년 - 년
한국기계항공기술학회(구 한국기계기술학회) 한국기계항공기술학회지(구 한국기계기술학회지) 제27권 제5호 2025.10 pp.1013-1019
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
This paper examines security vulnerabilities in current authentication methods for remote patient monitoring in Wireless Medical Sensor Networks (WMSNs), including offline password guessing and man-in-the-middle attacks. We propose a novel three-factor authentication protocol using fuzzy extractors and lightweight cryptography. Formal analysis via the Real-or-Random (ROR) model and Tamarin Prover confirms its robustness, perfect forward/backward secrecy, mutual authentication, anonymity, and untraceability. Performance comparisons demonstrate reduced overhead and enhanced security, offering a promising framework for IoMT development.
팬데믹 시나리오를 위한 의료 사물인터넷 인증 프로토콜에 내재된 쌍선형 페어링 검증 취약점을 개선한 프로토콜 제안 KCI 등재후보
중소기업융합학회 산업과 과학 제5권 제3호 2026.05 pp.70-77
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
의료 사물인터넷(IoMT)은 팬데믹 상황의 원격 모니터링 핵심 인프라라 할 수 있다. Alam과 Kumar가 제안한 쌍선형 페어링과 XOR 기반 IoMT 인증 프로토콜은 이러한 펜데믹 상황을 가정한 기술이다. 본 연구는 해당 프로토콜에 대해서 첫째, 신원 독립적 검증식으로 임의 공격자가 검증 통과 가능성, 둘째, XOR 세션 키의 평문 전송으로 세션 키복원 취약성, 셋째, 단방향 해시의 부적절한 사용으로 생체정보 복원 불가능성에 대한 보안 취약점을 확인하였다. 이에 본 연구에서는 신원 바인딩 페어링, 임시 비밀 기반 키 유도, 검증 가능 암호화를 제안하였고, 모의 시뮬레이션 실험을 통해서 제안한 프로토콜이 오버헤드 증가 없이 보안 속성을 복원함을 확인하였다.
The Internet of Medical Things (IoMT) is critical infrastructure for remote monitoring during pandemics. Alam and Kumar proposed a bilinear pairing and XOR-based IoMT authentication protocol. This study identifies three structural flaws: (1) identity-independent verification enables arbitrary adversaries to bypass authentication, (2) plaintext transmission of XOR-based session keys allows full key recovery, (3) improper use of one-way hash prevents mathematical recovery of biological information. We propose identity-binding pairing redesign, ephemeral secret-based key derivation, and verifiable symmetric encryption. Simulations confirm that all security properties are restored without increasing computational overhead.
사용자 편의성 및 안전성이 강화된 ZigBee 인증 프로토콜 KCI 등재
한국융합보안학회 융합보안논문지 제22권 제1호 2022.03 pp.81-92
※ 기관로그인 시 무료 이용이 가능합니다.
4,300원
빠르게 성장하고 있는 IoT 시장은 일반 가정에서뿐만 아니라 스마트홈이나 스마트시티까지 확대되고 있다. IoT에서 사용 하는 주요 프로토콜 중 ZigBee는 스마트홈의 도어락 시장에서 90% 이상 차지하고 있고 소형화된 센서 디바이스에서 주로 사 용하고 있어 프로토콜의 안전성이 매우 중요하다. 하지만, ZigBee를 사용하는 디바이스가 네트워크에 연결되는 인증과정에서 고정된 키를 사용하고 있어 전방향 안전성을 만족하지 못하고 있고, 최근에 개발한 ZigBee 3.0에서도 해결되지 못하였다. 본 논문에서는 ZigBee 인증 프로토콜에 전방향 안전성을 제공함과 동시에 기존 프로토콜에서도 빠르게 적용할 수 있는 설계방법 을 제안한다. 제안하는 개선된 ZigBee 인증 프로토콜은 IoT에서 연산량이 적고 전방향 안전성을 제공하는 ECDH를 적용하기 위해 최근 개발된 OWE 프로토콜을 분석 및 적용하였다. 이를 바탕으로 ZigBee 인증 프로토콜의 안전성을 제공하며, 별도의 인증서나 패스워드 입력이 필요하지 않아 사용자의 편의성 또한 제공할 수 있을 것으로 본다.
The rapidly growing IoT market is expanding not only in general households but also in smart homes and smart cities. Among the major protocols used in IoT, ZigBee accounts for more than 90% of the smart home's door lock market and is mainly used in miniaturized sensor devices, so the safety of the protocol is very important. However, the device using Zig Bee is not satisfied with the omnidirectional safety because it uses a fixed key during the authentication process that conn ects to the network, and it has not been resolved in the recently developed ZigBee 3.0. This paper proposes a design meth od that provides omnidirectional safety to the ZigBee authentication protocol and can be quickly applied to existing protoco ls. The proposed improved ZigBee authentication protocol analyzed and applied the recently developed OWE protocol to ap ply ECDH, which has low computational volume and provides omnidirectional safety in IoT. Based on this, it provides the safety of the ZigBee authentication protocol, and it is expected that it will be able to provide user convenience as it does not require a separate certificate or password input.
난수를 이용한 RFID 태그와 리더의 보안 인증 프로토콜 KCI 등재
한국디지털정책학회 디지털융복합연구 제10권 제4호 2012.05 pp.229-233
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
RFID 시스템은 태그와 리더사이의 무선통신 기술을 통해 사물의 정보를 감지하는 기술로 다양한 분야에 사용범위가 확장되고 있다. 그러나 무선으로 통신을 하므로 보안상 많은 취약점이 존재한다. 최근까지 RFID의 보안 및 안정성 문제를 해결하기 위하여 수많은 연구가 진행되고 있다. 본 논문에서는 여러 보안문제 중 프라이버시 보호를 위한 기존 기법의 취약점을 보완하여 태그가 리더로부터 수신한 해시 값과 난수 값을 기반으로 설계한 인증 프로토콜을 제안한다. 제안을 바탕으로 구현 할 때 태그와 리더간 그리고 리더와 DB 간에 각종 공격에 안전하다. 아울러 최근 제안된 타 프로토콜에 비해 보안성은 강력해지며 태그의 연산량은 줄이고 RFID시스템을 구현할 수 있는 프로토콜이다.
A RFID system is a technology for detecting information on an object through wireless communication between a tag on the object and a reader, and its applications are being expanded to various areas. Because of its wireless communication, however, there are many vulnerabilities in security. Until now, many studies have been executed in order to solve problems related to the security and stability of RFID. In order to resolve vulnerabilities in existing security methods for privacy protection, this study proposed an authentication protocol that uses hash values received from tags and random numbers. When the proposed protocol was implemented, it was safe from various types of attacks between tag and reader and between reader and DB. Furthermore, compared to recently proposed protocols, it could implement a RFID system with enhanced security and less computation in tags.
익명성을 보장하는 IoT 기반 헬스케어 사용자 인증 프로토콜의 취약점 분석 KCI 등재
한국융합보안학회 융합보안논문지 제24권 제4호 2024.10 pp.49-58
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
인터넷의 발전으로 PC, 모바일을 넘어 다양한 사물과 통신하는 IoT의 시대에 이르렀다. 특히 의료 서비스에서의 활용은 웨 어러블 기기 시장의 성장과 맞물려 심박수, 운동량, 수면 패턴과 같은 다양한 건강정보를 쉽게 실시간으로 수집하고 의사는 이를 활용해 환자의 정보를 분석하여 진료와 처방하고 있다. 이 과정에서 통신 간의 환자의 개인정보와 수집한 생체 정보가 노출되지 않도록 하는 통신의 보안성 또한 중요하게 관리해야 하는 부분이 되었다. 그중 IoT 의료 시스템의 보안성을 위한 프 로토콜을 Masud 등이 제안하였다. 이후 Chen, Chien-Ming 등은 Masud 등이 제안한 프로토콜에 다양한 취약점이 있음을 확 인하고 중복된 매개 변수를 삭제하고 통신을 경량화하여 향상된 경량화 IoT 프로토콜을 제안하였다. 본 논문에서는 Chen, Chien-Ming 등이 제안한 프로토콜의 동작 과정과 취약점을 분석하여, Chen, Chien-Ming 등이 제안한 프로토콜이 Offline Password Guessing Attack, Lack of Perfect Forward Secrecy, Bit Mismatch, User Specific Error at multi User, Weak Anonymity at Update에 취약하다는 것을 밝혔다.
With the development of the Internet, we have reached the era of IoT that communicates with various things beyond P Cs and mobiles. In particular, its use in medical services,ㄴㄴ in line with the growth of the wearable device market, easil y collects various health information such as heart rate, exercise, and sleep patterns in real time, and doctors use it to ana lyze the patient's information and prescribe it for treatment. In this process, the security of communication that prevents t he patient's personal information and collected biometric information between communications has also become an importa nt part to be managed. Among them, Masud et al. proposed a protocol for the security of the IoT medical system. Since then, Chen Chien-Ming et al. have confirmed that there are various vulnerabilities in the protocol proposed by Masud et a l., and proposed an improved lightweight IoT protocol by deleting duplicate parameters and reducing communication. In thi s paper, by analyzing the operation process and vulnerabilities of the protocol proposed by Chen Chien-Ming et al., it was revealed that the protocol proposed by Chen Chien-Ming et al. is vulnerable to Offline Password Guessing Attack, Lack of Perfect Forward Secrecy, Bit Mismatch, User Specific Error at Multi User, and Weak Anonymity at Update.
웹 사용자를 위한 통합 ID 인증 프로토콜에 관한 연구 KCI 등재
한국디지털정책학회 디지털융복합연구 제13권 제7호 2015.07 pp.197-205
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
기존의 웹 인증방식은 주민등록번호를 이용하여 신용평가회사의 실명확인 데이터베이스를 통해서 인증 방식 과 주민등록번호를 이용한 인증 방식을 개선한 대체인증 수단인 아이핀 인증방식 등이 있다. 기존 인증 방식을 개선 하여 모든 웹에서 이용할 수 있는 통합 ID 인증 프로토콜을 제안한다. 제안한 인증 방식은 안전성을 높이기 위해서 사용자 검증값을 암호화하여 인증기관의 데이터베이스에 고유 식별번호로 저장한다. 그리고 해당 웹에 로그인하기 위 해 필요한 패스워드는 일회용 난수를 인증기관으로부터 수신하기 때문에 사용자가 패스워드를 따로 기억할 필요가 없고 스마트폰을 사용하여 난수를 수신한다. 웹은 데이터베이스에 사용자의 개인정보를 저장하지 않기 때문에 개인정 보 관리가 용이하며 사용자에게는 통합 ID 하나만 기억하고 매번 일회성 난수를 패스워드로 발급받아 여러 ID와 패 스워드를 기억하고 관리하지 않아도 되는 편리성을 제공해 준다.
Existing Web authentication method utilizes the resident registration number by credit rating agencies separating i-PIN authentication method which has been improved authentication using resident registration number via the real name confirmation database. By improving the existing authentication method, and it provides the available integrated ID authentication on Web. In order to enhance safety, the proposed authentication method by encrypting the user of the verification value, and stores the unique identifier in the database of the certificate authority. Then, the password required to log in to the Web is for receiving a disposable random from the certificate authority, the user does not need to remember a separate password and receives the random number by using the smart phone. It does not save the user's personal information in the database, and it is easy to management of personal information. Only the integration ID needs to be remembered with random number on every time. It doesn’t need to use various IDs and passwords if you use this proposed authentication methods.
4,000원
최근 RFID/USN 환경에서 정보보호는 네트워크 보안 및 RFID 정보보호 기술로 구분될 수 프로토콜 설계가 활발히 연구되고 있다. 그러나, 저가의 RFID 태그의 생산과 사용자 프라이버시 보호를 위한 안전한 인증 프로토콜의 개발은 미흡한 실정이다. 따라서, 본 논문에서는 기존의 인증 프로토콜보다 RFID 태그에서 계산량을 감소시키고 통신 오버헤드를 감소시키므로 개인 프라이버시 보호를 위한 효제안하였다.
Recently, the security for RFID/USN environment is divided into network security and RFID security. The authentication protocol design for RFID security is studied to protect user privacy in RFID system. However, the study of efficient authentication protocol fot RFID system is not satisfy a security for low-cost RFID tag and user privacy. Therefore, this paper proposes a secure matrix-based RFID authentication protocol that decrease communication overhead and computation. In result, the Matrix-based RFID authentication protocol is an effective authentication protocol compare with HB and HB+ in traffic analysis attack and trace location attack.
베터리 전력 환경 IoT 디바이스 경량 인증 프로토콜 연구 KCI 등재
한국융합보안학회 융합보안논문지 제24권 제3호 2024.09 pp.165-171
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
IT융합 트렌드에 의해, 많은 산업 분야에서는 필요한 IoT 기술을 개발하고 있다. 특히 대용량 베터리와 모바일 통신 기술 발전으로, IoT는 스마트 팜이나 스마트 환경, 에너지 등을 포함한 다양한 분야로 확대될 수 있었다. 이러한 서비스들은 서비스 유지 시간 확보를 위해 목표한 기능에만 집중하며, 상대적으로 전력 소모가 많은 보안 기술 도입에 소극적이다. IoT 서비스의 IoT 단말의 취약한 보안 환경은 안정적인 서비스 제공에는 부적절하다. 안전한 IoT 서비스 제공을 위해서는, 베터리 전력 소 모를 고려한 보안 기술이 요구된다. 본 연구에서는 IoT 서비스에 대한 다양한 보안 요구사항 중, 전력 소모를 최소화하는 IoT 단말 인증 기술을 제안한다. 제안하는 기술은 Diffie-Hellman 알고리즘 기반의 단말 인증 기능으로, 전송 구간에서 인증 정보 가 유출되더라도 해당 단말을 위장할 수 없는 장점이 있다. 또 제안하는 인증 기술 실효성을 검증하기 위해 ID/PW 기반 인증 기술과 베터리 전력 소모율을 비교 검증한 결과, 본 연구에서 제안하는 인증 기술이 상대적으로 적은 전력을 소모하는 것으로 확인되었다. 본 연구에서 제안하는 단말 인증 기술이나 이를 준용한 인증 기술을 IoT 단말에 적용한다면, 더 안전한 IoT 보안 환경을 확보할 수 있을 것으로 예상된다.
Due to the IT convergence trend, many industrial domains are developing their own IoT services. With batteries and li ghtweight devices, IoT could expand into various fields including smart farms, smart environments, and smart energy. Ma ny battery-powered IoT devices are passive in enforcing security techniques to maintain service time. This is because sec urity technologies such as cryptographic operations consume a lot of power, so applying them reduces service maintenance time. This vulnerable IoT device security environment is not stable. In order to provide safe IoT services, security techniq ues considering battery power consumption are required. In this study, we propose an IoT device authentication technolog y that minimizes power consumption. The proposed technology is a device authentication function based on the Diffie-Hell man algorithm, and has the advantage that malicious attackers cannot masquerade the device even if salt is leaked during the transmission section. The battery power consumption of the authentication technology proposed in this study and the I D/PW-based authentication technology was compared. As a result, it was confirmed that the authentication technique prop osed in this study consumes relatively little power. If the authentication technique proposed in this study is applied to IoT devices, it is expected that a safer IoT security environment can be secured.
사이버-물리 시스템 기반 IoT 환경에서 ECC 삼중 인증 프로토콜의 보안 취약점 모델링과 보안 개선 설계 KCI 등재
한국기계항공기술학회(구 한국기계기술학회) 한국기계항공기술학회지(구 한국기계기술학회지) 제28권 제3호 2026.06 pp.389-393
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
This study critically analyzed a lightweight ECC-based three-factor authentication protocol designed for IoT-enabled e-Health cloud systems. Through adversarial modeling and formal verification, three core vulnerabilities were identified: static identity inference via XOR-cancellation across sessions, ephemeral key reuse leading to session key replay, and insufficient biometric template binding enabling cross-system correlation. Countermeasures proposed include dual-nonce ephemeral key diversification, salted fuzzy extractor-based biometric binding, dual-ephemeral Diffie–Hellman key exchange for forward secrecy, and a permissioned blockchain audit layer. Simulation results on Raspberry Pi 4 and Intel i5 demonstrate 100% replay detection, per-session forward secrecy, eliminated biometric linkability, and end-to-end latency increase within 6.7%, confirming suitability for resource-constrained IoT healthcare deployments.
기계 기술 분야에서 타원곡선 암호 기반 무선 주파수 식별 인증 프로토콜의 보안 취약점 분석 및 개선 방안 연구 KCI 등재
한국기계항공기술학회(구 한국기계기술학회) 한국기계항공기술학회지(구 한국기계기술학회지) 제28권 제3호 2026.06 pp.383-388
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
This study analyzed the security architecture of an RFID authentication protocol using Elliptic Curve Cryptography (ECC), identified potential vulnerabilities, and proposed improvement measures. Our study enhanced security by introducing random number combination-based signature verification, session-independent key derivation, dual hash binding, and an authentication delay mitigation structure. Simulation results showed the proposed model achieved 100% replay detection rate, kept authentication delay within 12%, and improved computational complexity by approximately 18%.
스마트 헬스 및 IoT 환경을 위한 블록체인 분산 인증 프로토콜의 취약점 분석 및 개선 KCI 등재
한국기계항공기술학회(구 한국기계기술학회) 한국기계항공기술학회지(구 한국기계기술학회지) 제28권 제2호 2026.04 pp.316-322
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
This study analyzed the security architecture of a blockchain-based authentication protocol and identified major vulnerabilities in smart health and Internet of Things (IoT) environments. The analysis confirmed potential risks including replay attacks due to key synchronization delays, incomplete verification logic in smart contracts, trust imbalance among nodes, and privacy breaches from private key reuse. To address these, the study proposes an enhanced protocol that integrates a time- and nonce-based multi-layered key derivation structure with dynamic trust indicators. Performance evaluation confirmed that the proposed solution simultaneously improves both throughput and security.
한국기계항공기술학회(구 한국기계기술학회) 한국기계항공기술학회지(구 한국기계기술학회지) 제27권 제5호 2025.10 pp.799-804
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
This research identifies security vulnerabilities in IoT-based healthcare authentication, specifically replay attacks, session key predictability, and biometric data leakage. We propose enhancements like adaptive timestamp verification and hybrid entropy sources for stronger session keys. Quantum-resistant cryptography and advanced biometric data protection are also recommended.
4,000원
본 연구는 의료 IoT(IoMT)를 위한 블록체인 기반 인증 프로토콜의 주요 보안 취약점(스마트 카드 보안, 생체 데이터 보호, 세션 키 관리, 자원 제약)을 평가하였다. 본 연구에서는 이를 개선하기 위해 PUF 통합, 고도 암호화, 임시 키 교환, 경량 알고리즘 적용 등의 향상 방안을 제안하였다. 이러한 개선은 민감한 의료 데이터 보호 를 목표로 하며, 향후 양자 내성 암호 알고리즘 탐색 및 AI 기반 적응형 보안 정책 개발을 통해 프로토콜의 복원력 을 강화할 것으로 사료된다.
This study evaluates key security vulnerabilities (smart card security, biometric data protection, session key management, resource constraints) in a blockchain-based authentication protocol for the Internet of Medical Things (IoMT). To address these, it proposes enhancements including PUF integration, advanced cryptography, ephemeral key exchange, and lightweight algorithms, aiming to protect sensitive medical data. Future research will focus on exploring quantum-resistant cryptographic algorithms and developing AI-driven adaptive security policies to strengthen the protocol's resilience.
4,000원
본 연구는 스마트 홈 환경에서의 블록체인 기반 클라우드-포그 협력 인증 프로토콜에 대한 보안 취약점 분석을 수행하였다. 제안된 프로토콜은 사용자의 익명성을 보장하고, 사칭 및 재생 공격을 방지하기 위해 타원 곡 선 암호화 및 영지식 증명을 통합하였다. 또한, 역할 기반 접근 제어(RBAC)를 도입하여 내부자 위협을 완화하고, 각 세션에 대한 완벽한 순방향 보안을 보장하였다. 향후 연구는 하이브리드 블록체인 합의 메커니즘과 양자 이후 암호화를 탐구하여 프로토콜의 복원력을 더욱 강화할 필요가 있다.
This study conducts a security vulnerability analysis of a blockchain-based cloud-fog collaborative authentication protocol in smart home environments. The proposed protocol integrates elliptic curve encryption and zero-knowledge proofs to ensure user anonymity and prevent impersonation and replay attacks. Additionally, it introduces role-based access control (RBAC) to mitigate insider threats and ensures perfect forward secrecy for each session. Future research will explore hybrid blockchain consensus mechanisms and post-quantum cryptography to further enhance the protocol's resilience.
스마트 카드 및 동적 ID 기반 멀티서버 원격 사용자 인증 프로토콜의 취약점 분석 KCI 등재
한국융합보안학회 융합보안논문지 제23권 제4호 2023.10 pp.43-52
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
많은 기업과 단체들은 원격 접근을 위해 스마트카드 기반 사용자 인증을 사용한다. 그 동안 다양한 연구를 통하여 사용자 와 서버 간의 연결을 보호하기 위해 분산된 다중 서버 환경에 대한 동적 ID 기반 원격 사용자 인증 프로토콜들이 제안되었다. 그 중, Qiu 등은 상호 인증 및 키 동의, 사용자 익명성, 다양한 종류의 공격에 대한 저항을 제공하는 효율적인 스마트카드 기 반 원격 사용자 인증 프로토콜을 제안하였다. 이후, Andola 등은 Qiu 등이 제안된 인증 프로토콜에 대한 다양한 취약점을 찾 아내었고, 그들의 인증 프로토콜에 대한 결점을 극복하고 사용자가 서버에 로그인하기를 원할 때마다 로그인하기 전에 사용자 ID가 동적으로 변경되는 향상된 인증 프로토콜을 제안하였다. 본 논문에서는 Andola 등이 제안한 프로토콜의 동작 과정 및 취약점을 분석하여, Andola 등이 제안한 프로토콜이 offline smart card attack, dos attack, lack of perfect forward secrecy, session key attack에 취약하다는 것을 밝혔다.
Many businesses and organizations use smartcard-based user authentication for remote access. In the meantime, through various studies, dynamic ID-based remote user authentication protocols for distributed multi-server environments have been proposed to protect the connection between users and servers. Among them, Qiu et al. proposed an efficient smart card-based remote user authentication system that provides mutual authentication and key agreement, user anonymity, and resistance to various types of attacks. Later, Andola et al. found various vulnerabilities in the authentication scheme proposed by Qiu et al., and overcame the flaws in their authentication scheme, and whenever the user wants to log in to the server, the user ID is dynamically changed before logging in. An improved authentication protocol is proposed. In this paper, by analyzing the operation process and vulnerabilities of the protocol proposed by Andola et al., it was revealed that the protocol proposed by Andola et al. was vulnerable to offline smart card attack, dos attack, lack of perfect forward secrecy, and session key attack.
HECC를 이용한 DNA 기반 인증 체계에 대한 취약점 분석 KCI 등재
한국EA학회 정보화연구 제19권 2호 2022.06 pp.127-135
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
DNA 암호화는 전산 DNA에서 새롭게 떠오르는 연구 분야이다. DNA 암호화는 일반 텍스트를 DNA 시퀀스로 변환하여 모빌리티 네트워크에서 비밀성을 제공하는 보다 안전하고 효율적인 기술인 모바일 사용자 인증으로 사용된다. 모빌리티 네트워크에서 인증 및 기밀 유지 서비스를 제공하는 것 은 매우 중요하다. 인증과 기밀성을 제공하기 위한 HECC(Hyper Elliptic Curve Cryptography)는 ECC, RSA, DES 등과 같은 다른 암호화 기술들 사이에서 인기가 있다. 최근 Madhusudhan R · Shashidhara R은 HECC를 이용한 DNA 기반 인증 체계를 제안하면서, 비공식 보안 분석을 통해 제 안된 프로토콜이 안전하다고 주장한다. 본 논문에서는 Madhusudhan R · Shashidhara R이 제안한 프로토콜에 대한 취약점 분석을 통하여, 이 프로토콜이 Offline ID, PW guessing attack, No Perfect Forward Secrecy, Design Flaws, Dos attack, User Impersonation attack에 취약하다는 것을 밝 혔다.
DNA encryption is an emerging field of research in computational DNA. DNA encryption extends to mobile user authentication, a more secure and efficient technology that provides secrets in mobility networks by converting plaintext into DNA sequences. Providing authentication and confidentiality services in a mobility network is very important. HECC for providing authentication and confidentiality is popular among other encryption technologies such as ECC, RSA, DES, etc. Recently, Madhusudhan R · Shashidhara R proposed a DNA-based authentication scheme using HECC, claiming that the proposed protocol is safe through informal security analysis. In this paper, through the vulnerability analysis of the protocol proposed by Madhusudhan R · Shashidhara R, it was revealed that this protocol is vulnerable to Offline ID, PW guessing attack, No Perfect Forward Secrecy, Design Flaws, Dos attack, and User Impersonation attack.
[NRF 연계] 한국통신학회 ICT Express Vol.11 No.4 2025.08 pp.636-642
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
With the rise of the Internet of Vehicles (IoV), secure and efficient authentication is essential to prevent cyber threats. This paper proposes a session key establishment protocol using Zero-Knowledge Proofs (zk-SNARKs) and Elliptic Curve Cryptography (ECC), including the Elliptic Curve Diffie?Hellman (ECDH) key exchange, to ensure privacy and efficiency. While zk-SNARK computations introduce additional verification overhead, our optimizations, such as precomputed proof parameters and lightweight session re-authentication, mitigate delays. Performance evaluation shows a 20% reduction in computation overhead and a 75% faster re-authentication time compared to existing methods, making it a secure and practical solution for real-world IoV applications.
Edge-enhanced decentralized vehicle authentication protocol for IoV
[NRF 연계] 한국통신학회 ICT Express Vol.11 No.4 2025.08 pp.624-630
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
The Internet of Vehicles (IoV) requires secure and efficient authentication. This study proposes a decentralized protocol leveraging edge nodes and consortium blockchain to enhance security while reducing cloud dependency. A mathematical model evaluates performance and scalability, while simulations validate resilience against network failures, attacks, and topology changes. The protocol integrates with IoT infrastructure and considers implementation costs. Results demonstrate improved efficiency, security, and feasibility for large-scale vehicular networks.
4,000원
최근 센서를 이용한 장치들의 사용은 증가추세이다. 이런 센서 장치들은 이종무선 센서네트워크 환경에서 최신 기술 들과 연관 지어 폭발적으로 증가하고 있다. 이런 환경에서 센서디바이스의 사용은 우리에게 편리함을 제공하기는 하나 여러 형태의 보안위협이 도사리고 있는 실정이다. 무선선서네트워크를 이용하여 원격으로 접속하여 제공받는 서비스에 존재하는 보안위협 중 대부분은 전송되는 정보의 유출과 사용자, 센서, 게이트웨이 사이의 인증에 대한 손실이 대부분이 다. 2019년 Chen 등이 이종무선 센서 네트워크에 안전한 사용자 인증 프로토콜을 제안하였다. 그러나 Ryu 등이 제안한 논문에서 그들이 제안 프로토콜은 password guessing attack과 session key attack에 취약하다는 것을 주장하였다. 본 논문은 이전에 제안된 논문의 취약점을 개선하여 더욱 안전하고 효율적인 사용자 인증 프로토콜을 제안하였다.
Recently, the use of sensor devices is gradually increasing. As various sensor device emerge and the related technologies advance, there has been a dramatic increase in the interest in heterogeneous wireless sensor networks (WSNs). While sensor device provide us many valuable benefits, automatically and remotely supported services offered and accessed remotely through WSNs also exposes us to many different types of security threats. Most security threats were just related to information leakage and the loss of authentication among the involved parties: users, sensors and gateways. An user authentication protocol for wireless sensor networks is designed to restrict access to the sensor data only to user. In 2019, Chen et al. proposed an efficient user authentication protocol. However, Ryu et al. show that it’s scheme still unstable and inefficient. It cannot resist offline password guessing attack and session key attack. In this paper, we propose an improved protocol to overcome these security weaknesses by storing secret data in device. In addition, security properties like session-key security, perfect forward secrecy, known-key security and resistance against offline password attacks are implied by our protocol.
Security Enhancement to an Biometric Authentication Protocol for WSN Environment KCI 등재
한국융합보안학회 융합보안논문지 제16권 제6호 제2호 2016.10 pp.83-88
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
바이오메트릭 정보를 이용한 인증방식은 사용자의 신체정보를 이용하여 신원을 확인 하고 시스템의 접근을 허가한 다. 요즘 들어, 패스워드나 보안토큰을 단독으로 이용하는 방식보다는 하나이상의 고유한 신체적, 행동적 형질에 기반 하여 개인의 생체 정보인 지문, 홍채 얼굴, 정맥 등을 활용하는 방식이 점차 증가하고 있는 추세이다. 2013년 Althobati 등이 WSN(Wireless Sensor Networks) 환경에 적합한 바이오메트릭 정보를 이용한 사용한 사용자 인증 스킴을 제안하 였다. 그러나 그들이 제안 프로토콜은 데이터 무결성에 대한 위협과 바이패싱 게이트웨이 공격에 취약하여 상호인증을 달성할 수 없었다. 본 논문은 이전에 제안된 논문의 취약점을 개선하여 WSN 환경에 적합한 안전한 프로토콜을 제안하였다.
Over recent years there has been considerable growth in interest in the use of biometric systems for personal authentication. Biometrics is a field of technology which has been and is being used in the identification of individuals based on some physical attribute. By using biometrics, authentication is directly linked to the person, rather than their token or password. Biometric authentication is a type of system that relies on the unique biological characteristics of individuals to verify identity for secure access to electronic systems. In 2013, Althobati et al. proposed an efficient remote user authentication protocol using biometric information. However, we uncovered Althobati et al.’s protocol does not guarantee its main security goal of mutual authentication. We showed this by mounting threat of data integrity and bypassing the gateway node attack on Althobati et al.’s protocol. In this paper, we propose an improved scheme to overcome these security weaknesses by storing secret data in device. In addition, our proposed scheme should provide not only security, but also efficiency since sensors in WSN(Wireless Sensor Networks) operate with resource constraints such as limited power, computation, and storage space.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.