한국어

Chapter 5: Safety and Security

Comprehensive Safety Management and Cybersecurity for Medical Drone Operations

5.1 Safety Management Systems

Medical drone operations require systematic safety management that identifies, assesses, and mitigates risks throughout all phases of operation. Safety Management Systems (SMS) provide the framework for achieving and maintaining acceptable safety levels.

10⁻⁷
Target Fatal Accident Rate
99.99%
Flight Completion Target
0
Acceptable Ground Injuries
SMS
ICAO Annex 19 Compliant

SMS Pillars

A complete Safety Management System comprises four pillars:

Pillar Components Key Activities
Safety Policy Management commitment, safety objectives Define acceptable safety levels, allocate resources
Safety Risk Management Hazard identification, risk assessment Analyze risks, implement mitigations
Safety Assurance Monitoring, auditing, continuous improvement Verify controls work, track trends
Safety Promotion Training, communication, culture Build safety awareness, share lessons

5.2 Risk Assessment Methodology

Medical drone operations employ systematic risk assessment to identify hazards and implement appropriate controls:

Risk Categories

Risk Matrix

Severity →
Likelihood ↓
Negligible Minor Major Hazardous Catastrophic
Frequent Low Medium High Unacceptable Unacceptable
Occasional Very Low Low Medium High Unacceptable
Remote Very Low Very Low Low Medium High
Improbable Very Low Very Low Very Low Low Medium

SORA Ground Risk Classes

The EASA Specific Operations Risk Assessment (SORA) methodology defines ground risk classes from GRC 1 (sparsely populated) to GRC 10 (crowds). Medical drone operations typically target GRC 2-4 through strategic route planning that avoids densely populated areas while serving healthcare facilities.

5.3 Technical Safety

Technical safety measures ensure aircraft reliability and safe behavior during normal operations and failures:

Redundancy Architecture

System Redundancy Type Failure Mode
Propulsion Multiple motors/ESCs Continue flight with reduced capability
Power Dual battery systems Return-to-home on single battery
Navigation Multi-constellation GNSS + INS Inertial navigation continues
Communication Primary + backup links Autonomous procedures on link loss
Flight Control Triple redundant autopilot Voting/failover to healthy system

Emergency Systems

⚠️ Single Points of Failure

Medical drone systems must identify and eliminate single points of failure that could cause loss of control. Critical systems require redundancy with independent failure modes. Regular fault tree analysis identifies potential failure paths that could compromise safety.

5.4 Operational Safety

Operational safety procedures protect against human error and ensure consistent, safe operations:

Pre-Flight Safety Checklist

  1. Aircraft Inspection: Visual check, component security, damage
  2. Battery Check: State of charge, health, secure mounting
  3. Payload Verification: Correct cargo, secure, within limits
  4. Weather Assessment: Current and forecast conditions acceptable
  5. Airspace Check: No restrictions, required authorizations in place
  6. Communication Test: Verify all links operational
  7. Systems Test: Control surfaces, sensors, GPS lock
  8. Emergency Review: Contingency procedures confirmed

Weather Limitations

Parameter Operating Limit Rationale
Wind Speed < 15 m/s (sustained) Control authority, energy consumption
Gusts < 20 m/s Structural limits, control margins
Visibility > 3 km (DAA equipped) Detect-and-avoid performance
Precipitation None or light Electronics protection, visibility
Temperature 0-40°C Battery performance, electronics
Icing No icing conditions Rotor/wing performance

5.5 Cybersecurity Framework

Medical drone operations face cybersecurity threats that could compromise safety, privacy, or operational continuity:

Threat Categories

Threat Attack Vector Potential Impact
Command Injection Compromise control link Unauthorized control, hijacking
GPS Spoofing False GPS signals Navigation errors, diversion
Jamming RF interference Communication loss, GPS denial
Data Theft Network intrusion Medical data exposure, PHI breach
Supply Chain Compromised components Backdoor access, malfunction

Security Controls

Security by Design

Cybersecurity must be built into medical drone systems from the design phase, not added as an afterthought. Security requirements should be defined alongside safety requirements, with both addressed in system architecture decisions.

5.6 Emergency Procedures

Defined emergency procedures ensure appropriate response to abnormal situations:

Emergency Response Matrix

Emergency Detection Response
Motor Failure Current anomaly, vibration Reduced capability flight, RTH or nearest safe landing
Battery Critical Voltage below threshold Immediate landing at nearest safe point
Communication Loss Link timeout Pre-programmed autonomous procedure (RTH/land)
GPS Loss Signal degradation Inertial navigation, land at known coordinates
Traffic Conflict DAA alert Automatic avoidance maneuver
Geofence Approach Position near boundary Automatic turn away, alert operator

5.7 Incident Reporting and Investigation

A non-punitive incident reporting culture enables learning and continuous improvement:

Reportable Events

Investigation Process

  1. Immediate Response: Secure scene, preserve evidence
  2. Data Collection: Flight logs, telemetry, video, witness statements
  3. Analysis: Determine sequence of events, contributing factors
  4. Root Cause: Identify underlying causes
  5. Corrective Actions: Implement measures to prevent recurrence
  6. Communication: Share lessons learned

✓ Just Culture

Effective safety reporting requires a "just culture" where honest mistakes are not punished, while reckless behavior is addressed. Personnel must feel safe reporting errors and near-misses without fear of blame. This culture enables identification of systemic issues before they cause accidents.

📌 Key Takeaways

📝 Review Questions

  1. Describe the four pillars of a Safety Management System and how each contributes to overall safety performance.
  2. Using the risk matrix, assess the risk of a motor failure over a suburban area. What mitigations would reduce this risk?
  3. Design a redundancy architecture for a medical drone navigation system. What independent failure modes should each redundant system have?
  4. What cybersecurity threats are most relevant to medical drone operations, and what controls address each threat?
  5. Develop an emergency procedure for complete GPS loss during a medical delivery flight 10km from the destination.
  6. Explain how a "just culture" supports safety improvement in drone operations.

Korea Standardization Infrastructure Mapping

Korea operates a comprehensive standards governance system through inter-ministerial cooperation. National Standards Council (under Prime Minister's Office, per Framework Act on National Standards Article 5) coordinates KATS (Korean Agency for Technology and Standards), MFDS (Ministry of Food and Drug Safety), MOTIE (Ministry of Trade, Industry and Energy), MSIT (Ministry of Science and ICT), MOIS (Ministry of the Interior and Safety), MOE (Ministry of Environment), MOHW (Ministry of Health and Welfare), MND (Ministry of National Defense), MCST (Ministry of Culture, Sports and Tourism), MOFA (Ministry of Foreign Affairs), MOJ (Ministry of Justice), and FSC (Financial Services Commission). Accreditation and Testing: KOLAS (Korea Laboratory Accreditation Scheme) accredits 800+ testing laboratories. KAS (Korea Accreditation System) accredits 50+ certification bodies. KTC (Korea Testing Certification), KTR (Korea Testing & Research Institute), KTL (Korea Testing Laboratory), and KCL (Korea Conformity Laboratories) provide conformance testing. Telecom and Cyber: KCC (Korea Communications Commission), KCA (Korea Communications Agency), TTA (Telecommunications Technology Association), IITP (Institute for Information & Communications Technology Planning & Evaluation), NIPA (National IT Industry Promotion Agency), KISA (Korea Internet & Security Agency), KCMVP (Korea Cryptographic Module Validation Program), NIS (National Intelligence Service), NSR (National Security Research Institute), and NCSC (National Cyber Security Center). National R&D Centers: KIST, ETRI, KAIST, Seoul National University, Yonsei University, Korea University, POSTECH, UNIST, GIST, DGIST, KISTI, KIER, KIMM, KRICT, KFRI, KRIBB. International Standards Cooperation: ISO TC/SC Korean secretariats, IEC TC/SC Korean secretariats, ITU-T Study Group Korean chairs, 3GPP RAN/SA Korean chairs, IEEE 802 Korean chairs, W3C Korea office, OASIS Korea office, IETF Korea cooperation, OECD CSTP, UN ESCAP, APEC SCSC Korean cooperation. Korean Industrial Standards (KS) Catalog: KS X (Information) 25,000+, KS A (Basic) 15,000+, KS B (Machinery) 25,000+, KS C (Electrical) 18,000+, KS D (Metallurgy) 12,000+, KS E (Mining) 5,000+, KS F (Construction) 18,000+, KS H (Food) 8,000+, KS I (Environment) 5,000+, KS J (Biology) 3,000+, KS K (Textile) 15,000+, KS L (Ceramics) 7,000+, KS M (Chemistry) 12,000+, KS P (Medical) 5,000+, KS Q (Quality Mgmt) 4,000+, KS R (Transport) 12,000+, KS S (Service) 3,000+, KS T (Packaging) 4,000+, KS V (Shipbuilding) 5,000+, KS W (Aerospace) 3,000+ — totaling 220,000+ Korean Industrial Standards. Key Acts: Personal Information Protection Act (Act 19234, effective Sept 15, 2024), Electronic Government Act, Electronic Signature Act, Act on Promotion of Information and Communications Network Utilization and Information Protection, Information and Communications Infrastructure Protection Act, Data Industry Act, Public Data Act, AI Framework Act (Act 20212, effective July 2026), Industrial Technology Innovation Promotion Act, Framework Act on Science and Technology — 70+ Korean standardization-related laws.

Korea Digital Transformation Detailed Mapping

Korea operates digital transformation through a comprehensive governance system. Digital Government: Digital Platform Government Committee (established September 2022, under the President)·Ministry of the Interior and Safety Digital Government Bureau·e-Government Support Center·Gov.kr·National Citizen Service·KDIS (Korea Digital Information Society)·NIA (National Information Society Agency)·MOIS (Ministry of the Interior and Safety). K-DNS Infrastructure: Korea Internet & Security Agency (KISA) Korea Internet Center·KISA DNS Root Server·KRNIC (Korea Network Information Center)·BGP Korea·National Cyber Security Center (NCSC)·KCC (Korea Communications Commission)·MSIT (Ministry of Science and ICT)·NIA·NIPA. Korean Cloud Infrastructure: KT Cloud·NAVER Cloud (NCloud)·Samsung SDS Cloud·LG U+ Cloud·NHN Cloud·Kakao Enterprise Cloud·SK Telecom Cloud·KISA Cloud Security Assurance Program (CSAP)·KCMVP-validated cloud·ISMS-P (Information Security & Personal Information Management System). Korean Security Certifications: KISA ISMS-P certification·KCMVP (Korean Cryptographic Module Validation Program)·NIS (National Intelligence Service) "National Cryptographic Technology Operation Standards"·NCSC "National Cyber Security Strategy 2024-2028"·CC (Common Criteria) Korean evaluation bodies·EAL4·EAL5·KS X ISO/IEC 15408·19790·24759 Korean Profile. Korean Data Standards: NIA AI Hub·National Data Standardization Committee·Statistics Korea (KOSTAT)·MyData 4 Designated Combination Specialists (Samsung SDS, KICI, KOSTAT, KFTC)·National Institute of Korean Language·National Law Information Center·National Spatial Information Platform·National Spatial Data Center·Korean Spatial Information Standards. Finance and Fintech Standards: FSC (Financial Services Commission)·FSS (Financial Supervisory Service)·FIU (Financial Intelligence Unit)·BOK (Bank of Korea)·FSEC (Financial Security Institute)·KFTC (Korea Financial Telecommunications)·KSD (Korea Securities Depository)·KRX (Korea Exchange) 8-agency cooperation. 5G/6G Communications Infrastructure: 5G subscribers 35 million (2024)·5G base stations 350,000·6G commercialization target 2028·5G dedicated networks 16 operators·6G Acceleration Council (MSIT, 2024). K-Content: KOCCA (Korea Creative Content Agency)·MCST (Ministry of Culture, Sports and Tourism)·KCA (Korea Communications Agency)·Korea Culture Information Service Agency·Korean Film Archive·Korea Publishing Industry Promotion Agency. Data 3 Acts (Personal Information Protection Act·Credit Information Act·Telecommunications Network Act, 2020 enforcement)·Data Industry Act (2021)·Public Data Act (2013)·AI Framework Act (2026)·Digital Platform Government Framework Act (2024 proposed) — Korea digital transformation core legislation.

Korea Industrial, Research, Education Infrastructure Mapping

Korea operates its industrial ecosystem and standardization system through the following core infrastructure. Korea Top 5 Groups: Samsung, Hyundai Motor, LG, SK, Lotte. Each group operates standardization committees and ISO/IEC TC Korean secretariats. Samsung Electronics (semiconductors, displays, home appliances, telecom)·Hyundai Motor (automobiles, mobility)·LG Electronics (home appliances, displays, OLED)·SK hynix (memory)·LG Energy Solution·Samsung SDI (batteries)·POSCO Future M (materials)·Hyundai Mobis (parts). Korean IT Big Tech: NAVER (search, cloud, AI HyperCLOVA)·Kakao (messenger, payment, mobility, banking)·Coupang (e-commerce, logistics)·Karrot Market·Toss·Woowa Brothers. Korea Telcos: SK Telecom·KT·LG U+. 5G·5G dedicated networks·B2B cloud·AI businesses operating. Korea Top 7 Research Universities: Seoul National University·KAIST·POSTECH·Yonsei University·Korea University·UNIST·DGIST·GIST. All serve as standardization R&D bases and ISO/IEC/IEEE Korean chairs. Korea Government-affiliated National Research Institutes (26): KIST, KAERI, KIMM, KIER, KFRI, KRICT, KRIBB, KARI, KASI, KIGAM, KICT, KISTI, KETI, ETRI, NIMS, KIMS, KISDI, KOTRA, STEPI, KOEN, KICCE, KIET, KIPF, KIHASA, KICJ, KLRI. Korea Industrial Complexes / Tech Valleys: Pangyo Techno Valley·Dongtan·Gwanggyo·Songdo IBD·Yeouido·Gangnam·Sihwa·Banwol·Gumi·Ulsan·Changwon·Geoje·Yeosu·Onsan·Cheongju·Iksan·Gwangyang·POSCO Gwangyang Steel Mill·Asan Bay·Seosan·Songdo·Incheon Airport·Sejong·Cheongna·Geomdan. Korea Trade and Finance Infrastructure: Korea International Trade Association (KITA)·Korea Trade-Investment Promotion Agency (KOTRA)·Export-Import Bank of Korea (KEXIM)·Bank of Korea·Kookmin Bank·Shinhan·Hana·Woori·NH Nonghyup·IBK Industrial Bank·SC First Bank·Citi Bank Korea·HSBC Korea·DBS Korea — 14 Korean major banks and foreign banks. Korea K-POP / K-Content: HYBE·SM·YG·JYP 4 major entertainment companies·CJ ENM·tvN·MBC·KBS·SBS·EBS·YTN·Yonhap News TV·JTBC Korean broadcasting·NETFLIX Korea·Disney Plus·TVING·Wavve·Watcha·Coupang Play. Korea Gaming Industry: Nexon·NCsoft·Krafton·Netmarble·Kakao Games·Pearl Abyss·Com2uS·Gamevil·NHN·Smilegate·Webzen. Korea Automotive / Battery: Hyundai Motor·Kia·Genesis·LG Energy Solution·Samsung SDI·SK On·POSCO Future M·EcoPro·L&F battery cathode material suppliers. Korea Semiconductor: Samsung Electronics (HBM3E·HBM4)·SK hynix (HBM3E 12-Hi)·DB HiTek·SK siltron·SK Enpulse·Dongjin Semichem·Seoul Semiconductor·Simmtech·Samsung Display·LG Display.

📐 시뮬레이터 패널 4