년 - 년
다양한 분야에서의 키 관리 시스템 분석을 통한 적응형 키 관리 프로세스 연구 KCI 등재
한국융합보안학회 융합보안논문지 제24권 제5호 2024.12 pp.27-36
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
디지털 환경에서 데이터 보안의 중요성이 증가하면서, 데이터를 암호화 및 복호화하는 암호 키의 안전한 관리가 필수적인 요소가 되고 있다. 이에 암호 키의 생명주기 전체 과정을 관리하는 키 관리 시스템(Key Management System, KMS)에 대한 필요성도 점차 증가하고 있다. 본 연구는 다양한 산업 분야에서 적용할 수 있는 적응형 키 관리 프로세스를 설계하고자, 보안 성 및 효율성의 균형을 고려하여 키 관리 프로세스를 설계하였다. 이를 위해, 본 연구에서는 공공, 금융, 의료, 제조 분야에서 사용되는 키 관리 시스템을 분석하여, 각 시스템의 특성을 파악하여 보안성 및 효율성을 고려한 세 가지 방향으로 키 관리 프 로세스를 설계한다. 첫 번째 프로세스는 보안성을 중시하여 키의 생성, 분배, 저장 및 폐기 절차 등을 강화하였으며, 두 번째는 효율성을 중시하여 자동화된 시스템 운영을 강조하였다. 세 번째는 보안성과 효율성을 균형 있게 반영한 프로세스로, 각 산업 의 특성에 맞는 적용 가능성을 검토하였다. 끝으로, 설계한 키 관리 프로세스를 검증하기 위해 전문가 검토를 통해 적용가능 성을 평가하였다. 본 연구를 통해 다양한 산업에서 적용 가능한 키 관리 시스템 설계에 기여하며, 향후 보안 위협에 대응할 수 있는 체계적이고 신뢰성 있는 키 관리 프로세스 발전에 기여할 것으로 기대한다.
As the importance of data security grows in the digital environment, the secure management of cryptographic keys, wh ich are crucial for encrypting and decrypting data, has become essential. Consequently, the need for a Key Management S ystem (KMS) that manages the entire lifecycle of cryptographic keys is increasing. This study aims to design an adaptive key management process applicable across various industries, considering a balance between security and efficiency. To ac hieve this, the study analyzes KMSs used in the public, financial, medical, and manufacturing sectors, identifying the char acteristics of each system and designing three key management processes based on both security and efficiency. The first process emphasizes security by reinforcing procedures for key generation, distribution, storage, and disposal. The second p rocess focuses on efficiency, highlighting automated system operations. The third process strikes a balance between securi ty and efficiency, with applicability assessed based on industry-specific requirements. Finally, expert reviews were conduct ed to evaluate the feasibility of the designed key management processes. This research contributes to the design of KMSs that can be applied across various industries and is expected to aid in the development of systematic and reliable key man agement processes that can effectively respond to evolving security threats.
Public key broadcast encryption scheme using new converting method
[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.18 No.6 2008 pp.199-206
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
Broadcast encryption is a cryptographical primitive which is designed for a content provider to distribute contents to only privileged qualifying users through an insecure channel. Anyone who knows public keys can distribute contents by means of public key broadcast encryption whose technique can also be applicable to many other applications. In order to design public key broadcast encryption scheme, it should devise some methods that convert a broadcast encryption scheme based on symmetric key cryptosystem to a public key broadcast encryption. Up to this point, broadcast encryption scheme on trial for converting from symmetric key setting to asymmetric public key setting has been attempted by employing the Hierarchical Identity Based Encryption (HIBE) technique. However, this converting method is not optimal because some of the properties of HIBE are not quite fitting for public key broadcast schemes. In this paper, we proposed new converting method and an efficient public key broadcast encryption scheme Pub-PI which is obtained by adapting the new converting method to the PI scheme [10]. The transmission overhead of the Pub-PI is approximately 3r, where r is the number of revoked users. The storage size of Pub-PI is O($c^2$), where c is a system parameter of PI and the computation cost is 2 pairing computations.
[Kisti 연계] 한국정보통신학회 Journal of information and communication convergence engineering Vol.13 No.4 2015 pp.280-285
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
Double random phase encryption (DRPE) is one of the well-known optical encryption techniques, and many techniques with DRPE have been developed for information security. However, most of these techniques may not solve the fundamental security problem caused by using fixed phase masks for DRPE. Therefore, in this paper, we propose a key phase mask updating scheme for DRPE to improve its security, where a spatial light modulator (SLM) is used to implement key phase mask updating. In the proposed scheme, updated key data are obtained by using previous image data and the first phase mask used in encryption. The SLM with the updated key is used as the second phase mask for encryption. We provide a detailed description of the method of encryption and decryption for a DRPE system using the proposed key updating scheme, and simulation results are also shown to verify that the proposed key updating scheme can enhance the security of the original DRPE.
한국AI디지털융합학회(구 한국디지털융합학회) IJICTDC Vol 5 No 2 2020.12 pp.18-21
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
In order to control the exposure of information outside using plain text communication between IoT devices on the MQTT protocol network, each device generates and shares a symmetric encryption key and then encrypts and decrypts communication messages with the key. We proposed, implemented, and verified an end-to-end encryption process that each device communicates with encrypting and decrypting only the payload of Publish Control Packet at MQTT protocol network.
DES(Data Encryption Standard) 속성 진단과 강화된 대칭키 암호 알고리즘 적용방법 KCI 등재후보
한국융합보안학회 융합보안논문지 제12권 제4호 2012.09 pp.85-90
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
DES는 64비트 단위로 나뉘어 진 각각의 블록이 한번의 암호화 알고리즘을 거쳐 암호화 된다. 대칭알고리즘으로서 똑같은 키와 알고리즘이 암호화와 복호화에 쓰인다. 복호화 할 때 키를 반대로 적용하는 등의 약간의 차이는 있다. 키 길이는 64비트로 표현되는데 이 중에서 실제로는 56비트만이 키로서 사용되고 나머지 8비트는 패리티 체크 비트로 사용된다. 암호화는 64비트 블록과 56비트 키를 바탕으로 만든 16개의 보조키가 총 16번의 혼돈과 확산을 거쳐 완료된다. DES 알고리즘을 선택한 이유는 암호 강도에 대한 의문이 제기되고 있기는 하지만 상업적으로 가장 널리 보급되어 이용되고 있다. 또한 기본 알고리즘을 DES 로 채택한 현장에서 앞으로도 상당한 기간 동안 이용이 계속될 것으로 예상되는 DES 알고리즘을 효과적으로 활용하는 방안이 현장에서 참고되기를 기대한다.
DES is a 64-bit binary, and each block is divided into units of time are encrypted through an encryption algorith m. The same key as the symmetric algorithm for encryption and decryption algorithms are used. Conversely, when decryption keys, and some differences may apply. The key length of 64 bits are represented by two ten thousand an d two 56-bit is actually being used as the key remaining 8 bits are used as parity check bits. The 64-bit block and 56-bit encryption key that is based on a total of 16 times 16 modifier and spread through the chaos is completed. D ES algorithm was chosen on the strength of the password is questionable because the most widely available comme rcially, but has been used. In addition to the basic DES algorithm adopted in the future in the field by a considerabl e period are expected to continue to take advantage of the DES algorithm effectively measures are expected to be in the field note
원격의료서비스에서 생체정보를 이용한 암호화키 생성방법 연구 KCI 등재
한국디지털정책학회 디지털융복합연구 제12권 제1호 2014.01 pp.573-578
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 세계가 고령화 사회로 진입함에 따라 U-Healthcare 서비스가 새롭게 각광받고 있다. 이러한 U-Healthcare 서비스가 발전하기 위해서는 U-Healthcare 환경에 최적화된 보안 솔루션이 요구된다. 그러나 U-Healthcare 환경은 기존 보안 솔루션의 적용이 어렵고 표준이 부재한 상황에 있다. 이러한 시점에서 안전한 U-Healthcare 환경을 구축하기 위해 데이터의 기밀성을 보장하는 목적으로 신체정보를 이용한 암호화키 생성방법을 제안하고자 한다.
Recently as we enter into the world of an aging society, the U-Healthcare service is newly spotlighted. In order to secure this U-Healthcare, a development of security solution that is suitable for the U-Healthcare environment is required. But the U-Healthcare environment is difficult to apply the existing security solution with the lack of standards, a security solution with high completeness was not developed. At this point, in order to structure the safe U-Healthcare environment, a generating method of an encryption key using the body information that helps the effective key management and ensuring the confidentiality of the data is proposed.
클라우드 환경에서 네트워크 가용성 개선을 위한 대칭키 암호화 기반 인증 모델 설계 KCI 등재
한국융합보안학회 융합보안논문지 제19권 제5호 2019.12 pp.47-53
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
네트워크를 통한 정보의 공유는 오늘날 클라우드 서비스 환경으로 발전하여 그 이용자수를 빠르게 증가시키고 있지 만 네트워크를 기반으로 하는 불법적인 공격자들의 주요 표적이 되고 있다. 아울러 공격자들의 다양한 공격 기법 중 IP 스푸핑은 그 공격 특성상 일반적으로 자원고갈 공격을 수반하기 때문에 이에 대한 빠른 탐지와 대응 기법이 요구 된다. IP 스푸핑 공격에 대한 기존의 탐지 방식은 연결 요청을 시도한 클라이언트의 트레이스 백 정보 분석과 그 일치 여부에 따라 최종적인 인증과정을 수행 한다. 그렇지만 트레이스 백 정보의 단순 비교 방식은 서비스 투명성을 요구하는 환경 에서 빈번한 False Positive로 인하여 과도한 OTP 발생을 요구할 수 있다. 본 논문에서는 이러한 문제를 개선하기 위해 트레이스 백 정보 기반의 대칭키 암호화 기법을 적용하여 상호 인증 정보로 사용하고 있다. 즉, 트레이스 백 기반의 암 호화 키를 생성한 후 정상적인 복호화 과정의 수행 여부로 상호 인증이 가능하도록 하였다. 아울러 이러한 과정을 통하 여 False Positive에 의한 오버헤드도 개선할 수 있었다.
Network-based sharing of information has evolved into a cloud service environment today, increasing its number of users rapidly, but has become a major target for network-based illegal attackers.. In addition, IP spoofing among attackers' various attack techniques generally involves resource exhaustion attacks. Therefore, fast detection and response techniques are required. The existing detection method for IP spoofing attack performs the final authentication process according to the analysis and matching of traceback information of the client who attempted the connection request. However, the simple comparison method of traceback information may require excessive OTP due to frequent false positives in an environment requiring service transparency. In this paper, symmetric key cryptography based on traceback information is used as mutual authentication information to improve this problem. That is, after generating a traceback-based encryption key, mutual authentication is possible by performing a normal decryption process. In addition, this process could improve the overhead caused by false positives.
M2M 환경의 디바이스 키 보호를 위한 암호 알고리즘 응용 기법 KCI 등재
한국디지털정책학회 디지털융복합연구 제13권 제10호 2015.10 pp.343-351
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
현재 M2M 환경은 다양한 서비스가 기관 및 기업이나 일상생활로 확대되면서 관련 기술의 보안 취약성 발생 가능성이 이슈화되고 있다. 본 논문은 이러한 보안 취약성 문제를 해결하기 위해 M2M 환경의 디바이스 키 보호를 위한 암호 알고리즘 응용 기법을 제안한다. 제안 기법은 타원곡선 암호 기반으로 초기 키 교환과 서명 교환을 통해 보안 세션을 생성하였고, 화이트박스 암호는 보안 세션 키를 이용하여 화이트박스 테이블을 생성하는 암호화에 응용하였다. 암호 알고리즘 적용 결과, 타원곡선 암호는 통신 세션에 대한 경량 화된 상호인증, 세션 키 보호를 제공하고, 화이트 박스 암호는 기존 암호 알고리즘과는 다른 방식으로 암호화에 사용되는 세션 키 보호를 보장하였다. 제안하는 프로토콜은 데이터변조 및 노출, 중간자 공격, 데이터 위조 및 변조 공격에 대해 안전한 장점이 있다.
With the diverse services of the current M2M environment being expanded to the organizations, the corporations, and the daily lives, the possibility of the occurrence of the vulnerabilities of the security of the related technologies have become an issue. In order to solve such a problem of the vulnerability of the security, this thesis proposes the technique for applying the cryptography algorithm for the protection of the device key of the M2M environment. The proposed technique was based on the elliptic curve cryptography Through the key exchange and the signature exchange in the beginning, the security session was created. And the white box cipher was applied to the encryption that creates the white box table using the security session key. Application results cipher algorithm, Elliptic Curve Cryptography provides a lightweight mutual authentication, a session key for protecting the communication session and a conventional white-box cipher algorithm and was guaranteed the session key used to encrypt protected in different ways. The proposed protocol has secure advantages against Data modulation and exposure, MITM(Man-in-the-middle attack), Data forgery and Manipulation attack.
Secret Key Awareness Security Public Key Encryption Scheme SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.5 No.4 2011.10 pp.49-58
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
In this paper, firstly, we introduce a new security definition called secret key awareness security which is to guarantee anyone gener-ating the public key to know the corresponding secret key. Following, we give a concrete implementing for secret key awareness security. Secondly, we present two applications: one is in plaintext awareness security cryp-tosystem, and another is in certificatless public key encryption scheme.
Research on Encryption Key Extraction From Iris Feature SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.9 No.5 2015.05 pp.133-140
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
The current encryption algorithm has some problems that key length is long, which is difficult to be memorized and kept so that a potential threat is caused to information security. The encryption key extracted from the biological feature is used for the encryption method, which has become a hotspot of the research. The Haar wavelet decomposition is carried out to the iris image, to extract the third-layer high frequency coefficient as the iris feature code. The random mapping function is used to generate a 128 - bit key. chi-square (χ2) test is used to analyze the key safety extracted. The results show that the key extracted from iris feature can meet requirements of the randomness and security of the encryption algorithm.
Applying Asymmetric Key Encryption to Secure Internet based SCADA
국제인공지능학회(구 한국인터넷방송통신학회) International Journal of Internet, Broadcasting and Communication Vol.4 No.2 2012.08 pp.17-21
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
As an acronym for Supervisory Control and Data Acquisition, SCADA is a concept that is used to refer to the management and procurement of data that can be used in developing process management criteria. The use of the term SCADA varies, depending on location. Conventionally, SCADA is connected only in a limited private network. In current times, there are also demands of connecting SCADA through the internet. The internet SCADA facility has brought a lot of advantages in terms of control, data generation and viewing. With these advantages, come the security issues regarding web SCADA. In this paper, we discuss web SCADA and its connectivity along with the issues regarding security and suggests a web SCADA security solution using asymmetric-key encryption.
Application of Asymmetric-key Encryption Method for Internet-based SCADA security
보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.5 No.6 2008.12 pp.537-544
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
As an acronym for Supervisory Control and Data Acquisition, SCADA is a concept that is used to refer to the management and procurement of data that can be used in developing process management criteria. The use of the term SCADA varies, depending on location. Conventionally, SCADA is connected only in a limited private network. In current times, there are also demands of connecting SCADA through the internet. The internet SCADA facility has brought a lot of advantages in terms of control, data generation and viewing. With these advantages, comes the security issues regarding web SCADA. We discuss web SCADA and its connectivity along with the issues regarding security. And suggests a web SCADA security solution using asymmetric-key encryption.
DNS Prevention Using 64-Bit Time Synchronized Public Key Encryption to Isolate Phishing Attacks SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.8 2016.08 pp.395-406
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
In this work, a quick authentication scheme is implemented to prevent Phishing and DNS spoofing. In DNS spoofing, attackers inject the fake DNS server by duplicating the IP addresses and fake server redirect network traffic to wrong destinations. In phishing, phishers clone the legitimate website and user think that it is original website and users giving away their username and passwords to attacker’s website and attackers hack their confidential information and they can misuse it for financial gain, identity theft, gaining fame, malware distribution and industrial espionage. We host the phishing website but we cannot pass the link through common hosting websites like Google and Facebook. So, phishers force the legitimate users to open a phished link with the DNS spoofing through fake DNS server then user directly redirect to a fake server. So our proposed work is to prevent DNS spoofing, to prevent the Phishing attacks by isolating it using 64-bit time synchronized public key encryption.
Key Aggregate Based Homomorphic Encryption for Efficient Authentication for Secure Cloud Storage SCOPUS
보안공학연구지원센터(IJDTA) International Journal of Database Theory and Application Vol.9 No.11 2016.11 pp.137-148
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Now a day’s data out sourcing is the main focusing term in real time cloud computing applications. Secure data outsourcing is another real time intellectual concept in cloud computing applications for proceeding efficient data transmission. Conventionally Attribute Based Encryption (ABE) performs efficient data security of data outsourcing in cloud. It performs effective data security based on attributes of uploaded data for storage. Attributes are key terms for converting plain file data to Meta (cipher) file, so every time attribute extraction is complexity in data storage in cloud for efficient security analysis. We describe new public cryptographic system which effects fixed size for efficient delegation of decryptions for cipher-texts. So in this paper we propose to KAE (Key Aggregate Encryption) for efficient data security for providing. The novelty is one can aggregate any set of secret keys and make them as complete with single key with power of all the keys been aggregated. We provide security analysis as a development in real time cloud applications for processing access control data delivery between users present in cloud. Our experimental results show efficient security with access control policies in data storage in cloud.
Public Key Generation and Encryption Mechanism Using the Elliptic Curve in Smart Phones SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.9 No.12 2015.12 pp.405-414
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Personal information stored in mobile devices can be unexpectedly exposed to others when users make use of mobile banking, Internet shopping and etc. Because of the important personal information that can be easily exposed in the mobile environment, it becomes more important to have a reliable security system. It is strongly required for this mobile security system to have a small memory size and a high processing speed as its components' characteristics. Considering these characteristics of the mobile security system, this paper aims at proposing a public key generation and an encryption mechanism that generates a hidden key using the Newton-Raphson method and applies the Diffie-Hellman key-exchange method to authenticate the peer. This mechanism uses an elliptic curve resulting in a small size of encryption key and a high security level.
Image Encryption Research based on Key Extracted from Iris Feature SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.9 No.6 2015.06 pp.157-166
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
The encryption algorithm has disadvantages like the long key making memory difficult and uneasy safekeeping, which causes a potential threat to the information security. Therefore, a new direction of the encryption method research is to combine the biometric information with the traditional encryption algorithm. The key extracted from the iris and AES encryption algorithm are used in the image encryption algorithm. The db2 wavelet decomposition to the iris region is performed, and the third level high frequency coefficient is extracted as the iris feature codes, from which a 192 bit key is generated by using the stochastic mapping function. The randomness of the key extraction is analyzed. The proposed algorithm is employed to do the encryption test to the image. The encryption effect is compared with the scrambling encryption effect of the classic Arnold method. The experiment results show that security of the encryption image gained by using the proposed algorithm is higher, achieving the purpose of protecting image information.
Quantum Chaotic Image Encryption with One Time Running Key SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.8 No.4 2014.07 pp.77-88
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
To improve image encryption mechanism and enhance the security of pixel value transformation, a new image encryption scheme is proposed based on quantum chaos. In the phase of key generation, running key related to plaintext is generated by cipher-text successively disturbing chaotic component. In the process of encryption, polynomial multiplication in Galois field is first introduced to perform pixel encryption and then the cipher-text is encrypted again with cipher-text feedback mechanism. The experiment results show that the introduction of disturbing mechanism implements one time running-key stream, minimization of dynamical degradation of digital chaos, and resistance to reconstruction attack. In addition, polynomial multiplication which is first applied in the encryption system degrades the possibility of breaking our scheme in theory. Finally, some analyses such as correlation, sensitivity, min-entropy, and time complexity further demonstrate the security and efficiency of our scheme.
보안공학연구지원센터(IJGDC) International Journal of Grid and Distributed Computing Vol.8 No.5 2015.10 pp.153-164
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Building applications on on-demand infrastructures instead of building applications on fixed and rigid infrastructures was provided by cloud computing providers. By simply positing into the cloud, it gains fast access to business applications or infrastructure resources with reduced Capital Expenditures (CAPEX). Dramatic increase in amount of information’s are placed into the cloud by individuals and industries, security issues are vital concern in mobile computing (MCC) and impends fast deployment of applications on the cloud. This work discus the different security issues that arises about how safe the mobile cloud computing environment is and provides a unified reliable security mechanism. There are two different types of the cloud users are: On-demand and Optimistic. On-demand is a non-preemptible for flexible leases given a user accessing to the resources within an interactive time of making the request and makes the resources available for an agreed-upon period of time, user can deploy any virtual machine (VM) compatible with the system. Optimistic is preemptible and pre-set contract gives a user access to resources at an indeterminate time and make resources available to the user for an insufficient amount of time. After that, this resources are initially (pre)-defined for the user by the cloud admin, that is the user cannot provide his or her own virtual machine (VM) based on defined access control for security.
A Study to Examine the Superiority of CSAVK, AVK over Conventional Encryption with a Single Key SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.2 2016.02 pp.279-286
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Time variant key is one of the great research challenges in the field of cryptography for achieving the perfect security. Automatic variable Key (AVK) has been well researched and established as an important technique to realize time variant key in achieving towards perfect security. In AVK, proposed by Bhunia, the key is made to vary from data to data or session to session that is essentially required for achieving perfect secrecy. The variable key is generated in each time a data is sent and or a session is made. The time variant key (in AVK) is found to reduce the frequency attack as seen in earlier research, while such key was in applied in AES algorithm. In the present experimental research the authors study the application of AVK & Computing & Shifting AVK (CSAVK) in RSA to examine the reducing effect of frequency attack.
키에스크로를 최소화한 계층적 아이디기반 암호 KCI 등재
보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.12 No.6 2015.12 pp.545-552
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
아이디기반 암호는 사용자의 아이디, 이메일주소 등 공개될 수 있는 임의의 정보를 공개키로 사용하고 이와 쌍이 되는 개인키는 개인키생성기관(PKG)이 생성하여 사용자에게 전달하는 공개키암호 기법이다[1][2]. 이것은 키분배를 효율적으로 수행할 수 있는 장점이 있으나 사용자의 개인키가 개인키생성기관(PKG)에게 노출된다는 키에스크로 단점이 있다. 아이디기반 암호는 그 특성상 독립적인 인증도메인을 갖는 복수개의 PKG가 사용되는 경우에는 아이디기반 암호만으로 인증을 확장하는 것이 어렵다고 생각되어 왔으나 Gentry, Silverberg[3]는 다수의 PKG가 계층적 구조로 연결된 일반적인 경우에도 아이디기반 암호만으로 인증을 확장할 수 있는 계층적 아이디기반 암호기법을 제시하였으며 이 논문은 많은 관련 연구들의 시발점이 되었다. 그런데 이 기법은 키에스크로 특성에 있어서 사용자의 모든 조상 PKG들이 사용자의 개인키를 가지고 있지 않음에도 불구하고 사용자에게 전송되는 암호문을 복호화할 수 있다는 단점이 있는데 이것은 매우 바람직하지 않은 특성이다. 본 연구에서는 이 기법을 수정하여 개인키를 가지고 있는 사용자와 사용자에게 개인키를 발급한 단말 PKG만이 복호화 능력을 가질 수 있도록 키에스크로 특성을 최소화할 수 있는 계층적 아이디기반 암호 기법을 제시한다.
Identity-based cryptography is a public key cryptosystem in which any arbitrary string such as identity, email address of user can be used as a public key and the corresponding private key is generated by a private key generator (PKG) and given to the user through a secure channel[1][2]. It has advantage in key distribution, but also has drawback of key escrow that PKG knows user’s private key. If multiple PKGs with independent certification domain are used and users belong to different PKGs, it was considered that expanding certification using only ID-based cryptography is difficult between two users who belong to different PKG domains. Gentry and Silverberg[3] presented a hierarchical identity based cryptography which successfully expands certification among multiple PKGs structured in hierarchical manner, thus lots of extended researches followed from it [4-10]. But this scheme has a drawback that all ancestor PKGs of a user can decrypt any message sent to the user even though they do not have the private key of the user, which is very undesirable feature. In this paper we modify Gentry and Silverberg’s hierarchical identity based encryption (HIBE) scheme and present a new HIBE scheme which minimize the key escrow property that only user and the end PKG who issued private key to the user can decrypt message.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.