Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 1
No
1

Structural Vulnerability Analysis of a Chebyshev Chaotic Map-Based TMIS Authentication Protocol KCI 등재후보

Haewon Byeon

한국융합학회 미래기술융합논문지 제5권 제2호 2026.06 pp.81-87

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

원격의료정보시스템(TMIS)은 개방형 통신 환경에서 다양한 보안 공격에 노출된다. 본 연구에서 취약점 탐지 결과 기존의 체비쇼프 혼돈 사상(CCM) 기반 3요소 인증 및 두 메시지 교환 방식의 TMIS 인증 프로토콜은 첫째, 타임스탬프 단독 신선도 검증으로 인한 서비스 거부(DoS) 취약점(V1). 둘째, 스마트 카드 탈취 및 서버 DB침해 복합 공격 시 사용자 비밀 인자 복원 가능성(V2). 셋째, 서버 비밀 키 노출 시 완전 순방향 비밀성(PFS)이 성립하지 않는 취약점(V3)의 세 가지 구조적 취약점이 확인되었다. 본 연구에서는 개선 방안으로 타임스탬프-논스 결합 검증, 서버 비밀 키 의존성을 제거한 세션 키 유도, 스마트 카드 인자의 분산 저장을 제안하였고, 시뮬레이션 결과 계산 오버헤드 1.3% 미만 증가로 모든 취약점이 해소됨을 확인하였다. 다만 본 연구의 검증은 수식 기반 공격 추적과 시뮬레이션 비교에 근거한 것이며, 개선 프로토콜의 완전한 형식적 안전성 증명은 향후 과제로 남는다.

This paper examines CCM-based TMIS protocol and identifies three structural weaknesses: (1) DoS vulnerability from timestamp-only freshness checks, (2) compound attacks enabling recovery of Tx(Idi||ni) via smart-card theft and server DB exposure, and (3) failure of perfect forward secrecy (PFS) when the server secret x is exposed. We propose nonce-bound freshness verification, a session-key derivation independent of x, and distributed storage of smart-card factors. Simulations show that the improved protocol eliminates all vulnerabilities with less than 1.3% additional computation overhead.

 
페이지 저장