년 - 년
한국기계항공기술학회(구 한국기계기술학회) 한국기계항공기술학회지(구 한국기계기술학회지) 제27권 제5호 2025.10 pp.799-804
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
This research identifies security vulnerabilities in IoT-based healthcare authentication, specifically replay attacks, session key predictability, and biometric data leakage. We propose enhancements like adaptive timestamp verification and hybrid entropy sources for stronger session keys. Quantum-resistant cryptography and advanced biometric data protection are also recommended.
한국기계항공기술학회(구 한국기계기술학회) 한국기계항공기술학회지(구 한국기계기술학회지) 제27권 제3호 2025.06 pp.437-443
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
This study evaluates a lightweight authentication protocol for IoMT systems, revealing vulnerabilities like node cloning and insider threats. It proposes enhancements including PUFs, homomorphic encryption, and RBAC/ABAC. Optimized session management and lightweight cryptography are also suggested to improve security and resource use. Future research should explore quantum-resistant cryptography and AI-based adaptive security policies for enhanced resilience against evolving threats.
개인정보 보호 법제의 법적 문제― 금융개인정보와 생체개인정보를 중심으로 ―
[NRF 연계] 민주주의법학연구회 민주법학 Vol.53 2013.11 pp.221-248
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
이 글은 현행 개인정보 보호 법제의 문제점을 지적하기 위한 글이다. 특히 금융개인정보와 생체개인정보에 주목하고 있다. 이 두 가지 개인정보의 경우, 나날이 그중요성이 높아감에도 불구하고 입법은 사실상 공백상태이기 때문이다. 따라서 글의 전반부에는 금융개인정보와 관련한 현행 법제의 문제점을 분석하고,이를 미국의 입법과 비교・검토하는 형식으로 구성한다. 금융당국이 미국 입법과 비교를 해 보아도 우리 법제의 보호제도가 우월하다는 입장을 밝혔기 때문이다. 한편 글의 후반부에서는 생체개인정보와 관련한 구체적인 쟁점사항을 검토하는형식으로 진행한다. 생체개인정보와 관련하여 가장 큰 난점은 개인정보보호법상의‘민감정보’에 해당하지 않는다는 것인데, 그 덕분에 ‘가이드라인’을 통한 자율적 규제에 의존하고 있는 상황이다. 이러한 문제에 관하여 필자는, 구체적인 입법적 대응방안을 제시한다. 금융개인정보의 경우, 우리 개인정보 보호 법제와의 조화를 위한 ‘옵트인’ 또는 세밀한 보호장치가 담보된 상황에서의 ‘옵트아웃’제도의 실시가 바람직하다는 것이 그것이다. 생체개인정보의 경우, 단순히 ‘민감정보’에의 편입으로 해결할 것이 아니라 생체개인정보에 관한 독립적인 입법체계를 새로이 구성하는 것이 바람직하다는 것이 이글의 결론이다.
This paper aims at pointing out several problems on the current legislative system of personal data protection. The most problematic are personal financial data and personal biometric data, since there is no appropriate regulation but the importance of both data is increasing. The first part of this article is thus allotted to analyzing the current legislative system about personal financial data, and compares it with the regulation thereon of the United States. That is because financial authorities of Korea have clarified their position that the Korean legislations are more protective than those of the United States. In the latter part of this article, then, I studied the controversial issues related to personal biometric data in detail. The biggest problem about them is that they are excluded from the definition of ‘sensitive information’ of the Personal Data Protection Act. Therefore those data are being regulated by a Guideline called a voluntary regulation. With regard to these problems, I tried to construct a legislative resolution in detail. Regarding personal financial data, I suggested either an ‘Opt in’ rule which is accordance with the principle of the current Personal Data Protection Act, or a very elaborate ‘Opt out’ rule which has reliable protection mechanisms. Concerning personal biometric data, I emphasized the need of a new legislative system which is specialized and independent, instead of incorporating those data into the definition of the ‘sensitive information’.
[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.31 No.4 2021 pp.841-852
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
바이오인식은 각 개인의 신체적, 생리적, 행동적 특성을 자동화된 장치로 측정하여 이를 등록한 후, 개인을 식별하거나 인증하는 기술을 말한다. 그런데, 여기서 사용되는 바이오인식 정보는 개인을 식별할 수 있으므로 개인정보에 해당된다. 따라서, 이것이 유출되거나 오용되었을 때 정보주체의 프라이버시에 부정적인 영향을 미치게 된다. 본 논문에서는 바이오인식 정보와 관련된 국내의 법적 현황을 살펴보고 이와 관련된 침해현황을 살펴본다. 이어서 대표적인 바이오인식 응용 모델을 도출하고, 각각에 대한 취약점 및 대책 방안을 논의한다. 최종적으로 바이오인식 시스템의 개발자와 서비스제공자를 위해 바이오인식 정보의 보호를 위한 수칙을 제시한다.
Biometric recognition refers to a technology that identifies or verifies an individual after registering each individual's physical, physiological, and behavioral characteristics with an automated device. However, the biometric data used here corresponds to personal information since it can identify an individual. Therefore, when it is compromised or misused, it negatively affects the privacy of the data subject. In this paper, we review the current status of domestic laws related to biometric information and the status of infringements related to this. And then, some biometric application models are derived and vulnerabilities and countermeasures for each model are discussed. Finally, for the developer and service provider of the biometric system, protection guidance is presented.
유럽 AI법에 따른 생체정보의 활용과 보호에 관한 고찰
[NRF 연계] 경북대학교 법학연구원 법학논고 Vol.85 2024.04 pp.57-82
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
유럽에서는 생체인식정보 기술의 발달과 AI 기술의 발달, 그리고 이 두가지 기술이 결합되어서 나타나게 되는 기본권 침해상황을 심각하게 생각하여 이를 규제하기 위한 법제를 만들기 위해 노력해왔다. 특히 2021년 인공지능법안이 유럽연합 집행위원회에서 유럽연합 의회에 제안되었고, 3년 이상의 기간동안 이에 대해 유럽의 학계와 정치계, 시민사회와 각 회원국에서 뜨겁게 논의된 결과 지난 2024년 3월 유럽연합 의회에서 압도적 다수로 인공지능법이 통과되었고, 일부 조항은 6개월 후부터, 2026년부터는 전면 시행된다. 이는 소위 브뤼셀 효과로 인하여 GDPR과 같이 세계에 영향을 미치는 인공지능 규제법으로 기능할 것으로 보인다. 이번에 통과된 인공지능법의 가장 큰 특징 중의 하나는 AI 기술을 이용한 생체인식정보의 처리를 강하게 규제하고자 한다는 점이다. EU에서는 생체인식기술과 AI기술이 결합하였을 때 발생할 수 있는 대량감시와 추적의 가능성과 이로 인한 일반적 인격권, 사생활의 비밀, 개인정보자기결정권, 평등권 등의 기본권 침해적 상황이 심각할 수 있다는 점에 대한 분명한 인식으로 이를 강하게 규제하고자 한다. 특히 감정인식시스템, 생체 인식 분류 시스템, 실시간 원격 생체 인식 시스템, 사후 원격 생체 인식 시스템 등의 새로운 기술에 대해 개념정의를 하고자 노력하였고, 이를 바탕으로 AI 기술과 생체인식정보가 결합되어 사용되는 경우 이러한 AI 시스템의 실행을 금지하거나 고위험 AI 시스템으로 분류하여 강하게 제한하고자 한다. 앞으로 AI 기술과 생체인식기술을 더욱 발전할 것이고, 이러한 기술이 우리의 삶 속에 우리의 생활을 편리하게 하기 위하여 더 광범위하게 사용될 것이 예측된다. 또한 이러한 기술을 사용하는 시장도 엄청나게 확대될 것으로 예상되는데, 이는 AI법이 AI를 규제하기 위한 법이면서도 목적조항에 인공지능의 활용을 촉진하고 혁신을 지원하기 위한 법이라고 명문으로 규정한 것에서도 알 수 있다. 따라서 이러한 기술의 사용을 전면적으로 금지함으로서 우리의 기본권을 보장한다는 생각은 더 이상 유효할 수 없고, 이러한 기술의 사용으로 인한 부작용을 최소화하는 방안을 마련하고, 이러한 기술의 사용을 어떻게 제한하여야 할 것인지에 대한 논의를 하여야 한다. 이런 점에서 유럽의 AI법이 우리에게 주는 시사점은 분명히 있다. 이러한 기술의 사용은 더욱 확대될 것이고 확대되어야 하는데, 이러한 기술의 사용이 더 유연해질 수 있도록 법제를 개편하는 것과 아울러 개인의 기본권이 더 실효적으로 보장될 수 있는 조화로운 방법을 모색하여야 할 것이다.
In Europe, the development of biometric data technology and the development of AI technology, and the violation of fundamental rights caused by the combination of these two technologies, have been seriously considered, and efforts have been made to create legislation to regulate them. In particular, the Artificial Intelligence Act was proposed to the European Parliament by the European Commission in 2021, and after more than three years of heated discussions in European academia, politics, civil society, and member states, the Artificial Intelligence Act was passed by the European Parliament with an overwhelming majority in March 2024, and some provisions will be implemented in six months, and all provisions will be implemented in 2026. Due to the so-called Brussels effect, it is expected to function as an AI regulatory law with global impact like the GDPR. One of the most significant features of the AI Act is that it seeks to strongly regulate the processing of biometric data using AI technology. The EU clearly recognizes the potential for mass surveillance and tracking that can arise from the combination of biometrics and AI technologies, and the potential for serious violations of fundamental rights such as the personality right, the right to privacy, the right to self-determination of personal information, and the right to equality. In particular, the Act endeavors to conceptualize new technologies such as emotion recognition systems, biometric categorisation systems, remote biometric identification systems, real-time remote biometric identification systems, and post remote biometric identification systems, and based on this, it seeks to prohibit the practices of such AI systems or classify them as high-risk AI systems and strongly restrict them when AI technology and biometric data are used in combination. It is expected that AI technology and biometrics will be further developed in the future, and that these technologies will be used more widely in our lives to make our lives easier. The market for the use of these technologies is also expected to expand tremendously, which is evident from the fact that the AI Act is intended to regulate AI, but the purpose clause clearly states that it is intended to promote the utilization of AI and support innovation. Therefore, the idea of ensuring our fundamental rights by prohibiting the use of these technologies outright is no longer valid, and we need to discuss how to minimize the adverse effects of these technologies and how to limit their use. In this regard, the implications of European AI law are clear. The use of these technologies will and should be expanded, and we need to find a harmonized way to ensure that the fundamental rights of individuals are better protected, while also reforming the legal framework to make it more flexible.
인공지능 시대 정보보호와 공공데이터 이용의 정책 갈등-생체정보와 딥러닝 기반 출입국관리 시스템을 중심으로
[NRF 연계] 참여연대 시민과 세계 Vol.44 2024.06 pp.71-113
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
인천공항의 출입국 관리 시스템 개발과 검증에 생체정보와 딥러닝 알고리즘을 활용하겠다는 정부의 계획은 한국 사회의 개인정보보호와 인공지능 정책에 대한 까다로운 질문을 우리에게 던졌다. 이 논문은 법무부 출입국․외국인정책본부와 과학기술정보통신부, 행정안전부, 개인정보보호위원회 등이 지향하는 원칙이 충돌하고 있다고 주장한다. 또 이 논문은 지능정보사회를 추진하고 디지털 플랫폼 정부를 앞당기기 위한 공공데이터 활용 정책이 생체정보를 이용한 감시를 견제하고, 개인정보보호와 정보의 자기 결정권을 보장하는 개인정보보호 정책과 잠재적 갈등 관계에 처했음을 보일 것이다. 이른바 인공지능 시대를 맞이하여 국경 앞에서 중단되지 않는 민주주의 원칙과 차별을 줄이기 위한 인권 정책에 부합하는 공공데이터 정책의 가능성을 찾기 위한 방법을 모색해야 할 시점이다.
The controversy on the border control system based on biometric information and deep learning in Incheon airport raised thorny questions on conflicts between public data utilization. This paper first lays out the detailed issues against the Korean discursive landscape of privacy and emerging technology policies. Then I will argue that the Ministry of Justice’s Korea Immigration Service, the Ministry of Science and ICT, and the Ministry of the Interior and Safety formulated and maintained conflicting policy principles. This paper also posits that the potential conflict exists between the policy for public data utilization toward intelligent information society and digital platform government on the one hand and the personal information protection policy that guarantees the right to informational self-determination on the other hand. This paper ends with an inquiry into possibilities of public data policy that resonates with the democratic principle that does not stop at the border and human rights policies for less discrimination.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.