글쓴이 보관물: Saesoltech

인공지능(AI) 기술 발전의 빛과 그림자, 핵심은 ‘사이버 보안’

가트너가 최근 발표한 자료에 따르면 2027년까지 AI에이전트가 계정 노출을 확인해서 정보를 빼내는 데 걸리는 시간을 50%까지 단축할 것이라고 한다.

가트너에 따르면 AI 에이전트는 딥페이크 음성을 기반으로 하는 사회 공학적 해킹 공격(시스템이 아닌 사람의 취약점을 공략하여 원하는 정보를 얻는 공격 기법)부터 사용자 인증 정보 도용의 종단간(E2E) 자동화에 이르기까지 다양한 계정 탈취를 위한 자동화율을 높일 것이다. 이에 대응하기 위해 소프트웨어 업계는 웹, 앱, API 등 전방위에 걸쳐 AI 에이전트와 관련된 상호 작용을 감시하고 모니터링하고 분류하는 제품과 서비스를 출시할 것으로 보인다.

(출처: https://www.gartner.com/en/newsroom/press-releases/2025-03-18-gartner-predicts-ai-agents-will-reduce-the-time-it-takes-to-exploit-account-exposures-by-50-percent-by-2027)

이렇듯 기술 발전에 따라 보안 침해 위험이 날로 높아지는 상황에서 인공지능 기술 발전에 따라 자동차 보안에 미치는 영향은 무엇이고 이를 어떻게 해소해 나가야 할지 이해할 필요가 있다.


💡 AI 기술 발전이 자동차 산업에 가져온 영향

최근까지만 해도 자동차는 전통적으로 하드웨어 중심으로 발전해왔다. 내연 기관의 효율성을 높이고 공해를 저감하는 목표가 그 무엇보다 중요했었다. 하지만 전기 자동차가 등장하면서 모든 것이 바뀌기 시작했다. 전기 자동차는 배터리의 힘으로 모터를 구동하는 방식으로 동작하다 보니까 전자/전기/제어가 훨씬 더 중요해졌다. 게다가 엔진을 돌려서 전력을 얻는 대신 배터리에서 직접 전력을 얻으므로 내부에 복잡한 컴퓨터를 구동할 여유도 생기므로 자동차의 소프트웨어도 고도화되기 시작했다.

딜로이트 컨설팅의 <모빌리티 혁명을 설계하는 소프트웨어 정의 차량> 보고서에 따르면, 소프트웨어 정의 차량(SDV, Software Defined Vehicle)시대가 본격화 된다고 전망한다. 1970년대 전자제어장치(ECU, Electronic Control Unit)가 도입된 이후에 지속적으로 소프트웨어 비중이 높아지기 시작했으며, 여러 가지 기술 발전에 힘입어 바퀴 달린 스마트폰처럼 기동하는 미래지향적 모빌리티로 향해가고 있다. 여러 가지 다양한 통계에 따르면 자동차 시장에서 40%를 넘어서 점점 늘어나는 소프트웨어 비중은 다음 그림에서 확연히 드러나고 있다.

[그림: SDV에서 늘어나는 소프트웨어 비중, 출처: <모빌리티 혁명을 설계하는 소프트웨어 정의 차량> 보고서]
모빌리티 혁명을 설계하는 소프트웨어 중심 자동차

💡 AI 기술 발전의 ‘빛’: 자동차 산업의 혁신

그렇다면 SDV에서도 AI 기술에 힘입어 자동차 업계를 뒤흔든 구체적인 혁신은 무엇일까? 크게 네 가지로 나눠서 정리해보겠다.

자율주행 기술 발전: AI는 자동차에 장착된 다양한 센서 데이터를 분석하고 차량 경로를 계획하고 움직임을 제어한다. 이렇게 함으로써 운전자의 개입 없이 차량이 스스로 운전하게 만들며, 운전자의 편의성을 높이고 교통 사고를 예방하는 효과를 얻고 있다.

커넥티드 차량 서비스의 확대: AI는 차량과 외부 환경을 연결해 다양한 커넥티드 카 서비스를 제공한다. 실시간 교통 정보, 네비게이션, 엔터테인먼트와 같은 기능은 물론이고 차량 진단이나 차량 간 교통 정보 교환 등 탑승자는 물론이고 운전자의 편의성을 높인다.

제조와 생산 공정의 혁신: AI는 자동차 제조와 생산 공정의 효율성을 높인다. 생산 라인을 자동화하고 생산성을 높이고 비용을 줄인다. 또한 AI 기반 품질 관리 시스템은 제품의 결함을 실시간으로 감지하고 예측해 불량품을 줄이고 제품의 품질을 향상시킨다.

차량 진단과 유지보수의 효율성 향상: AI는 차량 상태를 실시간으로 진단하고 예측해 유지 보수 시기를 최적화한다. 부품의 고장을 사전에 예측해 문제를 예방하고 차량 수명을 연장하고 안전성을 향상시킨다. 또한 운전자는 차량의 문제점을 사전에 감지해 예방 정비가 가능해진다.

이렇듯 소프트웨어와 AI는 자동차 산업의 패러다임을 바꾸고 있으며 다양한 분야에서 혁신을 이끌어내고 있다.

💡 AI 기술 발전의 ‘그림자’: 새로운 사이버 보안 위협

하지만 AI 기술 발전은 자동차 산업에 혁신적인 변화를 가져왔지만, 우려되는 부분 역시 짚어봐야 할 것이다. 크게 네 가지로 나누어 정리해보겠다.

✅ 사이버 보안 위협 증가: 자율주행이 늘어나면서 이를 해킹해서 차량 제어권을 탈취하거나 고의로 사고를 일으킬 가능성도 존재한다. 특히 커넥티드 차량의 경우에는 네트워크 공격을 통해 민감한 정보를 탈취하거나 시스템 오동작을 일으킬 가능성도 있기 때문이다.

개인 정보와 사생활 문제: 차량 내 센서나 카메라를 통해 개인 정보를 획득하거나 개인의 위치 정보나 방문 정보 등 민감한 정보를 탈취해 악용하는 상황이 벌어질 수 있다.

기술적인 문제: 물리적인 시스템과 비교해 AI 시스템은 복잡성으로 인해 오작동하더라도 원인을 쉽게 파악하기 힘들며 유지 보수도 그만큼 어려워지는 문제가 있다.

리적인 문제: 자율주행 차량의 사고 발생시 책임 소재가 불분명하고 AI 알고리즘의 편향성으로 인해 예상치 못한 사용자에 대한 차별 문제가 발생할 가능성도 있다.

물론 기술이 더욱 발전해 나감에 따라 문제점도 줄어들 가능성이 높아지긴 하겠지만, 아직은 시행착오를 거쳐 하나씩 해결해 나가야 하는 상황이므로 각별한 주의가 필요하다.

AI 기술 발전의 ‘그림자’: 새로운 사이버 보안 위협

💡 창과 방패: AI를 활용한 사이버 보안 강화 방안

악의적인 공격자들은 AI를 오용해 사이버 보안을 위태롭게 만들고 있다. 그렇다면 창에는 방패로 대응해야 하는데, 방어하는 쪽에서도 역시 AI를 활용해 공격에 대응하고 보안을 강화하는 방법을 사용하고 있다. 사이버 보안을 강화하는 현실적인 방법을 다음과 같이 정리해보겠다.

위험 탐지와 분석 강화: AI는 방대한 로그 데이터를 분석해 정상적인 패턴을 학습하고 비정상적인 행위를 실시간으로 감지할 수 있다. 또한 AI는 악성 코드 분석과 관련해서도 단순한 규칙 기반 분석이 아니라 변종 악성 코드까지 탐지할 수 있는 융통성을 발휘한다. 이렇듯 AI는 과거의 공격 패턴과 최신 보안 위협 정보를 분석해 공격 가능성을 예측하고 선제적으로 대응하는 기반을 제공한다.

보안 자동화와 대응 효율성 향상: AI는 탐지된 위협에 대해 자동으로 대응 조치를 취하며, 시스템 취약점을 분석해 필요한 조치를 취할 수 있다. 또한 보안 데이터를 분석해 최적의 보안 정책을 설정하고 변화하는 위협 환경에 맞춰 자동으로 정책을 업데이트할 수 있다.

사용자 인증과 접근 제어 강화: AI는 평상시 사용자 행동 패턴을 분석해 비정상적인 접근을 탐지하고 필요에 따라 추가적인 인증을 요구한다. 또한 사용자의 역할, 위치, 시간 등 다양한 컨텍스트 정보를 분석해 접근 권한을 동적으로 제어할 수 있다.

보안 위협 인텔리전스 강화: AI는 자연어 처리 기술을 활용해 다양한 보안 위협 정보를 분석하고 유용한 정보를 추출해 제공할 수 있다. 또한 여러 위협 정보를 통합적으로 분석해 조직 간에 공유할 수 있다.

이렇듯 AI를 활용하면 기존 보안 시스템에 비해 훨씬 더 정교하게 통제할 수 있으며, 주변 상황이 바뀌는 경우에도 사후 조치가 아니라 사전 대응이 가능해지므로 공격자의 침입 가능성을 줄일 수 있다.

💡 제로 트러스트 원칙의 도입 과정에서 시사점

제로 트러스트 (Zero Trust)는 “절대적으로 신뢰하지 않고, 항상 검증한다”는 원칙에 의거해 모든 접근과 통신을 보안 위협으로 간주하고, 최소 권한 부여, 마이크로 세그먼트, 지속적인 검증 등을 통해 보안을 강화하는 보안 패러다임이다. AI 시대를 맞이하여 제로 트러스트 원칙이 더욱 중요하게 부각되고 있는데, 이에 대한 필요성과 시사점을 정리해보았다.

가. 제로 트러스트 원칙의 필요성

AI 기반 공격에 대한 대응: 공격자가 더욱 정교하고 지능적인 공격을 수행하도록 돕는 AI 기반 보안 공격에 맞서 제로 트러스트는 모든 접근을 의심하고 검증하는 원칙을 통해 AI 기반 공격에 효과적으로 대응할 수 있다.

데이터 중심 보안의 중요성 증대: 특히 제로 트러스트는 데이터 접근 권한을 최소화하고 암호화해서 데이터 보안을 강화하므로, 데이터가 없으면 사실상 무용지물이 되어버리는 AI의 취약점을 공략해서 지능화된 공격을 방어한다.

클라우드와 IoT 환경의 확산: AI는 클라우드와 IoT 환경에서 활발하게 적용되고 있으며, 이런 환경은 복잡하고 동적으로 변화하는 보안 위협에 노출되어 있다. 제로 트러스트는 네트워크 경계 없이 모든 접근을 검증하므로 이런 복잡한 상황에서 대응력을 높인다.

나. 제로 트러스트 원칙의 시사점

AI 기반 보안 시스템과 통합: 제로 트러스트는 AI 기반의 이상 행위 탐지, 사용자 인증과 접근 제어 시스템과 통합되어 더욱 강력한 보안 체계를 구축할 수 있다.

데이터 중심의 보안 정책: 제로 트러스트는 데이터의 중요도에 따라 접근 권한을 차등화하고 데이터 암호화와 접근 제어 정책을 강화한다.

지속적인 모니터링과 분석: 제로 트러스트는 모든 접근을 지속적으로 모니터링하고 분석해 이상 행위를 탐지하고 대응한다. AI는 모니터링과 분석을 자동화하고 효율화 하는 과정에서 중요한 역할을 한다.

사용자 중심의 보안 환경 구축: 제로 트러스트는 사용자 편의성을 해치지 않으면서 보안을 강화한다. AI 기반 사용자 접근과 인증 시스템은 사용자 경험을 향상시키면서 보안을 강화하는 데 일조한다.


이처럼 AI 기술 발전은 사이버 보안 환경에 큰 변화를 가져왔으며, 제로 트러스트 원칙은 이런 변화에 대응하는 효과적인 보안 전략이다. 제로 트러스트 도입 과정에서 AI 기술을 적극적으로 활용하고 데이터 중심의 보안 정책을 수립하며 사용자까지 포함하는 보안 환경을 구축할 필요가 있다.

새솔테크 역시 글로벌 최고 수준의 보안 기술력에 인공지능(AI)을 접목하여 V2X(Vehicle-to-Everything) 환경의 고도화를 선도하고 있다. 특히 제로 트러스트(Zero Trust) 보안 원칙을 기반으로 V2X 통신 환경에서 메시지의 우선순위를 효과적으로 결정하는 ‘AI 기반 차량 이상행위 탐지(MBD) 플랫폼’ 등을 개발/연구 중에 있으며, 한층 진보된 스마트 모빌리티 생태계 구축에 박차를 가하고 있다.

새솔테크는 단순한 보안 기술을 넘어 생명 보호와 안전한 미래 모빌리티 환경 구축이라는 본질적인 가치를 실현해가고 있다. 앞으로도 모두가 안심하고 이동할 수 있는 생명을 향한 혁신을 선도해 나갈 것이다.



여기서 잠깐, 이 PRODUCT에 주목해보세요

새솔테크의 V2X 보안 솔루션에 대해 궁금한 내용이 있다면?
지금, 새솔테크 TEAM에 문의하세요!

새솔테크, ‘옴니에어 Virtual SCMS 상호운용성 테스트’ 성공적 마무리

자율주행 및 커넥티드카 보안 솔루션 전문기업 새솔테크(대표 한준혁)가 제안하고 글로벌 커넥티드카 인증 산업협회 옴니에어(OmniAir)가 주관한 ‘Virtual SCMS 상호운용성 테스트’가 성공적으로 종료됐다.

이번 테스트는 지난 3월 2주간 진행됐으며, 글로벌 반도체 및 무선통신장비 업체 등 총 9개사가 참여했다.

새솔테크는 이번 테스트에서 총 11회의 SCMS(보안 인증체계) 상호운용성 검증을 완료하며, 기술적 안정성과 효율성을 입증했다. (중략)

출처 : 데일리시큐(https://www.dailysecu.com)

https://www.dailysecu.com/news/articleView.html?idxno=165250

SAESOL Tech to Spearhead Virtual SCMS Interoperability Testing

SAESOL Tech to Spearhead Virtual SCMS Interoperability Testing

Wilmington, DE, March 19, 2025 — SAESOL Tech is set to lead the interoperability testing of the connected car security certification system, which is being conducted under the support of the U.S. Department of Transportation (USDOT).

SAESOL Tech, a company specializing in integrated security solutions for autonomous and connected cars, announced that it will lead the interoperability testing of the connected car security certification system (Virtual SCMS interoperability test) being conducted in OmniAir.

Read more https://markets.businessinsider.com/news/stocks/saesol-tech-to-spearhead-virtual-scms-interoperability-testing-1034492115

markets insider

새솔테크 SCMS, 국내 최초 中 TRCL 등재..’글로벌 기술력 입증’

자율주행·커넥티드카 보안 솔루션 전문기업 새솔테크(대표 한준혁)는 자사 V2X(차량 간 통신) 보안 인증체계(SCMS, 차량용 PKI) 기술이 국내 기업 최초로 중국 TRCL(중국 Root CA 인증서 신뢰 목록)에 등재됐다고 25일 밝혔다.

새솔테크 관계자는 “중국 TRCL은 북미 CTL(Certificate Trust List)과 유사한 개념으로, V2X 통신 보안을 위해 채택되는 신뢰할 만한 루트 인증서 목록”이라면서 “V2X 기술의 신뢰성과 호환성을 검증해 인증하며 중국 최상위 인증기관에서 관리한다”고 말했다. (중략)

머니투데이 / 이두리 기자

기사 원문보기 : 새솔테크 SCMS, 국내 최초 中 TRCL 등재..’글로벌 기술력 입증’ – 머니투데이

새솔테크, 미국서 커넥티드카 보안인증 상호운용성 테스트 이끈다

자율주행·커넥티드카 보안 솔루션 전문기업 새솔테크(대표 한준혁)가 올 3월 중 미국 교통부(USDOT) 주도로 진행되는 커넥티드카 보안인증체계 상호운용성 테스트를 이끈다.

새솔테크는 그동안 USDOT와 협력하며 ‘상호운용성 기술 작업반(ITWG)’에 참여해왔다. 최근 새솔테크가 제안한 ‘버추얼 SCMS 상호운용성 테스트’가 승인되면서 올 3월 옴니에어(OmniAir, 글로벌커넥티드카 인증 산업협회) 주관으로 테스트를 진행할 예정이다. (중략)

머니투데이 박새롬 기자

기사원문보기: https://news.mt.co.kr/mtview.php?no=2025030611374554172

Zero Trust, AI security, quantum security, robotic security, etc… Rapidly changing cybersecurity environment and response strategies 

During a meeting with Wall Street analysts after visiting CES 2025 in January, Jensen Huang was asked about the pace of development of early-stage quantum computers and stated, “It will take about 20 to 30 years to reach a useful level,” which led to a significant drop in the stock prices related to quantum computing. 

However, Sundar Pichai, the CEO of Alphabet, made a positive forecast at the World Government Summit held in Dubai on February 12, stating that “Quantum computing will be possible in 5 to 10 years”, overshadowing Jensen Huang’s outlook. 

The ‘Willow Chip’ from Google Quantum AI, announced on December 9, 2024, astonished experts by performing calculations that would take 10 trillion 700 billion years on a supercomputer in just 5 minutes, achieving a breakthrough in solving the random number generation problem, which is crucial for modern security infrastructure, using specific quantum algorithms. Sundar Pichai’s confidence undoubtedly stems from such empirical achievements. 

On January 19, Microsoft also announced the Majorana 1, a quantum chip using topological superconductors. According to Microsoft, Majorana 1 is a ‘topology core-based quantum processing unit’ (QPU) designed to scale up to one million qubits on a single chip, with the first product starting with 8 qubits. 

Topological superconductors implemented with indium arsenide and aluminum are praised for preventing damage to quantum information, and for enabling error detection and correction to be digitized and automatically controlled, bringing commercialization one step closer. The powerful capabilities of quantum computers are now within reach. 

Microsoft Majorana 1 chip 

Image: Microsoft Majorana 1 chip 

In this rapidly changing security technology environment, we examined three key technological advancements that the C-ITS and automotive industries must prepare for. 


💡 C-ITS/Automotive Industry Perspective on Zero Trust 

C-ITS (Cooperative Intelligent Transport Systems) is a core technology that can dramatically enhance traffic efficiency and safety, but it also faces the challenge of being exposed to various security threats. C-ITS is a complex system where various components such as vehicles, road infrastructure, and central systems are interconnected and exchange information, making it difficult to ensure effective security with traditional perimeter-based security methods. Data tampering, unauthorized access and control, denial-of-service attacks, and privacy violations are major security threats to C-ITS, which not only increase the risk of malfunctions and accidents but can also lead to social disruption and various side effects due to personal information leaks. 

Zero Trust is a security paradigm based on the principle of ‘never trust, always verify,’ which considers all access and communication as security threats. It enhances security through measures such as least privilege access, micro-segmentation, and continuous verification. Applying Zero Trust in the C-ITS environment can overcome the limitations of existing security methods and build a safer and more reliable future transportation system. 

Least Privilege Access: Only the minimum necessary permissions are granted to C-ITS components and users. Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) are applied to refine permissions, and permissions are dynamically adjusted as needed. 

Micro-Segmentation: The C-ITS network is divided into small areas (segments) based on criteria such as functionality, security level, and data importance. Strict access controls are applied between each segment to minimize damage in the event of an attack. 

Continuous Verification: All access and communication attempts involving C-ITS components, users, and network traffic are continuously verified. The level of security verification is enhanced through multi-factor authentication (MFA), behavior-based analysis, and the use of threat intelligence. 

The 5GAA (5G Automotive Association), which includes various global companies from the automotive, information and communication, and electrical and electronic industries, is researching a trust-building model centered on Dynamic Trust Assessment to address internal vehicle security threats, V2X communication vulnerabilities, and road infrastructure attacks. This approach aligns with the principles of zero trust and can further enhance the cybersecurity framework in the C-ITS environment. 

💡 AI Security

The emergence of generative AI is completely changing the mindset regarding security. Attackers use AI to perpetrate breaches, while companies use AI to defend against such attacks. Since AI serves as both a sword and a shield, it is not possible for one side to benefit exclusively. From a defensive perspective, AI helps strengthen defenses by improving vulnerabilities that had not been previously considered, identifying subtle attacks, and reducing response times. On the other hand, from an offensive perspective, it enables increasingly sophisticated attacks and assists in automatically generating code equipped with new attack techniques. Defenders and attackers are gradually escalating an arms race that will continue until one side becomes exhausted and gives up. 

In relation to automobiles, enhancing the security of autonomous driving assistance systems has emerged as the biggest issue. While AI is used as a core technology in autonomous driving systems, it can also become a target for hacking. In other words, a malicious attacker could manipulate AI algorithms or tamper with data to cause vehicle malfunctions, making it crucial to verify the integrity during the deployment of AI models and to develop technologies that defend AI models from external attacks. 

So, what strategies should be used to enhance AI security? Three main considerations can be made. 

Adoption of AI-based Security Automation: The era of manual security monitoring is coming to an end, and it is time to consider AI-based security automation. It can operate 24×7 and reduce human intervention, thus helping with risk contribution and prioritization. 

Development of a Zero Trust Strategy: Both external and insider threats are becoming increasingly significant risks. Therefore, the previously mentioned zero trust strategy must be expanded beyond existing boundaries. 

Focus on Data Protection: It is necessary to thoroughly defend internal software and internal data by implementing existing security mechanisms and enhanced security mechanisms to prevent unauthorized access. 

💡 Quantum Security

According to Cloudflare’s <Year in Review 2024>(https://radar.cloudflare.com/year-in-review/2024) report, global internet traffic has increased by 17.2%, and due to the rapid response to new technologies, post-quantum encryption has reached 13% of TLS 1.3 secure traffic. This change is driven by the growing need for post-quantum encryption to prepare for quantum computing attacks, as powerful quantum computers like Google’s Willow quantum chip and Microsoft’s Mayonara continue to be developed.https://radar.cloudflare.com/year-in-review/2024 

To this end, both security companies and browser vendors are moving quickly. Google Chrome and Mozilla Firefox have already released versions with post-quantum encryption features that are quantum-resistant, while Apple Safari is also in testing, and security infrastructure companies like Cloudflare are fundamentally enabling post-quantum encryption for their customers. In quantum security, it is essential to examine three major technologies. 

Post-Quantum Cryptography (PQC): The currently widely used public key cryptographic methods (such as RSA, ECC, etc.) have vulnerabilities that could be easily decrypted once quantum computers are developed. Therefore, encryption techniques that are secure against future quantum computer attacks are being researched. This technology can be applied in all areas where current encryption technologies are used, including blockchain, secure communication, data protection, and digital signatures. Following standardization efforts, implementations in various programming languages are emerging (e.g., the post-quantum cryptography standards JEP 496/497 in Java, https://www.infoq.com/news/2024/12/java-post-quantum/)https://www.infoq.com/news/2024/12/java-post-quantum/ 

Quantum Key Distribution (QKD):   A technology that securely shares cryptographic keys between two users using the principles of quantum mechanics. Unlike traditional cryptographic methods, QKD is based on physical principles rather than mathematical computational complexity, theoretically providing secure communication that is impossible to eavesdrop. Until observed, it does not have a definite value, and the uncertainty principle, which states that the value is determined at the moment of observation, along with the no-cloning theorem that prevents perfect replication of quantum states, enhances its stability. 

✅Quantum Random Number Generator (QRNG):   True randomness is required to eliminate predictable factors in the encryption process. Traditional methods generate random numbers using deterministic algorithms that rely on unpredictable initial values. In fields where security is critical, there is a need to address situations where such methods do not guarantee perfect randomness. Quantum random number generators can produce truly random numbers by utilizing the uncertainty principle of quantum mechanics and the property of quantum superposition, thereby enhancing security. 

💡Robot Security

There is a trend of evolving from fixed robots, such as assembly robots or cooking robots, to mobile robots like unmanned vehicles, delivery robots, and combat robots. Therefore, to ensure smooth control of these mobile robots, it is necessary to utilize the aforementioned C-ITS infrastructure to exchange information in real-time. Consequently, applying zero trust security to robots is essential. 

Of course, applying zero trust to robots can dramatically enhance security levels, but the characteristics of the robots themselves must not be overlooked. A few additional considerations are summarized as follows. 

Minimizing the impact on robot performance: The application of zero trust security policies may lead to a decrease in robot system performance. It is essential to apply a zero trust architecture and technologies that minimize performance impacts, considering the real-time performance requirements of robots, such as real-time control and high-speed data processing. 

Supporting various robot platforms and operating environments: A flexible and scalable zero trust architecture should be designed, taking into account various manufacturers, diverse functionalities, and different communication methods of robot platforms and operating environments. 

✅ Compliance with Standards and Regulations: A Zero Trust system must be established in compliance with international standards related to robot security (such as ISO TR 23482-2, IEC 62443, etc.) and domestic regulations. 

 Anomaly Detection Based on Robot Abnormal Behavior: The robot’s behavior patterns, movement paths, and API call patterns must be analyzed using machine learning to detect abnormal behaviors in advance. 

💡Respond to Next-Generation Security Threats with SAESOL Tech!

In this rapidly changing cybersecurity environment, SAESOL Tech has completed preparations to meet advanced security requirements by meticulously establishing an overall security system in anticipation of Zero Trust 2.0 to respond to next-generation security threats. 

In addition, we are conducting research on next-generation encryption technologies and security architectures that closely analyze the latest technological trends in AI-based security and quantum security. Based on this, we actively participate in the establishment of global and industry standards, leading the migration of the C-ITS and V2X security market. 

SAESOL Tech prioritizes the protection of all users’ personal information beyond next-generation mobility security. We will take the lead in creating a safer future and a trustworthy communication environment through continuous technological innovation. 

For a moment, pay attention to this PRODUCT. 

If you have any questions about SAESOL Tech’s V2X security solutions,
contact the TEAM now! 

KCMVP 인증 보안모듈, 새솔테크 SSCrypto v1.0 그것이 알고싶다!

미래 모빌리티에 최적화된 암호모듈, KCMVP 인증 보안모듈 SSCrypto v1.0의 모든 것!

✅ 국내암호모듈검증제도 (KCMVP) 1등급 획득

✅ 운영환경별 최적화된 구현을 통해 높은 성능 제공

✅ 널리 사용되는 OpenSSL 암호 라이브러리와 주요 API 수준에서 호환성 제공

✅대칭키 암호부터 전자서명까지 폭넓은 알고리즘 지원으로 TLS에 활용 가능

키사이트, 새솔테크와 자동차 인증 관리 혁신 맞손

키사이트테크놀로지스는 새솔테크와 엣지 케이스에서 인증서를 관리하는 혁신적인 방법을 입증하기 위한 개념증명(PoC)을 성공적으로 수행했다고 밝혔다. 이번 PoC는 인증서 수명 주기 관리가 촉박한 기한에 따른 인증서 만료 및 대규모 갱신과 같이 V2X 통신을 방해할 수 있는 시나리오에 초점을 맞췄다.

자동차 산업에서 기술과 안전한 통신은 성공의 필수 요소다. 통합 컴퓨터 시스템은 첨단 운전자 보조 시스템(ADAS), 어댑티브 크루즈 컨트롤, 하이브리드 엔진, 인터넷 액세스, 블루투스 연결과 같은 다양한 최신 기능을 제공하고 있다. 이에 제조사는 차량에 통합된 모든 기술이 규정 준수 및 보안 요구 사항을 충족하는지 확인해야 한다.

출처 : 데이터넷(https://www.datanet.co.kr)

Countermeasures Against Hacking Risks for Connected Cars and Infrastructure: V2X Security Solutions

While V2X technology maximizes traffic efficiency and safety by enabling communication between vehicles and infrastructure or vehicles themselves, it also increases the attack surface that hackers can exploit. In March 2024, two cybersecurity researchers from Mysk, an independent cybersecurity research team, identified a security vulnerability that allowed them to generate a digital key to unlock a specific electric vehicle. Despite the presence of two-factor authentication, they successfully hacked the car using a $169 Flipper Zero device and a Wi-Fi board to open the vehicle’s doors.

Source : https://www.bleepingcomputer.com/news/security/flipper-zero-can-be-used-to-launch-ios-bluetooth-spam-attacks

By equipping the Flipper Zero with a Wi-Fi expansion module, attackers can create fake public Wi-Fi networks at service centers or charging stations. When unsuspecting users attempt to log in, their credentials—including email addresses, passwords, and two-factor authentication codes—can be intercepted. The hackers can then add a digital key to their app, allowing them to unlock the vehicle later.

Beyond direct hacking methods like identity theft, other significant threats include interfering with On-Board Diagnostics (OBD) systems, disrupting Controller Area Network (CAN) message protocols, or exploiting vulnerabilities in Bluetooth Low Energy (BLE) to bypass digital locks without a key.

Increased Hacking Risks with IoT Advancements

Source : WIRED : https://www.youtube.com/watch?v=MK0SrxBC1xs

Source : adac : https://www.youtube.com/watch?v=0AHSDy6AiV0

In the past, cars were perceived as analog, mechanical devices. However, with rapid advancements in IoT technologies, vehicles have transformed into digital systems connected to surrounding infrastructure through Vehicle-to-Everything (V2X) communication. Consequently, hackers can now target not just the vehicle itself but also the broader traffic infrastructure and network protocols.

Technological Countermeasures for Enhancing V2X Contextual Security

How can we respond to potential security breaches as digitalization progresses? Here are some key technological countermeasures to strengthen security in the V2X context:

1. Establishing V2X Security Credential Management Systems (SCMS)
– Introduce systems like the U.S. Department of Transportation’s SCMS to create secure communication environments.
– Assign roles to multiple certification authorities to manage the issuance of registration and security certificates.
– Develop and operate systems to issue, renew, and revoke certificates.

2. Privacy Protection Through Certificates
– Use anonymized certificates to protect personal information, such as vehicle location, and periodically update temporary IDs to safeguard unique vehicle identifiers.
– Issue separate types of certificates for special and general vehicles.

3. Development of V2X Security Modules and Protocols
– Design and deploy hardware security modules to securely store encrypted communication, certificates, and private keys.
– Develop and implement security protocols tailored for V2X communication.

4. Message Authentication and Integrity Verification
– Authenticate the sender of messages received by vehicles and verify the integrity of the messages before accessing their content.
– Ensure confidentiality through encrypted communications.

5. Intrusion Detection and Prevention Systems (IDS/IPS)
– Monitor abnormal traffic in real time within vehicles and V2X communication networks using anomaly detection algorithms.
– Detect and mitigate threats such as Denial of Service (DoS) attacks or data tampering early.

To implement these measures, it is essential to expand V2X security platforms not only for vehicles but also for personal mobility devices like e-bikes and surrounding infrastructure. Furthermore, constructing Public Key Infrastructure (PKI)-based security authentication systems and establishing testing and certification infrastructures to verify compliance with authentication protocols are crucial.

Saesol Tech: From Connected Car Security to Integrated Mobility Security

Saesol Tech is strengthening the V2X security platform with the following three product lines:

1. V2X Security Platform
– Provides non-repudiation by ensuring the integrity of transmitted data and verifying the sender’s identity.
– Offers world-class performance in terms of speed, security, and reliability.

2. PKI-Based Security Authentication Server
– Delivers various authentication methods and issues certificates at ultra-high speeds.
– Ensures scalability, reliability, and high availability using cloud architecture, supporting integrated security per ISO 21177 standards.

3. V2X Mobility Testing/Certification Equipment
– Offers testing and certification solutions to evaluate compliance with security authentication systems and platform security.
– Identifies malfunctions, errors, and vulnerabilities in communication software through V2X fuzz testing tools attached to test devices.

Using these product lines, Saesol Tech makes it difficult to compromise identity by securely managing private keys and authentication methods on PKI systems. Additionally, by leveraging fuzz testing, vulnerabilities in communication software can be identified and addressed preemptively. Saesol Tech remains committed to advancing the fields of micro-mobility, electric vehicles, autonomous vehicles, and traffic infrastructure to safeguard human lives and personal information.

‘자율주행/커넥티드 카 보안’ 새솔테크, ‘기업대상’ 2년 연속상

한준혁 새솔테크 대표가 머니투데이 주최의 ‘2024 제10회 대한민국 기업대상’ 시상식에서 ‘2년 연속상’으로 ‘자율주행/커넥티드 카 보안’ 부문 ‘스타트업’ 분야 대상을 비대면 수상하고 기념 촬영 중이다.

머니투데이/이두리 기자

기사원문보기: https://news.mt.co.kr/mtview.php?no=2025010714241240922