We are pleased to share with you all an interesting article contributed by Anand R. Prasad who is information security leader experienced in developing successful businesses with over 20 years of proven professional track record.
Anand R. Prasad Chairman of 3GPP security working group (SA3) and Chief Advanced Technologist at NEC |
|
Yesterday I gave a talk on V2X security for 4G as well as 5G and thoughts on surrounding aspects of security at escar Asia held at the beautiful hotel Gajoen in Tokyo. A very well organized conference with very informative talks and good participation by all parties concerned with connected vehicle. Several companies were showing their security solutions such as Escrypt, Trillium with complete security suite, Harman with several solutions etc.
This goes hand-in-hand with consideration of regulatory aspects in each field and each country.
While holistic security is a must, vehicle industry must not forget baseline security which includes secure design, secure coding, hardening (software, protocols etc.), patching, lifecycle etc. A minimum baseline security requirement should be set, be it by the industry or by the regulators, a global activity to make this happen is required.
Today safety is measured by number of stars given after crash test and situation of passengers inside. Since connected vehicle started (day before yesterday?), safety should be defined by testing whether a given connected vehicle causes accident especially to a human on the street. This brings together the necessity to consider the whole aspect from many different angles such as cyber security protection, quality, insurance and regulations. This definition of safety for connected vehicle is needed.
Another aspect for connected vehicle is to consider security from all angles which includes system design but also business models and use cases (at-least near future). It is good that some in the industry has understanding of open source but different business models, use cases and lifetime of cars have their own implications on security. This is where secure network as a service becomes essential.
|
||||||||
As we tend to be more dependent on network , the network availability itself becomes another security issue. Service disruptions or degradation may threaten our lives quite soon.