년 - 년
클라우드 데이터센터로의 전환을 위한 보안요건 - N데이터센터를 중심으로 KCI 등재
한국디지털정책학회 디지털융복합연구 제12권 제11호 2014.11 pp.299-307
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
N데이터센터는 정부부처를 대상으로 클라우드 컴퓨팅 서비스를 제공하는 '클라우드 컴퓨팅센터'로 변모를 꾀하고 있으며, 각 부처에 필요한 만큼 정보자원을 서비스 형태로 제공하는 'IT서비스 센터'로 탈바꿈 예정이다. N센 터 8중의 보안체계 하에서 클라우드서비스가 이미 정부부처에 제공되고 있으며, 향후 보안을 전제조건으로 민간분야 까지 확대할 계획이다. 따라서 보안은 민간분야와의 클라우드 확산에 있어 선결요건이며, 이의 체계적이고 효율적 추 진을 위해서 클라우드 데이터 센터로서의 보안수준을 파악하고 적절한 방안을 제시할 필요가 있다. 본 연구에서는 이를 위해 선진 각국의 클라우드 데이터 센터의 보안 요건을 분석하고 클라우드 서비스 형태에 클라우드 컴퓨팅의 취약점을 파악하고, 선진 민간 클라우드 데이터 센터의 보안수준을 파악하고, 현행 N데이터센터 보안 수준과 선진 민간 클라우드 데이터센터와의 갭을 분석하여 보안관점에서 전환을 위한 요건을 제시하였다.
N-Data Center which provide of cloud computing service for the Government departments, will be prepared transforming to cloud data center and transformed into an 'IT service' provided as a service to the information resources required by each department. N-Data center already provide a cloud service to the departments as maintains a high level of security, and plan to connecting with the private sector as a precondition of security. Therefore, in order to promote them effectively, it is necessary to determine the level of security in the cloud data center, and we have proposed appropriate measures. In this paper, we analyze security requirements of cloud data centers in developed countries and identify the leading private cloud data center security. In addition, we identify the N-data center security level, and analyzes the data center and private cloud gap and provide a transition strategy in terms of security finally.
뉴스 데이터 토픽 모델링을 활용한 COVID-19 대유행 전후의 클라우드 보안 동향 파악 KCI 등재
한국융합보안학회 융합보안논문지 제22권 제2호 2022.06 pp.67-75
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
COVID-19 대유행으로 인해 많은 기업에서 재택근무를 도입했다. 하지만 재택근무 도입으로 기업의 민감한 정보에 접근하려는 공격 시도가 증가했고, 보안위협에 대응하기 위해 많은 기업에서 클라우드 서 비스를 이용하기 시작했다. 본 연구는 COVID-19 대유행 전후의 국내 클라우드 보안 동향의 변화를 분석 하기 위해 ‘클라우드 보안’ 키워드로 뉴스 데이터를 수집하여 LDA 토픽 모델링 기법을 사용했다. COVID -19 대유행 전에는 국내 클라우드 보안에 대한 관심이 낮아 추출한 토픽에서 대표성이나 연관성을 찾을 수 없었다. 다만, 현재 많은 연구가 이뤄지는 IT기술인 AI, IoT, 블록체인을 위해서는 높은 컴퓨팅 성능 을 위해 클라우드의 도입이 필요하다는 것을 분석할 수 있었다. 반면, COVID-19 대유행 이후 추출된 토 픽을 보면 국내에서 클라우드에 대한 관심이 증가했고, 이에 따라 클라우드 보안에 대한 관심이 향상된 것을 확인했다. 따라서 앞으로 계속 증가할 클라우스 서비스 사용량에 대비한 보안 대책을 수립해야 할 것이다.
Due to the COVID-19 pandemic, many companies have introduced remote work. However, the introduction of remote work has increased attacks on companies to access sensitive information, and many companies have begun to use cloud s ervices to respond to security threats. This study used LDA topic modeling techniques by collecting news data with the k eyword 'cloud security' to analyze changes in domestic cloud security trends before and after the COVID-19 pandemic. Be fore the COVID-19 pandemic, interest in domestic cloud security was low, so representation or association could not be fo und in the extracted topics. However, it was analyzed that the introduction of cloud is necessary for high computing perfo rmance for AI, IoT, and blockchain, which are IT technologies that are currently being studied. On the other hand, looking at topics extracted after the COVID-19 pandemic, it was confirmed that interest in the cloud increased in Korea, and accor dingly, interest in cloud security improved. Therefore, security measures should be established to prepare for the ever-incr easing usage of cloud services.
Encryption Techniques for Cloud Data Confidentiality
보안공학연구지원센터(IJGDC) International Journal of Grid and Distributed Computing Vol.7 No.4 2014.08 pp.11-20
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Cloud computing is one of the fastest growing internet based technology that facilitates users to utilize services by making use of large poll of resources without installation of any software. Adoption of this technology is increasing rapidly because of many advantages including reduction of cost and IT load. Despite the popularity of cloud computing, it faces many difficulties such as security that is one of the major inhibitors in the growth of cloud computing. Data confidentiality is at the top of the list of security concern for this technology. Many methods have been introduced to overcome this issue; encryption is one of them and widely used method to ensure the data confidentiality in cloud environment. In this study, an attempt is made to review the encryption techniques used for the data confidentiality. The results of review are classified on the basis of type of approach and the type of validation used to validate the approach.
Research of Data Security Model in Cloud Computing Platform for SMEs SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.7 No.6 2013.11 pp.97-108
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
In recent years, cloud computing has become a major mode to address SMEs inefficient and help improve their competitiveness. As cloud providers have priority access to data, so it is difficult to guarantee the confidentiality and integrity of users’ data. For this reason this paper proposed a model to solve the problem of data security in cloud computing. The model adopts efficient encryption mechanisms to protect users’ data. As the encrypted data is difficult to retrieve, we present a method of cipher text retrieval. Experimental results show that the model can better ensure data confidentiality and integrity.
A Study on Security Technique of Cloud Data Processing in Electronic Commerce SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.8 No.2 2014.03 pp.283-290
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
In the age of e-commerce, the issue of information leakage of internet users is a wide concern. The e-commerce enterprises should be prepared to deal with network data processing security, and to avoid various inconveniences led by the loss of data information. In this study, the "business to customer" (B2C) cloud data processing model is taken as an example to propose a security countermeasure for network data processing based on cloud computing platform. The cloud network computing model is adopted for the automated processing on B2C network data. Based on the network overlapping relationship and model settings, the security workflow of the cloud data computing processing is built. Moreover, the overlapping network plan and flow network technique are considered as the basis of the model, and a diversified security control platform is created by combining with modeling tools.
Data Security Monitoring Platform in Cloud for Enterprise SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.7 No.6 2013.11 pp.67-78
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Now most software systems in cloud platform use Multi - Tenancy architecture. A single software system serves for multiple client organization. All customers’ data will not be stored in only one node. So the system needs higher data security mechanism. This paper wants to build a data security monitoring model in cloud platform for large enterprises. The model can set the authentication, logging, fine-grained access control, dynamic data filtering strategy and data audit to realize the security protection for enterprises data. The model proposed by this paper uses multi-tenancy SaaS(Software as Service) application architecture, RBAC (Role-Based policies Access Control) model and operation in the context of environmental perception to realize the data access control. It using PMI framework to provide accession management services for enterprise users.
Security Data Auditing based on Multifunction Digital Watermark for Multimedia File in Cloud Storage SCOPUS
보안공학연구지원센터(IJMUE) International Journal of Multimedia and Ubiquitous Engineering Vol.9 No.9 2014.09 pp.231-240
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Cloud computing is a promising computing model that enables convenient and on-demand network access to a shared pool of configurable computing resources. In cloud computing, data owners host their data on cloud servers and data consumers can access the data from cloud servers. This new paradigm of data storage service also introduces new security challenges, because data owners and data servers have different identities and different business interests. Therefore, an independent auditing service is required to make sure that the data is correctly hosted in the Cloud. However, the existing solutions are not specific to the multimedia data. Moreover copyright protection is not provided. In this paper, we define specially a provable data possession model for multimedia file, and present a framework based on digital watermarking for multimedia data storages audit service, in which we analyze the security features of audit service for multimedia data outsourcing and the corresponding properties of digital watermarking. Moreover as an example, we present a provable data possession scheme based on double function self-embedded digital watermark, which integrate image content audit service and copyright protection.
A Proxy-Based Data Security Solution in Mobile Cloud SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.9 No.5 2015.05 pp.77-84
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
This paper proposes a data security solution in mobile cloud, which solves the security issues in the mobile client and cloud. The proposed solution also relieves the performance limitation of mobile client when executing security technologies. The analysis about the security, feasibility, compatibility and expansibility and the experiment suggests the proposed solution is rational.
The Research of Data Security Mechanism Based on Cloud Computing SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.9 No.3 2015.03 pp.363-370
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
With the wide use of cloud computing services, users require higher and higher security. So the safety of cloud computing is the first consideration of users to choose. In the development of cloud computing, the application proportion of virtualization gradually increase, the scope and depth of the safety gradually expand. The related concepts of cloud computing and development situation are introduced in this paper. Not only the key technologies of cloud computing security are analyzed, but also a cloud security framework is put forward combined with the current security problems needed to resolve in cloud computing. We analyze and compare the present research results of security model and mechanism in the cloud. At last, we propose a security mechanism based on cloud computing.
Security System for Healthcare Data in Cloud Computing SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.8 No.3 2014.05 pp.241-248
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Cloud computing is a renowned computing method of sharing data resources whether publicly or privately. Cloud computing is an answer for a better computing environment. It will reduce the costs which are used efficiently. Cloud computing can be used not only for business purposes but also for medical purposes which will be used by patients, specialists, pharmacists, nurses, doctors, and hospital administrations. As an implication, security is an important issue for cloud computing. Data privacy protection and data retrieval control are security issues for cloud computing. This Paper describes security elements like monitoring, recording, tracking and notification. For the purpose of encryption-decryption, AES-256/SHA will be used. Re-encryption "tag" and "mark" for data access system will only be functional for every legal user. It suggests that the cloud computing based on encryption and decryption services. Encrypted medical data could be accessed and decrypted from anywhere and whomever with particular authentication. The writer proposed the constructive idea of Healthcare data via cloud computing and the security accessing data by authorized individuals.
A New Innovation on User’s level Security for Storage Data in Cloud Computing
보안공학연구지원센터(IJGDC) International Journal of Grid and Distributed Computing Vol.7 No.3 2014.06 pp.213-220
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
In Cloud Computing data security as well as load balancing of cloud server is very important and most challenging issues. Cloud reduces cost by providing on demand access of resources, it provides guaranteed, reliable services and dynamic allocation of resources. In cloud a single server stores very huge amount of data so there is need to balance load and provide fast transmission on cloud. Many users store their information on a single server, so there are chances of threats by unauthorized user. As we know on cloud we don’t have control over our data so security is a very important and challenging issue for cloud. If any algorithm provides fast transmission between user and server then there would be minimum chances for congestion and the data spend minimum time on transmission channel so it will give minimum time to attack on their data. In this paper, I proposed an ides and try to implement an algorithm through which cloud service provider can give the control to user itself. This algorithm uses a key and that key should be unknown from unauthorized person, the key may be user’s password or any secret information then this algorithm will give control to user and provide better security for user’s data where user would be free from authentication, correctness integrity or confidentiality. It is very important to .give control on user’s hand for reliability of services. Keywords:
Cloud Security Mechanisms for Data Protection : A Survey SCOPUS
보안공학연구지원센터(IJMUE) International Journal of Multimedia and Ubiquitous Engineering Vol.9 No.9 2014.09 pp.81-90
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Cloud computing has evolved over the years in providing various services to the end users. The cloud features makes it acceptable by the industries in leveraging most of its applications in to the cloud. Security concerns exist in most cloud platforms and are prone to various attacks. This paper focuses on various security mechanisms that are provided in the enterprises and also discusses few of the common security mechanisms like authentication, authorization, encryption and access control. The methods deployed within each security mechanisms are also analyzed.
Security Techniques for Data Protection in Cloud Computing SCOPUS
보안공학연구지원센터(IJGDC) International Journal of Grid and Distributed Computing Vol.9 No.1 2016.01 pp.49-56
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Cloud computing has a lot of security issues that are gaining great attention nowadays, including the data protection, network security, virtualization security, application integrity, and identity management. Data protection is one of the most important security issues, because organizations won’t transfer its data to remote machines if there is no guaranteed data protection from the cloud service providers. Many techniques are suggested for data protection in cloud computing, but there are still a lot of challenges in this subject. The most popular security techniques include SSL (Secure Socket Layer) Encryption, Intrusion Detection System; Multi Tenancy based Access Control, etc. Goal of this paper is to analyze and evaluate the most important security techniques for data protection in cloud computing. Furthermore, security techniques for data protection will be recommended in order to have improved security in cloud computing.
An Improved Security Mechanism for Protecting Data in Mobile Cloud Environment
보안공학연구지원센터(IJAST) International Journal of Advanced Science and Technology Vol.89 2016.04 pp.37-44
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Cloud computing is a popular technology that provides services to the users on demand and on pay-per-usage fee that is they only pay for the data utilized when required. With the vast growth in the use of mobile phone applications, the users are relying on their phones for their personal as well as professional work and suffering from many problems (storage, processing, security etc). To overcome these limitations and growth in the use of cloud applications, a new development area has emerged recently called as Mobile cloud computing. Mobile cloud computing is an integration of three technologies cloud computing, mobile computing and internet, enabling the users to access the services at any time and from any place. Mobile phones are sensitive devices and the personal data is not secured when user stores data on cloud and can be easily attacked by unauthorized person. This paper presents a high level authentication and encryption model through a mobile application that encrypts the data before moving it to the cloud that ensures the security and the strong user authentication.
Reversible Data-hiding Algorithm in Encrypted Image for Security Application in Cloud Computing SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.7 2016.07 pp.59-70
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
There is a shortcoming in reversible data-hiding algorithm in encrypted images, it is the low capacity. we put forward a new algorithm oriented security application in cloud computing, in the new algorithm of reversible data-hiding algorithm in encrypted image, we bring in cloud computing service and singular value decomposition based on matrix. Using the powerful computing and storage capacity, compute the singular value decomposition of some selected bit planes of the encrypted image, and store the recovery dictionary that generated in this process, in the end ,we directly embed the information into the singular value matrix. Experimental results show that under the premise of ensured image privacy security and higher image fidelity, the embedding capacity has been significantly improved, and the image can be fully recovered after information extraction. In the same time, the processes of information extraction and image restoration are separable. Compared with other algorithms, it has higher embedding capacity.
Data Security in Cloud environments
[NRF 연계] 사단법인 미래융합기술연구학회 아시아태평양융합연구교류논문지 Vol.1 No.4 2015.12 pp.25-31
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
ntentional or unintentional leakage of confidential data is without a doubt a standout amongst the most serious security dangers that associations confront in the computerized period. The danger now reaches out to our own lives: a plenty of individual data is accessible to informal communities and advanced mobile phone suppliers and is in a roundabout way exchanged to dishonest outsider and fourth gathering applications. In this work, we display a non specific information heredity structure LIME for information stream over various substances that take two trademark, chief parts (i.e., proprietor and shopper). We characterize the correct security ensures required by such an information ancestry system toward ID of a blameworthy element, and recognize the improving non-revocation and trustworthiness presumptions. We then create and break down a novel responsible information exchange convention between two substances inside a noxious situation by expanding upon unaware exchange, powerful watermarking, and mark primitives. At long last, we play out a test assessment to exhibit the reasonableness of our convention and apply our system to the imperative information spillage situations of information outsourcing and interpersonal organizations. All in all, we consider LIME , our genealogy system for information exchange, to be a key stride towards accomplishing responsibility by plan.
Hybrid Data Management in Cloud Security
[NRF 연계] 사단법인 미래융합기술연구학회 아시아태평양융합연구교류논문지 Vol.1 No.4 2015.12 pp.33-39
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
Trust administration is a standout amongst the most difficult issues for the adoption and growth of cloud computing. The very dynamic, distributed, and non-transparent nature of cloud .Saving buyers' security is not a simple assignment because of the delicate data required in the cooperations amongst customers and the trust administration benefit. Ensuring cloud administrations against their noxious clients (e.g., such clients may give misdirecting criticism to detriment a specific cloud administration) is a troublesome issue. Ensuring the accessibility of the trust administration is another noteworthy test in light of the dynamic way of cloud situations. In this article, we depict the outline and usage of CloudArmor, a notoriety based trust administration system that gives an arrangement of functionalities to convey trust as a service (TaaS), which incorporates i) a novel convention to demonstrate the validity of trust criticisms and safeguard clients' security, ii) a versatile and vigorous believability display for measuring the believability of trust inputs to shield cloud administrations from malignant clients and to analyze the dependability of cloud administrations, and iii) an accessibility model to deal with the accessibility of the decentralized execution of the trust administration benefit. The feasibility and advantages of our approach have been approved by a model and exploratory reviews utilizing a gathering of real-world trust inputs on cloud administrations.
클라우드 컴퓨팅 서비스 도입에 따른 데이터보안에 관한 연구
[Kisti 연계] 한국정보통신학회 한국정보통신학회 학술대회논문집 2012 pp.736-739
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
클라우드 컴퓨팅(Cloud Computing)이 주목받고 활성화되면서 각 기업들 및 공공기관 등에서 급속도로 확산 및 도입되어지고 있다. 이러한 영향으로 인해 클라우드 컴퓨팅 기술을 이용한 정보시스템 자원의 활용과 통합은 크게 각광 받고 있으며 이에 따른 데이터 보안 또한 이슈화되고 있다. 본 논문에서는 클라우드 컴퓨팅 시스템 도입으로 인한 정보시스템의 자원 즉 데이터보안에 관한 측면을 조명하여 클라우드 컴퓨팅 인프라 구축을 위한 기반 지식을 제공하고자 한다.
Cloud Computing is attracting attention are activated and rapidly spread to companies and public institutions, etc. have been introduced are getting. Spotlighted these effects due to the utilization and integration of information system using cloud computing technology resources, and the resulting data security issue has been. In this paper, the side lights on due to the introduction of a cloud computing system, the resources of information systems, data security, and knowledge to provide the foundation for cloud computing infrastructure.
안전한 클라우드 데이터센터 구축을 위한 보안요구사항 분석
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2012 pp.931-933
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
IT기술 및 인터넷의 발전으로 시 공간의 제약 없이 다양한 서비스를 제공받을 수 있는 클라우드 컴퓨팅 기술이 등장하게 되었다. 이로 인해 기존 데이터센터를 가상화 및 클라우드 컴퓨팅 기술과 융합한 클라우드 데이터센터로 전환하여 개인용 클라우드 서비스(Private Cloud Service)나 외부 기업 등에게 아웃소싱 하여 공개형 클라우드 서비스(Public Cloud Service)를 제공하고 있다. 그러나 클라우드 환경은 기존의 IT환경에서 발생한 악성코드를 이용한 데이터 해킹 및 유출과 같은 보안 위협이 존재하며, 새로운 보안 위협들이 발생하고 있다. 따라서 본 논문에서는 안전한 클라우드 데이터센터 구축을 위한 보안요구사항에 대해서 분석한다.
안전한 클라우드 데이터센터 구축을 위한 보안요구사항 분석
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2012 pp.931-933
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
IT기술 및 인터넷의 발전으로 시 공간의 제약 없이 다양한 서비스를 제공받을 수 있는 클라우드 컴퓨팅 기술이 등장하게 되었다. 이로 인해 기존 데이터센터를 가상화 및 클라우드 컴퓨팅 기술과 융합한 클라우드 데이터센터로 전환하여 개인용 클라우드 서비스(Private Cloud Service)나 외부 기업 등에게 아웃소싱 하여 공개형 클라우드 서비스(Public Cloud Service)를 제공하고 있다. 그러나 클라우드 환경은 기존의 IT환경에서 발생한 악성코드를 이용한 데이터 해킹 및 유출과 같은 보안 위협이 존재하며, 새로운 보안 위협들이 발생하고 있다. 따라서 본 논문에서는 안전한 클라우드 데이터센터 구축을 위한 보안요구사항에 대해서 분석한다.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.