년 - 년
다양한 분야에서의 키 관리 시스템 분석을 통한 적응형 키 관리 프로세스 연구 KCI 등재
한국융합보안학회 융합보안논문지 제24권 제5호 2024.12 pp.27-36
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
디지털 환경에서 데이터 보안의 중요성이 증가하면서, 데이터를 암호화 및 복호화하는 암호 키의 안전한 관리가 필수적인 요소가 되고 있다. 이에 암호 키의 생명주기 전체 과정을 관리하는 키 관리 시스템(Key Management System, KMS)에 대한 필요성도 점차 증가하고 있다. 본 연구는 다양한 산업 분야에서 적용할 수 있는 적응형 키 관리 프로세스를 설계하고자, 보안 성 및 효율성의 균형을 고려하여 키 관리 프로세스를 설계하였다. 이를 위해, 본 연구에서는 공공, 금융, 의료, 제조 분야에서 사용되는 키 관리 시스템을 분석하여, 각 시스템의 특성을 파악하여 보안성 및 효율성을 고려한 세 가지 방향으로 키 관리 프 로세스를 설계한다. 첫 번째 프로세스는 보안성을 중시하여 키의 생성, 분배, 저장 및 폐기 절차 등을 강화하였으며, 두 번째는 효율성을 중시하여 자동화된 시스템 운영을 강조하였다. 세 번째는 보안성과 효율성을 균형 있게 반영한 프로세스로, 각 산업 의 특성에 맞는 적용 가능성을 검토하였다. 끝으로, 설계한 키 관리 프로세스를 검증하기 위해 전문가 검토를 통해 적용가능 성을 평가하였다. 본 연구를 통해 다양한 산업에서 적용 가능한 키 관리 시스템 설계에 기여하며, 향후 보안 위협에 대응할 수 있는 체계적이고 신뢰성 있는 키 관리 프로세스 발전에 기여할 것으로 기대한다.
As the importance of data security grows in the digital environment, the secure management of cryptographic keys, wh ich are crucial for encrypting and decrypting data, has become essential. Consequently, the need for a Key Management S ystem (KMS) that manages the entire lifecycle of cryptographic keys is increasing. This study aims to design an adaptive key management process applicable across various industries, considering a balance between security and efficiency. To ac hieve this, the study analyzes KMSs used in the public, financial, medical, and manufacturing sectors, identifying the char acteristics of each system and designing three key management processes based on both security and efficiency. The first process emphasizes security by reinforcing procedures for key generation, distribution, storage, and disposal. The second p rocess focuses on efficiency, highlighting automated system operations. The third process strikes a balance between securi ty and efficiency, with applicability assessed based on industry-specific requirements. Finally, expert reviews were conduct ed to evaluate the feasibility of the designed key management processes. This research contributes to the design of KMSs that can be applied across various industries and is expected to aid in the development of systematic and reliable key man agement processes that can effectively respond to evolving security threats.
클라우드 환경에서 헬스케어 데이터를 위한 효율적인 암호화 기법 KCI 등재
중소기업융합학회 융합정보논문지(구 중소기업융합학회논문지) 제8권 제3호 2018.06 pp.63-69
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 의료 서비스 분야는 사용자의 헬스케어 데이터를 효율적으로 관리하기 위해서 클라우드 서비스를 이용하고 있다. 그러나, 클라우드 환경에서 처리되는 사용자의 헬스케어 데이터의 안정성을 보장하는 연구는 미진한 상태이다. 본 논 문에서는 클라우드 환경에서 헬스케어 데이터를 효율적으로 암호화하는 부분 랜덤 암호화 기법을 제안한다. 제안 기법은 병원 의료 서비스에 최적화하도록 사용자가 생성하는 랜덤키(p, q)를 2개 생성하여 공개키와 개인키 생성에 반영한다. 제안 기법에서 사용되는 랜덤 키는 데이터를 전체 암호화하지 않고 일부분만을 암호화하여 사용자의 헬스케어 데이터 처리 효율 을 향상시켰다. 성능평가 결과, 제안 기법은 암호화 생성 비용을 평가한 결과 기존 기법에 비해 21.6% 낮추었고, 병원 내 사용자 헬스케어 데이터 처리 시간도 18.5% 향상된 결과를 얻었다.
Recently, healthcare services are using cloud services to efficiently manage users' healthcare data. However, research to ensure the stability of the user's healthcare data processed in the cloud environment is insufficient. In this paper, we propose a partial random encryption scheme that efficiently encrypts healthcare data in a cloud environment. The proposed scheme generates two random keys (p, q) generated by the user to optimize for the hospital medical service and reflects them in public key and private key generation. The random key used in the proposed scheme improves the efficiency of user 's healthcare data processing by encrypting only part of the data without encrypting the whole data. As a result of the performance evaluation, the proposed method showed 21.6% lower than the existing method and 18.5% improved the user healthcare data processing time in the hospital.
Genetic Symmetric Key Generation for IDEA
[Kisti 연계] 한국정보처리학회 Journal of information processing systems Vol.11 No.2 2015 pp.239-247
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
Cryptography aims at transmitting secure data over an unsecure network in coded version so that only the intended recipient can analyze it. Communication through messages, emails, or various other modes requires high security so as to maintain the confidentiality of the content. This paper deals with IDEA's shortcoming of generating weak keys. If these keys are used for encryption and decryption may result in the easy prediction of ciphertext corresponding to the plaintext. For applying genetic approach, which is well-known optimization technique, to the weak keys, we obtained a definite solution to convert the weaker keys to stronger ones. The chances of generating a weak key in IDEA are very rare, but if it is produced, it could lead to a huge risk of attacks being made on the key, as well as on the information. Hence, measures have been taken to safeguard the key and to ensure the privacy of information.
SoC Virtual Platform with Secure Key Generation Module for Embedded Secure Devices
[Kisti 연계] 한국정보처리학회 Journal of information processing systems Vol.20 No.1 2024 pp.116-130
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
In the Internet-of-Things (IoT) or blockchain-based network systems, secure keys may be stored in individual devices; thus, individual devices should protect data by performing secure operations on the data transmitted and received over networks. Typically, secure functions, such as a physical unclonable function (PUF) and fully homomorphic encryption (FHE), are useful for generating safe keys and distributing data in a network. However, to provide these functions in embedded devices for IoT or blockchain systems, proper inspection is required for designing and implementing embedded system-on-chip (SoC) modules through overhead and performance analysis. In this paper, a virtual platform (SoC VP) was developed that includes a secure key generation module with a PUF and FHE. The SoC VP platform was implemented using SystemC, which enables the execution and verification of various aspects of the secure key generation module at the electronic system level and analyzes the system-level execution time, memory footprint, and performance, such as randomness and uniqueness. We experimentally verified the secure key generation module, and estimated the execution of the PUF key and FHE encryption based on the unit time of each module.
Efficient and Secure Group Key Generation Protocol for Small and Medium Business
중소기업융합학회 융합정보논문지(구 중소기업융합학회논문지) 제4권 제4호 2014.12 pp.19-23
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
Group communication is becoming increasingly popular in Internet applications such as videoconferences, online chatting programs, games, and gambling. For secure communications, the integrity of messages, member authentication, and confidentiality must be provided among group members. To maintain message integrity, all group members use the Group Key (GK) for encrypting and decrypting messages while providing enough security to protect against passive attacks. Tree-based Group Diffie-Hellman (TGDH) is an efficient group key agreement protocol to generate the GK. TGDH assumes all members have an equal computing power. One of the characteristics of distributed computing and grid environments is heterogeneity; the member can be at a workstation, a laptop or even a mobile computer. Member reordering in the TDGH protocol could potentially lead to an improved protocol; such reordering should capture the heterogeneity of the network as well as latency. This research investigates dynamic reordering mechanisms to consider not only the overhead involved but also the scalability of the proposed protocol.
[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.32 No.5 2022 pp.915-932
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
개인정보 보호법과 가명정보 처리 가이드라인에 따르면, 서로 다른 결합신청자들이 결합을 희망할 때 Salt값을 포함한 결합키 생성항목의 해시값으로 매핑을 진행한다. 결합키 생성항목의 예시로는 성명, 전화번호, 생년월일, 주소 등의 개인정보가 될 수 있으며, 해시 함수의 특성상 서로 다른 결합신청자들이 이들의 항목을 정확히 동일한 형태로 저장하고 있을 때 문제없이 결합을 진행할 수 있다. 하지만 이러한 기법은 서로 다른 결합신청자들의 데이터베이스 갱신 시점이 달라서 발생하는 주소 변경, 개명 등의 시나리오에서의 결합은 취약하다. 따라서 본 연구에서 우리는 주소 변경, 개명 등의 결합키 생성항목이 갱신된 시나리오에서도 개인정보보호를 만족하는 강건한 결합키 생성기법을 확률적 자료 연계를 통한 임계값을 바탕으로 제안하며, 본 연구 결과를 활용한 국내 빅데이터 및 인공지능 사업의 발전에 기여하고자 한다.
According to the Personal Information Protection Act and Pseudonymization Guidelines, the mapping is processed to the hash value of the combination key generation items including Salt value when different combination applicants wish to combine. Example of combination key generation items may include personal information like name, phone number, date of birth, address, and so on. Also, due to the properties of the hash functions, when different applicants store their items in exactly the same form, the combination can proceed without any problems. However, this method is vulnerable to combination in scenarios such as address changing and renaming, which occur due to different database update times of combination applicants. Therefore, we propose a privacy preserving combination key generation scheme robust to updates of items used to generate combination key even in scenarios such as address changing and renaming, based on the thresholds through probabilistic record linkage, and it can contribute to the development of domestic Big Data and Artificial Intelligence business.
BYOD환경에서 키 생성 및 접근 제어 프로토콜에 관한 연구
[Kisti 연계] 한국콘텐츠학회 한국콘텐츠학회논문지 Vol.15 No.5 2015 pp.27-35
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
스마트 기기 사용자의 증가와 통신 기술 발전으로 시간과 장소에 제약 없이 업무환경에 대한 영역이 확대되고 있다. 사용자 개인의 장비를 활용하여 업무에 도입되어지고 있으며, 이를 BYOD(Bring Your On Device)라고 한다. 하지만 기존의 무선 환경에서 발생하고 있는 보안위협에 취약하며, 기업 내부에 의한 중요 정보 유출, 사용자 부주의로 인한 단말기 분실/도난 등으로 인하여 보안취약점이 이슈화 되고 있다. 그러므로 본 논문에서는 BYOD환경에서 사용자 정보 기반으로 세션 키를 생성하여 사용자 권한에 따른 접근 제어 프로토콜에 관하여 연구하였다. 사용자 정보 및 사용자 기기 정보를 기반으로 세션 키를 생성하였으며, 이후 접근제어 프로토콜을 설계하였다. 제안하는 프로토콜은 BYOD 환경 및 무선 랜 환경에서 발생할 수 있는 공격으로부터 보호할 수 있고, 사용자 권한을 관리하여 기업 내부의 중요 콘텐츠 유출로부터 보안 요구사항과 안전성을 강화하였다.
Depending on the smart device user growth and development of communication technology, the area about working environment was extended without constraints of time and places. It is introducing to work using user's devices and this environment is called 'BYOD(Bring Your On Device)'. But it is vulnerable to security threat that happened in existing wireless environment and its security threat issue which is caused by inside information leak by an inside job and lost or stolen terminal which is caused by careless user is getting heated. So we studied about access control protocol by user rights under the BYOD situation make a session key based on the user information. We make a session key based on the user information and user device information, after that we design an access control protocol. The protocol we suggest can protect from attack under the BYOD situation and wireless communication situation and also safety and security requirement from inside information leak because it controls user rights.
상용 비디오 콘텐츠 보호를 위한 일회용 바이오메트릭 키 생성 및 인증 모델 KCI 등재후보
한국융합학회 한국융합학회논문지 제5권 제4호 2014.12 pp.101-106
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
비디오 콘텐츠는 사람의 시각과 청각을 이용함으로 다른 종류의 콘텐츠 보다 이해하기 쉽기 때문에 많은 사람들이 선호한다. 더불어 스마트폰의 보급으로 인터넷을 이용한 비디오 콘텐츠 서비스에 대한 수요가 급증하고 있다. 콘텐츠 거래 활성화를 위해서는 유료 가입자에 대한 인증과 유료 채널로 전송되는 데이터의 보호가 중요하다. 가입자 채널 보호를 위해서는 일반적으로 대칭키 암호 기술이 사용되는데, 안전성을 높이기 위해서 키 값을 주기적으 로 변경해야 한다. 또한 다른 사용자에 의한 콘텐츠 불법 이용을 방지하려면 대리 인증이 불가해야 한다. 본 논문에서 는 가입자의 바이오메트릭 데이터를 이용한 본인 인증 및 일회용 암호키를 생성하는 모델을 제안한다. 제안한 모델은 바이오메트릭 데이터 등록, 일회용 키 생성, 채널 암호화 및 복호화 단계로 구성된다. 기존의 케이블 TV 콘텐츠 인증 기술인 CAS (Conditional Access System)와의 차이점을 분석하고 인터넷 상거래에서의 응용 분야를 제시한다.
Most peoples are used to prefer to view the video contents rather than the other contents since the video contents are more easy to understand with both their eyes and ears. As the wide spread use of smartphones, the demands for the contents services are increasing rapidly. To promote the contents business, it’s important to provide security of subscriber authentication and corresponding communication channels through which the contents are delivered. Generally, symmetric key encryption scheme is used to protect the contents in the channel, and the session key should be upadated periodically for the security reasons. In addition, to protect viewing paid contents by illegal users, the proxy authentication should not be allowed. In this paper, we propose biometric based user authentication and one time key generation models. The proposed model is consist of biometric template registration, session key generation and chanel encryption steps. We analyze the difference and benefits of our model with existing CAS models which are made for CATV contents protection, and also provides applications of our model in electronic commerce area.
사용자 순서 재조정을 통한 그룹 키 생성 트리 프로토콜 KCI 등재
한국디지털정책학회 디지털융복합연구 제10권 제6호 2012.07 pp.247-251
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
인터넷 응용프로그램을 통해 그룹 통신의 사용이 증가하면서 보안의 대한 요구사항인 메시지 무결성, 사용자 인증, 기밀성이 중요시 되고 있다. 보안 요구 사항을 위해서 그룹 통신 시에 암호 키를 생성하여 메시지 기밀성을 유지하는데, 키 생성을 효율적이면서도 안전하게 키 생성 트리를 이용하여 모바일 컴퓨팅 환경의 사용자도 쉽게 키를 생성하도록 사용자 재배치를 통해 키 생성 효율을 증대 시키기 위해 본 연구의 목표가 있다.
Tree-based Group Diffie-Hellman (TGDH) is one of the efficient group key agreement protocols to generate the GK. TGDH assumes all members have an equal computing power. As one of the characteristics of distributed computing is heterogeneity, the member can be at a workstation, a laptop or even a mobile computer. Therefore, the group member sequence should be reordered in terms of the member’s computing power to improve performance. This research proposes a reordering of members in the group key generation tree to enhance the efficiency of the group key generation.
[NRF 연계] 한국여성심리학회 한국심리학회지:여성 Vol.30 No.1 2025.03 pp.103-133
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 연구는 MZ세대의 감정 표현 데이터를 분석하여 주요 이슈를 도출하는 데 목적을 두고 수행되었다. 이를 위해 어플리케이션을 통해 수집된 MZ세대의 대화 데이터를 성별과 감정 유형별로 분류하고, LDA 토픽모델링 기법을 적용하였다. 분석 결과, MZ세대 남성과 여성의 슬픔 및 화 감정 토픽, 여성의 행복 감정 토픽에서 주요 이슈가 도출되었다. MZ세대 감정 표출 대화에서 나타난 주요 이슈는 가족(특히 아버지), 취업 및 직장 스트레스, 반려동물, 공동 거주 갈등이었다. 해당 이슈는 남성-슬픔 토픽에서 ‘자신과 가족 및 친구의 건강을 염려함’, ‘취업 스트레스’, ‘직무 스트레스로 몸과 마음이 지침’, ‘반려견의 죽음에 슬퍼함’주제에서 확인되었다. 여성-슬픔 토픽에서는 ‘가족과 친구의 건강을 염려함’, ‘반려견의 죽음에 슬퍼함’, ‘취업 스트레스’ 주제가 확인되었다. 또한, 남성과 여성 모두의 화 토픽에서 ‘직장 스트레스’, ‘공동 거주 갈등’, ‘유기견주에게 화가 남’주제가 확인되었다. 여성에서만 확인된 주요한 이슈로 어플리케이션을 통해 자신의 우울감을 다루기 위한 방법을 이야기한다는 특징이 도출되었으며, SNS를 통한 소비와 마라톤 취미와 같은 문화 트렌드도 주요한 특징으로 드러났다.
This study examines the emotional expressions of the generation MZ using app-based conversational data, which were classified by gender and emotion type and analyzed through LDA topic modeling. The analysis identified key topics related to sadness and anger for both genders, as well as happiness for females. Common issues among the MZ generation included family(particularly issues involving fathers), employment and workplace stress, companion animals, and shared living conflicts. Male-sadness topics highlighted concerns about personal, family, and friends’ health, employment stress, exhaustion from job responsibilities, and grief over the loss of a companion animal. Female-sadness topics similarly focused on concerns about family and friends’ health, grief over the death of a companion animal, and employment stress. Anger-related topics for both genders pointed to workplace stress, shared living conflicts, and anger toward irresponsible companion animal owners. Female-specific issues included discussions on coping strategies for depression through the app, as well as cultural trends such as SNS-driven consumption and marathon running.
Public Key Generation and Encryption Mechanism Using the Elliptic Curve in Smart Phones SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.9 No.12 2015.12 pp.405-414
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Personal information stored in mobile devices can be unexpectedly exposed to others when users make use of mobile banking, Internet shopping and etc. Because of the important personal information that can be easily exposed in the mobile environment, it becomes more important to have a reliable security system. It is strongly required for this mobile security system to have a small memory size and a high processing speed as its components' characteristics. Considering these characteristics of the mobile security system, this paper aims at proposing a public key generation and an encryption mechanism that generates a hidden key using the Newton-Raphson method and applies the Diffie-Hellman key-exchange method to authenticate the peer. This mechanism uses an elliptic curve resulting in a small size of encryption key and a high security level.
Metadata Driven Efficient CRE based Cipher Key Generation and Distribution in Cloud Security SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.8 No.3 2014.05 pp.377-392
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
The increasing popularity of cloud storage services has lead companies that handle critical data to think about using these services for their storage needs. To keep their sensitive data against untrusted cloud service providers, a natural way is to store only encrypted data in the cloud severs and providing an efficient access control mechanism.. The proposed model involves the attributes of metadata for key generation and distribution techniques. The key problems of this approach includes, the generation of cipher key and establishing an access control mechanism for the encrypted data using cipher key, where keys cannot be revoked without the involvement of user, metadata data server (MDS) and Data Server (DS). From this study, we propose a novel metadata driven cipher key generation and distribution policies by means of exploiting the characteristic of the metadata stored called CRE Scheme, a Cloud Re-Encryption model that improves the confidentiality of the data stored through the cipher-key Cmxn. We have implemented our security model using eucalyptus tool and evaluated the performance and scalability of the secured model. We observed that our protocols improved the security of the data stored and compared with existing security models.
M2M 통신 환경에서 트랩도어 충돌 해쉬를 이용한 그룹키 생성 및 교환 기법 KCI 등재
국제인공지능학회(구 한국인터넷방송통신학회) 한국인터넷방송통신학회 논문지 제15권 제5호 2015.10 pp.9-17
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
무선 통신 기술의 발전과 ICT 시장의 변화에 따라 M2M 서비스 활성화 및 기술은 지속적인 발전을 거듭하고 있다. 사람의 제어나 직접적인 개입 없이 사물과 사물간의 통신환경을 구축하는 M2M 환경이 주목받고 있다. 무선 통신 환경의 특성으로 데이터 노출, 위조, 변조, 삭제, 프라이버시 등의 문제에서 다양한 보안 위협에 노출 될 가능성과 안전한 통신 보안 기술이 중요 요구사항으로 이슈화되고 있다. 본 논문은 트랩도어 충돌 해쉬의 요구사항을 분석하고, 트랩도어의 특수성을 이용하여 M2M 환경에서 그룹간의 키를 생성하고, 이를 세션키로 교환하는 기법을 제안한다. 그리고 그룹키 생성에 이은 디바이스와 게이트웨이의 인증을 확인하는 기법을 제안한다. 제안하는 기법은 충돌 메시지와 충돌 해쉬의 특수성을 이용하여 그룹 통신 구간의 위장 공격, 중간자 공격, 재전송 공격 등의 공격 저항성을 가지는 안전한 기법임을 확인하였다.
The development of wireless communication technology and change in the ICT market has led to the development of the M2M service and technology. Under these circumstances, the M2M environment has been the focus of communication environment construction between machines without control or direct intervention of human being. With characteristics of wireless communication environment, the possibility of being exposed to numerous security threats and safe communication security technology have becoming an issue an important requirements for problems such as data exposure, forgery, modulation, deletion, and privacy. This research analyzes requirements of trapdoor collision hash, generates keys between groups under the M2M environment by using the specificity of trapdoor, and suggests technology to exchange keys with session keys. Further, it also suggests techniques to confirm authentication of device and gateway in accordance with group key generation. The techniques herein suggested are confirmed as safe methods in that they have attack resistance such as Masquerade Attack, Man-in-the-Middle Attack, and Replay Attack in the group communication block by using the speciality of collision message and collision hash.
M2M 통신 환경에서 해시 충돌을 이용한 그룹키 생성 및 교환 기법 연구 KCI 등재
국제인공지능학회(구 한국인터넷방송통신학회) 한국인터넷방송통신학회 논문지 제19권 제5호 2019.10 pp.9-17
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
IoT 환경이 보편화됨에 따라 사람의 직접적인 개입 없이 물체와 물체 사이의 통신 환경을 구축하는 M2M 환경의 안전성이 중요시 되고 있다. 무선 통신 환경의 특성상 데이터 노출, 위조, 변조, 삭제 및 개인 정보 보호와 같은 다양한 측면에서 보안 위협에 노출 될 가능성이 존재하고, 안전한 통신 보안 기술이 중요한 요구 사항으로 다뤄진다. 본 논문에 서는 해시충돌을 이용하여 기존 ‘M2M 통신 환경에서 트랩도어 충돌 해쉬을 이용한 그룹키 생성 및 교환 기법’ 연구의 한계점을 확인하고, 스니핑 공격에 안전한 그룹간에 키를 생성하고 이를 세션 키와 교환하는 기법과 그룹 키 생성 후에 장치와 게이트웨이의 인증을 확인하는 메커니즘을 제안한다. 제안 된 방법은 충돌 메시지 및 충돌 해시의 특이성을 이용 하여 그룹 통신 섹션의 위장 공격, 중간자 공격, 재전송 공격과 같은 공격 저항을 가지며, 해시충돌의 취약점에 대해 안전성을 증명하는 기법이다.
As the IoT environment becomes more popular, the safety of the M2M environment, which establishes the communication environment between objects and objects without human intervention, becomes important. Due to the nature of the wireless communication environment, there is a possibility of exposure to security threats in various aspects such as data exposure, falsification, tampering, deletion and privacy, and secure communication security technology is considered as an important requirement. In this paper, we propose a new method for group key generation and exchange using trap hash collision hash in existing 'M2M communication environment' using hash collision, And a mechanism for confirming the authentication of the device and the gateway after the group key is generated. The proposed method has attack resistance such as spoofing attack, meson attack, and retransmission attack in the group communication section by using the specificity of the collision message and collision hash, and is a technique for proving safety against vulnerability of hash collision.
시간 기반 키 생성 방식을 이용한 안티 디버깅 기법 KCI 등재
보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.10 No.3 2013.06 pp.291-304
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
디버깅(debugging) 도구는 소프트웨어 개발 과정에서 논리 오류나 버그가 발생되었을 때 프로그램의 내부 상태와 동작 방식을 사용자에게 보여줌으로써 오류를 찾고 수정하는데 도움을 주는 도구이다. 반면에 지적재산권이 포함된 프로그램의 내부 알고리즘 추출이나 권한 상승과 같은 시스템 공격을 위한 취약성 분석에 디버깅 도구가 악용되고 있어 문제가 되고 있다. 이에 대한 대응 기술로 디버깅을 방지할 수 있는 안티 디버깅(anti-debugging) 기술이 적용되고 있으나 이를 우회하는 기술도 지속적으로 발전하고 있다. 본 논문에서는 기존의 우회 기법을 방지할 수 있는 시간 기반 키 생성 방식을 이용한 안티 디버깅 기법을 제안한다. 제안하는 기법은 기존 디버깅을 탐지 후 조건문 방식으로 응답 하는 방식이 아닌 프로그램 실행 시간의 차분 값과 특정 코드 영역의 해시 값으로 키를 생성하고 이를 키 값으로 다음 실행될 코드 영역을 암호화함으로써 우회 공격을 어렵게 하는 방법이다. 또한 단순히 프로그램의 특정 영역의 실행 시간으로 키 값을 유도하는 방식이 아닌 시프트(shift) 연산으로 실행 시간의 범위를 설정할 수 있게 하는 방식을 소개한다. 이는 시스템 하드웨어에 따라 발생할 수 있는 실행 시간의 오차 범위를 설정할 수 있게 함으로써 기법을 유연하게 적용할 수 있게 한다.
Debuggers are the tools which are helping the user to find out and correct the logic errors or bug by showing internal state and running mechanism while developing software. But it is also misused as vulnerability analysis for system attacks like extracting internal algorithm of program or privilege elevation. For this reason, anti-debugging techniques are applied to prevent debugging, but the techniques to bypass anti-debugging are keep developing. In this paper, we propose anti-debugging techniques by using time-based key generation method to prevent previous bypass techniques. The proposed techniques are difficult to bypass attack generate key by using hash value instead of not using previous method which is detecting previous debugging and respond in conditional method. We also introduce scheme that setting scope of the execution time by shift operation instead of simply induce the value of the key by specific area of the program’s execution time. It can set a range of run-time errors can be occurred by system hardware so scheme can be applied flexibly in the various environments.
Biometrics-based Key Generation Research: Accomplishments and Challenges
[Kisti 연계] 한국스마트미디어학회 스마트미디어저널 Vol.6 No.2 2017 pp.15-25
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
The security and privacy issues derived from unsecurely storing biometrics templates in biometric authentication/ recognition systems have opened a new research area about how to secure the stored biometric templates. Biometrics-based key generation is the newest approach that provides not only a mechanism to protect stored biometric templates in authentication/ recognition systems, but also a method to integrate biometric systems with cryptosystems. Therefore, this approach has attracted much attention from researchers worldwide. A review of current research state to summarize the achievements and remaining works is necessary for further works. In this study, we first outlined the requirements and the primary challenges when implementing these systems. We then summarize the proposed techniques and achievements in representative studies on biometrics-based key generation. From that, we give a discussion about the accomplishments and remaining works with the corresponding challenges in order to provide a direction for further researches in this area.
A Survey on Face-based Cryptographic Key Generation
[Kisti 연계] 한국스마트미디어학회 스마트미디어저널 Vol.9 No.2 2020 pp.39-50
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
Derivation cryptographic keys from human biometrics opens a new promising research area when it can be used efficiently for not only verification or recognition tasks, but also symmetric-key based applications. Among existing biometric traits, face is considered as the most popular biometrics since facial features are informative and discriminative. In this paper, we present a comprehensive survey of Face-based key generation (FKGS). First, we summarize the trend of FKGS researches and sum up the methods which play important roles in the proposed key generation systems. Then we present the evaluation and the general performance analysis; from that, we give a discussion about the advantages and disadvantages of surveyed studies to clarify the fundamental requirements and the main challenges when implementing FKGS in practice. Finally, an outlook on future prospects is given.
[Kisti 연계] 한국전자통신연구원 ETRI journal Vol.45 No.2 2023 pp.346-357
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
Hardware security primitives, also known as physical unclonable functions (PUFs), perform innovative roles to extract the randomness unique to specific hardware. This paper proposes a novel hardware security primitive using a commercial off-the-shelf flash memory chip that is an intrinsic part of most commercial Internet of Things (IoT) devices. First, we define a hardware security source model to describe a hardware-based fixed random bit generator for use in security applications, such as cryptographic key generation. Then, we propose a hardware security primitive with flash memory by exploiting the variability of tunneling electrons in the floating gate. In accordance with the requirements for robustness against the environment, timing variations, and random errors, we developed an adaptive extraction algorithm for the flash PUF. Experimental results show that the proposed flash PUF successfully generates a fixed random response, where the uniqueness is 49.1%, steadiness is 3.8%, uniformity is 50.2%, and min-entropy per bit is 0.87. Thus, our approach can be applied to security applications with reliability and satisfy high-entropy requirements, such as cryptographic key generation for IoT devices.
[NRF 연계] 한국인터넷전자상거래학회 인터넷전자상거래연구 Vol.24 No.5 2024.10 pp.77-88
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
The purpose of this study is to propose methods to reduce the workload associated with large-scale data processing and the generation of linkage key information for estimating the de facto population, as well as to improve the accuracy of the underlying data. The de facto population includes the resident registration population, transient population, and foreign population. It is measured monthly through the combination of pseudonymized data. The study proposes a composition of linkage keys that excludes time-series keys for efficient data combination and suggests alternative methods to address the issue of duplicate linkage keys. It is expected that this research will serve as essential foundational data for the formulation and implementation of future policies related to pseudonymized data combination.
APPLICATION OF $(\upsilon,\kappa,\lambda)$-CONFIGURATION TO GENERATION OF A CONFERENCE KEY
[Kisti 연계] 한국전산응용수학회 Journal of applied mathematics & informatics Vol.8 No.2 2001 pp.531-537
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
In order for all participants at video conference to communicate mutually, the conference key should be necessary. In this paper, we present the communication protocol that generates a conference key efficiently based on $(\upsilon,\kappa,\lambda)$-configuration, one class of block designs, which minimizes message transmission overhead needed for this key. Especially, in the case of ${\lambda}=1$, the protocol requires only $O(\sqrt[v]{v})$ messages, where v is the number of participants.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.