Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 312
No
1

Key Management Server Design in Multiuser Environment for Critical File Protection

Sung-Hwa Han

[Kisti 연계] 한국정보통신학회 Journal of information and communication convergence engineering Vol.22 No.2 2024 pp.121-126

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

In enterprise environments, file owners are often required to share critical files with other users, with encryption-based file delivery systems used to maintain confidentiality. However, important information might be leaked if the cryptokey used for encryption is exposed. To recover confidentiality, the file owner must then re-encrypt and redistribute the file along with its new encryption key, which requires considerable resources. To address this, we propose a key management server that minimizes the distribution of encryption keys when critical files are compromised, with unique encryption keys assigned for each registered user to access critical files. While providing the targeted functions, the server employs a level of system resources comparable to that of legacy digital rights management. Thus, when implemented in an enterprise environment, the proposed server minimizes cryptokey redistribution while maintaining accessibility to critical files in the event of an information breach.

2

Key management for blockchain technology

Om Pal, Bashir Alam, Vinay Thakur, Surendra Singh

[NRF 연계] 한국통신학회 ICT Express Vol.7 No.1 2021.03 pp.76-80

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Public Key Infrastructure (PKI) is used in Blockchain Technology to authenticate the entities and to ensure the integrity of the blockchain. Proper Protection of Bitcoin wallet is required for private keys, seeds and keys stored in external hardware in Blockchain infrastructure. In this paper, overview of Blockchain, analysis of existing PKI for Blockchain and key management for Blockchain wallet are discussed. To achieve the confidentiality of sensitive records over the Blockchain network, a Group Key Management scheme for secure group communication is also proposed.

3

Secure Key Management Protocol in the Wireless Sensor Network

Jeong, Yoon-Su, Lee, Sang-Ho

[Kisti 연계] 한국정보처리학회 Journal of information processing systems Vol.2 No.1 2006 pp.48-51

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

To achieve security in wireless sensor networks (WSN), it is important to be able to encrypt messages sent among sensor nodes. We propose a new cryptographic key management protocol, which is based on the clustering scheme but does not depend on the probabilistic key. The protocol can increase the efficiency to manage keys since, before distributing the keys by bootstrap, the use of public keys shared among nodes can eliminate the processes to send or to receive keys among the sensors. Also, to find any compromised nodes safely on the network, it solves safety problems by applying the functions of a lightweight attack-detection mechanism.

4

Implementation of an RFID Key Management System for DASH7

Vegendla, Aparna, Seo, Hwajeong, Lee, Donggeon, Kim, Howon

[Kisti 연계] 한국정보통신학회 Journal of information and communication convergence engineering Vol.12 No.1 2014 pp.19-25

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

The wireless sensor networking standard DASH7 operates in low-power communication with a better transmission quality in active RFID networks. The DASH7 security standard supports public key cryptography. At present, the DASH7 standard uses the message authentication code in the network layer for authentication and integrity. However, its security standard is still in an incubation stage with respect to the implementation of a crypto exchange over a DASH7 network. Effective key management is an important factor for privacy and security. If organizations are not careful about where and how keys are stored, they leave the encrypted data vulnerable to theft. In this regard, we present a key management system designed for efficient key management through public key infrastructure authentication as well as a non-repudiation feature for the DASH7 standard. We analyze the performance of the proposed system on a basis of various performance criteria such as latency and throughput.

5

An Efficient Video Retrieval Algorithm Using Key Frame Matching for Video Content Management

Kim, Sang Hyun

[Kisti 연계] 한국콘텐츠학회 International journal of contents Vol.12 No.1 2016 pp.1-5

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

To manipulate large video contents, effective video indexing and retrieval are required. A large number of video indexing and retrieval algorithms have been presented for frame-wise user query or video content query whereas a relatively few video sequence matching algorithms have been proposed for video sequence query. In this paper, we propose an efficient algorithm that extracts key frames using color histograms and matches the video sequences using edge features. To effectively match video sequences with a low computational load, we make use of the key frames extracted by the cumulative measure and the distance between key frames, and compare two sets of key frames using the modified Hausdorff distance. Experimental results with real sequence show that the proposed video sequence matching algorithm using edge features yields the higher accuracy and performance than conventional methods such as histogram difference, Euclidean metric, Battachaya distance, and directed divergence methods.

6

Key trends, challenges, and opportunities in scientific journal management between 2013 and 2023: a systematic review

Muhamad Nur Azmi Wahyudi, Ida Nugroho Saputro, Alhaura Nabighatul Ula, Cahyo Widodo

[NRF 연계] 한국과학학술지편집인협의회 Science Editing Vol.12 No.1 2025.02 pp.12-19

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Purpose: Scientific journals play a pivotal role in disseminating research findings, validating methodologies, and promoting academic discourse. In the past decade, technological advancements, global collaborations, and evolving editorial policies have driven significant transformations in journal management. This systematic literature review investigated the key trends, challenges, and opportunities in scientific journal management between 2013 and 2023. Methods: Utilizing a PRISMA-guided methodology, 26 peer-reviewed articles from the Scopus database were analyzed. Results: The findings reveal five primary themes: (1) journal management systems and technological improvements; (2) editorial processes, policies, and best practices; (3) metrics, evaluation, and scientometrics; (4) case studies and implementation; and (5) ethical, social, and equity considerations. Technological innovations, such as artificial intelligence?driven tools, improved plagiarism detection systems, and semantic workflows, have improved operational efficiency. Editorial best practices and evaluation metrics have evolved to promote transparency, accountability, and research integrity. However, persistent challenges include financial sustainability, disparities in gender representation, and maintaining consistency in editorial quality. Conclusion: This review underscores the importance of adaptive strategies and innovative frameworks in ensuring the long-term sustainability, accessibility, and impact of scholarly journals in a rapidly evolving academic publishing landscape.

7

3,000원

Secure broadcasting is requirement for payment of TV systems, government or company. Hierarchical key management for access control provides efficient key management in those environment. Also, time-bound hierarchical key management technique generates different keys in each time period. In 2004, Tzeng proposed a time-bound cryptgraphic key assignment scheme for access control in a hierarchy and in 2008, Bertino et al proposed an efficient time-bound hierarchical key management scheme for secure broadcasting. Tzeng’s scheme and Bertino et al’s scheme are organized in different environment and primitive. In this paper, we analysis above two time-bound hierarchical key management scheme.

8

A New Group Key Management Protocol for WSN KCI 등재후보

Tegshbayar Gerelbayar, Sang Min Lee, Jong Sou Park

한국융합보안학회 융합보안논문지 제8권 제1호 2008.03 pp.143-152

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

Sensor networks have a wide spectrum of military and civil applications, particularly with respect to security and secure keys for encryption and This thesis presents a new centralized approach which focuses on the group key distribution with revocation capability for Wireless Sensor Networks. We propose a new personal key share distribution. When utilized, this approach proves to be secure against k-number of illegitimate colluding nodes. In contrast to related approaches, our scheme can overcome the shortcomings while keeping the small overhead requirements per node. It will be shown that our scheme is unconditionally secure and achieves both forward secrecy and backward secrecy. The analysis is demonstrated in terms of communication and storage heads.

9

4,000원

위기 상황을 잘 관리하여 국민⋅영토⋅주권⋅핵심기반 등의 안전을 확보하거나 피해를 최소화하는 것이 위기관리의 목표이다. 이 목표를 달성하는 방법은 통합관리시스템⋅위기운영센터 구축, 거버 넌스, 통합된 지휘⋅통제 등이 있다. 이러한 방법론을 구체적이고 직접적으로 실천하는 것이 상황관 리라고 할 수 있다. 상황관리는 긴급성, 중요성, 국민권익 침해 가능성 등을 속성으로 하기 때문에 구체적인 법률유보를 요구한다. 그러나 상황관리 업무를 수행하고 있는 각 기관의 소관 법률에는 상황관리에 관한 법률 조항이 없거나 불충분하다. 법률을 통해서 상황관리 업무 종사자들을 보호하 고 업무 효율성을 높일 수 있으며 국민권익을 더욱 확실히 보장할 수 있다는 측면에서 상황관리에 관한 법률을 보완할 필요가 있다. 본 연구는 상황관리 기능이 더 효과적이고 효율적으로 작동하는 데 필요한 법체계를 강화하는 방안을 제시하고 있다.

The goal of emergency management is not only to secure the safety of the people, territory, sovereignty, and core infrastructure, but also to minimize damage by managing the emergency situations well. Methods to achieve this goal include the establishment of an integrated management system and emergency operation center, governance, and integrated command & control. The concrete and direct practice of these Methods can be done by managing the situation. Situation management requires specific legal reservations because it has urgency, importance, and the possibility of infringement of civil rights and interests. However, there are no or insufficient provisions on situation management in the laws enforced by each agency performing the situation management task. The law on situation management needs to be supplemented in the sense that it can protect workers at situation management, increase work efficiency, and more reliably guarantee people’s rights and interests. This review suggests a way to strengthen the legal system necessary for the situation management function to operate more efficiently.

10

5,700원

11

6,000원

본 논문은 경제구조와 기업문화가 다른 한국과 미국기업들의 사내 급진적 경영 혁신시스템의 진화과정을 비교 분석하는데 초점을 맞춘 연구이다. 사내기업가정신은 기업의 전 구성원이 갖춰야할 자세로서 혁신 구축의 큰 역할을 한다. 구체적으로는, 사내기업가정신의 핵심요인이 어떻게 경영전략, 운영프로세스, 고객, 종업원과 같은 기업경영시스템의 요인들에 영향을 미치며, 이러한 경영시스템은 어떻게 기업의 급진적 혁신 시스템에 영향을 주는지에 살펴보고자 하였다. 본 연구를 위하여 4개의 한국의 대기업 및 중소기업의 경영자, 중간관리자, 그리고 종업원을 대상으로 설문조사와 심층인터뷰 등을 통해 분석하였다. 4개의 한국 기업의 분석결과 기업의 경영시스템이 혁신의 유형별로 영향을 미치며, 사내기업가정신의 핵심 요인이 기업 경영 시스템에 영향을 미치는 것으로 나타났다.

This research focuses on the evolution of a corporate radical innovation management system in the context of two different economic systems and business cultures in Korea and the U.S. In particular, to what extent do key elements of a corporate business system (strategy, process, customer, and employee) influence the development of a radical innovation management system; furthermore, to what extent do characteristics of corporate entrepreneurs (proactiveness, risk-taking, autonomy, and aggressiveness) influence the engagement of these four key elements of a corporate business system? Our in-depth analysis of four Korean firms reveals that different elements of a corporate business system influence the development of different types of innovation and also shows that different corporate entrepreneurship characteristics are related to each element of corporate business system

13

안전한 블록체인 기반 서비스를 위한 개인키 관리 가이드라인

노시완, 이경현

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.32 No.5 2022 pp.899-914

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

블록체인 기반 탈중앙 서비스는 참여자들의 합의에 기반하여 시스템을 운영함으로써 중앙화된 서버 없이도 신뢰 할 수 있는 서비스를 사용자에게 제공할 수 있다. 참여자들은 디지털서명 메커니즘을 사용하여 블록체인과 상호작용 할 수 있지만 개인키 관리와 관련된 이슈는 여전히 해결되지 않는 문제로 남아있다. NIST SP800-57 암호키 관리 권고안 등에서는 사용자의 개인키 관리에 관한 내용을 기술하고 있지만, 이는 탈중앙 서비스 환경을 고려하지 않았기에 블록체인 환경에 적용하기에는 적절하지 않다. 본 논문에서는 개인키 관리와 관련된 지갑 애플리케이션의 기능을 정의하고 NIST SP800-57을 반영한 블록체인 개인키 관리 방안과 이를 만족하기 위한 관련 기술을 제시한다. 마지막으로 논문에서 정의한 내용을 바탕으로 퍼블릭 블록체인에서 일반 사용자를 대상으로 하는 개인키 관리 가이드라인을 제안한다.

A blockchain-based decentralized service can offer reliable services without the centralized server by operating the system based on the consensus among byzantine participants. Participants can interact with the blockchain network through a digital signature mechanism but the private key management issue remains unresolved. NIST SP800-57 provides a key-management guidance but this guidance is not appropriate for blockchain-based services because it does not consider a decentralized environment. In this paper, we define the core functions of the blockchain wallet application for private key management and present security protections according to NIST SP800-57, as well as related techniques to satisfy them. Finally, we propose the private key management guideline for secure blockchain-based decentralized services.

14

발사체 텔레메트리를 위한 양자내성 기반 키 관리 및 안전 배포 구조

윤성진, 김진호, 배휘종, 김복기, 이남식

[Kisti 연계] 한국항행학회 한국항행학회논문지 Vol.29 No.6 2025 pp.762-769

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 연구는 발사체 텔레메트리 보안 구조에서 대칭키 분배 과정의 취약점을 해결하기 위해, 양자내성 KEM과 해시 기반 AEAD 계층을 통합한 키 관리 체계를 제안한다. 기존 연구[1]에서 제시된 QRNG 기반 이중 키 구조는 비행 중 nonce-key 재사용 문제[2]를 효과적으로 완화하였지만, rotation key 복호에 필요한 main key를 지상국에 안전하게 전달하는 문제는 여전히 남아 있었다. 본 논문에서는 이 상위 계층의 키 분배 취약점을 해결하기 위해, 양자 컴퓨터의 계산능력으로도 해킹이 어려운 양자내성 CRYSTALS-Kyber KEM 세션 키 공유 계층을 기반으로, 데이터 암호화용 SHAKE256과 송신자 인증용 KMAC256을 병용한 AEAD 계층을 추가하여 무결성을 확보하는 2단 구조의 키 데이터 암호화 방안을 설계하였다. 또한, 설계 내용을 검증하기 위해 실제로 텔레메트리에 적용되어 사용성이 검증된 MAX10 FPGA를 사용하였으며, 텔레메트리 기능을 위한 유저로직을 그대로 유지하고 보안 계층만 추가하는 형태로 구현하여 소모 리소스를 측정함으로써, 제안 설계의 실용성을 나타내었다.

This study proposes a key management framework that integrates a post-quantum key encapsulation mechanism (KEM) with a hash-based AEAD layer to address vulnerabilities in symmetric-key distribution for launch-vehicle telemetry systems. While prior work [1] introduced a dual-key structure based on a quantum random number generator (QRNG) that mitigated nonce-key reuse during flight [2], it left unresolved the secure delivery of the main key to the ground station. To overcome this, we designed a two-layer encryption architecture in which the session key is exchanged using the quantum-resistant CRYSTALS-Kyber KEM, and data integrity and authentication are ensured through a SHAKE256-based encryption and KMAC256-based authentication AEAD layer. The proposed system was implemented on a MAX10 FPGA-already proven in actual telemetry applications-by adding only the security layer without modifying existing telemetry logic, thereby validating the design's practicality through measured resource utilization.

15

IoT 환경의 MIPUF 기반 그룹키 관리 시스템 개선

탁금지, 정익래, 변진욱

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.29 No.6 2019 pp.1243-1257

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

IoT 환경이 등장함에 따라 여러 스마트기기를 통해 소비자에게 편리함과 다양한 서비스를 제공하고 있다. 하지만 개인 정보 유출과 같은 보안 위협 사례가 보고되면서 IoT 환경상의 보안 문제의 중요성이 대두되고 있고 특히 키 관리의 안전성 문제에 대해서 거론되면서 PUF를 활용한 방안이 대응 방안으로 거론되고 있다. 키 관리 문제와 관련하여 그룹 키 관리 시스템의 안전성 문제에 대해서 MIPUF를 이용한 키 관리 프로토콜이 제안된 바가 있다. 해당 시스템은 경량 IoT 환경에 적용할 수 있고 PUF의 안전성으로 인해 전체 시스템의 안전성을 보장하지만, 일부 과정에서 안전성 및 연산의 효율성 측면에서 한계점을 보인다. 본 논문은 구성원에 대한 인증 추가, 데이터 간의 독립성 보장, 불필요한 연산을 축약, 그리고 데이터베이스 검색의 효율 증대함으로써 기존 프로토콜을 개선한다. 특정 공격에 대해 안전성 분석을 진행하고 연산량 비교를 통한 효율성 분석 결과를 제시한다. 이를 통해 본 논문은 데이터에 대한 신뢰도를 향상하고 본 논문이 제안한 방안이 기존 프로토콜보다 더 경량화 시켰음을 보인다.

With the emergence of the IoT environment, various smart devices provide consumers with the convenience and various services. However, as security threats such as invasion of privacy have been reported, the importance of security issues in the IoT environment has emerged, and in particular, the security problem of key management has been discussed, and the PUF has been discussed as a countermeasure. In relation to the key management problem, a protocol using MIPUF has been proposed for the security problem of the group key management system. The system can be applied to lightweight IoT environments and the safety of the PUF ensures the safety of the entire system. However, in some processes, it shows vulnerabilities in terms of safety and efficiency of operation. This paper improves the existing protocol by adding authentication for members, ensuring data independence, reducing unnecessary operations, and increasing the efficiency of database searches. Safety analysis is performed for a specific attack and efficiency analysis results are presented by comparing the computational quantities. Through this, this paper shows that the reliability of data can be improved and our proposed method is lighter than existing protocol.

16

Kano 모델 기반 건설프로젝트 핵심 리스크관리 요인 도출

조진호, 김병수

[Kisti 연계] 대한토목학회 대한토목학회논문집 Vol.42 No.2 2022 pp.239-248

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 건설환경의 변화에 따른 건설프로젝트에서 리스크는 현저하게 증가하고 있다. 리스크를 기회로 인식하는 적극적인 리스크관리가 요구된다. 본 연구의 목적은 Kano 모델, Timko CSC (Customer Satisfaction Coefficient), ASC (Average Satisfaction Coefficient)를 활용한 비교 분석을 통해 중요도 결정 방법의 리스크관리 모델을 제안하는 것이다. 선행연구를 바탕으로 델파이기법을 활용하여 실무자 면담을 통해 Kano 모델을 수정한 설문지를 통해 리스크관리 요인 결정의 타당성을 검토한다. 이를 통해 국내 건설프로젝트 실무자가 인식하는 핵심 리스크관리 요인을 선정하여 적합한 리스크관리 모델을 제시한다. 연구 결과, 건설프로젝트 리스크관리 검증을 위해 개발된 Kano 모델은 실무자의 리스크관리를 검증하는데 유효한 것으로 평가되었다. 본 연구에서 제시한 Kano 모델이 건설프로젝트 리스크관리의 중요도를 검증하는 데에 적극적으로 활용되기를 기대한다.

Risks in construction projects are increasing remarkably due to recent changes in the construction environment. Active risk management is required to recognize risks as opportunities. The purpose of this study is to propose a risk management model of the importance determination method through comparative analysis using Kano model, Timko CSC (Customer Satisfaction Coefficient), and ASC (Average Satisfaction Coefficient). Based on previous studies, the validity of risk management factor determination is reviewed through a questionnaire modified Kano model through interviews with working-level workers using the Delphi technique. Through this, a suitable risk management model is presented by selecting key risk management factors recognized by domestic construction project practitioners. As a result of the study, the Kano model developed to verify risk management of construction projects was evaluated to be effective in verifying the risk management of practitioners. It is expected that the Kano model presented in this study will be actively used to verify the importance of risk management for construction projects.

17

USB 메모리의 컨테이너ID를 이용한 PKI 기반의 개인키 파일의 안전한 관리 방안

김선주, 조인준

[Kisti 연계] 한국콘텐츠학회 한국콘텐츠학회논문지 Vol.15 No.10 2015 pp.607-615

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

대부분의 인터넷 사용자 및 스마트폰 보유자는 공인인증서를 발급 받았고, 공인인증서를 통해 계좌 이체, 주식거래, 쇼핑 등 다양한 업무에 활용하고 있다. 대부분은 PC나 USB 메모리와 같은 외부 저장매체에 공인인증서와 개인키를 저장한다. 특히, 공인인증기관에서는 공인인증서와 개인키 저장매체로 하드디스크 보다는 보안토큰, 휴대폰, USB 메모리 등의 저장매체를 권장하고 있다. 그러나 USB메모리는 PC에 연결되는 순간 쉽게 이동/복사될 수 있고, 악성코드나 파밍 사이트 연결을 통해 쉽게 해커에게 인증서 파일과 개인키 파일이 노출될 수 있다. 더욱 큰 문제는 해커에게 복사된 인증서 파일과 개인키 파일은 아무런 제약 없이 사용자의 패스워드만 알면 정당한 사용자처럼 사용할 수 있다는 점이다. 이에 본 논문에서는 암호화된 개인키 파일의 패스워드와 USB 메모리의 HW 정보를 이용하여 USB 메모리에 개인키 파일의 안전한 관리 방안을 제안하였다. 이를 통해, 해커에 의해 암호화된 개인키 파일을 임의로 이동/복사되거나 또는 개인키 파일이 노출되더라도 암호화된 개인키를 안전하게 보호할 수 있다. 또한, 개인키 파일의 패스워드가 노출되더라도 USB 메모리의 컨테이너ID라는 추가 인증요소를 활용하여 개인키를 안전하게 보호할 수 있다. 따라서 활용도가 매우 높은 공인인증체계에서 제안시스템은 저장매체 보호 방안으로 보안성이 크게 향상될 것으로 기대한다.

Mosts user of internet and smart phone has certificate, and uses it when money transfer, stock trading, on-line shopping, etc. Mosts user stores certificate in a hard disk drive of PC, or the external storage medium. In particular, the certification agencies are encouraged for user to store certificate in external storage media such as USB memory rather than a hard disk drive. User think that the external storage medium is safe, but when it is connect to a PC, certificate may be copied easily, and can be exposed to hackers through malware or pharming site. Moreover, if a hacker knows the user's password, he can use user's certificate without restrictions. In this paper, we suggest secure management scheme of the private key file using a password of the encrypted private key file, and a USB Memory's hardware information. The private key file is protected safely even if the encrypted private key file is copied or exposed by a hacker. Also, if the password of the private key file is exposed, USB Memory's container ID, additional authentication factor keeps the private key file safe. Therefore, suggested scheme can improve the security of the external storage media for certificate.

18

스마트폰 고유정보를 이용한 안전한 개인키 관리 방안

김선주

[Kisti 연계] 한국콘텐츠학회 한국콘텐츠학회논문지 Vol.16 No.8 2016 pp.90-96

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

우리나라는 스마트폰 보급률이 83%로 성인인구 4,000만명 중 3,390만 명이 사용하고 있으며, 이러한 사용자 대부분이 공인인증서에 대한 안전성 문제가 지속적으로 제기됨에도 불구하고 공인인증서를 사용하고 있다. 이러한 안전성의 문제로 인해 SMS를 이용한 휴대폰 소유자 인증기술, 생체인증을 통한 본인 인증기술 등 다양한 인증기술들이 제안되고 있다. 그러나 아직까지도 공인인증서를 대체할 만한 안전하고 믿을 만한 인증체계가 제시되지 않고 있다. 또한 사용자가 제일 많은 공인인증서와 개인키에 대한 탈취 시도가 지속적으로 발생하고 있다. 이러한 이유로 인해 보안전문가들은 공인인증서와 개인키를 USB 플래시 드라이브, 보안토큰, 스마트폰에 저장하도록 권고한다. 하지만 보안전문가가 추천하는 외부 저장매체 중 스마트폰은 앱을 통해 악성코드가 쉽게 전파되고, 악성코드에 의한 인증서나 개인키 파일을 외부로 유출이 가능하다. 해커가 유출한 인증서와 개인키 파일과 함께 개인키 암호용 패스워드만 알아내면 언제든지 정당한 사용자로 위장할 수 있다. 이에 본 논문에서는 스마트폰의 고유정보와 사용자 패스워드를 조합하여 스마트폰에 저장된 개인키 파일의 안전한 관리 방안을 제안한다. 제안 방안을 활용하게 되면 스마트폰에 저장된 개인키와 인증서 파일이 공격자에게 탈취되더라도 스마트폰의 고유 정보를 획득할 수 없으므로 암호화된 개인키의 재사용이 불가능하다. 따라서 제안 방안을 공인인증 체계에 활용한다면 스마트폰 사용자에게 현재보다 훨씬 향상된 보안 서비스를 제공할 수 있을 것으로 예상한다.

The 3390 million people, around 83% of the adult population in Korea use smartphone. Although the safety problem of the certificate has been occurred continuously, most of these users use the certificate. These safety issues as a solution to 'The owner of a mobile phone using SMS authentication technology', 'Biometric authentication', etc are being proposed. but, a secure and reliable authentication scheme has not been proposed for replace the certificate yet. and there are many attacks to steal the certificate and private key. For these reasons, security experts recommend to store the certificate and private key on usb flash drive, security tokens, smartphone. but smartphones are easily infected malware, an attacker can steal certificate and private key by malicious code. If an attacker snatchs the certificate, the private key file, and the password for the private key password, he can always act as valid user. In this paper, we proposed a safe way to keep the private key on smartphone using smartphone's unique information and user password. If an attacker knows the user password, the certificate and the private key, he can not know the smart phone's unique information, so it is impossible to use the encrypted private key. Therefore smartphone user use IT service safely.

19

종합병원과 요양병원의 유행성 감염병 대응 간호인력관리 주요 요인의 상대적 중요도 분석

차정은, 윤은경

[Kisti 연계] 한국간호과학회 Journal of Korean academy of nursing Vol.55 No.2 2025 pp.236-248

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Purpose: This study aimed to identify the key factors in nursing workforce management for pandemic response in general hospitals and long-term care hospitals and to analyze the relative importance of these factors. Methods: A validity test was conducted with experts to select four categories and 30 key factors related to nursing workforce management for pandemic response. Surveys were collected from 25 nursing managers in general hospitals and 21 nursing managers in long-term care hospitals, and the relative importance of the key factors was analyzed using the analytic hierarchy process method. Results: Differences were found between the two groups in the relative importance of nursing workforce management for pandemic response. Specifically, the highest-ranking category was "workforce recruitment and redeployment" for general hospitals, but "workforce support and protection" for long-term care hospitals. The most important factor regarding nursing workforce management was the "nurse-to-patient ratio" for both general and long-term care hospitals. Conclusion: General and long-term care hospitals need to establish nursing workforce management strategies to effectively respond to pandemics with appropriate consideration of the relative importance and prioritization of key factors based on hospital characteristics.

20

다양한 분야에서의 키 관리 시스템 분석을 통한 적응형 키 관리 프로세스 연구 KCI 등재

오정훈, 김사연, 이올미, 장우현

한국융합보안학회 융합보안논문지 제24권 제5호 2024.12 pp.27-36

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

디지털 환경에서 데이터 보안의 중요성이 증가하면서, 데이터를 암호화 및 복호화하는 암호 키의 안전한 관리가 필수적인 요소가 되고 있다. 이에 암호 키의 생명주기 전체 과정을 관리하는 키 관리 시스템(Key Management System, KMS)에 대한 필요성도 점차 증가하고 있다. 본 연구는 다양한 산업 분야에서 적용할 수 있는 적응형 키 관리 프로세스를 설계하고자, 보안 성 및 효율성의 균형을 고려하여 키 관리 프로세스를 설계하였다. 이를 위해, 본 연구에서는 공공, 금융, 의료, 제조 분야에서 사용되는 키 관리 시스템을 분석하여, 각 시스템의 특성을 파악하여 보안성 및 효율성을 고려한 세 가지 방향으로 키 관리 프 로세스를 설계한다. 첫 번째 프로세스는 보안성을 중시하여 키의 생성, 분배, 저장 및 폐기 절차 등을 강화하였으며, 두 번째는 효율성을 중시하여 자동화된 시스템 운영을 강조하였다. 세 번째는 보안성과 효율성을 균형 있게 반영한 프로세스로, 각 산업 의 특성에 맞는 적용 가능성을 검토하였다. 끝으로, 설계한 키 관리 프로세스를 검증하기 위해 전문가 검토를 통해 적용가능 성을 평가하였다. 본 연구를 통해 다양한 산업에서 적용 가능한 키 관리 시스템 설계에 기여하며, 향후 보안 위협에 대응할 수 있는 체계적이고 신뢰성 있는 키 관리 프로세스 발전에 기여할 것으로 기대한다.

As the importance of data security grows in the digital environment, the secure management of cryptographic keys, wh ich are crucial for encrypting and decrypting data, has become essential. Consequently, the need for a Key Management S ystem (KMS) that manages the entire lifecycle of cryptographic keys is increasing. This study aims to design an adaptive key management process applicable across various industries, considering a balance between security and efficiency. To ac hieve this, the study analyzes KMSs used in the public, financial, medical, and manufacturing sectors, identifying the char acteristics of each system and designing three key management processes based on both security and efficiency. The first process emphasizes security by reinforcing procedures for key generation, distribution, storage, and disposal. The second p rocess focuses on efficiency, highlighting automated system operations. The third process strikes a balance between securi ty and efficiency, with applicability assessed based on industry-specific requirements. Finally, expert reviews were conduct ed to evaluate the feasibility of the designed key management processes. This research contributes to the design of KMSs that can be applied across various industries and is expected to aid in the development of systematic and reliable key man agement processes that can effectively respond to evolving security threats.

 
1 2 3 4 5
페이지 저장