하드웨어 기반 크로스도메인 솔루션(CDS)을 활용한 ZTA 정책 시행 지점(PEP) 고도화 방안 연구
A Study on Enhancing Policy Enforcement Points (PEP) in Zero Trust Architecture Using Hardware based Cross Domain Solutions (CDS)
In Zero Trust Architecture (ZTA), the Policy Enforcement Point (PEP) constitutes a core component responsible for the control of all access requests. Nevertheless, contemporary software-based methodologies such as SDP, proxies and API gateways inherently carry the risk of policy enforcement being circumvented due to vulnerability exploitation, privilege escalation or configuration errors. The present study proposes a high-trust architecture (CDS-PEP) that integrates a hardware-based Cross Domain Solution (CDS) as the PEP. The security effectiveness of the software PEP model and the proposed CDS-PEP model was compared using the Meta Attack Language (MAL) framework. The findings of the analysis indicated that the hardware-based CDS-PEP demonstrates a substantially higher degree of structural resistance to compromise in comparison with the software-based model.
한국어
제로 트러스트 아키텍처(ZTA)에서 정책 시행 지점(PEP)은 모든 접근 요청을 통제하는 핵심 구성요소이나, 현재 SDP·프록시·API 게이트웨이 등 소프트웨어 방식에 의존하여 취약점 악용·권한 상승·구성 오류에 의한 정책 집행 우회 가능성을 내포한다. 본 연구는 하드웨어 기반 크로스 도메인 솔루션(CDS)을 PEP로 통합하는 고신뢰 아키텍처(CDS-PEP)를 제안한다. MAL(Meta Attack Language) 프레임워크를 활용하여 소프트웨어 PEP 모델과 제안된 CDS-PEP 모델의 보안 효과성을 비교하였다. 분석 결과, 하드웨어 기반의 CDS-PEP가 소프트웨어 기반 모델 대비 구조적 침해 저항성이 월등히 높음을 확인하였다.
목차
요약 ABSTRACT 1. 서론 2. 배경 지식 및 관련 연구 2.1 Cross Domain Solution (CDS) 2.2 Zero Trust Architecture (ZTA) 2.3 관련 연구의 한계 3. 제안 방안 3.1 아키텍처 3.2 핵심 기능 4. 시뮬레이션 검증 4.1 ZTA-CDS Language 및 모델 정의 4.2 TTC 비교 분석 결과 5. 결론 참고문헌