년 - 년
스마트팩토리 확산을 위한 비파일시스템(None File System) 기반의 차세대 데이터보호에 관한 연구 KCI 등재
한국재난정보학회 한국재난정보학회논문집 제17권 1호 통권51호 2021.03 pp.176-183
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
연구목적: 우리나라 최근 4차 산업 혁명의 핵심 기술인 인공지능(AI), 사물인터넷(loT), 가상현실(VR) 등을 제조 환경에 반영한 스마트공장 도입이 활발히 추진되고 있다. 그러나 기존 운영체제 기반의 파일 시스템에서 발생하는 각종 문제점을 해결하고자 비파일시스템 기반의 데이터보호 기술을 연구·검증하 고자 한다. 연구방법: 본 연구에서는 운영체제에 의해 식별되거나 제어되지 않는 보안저장부와 디지털 키 값의 입력에 따라 보안 저장부를 활성화할 수 있는 방법연구와 BIOS 동작 시 연결을 위한 입출력 정보만 제공하는 제어부를 설정하고 보안 저장부의 활성화에 따라 제2 메타 데이터를 사용한 맵핑 동작을 수행할 수 있도록 비파일형태의 구 조를 연구함. 연구결과: 첫째, 비파일시스템 기반의 보안 저장부의 생성과 데이터 입출력 시 데이터 손상 여부를 샘플 데이터의 해시함수 값 과 일반 저장부 및 보안 저장부의 해시함수 값을 비교하여 일치하는 것을 확인하였음. 둘째, 보안 저장부의 데이터 보호 성능 실험에서는 원 본 파일의 해시함수 값과 랜섬웨어 활동 이후의 일반 저장부와 보안 저장부의 해시함수 값을 비교하여 악성코드인 랜섬웨어로부터 데이터 보호 성능을 확인함. 결론: 본 연구는 국가적으로 추진하고 있는 스마트팩토리 구축 사업을 통해 기업에 도입되고 있는 정보시스템 내의 중 요 데이터를 보호하기 위한 새로운 개념의 데이터 보호 기술을 구현하고 실험하였다. 정보보안의 목적인 중요 데이터의 보호를 위해 기존의 저장 개념과 달리 파일 시스템에 비의존적인 비파일 형태의 보안 저장부 생성기술을 구현하였고 그 안전성을 검증하였음.
Purpose: The introduction of smart factories that reflect the 4th industrial revolution technologies such as AI, IoT, and VR, has been actively promoted in Korea. However, in order to solve various problems arising from existing file-based operating systems, this research will focus on identifying and verifying non-file system-based data protection technology. Method: The research will measure security storage that cannot be identified or controlled by the operating system. How to activate secure storage based on the input of digital key values. Establish a control unit that provides input and output information based on BIOS activation. Observe non-file-type structure so that mapping behavior using second meta-data can be performed according to the activation of the secure storage. Result: First, the creation of non-file system-based secure storage’s data input/output were found to match the hash function value of the sample data with the hash function value of the normal storage and data. Second, the data protection performance experiments in secure storage were compared to the hash function value of the original file with the hash function value of the secure storage after ransomware activity to verify data protection performance against malicious ransomware. Conclusion: Smart factory technology is a nationally promoted technology that is being introduced to the public and this research implemented and experimented on a new concept of data protection technology to protect crucial data within the information system. In order to protect sensitive data, implementation of non-file-type secure storage technology that is non-dependent on file system is highly recommended. This research has proven the security and safety of such technology and verified its purpose.
협업을 위한 클라우드 스토리지에서의 사용자 인증과 데이터 보호에 관한 연구 KCI 등재
한국디지털정책학회 디지털융복합연구 제12권 제9호 2014.09 pp.153-158
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
협업을 위한 클라우드 스토리지란 협업에 참여하는 사용자들이 클라우드 스토리지를 공유하여 이용하는 것 을 말한다. 협업에 이용되는 클라우드 스토리지는 여러 사람이 새로운 데이터를 저장하고 다른 사용자의 저장된 데 이터를 읽을 수 있기 때문에 협업에 참여하는 사용자에 대한 인증과 데이터 보호의 문제가 일반의 그것보다 더 중 요하다 할 것이다. 이에 본 논문에서는 협업을 위한 클라우드 스토리지를 공유하는 사용자에 대한 인증 방법과 저장 된 데이터를 보호하는 방법을 제안하고자 한다.
The Collaborative Cloud Storage is that several members of collaborating group together use data stored in a storage. Therefore, it is obvious that it is more complicated and important to protect data stored in the sharing storage than general cloud storage, not Collaborative Cloud Storage. this paper proposes a method for user authentication and data protection.
클라우드 시스템에서의 사용자 데이터 보호에 관한 연구 KCI 등재
한국디지털정책학회 디지털융복합연구 제10권 제11호 2012.12 pp.389-394
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
클라우드 컴퓨팅은 인터넷 기술을 활용하여 IT자원을 서비스로 제공하는 컴퓨팅으로 최근 많은 관심을 받고 있다. 클라우드 스토리지 서비스들은 사용자에게 편리함을 제공하지만, 그러나 사용자 데이터에 대한 접근을 데이터 소유자가 통제하기 어렵기 때문에 데이터 기밀성을 보장하지 못하는 문제점이 있다. 본 논문에서는 클라우드 시스템에서 사용자 데이터 보호를 위하여 사용자 데이터를 블록으로 분할하여 그 중 한 블록에 대해서만 공개키 암호화 방식을 이용한 기법을 제안하였다. 따라서 클라우드 스토리지 서버에 저장된 사용자 데이터에 대한 기밀성과 무결성을 제공한다.
The cloud computing is a system that provides IT resources service by using internet technologies, which grabs lots of attention today. Though cloud storage services provide service users with convenience, there is a problem in which data confidentiality is not guaranteed because it is hard for data owners to control the access to the data. This article suggested the technique by applying Public-Key Cryptosystem only to a block after dividing users’ data into blocks in order to protect users’ data in cloud system. Thus confidentiality and integrity are given to users’ data stored in cloud storage server.
AI와 게임 개발의 융합 : 기술 스택의 재구성과 산업·윤리적 함의 KCI 등재후보
제주대학교 융합과학기술사회연구소 융합과학기술사회연구 제5권 1호 2026.06 pp.37-40
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
게임은 인공지능(AI)의 연구·검증·상용화가 동시에 일어나는 대표적 응용 영역이다. 전통적으로 게임 AI는 규칙 기반(상태기계, 행동트리)과 탐색(미니맥스 등)에 기반해 NPC 행동을 구현해 왔다. 그러나 딥러닝과 강화학습의 발전은 게임 제작 파이프라인 전반(기획-개발-운영)에서 데이터 기반 의사결정, 콘텐츠 생성, 플레이어 모델링/개인화를 가능하게 하며, 게임을 "정적 콘텐츠"에서 "동적 경험 시스템"으로 전환시키고 있다. 본 글은 (1) 게임 AI의 기술 계보를 정리하고, (2) 현대 게임 개발에서의 AI 적용 지점을 제작 파이프라인 관점에서 체계화하며, (3) 대표 연구·사례(AlphaStar, OpenAI Five, MuZero, PCGML 등)를 통해 기술적 성취와 한계를 비교 분석한다. 마지막으로 (4) 데이터·프라이버시, 공정성, 설계 윤리(특히 확률형 아이템) 측면의 쟁점을 검토하고, 지속 가능한 융합을 위한 연구 과제를 제시한다.
Games are a representative application area where research, verification, and commercialization of artificial intelligence (AI) occur simultaneously. Traditionally, game AI has implemented NPC behaviors based on rule-based approaches (state machines, behavior trees) and exploration (e.g., minimax). However, advances in deep learning and reinforcement learning are enabling data-driven decision-making, content creation, and player modeling/personalization across the entire game development pipeline (planning, development, and operation), transforming games from "static content" to "dynamic experience systems." This paper (1) summarizes the technological genealogy of game AI, (2) systematizes AI application in modern game development from a production pipeline perspective, and (3) compares and analyzes technical achievements and limitations through representative studies and case studies (e.g., AlphaStar, OpenAI Five, MuZero, and PCGML). Finally, (4) examines issues related to data privacy, fairness, and design ethics (especially regarding random items), and proposes research challenges for sustainable convergence.
업무용 생성형 AI 모델의 안전한 활용을 위한 중요 기술정보 개체명 인식 및 비식별화 기법 개발 연구 KCI 등재
한국산업안보학회(구 한국산업보안연구학회) 한국산업보안연구 제16권 특별호 2026.01 pp.1-26
※ 기관로그인 시 무료 이용이 가능합니다.
6,400원
최근 기업 및 공공기관에서 생성형 AI 기술을 적극적으로 도입하여 업무 자동화와 생산성이 향상되는 반면, 민감한 기술 정보 유출 위험도 증가하고 있다. 기존 연구는 개인정보 재식별 위 험 측정이나 악성 프롬프트 및 데이터 오염 대응에 주목하고 있어 업무 시 발생하는 중요기술 유 출 문제를 실시간으로 대응하기에 한계가 존재한다. 본 연구는 업무용 생성형 AI 모델의 안전한 활용을 위해 프롬프트 입력문서 내 중요 기술 정보를 식별하고 비식별처리하는 기술보존 비식별 화 기법을 제안한다. 구체적으로, 개체명 인식 기법으로 중요기술용어를 BIO 태깅하고, 퓨샷 기 반 거대언어모델을 활용하여 핵심 기술어를 추출한다. 이후 k-익명성 기반 기술보존 비식별화를 적용하여, 마스킹·대체어·토큰화와 비교분석한다. 특허 대표청구항을 대상으로 실험한 결과, BIO 태깅을 통한 기술용어 인식 정확도와 비식별화 전후 문서 간 의미론적 유사도가 높게 나타 나 원문 기술 정보 보존 효과를 확인하였다. 본 연구는 생성형 AI의 안전한 활용을 위한 실질적 방안을 제시함으로써, 기술정보 유출 방지와 업무 품질 유지를 동시에 달성할 수 있는 새로운 패 러다임을 제안하여 산업적·학문적 기여를 도모한다. 향후 연구에서는 다양한 산업 도메인에 적 용한 프레임워크로 확장하여 범용성을 확보하고자 한다.
While enterprises and public institutions are actively adopting generative AI technologies to enhance work automation and productivity, the risk of sensitive technical information leakage has also increased. Existing research has primarily focused on measuring personal information re-identification risks and addressing malicious prompts and data poisoning, presenting limitations in real-time response to critical technology leakage issues during business operations. This study proposes a technique-preserving de-identification method to identify and de-identify critical technical information in prompt input documents for the safe utilization of generative AI models in business contexts. Specifically, the approach employs Named Entity Recognition techniques to perform BIO tagging of important technical terms and utilizes few-shot learning to extract key technical terminology. Subsequently, masking, substitution, and tokenization methods are compared and applied. Experimental results on representative patent claims demonstrate high accuracy in technical term recognition through BIO tagging and high semantic similarity between documents before and after de-identification, confirming the effectiveness of preserving original technical information. This research presents a practical solution for safe generative AI utilization, proposing a new paradigm that simultaneously achieves technical information leakage prevention and work quality maintenance, thereby contributing to both industrial and academic advancement. Future research aims to expand the framework to various industrial domains to ensure broader applicability.
개인정보 라이프 사이클 모델 선택 시 고려 요소 : 선형과 순환형을 중심으로 KCI 등재
한국융합보안학회 융합보안논문지 제25권 제1호 2025.03 pp.47-57
※ 기관로그인 시 무료 이용이 가능합니다.
4,200원
본 연구는 개인정보 라이프 사이클의 사용에 있어서 어떠한 경우에 선형 또는 순환형을 선택하는 것이 타당한지를 실증 적으로 분석해 개인정보 처리의 효율적성과 체계성을 높이는 것을 목표로 했다. 이를 위해 본 연구는 선형 모델인 영향평가모 델, 인공지능 학습 특성 고려 모델과 순환형인 동의 관리 기반 모델, 이중 순환형 모델을 검토했다. 이를 토대로 개인정보 라 이프 사이클 모델 선택을 위한 고려 요소로 컴플라이언스, 정보주체의 권리 보호, 개인정보 품질 유지, 효율성, 위험 관리 항목 을 도출 및 측정해 선형 모델은 효율성 측면에서 장점이 있고, 순환형은 컴플라이언스, 정보주체의 권리 보호, 위험 관리 측면 에서 장점이 있는 것을 확인했다. 이 연구는 개인정보 라이프 사이클 모델의 선택과 구성에 대한 새로운 기준을 제공하였으며, 각각의 모델이 가지는 장단점을 명확히 밝혀냈다는 측면에서 의의가 있다.
This study seeks to enhance the efficiency and systematic management of personal data processing by empirically investigating the conditions under which linear or circular models are most suitable for implementing personal data life cycles. To achieve this, the study examined linear models, such as Privacy Impact Assessment Models and those considering Artificial Intelligence Learning Characteristics, alongside circular models, including Consent Management-based Models and Dual Circular Models. Through this analysis, several key considerations were identified and evaluated for selecting a suitable personal data life cycle model: compliance, protection of data subjects’ rights, maintenance of personal data quality, efficiency, and risk management. The findings revealed that linear models excel in terms of efficiency, while circular models demonstrate advantages in compliance, protecting data subjects’ rights, and risk management. This study holds significance in providing new criteria for selecting and structuring personal data life cycle models, as well as in clearly highlighting the strengths and weaknesses inherent in each approach.
효율적인 개인정보 관리와 보호를 위한 이중 순환형 개인정보 라이프 사이클 모델 제안 KCI 등재
한국융합보안학회 융합보안논문지 제24권 제5호 2024.12 pp.79-88
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
본 연구는 기존 모델보다 효율적인 개인정보 라이프 사이클 모델을 제안함으로써 개인정보 보호를 강화하고, 비용 절감과 효율적인 개인정보 관리를 목표로 한다. 이를 위해 기존에 개발된 다양한 라이프 사이클 모델을 체계적으로 분석했다. 또한, 한국인터넷진흥원(KISA) 개인정보침해 신고센터에 접수된 라이프 사이클 관련 데이터를 분석하여, 주요 개인정보 침해 원인 과 라이프 사이클 단계 간의 인과 관계 및 잠재적 구조를 도출했다. 이를 바탕으로 본 연구는 생성·수집, 보유, 이용·제공, 정 지·파기의 순서를 갖는 외부 순환 요소와, 이를 지원하는 감사, 모니터링, 컴플라이언스, 정보보안 등의 내부 순환 요소로 구성 된 이중 순환형 개인정보 라이프 사이클 모델을 제시했다. 제안된 모델은 개인정보 처리 과정의 안전성과 체계성을 강화하며, 기존 모델 대비 보다 포괄적이고 실질적인 활용성을 제공하는 데 장점이 있다.
This study aims to strengthen personal information protection while achieving cost reduction and efficient personal information management through the proposal of a more efficient personal information life cycle model than existing approaches. To accomplish this, this paper systematically analyzed various previously developed life cycle models. Furthermore, we examined life cycle-related data collected by the Personal Information Infringement Report Center of the Korea Internet & Security Agency (KISA), identifying causal relationships and underlying structures between major personal information infringement causes and life cycle stages. Based on these insights, this study introduces a dualcircular personal information life cycle model. This model integrates external circulation processes—comprising creation/collection, possession, use/provision, and suspension/destruction—and internal circulation processes, such as auditing, monitoring, compliance, and information security, to ensure seamless functionality. The proposed model enhances the safety and systematicity of personal information processing, offering more comprehensive and practical usability compared to existing models.
불특정 위협으로부터 데이터를 보호하기 위한 보안 저장 영역의 생성 및 접근 제어에 관한 연구 KCI 등재
한국재난정보학회 한국재난정보학회논문집 제17권 4호 통권54호 2021.12 pp.897-903
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
연구목적: 최근 국내외에서 해킹으로 피해자의 데이터를 암호화하고 이를 풀어주는 대가로 금전적 대 가를 요구하는 랜섬웨어 피해가 증가하고 있다. 이에 다양한 방식의 대응기술과 솔루션에 대한 연구개 발이 진행되고 있으며, 본 연구에서는 데이터를 저장하는 저장장치에 대한 보안 연구개발을 통해 근본 적인 대응방안을 제시하고자 한다. 연구방법: 동일한 가상환경에 보안 저장영역과 일반 저장영역을 생 성하고 접근 프로세스를 등록하여 샘플 데이터를 저장하였다. 저장된 샘플 데이터의 침해 여부를 확인 하기 위해 랜섬웨어 샘플을 실행하여 침해 여부를 해당 샘플 데이터의 Hash 함수를 확인하였다. 접근 제어 성능은 등록된 접근 프로세스와 동일한 이름과 저장위치를 통해 샘플 데이터의 접근 여부를 확인 하였다. 연구결과: 실험한 결과 보안 저장 영역의 샘플 데이터는 랜섬웨어 및 비인가된 프로세스로부터 데이터의 무결성을 유지하였다. 결론: 본 연구를 통해 보안 저장영역의 생성과 화이트리스트 기반의 접 근 제어 방법이 중요한 데이터를 보호하는 방안으로 적합한 것으로 평가되며, 향후 기술의 확장성과 기 존 솔루션과의 융합을 통해 보다 안전한 컴퓨팅 환경을 제공할 수 있을 것으로 기대된다.
Purpose: Recently, ransomware damage that encrypts victim's data through hacking and demands money in exchange for releasing it is increasing domestically and internationally. Accordingly, research and development on various response technologies and solutions are in progress. Method: A secure storage area and a general storage area were created in the same virtual environment, and the sample data was saved by registering the access process. In order to check whether the stored sample data is infringed, the ransomware sample was executed and the hash function of the sample data was checked to see if it was infringed. The access control performance checked whether the sample data was accessed through the same name and storage location as the registered access process. Result: As a result of the experiment, the sample data in the secure storage area maintained data integrity from ransomware and unauthorized processes. Conclusion: Through this study, the creation of a secure storage area and the whitelist-based access control method are evaluated as suitable as a method to protect important data, and it is possible to provide a more secure computing environment through future technology scalability and convergence with existing solutions.
6,700원
인공지능은 무한한 잠재력과 함께 빠르게 발전하고 있다. 이미 오늘날 인공지능은 보건의료를 개선시키고, 농업의 효율성을 높이며, 에너지소비를 감소시키고, 기후보호에 기여하며, 천연자원의 효율적인 사용을 가능하게 하고, 여전히 많은 방법을 통하여 전 세계적으로 우리 삶에 큰 영향을 미치고 있다. 우리는 아직 인공지능의 상당한 응용범위를 예측하지 못하고 있다. 이런 상황에서 유럽위원회는 2021년 4월 인공지능의 규율을 목적으로 하는 안을 마련한 바 있다. 오늘날 이미 다양한 영역에서 인공지능의 광범위한 활용이 필요하고 앞으로도 그러할 것이기에, 유럽위원회가 제안한 인공지능 규율을 위한 안은 적어도 유럽연합 내에서 인공지능의 사용을 위한 일관된 기준을 포함하며 인공지능의 삽입과 결부된 새로운 법적 질서를 규정하기 위한 중요한 법적 내용들을 제시하고 있다. 본 논문은 인공지능의 사용과 그것의 전략적인 기술 발전을 위한 고려사항을 담고 있고,미래에 인공지능의 효과적인 활용 및 그것의 감독과 통제를 위하여 필요한 법적 근거를 검토하고 있다. 이를 토대로 본 논문은 유럽위원회의 인공지능 전략, 인공지능 규정안의 목적과 주요 내용을 분석하고 있고, 인적관련 데이터의 보호를 중심으로 하면서 독일 정부의 의견서를 참고하며 유럽위원회의 인공지능 규정안을 평가하고 있다. 나아가 본 논문은 인공지능의 효과적인 활용과 통제를 위하여 그리고 효과적으로 인적관련 데이터를 보호하기 위하여 요청되는 법적 근거에 포함되어야 하는 내용들을 제시하고 있다.
Artificial intelligence (AI) is developing rapidly with almost unlimited potential. Already today, AI has a major global impact on our lives by improving healthcare, increasing agricultural efficiency, reducing energy consumption, contributing to climate change mitigation, enabling more efficient use of natural resources, and in many other ways. Today, we cannot yet foresee many of the potential applications. In this situation, the European Commission presented a proposal for an AI-Regulation in April 2021. Since the use of AI at various levels is already necessary today and will continue to increase, the European Commission's AI-Regulation proposal is an important legal act for addressing the novel regulatory challenges associated with the use of AI by providing uniform criteria for the use of AI, at least in the European Union. This article contains reflections on the development of this strategic technology and the use of AI, and also examines the necessary legal foundations for the effective application of AI and for the monitoring and control of its use in the future. On the basis of this consideration, the article analyzes the European Commission's AI strategy, the objectives and main content of its proposed AI-Regulation, and evaluates the AI-Regulation, taking into account a statement from the German government on personal data protection, among other issues. Finally, the article identifies the requirements to be met by the legal framework for the effective application and control of AI and effective personal data protection.
Die Künstliche Intelligenz (KI) entwickelt sich schnell mit nahezu unbegrenztem Potenzial. Bereits heute hat die KI global eine große Auswirkung auf unser Leben, indem sie die Gesundheitsversorgung verbessert, die Effizienz der Landwirtschaft erhöht, den Energieverbrauch senkt, zum Klimaschutz beiträgt, eine effizientere Nutzung von Naturressourcen ermöglicht und noch auf viele andere Arten und Weisen. Viele der Einsatzmöglichkeiten können wir heute noch nicht abschließend absehen. In dieser Situation hat die Europäische Kommission im April 2021 einen Vorschlag für eine KI-Verordnung vorgelegt. Da die Anwendung von KI auf verschiedenen Ebenen schon heute notwendig ist und weiter zunimmt, stellt der KI-Verordnungsvorschlag der Europäischen Kommission einen wichtigen Rechtsakt für die Regelung der mit dem Einsatz von KI einhergehenden neuartigen regulatorischen Herausforderungen dar, der einheitliche Kriterien für die Nutzung von KI zumindest in der Europäischen Union enthält. Dieser Aufsatz enthält Überlegungen zur Entwicklung dieser strategischen Technologie und zur Nutzung von KI und untersucht auch die notwendigen rechtlichen Grundlagen für eine effektive Anwendung von KI sowie für die Überwachung und Kontrolle ihres Einsatzes in der Zukunft. Auf Grundlage dieser Überlegung analysiert der Aufsatz die KI-Strategie der Europäischen Kommission, die Ziele und den Hauptinhalt ihres KI-Verordnungsvorschlags und bewertet die KI-Verordnung unter Berücksichtigung einer Stellungnahme der deutschen Bundesregierung unter anderem im Hinblick auf den personenbezogenen Datenschutz. Schließlich zeigt der Aufsatz die Anforderungen auf, die von den rechtlichen Grundlagen für eine effektive Anwendung und Kontrolle von KI und einen wirksamen personenbezogenen Datenschutz zu erfüllen sind.
중국의 의약품 관련 정책 및 제도변화와 FTA에서 우리의 대응방안 KCI 등재
한국지식재산학회 산업재산권 제62호 2020.01 pp.73-104
※ 기관로그인 시 무료 이용이 가능합니다.
7,300원
최근 의약품 관련 지식재산권 조항들이 FTA 협상 시 중요한 이슈 로서 제기되고 있다. 제약산업은 기업뿐만 아니라 국가의 경쟁력의 차원에서도 큰 역할을 하고 있기 때문에 선진국은 FTA에서 신약의 독점권을 연장하는 의약품 지식재산권 관련된 이슈를 중요하게 다루 고 있는 것이다. 최근 CPTPP 및 USCMA 등에서도 미국은 자국의 제 약산업을 위해 의약품 특허존속기간연장, 자료보호, 허가특허연계 등 다양한 이슈를 제기해 자국의 이익을 취하려고 하였다. 이러한 제약 산업과 의약품 지식재산권의 중요성에 대해 최근에는 중국도 이를 인 식하고 자국의 산업발전을 위해 정책적으로 많은 노력을 하고 있다. 중국은 자국의 의약품 산업 발전 수준을 고려하여 허가특허연계제 도의 도입, 존속기간 연장, 의약품 자료보호 등 다양한 이슈에 대해 서 정책, 제도적 변화를 꾀하고 있다. 그런데 이러한 변화는 향후 우 리나라와의 FTA 협상에서도 상당한 영향을 끼칠 것으로 예상된다. 즉, 기존 한국과 중국이 모두 참여한 협상인 한중 FTA 및 RCEP 협 상에서는 의약품 관련 조항들이 낮은 수준으로 유지되었다면, 현재 협상 중인 한중일 FTA에서는 현재의 중국 제도변화가 반영된 협정 문이 도출 될 수 있을 것이기 때문이다. 중국은 의약품 교역과 관련해서 우리나라에 중요한 국가로서 이러 한 상황에 대비하여 현재 중국의 변화에 대해서 구체적으로 파악하고, 이를 반영하여 현실에 맞는 대응방안을 모색할 필요성이 있어 보인다.
Recently, provisions on intellectual property rights related to pharmaceutical have been raised as important issues for FTA negotiations. Since pharmaceutical industries are taking big roles not just for businesses but also for the level of the nation’s competitiveness, advanced countries are cautiously dealing with issues related to intellectual property rights to extend exclusive rights of pharmaceutical products in FTA. In the recent CPTPP, USCMA, etc, the USA raised diverse issues as pharmaceuticals patent-term extensions, protection of test data, patent linkage, etc to keep their national interests by protecting their pharmaceutical industry. China has also recently recognized the importance of intellectual property rights on its pharmaceutical industry and medical supplies and it is making a lot of effort in policies for its industrial development. China is working on changes in policies and systems for diverse issues as introduction of patent linkage system, patent-term extension, protection of test data on pharmaceuticals, etc, considering the development level of its pharmaceutical industry. These changes, however, are expected to have considerable impact on FTA with Korea. That is, clauses related to pharmaceuticals were kept at low levels in the Korea-China FTA and the RCEP negotiated by both sides, Korea and China, but the Korea-China-Japan FTA being negotiated now may draw an agreement reflected the changes of China. China is an important country for Korea in terms of trades of pharmaceuticals and we should understand the changes of the country clearly and search realistic countermeasures to be prepared for this situation.
[NRF 연계] 한국과학학술지편집인협의회 Science Editing Vol.6 No.1 2019.02 pp.73-77
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
.
[NRF 연계] 한국통신학회 ICT Express Vol.7 No.3 2021.09 pp.308-315
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
To identify health risks in working environments, it is crucial for companies to share personal health data demonstrating to clients and suppliers their employees are healthy, while being compliant with data protection legislation. Based on these considerations, our Blockchain-based BlockHealth solution allows personal health data sharing with tamper proofing and data protection. Traditionally, the Blockchain guarantees data immutability but not confidentiality. On the contrary, BlockHealth stores in the Blockchain only hash values of data. Health data is stored in private databases managed by companies, thus also allowing to delete data in compliance with the right to be forgotten.
유럽연합(EU) 정보보호법 (General Data Protection Regulation)개정안상의 잊혀질 권리와 현행 우리 법의 규율 체계 및 앞으로의 입법방향에 관한 소고 KCI 등재
한국디지털정책학회 디지털융복합연구 제10권 제11호 2012.12 pp.87-92
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 유럽연합이 잊혀질 권리를 폭넓게 인정하는 정보보호법 개정안을 공표하면서 전세계적으로 이에 관한 논의가 이루어지고 있다. 우리나라에서도 이와 관련된 논의가 이루어지고 일부에서는 입법화 움직임까지 있다. 현행 법상 정보주체는 제한적으로 개인정보처리자나 정보통신서비스 제공자가 수집한 개인정보에 대해 정정 내지 삭제를 요구할 수 있을 뿐, 자신의 권리가 침해되지 않은 경우에는 온라인 게시판 등에서의 자신의 개인정보의 삭제를 요구할 수 없다. 이와 관련하여 앞으로의 입법과정에서는 정보주체 자신이 직접 올린 정보의 경우에만 잊혀질 권리를 한정할 것인지, 그리고 자신이 직접 올린 것이라면 제3자가 차후에 복사 등을 한 모든 경우에 대해 정보통신서비스 제공자 등에게 삭제할 의무를 부여할 것인지 충분히 검토되어야 한다. 최근 사이버 공간을 통한 국민 일반의 참여가 확장되고 직접민주주의를 향한 목소리도 커져가고 있는 상황에서 표현의 자유의 보장은, 설령 그것이 거대 미디어로 인한 정보를 통한 개인통제의 위험성에도 불구하고, 쉽게 포기될 수 없는 것이기 때문이다. 특히 표현의 자유와 관련하여 정보주체 자신이 직접 올리지 않은 정보에 대해서 잊혀질 권리를 인정하는 것이 자칫 사전검열에 해당할 수 있다는 점에서 신중히 접근될 필요가 있다.
In the early 2012, European Union proposed new legal framework, including the right to be forgotten, for the protection of personal data. The new Proposal articulates kind of sweeping new privacy right and there has been debates on its potential threat to free speech in the digital age. While the situation is similar in Korea, I want to introduce the right to be forgotten in the Proposal. Then, I will analyze current legal system in Korea regarding the new privacy right and suggest some guidelines in searching direction for the coming legislation with respect to the right to be forgotten. The right to be forgotten should not have been promulgated without considering fully its effect on the free speech, especially in the society where the voice toward direct democracy or movement toward participation of the citizen, mainly through cyber space or Social Network Services, has risen much higher in Korea. Especially, the new right seems not to cover the control of data subject on a third party where the third party expressing his opinion by posting himself other's personal data on his blog or others.
Towards quantitative evaluation of privacy protection schemes for electricity usage data sharing
[NRF 연계] 한국통신학회 ICT Express Vol.4 No.1 2018.03 pp.35-41
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
Thanks to the roll-out of smart meters, availability of fine-grained electricity usage data has rapidly grown. Such data has enabled utility companies to perform robust and efficient grid operations. However, at the same time, privacy concerns associated with sharing and disclosure of such data have been raised. In this paper, we first demonstrate the feasibility of estimating privacy-sensitive household attributes based solely on the energy usage data of residential customers. We then discuss a framework to measure privacy gain and evaluate the effectiveness of customer-centric privacy-protection schemes, namely redaction of data irrelevant to services and addition of bounded artificial noise.
Legal Examination of User Data Protection in the Bankruptcy of Chinese Digital Platform Enterprises KCI 등재
전북대학교 동북아법연구소 동북아법연구 제19권 제3호 2026.02 pp.121-149
※ 기관로그인 시 무료 이용이 가능합니다.
6,900원
디지털 경제가 급속히 발전하면서 디지털 플랫폼형 기업의 파산이 초래한 사용자 데이터 보호 문제가 점점 더 두드러지고 있다. 사용자 데이터는 인격권과 재산권 의 이중 속성을 모두 가지고 있으며, 이러한 특성은 파산절차에서 사용자의 인격권 과 채권자의 재산 이익, 데이터 준수 요구사항, 파산절차의 효율성에 근본적인 충돌 을 일으킨다. 현행 중국의 《기업파산법》, 《개인정보보호법》, 《데이터 보안법》은 가 치 목표의 충돌과 특별한 상황 규칙의 공백이 존재하여, 실무에서 데이터 소유권 정 의의 모호성, 평가 및 처리의 불균형, 규제 부재, 사용자 권리 보호의 어려움 등 여 러 해결해야 할 문제가 존재한다. 이러한 문제의 연구는 중요한 이론적 및 현실적 가치를 지니고 있으며, 전통적인 파산제도와 디지털 경제 시대의 새로운 권리보호의 연결을 위해 공백을 메울 수 있 을 뿐만 아니라, 사용자 데이터 보안과 채권자 이익 보장에 법적 지원을 제공할 수 있다. 이 문제를 해결하기 위해서는 이념적 전환을 실현하고, ‘사용자 데이터권 우 선’ 원칙을 확립해야 하며, 데이터 ‘플랫폼 제한 사용권’의 소유권을 명확히 하고, ‘삭제 및 이전 우선’ 처분 규칙을 제정하며, 데이터 준법관 제도를 도입하여 핵심 규범을 완비해야 한다. 또한, 법원과 규제기관의 협력심사, 데이터 관리이전 표준화, 사용자 권리의 다원화 구제를 위한 협력보호체계를 구축하여 최종적으로 《기업파산법》과 데이터 보호 관련법의 원활한 연계를 실현하고, 디지털 경제의 건강한 발전을 위한 법적 보장을 제공하여야 한다.
With the growth of the digital economy, user data protection due to digital platform enterprise bankruptcy has become more important. The personality rights of users and the property interests of creditors conflict with data compliance and bankruptcy proceedings' efficiency due to user data's dual nature. The Chinese Enterprise Bankruptcy Law , the Personal Information Protection Law, and the Data Security Law have conflicting value goals and blank rules in special situations, resulting in ambiguous data ownership, valuation and disposal irregularities, regulatory absence, and user rights protection issues. This study has important theoretical and practical value because it can fill the gap between the traditional bankruptcy legal system and the new rights protection in the digital economy era, as well as support user data security and creditors' interests. To resolve this issue, the article suggests transforming ideas and establishing the principle of "priority of user data rights"; improving core norms by clarifying data ownership "platform restricted right of use", creating the disposal rule of "deletion and migration prior to sale", and introducing the data compliance officer system; and building a collaborative protection system of court and regulatory review.
조선대학교 기초과학연구원 통합자연과학논문집(구 조선자연과학논문집) 제14권 4호 2021.12 pp.189-196
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
Recently, as a countermeasure for cyber breach attacks and confidential leak incidents on PC hard disk memory storage data of the metaverse industry, it is required when reviewing and developing a remote-based regular/realtime monitoring and analysis security system. The reason for this is that more than 90% of information security leaks occur on edge-end PCs, and tangible and intangible damage, such as an average of 1.20 billion won per metaverse industrial security secret leak (the most important facts and numerical statistics related to 2018 security, 10.2018. the same time as responding to the root of the occurrence of IT WORLD on the 16th, as it becomes the target of malicious code attacks that occur in areas such as the network system web due to interworking integration when building IT infrastructure, Deep-Access-based regular/real-time remote. The concept of memory analysis and audit system is key.
Nature of Data Assets and Their Protection and Exemption Measures for Analysis KCI 등재
한국산업안보학회(구 한국산업보안연구학회) 한국산업보안연구 제11권 제2호 통권 제21호 2021.08 pp.129-158
※ 기관로그인 시 무료 이용이 가능합니다.
7,000원
이 논문은 데이터의 산업적·사회적 활용 촉진을 통한 효용 창출이라는 데이터 자산의 본질적 목적을 실현하면서 가장 쟁점이 되는 ‘데이터 보호(오너십)’와 ‘데이터 분석 시 면책’이라는 다소 상반되는 개념에 대한 국제적 논의와 주요국의 입법 동향을 비교·분석하고 적절한 대안을 제시하였다. 특히 데이터 오너쉽을 중심으로 학술적·이론적인 고찰만을 다룬 기존 연구와는 달리 데이터 보호 및 분석 면책에 대한 입법적 가이드를 제시하고 있다는 점에서 데이터 선도국은 물론 후발국에 도움을 줄 것으로 여겨진다. 데이터의 보호에 관하여 몇몇 국가의 입법례 및 학술적 논의를 검토한 결과, ① 데이터를 소유권으로 보호하자거나, ② 지식재산권과 유사한 배타적 권리로 보호하자는 주장 및 ③ 데이터를 부정경쟁 방지의 원리에 입각하여 보호하는 입법 프레임워크가 존재한다. 한편, 데이터 분석 과정에서 필연적으로 직면하게 되는 저작권 침해 문제를 해결하기 위해서 분석(TDM) 면책에 관한 몇몇 국가의 입법례를 검토하였다. TDM 면책에 관한 주요국의 입법례를 검토한 결과, ① 공정이용의 원리에 입각하여 TDM을 허용하는 경우, ② 입법을 통해 비영리적 목적에 한하여 TDM을 허용하는 경우, ③ 역시 입법을 통해 비영리적 목적 여부를 불문하고 TDM을 허용하는 경우가 존재한다. 이 논문은 데이터에 대한 “적절한 법적 보호”의 필요성과 방안을 제안하고 있으며, 그 대안으로서 “부정경쟁 방지 원리에 입각한 데이터 보호”를 주장한다. 예컨대 일본은 이미 이러한 입법례를 마련하였으며, 한국 또한 데이터에 대한 적절한 보호 및 데이터 산업발전을 위한 법적 체계를 준비하고 있다. 한편 주요국들은 TDM에 대한 저작권 예외를 허용하는 경향을 보이지만 그 허용 범위에 대해서는 차이를 보이고 있으며 개별 국가의 상황에 따라 판단할 문제라고 본다. 이 논문은 저작권자의 이익을 고려하되, 빅데이터 분석에 이용되는 음향, 영상, 이미지 등 저작물에 대한 모든 저작권자의 동의를 받는 것은 현실적으로 어려운 일임도 고려하도록 제안한다. 또한, GDPR을 비롯한 「개인정보 보호법」이 민간기업이 과학적 목적을 위하여 정보주체의 동의없이 가명정보를 이용할 수 있도록 한 점 등도 입법의 방향성 설정에 있어서 고려하도록 제안하고 있다.
This study has realized the essential purpose of data assets, which is the creation of utility through the promotion of the industrial and social use of data. Furthermore, this work compared and analyzed international discussions and the legislative trends in major countries regarding the conflicting concepts of “data protection (ownership)” and “immunity for data analysis,” which are the most controversial issues, to present appropriate alternatives. Unlike previous studies that mainly addressed various theoretical discussions centering around data ownership, this study will help data leaders and latecomers in that it provides legislative guidelines for data protection and immunity for analysis. This study proposes the necessity of and measures for “appropriate legal protection” regarding data, and as an alternative, to maintain “data protection based on the doctrine of unfair competition.” Japan has already prepared such enactments, while South Korea has also been preparing a legal framework for the appropriate protection of data and development of the data industry. Meanwhile, this study considered the interests of copyright holders, and simultaneously, the practical difficulty in obtaining the consent of all copyright holders for works such as sounds, videos, and images used for big data analysis.
Applications of Medical Big Data and Personal Information Protection KCI 등재
원광대학교 법학연구소 의생명과학과 법 제31권 2024.06 pp.233-262
현재의 정보사회라는 환경에서 의료빅데이터의 생성 및 활용은 모든 시민의 개인정보보호와 직결되며, 특히, 의료빅데이터의 활용은 개인정보보호와 밀접한 관련이 있다. 의료기술의 지속적인 발전과 함께 의료빅데이터의 활용은 점점 더 광범위해지고 있으며, 한편으로 의료빅데이터의 활용은 의료기술의 발전을 촉진 할 뿐만 아니라, 약물 개발, 의료 개인화 및 정밀 치료의 발전에 많은 기여를 하고 있다. 한편, 의료빅데이터는 국민의 개인정보보호의 중요한 부분인 개인정 보와 관련이 있으며, 실제로 현행법 상 의료빅데이터의 활용과 개개인의 정보이 익 보호 간에 법적 모순이 없다고 할 수 없다. 의료빅데이터의 관점에서 국민의 개인정보, 의료건강정보, 의료빅데이터 정보의 범위가 교차하는 부분이 있음에 도 법률규정이 다른 부분이 있다. 또한, 현행법 상 개인정보의 제공 과정에서 정보의 사용 등에 대해 ‘고지-동 의’의 규정에만 의존하는 것은 개인정보를 종합적으로 보호할 수 없으며, 의료 빅데이터의 활용과 발전을 보장하기 어렵다. 이에 본 연구에서는 중국의 의료빅 데이터와 관련한 개인정보보호 문제를 분석하고, 현행법상 구체적으로 발생하는 문제들을 지적하고, 그 해결방안을 제시한다. 이를 통해 의료데이터 개방의 합 법화 추진에 입법근거를 마련할 수 있는 토대가 될 것이라 본다.
In the current social environment, the generation and application of medical big data is closely related to the personal information security of every citizen. With the continuous development of medical technology, the application of medical big data has become increasingly widespread. On one hand, it can promote the development of medical technology, including drug development, personalized medicine, and precision treatment. On the other hand, medical big data also concerns the private information of citizens, which is a crucial part of personal information protection. However, in practice, there often exists a contradiction between medical big data and the protection of citizens' personal information rights. From the perspective of medical big data, there are overlaps and differences among citizens' personal information, privacy information, medical health information, and medical big data information. Relying solely on the “informed consent” rule for personal information cannot effectively protect personal information comprehensively or guarantee the application and development of medical big data. This article analyzes the issues surrounding Chinese medical big data in terms of personal information from a legal perspective, and proposes corresponding solutions to these issues. It is hoped that this research can contribute to advancing the legalization of medical data openness, re-examining patients' personal information in the context of medical big data, and balancing the conflicts between individual privacy interests, public interests, and economic benefits of medical data, thus better protecting individuals' personal information interests under social and private benefits.
在当前的社会环境下,医疗大数据的产生和应用,关系到每个公民的个人信息安 全,医疗大数据的应用与个人信息保护紧密相关。随着医疗技术的不断发展,医疗 大数据的应用越来越广泛,一方面,医疗大数据的应用能够推动医疗技术的发展, 促进药物开发、医疗个性化、精准治疗等方面的发展。另一方面,医疗大数据同时 也关系到公民个人隐私信息,是个人信息保护的重要组成部分,在实践中,医疗大 数据与公民个人的信息权益保护方面往往存在矛盾。在医疗大数据的视角下,公民 个人信息、隐私信息、医疗健康信息、医疗大数据信息存在着范围的交叉和重叠, 相互之间又存在差别。单纯依靠个人信息的“知情-同意”规则,并不能很好地对个人 信息进行全方位的保护,也不能很好保障医疗大数据的应用和发展。本文从法律角 度分析中国医疗大数据在个人信息方面存在的问题,并针对这些问题提出来相对应 的解决措施,期望本文的研究能够对推动医疗数据开放的法制化程度向前发展起到 些许作用。以重新审视医疗大数据背景下的患者个人信息,平衡个体隐私利益、公 共利益以及医疗数据经济利益之间的冲突,从而在社会效益和私人效益之下更好的 保护个体的个人信息利益。
A Protection Model for Smart Greenhouse Data with Federated Learning and Differential Privacy KCI 등재후보
중소기업융합학회 산업과 과학 제5권 제2호 2026.03 pp.1-11
※ 기관로그인 시 무료 이용이 가능합니다.
4,200원
분산형 농업 IoT 애플리케이션에서 데이터 프라이버시 문제는 스마트 온실 시스템이 생성하는 방대한 양의 민감한 환경 및 작물 관련 데이터로 인해 제기된다. 본 연구는 온실 환경에서의 데이터 보호를 개선하기 위해 차등 프라이버시를 통합한 프라이버시 강화 FL 아키텍처를 제안한다. 이 접근법은 특히 라즈베리 파이와 같은 제한된 자원을 가진 에지 디바이스를 위해 설계했다. 실제 온실 환경 데이터셋을 대상으로 한 실험에 따르면, 중앙 집중식 훈련은 최대 정확도(92.4%)를 달성하지만 프라이버시 보호 기능이 전혀 제공되지 않는다. 정확도, 프라이 버시 예산, 시스템 효율성 간의 균형 잡힌 절충점을 달성하기 위해 제안된 계층적 FL+DP 전략은 모델 업데이트를 크게 안정화하고 통신 오버헤드를 낮춘다. 이러한 결과는 높은 데이터 기밀성과 정확한 예측이 필요한 프라이버시 민감형 스마트 온실 애플리케이션에 FLDP 프레임워크가 적합함을 보여주었다.
Concerns with data privacy in dispersed agricultural IoT applications are raised by the massive amounts of sensitive environmental and crop-related data generated by smart greenhouse systems. In order to improve data protection in greenhouse settings, this study suggests a privacy -enhanced federated learning architecture that incorporates differential privacy. In order to achieve a balanced trade-off between accuracy, privacy budget, and system efficiency, the suggested hierarchical FL+DP strategy significantly stabilizes model updates and lowers communication overhead. The suggested model shows a favorable privacy-accuracy trade-off when compared to ordinary federated learning, achieving up to 88.7% prediction accuracy under moderate noise circumstances (σ = 0.3–0.5) while offering explicit differential privacy guarantees. These findings show that the FLDP framework is a good fit for privacy-sensitive smart greenhouse applications that need high data secrecy and accurate prediction.
A Privacy Protection Model for IoT Healthcare Data Using Federated Learning and Differential Privacy KCI 등재후보
중소기업융합학회 산업과 과학 제5권 제1호 2026.01 pp.37-47
※ 기관로그인 시 무료 이용이 가능합니다.
4,200원
연방학습은 환자의 원시 데이터를 교환하지 않고 여러 의료기관간 협력적 모델훈련을 가능하게 함으로써 의료 AI의 개인정보 보호 문제를 해결한다. 그러나 기존 연방학습은 여전히 기울기 노출로 인한 개인정보 유출 위 험이 존재한다. 본 연구는 데이터와 모델 매개변수를 보호하기 위해 차등 프라이버시(DP)와 동형 암호화(HE)를 결합한 프라이버시 강화연방학습 프레임워크를 제안한다. 동형암호는 암호화된 연산을 통해 통신을 암호화하는 반 면, 차등 프라이버시는 기울기에 제어된 노이즈를 추가한다. 실제 의료 데이터셋을 활용한 질병분류 실험결과, 제안 한 모델은 우수한 프라이버시(ε = 1.2)와 적당한 통신비용으로 90.7%의 정확도를 보였다. 안전한 의료 애플리케이 션을 위해 본 모델은 효율성, 프라이버시, 성능간의 적절한 균형을 제공한다.
Federated Learning (FL) addresses privacy concerns in medical AI by facilitating cooperative model training across several healthcare organizations without exchanging patients' raw data. However, traditional FL still runs the danger of privacy leaking due to gradient exposure. In order to protect data and model parameters, this research aims to provide a privacy-enhanced FL framework that combines Differential Privacy (DP) with Homomorphic Encryption (HE). While HE encrypts communication with encrypted computation, DP adds controlled noise to gradients. Experiments on a real medical dataset for disease classification demonstrate that the suggested FL + DP + HE strategy achieves 90.7% accuracy with good privacy (ε = 1.2) and modest communication cost. For safe healthcare applications, the model provides a good balance between efficiency, privacy, and performance.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.