년 - 년
Wearable Sensor-Based Biometric Gait Classification Algorithm Using WEKA
[Kisti 연계] 한국정보통신학회 Journal of information and communication convergence engineering Vol.14 No.1 2016 pp.45-50
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
Gait-based classification has gained much interest as a possible authentication method because it incorporate an intrinsic personal signature that is difficult to mimic. The study investigates machine learning techniques to mitigate the natural variations in gait among different subjects. We incorporated several machine learning algorithms into this study using the data mining package called Waikato Environment for Knowledge Analysis (WEKA). WEKA's convenient interface enabled us to apply various sets of machine learning algorithms to understand whether each algorithm can capture certain distinctive gait features. First, we defined 24 gait features by analyzing three-axis acceleration data, and then selectively used them for distinguishing subjects 10 years of age or younger from those aged 20 to 40. We also applied a machine learning voting scheme to improve the accuracy of the classification. The classification accuracy of the proposed system was about 81% on average.
[NRF 연계] 한국통신학회 ICT Express Vol.5 No.1 2019.03 pp.16-20
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
On-demand ride services and the rideshare infrastructure primarily focus on the minimization of travel time and cost. However, the safety of riders is overlooked by service providers. For driver authentication, existing identity management methods typically check the driving license, which can be easily stolen, forged, or misused. Further, background checks are not performed at all; instead, social profiles and peer reviews are used to foster trust, thereby compromising the safety and security of riders. Moreover, the present mechanism seems ineffective in discontinuing a malicious driver from offering the services. In this paper, we present DriverAuth?a fully transparent and easy-to-use authentication scheme for drivers that is based on common behavioral biometric modalities, such as hand movements, swipes, and touch-strokes while the drivers interact with the dedicated smartphone-based application for accepting the booking. A preliminary study of behavioral biometric-based approaches offers a usable verification mechanism on smartphones that could be a potential solution to improve the safety of riders in the emerging on-demand ride and the rideshare infrastructure.
4,000원
본 논문에서는 WMSN(무선 의료 센서 네트워크)을 위한 생체 인식 기반 인증 프로토콜의 보안 취약점을 분석하였다. 분석결과, 오프라인 비밀번호 추측, 위장 공격, 임시 비밀 유출 등의 취약점이 확인되었다. 이러한, 취약점을 개선하는 방법으로 솔트 암호화 해싱, 메시지 인증 코드, 디지털 서명, 개선된 키 합의 프로토콜 등 강화 된 전략을 제안하였다. 향후 리소스가 제한된 WMSN 환경에서 프로토콜의 견고성을 높이고 데이터 기밀성 및 무결성을 보장할 수 있는 고도화된 프로토콜의 개발이 요구된다.
This paper analyzes security vulnerabilities in a biometric-based authentication protocol for Wireless Medical Sensor Networks (WMSNs), identifying weaknesses like offline password guessing, impersonation, and ephemeral secret leakage. It proposes enhanced strategies, including salted password hashing, message authentication codes, digital signatures, and improved key agreement protocols, to bolster the protocol's robustness and ensure data confidentiality and integrity in resource-constrained WMSN environments.
한국EA학회 한국EA학회 학술발표논문집 International Conference on e_Gov. Enterprise Architecture & Cloud Computing(eGEAC 2018) 2018.12 pp.229-243
※ 기관로그인 시 무료 이용이 가능합니다.
4,800원
Responsible AI 기반 공항 생체인식 감시기술의 사회적 수용성 : Triple Tension Model을 활용한 국가별 조정 메커니즘 비교 연구 KCI 등재
한국경영정보학회 경영정보학연구 제28권 제2호 2026.05 pp.97-127
※ 기관로그인 시 무료 이용이 가능합니다.
7,200원
본 연구는 AI 기반 생체인식 감시기술이 공항과 같은 고위험 공공 인프라 환경에서 어떠한 방식으로사회적으로 수용되는지를 정보시스템(IS) 관점에서 분석한다. 기존 기술수용 연구가 개인의 인지적평가와 기술 성능에 기반한 선형적 설명에 주로 초점을 맞추어 온 것과 달리, 본 연구는 감시기술수용이 제도적 신뢰, 감시 불안, 사회적 편향 인식이 상호작용하는 구조적 긴장 관계 속에서 형성된다는점에 주목한다. 이에 신뢰-불안-편향의 균형 구조를 설명하는 이론적 틀로서 Triple Tension Model을제안하고, Responsible AI 조정 메커니즘(설명가능성, 동의, 감독, 참여)이 이러한 균형 구조에 어떠한영향을 미치는지를 분석한다. 문헌 기반 질적 비교사례연구(Qualitative Comparative Case Study)를적용하여 유럽연합(EU), 미국, 대한민국, 중국의 주요 국제공항을 분석한 결과, 국가별 감시 거버넌스의특성과 Responsible AI 제도화 수준에 따라 신뢰-불안-편향의 균형 유형이 상이하게 형성됨이 확인되었다. EU 사례에서는 제도적 신뢰가 불안과 편향을 조정하는 조화형(trust-balanced) 구조가 나타났으며, 미국사례에서는 불안과 편향 요인이 신뢰 형성에 상대적으로 두드러지는 양상을 보이는 긴장 우세형(Tension-dominant) 구조로 해석되었다. 대한민국은 제도화 수준에 따라 균형이 이동 가능한 전환형(transitional) 구조를 보였으며, 중국은 제도적 관리 체계를 중심으로 불안과 편향 인식이 낮은 수준으로유지되는 비대칭 안정형(asymmetrical stability) 구조로 해석되었다. 본 연구는 AI 감시기술의 사회적수용성이 기술 성능 자체의 차이보다는 제도적 신뢰 형성 방식과 Responsible AI 조정 메커니즘의제도화 수준과 밀접하게 연관되어 있음을 보여준다. 이를 통해 기존 IS 기술수용 연구의 분석 범위를고위험․비자발․권력 비대칭 환경으로 확장하고, 신뢰 기반 감시 거버넌스 설계의 이론적․정책적함의를 제시한다.
This study examines how AI-based biometric surveillance technologies are socially accepted in high-risk public infrastructure environments such as airports from an information systems (IS) perspective. Moving beyond traditional technology acceptance models that emphasize individual cognition and performance, this research conceptualizes acceptance as a structural tension among institutional trust, surveillance anxiety, and perceived bias. The study proposes the Triple Tension Model and analyzes how Responsible AI mechanisms—explainability, consent, supervision, and participation—shape this balance. Using a qualitative comparative case study of major international airports in the EU, the United States, South Korea, and China, the findings reveal distinct equilibrium patterns across governance contexts. The EU exhibits a trust-balanced structure, the United States a tension-dominant structure, South Korea a transitional structure, and China an asymmetrical stability structure. The results highlight that social acceptance of AI surveillance is less determined by technological performance than by institutional trust formation and the level of Responsible AI implementation. This study extends IS research into high-risk, non-voluntary, and power- asymmetric contexts and offers theoretical and policy implications for designing trust-based surveillance governance.
모바일 장치에서 신체정보기반의 효용성 분석을 이용한 인증기법에 관한 연구 KCI 등재
한국디지털정책학회 디지털융복합연구 제11권 제11호 2013.11 pp.795-801
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
과거의 오프라인에서만 이루어졌던 생활이 온라인에서의 활동으로 발전함으로 인해 온라인상에서 사용자가 올바른 사용자인지의 여부는 중요한 문제이다. 온라인상이나 나아가 일반 생활에서도 사용자 인증을 보다 정확하게 하기 위하여 생체인식 기술을 도입하고 있다. 생체인식 기술은 개인의 고유한 특징을 이용하여 인증을 수행하는 방 법으로 비밀번호를 대체하는 차세대 인증 기술로 각광받고 있다. 인간의 고유한 특징의 종류는 매우 다양하며 이러 한 특징을 추출하는 생체인식 기술도 다양한 장치와 알고리즘을 이용하여 이루어진다. 본 논문에서는 첫째로 이러한 다양한 장치인 스마트폰, 스마트와치, M2M 플랫폼을 분석하고 적용하였을 경우 어떤 효용성이 있는지 분석한다. 둘 째로, 다른 장치 플랫폼에서 포괄적인 인증인 효용성기반의 AIB를 제안한다. 제안 인증기법은 신체정보를 이용한 효 율적인 인증을 포함한다.
As the life which existed only offline has changed into a life part of which is led online, it is an important problem to identify whether an online user is legitimate one or not. Biometric authentication technology was developed to identify the user more correctly either online or in offline daily life. Biometric authentication is a technology where a person is identified by his or her unique characteristics, and is highlighted as a next-generation authentication technology replacing password. There are various kinds of traits unique to each individual, and biometric authentication technologies drawing on such traits use various devices and algorithms. Firstly, this paper classified such various biometric authentication technologies, and analyzed the effects of them when they are applied on smartphone, smartwatch and M2M of the different devices platforms. Secondly, it suggested the effectiveness-based AIB(Authentication for Integrated Biometrics) authentication technique, a comprehensive authentication technique, which can be used in different devices platforms. We have successfully included the establishment scheme of the effectiveness authentication using biometrics.
4,300원
컴퓨터망의 확대 및 컴퓨터 이용의 급격한 증가에 따른 부작용으로 컴퓨터 보안 문제가 중요하게 대두되고 있다. 이에 따라 침입자로부터 침입을 줄이기 위한 침입탐지시스템에 관한 연구가 활발하다. 본 논문은 멀티레벨에서 감사자료를 수집하고, 필터링하여 오용행위 탐지기법에 대한 선천성면역, 비정상행위 탐지기법에 대한 후천성 면역을 사용한 하이브리드 침입탐지 시스템이다. 다중호스트 기반에서 감사자료를 하나의 시스템으로 모아서 탐지하므로 하나의 호스트에서 탐지한 침입보다 여러 호스트에서 탐지가 가능하며, 비정상행위 탐지 기법에서 탐지한 침입은 오용행위 탐지 기법에서 신속하게 탐지할 수 있는 면역력을 가진 침입탐지 시스템의 설계 및 구현한다.
Computer security is considered important because of the side effect generated from the expansion of computer network and rapid increase of the use of computer. Intrusion Detection System(IDS) has been an active research area to reduce the risk from intruders. In this paper, the Hybrid Intrusion Detection System(HIDS) based biometric immuntiy collects and filters audit data by misuse detection is innate immune, and anomaly detection is acquirement immune in multi-hosts. Since, collect and detect audit data from one the system in molt-hosts, it is design and implement of the intrusion detection system which has the immuntiy the detection intrusion in one host possibly can detect in multi-hosts and in the method of misuses detection subsequently.
바이오 정보 기반 사용자 인식 시스템의 프라이버시 침해 위협 고찰
한국경영컨설팅학회 경영컨설팅연구 제9권 제4호 통권 제23호 2009.12 pp.129-148
※ 기관로그인 시 무료 이용이 가능합니다.
5,500원
4,000원
대리 인증은 제 3자에게 자신의 인증 정보를 제공하여 본인 대신 인증을 받도록 하는 것으로, 패스워드와 같이 내가 기억하는 것에 기반을 둔 인증 방법은 이러한 공격에 취약하다. 바이오메트릭 인증은 사람마다 고유한 바이오메트릭 데이터를 이용하기 때문에 대리 인증의 위험을 최소화할 수 있다. 그룹 인증은 그룹 멤버들이 해당 그룹에 속해 있음을 증명하는 것이다. 전자투표, 모바일 회의와 같이 멤버의 수가 동적으로 변하는 응용에서는 그룹 상태의 변화를 실시간으로 반영하는 새로운 인증 기법이 필요하다. 본 논문에서는 바이오메트릭 인증 기반의 동적 그룹 서명 기법을 제안한다. 제안한 기법은 바이오메트릭 키 생성, 그룹 공통키 생성, 그룹 서명 생성, 그룹 서명 검증 그리고 멤버 업데이트 프로토콜로 구성된다. 제안한 멤버 업데이트 프로토콜은 기존 멤버의 공모 공격으로부터 안전하고 그룹 상태를 실시간으로 반영한다.
In a delegate authentication, a user can lend his/her own authentication data to the third parties to let them be authenticated instead of himself/herself. The user authentication schemes based on the memory of unique data such as password, are vulnerable to this type of attack. Biometric authentication could minimize the risk of delegate authentication since it uses the biometric data unique by each person. Group authentication scheme is used to prove that each group member belongs to the corresponding group. For applications such as an electronic voting or a mobile meeting where the number of group members is changing dynamically, a new group authentication method is needed to reflect the status of group in real time. In this paper, we propose biometric authentication based dynamic group signature scheme. The proposed scheme is composed of biometric key generation, group public key creation, group signature generation, group signature verification and member update protocols. The proposed member update protocol is secure against colluding attacks of existing members and could reflect group status in real time.
서버 기반 실시간 바이오메트릭 서명 기법 KCI 등재
한국디지털정책학회 디지털융복합연구 제11권 제9호 2013.09 pp.173-179
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
바이오메트릭 인증은 사용자 고유의 신체 정보인 바이오메트릭 데이터를 이용하여 제 3자에게 본인임을 입 증하는 것이다. 사용자는 매 인증 세션 마다 직접 참여해야 하기 때문에 제 3자에 의한 대리 인증이 불가능하다. 바 이오메트릭 서명은 인증과 달리 서명한 메시지 내용이 틀림이 없다는 것을 제 3자에게 입증하는 것이다. 서명에 사 용된 개인키는 바이오메트릭 데이터를 이용하여 생성된다. 하지만 일단 생성된 서명키는 서명자가 접근할 수 있어서 제 3자에게 서명키를 임대할 수 있다. 본 연구에서는 서명자가 직접 서명에 참여해야 하는 서버 기반의 실시간 바이 오메트릭 서명 기법을 제안한다. 제안한 기법은 대리서명이 허용되지 않는 전자 선거에서의 투표권 인증, DRM이 적 용된 모바일 상거래에서의 저작권자 인증에 적용될 수 있다.
In a biometric authentication scheme, a user’s biometric data that is unique to the user is used to prove the user’s identity to the third party. Since the user should have to participate in every authentication sessions, it's not possible to delegate other users to authenticate instead of himself/herself. In a biometric signature scheme, contrary to authentication scheme, a user’s biometric data is used to prove that “this message is signed by the signer who claims to be” to the third party. However, once the biometric key is created, it can be accessed by the signer. Thus, it’s possible to lend the biometric key to other users. In this study, the server based biometric realtime signature scheme is proposed. The proposed scheme can be applied to sign the vote in electronic voting or to authenticate the copyright owner in DRM enabled mobile commerce where the proxy signatures are not allowed.
차량 애드 혹 망을 위한 생체 키 기반의 인증 기법 KCI 등재
한국디지털정책학회 디지털융복합연구 제10권 제11호 2012.12 pp.365-369
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
사물지능통신은 낮은 네트워크 비용과 범위에서 이점을 가지고 있다. 사물지능통신의 지능형 자동차는 구성요소와 망 규모의 비율로 차량간 위치에서 극심한 변화를 보여준다. 지능형 자동차는 무선 통신 기능으로 자동차 장치들 간에 정보를 교환하기 위해 차량 애드 혹 망에서 생체 정보를 통하여 안전성 제공을 요구한다. 본 논문은 자동차 이동시 자동차간의 상호 인증을 위해 생체 정보를 제공하는 기법을 제안한다.
M2M has shown the advantages of better coverage and lower network deployment cost. Intelligent vehicle section shows severe changes in position between vehicles and has numerous large scales of networks in its components, therefore, it is required to provide safety by exchanging information between vehicles equipped with wireless communication function via biometric information in VANET(Vehicular Ad hoc Network). This thesis is to propose scheme that mutually authenticates between vehicles by composing vehicle movement as biometric information.
직무만족도 조사에 따른 항공보안검색요원의 전문성 제고 방안에 대한 연구
한국항공보안학회 항공보안·안전 거버넌스(구 한국항공보안학회지) Vol. 2 No. 1 2020.12 pp.119-137
※ 기관로그인 시 무료 이용이 가능합니다.
5,400원
As the number of airport users continues to grow over the past decade and the increasing threat to terrorism and terrorism against civil aviation has led to an increasing number of aviation security vulnerabilities, the infrastructure involved, including aviation security equipment, is becoming more advanced. In response, the relevant organizations and States, including the International Civil Aviation Organization (ICAO), are make an endeavor in many ways to strengthen aviation security.Workers engaged in aviation security work are classified as airport special security guards and air security search personnel and they can be considered as performing important tasks in airport safety and security. However, due to the vertical organizational culture arising from the nature of the task and the high resignation rate by heavy workload, personnel input with a lack of professionalism and the lack of security supervisors, it is difficult to maintain order at the airport and at the same time some cases of failure and failure in aviation security have occurred. Therefore, the government is endeavoring to take various measures for the enhancement of aviation security in terms of quality, including measures to enhance expertise in 'Aviation Security Master Plan', but it is a situation that there is a lack of comprehensive measures to enhance the expertise of aviation security personnel, which is one of the main factors in aviation security. The security screening is considered the beginning of the journey that air passengers face when they visit the airport and the biggest factor to determine their satisfaction with a passenger experience at the airport. Since, among these, an air security screening personnel can be classified as service personnel who are actually facing with passengers and who are in the position of screening, this study aims to find a way to be efficient, perfect, and faithful to safety and security tasks by seeking the ways to relieve the stress and pressure of air security search personnel, enhance their professionalism. Therefore, the purpose of this paper is to identify whether job satisfaction of aviation security screening personnel is a deterrent to the professionalism of aviation security personnel by conducting a task satisfaction survey among aviation security personnel who are actually higher interaction with passengers and to contribute to the formation of comprehensive measures to further enhance aviation security by seeking improvements.
한국항공보안학회 항공보안·안전 거버넌스(구 한국항공보안학회지) Vol. 2 No. 1 2020.12 pp.1-22
※ 기관로그인 시 무료 이용이 가능합니다.
5,800원
This study analyzed the current status of aviation security and presented biometric technology-based aviation security in an innovative way that can simultaneously be promoted to enhance aviation security and improve passenger experience. Recently, research and development of biometric information and its applications has been actively carried out at home and abroad as interest in biometric technology has been heightened in order to increase the accuracy of user authentication or to identify identity. However, since biometric technology extracts and analyzes human physiological or behavioral characteristics to create a certification system, the view that biometric information itself represents human characteristics is also very important, along with aviation security, as well as privacy protection for biometric information. In addition, based on this study, the following practical implications can be derived from the global airport authorities and airlines for the smooth introduction of biometric technology. If airport authorities and others provide performance and learning-time information, such as the accuracy of biometric technology, to reduce the performance risk and time risk of passengers by dispelling vague anxiety about biometric technology, aviation security and passenger experience could be improved simultaneously through the use of higher biometric technology-based identification. Furthermore, as an innovative way to enhance aviation security and improve passenger experience, we would like to propose a future converged aviation security model called Moving Airport. Finally, biometric identification technology is a function that replaces the presentation of identification cards and tickets at each stage of the boarding process, and can be used in the same form as the departure hall in other procedures at the airport, such as check-in and boarding. In addition, the realization of Moving Airports requires an enterprising improvement in aviation security-related legislation so that boarding procedures and security checks can be carried out on mobile vehicles other than airport passenger offices.
IoT기반 다중 생체정보 측정을 위한 원격 의료 스마트 헬스케어 시스템 KCI 등재
한국융합학회 한국융합학회논문지 제11권 제10호 2020.10 pp.53-61
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 코로나19 바이러스로 인하여 언컨텍트 서비스가 본격적으로 활성화됨에 따라 비대면 접촉 원격 의료 서비 스를 제공하기 위한 시스템 개발의 필요성이 증가하게 되었다. 본 연구에서는 원격진료를 지원하기 위한 스마트 헬스케 어 시스템인 Rm_She(Remote Medical Smart Healthcare System)을 제안한다. Rm_She는 IoT를 기반으로 생체신 호를 감지하는 다양한 헬스케어 제품을 하나의 애플리케이션으로 연결하여 여러 가지의 생체신호 정보를 수집 및 관리 할 수 있다. 스마트 폰에 실행되는 헬스체크 앱(HC_app)을 이용하여 여러 종류의 생체신호 측정 장치와 무선랜으로 연결하고, 생체신호 값을 HC_app에서 전송 받아, 사용자에게 측정된 생체신호를 출력하고, 해당 정보를 헬스케어관리 서버로 전송한다. 헬스케어 서버에서는 측정값을 전송 받아 데이터베이스에 저장하고, 저장된 측정값은 의료진들이 원 격에서 실시간으로 모니터링 할 수 있도록 웹서비스로 제공한다.
Recently, as the uncontact service is activated in earnest due to the Corona 19 virus, the necessity of system development to provide non-face-to-face contact remote medical service has increased. In this study, we propose a smart healthcare system, Rm_She(Remote Medical Smart Healthcare System). Rm_She can collect and manage various vital signs information by connecting various healthcare products that detect bio-signals based on IoT to one application. The health check app (HC_app) is used to connect vital sign measurement devices to a wireless LAN and receive vital sign values from the HC_app. Then, the vital signs are output to the user on the smartphone, and the corresponding information is transmitted to the healthcare management server. The healthcare server receives the measured values and stores them in a database, and the stored measured values are provided as a web service so that medical staff can remotely monitor them in real time.
생체 인증 기반 모바일 결제 서비스 수용의도 분석 : 애플페이를 중심으로 KCI 등재
한국디지털정책학회 디지털융복합연구 제18권 제7호 2020.07 pp.123-133
※ 기관로그인 시 무료 이용이 가능합니다.
4,200원
본 연구에서는 애플페이를 중심으로 하여 지문인식, 안면인식과 같은 생체 인증 기반 기술들을 이용한 모바일 결제 서비스에 대한 국내 사용자의 수용의도와 정보보호 관련 요인들이 미치는 영향을 분석하고자 하였다. 정보보호와 관련된 요인들에 대한 연구가 부족하였던 기존 모바일 결제 수용의도 연구들과 달리, 본 연구에서는 정보보호 관련 요인 들을 추가한 모형을 통합기술수용이론(UTAUT)을 기반으로 만들고, 이를 PLS(Partial Least Squares) 기법을 이용하 여 분석하였다. 분석을 통하여 기업의 정보보호 노력을 통한 제공 서비스 신뢰도 확보, 개인의 성향, 그리고 적용 보안기 술에 대한 신뢰도는 사회적 인식 및 서비스 인프라와 함께 국내 사용자들에게 중요한 요인임을 알 수 있었다. 본 연구 결과는 생체인증 기반 모바일 결제 서비스를 제공하는 기업 또는 조직에게 국내 소비자들을 파악하는데 도움이 될 것으 로 판단된다. 향후 본 연구를 바탕으로 동일 기업 또는 경쟁 기업 제품 사용 경험이 수용의도에 미치는 영향을 분석할 수 있을 것으로 기대한다.
The aim of this study is to scrutinize acceptance intentions of Korean users and influences of information security related factors on mobile payment services based on biometric authentication methods, like finger print authentication or face recognition authentication, by focusing on ApplePay. Unlike previous studies on user acceptance of mobile payment which lack considerations on information security related factors, this study employs the UTAUT with detailed information security factors to create a research model and PLS(Partial Least Squares) method to analyze the model. Based on the analysis, gaining trust on service through company's efforts on information protection, personal characteristics and trust on applied security technologies are important factors to Korean users along with social awareness and service infrastructures. The result of this study would be helpful to companies or organizations, which provide biometric-based mobile payment services, to understand needs of Korean consumers. Based on this study, further analysis is expected to find impacts of user experiences on same company's or competitors' products to acceptance intentions.
블록체인을 이용한 생체정보와 OTP 기반의 안전한 인증 기법 KCI 등재
중소기업융합학회 융합정보논문지(구 중소기업융합학회논문지) 제8권 제3호 2018.06 pp.85-90
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
블록체인 기술은 분산된 신뢰구조를 제공하고, 위변조가 불가능한 시스템 구현이 가능하고, Smart Contract 등 이 가능하면서 인터넷 차세대 보안 기술로 발전하고 있다. 블록체인 기술이 차세대 보안기술로 부각되면서 무결성 뿐만 아니라 인증을 비롯하여 다양한 보안 서비스에 대한 연구가 진행되고 있다. 인터넷 기반의 다양한 서비스는 패스워드 기반의 사용 자 인증으로 이루어지고 있지만 클라이언트나 네트워크에서 가로채기가 가능하고, 패스워드 정보가 저장된 서버가 해킹의 위험에 노출되어 있다. 따라서 무결성을 보장할 수 있는 블록체인 기반 기술과 OTP 기반의 안전한 인증 기법을 제안한다. 특히, 이중 인증(Two-Factor Authentication) 은 OTP 기반의 인증과 사용자가 가지고 있는 생체인증의 결합으로 패스워드 없이 안전한 인증이 가능하다. 제안기법은 인증에 필요한 생체정보를 식별할 수 없도록 다중 해시함수를 적용하여 트랜잭션 을 생성하여 블록에 담기 때문에 서버로부터 분리되어 서버 공격에 안전하다.
Blockchain technology provides distributed trust structure; with this, we can implement a system that cannot be forged and make Smart Contract possible. With blockchain technology emerging as next generation security technology, there have been studies on authentication and security services that ensure integrity. Although Internet-based services have been going with user authentication with password, the information can be stolen through a client and a network and the server is exposed to hacking. For the reason, we suggest blockchain technology and OTP based authentication mechanism to ensure integrity. In particular, the Two-Factor Authentication is able to ensure secure authentication by combining OTP authentication and biometric authentication without using password. As the suggested authentication applies multiple hash functions and generates transactions to be placed in blocks in order for biometric information not to be identified, it is protected from server attacks by being separate from the server.
글로벌 바이오정보 프라이버시 논점 분석을 기반으로 한 바이오정보 보호 가이드라인 개선 방안 KCI 등재
한국융합보안학회 융합보안논문지 제18권 제3호 2018.09 pp.87-94
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
프라이버시는 개인의 사생활이나 사적인 일이 타인에게 공개되지 않을 권리를 뜻한다. 바이오정보는 그 사람 자체에 대한 가장 사적인 개인정보로 기술이 발전함에 따라 개인 식별뿐만 아니라 개인에 대한 분석 및 판단까지도 가능하다. 개인정보보 호법은 글로벌 프라이버시 원칙들을 기반으로 하여 만들어 졌으나 바이오정보보호를 위한 법제는 아직 제정되어 있지 않으며, 가이드라인으로 규정되어 있다. 이에 바이오정보를 일반 개인정보보다 더욱 민감한 정보로서 보호해야 할 시점에 이르러 바이 오정보 보호를 위한 국제적인 프라이버시 논의들을 살펴보고 최근 개정된 바이오정보 보호 가이드라인을 개선할 수 있는 프 라이버시 원칙들과 바이오정보의 활용을 위한 조치 사항을 제안하고자 한다.
Privacy means the right not to interfere with the private life of an individual. Bio data is the most private personal information about the person itself, and according to advancement of technology, it is possible to analyze and judge individual as well as identify individual. The Personal Information Protection Act is based on global privacy principles, but the legislation for the protection of bio information has yet to be enacted. Therefore, it is time to protect biometric data as more sensitive information than general personal information. We will review the global privacy discussions for protecting biometric information and propose additional privacy principles and measures for utilization that should be defined in the biometric information protection guideline.
eHealth 클라우드 시스템을 위한 생체정보-스마트카드 기반 인증 프로토콜의 보안 취약점 분석 및 개선 방안 KCI 등재후보
중소기업융합학회 산업과 과학 제5권 제2호 2026.03 pp.84-89
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
본 논문은 eHealth 클라우드 시스템을 위해 설계된 생체정보 및 스마트카드 기반 인증 프로토콜에 대한 포괄적인 보안 분석과 개선안을 제시한다. 분석 결과, 세션키 생성의 취약성, 전방향 기밀성 부재, 재전송(replay) 공격에 대한 노출, 생체정보 누출 가능성 등 핵심 취약점이 확인되었다. 이를 완화하기 위해 본 연구는 강건한 암호 학적 보호기법을 통합한 향상된 프로토콜을 제안한다. 주요 개선점은 전방향 기밀성 확보를 위한 일회성 키 교환 (ephemeral key exchange) 채택, 생체 템플릿 보호를 위한 퍼지 추출기(fuzzy extractor) 적용, 그리고 재전송 시도를 차단하기 위한 상호 논스 검증(mutual nonce verification) 도입이다. 시뮬레이션 및 IoT 환경에서의 실 험 평가 결과, 제안한 개선 설계는 계산 오버헤드를 소폭만 증가시키면서도 주요 공격 벡터에 대한 저항성을 유의 미하게 강화함을 확인하였다. 따라서 본 연구의 스킴은 자원 제약이 있는 eHealth 응용에서 적용 가능한 안전·효 율·실용적 인증 해법을 제공한다.
This paper conducts a security analysis of a biometric and smartcard-based protocol for eHealth clouds, identifying weaknesses in key generation, forward secrecy, and replay attack resilience. An enhanced protocol is proposed, featuring ephemeral key exchange, a fuzzy extractor for biometrics, and mutual nonce verification. Evaluation in IoT settings confirms it strengthens security against major threats with low computational overhead, providing a practical and efficient solution for eHealth systems.
네트워크 바이오 인증 기반 산업기술 유출방지 시스템에 관한 연구 KCI 등재후보
한국융합보안학회 융합보안논문지 제11권 제4호 2011.08 pp.31-36
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
첨단기술을 보유하고 있는 기업이나 핵심정보를 처리하는 정보기관은 조직의 기밀이 유출되는 시점에서 막대한 경제적 손실은 물론, 치명적인 피해에 따른 조직의 존립 자체가 흔들리게 된다. 기존의 오프라인으로 유출되던 기밀정보는 최근 유비쿼터스 통신 환경을 기반으로, 다양한 장비를 통해 언제든지 네트워크를 통해 유출이 가능해졌다. 본 논문에서는 네트워크로 전송되는 기밀유출을 차단하기 위해 전송되는 모든 패킷에 대해 실시간으로 패킷을 인증하고 차단하는 통신 프로토콜을 제안한다. 특히, 기밀유출을 시도하는 사용자를 구분하기 위하여 전송되는 패킷마다 사용자 바이오 정보를 투명하게 삽입하는 기법을 제시한다. 또한, 실험을 통해 사용자 바이오 정보를 삽입하고 패킷마다 인증하더라도 효과대비 그 성능이 크게 저하되지 않음을 확인한다.
Enterprise which has a core technology or organization which manages a core information will be walking into a critical situation like a ruins when organization's confidential information is outflowed. In the past confidential information that was leaked to the off-line, recently the outflow made possible through a variety of equipment at any time via the network based on theubiquitous communication environment. In this paper, we propose to authenticate and block all packets transmitted via the network at real-time in order to prevent confidentials outflow. Especially in or der to differentiate between users who attempt to disclose confidentials, we propose to insert user's biometric informaion transparently at per-packet basis, and also verify a performance by simulation
Enhanced Biometric-based User Authentication Protocol Using Non-tamper Resistant Smart Cards SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.9 No.12 2015.12 pp.129-136
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
This paper reviews An’s enhanced biometric-based user authentication protocol and shows that it is weak against the password guessing attack and has a problem of verification in the authentication phase. They are very important features to be secured to the user authentication protocol. Furthermore, this paper proposes an enhanced biometric-based user authentication protocol using non-tamper resistant smart cards to solve the problems in An’s protocol. The overall security analyses show that the proposed protocol could achieve the desired security goals.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.