양자 내성 TOTP(Time-based One-Time Password)를 이용한 Credential Stuffing 공격 방지 기법
A Method for Prevention to Credential Stuffing Attacks using Post-Quantum TOTP(Time-based One-Time Password)
Credential stuffing attacks have significantly increased due to large-scale credential leaks. Conventional Time-based One-Time Password (TOTP) mechanisms mitigate password reuse attacks; however, HMAC-SHA-based constructions may suffer reduced security strength in the presence of quantum adversaries. This paper proposes a Post-Quantum TOTP (PQ-TOTP) scheme leveraging lattice-based and hash-based post-quantum cryptography. The proposed mechanism incorporates device binding and session randomness to reduce the success probability of credential stuffing attacks. Security analysis demonstrates that the proposed scheme provides enhanced resistance against quantum attacks and replay-based credential reuse compared to conventional TOTP mechanisms.
한국어
최근 대규모 개인정보 유출 사고로 인해 Credential Stuffing 공격이 급증하고 있다. 기존의 TOTP(Time-based One-Time Password) 기반 이중 인증 기법은 비밀번호 재사용 공격을 완화하는 데 효과적이지만, HMAC-SHA 기반 구조는 장기적으로 양자 컴퓨팅 환경에서 보안 강도가 저하될 수 있다. 본 논문에서는 격자 기반 및 해시 기반 양자 내성 암호 구조를 적용한 PQ-TOTP(Post-Quantum TOTP) 인증 기법을 제안한다. 제안 기법은 디바이스 바인딩과 세션 난수 결합 메커니즘을 통해 Credential Stuffing 공격의 성공 확률을 이론적으로 감소시킨다. 보안성 분석 결과, 제안 기법은 기존 TOTP 대비 양자 공격 저항성과 재사용 공격 방어 측면에서 향상된 보안 수준을 제공함을 확인하였다.
목차
요약 ABSTRACT 1. 서론 2. 본론 2.1 크리덴셜 스터핑 공격 2.2 TOTP를 이용한 크리덴셜 스터핑 공격 방지 기법 2.3 양자 내성 알고리즘 3. 양자 내성 TOTP기반 크리덴셜스터핑 공격 방지 기법 제안 3.1 양자 내성 TOTP(PQ-TOTP) 3.2 PQ-TOTP 인증 프로토콜 3.3 분석 3.4 실험 및 성능 분석 4. 결론 참고문헌