Automotive Cybersecurity μ©μ΄μ§¶
μ΄ νμ΄μ§λ Automotive Cybersecurity μ½μ€μ ν΅μ¬ μ©μ΄ λͺ¨μμ λλ€. κ° νλͺ©μ ISO 11179 νμ(Definition / Source / Related / Example / See also)μ λ°λ¦ λλ€.
κ²μ νμ©
μλ¨ κ²μμ°½μ μ©μ΄λ₯Ό μ λ ₯νλ©΄ λ³Έλ¬Έμμμ μ¬μ©μ²λ ν¨κ» μ°Ύμ μ μμ΅λλ€.
A¶
AUTOSAR¶
- Definition. μ°¨λ ECU μννΈμ¨μ΄ μν€ν μ² νμ€μΌλ‘, Classic Platform(MCU κΈ°λ° μ€μκ°)κ³Ό Adaptive Platform(POSIX κΈ°λ° κ³ μ±λ₯) λ κ°λμ μ¬μμ μ μνλ€.
- Source. AUTOSAR Consortium specification.
- Related. Classic Platform, Adaptive Platform, SecOC, BSW.
- Example. Classic AUTOSAR μ SecOC λͺ¨λμ CAN λ©μμ§μ MAC μ λΆμ°©νμ¬ μΈμ¦νλ€.
- See also. Module 02 β Automotive SoC Security.
C¶
CAN (Controller Area Network)¶
- Definition. μ°¨λ ECU κ° ν΅μ μ μν΄ μ€κ³λ λ©ν°λ§μ€ν° μ§λ ¬ λΈλ‘λμΊμ€νΈ λ²μ€λ‘, 11/29-bit ID κΈ°λ° λΉνκ΄΄μ μ°μ μμ μ€μ¬(arbitration) λ°©μμ μ¬μ©νλ€.
- Source. ISO 11898-1.
- Related. Arbitration, OBD-II, CAN-FD.
- Example. ID 0x100 λ©μμ§κ° ID 0x200 λ³΄λ€ μ°μ νμ¬ λ²μ€ μ μ .
- See also. Module 01 β CAN Bus Fundamentals.
CAN-FD¶
- Definition. CAN μ νμ₯ νλ‘ν μ½λ‘, λ°μ΄ν° νμ΄λ‘λλ₯Ό μ΅λ 64λ°μ΄νΈλ‘ λλ¦¬κ³ λ°μ΄ν° phase μ λΉνΈλ μ΄νΈλ₯Ό λ λκ² μ€μ ν μ μκ² ν κ².
- Source. ISO 11898-1:2015.
- Related. CAN, SecOC, MAC truncation.
- Example. 64λ°μ΄νΈ payload λμ 16λ°μ΄νΈ MAC μ λλ΄ν μ¬μ κ° μκΈ΄λ€.
- See also. Module 01, Module 02.
CSMS (Cyber Security Management System)¶
- Definition. UN R155 κ° OEM μ μꡬνλ μ‘°μ§ μ°¨μμ μ¬μ΄λ²λ³΄μ κ΄λ¦¬ 체κ³λ‘, μν μλ³Β·ν΅μ Β·λͺ¨λν°λ§Β·μ¬κ³ λμμ λΌμ΄νμ¬μ΄ν΄μ μ μνλ€.
- Source. UN ECE R155.
- Related. SUMS, TARA, ISO/SAE 21434.
- Example. OEM μ CSMS μΈμ¦μ λ°μμΌ μ μ°¨ νμ μΉμΈμ λ°μ μ μλ€.
- See also. Module 04.
D¶
Defense in Depth¶
- Definition. λ¨μΌ 보μ ν΅μ μ μμ‘΄νμ§ μκ³ μ¬λ¬ λ 립μ κ³μΈ΅(물리·ν΅μ Β·OSΒ·μ±Β·ν΄λΌμ°λ) μ ν΅μ κ° μ§λ ¬λ‘ μμ©νλλ‘ μ€κ³νλ 보μ μμΉ.
- Source. Common security architecture principle.
- Related. Layered Security, Threat Modeling.
- Example. Secure Boot(L1) β SecOC(L2) β Gateway(L3) β IDS(L4) μ 4κ³μΈ΅ μ€ν.
- See also. Module 04.
F¶
Freshness Value¶
- Definition. SecOC λ©μμ§μ ν¬ν¨λλ λ¨μ‘° μ¦κ° μΉ΄μ΄ν°/νμμ€ν¬νλ‘, λμΌν λ©μμ§μ μ¬μ μ‘(replay) μ μμ μΈ‘μ΄ κ±°λΆν μ μκ² ν΄ μ£Όλ κ°.
- Source. AUTOSAR SecOC specification.
- Related. SecOC, MAC, Replay Attack.
- Example. μΉ΄μ΄ν°κ° μ΄μ κ°λ³΄λ€ μκ±°λ κ°μ λ©μμ§λ νκΈ°.
- See also. Module 02.
H¶
HSM (Hardware Security Module)¶
- Definition. ν€ μμ±Β·μ μ₯Β·μνΈ μ°μ°μ μν΄ λ©μΈ CPU μ 격리λ 보μ μ½νλ‘μΈμλ‘, ν€κ° νλ¬Έ μνλ‘ μΈλΆμ λ ΈμΆλμ§ μλλ‘ νλμ¨μ΄λ‘ 보νΈνλ€.
- Source. EVITA / SHE specifications.
- Related. Root of Trust, Secure Boot, SecOC.
- Example. SecOC MAC μ°μ°μ HSM λ΄λΆμμ μνλμ΄ μΈμ ν€κ° μΈλΆλ‘ λκ°μ§ μλλ€.
- See also. Module 02.
I¶
IDS (Intrusion Detection System) β Automotive¶
- Definition. μ°¨λ λ€νΈμν¬μ νΈλν½ ν¨ν΄μ λͺ¨λν°λ§νμ¬ μκ·Έλμ² λλ ML λͺ¨λΈλ‘ λΉμ μ λ©μμ§λ₯Ό νμ§νλ μμ€ν .
- Source. Common automotive security architecture.
- Related. SecOC, Gateway, V-SOC.
- Example. μ μ μ£ΌκΈ° 100ms μΈ λ©μμ§κ° κ°μκΈ° 1ms μ£ΌκΈ°λ‘ λ°μ β μ΄μ νμ§.
- See also. Module 02, Module 04.
ISO/SAE 21434¶
- Definition. μ°¨λ μ¬μ΄λ²λ³΄μ μμ§λμ΄λ§ λΌμ΄νμ¬μ΄ν΄μ μ μνλ κ΅μ νμ€μΌλ‘, TARA(Threat Analysis & Risk Assessment) λ₯Ό ν΅μ¬ νλμΌλ‘ μꡬνλ€.
- Source. ISO/SAE 21434:2021.
- Related. TARA, UN R155, CSMS.
- Example. μ½μ νΈ λ¨κ³ TARA β κ°λ° λ¨κ³ 보μ μꡬμ¬ν β κ²μ¦ λ¨κ³ μΉ¨ν¬ ν μ€νΈ.
- See also. Module 04.
M¶
MAC (Message Authentication Code)¶
- Definition. λ©μμ§μ 무결μ±κ³Ό λ°μ μ μΈμ¦μ λμμ 보μ₯νκΈ° μν΄ κ³΅μ ν€μ λ©μμ§λ‘λΆν° κ³μ°λλ μ§§μ κ³ μ κΈΈμ΄μ κ²μ¦κ°.
- Source. Common cryptography (HMAC, CMAC λ±).
- Related. SecOC, Freshness Value, HMAC, AES-CMAC.
- Example. SecOC λ truncated CMAC 24~64bit λ₯Ό CAN λ©μμ§μ 첨λΆ.
- See also. Module 02.
O¶
OBD-II¶
- Definition. 1996 λ λ―Έκ΅μμ μ무νλ μ°¨λ μ§λ¨ νμ€ μ»€λ₯ν°/νλ‘ν μ½λ‘, μ°¨λ λ΄λΆ CAN λ²μ€μ μ§μ μ κ·Όν μ μλ μΈλΆ ν¬νΈλ₯Ό μ 곡νλ€.
- Source. SAE J1962, ISO 15765.
- Related. CAN, Diagnostic, Attack Surface.
- Example. OBD-II λκΈμ ν΅ν΄ μΈλΆ 곡격μκ° CAN λ©μμ§λ₯Ό μ£Όμ .
- See also. Module 01, Module 04.
R¶
Replay Attack¶
- Definition. μ μμ μΌλ‘ λ°μνλ μΈμ¦λ λ©μμ§λ₯Ό μΊ‘μ²νμ¬ νμΌ μ¬μ μ‘ν¨μΌλ‘μ¨ μμ€ν μ μλͺ»λ μνλ‘ μ λνλ 곡격.
- Source. Common security taxonomy.
- Related. Freshness Value, MAC, SecOC.
- Example. "λμ΄ μ κΈ ν΄μ " λ©μμ§λ₯Ό λ Ήμ ν μ¬μ μ‘νμ¬ μ°¨λμ λ€μ μ°λ€.
- See also. Module 02.
Root of Trust (RoT)¶
- Definition. μμ€ν 보μμ λͺ¨λ μ λ’° μ¬μ¬μ΄ μμλλ λ³κ²½ λΆκ°λ₯ν νλμ¨μ΄ ꡬμ±μμλ‘, μΌλ°μ μΌλ‘ ROM μ½λ + HSM μ λ΄μΈλ ν€λ‘ ꡬνλλ€.
- Source. TCG Root of Trust definitions.
- Related. Secure Boot, HSM, Attestation.
- Example. OTP μ λ΄μΈλ OEM 곡κ°ν€ ν΄μκ° λΆν κ²μ¦μ μμμ .
- See also. Module 02.
S¶
Secure Boot¶
- Definition. λΆν μ κ° λ¨κ³μ νμ¨μ΄/μ΄λ―Έμ§λ₯Ό λ€μ λ¨κ³κ° μμλκΈ° μ μ λμ§νΈ μλͺ μΌλ‘ κ²μ¦νμ¬, λ³μ‘°λ μ½λκ° μ€νλμ§ μλλ‘ λ³΄μ₯νλ λ©μ»€λμ¦.
- Source. TCG / EVITA / NIST SP 800-193.
- Related. Root of Trust, HSM, Chain of Trust.
- Example. ROM β BL1 β BL2 β BL3 λ¨κ³λ§λ€ μλͺ κ²μ¦, μ€ν¨ μ boot halt.
- See also. Module 02.
Secure Gateway¶
- Definition. μ°¨λ λ΄λΆμ λλ©μΈ(Powertrain/Chassis/Body/Infotainment) μ¬μ΄μμ λ©μμ§ λΌμ°ν , νμ΄νΈλ¦¬μ€νΈ νν°λ§, λ μ΄νΈ 리미ν μ μννλ μ€μ ECU.
- Source. Common automotive E/E architecture.
- Related. Domain Isolation, IDS, OBD-II Gateway.
- Example. Infotainment λλ©μΈμμ Powertrain λλ©μΈμΌλ‘μ λΉνμ© λ©μμ§λ₯Ό drop.
- See also. Module 02.
SecOC (Secure Onboard Communication)¶
- Definition. AUTOSAR κ° μ μν μ°¨λ λ΄λΆ ν΅μ 보μ λͺ¨λλ‘, λ©μμ§μ truncated MAC κ³Ό Freshness Value λ₯Ό λΆμ°©νμ¬ μΈμ¦κ³Ό replay λ°©μ΄λ₯Ό μ 곡νλ€.
- Source. AUTOSAR SecOC specification.
- Related. MAC, Freshness Value, HSM.
- Example. 16λ°μ΄νΈ payload μ€ 4λ°μ΄νΈλ₯Ό truncated MAC μΌλ‘ μ¬μ©.
- See also. Module 02.
SUMS (Software Update Management System)¶
- Definition. UN R156 μ΄ μꡬνλ μ°¨λ μννΈμ¨μ΄ μ λ°μ΄νΈ λΌμ΄νμ¬μ΄ν΄ κ΄λ¦¬ 체κ³λ‘, OTA ν¨ν€μ§μ 무결μ±Β·λ‘€λ°±Β·μ°¨λλ³ μ ν©μ±μ κ΄λ¦¬νλ€.
- Source. UN ECE R156.
- Related. OTA, CSMS, Code Signing.
- Example. μ λ°μ΄νΈ ν¨ν€μ§κ° μ°¨λ VIN κΈ°λ° μ μ± μ λ§μ λλ§ μ μ©.
- See also. Module 04.
Sybil Attack¶
- Definition. ν 곡격μκ° λ€μμ κ°μ§ μ μ(λ Έλ) μ λ§λ€μ΄ λ€λλ€ μμ€ν (μ: V2X) μ μ λ’° λͺ¨λΈμ μ곑νλ 곡격.
- Source. Common distributed systems security taxonomy.
- Related. V2X, Pseudonym Certificate, Misbehavior Detection.
- Example. ν μ°¨λμ΄ 20κ°μ κ°μ§ μ°¨λμΌλ‘ μμ₯νμ¬ κ°μ§ μ 체 μ 보 broadcast.
- See also. Module 04.
T¶
TARA (Threat Analysis & Risk Assessment)¶
- Definition. ISO/SAE 21434 κ° μꡬνλ νλμΌλ‘, μμ° μλ³ β μν μλλ¦¬μ€ β μν₯/μ€νκ°λ₯μ± νκ° β μν λ±κΈ μ°μ β μ²λ¦¬ λ°©μ κ²°μ μ μ μ°¨.
- Source. ISO/SAE 21434:2021.
- Related. STRIDE, Attack Tree, Threat Modeling.
- Example. "OBD-II ν¬νΈλ₯Ό ν΅ν CAN λ©μμ§ μ£Όμ " μνμ λν΄ μν₯=High/μ€νκ°λ₯μ±=Medium β Risk=Medium.
- See also. Module 04.
U¶
UN R155 / R156¶
- Definition. UNECE κ° μ μν μ°¨λ μ¬μ΄λ²λ³΄μ(R155) λ° SW μ λ°μ΄νΈ(R156) νμ μΉμΈ κ·μ λ‘, 2024 λ λΆν° μ μ°¨ μΆμμ μ¬μ€μ νμ μκ±΄μ΄ λλ€.
- Source. UNECE WP.29.
- Related. CSMS, SUMS, ISO/SAE 21434.
- Example. R155 μΈμ¦ μμ΄λ EU μμ₯ μ μ°¨ λ±λ‘ λΆκ°.
- See also. Module 04.
V¶
V2X (Vehicle-to-Everything)¶
- Definition. μ°¨λκ³Ό λ€λ₯Έ μ°¨λ(V2V), μΈνλΌ(V2I), 보νμ(V2P), λ€νΈμν¬(V2N) κ°μ 무μ ν΅μ μ ν΅μΉνλ μ©μ΄λ‘, DSRC λλ C-V2X κΈ°μ μ μ¬μ©νλ€.
- Source. SAE J2945, ETSI ITS-G5.
- Related. SCMS, Pseudonym Certificate, Misbehavior Detection.
- Example. κ΅μ°¨λ‘ μ§μ μ°¨λμ΄ BSM μΌλ‘ μ£Όλ³μ μμΉ/μλ broadcast.
- See also. Module 04.