사이버-물리 시스템 기반 IoT 환경에서 ECC 삼중 인증 프로토콜의 보안 취약점 모델링과 보안 개선 설계
Improvements for ECC-Based Three-Factor Authentication Protocols in IoT-Enabled e-Health Cloud Systems
※ 기관로그인 시 무료 이용이 가능합니다.
※ 학술발표대회집, 워크숍 자료집 중 4페이지 이내 논문은 '요약'만 제공되는 경우가 있으니, 구매 전에 간행물명, 페이지 수 확인 부탁 드립니다.
4,000원
원문정보
초록
영어
This study critically analyzed a lightweight ECC-based three-factor authentication protocol designed for IoT-enabled e-Health cloud systems. Through adversarial modeling and formal verification, three core vulnerabilities were identified: static identity inference via XOR-cancellation across sessions, ephemeral key reuse leading to session key replay, and insufficient biometric template binding enabling cross-system correlation. Countermeasures proposed include dual-nonce ephemeral key diversification, salted fuzzy extractor-based biometric binding, dual-ephemeral Diffie–Hellman key exchange for forward secrecy, and a permissioned blockchain audit layer. Simulation results on Raspberry Pi 4 and Intel i5 demonstrate 100% replay detection, per-session forward secrecy, eliminated biometric linkability, and end-to-end latency increase within 6.7%, confirming suitability for resource-constrained IoT healthcare deployments.
목차
Abstract 1. 서론 2. 관련 연구 3. 연구 방법 4. 프로토콜 분석 4.1 기존 ECC 기반 삼중 인증 프로토콜 4.2 취약점 분석 5. 프로토콜 개선 방안 제안 5.1 이중 난수 기반 에피머럴 키 신선성 강화 5.2 솔팅된 퍼지 추출기 기반 생체정보 바인딩 5.3 이중 에피머럴 디피-헬만 교환을 통한 전방비밀성 확보 5.4 허가형 블록체인 감사 로그 및 스마트카드 저장 보안 강화 6. 모의 실험 결과 7. 결론 References