Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 27
No
1

4,000원

최근 인터넷 기반 서비스에서 사용자 인증 과정의 취약점을 이용한 공격이 급증하고 있다. 특히, 인터넷 뱅킹과 인터넷전화가 많이 보급됨에 따라 보안사고가 급증하고 있으며 공격자들의 공격 수법도 점차 지능화 되고 있다. 결국 인터넷뱅킹과 인터넷전화 등의 서비스에서 바이오메트릭 정보와 같이 사용자가 소유하고 있는 개인 고유 정보 등을 이용하여 보다 강화된 인증을 제공할 필요가 있다. 따라서 본 연구에서 제시하는 B-OTP 기술은 바이오 메트릭 정보(Biometric Data)를 OTP 방식과 접목하는 기술로 기존 인터넷 서비스에서의 사용자 인증을 강화시킬 수 있는 방법이다. 사용자가 입력한 바이오메트릭 정보를 이용하여 생성된 B-OTP 값을 이용할 경우 인터넷뱅킹과 인터넷전화 서비스 등의 보안성을 높일 수 있을 것으로 기대된다.

Diverse kind of attack using the vulnerability of user authentication on Internet service is announced recently. Especially, security accidents on the Internet banking service and Internet telephony service(SIP) are increased rapidly. Attack skills are also evolved into intelligent mechanism. Therefore, more enhanced authentication mechanism is required on existing Internet banking and telephone services for preventing those kinds of attacks using personal identity information such as biometric data. In this research, the proposed B-OTP mechanism can be used to enhance security on a user authentication procedure by combining biometric data with existing OTP mechanism. As a result, the security on internet banking and Internet telephone service will be more improved by using proposed B-OTP mechanism.

2

Predicting the Adoption of Health Wearables with an Emphasis on the Perceived Ethics of Biometric Data KCI 등재 SCOPUS

Tahereh Saheb, Tayebeh Saheb

한국경영정보학회 Asia Pacific Journal of Information Systems 제31권 제1호 2021.03 pp.121-140

※ 기관로그인 시 무료 이용이 가능합니다.

5,500원

The main purpose of this research is to understand the strongest predictors of wearable adoption among athletes with an emphasis on the perceived ethics of biometric data. We performed a word co-occurrence study of biometrics research to determine the ethical constructs of biometric data. A questionnaire incorporating the Unified Theory of Acceptance and Use of Technology (UTAUT), Health Belief Model and Biometric Data Ethics was then designed to develop a neural network model to predict the adoption of wearable sensors among athletes. Our model shows that wearable adoption’s strongest predictors are perceived ethics, perceived profit, and perceived threat; which can be categorized as professional stressors. The key theoretical contribution of this paper is to extend the literature on UTAUT by developing a predictive modeling of factors affecting acceptance of wearables by athletes, and highlighting the ethical implications of athlete’s adoption of wearables.

3

바이오인식 정보의 안전한 활용 및 보호방안

송창규, 김영진, 전명근

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.31 No.4 2021 pp.841-852

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

바이오인식은 각 개인의 신체적, 생리적, 행동적 특성을 자동화된 장치로 측정하여 이를 등록한 후, 개인을 식별하거나 인증하는 기술을 말한다. 그런데, 여기서 사용되는 바이오인식 정보는 개인을 식별할 수 있으므로 개인정보에 해당된다. 따라서, 이것이 유출되거나 오용되었을 때 정보주체의 프라이버시에 부정적인 영향을 미치게 된다. 본 논문에서는 바이오인식 정보와 관련된 국내의 법적 현황을 살펴보고 이와 관련된 침해현황을 살펴본다. 이어서 대표적인 바이오인식 응용 모델을 도출하고, 각각에 대한 취약점 및 대책 방안을 논의한다. 최종적으로 바이오인식 시스템의 개발자와 서비스제공자를 위해 바이오인식 정보의 보호를 위한 수칙을 제시한다.

Biometric recognition refers to a technology that identifies or verifies an individual after registering each individual's physical, physiological, and behavioral characteristics with an automated device. However, the biometric data used here corresponds to personal information since it can identify an individual. Therefore, when it is compromised or misused, it negatively affects the privacy of the data subject. In this paper, we review the current status of domestic laws related to biometric information and the status of infringements related to this. And then, some biometric application models are derived and vulnerabilities and countermeasures for each model are discussed. Finally, for the developer and service provider of the biometric system, protection guidance is presented.

4

DNA 프로필 데이터 교환 국제표준 가이드라인 설정 연구

박현철, 한병진, 권영빈, 한면수

한국법과학회 한국법과학회지 제12권 제1ㆍ2호 2011.09 pp.1-8

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

5

Biosensor Interface: Interactive Media Art Using Biometric Data SCOPUS

Dongjo Kim, Hyunggi Kim

보안공학연구지원센터(IJBSBT) International Journal of Bio-Science and Bio-Technology Vol.6 No.1 2014.01 pp.129-136

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Recently, as biomimetics is applied to design and engineering and receive attention from the society, its artistic value also is receiving people’s interest. Data visualization is expressed regarding brain wave, iris, fingerprint, pulse, body fat, etc. Particularly, developing of convergence contents, biometric data is also influencing development of affective data. This study is focused on research on media art using biometric data, and an artwork using pulse data was created as an example based on review of relevant research. By developing the process in which the audience sees their real-time biometric data, aesthetic contemplation according to sophistication of emotional contents will be studied.

6

Development of a Smart Wearable Device for Human Activity and Biometric Data Measurement SCOPUS

Hyun-Sik Kim, Jong-Soo Seo, Jeongwook Seo

보안공학연구지원센터(IJCA) International Journal of Control and Automation Vol.8 No.11 2015.11 pp.45-52

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

This paper presents a smart wearable device cooperating with smartphones to measure and utilize human activity and biometric data such as motion tracking, photoplethysmography (PPG), skin temperature (SKT), and galvanic skin response (GSR). It is comfortably designed and implemented as a wristband-type device and provides wireless Bluetooth Low Energy (BLE) connection to smartphones based on the Android operating system. According to the predefined packet format and control commands, the proposed smart wearable device can transmit measured sensing data and update its firmware. Implemention results verify the feasibility and usability of the proposed smart wearable device. It can be applied to various healthcare and wellness services or even emotional game applications.

7

A Study on the Security Technology of Real-time Biometric Data in IoT Environment

Shin, Yoon-Hwan

[Kisti 연계] 한국컴퓨터정보학회 Journal of the Korea society of computer and information Vol.21 No.1 2016 pp.85-90

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

In this paper, the biometric data is transmitted in real time from the IoT environment is runoff, forgery, alteration, prevention of the factors that can be generated from a denial-of-service in advance, and the security strategy for the biometric data to protect the biometric data secure from security threats offer. The convenience of living in our surroundings to life with the development of ubiquitous computing and smart devices are available in real-time. And is also increasing interest in the IOT. IOT environment is giving the convenience of life. However, security threats to privacy also are exposed for 24 hours. This paper examines the security threats to biological data to be transmitted in real time from IOT environment. The technology for such security requirements and security technology according to the analysis of the threat. And with respect to the biometric data transmitted in real time on the IoT environment proposes a security strategy to ensure the stability against security threats and described with respect to its efficiency.

8

Robust SVM Design for Multi-Class Classification - Application to Biometric data -

조민국, 박혜영

[Kisti 연계] 한국정보과학회 한국정보과학회 학술대회논문집 2005 pp.760-762

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Support vector machine(SVM)은 졸은 일반화 능력을 가진 학습시스템으로, 최근 다양한 패턴 인식 분야에서 적용되고 있다. SVM은 기본적으로 이진 분류기이므로 두 개 이상의 클래스를 분류하기 위해서는 다중 클래스 분류가 가능한 형태로의 설계 방법이 필요하다. 이를 위해 각 클래스별로 독립적인 SVM들을 만들어 결과를 병합하는 방식이 주로 사용되어 왔다. 그러나 이러한 방법은 클래스의 수는 않고 한 클래스 내의 데이터의 수가 많지 않은 경우에는 SVM의 일반화 성능을 저하시키고 노이즈에 민감해지는 문제점을 가지고 있다. 이를 해결하기 위해 본 논문에서는 각 클래스내의 데이터간의 유사도 측정을 위한 통계적 정보를 안정적으로 추출하기 위해 두 데이터의 쌍을 입력으로 받는 새로운 SVM 설계 방법을 제시한다. 제안한 방법을 실제 생체인식 데이터에 적용한 실험에서 기존의 방법보다 우수한 분류 성능을 보임을 확인할 수 있었다.

9

Robust SVM Design for Multi-Class Classification - Application to Biometric data -

조민국, 박혜영

[Kisti 연계] 한국정보과학회 한국정보과학회 학술대회논문집 2005 pp.760-762

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Support vector machine(SVM)은 졸은 일반화 능력을 가진 학습시스템으로, 최근 다양한 패턴 인식 분야에서 적용되고 있다. SVM은 기본적으로 이진 분류기이므로 두 개 이상의 클래스를 분류하기 위해서는 다중 클래스 분류가 가능한 형태로의 설계 방법이 필요하다. 이를 위해 각 클래스별로 독립적인 SVM들을 만들어 결과를 병합하는 방식이 주로 사용되어 왔다. 그러나 이러한 방법은 클래스의 수는 않고 한 클래스 내의 데이터의 수가 많지 않은 경우에는 SVM의 일반화 성능을 저하시키고 노이즈에 민감해지는 문제점을 가지고 있다. 이를 해결하기 위해 본 논문에서는 각 클래스내의 데이터간의 유사도 측정을 위한 통계적 정보를 안정적으로 추출하기 위해 두 데이터의 쌍을 입력으로 받는 새로운 SVM 설계 방법을 제시한다. 제안한 방법을 실제 생체인식 데이터에 적용한 실험에서 기존의 방법보다 우수한 분류 성능을 보임을 확인할 수 있었다.

10

개인정보 보호 법제의 법적 문제― 금융개인정보와 생체개인정보를 중심으로 ―

오길영

[NRF 연계] 민주주의법학연구회 민주법학 Vol.53 2013.11 pp.221-248

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

이 글은 현행 개인정보 보호 법제의 문제점을 지적하기 위한 글이다. 특히 금융개인정보와 생체개인정보에 주목하고 있다. 이 두 가지 개인정보의 경우, 나날이 그중요성이 높아감에도 불구하고 입법은 사실상 공백상태이기 때문이다. 따라서 글의 전반부에는 금융개인정보와 관련한 현행 법제의 문제점을 분석하고,이를 미국의 입법과 비교・검토하는 형식으로 구성한다. 금융당국이 미국 입법과 비교를 해 보아도 우리 법제의 보호제도가 우월하다는 입장을 밝혔기 때문이다. 한편 글의 후반부에서는 생체개인정보와 관련한 구체적인 쟁점사항을 검토하는형식으로 진행한다. 생체개인정보와 관련하여 가장 큰 난점은 개인정보보호법상의‘민감정보’에 해당하지 않는다는 것인데, 그 덕분에 ‘가이드라인’을 통한 자율적 규제에 의존하고 있는 상황이다. 이러한 문제에 관하여 필자는, 구체적인 입법적 대응방안을 제시한다. 금융개인정보의 경우, 우리 개인정보 보호 법제와의 조화를 위한 ‘옵트인’ 또는 세밀한 보호장치가 담보된 상황에서의 ‘옵트아웃’제도의 실시가 바람직하다는 것이 그것이다. 생체개인정보의 경우, 단순히 ‘민감정보’에의 편입으로 해결할 것이 아니라 생체개인정보에 관한 독립적인 입법체계를 새로이 구성하는 것이 바람직하다는 것이 이글의 결론이다.

This paper aims at pointing out several problems on the current legislative system of personal data protection. The most problematic are personal financial data and personal biometric data, since there is no appropriate regulation but the importance of both data is increasing. The first part of this article is thus allotted to analyzing the current legislative system about personal financial data, and compares it with the regulation thereon of the United States. That is because financial authorities of Korea have clarified their position that the Korean legislations are more protective than those of the United States. In the latter part of this article, then, I studied the controversial issues related to personal biometric data in detail. The biggest problem about them is that they are excluded from the definition of ‘sensitive information’ of the Personal Data Protection Act. Therefore those data are being regulated by a Guideline called a voluntary regulation. With regard to these problems, I tried to construct a legislative resolution in detail. Regarding personal financial data, I suggested either an ‘Opt in’ rule which is accordance with the principle of the current Personal Data Protection Act, or a very elaborate ‘Opt out’ rule which has reliable protection mechanisms. Concerning personal biometric data, I emphasized the need of a new legislative system which is specialized and independent, instead of incorporating those data into the definition of the ‘sensitive information’.

11

감성 인식을 위한 생체 정보 수집

황세희, 박창현, 심귀보

[Kisti 연계] 한국지능시스템학회 한국지능시스템학회 학술대회논문집 2005 pp.353-356

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

감성이란 외부의 여러 가지 감각적인 자극에 대해 직관적이고 반사적으로 발생하는 반응이다. 감성에는 희로애락과 같은 다양한 감정이 포함된다. 감성은 개인과 환경의 영향을 받는 동시에 사회$\cdot$문화적인 영향에 의해 달라지는 종합적이고 복합적인 느낌이기 때문에 명확하게 표현하기 어렵다. 개인적인 차이는 있지만 인간의 감정은 다양한 행동이나 신체적 혹은 생리적인 반응으로 표출되기 때문에 이러한 다양한 반응을 이용해서 인간의 감정을 유추할 수 있다. 행동이나 신체적인 표현은 개인과 환경, 사회$\cdot$문화적인 영향에 따라 다양하게 나타나기 때문에 이를 정량화하기에는 힘든 부분이 있다. 반면 감정 상태에 따른 생리적인 반응은 여러 사람들에게서 공통적인 부분을 찾을 수가 있다. 본 논문에서는 감정에 따라 다양하게 나타나는 인간의 생리적인 반응 정토를 측정하고 이들의 공통점에 따라 생리적 반응을 통해 인간의 감정에 유추할 수 있는 공학적 모델을 제시하고자 한다.

12

안면인식기술을 이용한 생체인식정보의 활용과 그 한계 – 실종아동 등 신원확인을 위한 법제를 중심으로 –

김송옥, 권건보

[NRF 연계] 한국헌법학회 헌법학연구 Vol.27 No.1 2021.03 pp.115-163

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

안면인식기술이 국가에 의한 감시의 도구로 전락할 위험성에 따라 그 확대에 대해서는 논쟁적이다. 중국이 이 기술을 전면적으로 사용함으로써 인권침해국가라는 비난을 받고 있는 가운데, 미국이나 유럽에서도 이 기술의 금지 또는 확장을 놓고 활발한 논의가 진행 중이다. 감시의 위험성을 심각하게 받아들여야 하는 이유는 감시의 효과가 곧 기본권 제한과 연결되기 때문이다. 그것은 사생활의 비밀과 자유에 대한 제한만이 아니라 표현의 자유, 일반적 행동의 자유 등 여러 기본권들을 동시에 제한할 수 있다. 특히 CCTV에 안면인식기술이라는 AI 기술을 적용할 경우, 감시는 원격에서 실시간으로 정보주체가 인식하지 못한 상태에서 이루어질 수 있다는 점에서 그 위험성은 높아진다. 그러나 유럽연합의 기본권보호청(FRA)이 안면인식기술에 관한 보고서에서 지적하는 바와 같이 이러한 기술은 또한 테러와 같은 상황에 적절히 대응하거나 실종아동을 신속하고 효율적으로 찾는 방법이 될 수도 있다는 점에서 전면적인 금지는 어려울 전망이다. 또한 수집의 편리성이라는 이 기술의 효용으로 인하여 출입국심사와 치안 등 제한적인 영역에서는 이미 사용 중에 있다. 이러한 배경 하에 본 논문은 실종아동을 찾기 위한 신속하고 효율적인 대응의 필요성에 착안하여, 안면인식기술을 적용한 CCTV 영상 처리시스템을 도입할 경우 제기될 수 있는 여러 위험성과 법적 문제점을 진단하고, 이러한 위험성을 차단하고 문제점을 해결해 나갈 수 있는 방안을 제시하고자 하였다. 이를 위해 유럽연합의 GDPR를 포함한 개인정보보호법제를 참고하고, 안면인식기술에 관한 유럽연합내 최근 논의들을 따라가며 참고할만한 시사점을 얻고자 하였다. 어떠한 선한 목적의 정보처리시스템이라도 그 오용과 남용의 위험성은 항시 존재하므로, 시스템의 투명성 제고를 위해 법률에 근거한 시스템 도입 및 운영은 필수적이라고 하겠다. 나아가 목적제한의 원칙, 데이터최소화의 원칙 등 개인정보처리의 기본원칙들을 준수하도록 하고 정보주체의 열람권, 처리거부권, 정정권 등 개인정보보호권을 보호하며, 이러한 원칙들이 준수되고 있는지와 아울러 정보주체의 권리들이 제대로 보장되는지에 관한 정기적인 개인정보 영향평가와 감독기구에 의한 모니터링이 뒷받침되어야 할 것이다.

The expansion of facial recognition technology is controversial depending on the risk of becoming a tool for surveillance by the state. While China is accused of being a human rights violation state by the full use of the technology, active discussions are underway over the ban or expansion of the technology in the U.S. and European Union. The reason why the risk of surveillance should be taken seriously is that the effect of surveillance is linked to fundamental rights violations. It can simultaneously limits not only privacy secrets and freedom, but also various fundamental rights such as freedom of expression and general freedom of action. In particular, if facial recognition technology, one of AI technology, is applied to CCTV, the risk of surveillance increases because it can be done remotely and in real time without the data subject recognition. But as the European Union Agency for Fundamental Rights(FRA) points out in its report on facial recognition technology, it is also unlikely to be a full ban, given that it could be a quick and efficient way to respond to situations like terrorism or find missing children. In addition, due to the utility of this technology, the convenience of capture, it is already in use in restricted areas such as immigration and security. Under this background, this paper aimed at diagnosing various risks and legal problems posed by the introduction of CCTV systems applied with facial recognition technology, and suggesting ways to prevent the risks and solve the problems. To this end, it was intended to refer to the EU’s data protection laws, including GDPR, and to follow recent discussions within the European Union on facial recognition technology to obtain some useful implications. Even data processing systems for good purposes, there is always a risk of misuse and abuse, so it is essential to operate the system based on law to improve transparency in its introduction and operation. Furthermore, it should comply with the basic principles relating to personal data processing, such as the principle of purpose limitation and data minimization, protect the right of data subjects, such as right of access, right to object and right to rectification. Also, regular privacy impact assessments and monitoring by supervisory bodies should be conducted on whether these principles are being followed and whether the rights of data subjects are properly guaranteed.

13

인공지능 학습에서 생체정보 처리의 구조적 위험과 형사법적 통제

이경열, 임채훈

[NRF 연계] 강원대학교 비교법학연구소 강원법학 Vol.83 2026.05 pp.225-264

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

인공지능 기술의 발전에 따라 고품질의 학습 데이터를 확보하기 위하여 대규모의 얼굴·음성과 같은 생체정보가 데이터로 편입되는 경우가 빈번하게 발생하고 있다. 하지만 생체정보는 개인의 신체적·인격적 동일성을 표시하는 특성을 지니고 있으며, 한 번 유출되는 경우 그 변경·회수가 사실상 불가능하다는 점에서 비가역적인 특성이 있다. 이러한 생체정보의 특성과 함께 인공지능 학습의 반복적인 데이터 처리와 그러한 과정에서 발생하는 정보의 집적(集積)에 따라 인공지능 모델 내부에 생체정보가 내재화되고 재결합하면서 장기적으로는 인공지능 모델이 작동하는 과정에서 생체정보가 드러나는 위험이 증폭된다. 이런 경우 정보 주체는 인공지능의 블랙박스 현상과 정보 비대칭으로 인하여 자신의 생체정보가 학습에 포함되었는지조차 인식하기 어려우며, 사후적으로 생체정보를 배제하거나 통제하는 것 역시 구조적으로 곤란하다. 그런데 이러한 위험을 이유로 생체정보 학습 전반을 포괄적으로 금지한다거나 위험 발생의 가능성만을 근거로 예방형법을 통하여 문제를 해결하고자 한다면, 이는 형사법 원칙에 부합하지 아니하고 최후 수단으로서의 형법이 퇴색될 수 있다. 이에 본 논문은 인공지능 학습 단계의 생체정보 처리를 단순한 개인정보 침해의 문제가 아닌, 더 강한 보호가 필요한 영역의 특별한 정보로 재구성함과 동시에 허용된 위험과 주의의무의 규범화를 중심으로 사회적으로 허용이 가능한 학습행위의 조건을 설정하고, 그러한 조건에 부합하지 아니하고 위험을 증대하는 경우 책임을 부과하는 통제모형을 제시한다. 나아가 현행 개인정보보호법상의 생체정보 관련 정의 체계와 인공지능 개발자에 대한 책임 규정의 한계를 확인하고, 실질적인 위험통제 요건을 중심으로 개선 방안을 도출한다. 특히 딥페이크, 딥보이스와 같은 인공지능의 범죄적 이용에 적합하도록 모델·도구를 설계·제공하거나 인공지능 모델의 고위험성을 인지하면서도 안전조치·검증 절차를 의도적으로 배제하고 배포를 강행하는 개발자·운영자의 행위에 초점을 맞추어, 이를 고의적 위험증대 행위로 특정하여 악의적 개발자의 행위를 억제하고자 하는 형사책임 귀속을 정밀화한다. 결론적으로 생체정보의 보호와 인공지능의 발전 간의 조화가 이루어지도록 목적 중심의 형식적 적법성 판단을 넘어 위험통제 의무의 명문화와 책임 귀속의 정밀화를 결합하여 형사법적 개선 방향을 제시한다.

In order to secure high-quality learning data with the development of artificial intelligence technology, there are frequent cases where biometric information such as large-scale face and voice is incorporated into data. However, biometric information is an indicator of an individual's physical and personal identity, and such biometric information has irreversible characteristics that it is virtually impossible to change or recover once leaked. Along with these characteristics of biometric information, the risk of revealing biometric information in the long run of the artificial intelligence model is amplified by the repetitive data processing of artificial intelligence learning and the accumulation of information generated in the process. At this time, it is difficult for the data subject to recognize even whether his or her biometric information is included in the learning due to the black box phenomenon and information asymmetry, and it is also structurally difficult to exclude or control biometric information afterwards. However, if the entire learning of biometric information is comprehensively prohibited due to these risks, or if the problem is solved through the preventive criminal law due to the possibility of risks, this does not conform to the principles of criminal law and can lead to the disappearance of criminal law as the best means. Therefore, this paper presents a control model that establishes the conditions for socially acceptable learning behavior, focusing on the standardization of permitted risks and duty of care, and imposes responsibility only when the risk is increased without meeting those conditions. Furthermore, by identifying the limitations centered on the purpose requirements of special cases for processing pseudonym information under the current Personal Information Protection Act and reorganizing them around practical risk control requirements, we intend to derive improvement measures so that a smoother development environment can be formed for developers. In addition, responsibility attribution is refined by focusing on the actions of developers and operators. In particular, the act of designing and providing models and tools to suit the criminal use of artificial intelligence such as deepfake and deep voice, or deliberately excluding safety measures and verification procedures while recognizing the high risk of artificial intelligence models, and forcing distribution is intended to suppress malicious developer behavior by specifying it as an act of increasing risk. In conclusion, this paper proposes a direction for improving criminal law by combining the stipulation of risk control obligations and the precision of responsibility attribution beyond the purpose-oriented formal legitimacy judgment so that the protection of biometric information and the development of artificial intelligence can be harmonized.

14

형사절차에서의 생체정보 수집 및 활용과 그 위험성

박성민

[NRF 연계] 한국형사정책학회 형사정책 Vol.37 No.1 2025.04 pp.233-266

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

생체정보(biometric data)는 특정 기술 처리를 통해 얻어진 자연인의 신체적, 생리적, 행태적 특성과 관련된 정보로서, 자연인을 고유하게 식별할 수 있도록 확인하는데 사용되는 정보를 의미한다. 생체정보는 DB에 저장된 인물정보와 동일한지 여부를 확인하기 위한 생체정보‘인식’ 이외에 권리의무관계나 법률관계의 존부를 확인하거나 그 진위여부를 검증하기 위한 생체정보‘인증’에도 사용된다. 특히 형사절차에 있어 생체정보는 수사절차에서 피의자의 신병을 확보하는데 사용되고, 공판절차에서 증거방법으로서 기능하며, 형집행절차에서는 보안처분의 집행 등에 활용된다. 문제는 우리 수사기관이 특정사건의 형사절차 이외에 범죄예방 및 피해자보호라는 특수한 형사정책적 목적 달성을 위해 범죄자의 생체정보를 활용하고 있다는 점이다. 이 글에서는 경찰청의 훈령 및 예규를 분석함으로써, 특별한 법적 근거 없이 9개 범죄군의 범죄자의 생체정보 등 민감정보를 거의 반영구적으로 관리하고 있다는 점, 수집정보의 범위에 대한 수범자들의 예측가능성이 제한된다는 점 등의 문제점을 확인하였다. 또한 개정 경찰관직무집행법에 근거한 경찰착용기록장치사용으로 범죄자의 생체정보 뿐 아니라 일반인의 생체정보도 수집될 우려가 커지고 있다는 점도 지적하였다. 이 글에서는 필자는 이와 같이 형사절차에서 생체정보 수집 및 활용과정을 확인하면서 그 위험성을 분석하고 수집 및 활용과정에서 고려되어야 할 점을 제시하였다. 실제 형사소송절차에서는 인공지능감시체계구축에 국민적 저항감이 없고, 법제도적 근거를 마련하는 것도 어렵지 않다. 다만, 생체정보 수집이 범죄예방이나 피해자보호를 목적으로 하는 경우에는 피의자가 아닌 일반인을 대상으로 하는 경우가 있으므로, 국민적 합의 및 법적 근거, 인권영향평가 등 고려해야 할 요소가 많음을 확인하였다.

Biometric data refers to information related to the physical, physiological, and behavioral characteristics of a natural person obtained through specific technological processing, and is used to uniquely identify a natural person. Biometric data is used for biometric information 'recognition' to check whether the data is the same as the personal information stored in the DB, and is also used for 'authentication' to check the existence of rights and obligations or to verify its authenticity. The problem is that our investigative agencies are using criminal's biometric data to achieve special criminal policy goals such as crime prevention and victim protection in addition to criminal procedures for specific cases. In this article, by analyzing the instructions and regulations of the National Police Agency, it is found that biometric data of criminals in 9 crime groups is managed semi-permanently without special legal basis, and that the public's predictability regarding the scope of collected information is limited. It was also pointed out that there is a growing concern that biometric data of the general public may be collected through the use of police body camera based on the Act On The Performance Of Duties By Police Officers. In this article, the author looked at the process of collecting and utilizing biometric information in criminal proceedings, analyzed its risks, and presented points that should be considered in the collection and utilization process. In actual criminal procedures, there is no public resistance to establishing an artificial intelligence surveillance system, and it is not difficult to establish a legal basis. However, when collecting biometric information for the purpose of crime prevention or victim protection, the target may be the general public rather than the suspect, so it was confirmed that there are many factors to consider, such as national consensus, legal basis, and human rights impact assessment.

15

생체 데이터를 활용한 Role-Playing Game (RPG) 개발

한성욱, 고명진, 함범진, 최성용

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2023 pp.965-966

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 논문은 사용자의 생체 데이터를 기반으로 하는 Role-Playing Game(RPG)의 개발과정과 특징에 관하여 다룬다. 온라인 게임과 실제 생체데이터를 결합하여 게임 이용을 통한 건강 습관 촉진을 목표로 한다. 사용자의 생체 데이터는 게임 내 캐릭터의 능력치로 환산되며, 게임 플레이를 통해 건강한 생활습관과 운동 동기부여가 이루어진다. 교육과 의료 분야에서의 활용 가능성도 탐색되며, 미래 지향적인 게임의 새로운 방향성을 제시한다.

16

유럽 AI법에 따른 생체정보의 활용과 보호에 관한 고찰

이권일

[NRF 연계] 경북대학교 법학연구원 법학논고 Vol.85 2024.04 pp.57-82

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

유럽에서는 생체인식정보 기술의 발달과 AI 기술의 발달, 그리고 이 두가지 기술이 결합되어서 나타나게 되는 기본권 침해상황을 심각하게 생각하여 이를 규제하기 위한 법제를 만들기 위해 노력해왔다. 특히 2021년 인공지능법안이 유럽연합 집행위원회에서 유럽연합 의회에 제안되었고, 3년 이상의 기간동안 이에 대해 유럽의 학계와 정치계, 시민사회와 각 회원국에서 뜨겁게 논의된 결과 지난 2024년 3월 유럽연합 의회에서 압도적 다수로 인공지능법이 통과되었고, 일부 조항은 6개월 후부터, 2026년부터는 전면 시행된다. 이는 소위 브뤼셀 효과로 인하여 GDPR과 같이 세계에 영향을 미치는 인공지능 규제법으로 기능할 것으로 보인다. 이번에 통과된 인공지능법의 가장 큰 특징 중의 하나는 AI 기술을 이용한 생체인식정보의 처리를 강하게 규제하고자 한다는 점이다. EU에서는 생체인식기술과 AI기술이 결합하였을 때 발생할 수 있는 대량감시와 추적의 가능성과 이로 인한 일반적 인격권, 사생활의 비밀, 개인정보자기결정권, 평등권 등의 기본권 침해적 상황이 심각할 수 있다는 점에 대한 분명한 인식으로 이를 강하게 규제하고자 한다. 특히 감정인식시스템, 생체 인식 분류 시스템, 실시간 원격 생체 인식 시스템, 사후 원격 생체 인식 시스템 등의 새로운 기술에 대해 개념정의를 하고자 노력하였고, 이를 바탕으로 AI 기술과 생체인식정보가 결합되어 사용되는 경우 이러한 AI 시스템의 실행을 금지하거나 고위험 AI 시스템으로 분류하여 강하게 제한하고자 한다. 앞으로 AI 기술과 생체인식기술을 더욱 발전할 것이고, 이러한 기술이 우리의 삶 속에 우리의 생활을 편리하게 하기 위하여 더 광범위하게 사용될 것이 예측된다. 또한 이러한 기술을 사용하는 시장도 엄청나게 확대될 것으로 예상되는데, 이는 AI법이 AI를 규제하기 위한 법이면서도 목적조항에 인공지능의 활용을 촉진하고 혁신을 지원하기 위한 법이라고 명문으로 규정한 것에서도 알 수 있다. 따라서 이러한 기술의 사용을 전면적으로 금지함으로서 우리의 기본권을 보장한다는 생각은 더 이상 유효할 수 없고, 이러한 기술의 사용으로 인한 부작용을 최소화하는 방안을 마련하고, 이러한 기술의 사용을 어떻게 제한하여야 할 것인지에 대한 논의를 하여야 한다. 이런 점에서 유럽의 AI법이 우리에게 주는 시사점은 분명히 있다. 이러한 기술의 사용은 더욱 확대될 것이고 확대되어야 하는데, 이러한 기술의 사용이 더 유연해질 수 있도록 법제를 개편하는 것과 아울러 개인의 기본권이 더 실효적으로 보장될 수 있는 조화로운 방법을 모색하여야 할 것이다.

In Europe, the development of biometric data technology and the development of AI technology, and the violation of fundamental rights caused by the combination of these two technologies, have been seriously considered, and efforts have been made to create legislation to regulate them. In particular, the Artificial Intelligence Act was proposed to the European Parliament by the European Commission in 2021, and after more than three years of heated discussions in European academia, politics, civil society, and member states, the Artificial Intelligence Act was passed by the European Parliament with an overwhelming majority in March 2024, and some provisions will be implemented in six months, and all provisions will be implemented in 2026. Due to the so-called Brussels effect, it is expected to function as an AI regulatory law with global impact like the GDPR. One of the most significant features of the AI Act is that it seeks to strongly regulate the processing of biometric data using AI technology. The EU clearly recognizes the potential for mass surveillance and tracking that can arise from the combination of biometrics and AI technologies, and the potential for serious violations of fundamental rights such as the personality right, the right to privacy, the right to self-determination of personal information, and the right to equality. In particular, the Act endeavors to conceptualize new technologies such as emotion recognition systems, biometric categorisation systems, remote biometric identification systems, real-time remote biometric identification systems, and post remote biometric identification systems, and based on this, it seeks to prohibit the practices of such AI systems or classify them as high-risk AI systems and strongly restrict them when AI technology and biometric data are used in combination. It is expected that AI technology and biometrics will be further developed in the future, and that these technologies will be used more widely in our lives to make our lives easier. The market for the use of these technologies is also expected to expand tremendously, which is evident from the fact that the AI Act is intended to regulate AI, but the purpose clause clearly states that it is intended to promote the utilization of AI and support innovation. Therefore, the idea of ensuring our fundamental rights by prohibiting the use of these technologies outright is no longer valid, and we need to discuss how to minimize the adverse effects of these technologies and how to limit their use. In this regard, the implications of European AI law are clear. The use of these technologies will and should be expanded, and we need to find a harmonized way to ensure that the fundamental rights of individuals are better protected, while also reforming the legal framework to make it more flexible.

17

수면다원검사에 기반한 생체데이터 시청각화 연구

김희수, 오나예, 박진완

[NRF 연계] 한국전시산업융합연구원 한국과학예술융합학회 Vol.35 2018.09 pp.145-155

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 연구는 일반인에게 접근과 해석에 장벽이 있는 수 면다원검사 데이터를 바탕으로, 사례분석과 작품 제작 을 통해 새로운 형태의 시청각화 방법을 제시한다. 대 부분의 예술작품은 깨어있는 동안 행하는 의식적인 행 동을 바탕으로 완성된다. 본 작품에서는 수면 중 발현 되는 무의식을 관찰하여 이를 예술로 표현하고자 한다. 수면다원검사를 통해 측정된 수면장애 그래프를 중 점적으로 분석하여 정상 군과 기면증, 불면증, 수면무 호흡증으로 분류했고 습득한 생체데이터를 정제 후 수치화 시켰다. 정제된 데이터는 MAYA를 통해 3D 애니메이션 이미지로 렌더링 했고, 심장박동 데이터 스크립트는 midi형태로 변형시켜 garage band에서 청 각화 시켰다. 이후 After Effects로 이미지와 사운드를 결합했다. 총 4개의 <Sleep Scape>는 각각 3분 20초 의 싱글 채널 영상으로 제작했다. <Sleep Scape>는 수면 의학 데이터를 예술로 표현 함으로써 난해한 정보를 직관적으로 이해시키는 데에 목적이 있다. 또한 의식적인 활동이 일어나지 않는 수 면 상태에서 무의식 데이터로부터 예술 표현의 가능 성을 드러내고자 한다.

The goal of the study is to provide a new type of audio-visualization method through case analysis and work production based on Polysomnography(PSG) data that is difficult to interpret or not familiar to the public. Most art works are produced with conscious actions during waking hours. On the other hand, during sleep, we get into the world of unconsciousness. Therefore, through the experiment, want to discover if could get something new when we were in the subconscious state, and if so, wondered what kind of art could be made through it. The study method is to consider definition of sleep and sleep data first. The sleep data were classified into normal group and Narcolepsy, Insomnia, and sleep apnea by focusing on sleep disorder graphs that is measured by sleep polygraph. After that, I refined and converted the acquired biometric data into a text-based script. The degree of sleep in the text form of the script was rendered as a 3D animated image using Maya. In addition, the heart rate data script was transformed into a midi format, and the audition was implemented in the garage band. After Effects combines the image and sound to create four single channel images of 3 minutes and 20 seconds each. As a result of the research, I made an opportunity for anyone easy to understand the results, having difference with the normal data, through art instead of using difficult medical term. It also showed the possibility of artistic expression even when conscious actions did not occur. Through the results of this research, I expect the expansion and diversity of artistic audiovisual expression of biometric data.

18

바이오메트릭 데이터를 이용한 QR-ID 카드 개발

송규현, 김동희, 윤성현

[Kisti 연계] 한국컴퓨터정보학회 한국컴퓨터정보학회 학술대회논문집 2014 pp.371-374

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

현재 국내에서 사용되고 있는 신분 인증 시스템은 주민등록번호와 같은 개인 정보를 기반으로 인증을 수행하여, 프라이버시 침해 위협이 존재한다. 그 해결 방안으로 가상 ID를 이용하는 I-PIN과 e-ID 카드가 제안되었지만, 문제점은 ID와 패스워드만 알고 있다면 누구나 도용이 가능하고 오프라인에서 사용하는 플라스틱 카드의 경우 위 변조가 가능하다는 한계를 갖는다. 본 논문에서는 주민등록번호를 대체할 식별 데이터인 QR-ID를 생성하고, 이에 기반을 둔 QR-ID 카드를 제안한다. QR 코드는 인식기에 대한 제약이 적고 일부 데이터 조작만으로 새로운 QR 코드 생성이 가능하여 노출 시 새로운 ID로 갱신할 수 있으며, QR-ID는 소유자의 바이오메트릭 데이터로 암호화되어 타인이 복호화 할 수 없다.

19

스마트카드와 생체정보를 이용한 다중서버 인증스킴의 취약성 분석

신광철

[NRF 연계] 한국지식정보기술학회 (사)한국지식정보기술학회논문지 Vol.11 No.4 2016.08 pp.371-383

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

과거에는 대부분의 패스워드 인증스킴들이 다중서버환경에는 부적합한 단일서버환경에 기반을 두고 있었다. 그러나 최근에는 멀티서버 환경에서 패스워드와 생체정보에 의한 원격 사용자 인증스킴에 중점을 두고 많은 연구가 이루어지고 있다. 본 논문에서는 Mishra et al'.s 가 제안한 다중서버 환경에서 사용자 인증스킴의 취약점을 분석한다. 그동안 식별자 및 패스워드기반의 다중서버 환경에 대한 스킴들이 많이 제안되었으나 패스워드추측공격과 사전공격 등으로 안전성에 취약성이 발견되었다. 이와 같은 취약성을 극복하기 위하여 다중서버환경과 분산네트워크에서 사용될 수 있는 생체정보를 이용한 다중서버 인증스킴을 제안한 이래 많은 연구가 이루어져 왔다. Mishra et al'.s 스킴은 Chuang et al'.s 스킴의 취약점을 방지하기 위해 사용자 인증 파라미터 h(PSK)를 사용하여 개선하였다. 그러나 Mishra et al'.s 스킴은 사용자/서버 위장공격, 서비스거부공격, 가장공격과 중간자공격에 취약하다. 본 논문에서는 C&C 스킴을 분석하고 개선하여 제안한 Mishra et al'.s 스킴의 취약성과 문제점을 재분석하고 비교한다.

In the past, most of the existing password authentication schemes are based on a single server environment which are inadequate for the multi-server environments. But recently, researches have been performed focusing on the remote user authentication scheme by password and bio-metric data in a multi-server environment. The following study analyzes weaknesses in user Authentication schemes in multiple server environments as suggested by Mishra et al’.s. Over the years, various identifier and password based schemes for multiple server environments have been suggested. However, they have been found of password guessing or dictionary attack based vulnerabilities. In order to overcome such weaknesses, there's been many papers since then that suggested various multiple server verification schemes that utilize biometric data for use in multiple server environments and distributed networks. In order to prevent weaknesses in Mishra et al'.s scheme and Chuang et al'.s scheme, the user verification parameter h(PSK) was utilized to improve upon the weaknesses. However, Mishra et al'.s scheme is vulnerable to user/server spoof attack, denial of service attack, impersonation attack, and man-in-the-middle attack. The following study analyzes C&C scheme and improves it, in order to reanalyze and compare weaknesses and problems to Mishra et al'.s scheme.

20

홈 헬스케어 의료기기 생체 데이터와 의료 정보의 활용을 위한 HL7 기반 진단지원 시스템 설계

허성욱, 강성인, 김관형, 최성욱, 김종판, 오암석

[Kisti 연계] 한국정보통신학회 한국정보통신학회 학술대회논문집 2013 pp.947-949

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

개인 휴대단말기로부터 측정된 생체정보 데이터가 PHR에 데이터베이스화되기 위해서는 응용 계층 표준 프로토콜인 HL7 CDA 표준에 따라야 한다. 하지만 국제 표준 HL7 CDA는 병원 시스템 간 의료정보 전달을 위한 프로토콜이기 때문에 개인 건강 기기로부터 측정된 생체 정보가 IEEE 11073 PHD 표준에 준하여 전달하더라도 HL7 CDA 프로토콜과 연동될 수 없다. 즉, 모바일 단말기 기반의 u-헬스케어 모니터링 서비스를 위해서는 IEEE 11073 PHD와 HL7 CDA 간 메시지 변환 게이트웨이가 필요하다. 이에 본 논문에서는 개인 휴대단말기를 통해 원격지에 있는 의료진이 사용자의 생체데이터를 실시간 관리하기 위해 ISO/IEEE 11073과 HL7 CDA 간 메시지 변환 게이트웨이 및 HL7 기반 진단지원시스템을 설계하였다.

 
1 2
페이지 저장