Earticle

현재 위치 Home

[일반논문]

모바일 신분증 앱 아티팩트 분석 및 표준 개선방안
Analysis of Mobile ID App Artifacts and Standard Improvement for the Service

첫 페이지 보기
  • 발행기관
    한국산업안보학회(구 한국산업보안연구학회) 바로가기
  • 간행물
    한국산업보안연구 KCI 등재 바로가기
  • 통권
    제13권 제1호 (2023.04)바로가기
  • 페이지
    pp.55-81
  • 저자
    윤지희, 김경진, 오예솔, 전유란, 전가혜, 김성민
  • 언어
    한국어(KOR)
  • URL
    https://www.earticle.net/Article/A429817

※ 기관로그인 시 무료 이용이 가능합니다.

6,600원

원문정보

초록

영어
After the emergence of decentralized identity (DID) as a means to overcome security vulnerabilities of centralized identity verification, the government has begun to offer mobile ID services that utilize DID for both online and offline public sectors. Standards for DID include the "Framework for Identity Management Using Decentralized Identifiers" by the Korea Information and Communications Technology Association, and the international standards "Decentralized Identifiers" and "Verifiable Credentials Data Model" by W3C. However, despite the introduction of domestic standards, no further improvements have been made since their establishment, despite the revision of international standards. This paper aims to explore ways to improve the service by performing artifact analysis through mobile ID app forensics, and comparing and analyzing domestic and international standards. The structural and security artifacts were evaluated based on the principles of self-sovereign identity. The shortcomings in terms of safety aspects of domestic standards were analyzed and improvement measures were derived by comparing them with international standards. Based on this research, we hope to ensure the safety and convenience of DID-based identity verification services, which are being activated in various industries, so that service users can use them with confidence.
한국어
중앙 집중식 신원인증의 보안 취약점 극복 수단인 분산ID의 등장 이후, 정부는 공공분야에서 분산ID를 적용한 온․오프라인 공용의 모바일 신분증 서비스를 제공하기 시작하였다. 분산ID는 국내 한국정보통신기술협회 ‘분산ID를 활용한 신원 관리 프레임워크’ 표준 및 국제 W3C ‘Decentralized Identifiers’과 ‘Verifiable Credentials Data Model’ 표준이 존재한다. 그러나 국내 표준이 도입된 시기를 기준으로, 이후 국외 표준의 개정이 이루어졌음에도 국내 표준은 제정일 이후로 추가적인 보완이 이루어지지 않고 있다. 본 논문에서는 모바일 신분증 앱 포렌식을 통해 아티팩트 분석을 수행하고, 이를 바탕으로 국내외 표준의 비교 분석을 통해 서비스 개선방안을 모색하고자 한다. 포렌식 분석으로 구조 아티팩트 및 보안 아티팩트를 도출하여 자기주권신원 원칙을 바탕으로 평가하 였으며, 국내 표준과 국외 표준을 비교하여 국내 표준의 안전성 측면의 미비점을 분석하고 개선방안 을 도출하였다. 본 연구를 바탕으로 다양한 산업에서 활성화 되고 있는 분산ID 활용 신원인증 서비스 안전성과 이용자 편의성을 보장하여 서비스 이용자가 안심하고 이용할 수 있기를 기대한다.

목차

요약
Ⅰ. 서론
Ⅱ. 관련 연구
Ⅲ. 모바일 신분증 아티팩트 분석 및 표준 개선안 제시
Ⅳ. 분석결과
Ⅴ. 결론
참고문헌
Abstract

저자

  • 윤지희 [ Geehee Yun | 성신여자대학교 미래융합기술공학과 석사과정 ] 제1저자
  • 김경진 [ Kyungjin Kim | 성신여자대학교 융합보안공학과 조교수 ] 교신저자
  • 오예솔 [ Yesol Oh | 성신여자대학교 미래융합기술공학과 석사과정 ] 공동저자
  • 전유란 [ Yuran Jeon | 성신여자대학교 미래융합기술공학과 석사과정 ] 공동저자
  • 전가혜 [ Gahye Jeon | 성신여자대학교 미래융합기술공학과 석사과정 ] 공동저자
  • 김성민 [ Seongmin Kim | 성신여자대학교 융합보안공학과 조교수 ] 공동저자

참고문헌

자료제공 : 네이버학술정보

간행물 정보

발행기관

  • 발행기관명
    한국산업안보학회(구 한국산업보안연구학회) [The Korean Association for Industrial Security(구 The Korean Association for Research of Industrial Security)]
  • 설립연도
    2009
  • 분야
    사회과학>경영학
  • 소개
    학회는 기업, 연구소, 대학의 산업기술 등 물적, 인적자산 및 절ㅇ보에 대한 보보방안 연구를 통해 산업보안을 학문으로 체계화하고 국가경제 및 기업의 성장과 경쟁력 강화를 지원하는 한편 산업보안 관련 산업의 국제화 도모를 목적으로 한다.

간행물

  • 간행물명
    한국산업보안연구 [Korean Journal of Industry Security]
  • 간기
    연3회
  • pISSN
    2765-2327
  • eISSN
    2733-8363
  • 수록기간
    2009~2026
  • 등재여부
    KCI 등재
  • 십진분류
    KDC 325 DDC 330

이 권호 내 다른 논문 / 한국산업보안연구 제13권 제1호

    피인용수 : 0(자료제공 : 네이버학술정보)

    함께 이용한 논문 이 논문을 다운로드한 분들이 이용한 다른 논문입니다.

      페이지 저장