년 - 년
핀테크 금융 기술을 이용한 국내외 보안 사례 분석 및 대응 방안에 대한 연구
중소기업융합학회 융합정보논문지(구 중소기업융합학회논문지) 제5권 제3호 2015.09 pp.1-7
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
An Authentication Scheme with Tampering Localization for PS Method
한국정보통신설비학회 한국정보통신설비학회 학술대회 2012년도 정보통신설비 학술대회 2012.08 pp.231-234
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
핀테크 환경에서 보안 키패드와 생체인증을 이용한 1.5-factor 인증 기법 KCI 등재
대한산업경영학회 산업융합연구(구 대한산업경영학회지) 제20권 제11호 2022.11 pp.191-196
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
핀테크 환경에서 스마트 폰을 이용한 금융거래가 활발하게 이루어지고 있다. 안전한 금융거래를 위해 사용자 인증 기술이 필수적이다. 기존 보안 키패드를 통한 PIN 인증은 입력 편리성이 좋지만, 보안성이 떨어지고 취약점이 존재한다. 생 체인증 기법은 보안성이 안전하지만 오탐 및 미탐 인증 가능성이 있다. 이를 보완하기 위해 2-factor 인증을 사용한다. 본 논 문에서는 생체인증 기법을 적용한 PIN 입력을 통해 편리성과 보안성을 높일 수 있는 1.5-factor 인증을 제안하고자 한다. 지 문인증의 안정성과 2~4번의 PIN 입력을 통해 편리성을 제공하여 안전한 금융거래가 가능하다. 제안기법은 PIN 입력 시 생 체인증을 동시에 수행하므로 PIN 입력할 때 터치하는 영역에 지문인식을 적용하는 방식이다. 보안이 요구되는 경우 높은 안 전성이 요구되는 상황에서는 추가적인 PIN 입력을 통해 입력 편리성을 보장하면서 사용자 인증을 수행하여 안전한 금융거래 가 가능하다.
In the fintech field, financial transactions with smart phones are actively conducted. User authentication technology is essential for safe financial transactions. PIN authentication through the existing security keypads is convenient to input but has weaknesses in security and others. The biometric authentication technique is secure, but there is a possibility of false positive and false negative authentication. To compensate for this, two-factor authentication is used. In this paper, we propose the 1.5-factor authentication that can increase convenience and security through PIN input with biometric authentication. It provides the stability of fingerprint authentication and convenience of two or three PIN inputs, and this makes safe financial transaction possible. Since biometric authentication is performed at the same time when entering PIN, while security is required by applying fingerprint authentication to the area touched while entering PIN. The User authentication is performed while ensuring convenience to input through additional PIN input in situations where high safety is required, and Safe financial transactions are possible.
유비쿼터스 환경의 인증 및 권한 메커니즘 동향을 통한 분산 인증기법 방안 연구 KCI 등재후보
한국융합보안학회 융합보안논문지 제8권 제1호 2008.03 pp.35-42
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
사용자가 접하는 정보 시스템과 어플리케이션에 대한 관리가 중요한 문제로 대두되면서 시스템 접근과 관리를 위한 방법론이 제기되고 있다. 여러 가지 형태의 인증 기술이 사용되고 있지만, 복잡한 인증 관리 및 운용에 따른 비효율성은 유무선 환경의 다양하고 새로운 비즈니스의 성공적인 전개를 위해서는 부적절하다. 또한 서로 다른 인증 방식을 사용하는 모바일 컴퓨팅 환경 하에서 유연하고 연속적인 서비스를 기대하기란 매우 어렵다. 유비쿼터스 컴퓨팅 환경하에서는 상호운용성 및 보안성이 지원되는 분산 인증 방안을 연구개발하는 것은 매우 중요한 사안이다. 이에 따라 본 논문에서는 유선(fixed) 컴퓨팅 환경에서뿐만 아니라 이동(mobile) 컴퓨팅 환경까지 고려한 유비쿼터스 컴퓨팅 환경으로 확장 가능한 분산 인증의 관리 및 운용 방안에 대한 요구사항과 권한 메커니즘에 대해 살펴봄으로써, 향후 진정한 유비쿼터스 환경에서의 분산형 인증기법에 관한 적극적인 참여를 유도할 수 있을 것으로 기대한다.
While an information system and administration for an application that a user contacts with raise a head by an important problem, a system approach and methodology for administration are mentioned. Authentication technology of various configuration is used, but non-efficiency by complicated authentication administration and operation inappropriate use are for a successful expansion of various and new business of wire/wireless environment. In addition, under the mobile computer environment with different authentic method each other, it is difficult at all to expect flexible and continuous service. Under the ubiquitous computing environment, It is very important thing plan to research and develop compatibility and the side of variance authentication plan that preservation characteristics are helped. Hereby, This paper look around an requirement items and authority mechanism for the administration and the operation mechanism of the distributed authentication considering expansion possibility of the ubiquitous computing environment not only fixed computing environment but also mobile computing. In future, we expect it by can guide participation about distributed authentication technique of the genuine ubiquitous environment.
FIDO 환경에서 다중 생체정보를 이용한 인증 방법 KCI 등재
한국디지털정책학회 디지털융복합연구 제16권 제1호 2018.01 pp.159-164
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
생체정보는 저장, 암기, 손실 우려가 없고 도용이 불가능하다는 점에서 패스워드, PKI 등 기존 인증 방법의 대체 수단으로 주목받고 있지만, 개인정보 유출로 인한 프라이버시 침해가 발생한다. 이러한 취약점을 극복하고자 FIDO에서는 생체정보를 사용자 디바이스에 보존하여 인증하는 방식을 사용하여 서버에서의 개인정보 유출 문제를 해결하였다. 본 논문 에서는 국내·외에서 활발히 연구되고 있는 FIDO 환경에서 사용할 수 있는 다중 생체정보 인증 방법을 제안한다. 다중 생체정보를 이용하기 위해 지문과 뇌전도 신호를 뇌지문 정보를 생성하여 이를 FIDO 시스템에서 사용할 수 있는 방법을 제안한다. 제안 방법은 현재 기존 2-Factor 인증 체계의 한계로 인한 문제점을 다중 생체정보를 이용한 인증으로 해결할 수 있다.
Biometric information does not need to be stored separately, and there is no risk of loss and no theft. For this reason, it has been attracting attention as an alternative authentication means for existing authentication means such as passwords and authorized certificates. However, there may be a privacy problem due to leakage of personal information stored in the server. To overcome these weaknesses, FIDO solved the problem of leakage of personal information on the server by using biometric information stored on the user device and authenticating. In this paper, we propose a multiple biometric authentication method that can be used in FIDO environment. In order to utilize multiple biometric information, fingerprints and EEG signals can be generated and used in FIDO system. The proposed method can solve the problem due to limitations of existing 2-factor authentication system by authentication using multiple biometric information.
4,000원
스마트폰을 이용하는 사용자는 인증이 필요한 시스템에 접근 권한을 획득하기 위해서 지식기반 인증, 소유기반 인증, 생체기반 인증, 토큰기반 인증 등을 이용하여 인증을 진행한다. 하지만 데스크탑 컴퓨터 사용자는 다양한 인증 방식이 있음에도 불구하고 인증 기기의 제한으로 지식기반 인증 요소인 아이디와 비밀번호를 이용하여 인증하는 방식을 주로 사용하고 있다. 본 논문에서는 사용자가 원하는 방식의 인증 방식을 사용할 수 있는 기능을 제공하는 라즈베리 파이 기반의 다중 방식 인증 시스템을 설계하고 구현하였다. 구현 시스템은 지식기반 인증, 소지기반 인증, 생체기반 인증, 토큰기반 인증 방식을 사용한다. 제안 시스템을 이용하면 경제적인 부담 때문에 별도의 보안 담당자를 두기 어려 운 중소기업에서 활용이 가능한 보안 기능을 제공할 수 있다. 구현된 시스템은 개인용뿐만 아니라 기업에서도 사용 가능 하며, 금융, 게임 등 다양한 분야에 적용할 수 있다.
Users who use smartphone can using knowledge-based authentication, possession-based authentication, biometric-based authentication, and token-based authentication in order to access rights to systems requiring authentication. However, desktop computer users use method only ID and password, which are knowledge-based authentication factors, due to limitations of authentication devices, despite various authentication methods. In this paper, we designed and implemented a raspberry pi based authentication system that provides multiple authentication method of a user's desired type. The implementation system uses knowledge-based authentication, possessive-based authentication, biometric-based authentication, and token-based authentication. The proposed system can provide a security function that can be used by SMEs, which is difficult to hire a security officer due to the economic burden. The implemented system can be used not only for personal use but also for enterprise, and it can be applied to various fields such as finance and game.
FIDO 시스템에서 EEG 신호를 이용한 사용자 인증 방법 KCI 등재
한국융합학회 한국융합학회논문지 제9권 제1호 2018.01 pp.465-471
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 IT기슬과 금융 시스템의 융합으로 생체인식 기술이 사용되기 시작하였다. 이러한 생체 인식 기술인 FIDO(Fast Identity Online) 기술을 이용하여 삼성과 애플은 삼성페이와 애플페이 서비스를 시작하였다. FIDO 인증 기술은 패스워드와 같은 기존 인증 방법을 대체하고 있다. 생체 인식 기술 중 지문인식 기술은 비교적 저렴한 가격의 디바이스와 사용자 거부 반응을 최소화 할 수 있다는 점 때문에 주목받고 있다. 그러나 지문정보의 경우 사용자가 가지고 있는 수가 제한적이며, 외부 공격자에 의해 지문정보가 유출될 경우 재사용할 수 없다는 단점이 있다. 그러므로 본 논문에서는 생체 인식 기술 중 하나인 EEG 신호를 이용하여 사용자를 인증할 수 있는 방법을 제안한다. 제안 논문에서는 기존의 다채널 EEG 디바이스를 사용하지 않고 단채널 EEG 디바이스를 사용하여 편리성을 높였으며, EEG 신호 측정값을 FIDO 시스템에 사용할 수 있는 방법을 제안하였다. 제안 논문에서는 특정 개체 인식 전·후의 EEG 신호를 측정하여 사용자가 특정 개체를 인식하였을 때의 EEG 신호를 사용자 인증 수단을 활용할 수 있는 방법을 제안하였다.
Recently, biometric technology has begun to be used as a fusion of IT technology and financial system. Using this biometric technology, FIDO(Fast Identity Online) technology, Samsung and Apple started Samsung Pay and Apple Pay service. FIDO authentication technology replaces existing authentication methods such as passwords. Among the biometric technologies, fingerprint recognition technology is attracting attention because it can minimize the device and user rejection at a relatively low price. However, fingerprint information has a limited number of users and it can not be reused if fingerprint information is leaked by an external attacker. Therefore, in this paper, we propose a method to authenticate a user using EEG signal which is one of biometrics technologies. W propose a method to use EEG signal measurement value in FIDO system by using convenience channel by using short channel EEG device. And propose a method to utilize EEG signal when the user recognizes a specific entity by measuring the EEG signal before and after recognizing a specific entity.
스마트 폰 이나 스마트 패드와 같은 스마트 기기에서 사용되는 가장 일반적인 사용자 인증 방법은 개인 식별 번호 (personal identification number: PIN)를 입력하는 방법이다. 그러나 기존의 PIN 입력 방법은 각종 공격에 취 약함이 알려져 있다. 본 논문에서는 이러한 문제를 해결하기 위해 스마트 기기에서 발생하는 진동 피드백을 이용하 여 PIN을 입력하는 새로운 방법을 제안한다. 제안된 방법은 진동을 사용하면서도 PIN 입력 시간을 실용적 수준으 로 유지함과 동시에 엿보기 공격(shoulder surfing attack) 및 레코딩 공격(recording attacks)에 대한 저항성 을 개선한다.
무선센서네트워크 기반 차량용 스마트키를 위한 사용자 인증 기법
한국정보통신설비학회 한국정보통신설비학회 학술대회 2011년도 정보통신설비 학술대회 2011.08 pp.434-437
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
4,000원
정보보호는 외부 사이버공격으로부터의 보호와 더불어 내부자료 유출 위험요인을 사전에 식별하여 차단하는 것이 중요하다. 이를 위해 많은 기업과 기관에서는 자료(파일) 자체를 암호화해 외부로 유출 시 내용확인을 불가능하게 DRM(Digital Rights Management) 문서보안 솔루션과 전산장비의 USB포트 등 매체제어를 통해 데이터 유출방지를 위한 DLP(Data Loss Prevention) 솔루션을 대표적으로 운용하고 있다. 이와 같이 내부 자료유출 방지 노력이 중요한 시점에서 관리 사각지대에 놓일 수 있는 단독망 환경의 정보자산 식별과 매체제어와 같은 통제정책 운용이 요구된다. 본 연구에서는 내부 업무망에도 연결되지 않는 단독망 정보자산의 인증을 통해 해당 정보자산에 유일하게 적용되는 매체통제정책 생성-배포-적용 모델을 제시하였으며, 이를 위해 정보자산 획득 시 자동으로 등록되는 자산관리시스템 정보와 연계한 인증기법을 개발하여 정확한 정보자산 식별 및 유연한 매체통제가 가능한 시스템을 설계 및 구축하였다.
Information security is crucial not only for protecting against external cyber-attacks but also for identifying and blocking internal data leakage risks in advance. To this end, many companies and institutions implement digital rights management(DRM) document security solutions, which encrypt files to prevent content access if leaked, and data loss prevention(DLP) solutions, which control devices such as USB ports on computing equipment to prevent data leaks. At a time when efforts to prevent internal data leaks are crucial, there is a growing need for control policies such as device control and the identification of information assets in standalone network environments, which could otherwise fall into unmanaged domains. In this study, we propose a Generation-Distribution-Application model for device control policies that are uniquely applied to standalone information assets that are not connected to internal networks. To achieve this, we developed an authentication technique linked with the asset management system, where information assets are automatically registered upon acquisition. This system allows for precise identification of information assets and enables flexible device control, and we have designed and implemented a system based on these principles.
제로 트러스트 개념을 활용한 지방행정공통정보시스템 사용자 본인 인증 방법 제안
제주대학교 융합과학기술사회연구소 융합과학기술사회연구 제2권 2호 2023.12 pp.27-31
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
디지털 기술의 발전과 코로나19 확산에 따른 재택근무 ‧ 원격회의 증가, 워케이션의 도입 등 공직사회의 업무 환경이 급속하게 변화되고 있다. 이와 더불어, 행정정보시스템의 민간 클라우드 시스템 전환 속도가 빨라짐에 따라, 외부에서 공공기관 내부행정시스템으로의 접근 경로가 다양해지고, 횟수 또한 증가하고 있다. 그러나, 많은 내부행정시스템의 보안 정책은 시대적 흐름에 따라가지 못하고 있다. 특히 지방공무원의 업무 근간이 되는 지방행정공통정보시스템은 구축된 지 오래되어 시스템 노후화 및 신기술 적용이 어려운 실정이다. 대용량 데이터, 고유식별번호 등 행정기관이 관리하는 데이터는 외부 유출 시 범죄의 도구로 활용될 가능성이 높아 행정정보시스템에 접근하는 정보자원(인원, 장치) 에 대한 검증이 무엇보다 중요하다. 이를 위해 최근 새롭게 대두되고 있는 제로 트러스트 개념을 활용한 사용자 본인 인증 방법의 도입이 시급한 상황에서 지방행정공통정보시스템 사용자 본인 인증 방식에 대한 선행 연구와 제로 트러스트 개념을 활용하여 현장에서 바로 적용 가능한 사용자 본인 인증 방법을 제안하고자 한다.
The work environment of the public office is rapidly changing, such as the development of digital technology, the increase of telecommuting and remote conferencing due to the spread of COVID-19, and the introduction of workplaces. As the speed of the administrative information system to the private cloud system is accelerating, the access paths from the outside to the internal administrative system of public institutions are diversified, and the number of times is increasing. However, many internal administrative systems' security policies have not kept up with the trend of the times. In particular, the common information system for local administration, which is the basis of the work of local public officials, has been established for a long time, making it difficult to deteriorate the system and apply new technologies. Data managed by administrative agencies, such as large-capacity data and unique identification numbers, are likely to be used as tools of crime in case of external leakage, so verification of information resources (person, device) accessing the administrative information system is of paramount importance. To this end, it is urgent to introduce a user self-authentication method using the concept of zero trust, which has recently emerged. In this study, we would like to propose a user self-authentication method that can be applied directly in the field by utilizing previous studies on the user self-authentication method of the common information system for local administrations and the concept of zero trust.
인터넷 상의 사용자가 목적지 시스템으로 정보를 전송할 수 있도록 라우팅 정보를 서로 교환하여 라우팅 테이블을 생성하고 변화된 정보를 업데이트 해주는 라우팅 프로토콜 중 가장 중요한 프로토콜이 BGP 이다. 이러한 BGP의 보안 취약점은 TCP/IP의 보안 취약점과 유사하며, 이에 대한 대응기법들이 다수 연구되었으나 기존의 보안 기법들 은 현재 운용중인 BGPv4의 통신과 호환되지 않고, 동시성 문제 등으로 인해 활용되지 못하고 있다. 본 논문은 BGP의 대표적인 보안 취약점에 대한 공격기법인 Fake-IP 공격에 대한 실제 공격실험을 수행하여 공격기법들을 분석하고, Fake-IP 공격을 식별하는 알고리즘을 제안하였다.
The BGP is the most important protocol in routing protocols that exchange routing information to create a routing table and update the changed information so that users on the Internet can transmit information to the destination system. Although the security vulnerabilities of BGP are similar to those of TCP / IP and many countermeasures against them have been studied, the existing security techniques are not compatible with the communication of BGPv4 currently in use and are not utilized due to the concurrency problem and etc. In this paper, we analyze attack techniques by performing real attacks test with Fake-IP attack, which is a representative attack against security vulnerabilities of BGP, and propose a method to identify Fake-IP attack.
단수 계정에 다중 권한 부여가 가능한 다중 해시값 기반의 안전한 패스워드 인증 기법 설계 KCI 등재
대한산업경영학회 산업융합연구(구 대한산업경영학회지) 제21권 제9호 2023.09 pp.49-56
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
개인별 서비스를 위한 ID 기반 인증으로 ID가 식별정보로 활용되고, 패스워드가 사용자 인증에 사용된다. 안전한 사 용자 인증을 위해 패스워드는 클라이언트에서 해시값으로 생성하여 서버에 전달되고 서버에 저장된 정보와 해시값을 비교하 며 인증을 수행한다. 하지만 패스워드의 해시값은 패스워드에서 한 개라도 틀리면 전혀 다른 해시값이 생성되어 사용자 인증 에 실패하여 패스워드에 의한 다양한 기능을 적용할 수 없다. 본 연구에서는 입력된 패스워드의 해시값을 허수를 포함하여 여 러 개 생성하고 서버에 전송해서 인증을 수행한다. 또한 제안 기법에서는 여러 권한을 가진 사용자가 하나의 계정으로 다양한 권한을 부여받을 수 있도록 패스워드에 따라 권한을 차등적으로 부여할 수 있다. 제안 기법을 통해 허수 패스워드를 생성함으 로써 엿보기 공격을 차단하고, 패스워드 기반으로 권한을 부여하므로 다양한 권한을 가진 사용자에게 편리성을 제공할 수 있다.
ID is used as identifying information and password as user authentication for ID-based authentication. In order to have a secure user authentication, the password is generated as a hash value on the client and sent to the server, where it is compared with the stored information and authentication is performed. However, if even one character is incorrect, the different hash value is generated, authentication will be failed and cannot be performed and various functions cannot be applied to the password. In this study, we generate several hash value including imaginary number of entered password and transmit to server and perform authentcation. we propose a technique can grants the right differentially to give various rights to the user who have many rights by one account. This can defend shoulder surfing attack by imaginary password and provide convenience to users who have various rights by granting right based on password.
Open Authorization에서의 안전한 사용자 권한 인증 방법에 관한 연구 KCI 등재
한국디지털정책학회 디지털융복합연구 제12권 제8호 2014.08 pp.289-294
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 다양한 웹 서비스와 어플리케이션들이 사용자에게 제공되고 있다. 이러한 서비스들은 인증된 사용자에 한해서 서비스를 제공하기 때문에 사용자는 매번 서비스 별로 인증을 수행해야 하는 불편함을 겪고 있다. 이러한 불 편함을 해결하기 위해 3rd Party 어플리케이션이 웹 서비스에 대하여 제한된 접근 권한을 얻을 수 있게 해주는 OAuth(Open Authorization) 프로토콜이 등장하게 되었다. 이러한 OAuth 프로토콜은 사용자에게 편리하고 유연한 서 비스를 제공하지만 권한 획득에 대한 보안 취약점을 가지고 있다. 그러므로 본 논문에서는 OAuth 2.0 프로토콜에서 발생할 수 있는 보안 취약점을 분석하고 이러한 보안 취약점을 보완한 방안을 제시한다.
Recently, the various web service and applications are provided to the user. As to these service, because of providing the service to the authenticated user, the user undergoes the inconvenience of performing the authentication with the service especially every time. The OAuth(Open Authorization) protocol which acquires the access privilege in which 3rd Party application is limited on the web service in order to resolve this inconvenience appeared. This OAuth protocol provides the service which is convenient and flexible to the user but has the security vulnerability about the authorization acquisition. Therefore, we propose the method that analyze the security vulnerability which it can be generated in the OAuth 2.0 protocol and secure user authority authentication method.
Lagerstroemia speciosa (commonly known as Banaba tree) is a medicinal plant known for its antidiabetic and antioxidant effects, and its demand is increasing as a raw material for dietary supplements in Korea. However, due to its morphological similarity in processed raw materials with other plants such as Diospyros kaki , Eriobotrya japonica , and Lagerstroemia indica , there is a high risk of intentional adulteration during commercial distribution. To address this issue, we developed a rapid and accurate genetic authentication assay methods using Sequence Characterized Amplified Region (SCAR) primers designed based on species-specific nucleotide within the psb A-trn H region of L. speciosa , D. kaki , E. japonica , and L. indica . In this study, we analyzed 14 samples for these four plant species, and the psb A-trn H region were successfully amplified and sequenced. Multiple sequence alignment results revealed several species-specific nucleotide variations, which were subsequently used to design SCAR primers for each species. PCR assays using these primers generated species-specific amplicons ranging from 91 to 402 bp, enabling precise species discrimination. Sensitivity analysis confirmed that the detection limits varied among species, with the assay capable of detecting admixture levels as low as 0.1–1.0%, depending on the species. The SCAR primers-based genetic assay developed in this study provides a rapid and reliable method for the accurate identification of L. speciosa and its morphologically similar species, offering a valuable tool for the quality control and safety assurance of functional plant materials used in herbal and health food products.
DNA 바코드 분석을 통한 한약 및 식품원료로 사용되는 감나무속 식물 유전자 감별법 개발 KCI 등재후보
한약정보연구회 한약정보연구회지 제12권 제2호 2024.12 pp.115-127
Objective: The leaves, fruits, and calyx of persimmon have been used as food ingredients, dietary supplements, and herbal medicines. In the Korean Herbal Pharmacopoeia, Kaki Calyx is described solely as the calyx of Diospyros kaki L.f. According to the Korean Food Standards Codex, the fruits and leaves of D. kaki or D. lotus , and fruits of D. virginiana or D. malabarica , are permitted for use as food ingredients and dietary supplements. However, the leaves and calyx of D. lotus have been frequently adulterated as authentic herbal medicine and resources for dietary supplements. To develop a reliable genetic identification method to distinguish these Diospyros species, we analyzed universal DNA barcode sequences. Methods: To obtain the matK and rbcL sequences of Diospyros species, PCR amplification and sequencing were carried out for D. kaki and D. lotus , and GenBank data were analyzed for D. virginiana and D. malabarica . To identify species-specific nucleotide sequences, the entire matK and rbcL DNA barcode sequences were comparatively analyzed using ClustalW. Results: We identified several species-specific marker nucleotide sequences unique to each Diospyros species, enabling their distinct identification. Additionally, we confirmed the species identification ability of DNA barcode sequences using raw materials distributed in the markets. These results indicate that the mat K and rbc L sequences provide useful genetic information to identify Diospyros species. Conclusions: We successfully developed distinct molecular markers useful for Diospyros species, allowing their differentiation based on two universal DNA barcode sequences. Therefore, the matK and rbcL sequences are significant as valuable tools for authenticating Diospyros species, including Kaki Calyx.
사용자의 손가락별 Stroke 특성을 이용한 PC 기반 사용자 지속적 인증 방법 및 시스템 KCI 등재
한국차세대컴퓨팅학회 한국차세대컴퓨팅학회 논문지 Vol.19 No.2 2023.04 pp.114-130
사용자의 행동을 기반으로 지속적 인증을 수행 하는 생체인식 기술은 디바이스 종류와 입력장치, 센서의 종류에 따 라 다양한 연구가 진행되어왔다. 모바일 디바이스에서의 지속적 인증은 다양한 센서를 이용하여 사용자 행동을 인식 하고 인증하는 방식으로 연구되어 왔다. 이에 반해, 센서가 다양하지 않은 PC 기반의 지속적 인증은 키보드나 마우 스의 입력 패턴에서 피처를 추출하여 분석하는 방식으로 연구가 진행되고 있다. 본 논문에서는 PC에서 qwerty 키 보드로 입력하는 사용자의 손가락 별로 피처를 추출하여 지속적 인증에 사용한다. 키보드는 일반적으로 각각의 키를 누르는 양손의 손가락들이 할당되어 있다. 이에, 1개의 키를 누를 때 발생하는 key hold(key1 Down–key 1 Up) latency와 손가락과 손가락 사이의 상호작용에 의해 발생하는 key press(key1 Down-key2 Down latency) latency, key interval(key1 UP–key2 Down latency) latency를 피처로 추출하여 지속적 인증의 정확도를 높였다. 지속적 인증 모델은 SVDD, Decision Tree, CNN을 이용했다. 실험데이터는 각각의 실험자들이 랜덤하 게 나타나는 문장을 입력하는 행위를 통해 수집하고 데이터베이스에 저장했다. 마지막으로 저장된 데이터에서 일반 피처를 추출해 학습한 지속적 인증 모델과 손가락 기반 피처를 추출해 학습한 지속적 인증 모델을 비교하는 실험을 진행했고, 각 모델의 분류 정확도(ACC), ROC Curve와 FRR, FAR의 임계치인 EER를 산출했다. 실험결과 손가 락 기반 피처를 학습한 모델이 일반 피처만을 학습한 모델보다 정확도가 더 높게 나타난 것으로 확인되었다.
Continuous authentication using biometric technology based on user behavior has been studied using various types of devices, input devices, and sensors. Continuous authentication on mobile devices has been studied by recognizing and authenticating user behavior using various sensors. In contrast, continuous authentication on PC-based devices with limited sensors has been studied by extracting and analyzing features from keyboard and mouse input patterns. In this paper, features are extracted based on finger-specific input patterns of users typing on a qwerty keyboard on a PC. The keyboard is typically allocated to the fingers of both hands when pressing each key. Therefore, key hold (key1 Down-key1 Up) latency, key press (key1 Down-key2 Down latency) latency caused by interaction between fingers, and key interval (key1 UP-key2 Down latency) latency are extracted as characteristics to improve the accuracy of continuous authentication. The continuous authentication model uses SVDD, Decision Tree, and CNN, and raw data is collected by conducting experiments where users input random sentences. The verification of the continuous authentication model was conducted by comparing the classification accuracy (ACC), EER which is the threshold of ROC curve and FRR, FAR, and the result showed that using finger-specific input characteristics of the user yielded higher accuracy than the existing research that utilized only general key input characteristics.
안전한 Lora 네트워크를 위한 블록체인(A-PBFT) 기반 인증 기법 KCI 등재
대한산업경영학회 산업융합연구(구 대한산업경영학회지) 제20권 제10호 2022.10 pp.17-24
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
장거리 무선 표준 LPWAN 표준의 비 대역망 기술인 Lora는 내부 단말 인증 및 무결성 검증에 ABP, OTTA 방식과 AES-128 기반 암호 알고리즘(공유키)을 사용한다. Lora는 최근 펌웨어 변조 취약점과 공유키 방식의 암호 알고리즘 구조상 MITM 공격 등에 방어가 어려운 문제가 존재한다. 본 연구는 Lora 네트워크에 안전성 강화를 위해 블록체인을 합의 알고리 즘(PBFT)을 적용한다. GPS 모듈을 활용하여 노드 그룹을 검색하는 방식으로 인증과 PBFT의 블록체인 생성과정을 수행한 다. 성능분석 결과, 새로운 Lora 신뢰 네트워크를 구축하고 합의 알고리즘의 지연 시간이 개선했음을 증명하였다. 본 연구는 4차 산업 융합연구로써 향후 Lora 장치의 보안 기술 개선에 도움이 되고자 한다.
Lora, a non-band network technology of the long-distance wireless standard LPWAN standard, uses ABP and OTTA methods and AES-128-based encryption algorithm (shared key) for internal terminal authentication and integrity verification. Lora’s recent firmware tampering vulnerability and shared-key encryption algorithm structure make it difficult to defend against MITM attacks. In this study, the consensus algorithm(PBFT) is applied to the Lora network to enhance safety. It performs authentication and PBFT block chain creation by searching for node groups using the GPS module. As a result of the performance analysis, we established a new Lora trust network and proved that the latency of the consensus algorithm was improved. This study is a 4th industry convergence study and is intended to help improve the security technology of Lora devices in the future.
한국정보통신설비학회 한국정보통신설비학회 학술대회 2015년도 정보통신설비 학술대회 2015.08 pp.7-9
※ 기관로그인 시 무료 이용이 가능합니다.
3,000원
Brainwave authentication has been researched for over a decade, yet it is not readily available to be used in practical access control systems. In this paper a new duress detection functionality using brainwave is proposed. Existing duress detection methods involve concatenating a duress code to pass a covert message about the situation. Such methods help the user to alert authorities without being distinguished as non-cooperating victim by the attacker. However, they require the victim to remember the duress code in stressful situation. The proposed system detects user stress situation from his brainwave signal collected for login. The method meets the requirements stated in the previous duress detection methods. In addition, unlike previous methods, the user is not required to remember any additional code to alert the authorities about his situation.
RFID 환경에서 보안 통신을 위한 안전한 인증 방안에 관한 연구 KCI 등재후보
한국융합보안학회 융합보안논문지 제5권 제3호 2005.09 pp.59-65
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
네트워크와 무선통신의 발달에 힘입어 유비쿼터스 시대가 도래하고 있다. 유비쿼터스 컴퓨팅에서의 시큐리티 문제는 인터넷 시대의 시큐리티 문제보다 복잡하며 공격이 용이하나 대책 수립은 현재로서는 굉장히 초보수준이다. 유비쿼터스 컴퓨팅 환경은 기존의 보안 기술로 적용하기에는 많은 다른점을 가지고 있다. Confidence level이 서로 다른 인증 방식이 필요하거나 또한 사용자의 위치에 대한 프라이버시도 만족해야 하는 인증 방식이 필요하다. 기존의 대표적인 인증 방식인 kerberos 인증 방식은 사용 범위가 지정 워크스테이션으로 국한되거나 클라이언트의 안전한 환경을 가정하여 이용되지만 유비쿼터스 컴퓨팅 환경에서는 이러한 조건을 제공하기가 어렵기 때문에 새로운 보안메커니즘이 필요하다. 또한 유비쿼터스 컴퓨팅 환경은 무선전송이나 이동통신에 크게 의존하게 되므로 이들 통신 구간에 대한 보안이 중요한 문제로 대두되고 있다. 이에 본 논문에서는 무선 인증서를 이용하여 사용자 인증 및 기밀성 제공을 위한 유비쿼터스 환경의 SSL을 적용 방안을 연구하여 실험을 통하여 결과를 증명하고자 한다. 즉, 유비쿼터스 환경에서 기밀성 및 인증을 제공하는 기법을 제안한다.
Ubiquitous computing environment has a lot of different things as for applying existing security technical. It needs authentication method which is different kinks of confidence level or which satisfies for privacy of user's position. Using range localizes appoint workstation or it uses assumption which is satify environment of client in Kerberos authentication method which is representation of existing authentication method but it needs new security mechanism because it is difficult to offer the condition in ubiquitous computing environment. This paper want to prove the result which is authentication method for user authentication and offering security which are using wireless certificate from experiment in ubiquitous environment. Then I propose method which is offering security and authentication in ubiquitous environment.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.