Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

년 - 년

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 26건
No
1

A Study on the Development Site Security for Embedded Software

여상수, 김태훈, 조성언, 코우이치 사쿠라이

[Kisti 연계] 한국항행학회 한국항행학회논문지 Vol.11 No.3 2007 pp.259-265

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

유비쿼터스 컴퓨팅을 구현하기 위한 임베디드 시스템적 요소, 즉 각종 전자기기, 가전제품, 제어장치 들은 단순히 회로로만 구성되어 있는 것이 아니라 특정한 기능을 수행하도록 프로그램이 내장되어 있는데 이러한 시스템 제어역할을 수행하는 다양한 프로그램을 임베디드 소프트웨어라고 정의할 수 있다. 임베디드 소프트웨어는 시스템의 기능을 제어하는 핵심 요소이므로 내용이나 제어 구조가 공개되는 경우에는 심각한 영향을 받을 수 있다. 임베디드 소프트웨어의 보안은 크게 두 부분으로 나뉘어 고려될 수 있다. 첫 번째는 외부의 위협원이 내부로 침투하여 관련 정보를 유출하는 것이고, 두 번째는 내부 혹은 외부의 위협원이 임베디드 소프트웨어에 악성 코드를 삽입하는 등 불법적인 행동을 하는 것이다. 본 논문에서는 첫 번째 관점에서, 임베디드 소프트웨어를 개발하고 있는 개발 현장에 대한 보안 점검 요소들을 도출하고 제안하였다. 개발 현장에 대한 보안 점검을 통해 외부 위협원의 접근을 원천적으로 차단하는 동시에, 임베디드 소프트웨어의 비인가된 변형을 간접적으로 예방할 수 있을 것으로 기대된다.

Systematic components for implementing ubiquitous computing, for example, electronic devices, electric home appliances, and controllers, etc, are consist of not only circuits but also softwares expected to do some special system-controlling functions, and these softwares used to be called like as embedded software. Because embedded software is a core component controlling systems, the codes or control flows should be protected from being opened to the public or modified. Embedded software security can be divided into 2 parts: first is the unauthorized access to development site and embedded software, second is the unauthorized disclosure or modification. And this research is related to the first aspect of them.This paper proposes some security check requirements related to embedded software development site by analyzing the ALC_DVS.1 of the ISO/IEC 15408 and Base Practices (BPs) of the ISO/IEC 21827. By applying this research, we expect to protect unauthorized modification of embedded software indirectly.

2

Security Improvement of File System Filter Driver in Windows Embedded OS

Seong, Yeon Sang, Cho, Chaeho, Jun, Young Pyo, Won, Yoojae

[Kisti 연계] 한국정보처리학회 Journal of information processing systems Vol.17 No.4 2021 pp.834-850

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

IT security companies have been releasing file system filter driver security solutions based on the whitelist, which are being used by several enterprises in the relevant industries. However, in February 2019, a whitelist vulnerability was discovered in Microsoft Edge browser, which allows malicious code to be executed unknown to users. If a hacker had inserted a program that executed malicious code into the whitelist, it would have resulted in considerable damage. File system filter driver security solutions based on the whitelist are discretionary access control (DAC) models. Hence, the whitelist is vulnerable because it only considers the target subject to be accessed, without taking into account the access rights of the file target object. In this study, we propose an industrial device security system for Windows to address this vulnerability, which improves the security of the security policy by determining not only the access rights of the subject but also those of the object through the application of the mandatory access control (MAC) policy in the Windows industrial operating system. The access control method does not base the security policy on the whitelist; instead, by investigating the setting of the security policy not only for the subject but also the object, we propose a method that provides improved stability, compared to the conventional whitelist method.

3

4,000원

스마트키는 다양한 임베디드 환경에서 활용하고 있지만 사용자의 위치에서 신호의 증폭을 통한 원격지 공격이 발생하고 있음을 알 수 있다. 방어 기법에 대한 기존 연구는 다수의 센서를 사용하거나 인증 속도의 개선을 위한 해시 함수를 사용한 경우가 있는데 이는 전력 소모를 증가시키거나 1종 오류가 발생할 가능성을 가지고 있다. 이에 본 논문에 서는 컨트롤러와 호스트 장치간의 인증 방식을 개선하여 사용자의 이동 정보와 클라이언트 인증 기반의 임베디드 보안 컨트롤러 모델을 제안하고자 한다. 제안하는 모델에 대하여 아두이노 보드와 GPS 및 블루투스를 이용한 통신을 위하여 암호화 알고리즘을 적용하였으며 인증을 위하여 사용자의 이동 정보를 사용하여 경로 분석을 통해 인증을 수행하였다. 그리고 제안하는 모델을 사용하여 동작 수행을 하더라도 작동 편이성에 큰 영향을 미치지 않았음을 암호화 및 복호화 시간 측정을 통하여 확인하였다. 제안하는 모델의 임베디드 보안 컨트롤러는 이륜차와 같은 리모트 컨트롤러와 이동 또는 고정형 호스트 장치를 가지고 있는 시스템 구조에서 적용할 수 있으며 연구 과정에 암호화 및 복호화 시간이 각각 100ms 이내에 처리를 수행할 수 있음을 확인하였으며 향후 경로 데이터 관리 방법에 대한 추가연구 및 암호화 및 복호 화 소요 시간과 데이터 통신 시간을 줄일수 있는 프로토콜에 대한 연구가 더 필요할 것으로 판단된다.

A smart key has been used in a variety of embedded environments and there also have been attacks from a remote place by amplifying signals at a location of a user. Existing studies on defence techniques suggest multiple sensors and hash functions to improve authentication speed; these, however, increase the electricity usage and the probability of type 1 error. For these reasons, I suggest an embedded security controller based on client authentication and user movement information improving the authentication method between a controller and a host device. I applied encryption algorithm to the suggested model for communication using an Arduino board, GPS, and Bluetooth and performed authentication through path analysis utilizing user movement information for the authentication. I found that the change in usability was nonsignificant when performing actions using the suggested model by evaluating the time to encode and decode. The embedded security controller in the model can be applied to the system of a remote controller for a two-wheeled vehicle or a mobile and stationary host device; in the process of studying, I found that encryption and decryption could take less then 100ms. The later study may deal with protocols to speed up the data communication including encryption and decryption and the path data management.

4

임베디드 디바이스 보안을 위한 SDN 적용 시 고려사항

구금서, 심갑식

[Kisti 연계] 한국콘텐츠학회 한국콘텐츠학회논문지 Vol.21 No.6 2021 pp.51-61

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

사물인터넷과 빅데이터 그리고 인공지능으로 상징되는 4차 산업혁명시대에 다양한 임베디드 디바이스가 기하급수적으로 증가하고 있다. 이러한 디바이스는 낮은 사양임에도 통신 기능을 보유하고 있어서 개인 정보유출 가능성이 높아지고 있으며 보안의 위협 또한 증가하고 있다. 임베디드 디바이스는 하드웨어부터 네트워크를 통한 서비스까지 대부분의 단계에서 보안 이슈가 발생 가능하다. 또한 저사양과 저전력 등 자원 제약의 특징을 가지며 관련 기술의 표준화가 이루어지지 않은 상황이므로 일반적인 보안 기법을 적용하기에는 어려움이 따른다. 본 연구에서는 임베디드 디바이스에 SDN 적용 시 취약점과 발생 가능한 문제점과 고려사항을 제시하였다. 하드웨어 관점에서 와이파이 칩과 블루투스의 문제, 오픈플로우 구현상의 문제, SDN 컨트롤러 및 구조적 특성에 따른 사례를 고려하여 제시하였다. SDN은 데이터 플레인과 제어 플레인을 각각 분리하여 둘 사이에 표준화된 인터페이스를 제공하여 통신을 효율적으로 제어할 수 있으며 빠른 변화에 대응하기 어려운 기존 네트워크 기술에서의 보안의 한계에 대응할 수 있다.

In the era of the 4th industrial revolution symbolized by the Internet of Things, big data and artificial intelligence, various embedded devices are increasing exponentially. These devices have communication functions despite their low specifications, so the possibility of personal information leakage is increasing, and security threats are also increasing. Embedded devices can have security issues at most levels, from hardware to services over the network. In addition, it is difficult to apply general security techniques because it has characteristics of resource constraints such as low specifications and low power, and the related technology has not been standardized. In this study, we present vulnerabilities and possible problems and considerations in applying SDN to embedded devices in consideration of structural characteristics and real-world discovered cases. This study presents vulnerabilities and possible problems and considerations when applying SDN to embedded devices. From a hardware perspective, we consider the problems of Wi-Fi chips and Bluetooth, the problems of open flow implementation, SDN controllers, and examples of structural properties. SDN separates the data plane and the control plane, and provides a standardized interface between the two, enabling efficient communication control. It can respond to the security limitations of existing network technologies that are difficult to respond to rapid changes.

5

A New Ultra Lightweight Encryption Design for Security at Node Level SCOPUS

Ting Wang, Dongning Zhao, Zhiwei Sun, Weixin Xie

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.12 2016.12 pp.111-128

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

This paper proposes a new lightweight cipher VAYU. VAYU has a balanced Feistel structure. VAYU cipher supports 64 bit plaintext and 128/80 bit key length and it has a total of 31 rounds. It needs only 1290 GEs for 128 bit key length. It also results in minimal memory size as compared to all other existing lightweight ciphers. This paper discusses the security analysis of VAYU cipher design which is adequate against linear and differential cryptanalysis, Biclique attack, zero correlation attack, algebraic attack. VAYU cipher design will be best suitable for applications like IoT, smart Wireless Sensor networks. VAYU cipher uses two F-functions with substitution box, which results in a high diffusion mechanism.

6

Network Security in Embedded System Using TLS SCOPUS

Vivek Negi, Himanshu Verma, Ipsita Singh, Aditya Vikram, Kanika Malik, Archana Singh, Gaurav Verma

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.2 2016.02 pp.375-384

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Security in terms of Networks have turn out to be more significant to Organizations, Military and personal computer user’s. Since various kinds of threats are for data from sending it from sender side over internet till it reaches to receiver. Here we will focus on SSL it is a technique used to give client and server authentication, data confidentiality and data integrity. It transform our data into unintelligible form, data which we will be sending can be text or no text form, by encrypting our data we can save it from attacks like eavesdropping, in which interception of communication by unauthorized person, he can either listen or can add malicious information in our data which can lead to catastrophic results. This technique of secure data transmission is very useful in securing the integrity of data sent by the Unmanned Aerial Vehicles in military application to commercially used Electricity meter. Since the above mentioned devices uses microcontroller to send data through internet hence this data is always going to be susceptible to above mentioned threats so it is important to ensure that it doesn’t fall in wrong hands, our objective is that our microcontroller sends the data to remote location has authenticity, confidentiality and integrity. First we will send some meaningful text already stored in controller of STM3240G Eval-board then that data will be sent to server. These encrypted packets will be sending to remote server through Ethernet. At the receiver end this data will be received and decrypted to get the original captured data.

7

An Embedded Encryption Protocol for Healthcare Networks Security SCOPUS

Ndibanje Bruce, Won Tae Jang, Hoon Jae Lee

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.8 No.2 2014.03 pp.139-144

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Data availability service is now ubiquitously practical from the high-end systems such as routers, gateways, firewalls, and web servers to the low-end systems such as smart phone, tablet, etc…with the emerging growth of the embedded systems, there is parallel rapid increase in the amount of information flowing across intranets and the Internet. Hence, security has become an essential part of today’s computing world. This promise of universal connectivity for embedded systems creates increased possibilities for malicious users to gain unauthorized access to sensitive information. This paper presents a framework for HNS in which an embedded encryption protocol scheme enables negotiation between entities to specify authorization requirements that must be met before accessing the network and data.

8

Design and Development of a Security Kernel in an Embedded System SCOPUS

Liu Shian

보안공학연구지원센터(IJCA) International Journal of Control and Automation Vol.7 No.11 2014.11 pp.49-58

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Dynamic strategy-based security Kernel is very important in an embedded system. It is the core of a secure computing environment that can be implemented in the form of a hardware component installed in a computer or network topology, a software implementation, or a firmware system installed in a computer microchip, or in an embedded system. With increasing dependence on embedded systems, their reliability and security become more and more of an issue. This paper designs and develops a security Kernel prototype system which is named as SK-I. This prototype is very generic since it could be easily inserted to other systems or platforms. It is based on the safety identification, access control, user authority verification, and authority mechanisms. SK-I has been tested under difference dimensions so that the functionalities and performance are examined. From the testing, it is observed that create and delete operation costs a lot and the decision buffer plays an important role in enhancing the performance of an embedded system.

9

Study on Structural and Systematic Security Threats of Vehicle Black Box as Embedded System KCI 등재후보

Jaehyun Park, WoongChul Choi

국제인공지능학회(구 한국인터넷방송통신학회) International Journal of Internet, Broadcasting and Communication Vol.9 No.3 2017.08 pp.9-16

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Recently, more users have been using IoT embedded systems. Since the wireless network function is a basic and core function in most embedded systems, new security threats and weaknesses are expected to occur. In order to resolve these threats, it is necessary to investigate the security issues in the development stages according to the Security Development Lifecycle (SDL). This study analyzes the vulnerabilities of the embedded systems equipped with the wireless network function, and derives possible security threats and how dangerous such threats are. We present security risks including bypassing the authentication stage required for accessing to the embedded system.

10

보안 임베디드 소프트웨어 개발을 위한 융합 모델 KCI 등재후보

김행곤

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.7 No.5 2010.10 pp.531-550

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

최근 융․복합에 대한 관심이 높아지면서 융합형 임베디드 소프트웨어 응용 분야 및 이를 개발하기 위한 다양한 방법론 및 도구에 대한 연구가 활발히 진행되고 있다. 특히, 임베디드 소프트웨어의 생산성 및 품질 향상을 위한 개발 방법론 및 테스팅에 관한 연구가 필수적으로 요구되고 있다. 따라서 임베디드 응용에 적합한 개발 모델 및 절차에 대한 체계적 연구가 필요하며 인증된 모델 융합이 요구된다. 본 연구에서는 소프트웨어 신기술인 소프트웨어 모델인 MDA(Model Driven Architecture) 와 프로덕트 라인 그리고 CBD기술을 도입하여 응용 임베디드 도메인에 적합한 소프트웨어 개발 도구 및 환경 지원을 위한 통합 모델을 연구 한다. 플랫폼-독립적인 임베디드 소프트웨어 개발 모델과 플랫폼-종속적인 영역을 관심의 분리를 통해 분리하여 추후 구현단계에서 융합하는 임베디드 소프트웨어 개발지원 통합 모델 기법을 제안하고 임베디드 소프트웨어 생산성 및 품질을 높이게 한다.

Recently, There are many active researches of methodologies and tools for embedded software applications to meet convergence and integration areas. It requires development methodologies and tools for high productivity and quality. First of all, procedural and aproved model convergence is required to meet it. In this paper, We suggest software development tools and environment, as convergence model, using MD, Product line and CBD for specific model. We approach two different models as PIM (Platform Independent Model) and PSM (Platform Specific Model) with seperate of concern. We finally describe the convergence model for embedded software for high quality and productivity.

11

임베디드 시스템의 보안 위협에 관한 고찰

이승욱, 김종태

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.1 No.1 2005.08 pp.42-45

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

12

무기체계 임베디드 소프트웨어의 유지보수 체계 개선 및 정보보호체계 구축 방안 KCI 등재

박철현, 안훈상, 김승규, 배종호

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.12 No.4 2015.08 pp.363-378

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

무기체계 임베디드SW는 그 중요성에 비해 충분한 유지관리가 진행되지 않아 자체 결함 및 외부 침입에 대한 취약성을 내포하고 있다. 이에 따라 현재 관리 실태를 면밀히 관찰하여 군 내 전문인력· 조직 구축, 품질보증 제도화, SW ILS 제도화 등 유지보수 체계 개선을 위한 대책을 제시한다. 또한 S-SLA기반 정보보호 유지보수, 화이트리스트 기법 + TPM 적용 등 정보보호체계 구축을 위한 대안을 제시한다.

S. Korea's weapon systems embedded softwares have some vulnerabilities to their own defects and outer invasions as a result of the insufficient maintenance and management system in spite of their growing importance. In this paper, we analyzed the actual outcome of its current operation of management system. Then we introduce a strategy to improve the current maintenance system such as organization of professional maintenance division and institutionalization of SW quality assurance and Integrated Logistics Support(ILS). Lastly, we suggest S-SLA-based security maintenance and Whitelist-based solutions+TPM in order to develop information security system for the weapon systems embedded SWs.

13

이중 방법을 지원하는 임베디드 보안 팩스 서버 개발

이상학, 정태충

[NRF 연계] 한국정보처리학회 KIPS Transactions on Computer and Communication Systems Vol.11 No.3 2004.06 pp.129-138

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

지난 수십 년간 문서 전송 수단으로 사용되어 왔던 팩스는 인터넷의 출현으로 전자우편, 파일 전송 규약 등이 널리 이용되는 현재에도 여전히 중요한 데이터 통신 수단이다. 인터넷과 마찬가지로 팩스 데이터의 보안에 대한 필요성은 높지만 그 연구는 인터넷에 비해 미비한 상태이다. 본 논문에서는 일반 팩스의 사용을 그대로 유지하면서 보안성을 높일 수 있는 임베디드 보안 팩스 서버의 하드웨어, 소프트웨어의 개발에 대해 기술한다. 개발된 시스템은 데이터의 암·복호화에 대한 지연을 최소화 하면서 보안을 제공할 수 있도록 설계되고 구현되었다. 암호 알고리즘은 국제 규격과 자국의 규격이 있으며, 각 국가마다 정책적 제한을 두고 있기 때문에 국내에서 인정되는 표준 암호 알고리즘을 적용하였다. 또한 보안(Security) 모드와 비보안(Non-Security) 모드의 이중 동작 방법을 지원하여 사용자가 선택적으로 이용할 수 있도록 하였다. 정부, 기업 등의 실사용자의 기술적 요구사항을 반영하여 실제 직접 적용될 수 있는 시스템을 개발하였으며, 실제 환경 하에서 시험을 거쳐 성능 및 기능에 대해 검증하였다.

Even though the Internet applications such as e-mail and FTP are widely used, fax is still an important media for data communications till today. Many researches on security over the Internet data communications have been done over the years, on the other hand not many researches have been dedicated to the fax security issue which is as important as the Internet. In this paper, we describe the development of hardware and software of the embedded security fax server which increases the security in supporting existing fax. The developed system is designed and implemented to maintain security while minimizing the delay due to encryption·decryption. Since there's international or domestic cryptographic standard and each nation have their policy to restrict the use of cryptographic system, we adopt domestic standard cryptographic protocol admitted in Korea. And the system supports two modes:Security mode and Non-Security mode that user can choose from. The system can be applied directly which is the requirements of users at company and the government. We verify the performance and functioning of the system in various real environment.

14

비디오 컨텐츠의 보안기능을 내장한 실시간 리프팅 기반 코텍의 FPGA 설계

서영호, 김동욱

[Kisti 연계] 한국통신학회 한국통신학회 학술대회논문집 2004 p.280

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

15

ECDSA 하드웨어 가속기가 내장된 보안 SoC

정영수, 김민주, 신경욱

[Kisti 연계] 한국정보통신학회 한국정보통신학회논문지 Vol.26 No.7 2022 pp.1071-1077

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

타원곡선 암호 (elliptic curve cryptography; ECC) 기반의 공개키 기반구조 구현에 사용될 수 있는 보안 SoC(system-on-chip)를 설계하였다. 보안 SoC는 타원곡선 디지털 서명 알고리듬 (elliptic curve digital signature algorithm; ECDSA)용 하드웨어 가속기가 AXI4-Lite 버스를 통해 Cortex-A53 CPU와 인터페이스된 구조를 갖는다. ECDSA 하드웨어 가속기는 고성능 ECC 프로세서, SHA3 (secure hash algorithm 3) 해시 코어, 난수 생성기, 모듈러 곱셈기, BRAM (block random access memory), 그리고 제어 FSM (finite state machine)으로 구성되며, 최소의 CPU 제어로 ECDSA 서명 생성과 서명 검증을 고성능으로 연산할 수 있도록 설계되었다. 보안 SoC를 Zynq UltraScale+ MPSoC 디바이스에 구현하여 하드웨어-소프트웨어 통합 검증을 하였으며, 150 MHz 클록 주파수로 동작하여 초당 약 1,000번의 ECDSA 서명 생성 또는 서명 검증 연산 성능을 갖는 것으로 평가되었다. ECDSA 하드웨어 가속기는 74,630개의 LUT (look-up table)와 23,356개의 플립플롭, 32kb BRAM 그리고 36개의 DSP (digital signal processing) 블록의 하드웨어 자원이 사용되었다.

A security SoC that can be used to implement elliptic curve cryptography (ECC) based public-key infrastructures was designed. The security SoC has an architecture in which a hardware accelerator for the elliptic curve digital signature algorithm (ECDSA) is interfaced with the Cortex-A53 CPU using the AXI4-Lite bus. The ECDSA hardware accelerator, which consists of a high-performance ECC processor, a SHA3 hash core, a true random number generator (TRNG), a modular multiplier, BRAM, and control FSM, was designed to perform the high-performance computation of ECDSA signature generation and signature verification with minimal CPU control. The security SoC was implemented in the Zynq UltraScale+ MPSoC device to perform hardware-software co-verification, and it was evaluated that the ECDSA signature generation or signature verification can be achieved about 1,000 times per second at a clock frequency of 150 MHz. The ECDSA hardware accelerator was implemented using hardware resources of 74,630 LUTs, 23,356 flip-flops, 32kb BRAM, and 36 DSP blocks.

16

CC/CEM에서 유도한 오픈소스 내포형 정보보호시스템의 평가지침

강연희, 김정대, 최성자, 이강수, 윤여웅, 이병권

[Kisti 연계] 한국정보과학회 한국정보과학회 학술대회논문집 2004 pp.397-399

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

오늘날 조직에서 공개된 소프트웨어를 이용한 오픈소스 내포형 정보보호시스템(OSS-embedded Information Security System) 개발이 증가되고 있으며 소스의 상당부분을 오픈소스 소프트웨어(OSS : Open source Software)를 이용함으로써 복잡한 IT환경 속에서 효율성 증대와 고가의 라이센스에 대한 비용 절감 효과 등을 통해 높은 시장성이 예상된다. 그러므로 오픈소스 내포형 정보보호시스템에 대한 평가 제출물 준비 및 평가에 대한 기준을 정의할 필요가 있으며 공통평가기준(CC : Common Criteria)과 공통평가방법론(CEM : Common Evaluation Methodology)에서 유도한 OSS 평가요구사항을 분석하고자 한다.

17

임베디드 시스템의 보안성 향상을 위한 LLVM 기반의 소스코드 난독화 도구 설계

하재현, 곽동규

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2022 pp.201-203

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

임베디드 시스템이 일상생활 및 각종 산업에 밀접하게 연관되어 개인 정보 및 국가 기술 등 지적 자산에 대한 보안의 필요성이 나타나고 있다. 이러한 문제점은 임베디드 시스템에 들어가는 소프트웨어의 역공학으로부터 초래된다. 따라서 본 논문은 소스 코드에 대해 제어 흐름 평탄화라는 난독화 알고리즘을 설계하는 방법을 제안한다. 이는 독자적으로 작성된 난독화 알고리즘이기 때문에 오픈 소스로 공개되어져 있는 다른 난독화 도구들에 비해 안전한 특징을 가진다. 제어 흐름 평탄화는 프로그램의 기능을 유지하면서 소스 코드의 정적 분석을 어렵게 하는 기법으로, 데이터를 탈취하려는 악의적인 행위를 사전에 예방할 수 있다. 본 논문에서 제안하는 제어 흐름 평탄화 알고리즘은 하나의 기본 블록으로 이루어진 단순한 소스 코드를 여러 개의 기본 블록으로 분할하고, 조건문을 통해 연결하는 방법을 사용하여 알고리즘의 복잡도를 높였다. 이처럼 새롭게 작성된 Pass를 통해 소스코드 난독화를 적용시켜 임베디드 시스템의 보안성을 향상시킬 수 있다.

18

임베디드 전력 모니터링 보안 모듈 설계

윤찬호, 김광준, 장창수

[Kisti 연계] 한국전자통신학회 The Journal of the Korean institute of electronic communication sciences Vol.8 No.10 2013 pp.1485-1490

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

스마트 그리드용 전력망이 구축시범사업이 진행됨에 따라 스마트 디지털가전 AV기술, 냉난방 습도 공기 자동관리를 위한 복합에너지 관리기능을 담당하는 스마트 홈 에너지관리기술, 노약자와 장애인을 위한 주거설계와 가족 구성원에 대한 개인별 바이오정보 측정을 담당하게 될 헬스케어 기술, 생체인식 보안과 동작감지센서 등을 다루는 스마트 홈 시큐리티 기술 등 연구가 진행되고 있다. 본 논문에서는 물리적 공격에 취약한 외부에 노출되는 문제점이 발생하게 되는 스마트미터기에 대응되는 암호기술을 분석하고 단말기의 효율성을 극대화 할수 있는 스마트 미터기 단말기용 보안시스템 설계를 제안하였다.

The demonstration project of the electrical grid for Smart grid is progressed, the smart digital appliances AV technology, Smart home energy management technology charging the management function of complex energy for the automation management of air conditioning and heating, humidity and air, the health care technology charging the design of housing for the elderly and disabled and the measurement of individual bio information, and the Smart home security technology dealing with the biometric security and motion sensors, etc. have been studied. The power monitoring terminal which uses a variety of wired and wireless networks and protocol is the target additionally to be considered in addition to the security vulnerabilities that was occurred in the existing terminal. In this research paper, the author analyzes the cryptographic techniques corresponding to the smart meter occurred by the problems that are exposed on the outside which are vulnerable to physical attacks, and intends to propose the design of the security systems for the Smart meter terminal being able to maximize the efficiency of the terminal.

19

VPN을 이용한 Embedded 홈 네트워크 시스템 보안

진선일, 정진규, 안광혁, 유영동, 홍석교

[Kisti 연계] 대한전기학회 대한전기학회 학술대회논문집 2003 pp.701-704

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

The home network system of ubiquitous computing concept is changing present our home life as more comfortable and safe. Also, it permits that we can connect the home network system and control the appliance which is linked to the home network system without limitation in time and place. But, as other systems that use the public network like the Internet, remote control/monitoring of the home network system that use the Internet includes problems such as user's access which is not admitted and information changing. This paper presents the efficient solution about the security problem that is recognized to important problem of the home network system. Also this paper implements the security of the home network system based on the UPnP (Universal Plug and Play), adding VPN (Virtual Private Network) router that uses the IPsec to the home network system which is consisted of the ARM9 and the Embedded Linux.

20

보안용 임베디드 홈 네트워크 서버 개발

김유경, 김남호

[Kisti 연계] 한국지능정보시스템학회 한국지능정보시스템학회 학술대회논문집 2005 pp.321-325

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 가정 내 디지털 기기 간 네트워크 가능성이 현실화되면서 관련 산업과 기술에 대한 관심이 고조되고 있다. 또한 최근 들어 컴퓨터의 보급이 확산되어 2대 이상 보유가구가 늘어나고, 점점 더 많은 전자기기를 소유하면서 각각의 장치들을 한데 묶어 서로 연결하며, 인터넷 접속을 통해 더욱 편리함과 부가가치를 창출하고자 하는 욕구가 증대되고 있다. 이에 본 연구는 댁내에 안전한 삶을 누릴 수 있도록 홈 디지털 기기간의 통신 방법의 설계 및 제어할 수 있도록 구현하고, 임베디드 장비를 이용하여 보안 기기와 통신할 수 있는 홈 서버를 개발한다. 댁내, 외 어디에서나 집안의 현재 상황을 관리, 제어 및 모니터링이 가능하도록 설계하였다.

 
1 2
페이지 저장