Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 152
No
1

클라우드 환경에서 서로 다른 IoT 장치간 효율적인 접근제어 기법 KCI 등재

정윤수, 한군희

한국융합학회 한국융합학회논문지 제9권 제4호 2018.04 pp.57-63

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

IoT 장치는 클라우드 환경에서 다양한 역할과 기능을 수행할 수 있도록 여러 분야에서 사용되고 있다. 그러나, IoT 장치를 안정적으로 제어할 수 있는 접근제어에 대한 방안은 아직 구체적으로 제시되고 있지 않은 상황이다. 본 논문에서는 클라우드 환경에서 사용되고 있는 IoT 장치의 안정적인 접근을 수행할 수 있는 계층적 기반의 다단계 속성 접근제어 기법을 제안한다. 제안 방법은 IoT 장치의 원활한 접근을 돕기 위해서 IoT Hub을 두어 IoT 장치에 고유한 ID 키(보안 토큰)를 제공 할 뿐만 아니라 수 있도록 하는 X.509 인증서 및 개인 키를 IoT Hub에서 인증하도록 하여 IoT 장치의 개인키를 IoT 장치 외부에서 알 수 없도록 하였다. 성능평가 결과, 제안방법은 기존 기법보다 인증 정확도가 평균 10.5% 향상되었으며 처리 시간 도 14.3% 낮은 결과를 얻었다. IoT 속성 수에 따른 IoT Hub의 오버헤드는 기존 기법보다 9.1% 낮은 결과를 얻었다.

IoT devices are used in many areas to perform various roles and functions in a cloud environment. However, a method of access control that can stably control the IoT device has not been proposed yet. In this paper, we propose a hierarchical multi-level property access control scheme that can perform stable access of IoT devices used in a cluster environment. In order to facilitate the access of the IoT device, the proposed method not only provides the ID key (security token) unique to the IoT device by providing the IoT Hub, but also allows the IoT Hub to authenticate the X.509 certificate and the private key, So that the private key of the IoT device can not be seen outside the IoT device. As a result of the performance evaluation, the proposed method improved the authentication accuracy by 10.5% on average and the processing time by 14.3%. The overhead of IoT Hub according to the number of IoT attributes was 9.1% lower than the conventional method.

2

헬스케어 환경을 위한 칼라 모델 기반의 사용자 인증 키 설립 기법 KCI 등재

정윤수

한국융합학회 한국융합학회논문지 제8권 제3호 2017.03 pp.115-121

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

병원의료 서비스는 사용자의 헬스케어 정보를 융합하여 신속한 의료서비스를 사용자에게 제공하거나 의 료서비스의 질 개선을 위해서 많은 노력을 하고 있다. 그러나, 최근 연구에서는 사용자의 헬스케어 정보를 유․무선 을 통해 병원 서버에 전달하려고 할 때, 사용자의 헬스케어 정보가 노출되는 문제점이 있다. 본 논문에서는 사용자 의 헬스케어 정보를 안전하게 전달하기 위한 칼라 모델 기반의 사용자 인증 키 설립 프로토콜 기법을 제안한다. 제안 기법은 칼라 모델에서 사용되는 칼라 정보를 랜덤하게 3개 추출하여 추출된 임의의 정보를 벡터화하여 사용자 인증에 필요한 키 정보를 직교 벡터의 합으로 구함으로써 효율성을 높이는 것을 목적으로 한다. 또한, 제안 기법은 추가적인 암호 알고리즘을 사용하지 않으면서 사용자 인증에 필요한 키 정보를 안전하게 생성할 수 있다. 성능 평가 결과, 제안 기법은 사용자의 헬스케어 정보의 수가 증가할수록 생성된 정보를 처리하는 서버의 시간이 기존 기법보 다 평균 8.1% 낮게 나타났으며, 오버헤드는 기존 기법보다 7.7% 낮은 결과를 얻었다.

Hospital medical services are making great efforts to provide prompt medical services to patients or improve the quality of medical services by convergence patient's healthcare information. However, recent research suggests problems about safety and efficiency when trying to transmit patient's healthcare information to hospital server via radio and wireless. In this paper, we propose a color model - based patient authentication key establishment protocol method to securely transmit patient healthcare information. The proposed method extracts randomly three color information used in the color model and vectorizes the extracted arbitrary information to obtain the key information required for user authentication as the sum of orthogonal vectors to improve the efficiency. In addition, the proposed method can securely generate key information used for user authentication without using an additional encryption algorithm. In performance evaluation result, proposed method shows that the server processing time of the sensed information is 8.1% higher than the existing method and 7.7% lower than the existing method.

4

4,000원

이 논문에서는 ad-hoc 네트워크의 제한된 문제점들을 살펴보고 ad-hoc 네트워크에 보다 효율적으로 적용할 수 있 는 2-tier 계층적 네트워크를 적용하는 새로운 동적 라우팅 방법을 제안한다. 효율적으로 네트워크를 관리하기 위하여 p roactive와 reactive 라우팅 방법의 장점을 결합할 수 있는데, 이라한 방법을 NSDR(New Secure Dynamic Routing)이라 고 정의한다. 이 논문에서는 또한 이러한 네트워크상에서의 신뢰할 수 있는 인증방법과 키 관리 방법을 제안한다. Adhoc 네트워크와 차세대 모바일 네트워크와 결합하여 신뢰성을 향상시키는 인증 방법이나 키 관리를 위한 부차적인 연구 를 수행하고 있다.

In this paper, we consider the limit of the previous works for ad-hoc network, then propose a dynamic routing scheme which employs a 2-tier hierarchical structure. We adopt the advantages of proactive and reactive routing scheme for efficient network management. We define this method as NSDR(New Secure Dynamic Routing) scheme. We also propose a trustworthy authentication and key management for the proposed ad-hoc network. We currently study the possibility that ad-hoc networks can provide a service such as key management and authentication for the next generation mobile network.

5

IoT 환경에서 Tyagi 등이 제안한 사용자 인증 및 키 동의 스킴에 대한 취약점 분석 KCI 등재

변승민, 이학준

한국EA학회 정보화연구 제20권 3호 2023.09 pp.165-173

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

IoT에서 무선 센서 네트워크는 핵심적인 역할을 한다. 무선 센서 네트워크는 여러 개의 무선 센 서 노드가 상호 연결되어 정보를 수집하고 전송하는 네트워크이다. 무선 센서 네트워크는 무선 기술 을 사용하여 노드 간의 통신이 이루어진다. 또한 IoT 장치 간의 통신을 가능하게 하고, 기존의 네트워 크와는 다르게 의사소통 수단이 아닌 자동화된 원격 정보 수집을 목적으로 한다. 무선 센서 네트워크 는 센서 데이터를 모으기 위해 주로 사용되고, 실시간 데이터 수집 및 분석을 할 수 있으며, 무인 분 야에서 다양하게 활용되고 있다. 그리고 다양한 IoT 애플리케이션인 스마트 도시, 스마트 홈, 스마트 그리드 등에 사용되고 있다. 하지만 무선 센서 네트워크는 노드들이 일반적으로 변조 방지 기능이 없 기 때문에 보안에 취약하다. 따라서 사용자 인증 및 키 합의 프로토콜은 무선 센서 네트워크에서 중 요한 연구 분야이다. 최근 Tyagi 등은 보안 취약점을 개선한 무선 센서 네트워크를 위한 사용자 인증 및 키 합의 프로토콜을 제안했지만 본 논문에서는 Tyagi 등이 제안한 프로토콜의 동작 과정을 분석 하여 Offline ID, PW guessing attack, Bits mismatch, No perfect forward secrecy, No provision of revocation, Insider attack에 취약하다는 것을 밝혀낸다.

Wireless Sensor Networks play a key role in IoT. A wireless Sensor Network is a network in which a plurality of wireless sensor nodes are interconnected to collect and transmit information. Wireless Sensor Networks use wireless technology to communicate between nodes. It also enables communication between IoT devices, and unlike existing networks, it is not intended as a means of communication, but rather as an automated remote information collection. Wireless Sensor Networks are mainly used to collect sensor data, can collect and analyze real-time data, are used in various fields of unmanned, and are used in various IoT applications such as smart cities, smart homes, and smart grids. However, Wireless Sensor Networks are vulnerable to security because nodes generally do not have tampering protection. Therefore, user authentication and key agreement protocols are an important field of research in Wireless Sensor Networks. Recently, Tyagi et al. proposed a user authentication and key agreement protocol for wireless sensor networks that improved security vulnerabilities, but this paper analyzes the operation process of the protocol proposed by Tyagi et al. to reveal that it is vulnerable to offline ID, PW guessing attack, bits mismatch, no perfect forward secrecy, no provision of revocation and insider attack.

6

4,000원

무선센서네트워크는 다양한 응용을 가지고 있고 아주 넓은 지역에 배치된다. 특히, 이들 네트워크는 잠재적 인 위험을 포함한 환경에 배치됨으로 이에 대한 보안 이슈를 해결하기 위한 많은 노력이 있다. 최근에 무선센서네트 워크에서 대칭키암호시스템에 기반한 익명의 사용자 인증과 키동의 기법 (AUAKAS)이 제안되었다. AUAKAS는 가 장공격을 포함한 다양한 공격에 안전하다고 주장하였다. 하지만 본 논문은 AUAKAS가 게이트웨이에 등록된 정당한 사용자에 의하여 사용자 가장 공격과 게이트웨이 가장 공격에 취약함을 보인다. 본 논문의 보안 분석은 다양한 새로 운 보안 기법의 설계에 있어서 미리 고려할 중요한 특성 분석에 있어서 도움을 줄 수 있을 것이다.

Wireless sensor networks (WSNs) have many applications and are deployed in a wide variety of areas. They are often deployed in potentially adverse or even hostile environment so that there are concerns on security issues in these WSNs. Recently, an anonymous user authentication and key agreement scheme (AUAKAS) was proposed based on symmetric cryptosystem in WSNs. It is claimed in AUAKAS that it assures security against different types of attacks including impersonation attacks. However, this paper shows that AUAKAS does not cope from user impersonation attack and gateway impersonation attack from the legally registered user on the gateway. The security analysis could guide the required features of the security scheme to be satisfied.

7

차량 애드 혹 망을 위한 생체 키 기반의 인증 기법 KCI 등재

이근호

한국디지털정책학회 디지털융복합연구 제10권 제11호 2012.12 pp.365-369

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

사물지능통신은 낮은 네트워크 비용과 범위에서 이점을 가지고 있다. 사물지능통신의 지능형 자동차는 구성요소와 망 규모의 비율로 차량간 위치에서 극심한 변화를 보여준다. 지능형 자동차는 무선 통신 기능으로 자동차 장치들 간에 정보를 교환하기 위해 차량 애드 혹 망에서 생체 정보를 통하여 안전성 제공을 요구한다. 본 논문은 자동차 이동시 자동차간의 상호 인증을 위해 생체 정보를 제공하는 기법을 제안한다.

M2M has shown the advantages of better coverage and lower network deployment cost. Intelligent vehicle section shows severe changes in position between vehicles and has numerous large scales of networks in its components, therefore, it is required to provide safety by exchanging information between vehicles equipped with wireless communication function via biometric information in VANET(Vehicular Ad hoc Network). This thesis is to propose scheme that mutually authenticates between vehicles by composing vehicle movement as biometric information.

8

Key-Stroke 기반 Two-Factor 인증 기술 KCI 등재

안준연, 고광필, 이태진

한국융합보안학회 융합보안논문지 제20권 제3호 2020.09 pp.29-37

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

ID/Password 기반 인증기술은 간편하면서 일정한 보안수준을 제공하기에 대부분의 시스템에서 사용되고 있 으나, 이미 무수히 많은 개인정보 노출사고가 있었으며, 무엇보다 한번 노출된 패스워드를 회수하기 어렵다. 이 에, 다양한 two-factor 인증기법들이 도입되었으나, 이들은 많은 비용이 필요하며, 무엇보다 사용자의 불편함을 초래하게 된다. 본 논문에서는 기존과 같이 단 한번의 ID/Password 인증과정에서 사용자마다 고유한 Key-Stroke를 동시에 인증하여 비용대비 효과적이면서, 사용자의 불편함을 초래하지 않고, ID/Password 노출 시에도 Key Stroke Dynamics 패턴이 달라 실패하여 높은 보안성을 보장할 수 있는 기술을 제안한다. 본 논문의 제안 모델은 시스템으로 구축하여 효과성을 확인하였다.

Password based authentication technology is yet certain and id to provide a level of security being used in most systems, but already a myriad of personal information exposure to the accident. Above all, and once exposed, it is difficult to recover the password. Thus, the various authentication techniques - factor two was introduced, but they are expensive and discomfort to users, to lead. In this paper, the existing unique to users in such a single accreditation process / password id key - stroke, user authentication and cost effectively and at the same time. And not cause discomfort, suggested technologies that can also ensure high security exposure, password id. This paper's proposals and determine the effectiveness of the system to build model.

9

4,000원

드론이나 로봇과 같이 조정자가 직접 탑승하여 운영하지 않는 무인 자율이동체는 국방이나 재난 대응 분야에서 감시, 정찰, 표적 추적, 재난 대응 등 다양한 임무를 사람을 대신하여 수행해 주는 주요 도구로 활용되고 있다. 최근 인공지능을 포함하여 진보된 ICT 기술이 적용됨에 따라 물류 배송, 스마트 농업, 상황 모니터링 등 다양한 산업 분야에서 필수적인 자산으로 자리 매김하고 있다. 그러나, 현재의 드론 운영 시스템은 다양한 보안 위협과 공격에 취약한 한계를 갖는다. 특히, 양자컴퓨터가 상 용화되어 사용되면 기존의 정적 암호 체계는 더욱 취약할 것으로 판단된다. 본 논문에서는 이러한 문제를 해결하기 위해, 드 론과 GCS 환경에 적합한 경량, 양자 내성, 안전성을 충족하는 3단계 보안 프로토콜을 적용한 안전한 보안 통신 채널을 설정 할 수 있는 방법을 구현하고 시험한다.

Unmanned autonomous systems such as drones and robots, operated without a human pilot onboard, have become essential tools in national defense and disaster-response missions, performing surveillance, reconnaissance, target tracking, and emergency operations in place of human operators. With the recent integration of advanced information and communication technologies (ICT), including artificial intelligence (AI), these systems are now widely utilized across various industrial domains such as logistics and delivery services, smart agriculture, and environmental or situational monitoring, making them indispensable assets in both military and civilian sectors. However, current drone operation systems remain vulnerable to numerous security threats and attacks. In particular, as quantum computers become commercially viable, conventional static cryptographic schemes are expected to become increasingly insecure. To address these challenges, this paper proposes and evaluates a scheme for establishing a secure communication channel between drones and Ground Control Stations (GCS) by applying a lightweight, quantum-resistant, and security-enhanced three-phase protocol specifically designed for UAV environments.

10

클라우드 환경에서 네트워크 가용성 개선을 위한 대칭키 암호화 기반 인증 모델 설계 KCI 등재

백용진, 홍석원, 김상복

한국융합보안학회 융합보안논문지 제19권 제5호 2019.12 pp.47-53

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

네트워크를 통한 정보의 공유는 오늘날 클라우드 서비스 환경으로 발전하여 그 이용자수를 빠르게 증가시키고 있지 만 네트워크를 기반으로 하는 불법적인 공격자들의 주요 표적이 되고 있다. 아울러 공격자들의 다양한 공격 기법 중 IP 스푸핑은 그 공격 특성상 일반적으로 자원고갈 공격을 수반하기 때문에 이에 대한 빠른 탐지와 대응 기법이 요구 된다. IP 스푸핑 공격에 대한 기존의 탐지 방식은 연결 요청을 시도한 클라이언트의 트레이스 백 정보 분석과 그 일치 여부에 따라 최종적인 인증과정을 수행 한다. 그렇지만 트레이스 백 정보의 단순 비교 방식은 서비스 투명성을 요구하는 환경 에서 빈번한 False Positive로 인하여 과도한 OTP 발생을 요구할 수 있다. 본 논문에서는 이러한 문제를 개선하기 위해 트레이스 백 정보 기반의 대칭키 암호화 기법을 적용하여 상호 인증 정보로 사용하고 있다. 즉, 트레이스 백 기반의 암 호화 키를 생성한 후 정상적인 복호화 과정의 수행 여부로 상호 인증이 가능하도록 하였다. 아울러 이러한 과정을 통하 여 False Positive에 의한 오버헤드도 개선할 수 있었다.

Network-based sharing of information has evolved into a cloud service environment today, increasing its number of users rapidly, but has become a major target for network-based illegal attackers.. In addition, IP spoofing among attackers' various attack techniques generally involves resource exhaustion attacks. Therefore, fast detection and response techniques are required. The existing detection method for IP spoofing attack performs the final authentication process according to the analysis and matching of traceback information of the client who attempted the connection request. However, the simple comparison method of traceback information may require excessive OTP due to frequent false positives in an environment requiring service transparency. In this paper, symmetric key cryptography based on traceback information is used as mutual authentication information to improve this problem. That is, after generating a traceback-based encryption key, mutual authentication is possible by performing a normal decryption process. In addition, this process could improve the overhead caused by false positives.

11

4,000원

비디오 콘텐츠는 사람의 시각과 청각을 이용함으로 다른 종류의 콘텐츠 보다 이해하기 쉽기 때문에 많은 사람들이 선호한다. 더불어 스마트폰의 보급으로 인터넷을 이용한 비디오 콘텐츠 서비스에 대한 수요가 급증하고 있다. 콘텐츠 거래 활성화를 위해서는 유료 가입자에 대한 인증과 유료 채널로 전송되는 데이터의 보호가 중요하다. 가입자 채널 보호를 위해서는 일반적으로 대칭키 암호 기술이 사용되는데, 안전성을 높이기 위해서 키 값을 주기적으 로 변경해야 한다. 또한 다른 사용자에 의한 콘텐츠 불법 이용을 방지하려면 대리 인증이 불가해야 한다. 본 논문에서 는 가입자의 바이오메트릭 데이터를 이용한 본인 인증 및 일회용 암호키를 생성하는 모델을 제안한다. 제안한 모델은 바이오메트릭 데이터 등록, 일회용 키 생성, 채널 암호화 및 복호화 단계로 구성된다. 기존의 케이블 TV 콘텐츠 인증 기술인 CAS (Conditional Access System)와의 차이점을 분석하고 인터넷 상거래에서의 응용 분야를 제시한다.

Most peoples are used to prefer to view the video contents rather than the other contents since the video contents are more easy to understand with both their eyes and ears. As the wide spread use of smartphones, the demands for the contents services are increasing rapidly. To promote the contents business, it’s important to provide security of subscriber authentication and corresponding communication channels through which the contents are delivered. Generally, symmetric key encryption scheme is used to protect the contents in the channel, and the session key should be upadated periodically for the security reasons. In addition, to protect viewing paid contents by illegal users, the proxy authentication should not be allowed. In this paper, we propose biometric based user authentication and one time key generation models. The proposed model is consist of biometric template registration, session key generation and chanel encryption steps. We analyze the difference and benefits of our model with existing CAS models which are made for CATV contents protection, and also provides applications of our model in electronic commerce area.

12

4,000원

IT와 융합한 지능형 자동차에 대한 연구가 현재 활발히 진행중이다. 안전한 지능형 자동차 서비스를 위해 다양한 통신 기술이 제공이 되고 있다. 지능형 자동차가 통신기술을 이용한 서비스가 제공되면서 다양한 보안위협 요소가 도출되고 있다. 지능형 자동차에서 보안 인증 솔루션을 위해서는 소유권, 지식, 생체정보를 포함하고 있어야 한다[6,7]. 본 논문에서는 지능형 자동차의 보안위협 요소를 분석하고 지능형 자동차의 보안 솔루션인 생체정보를 이용한 인증 기법을 제공한다. 기존의 지능형 자동차 인증보안 솔루션보다 높은 보안성을 갖는 구현의 문제점이 해결 되도록 사용자 생체인증기법을 제안한다.

Studies on the intelligent vehicles that are converged with IT and vehicular technologies are currently under active discussion. A variety of communication technologies for safety intelligent vehicle services are support. As such intelligent vehicles use communication technologies, they are exposed to the diverse factors of security threats. To conduct intelligent vehicle security authentication solutions, there are some factors that can be adopted ownership, knowledge and biometrics[6,7]. This paper proposes to analyze the factors to threaten intelligent vehicle, which are usually intruded through communication network system and the security solution using biometric authentication scheme. This study proposed above user's biometrics information-based authentication scheme that can solve the anticipated problems with an intelligent vehicle, which requires a higher level of security than existing authentication solution.

13

세션 키 동의를 제공하는 상호인증 패스워드 인증 스킴에 대한 취약점 공격 KCI 등재

서한나, 최윤성

한국융합보안학회 융합보안논문지 제22권 제4호 2022.10 pp.179-188

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

패스워드 인증 체계 (PAS)는 개방형 네트워크에서 안전한 통신을 보장하는데 사용되는 가장 일반적인 메커니즘이다. 인수 분해와 이산 로그 등의 수학적 기반의 암호 인증 체계가 제안되고 강력한 보안 기능을 제공하였으나, 암호를 구성하는데 필요 한 계산 및 메시지 전송 비용이 높다는 단점을 가지고 있었다. Fairuz et al.은 스마트 카드 체계를 이용한 세션 키 동의와 관 련하여 인수분해 및 이산 로그 문제를 기반으로 한 개선된 암호 인증 프로토콜을 제안했다. 하지만 본 논문에서는 취약성 분 석을 통하여, Fairuz et al.의 프로토콜이 Privileged Insider Attack, Lack of Perfect Forward Secrecy, Lack of User Anonymity, DoS Attack, Off-line Password Guessing Attack에 관한 보안 취약점을 가지고 있다는 것을 확인하였다.

Password authentication schemes (PAS) are the most common mechanisms used to ensure secure communication in open networks. Mathematical-based cryptographic authentication schemes such as factorization and discrete logarithms have been proposed and provided strong security features, but they have the disadvantage of high computational and message transmission costs required to construct passwords. Fairuz et al. therefore argued for an improved cryptographic authentication scheme based on two difficult fixed issues related to session key consent using the smart card scheme. However, in this paper, we have made clear through security analysis that Fairuz et al.'s protocol has security holes for Privileged Insider Attack, Lack of Perfect Forward Secrecy, Lack of User Anonymity, DoS Attack, Off-line Password Guessing Attack.

14

4,000원

15

4,000원

클라우드 컴퓨팅은 의료, 금융 등 다양한 분야의 핵심 인프라이나, 개방형 네트워크 환경에서 인증 및 세션 키 관리에 심각한 보안 위협이 존재한다. 본 연구에서 최근 개발된 ECC 기반 3요소 인증 및 세션 키 협상 프로토콜을 분석한 결과, 첫째, 서버 데이터베이스에 집중된 사전 공유 대칭 키 k가 단일 장애점으로 작용하여 서버 침해 시 모든 사용자의 인증 메시지 위조가 가능하다(V1). 둘째, 타임스탬프만으로 신선도를 검증하여 적대적 조작 시 서비스 거부(DoS) 공격이 발생한다(V2). 셋째, 서버 개인키 노출 시 과거 모든 세션 키가 복원되어 완전 순방향 비밀성(PFS)이 결여(V3)의 세 가지 구조적 취약점을 식별되었다. 본 연구에서는 개선 방안으로 사용자별 파생 키 적용, 타임스탬프-논스 결합 검증, 임시 ECDH 기반 세션 키 도출을 제안하였고, 모의실험을 통해 원본 대비 동등한 계산 비용 수준에서 세 취약점을 모두 해소함을 확인하였다. 또한 본 연구의 검증은 수식 기반 공격 추적과 시뮬레이션 비교에 기반하며, 형식적 안전성의 완전한 증명은 향후 과제로 남는다.

This paper identifies three structural vulnerabilities in Rangwani and Om’s ECC-based three-factor cloud authentication protocol: (1) a single point of failure from the globally shared secret k, (2) timestamp-only freshness checks enabling DoS attacks, and (3) lack of perfect forward secrecy (PFS) due to reliance on the server’s long-term private key. We propose user-specific derived keys, nonce-bound timestamp verification, and ephemeral ECDH-based session key establishment. Simulation results confirm that the improved protocol closes all vulnerabilities with computation cost equivalent to the original design.

16

Quantum Authentication of Classical Messages without Entangled State as Authentication Key SCOPUS

Xiangjun Xin, Fagen Li

보안공학연구지원센터(IJMUE) International Journal of Multimedia and Ubiquitous Engineering Vol.10 No.8 2015.08 pp.199-206

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Classical messages can be authenticated by traditional authentication protocols based on hash functions. The security of these protocols depends on long authentication keys, the selection of appropriate hash functions and some assumptions concerning the computational complexity of some algorithms. In this paper, by encoding the classical binary messages and binary keys as nonorthogonal quantum messages and nonorthogonal sets of states, respectively, and using quantum encrypting scheme, a new quantum authentication protocol is proposed. In our protocol, instead of entangled quantum states, the traditional binary bits, which can be easily saved, are encoded as quantum keys. Because the quantum messages are nonorthogonal, any forgery or measurement on the quantum messages will be detected with a certain probability. Our protocol allows the authentication of binary classical messages in a secure manner.

17

HSKAS : A Novel Hierarchical Shared Key Authentication Scheme in Wireless Sensor Networks SCOPUS

Zeyu Sun, Xiaohui Ji, Yuanbo Li

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.4 2016.04 pp.105-116

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Wireless sensor networks (WSNs) are often deployed in hostile environments, thus being subjected to great security risks. However, due to the influence of environment and dynamic topology, the communication radiuses of all nodes are no strictly consistent, which may cause different neighbor number and redundant neighbors for one central node. In this paper, we present a key agreement scheme without the trusted third parties by exploiting the special characteristics of Hopfield neural network: the two nodes converge in a steady state from their respective initial states after iterating finite times, while maintaining the confidentiality of the key by quantifying the key to strings. Compared to existing solution, the proposed method requires less memory and has lower communication overhead to key agreement.

18

Experimental Analysis using Robust Key Exchange Authentication Scheme in Mobile Ad-hoc Environments SCOPUS

Cheol-seung Lee

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.10 2016.10 pp.135-146

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

A network of autonomous by multiple mobile nodes with a wireless interface in the absence of a particular network infrastructure environment is referred to as Mobile Ad-hoc network. The demanding in construction of the stand-alone networks and interconnection between convergence devices have led an increase in research on Mobile Ad-hoc Network and the application of Mobile Ad-hoc environments has been paid much attention as a wireless computing which is growing fast in the field of computer engineering With performance both as hosts and routers, easy network configuration, and fast response, mobile nodes participating in Mobile Ad-hoc Networks are suitable for mobile computing but have vulnerable points, about lack of dynamic network topology due to mobility, network scalability, passive attacks and active attacks which make it impossible to manage continuous security authentication service. In this study, proposes Session key-Encrypted key exchange authentication mechanism for a robust authentication based on Mobile Ad-hoc Network and through identify wireless environment security vulnerabilities, currently being used in OTP S/Key and DH-EKE analyzes.

19

A Study on the Device Authentication and Key Distribution Method for Internet of Things SCOPUS

Jae-young Lee, Do-Eun Cho

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.8 2016.08 pp.365-374

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

The internet of things (IoT) is a technology exchanging and sharing information without an operation and a help of a human. The technology is commercialized rapidly. However, IoT processes and transmits various forms of data at complex and different networks and it is exposed to the risks of information leakage, manipulation, and falsification. Moreover, the security vulnerability of IoT increased even further because IoT is composed of many low-performance devices and it is hard to apply the conventional security technologies to these low-performance devices. This study proposed a security method using a hash function and a symmetric encryption method to enhance confidentiality, mutual authentication, and data privacy under the IoT environment with limited resources. The proposed method authenticated a device by using a secret key, a device ID, and a random number and produced a session key, which was necessary to encrypt the transmitted data. This method could properly respond to the counterfeit, falsification, disguise, and replay attacks and secure the confidentiality of the data.

20

A Chebyshev-Map Based One-Way Authentication and Key Agreement Scheme for Multi-Server Environment SCOPUS

Zengyu Cai, Yuan Feng, Junsong Zhang, Yong Gan, Qikun Zhang

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.9 No.6 2015.06 pp.147-156

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

One-way authentication and key agreement scheme can achieve strong user anonymity and transmitted data confidentiality over insecure public communication channel, which is very useful for the user who cares about his/her identity information. In conventional networks, Public Key Infrastructure (PKI) is a very useful component to design one-way authentication key agreement scheme. However, it will consume large amounts of computing resources. Therefore, it is inappropriate to PKI in a resource-constrained environment. In this paper, we proposed a new one-way authentication and key agreement scheme based on Chebyshev chaotic map. Compared with the related research activities, our proposed scheme has not only the high efficiency and unique functions, but also robust to various attacks and achieves perfect forward secrecy. Security and performance analyses demonstrate that the proposed scheme can solve various types of security problems and can meet the requirements of computational complexity for low-power mobile devices.

 
1 2 3 4 5
페이지 저장