λ‹€.
  • See also. Module 02.

I

IDS (Intrusion Detection System) β€” Automotive

  • Definition. μ°¨λŸ‰ λ„€νŠΈμ›Œν¬μ˜ νŠΈλž˜ν”½ νŒ¨ν„΄μ„ λͺ¨λ‹ˆν„°λ§ν•˜μ—¬ μ‹œκ·Έλ‹ˆμ²˜ λ˜λŠ” ML λͺ¨λΈλ‘œ 비정상 λ©”μ‹œμ§€λ₯Ό νƒμ§€ν•˜λŠ” μ‹œμŠ€ν…œ.
  • Source. Common automotive security architecture.
  • Related. SecOC, Gateway, V-SOC.
  • Example. 정상 μ£ΌκΈ° 100ms 인 λ©”μ‹œμ§€κ°€ κ°‘μžκΈ° 1ms 주기둜 λ°œμƒ β†’ 이상 탐지.
  • See also. Module 02, Module 04.

ISO/SAE 21434

  • Definition. μ°¨λŸ‰ μ‚¬μ΄λ²„λ³΄μ•ˆ μ—”μ§€λ‹ˆμ–΄λ§ 라이프사이클을 μ •μ˜ν•˜λŠ” ꡭ제 ν‘œμ€€μœΌλ‘œ, TARA(Threat Analysis & Risk Assessment) λ₯Ό 핡심 ν™œλ™μœΌλ‘œ μš”κ΅¬ν•œλ‹€.
  • Source. ISO/SAE 21434:2021.
  • Related. TARA, UN R155, CSMS.
  • Example. μ½˜μ…‰νŠΈ 단계 TARA β†’ 개발 단계 λ³΄μ•ˆ μš”κ΅¬μ‚¬ν•­ β†’ 검증 단계 침투 ν…ŒμŠ€νŠΈ.
  • See also. Module 04.

M

MAC (Message Authentication Code)

  • Definition. λ©”μ‹œμ§€μ˜ 무결성과 λ°œμ‹ μž 인증을 λ™μ‹œμ— 보μž₯ν•˜κΈ° μœ„ν•΄ 곡유 킀와 λ©”μ‹œμ§€λ‘œλΆ€ν„° κ³„μ‚°λ˜λŠ” 짧은 κ³ μ • 길이의 검증값.
  • Source. Common cryptography (HMAC, CMAC λ“±).
  • Related. SecOC, Freshness Value, HMAC, AES-CMAC.
  • Example. SecOC λŠ” truncated CMAC 24~64bit λ₯Ό CAN λ©”μ‹œμ§€μ— 첨뢀.
  • See also. Module 02.

O

OBD-II

  • Definition. 1996 λ…„ λ―Έκ΅­μ—μ„œ μ˜λ¬΄ν™”λœ μ°¨λŸ‰ 진단 ν‘œμ€€ 컀λ„₯ν„°/ν”„λ‘œν† μ½œλ‘œ, μ°¨λŸ‰ λ‚΄λΆ€ CAN λ²„μŠ€μ— 직접 μ ‘κ·Όν•  수 μžˆλŠ” μ™ΈλΆ€ 포트λ₯Ό μ œκ³΅ν•œλ‹€.
  • Source. SAE J1962, ISO 15765.
  • Related. CAN, Diagnostic, Attack Surface.
  • Example. OBD-II 동글을 톡해 μ™ΈλΆ€ κ³΅κ²©μžκ°€ CAN λ©”μ‹œμ§€λ₯Ό μ£Όμž….
  • See also. Module 01, Module 04.

R

Replay Attack

  • Definition. μ •μƒμ μœΌλ‘œ λ°œμƒν–ˆλ˜ 인증된 λ©”μ‹œμ§€λ₯Ό μΊ‘μ²˜ν•˜μ—¬ 후일 μž¬μ „μ†‘ν•¨μœΌλ‘œμ¨ μ‹œμŠ€ν…œμ„ 잘λͺ»λœ μƒνƒœλ‘œ μœ λ„ν•˜λŠ” 곡격.
  • Source. Common security taxonomy.
  • Related. Freshness Value, MAC, SecOC.
  • Example. "도어 잠금 ν•΄μ œ" λ©”μ‹œμ§€λ₯Ό λ…ΉμŒ ν›„ μž¬μ „μ†‘ν•˜μ—¬ μ°¨λŸ‰μ„ λ‹€μ‹œ μ—°λ‹€.
  • See also. Module 02.

Root of Trust (RoT)

  • Definition. μ‹œμŠ€ν…œ λ³΄μ•ˆμ˜ λͺ¨λ“  μ‹ λ’° μ‚¬μŠ¬μ΄ μ‹œμž‘λ˜λŠ” λ³€κ²½ λΆˆκ°€λŠ₯ν•œ ν•˜λ“œμ›¨μ–΄ κ΅¬μ„±μš”μ†Œλ‘œ, 일반적으둜 ROM μ½”λ“œ + HSM 의 λ΄‰μΈλœ ν‚€λ‘œ κ΅¬ν˜„λœλ‹€.
  • Source. TCG Root of Trust definitions.
  • Related. Secure Boot, HSM, Attestation.
  • Example. OTP 에 λ΄‰μΈλœ OEM κ³΅κ°œν‚€ ν•΄μ‹œκ°€ λΆ€νŒ… κ²€μ¦μ˜ μ‹œμž‘μ .
  • See also. Module 02.

S

Secure Boot

  • Definition. λΆ€νŒ… μ‹œ 각 λ‹¨κ³„μ˜ νŽŒμ›¨μ–΄/이미지λ₯Ό λ‹€μŒ 단계가 μ‹œμž‘λ˜κΈ° 전에 λ””μ§€ν„Έ μ„œλͺ…μœΌλ‘œ κ²€μ¦ν•˜μ—¬, λ³€μ‘°λœ μ½”λ“œκ°€ μ‹€ν–‰λ˜μ§€ μ•Šλ„λ‘ 보μž₯ν•˜λŠ” λ©”μ»€λ‹ˆμ¦˜.
  • Source. TCG / EVITA / NIST SP 800-193.
  • Related. Root of Trust, HSM, Chain of Trust.
  • Example. ROM β†’ BL1 β†’ BL2 β†’ BL3 λ‹¨κ³„λ§ˆλ‹€ μ„œλͺ… 검증, μ‹€νŒ¨ μ‹œ boot halt.
  • See also. Module 02.

Secure Gateway

  • Definition. μ°¨λŸ‰ λ‚΄λΆ€μ˜ 도메인(Powertrain/Chassis/Body/Infotainment) μ‚¬μ΄μ—μ„œ λ©”μ‹œμ§€ λΌμš°νŒ…, ν™”μ΄νŠΈλ¦¬μŠ€νŠΈ 필터링, 레이트 λ¦¬λ―ΈνŒ…μ„ μˆ˜ν–‰ν•˜λŠ” 쀑앙 ECU.
  • Source. Common automotive E/E architecture.
  • Related. Domain Isolation, IDS, OBD-II Gateway.
  • Example. Infotainment λ„λ©”μΈμ—μ„œ Powertrain λ„λ©”μΈμœΌλ‘œμ˜ λΉ„ν—ˆμš© λ©”μ‹œμ§€λ₯Ό drop.
  • See also. Module 02.

SecOC (Secure Onboard Communication)

  • Definition. AUTOSAR κ°€ μ •μ˜ν•œ μ°¨λŸ‰ λ‚΄λΆ€ 톡신 λ³΄μ•ˆ λͺ¨λ“ˆλ‘œ, λ©”μ‹œμ§€μ— truncated MAC κ³Ό Freshness Value λ₯Ό λΆ€μ°©ν•˜μ—¬ 인증과 replay λ°©μ–΄λ₯Ό μ œκ³΅ν•œλ‹€.
  • Source. AUTOSAR SecOC specification.
  • Related. MAC, Freshness Value, HSM.
  • Example. 16λ°”μ΄νŠΈ payload 쀑 4λ°”μ΄νŠΈλ₯Ό truncated MAC 으둜 μ‚¬μš©.
  • See also. Module 02.

SUMS (Software Update Management System)

  • Definition. UN R156 이 μš”κ΅¬ν•˜λŠ” μ°¨λŸ‰ μ†Œν”„νŠΈμ›¨μ–΄ μ—…λ°μ΄νŠΈ 라이프사이클 관리 μ²΄κ³„λ‘œ, OTA νŒ¨ν‚€μ§€μ˜ λ¬΄κ²°μ„±Β·λ‘€λ°±Β·μ°¨λŸ‰λ³„ 적합성을 κ΄€λ¦¬ν•œλ‹€.
  • Source. UN ECE R156.
  • Related. OTA, CSMS, Code Signing.
  • Example. μ—…λ°μ΄νŠΈ νŒ¨ν‚€μ§€κ°€ μ°¨λŸ‰ VIN 기반 정책에 λ§žμ„ λ•Œλ§Œ 적용.
  • See also. Module 04.

Sybil Attack

  • Definition. ν•œ κ³΅κ²©μžκ°€ λ‹€μˆ˜μ˜ κ°€μ§œ 신원(λ…Έλ“œ) 을 λ§Œλ“€μ–΄ λ‹€λŒ€λ‹€ μ‹œμŠ€ν…œ(예: V2X) 의 μ‹ λ’° λͺ¨λΈμ„ μ™œκ³‘ν•˜λŠ” 곡격.
  • Source. Common distributed systems security taxonomy.
  • Related. V2X, Pseudonym Certificate, Misbehavior Detection.
  • Example. ν•œ μ°¨λŸ‰μ΄ 20개의 κ°€μ§œ μ°¨λŸ‰μœΌλ‘œ μœ„μž₯ν•˜μ—¬ κ°€μ§œ 정체 정보 broadcast.
  • See also. Module 04.

T

TARA (Threat Analysis & Risk Assessment)

  • Definition. ISO/SAE 21434 κ°€ μš”κ΅¬ν•˜λŠ” ν™œλ™μœΌλ‘œ, μžμ‚° 식별 β†’ μœ„ν˜‘ μ‹œλ‚˜λ¦¬μ˜€ β†’ 영ν–₯/μ‹€ν˜„κ°€λŠ₯μ„± 평가 β†’ μœ„ν—˜ λ“±κΈ‰ μ‚°μ • β†’ 처리 λ°©μ•ˆ κ²°μ •μ˜ 절차.
  • Source. ISO/SAE 21434:2021.
  • Related. STRIDE, Attack Tree, Threat Modeling.
  • Example. "OBD-II 포트λ₯Ό ν†΅ν•œ CAN λ©”μ‹œμ§€ μ£Όμž…" μœ„ν˜‘μ— λŒ€ν•΄ 영ν–₯=High/μ‹€ν˜„κ°€λŠ₯μ„±=Medium β†’ Risk=Medium.
  • See also. Module 04.

U

UN R155 / R156

  • Definition. UNECE κ°€ μ •μ˜ν•œ μ°¨λŸ‰ μ‚¬μ΄λ²„λ³΄μ•ˆ(R155) 및 SW μ—…λ°μ΄νŠΈ(R156) ν˜•μ‹ 승인 규제둜, 2024 λ…„λΆ€ν„° μ‹ μ°¨ μΆœμ‹œμ— 사싀상 ν•„μˆ˜ μš”κ±΄μ΄ λœλ‹€.
  • Source. UNECE WP.29.
  • Related. CSMS, SUMS, ISO/SAE 21434.
  • Example. R155 인증 μ—†μ΄λŠ” EU μ‹œμž₯ μ‹ μ°¨ 등둝 λΆˆκ°€.
  • See also. Module 04.

V

V2X (Vehicle-to-Everything)

  • Definition. μ°¨λŸ‰κ³Ό λ‹€λ₯Έ μ°¨λŸ‰(V2V), 인프라(V2I), λ³΄ν–‰μž(V2P), λ„€νŠΈμ›Œν¬(V2N) κ°„μ˜ 무선 톡신을 ν†΅μΉ­ν•˜λŠ” μš©μ–΄λ‘œ, DSRC λ˜λŠ” C-V2X κΈ°μˆ μ„ μ‚¬μš©ν•œλ‹€.
  • Source. SAE J2945, ETSI ITS-G5.
  • Related. SCMS, Pseudonym Certificate, Misbehavior Detection.
  • Example. ꡐ차둜 μ§„μž… μ°¨λŸ‰μ΄ BSM 으둜 주변에 μœ„μΉ˜/속도 broadcast.
  • See also. Module 04.