Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 85
No
1

본 논문에서는 데이터베이스, 리더 그리고 태그 간의 모든 통신채널이 안전하지 않은 비보호채널이라고 가정한 RFID 상호인증 모델에 기반한 새로운 프로토콜을 제안한다. 제안한 프로토콜은 태그의 전방향 안전성뿐만 아니라 기존의 많은 프로토콜들이 제공하지 않는 모바일 리더의 전방향 안전성까지도 제공함으로써 모바일 리더 소지자의 프라이버시를 보장한다. 또한, 제안한 프로토콜은 DB에서 태그의 ID와 리더의 ID를 검색하고 인증할 경우, n번의 해쉬연산을 수행하는 문제를 단 1번의 해쉬연산으로 개선한다.

In this paper, we proposed a new protocol based on the RFID mutual authentication model which assumed that all communication channels between the database, the reader and the tag are insecure communication channels. The proposed protocol supports the privacy of mobile reader holders as well as the tag forward secrecy by providing forward secrecy of mobile reader that the existing many protocols have not provided. Besides, the proposed protocol reduced the problem of n times of hash computational load to only one time of hash computation when DB searches and authenticates the tag's ID and the reader's ID.

2

4,000원

드론이나 로봇과 같이 조정자가 직접 탑승하여 운영하지 않는 무인 자율이동체는 국방이나 재난 대응 분야에서 감시, 정찰, 표적 추적, 재난 대응 등 다양한 임무를 사람을 대신하여 수행해 주는 주요 도구로 활용되고 있다. 최근 인공지능을 포함하여 진보된 ICT 기술이 적용됨에 따라 물류 배송, 스마트 농업, 상황 모니터링 등 다양한 산업 분야에서 필수적인 자산으로 자리 매김하고 있다. 그러나, 현재의 드론 운영 시스템은 다양한 보안 위협과 공격에 취약한 한계를 갖는다. 특히, 양자컴퓨터가 상 용화되어 사용되면 기존의 정적 암호 체계는 더욱 취약할 것으로 판단된다. 본 논문에서는 이러한 문제를 해결하기 위해, 드 론과 GCS 환경에 적합한 경량, 양자 내성, 안전성을 충족하는 3단계 보안 프로토콜을 적용한 안전한 보안 통신 채널을 설정 할 수 있는 방법을 구현하고 시험한다.

Unmanned autonomous systems such as drones and robots, operated without a human pilot onboard, have become essential tools in national defense and disaster-response missions, performing surveillance, reconnaissance, target tracking, and emergency operations in place of human operators. With the recent integration of advanced information and communication technologies (ICT), including artificial intelligence (AI), these systems are now widely utilized across various industrial domains such as logistics and delivery services, smart agriculture, and environmental or situational monitoring, making them indispensable assets in both military and civilian sectors. However, current drone operation systems remain vulnerable to numerous security threats and attacks. In particular, as quantum computers become commercially viable, conventional static cryptographic schemes are expected to become increasingly insecure. To address these challenges, this paper proposes and evaluates a scheme for establishing a secure communication channel between drones and Ground Control Stations (GCS) by applying a lightweight, quantum-resistant, and security-enhanced three-phase protocol specifically designed for UAV environments.

3

4,000원

메일 시스템은 기업 간 거래와 같은 중요한 내용을 전달하는 목적에 사용된다. 그러나 메일 시스템에서 메 일 주소를 변경하여 보내는 공격은 어렵지 않다. 기업 간 거래에서 메일 서버를 인증하는 것과 메일 서버에 등록된 사용자를 인증하는 것은 매우 중요하다. 본 논문에서 제안하는 시스템은 기업 환경에서 송신자와 수신자의 인증과 권한을 확인하는 프락시를 두어 기업 간 거래 사기를 방지할 수 있는 메일 프락시를 제안하고자 한다. 제안된 안전 한 메일 플랫폼은 프락시를 기반으로 메일서버들의 도메인을 구성하고, 도메인에 속한 메일 서버들을 확인하고 사용 자를 상호인증(mutual authentication)하여, 메일 송신자와 수신자가 정당한 사용자일 경우 기밀성(confidentiality)을 위 한 비밀키를 교환하고, 암호화하여 메일을 송신한다. 본 논문에서는 상호인증 프로토콜과 키 교환 방법을 제안하고 Casper 검증기법을 이용하여 안정성을 검증하였다. 향후 연구로는 메일의 안전성을 위한 도메인구성 전반적인 플랫 폼에 대하여 연구를 할 것이다.

The purpose of Email system is used to transmit important information between companies in today. But Email system has vulnerabilities such that changing email address of sender by attacker. So it is important to authenticate mail server and user using mail server. This paper proposed mail proxy located between mail servers that evaluate authority and authenticate sender and receiver. The proposed email platform has some functions to compose trusted domain and to authenticate mail servers in the domain. Also, if sender and recipient are valid users in mail system, each exchanges a key for confidentiality and the sender sends an e-mail encrypted with exchanged key to recipient. In this paper, we propose a key exchange scheme in proposed platform and verify this protocol using Casper which is the formal analysis tool. In the future research, we will study the overall platform of the domain configuration for the security of mail.

4

4,000원

바이오메트릭 정보를 이용한 인증방식은 사용자의 신체정보를 이용하여 신원을 확인 하고 시스템의 접근을 허가한 다. 요즘 들어, 패스워드나 보안토큰을 단독으로 이용하는 방식보다는 하나이상의 고유한 신체적, 행동적 형질에 기반 하여 개인의 생체 정보인 지문, 홍채 얼굴, 정맥 등을 활용하는 방식이 점차 증가하고 있는 추세이다. 2013년 Althobati 등이 WSN(Wireless Sensor Networks) 환경에 적합한 바이오메트릭 정보를 이용한 사용한 사용자 인증 스킴을 제안하 였다. 그러나 그들이 제안 프로토콜은 데이터 무결성에 대한 위협과 바이패싱 게이트웨이 공격에 취약하여 상호인증을 달성할 수 없었다. 본 논문은 이전에 제안된 논문의 취약점을 개선하여 WSN 환경에 적합한 안전한 프로토콜을 제안하였다.

Over recent years there has been considerable growth in interest in the use of biometric systems for personal authentication. Biometrics is a field of technology which has been and is being used in the identification of individuals based on some physical attribute. By using biometrics, authentication is directly linked to the person, rather than their token or password. Biometric authentication is a type of system that relies on the unique biological characteristics of individuals to verify identity for secure access to electronic systems. In 2013, Althobati et al. proposed an efficient remote user authentication protocol using biometric information. However, we uncovered Althobati et al.’s protocol does not guarantee its main security goal of mutual authentication. We showed this by mounting threat of data integrity and bypassing the gateway node attack on Althobati et al.’s protocol. In this paper, we propose an improved scheme to overcome these security weaknesses by storing secret data in device. In addition, our proposed scheme should provide not only security, but also efficiency since sensors in WSN(Wireless Sensor Networks) operate with resource constraints such as limited power, computation, and storage space.

5

M2M 환경의 디바이스 키 보호를 위한 암호 알고리즘 응용 기법 KCI 등재

최도현, 박중오

한국디지털정책학회 디지털융복합연구 제13권 제10호 2015.10 pp.343-351

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

현재 M2M 환경은 다양한 서비스가 기관 및 기업이나 일상생활로 확대되면서 관련 기술의 보안 취약성 발생 가능성이 이슈화되고 있다. 본 논문은 이러한 보안 취약성 문제를 해결하기 위해 M2M 환경의 디바이스 키 보호를 위한 암호 알고리즘 응용 기법을 제안한다. 제안 기법은 타원곡선 암호 기반으로 초기 키 교환과 서명 교환을 통해 보안 세션을 생성하였고, 화이트박스 암호는 보안 세션 키를 이용하여 화이트박스 테이블을 생성하는 암호화에 응용하였다. 암호 알고리즘 적용 결과, 타원곡선 암호는 통신 세션에 대한 경량 화된 상호인증, 세션 키 보호를 제공하고, 화이트 박스 암호는 기존 암호 알고리즘과는 다른 방식으로 암호화에 사용되는 세션 키 보호를 보장하였다. 제안하는 프로토콜은 데이터변조 및 노출, 중간자 공격, 데이터 위조 및 변조 공격에 대해 안전한 장점이 있다.

With the diverse services of the current M2M environment being expanded to the organizations, the corporations, and the daily lives, the possibility of the occurrence of the vulnerabilities of the security of the related technologies have become an issue. In order to solve such a problem of the vulnerability of the security, this thesis proposes the technique for applying the cryptography algorithm for the protection of the device key of the M2M environment. The proposed technique was based on the elliptic curve cryptography Through the key exchange and the signature exchange in the beginning, the security session was created. And the white box cipher was applied to the encryption that creates the white box table using the security session key. Application results cipher algorithm, Elliptic Curve Cryptography provides a lightweight mutual authentication, a session key for protecting the communication session and a conventional white-box cipher algorithm and was guaranteed the session key used to encrypt protected in different ways. The proposed protocol has secure advantages against Data modulation and exposure, MITM(Man-in-the-middle attack), Data forgery and Manipulation attack.

6

스마트폰 피싱에 안전한 메신저 인증 프로토콜 설계 및 구현

유병석, 윤성현

한국융합학회 한국융합학회논문지 제2권 제4호 2011.12 pp.9-14

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

피싱(Phishing)은 사용자 또는 기기를 가장하여 사용자 신분을 도용하는 공격이다. 최근 스마트폰 및 메 신저 프로그램 보급에 따라 그 피해가 급증하고 있다. 스마트폰은 음성 통화, SMS와 같은 고유 기능 외에 무선 네트워크 기반의 다양한 응용 프로그램을 구동할 수 있다. 일반적으로 카카오톡, 네이트온과 같은 메신저 프로그램 은 클라이언트-서버 구조로 구성되며 안전한 통신을 위해서 상호 인증이 필수적이다. 본 논문에서는 스마트폰 피싱 공격에 안전한 메신저 인증 프로토콜을 제안한다. 제안한 기법은 사용자들 간의 대화를 보호하기 위하여 메시지 암호화 기능과 인증 기능을 제공한다.

Phishing is an attack to theft an user’s identity by masquerading the user or the device. The number of phishing victims are sharply increased due to wide spread use of smart phones and messenger programs. Smart phones can operate various wi-fi based apps besides typical voice call and SMS functions. Generally, the messenger program such as Kakao Talk or Nate On is consisted of client and server functions. Thus, the authentication between the client and the server is essential to communicate securely. In this paper, we propose the messenger authentication protocol safe against smart phone phishing. To protect communications among clients, the proposed method provides message encryption and authentication functions.

7

4,000원

IoT 환경 확산으로 ECC 기반 RFID 인증 프로토콜의 보안성 요구가 증가하고 있다. 본 논문은 Gabsi 등이 분석한 Zheng 및 Naeem 프로토콜의 수식적 근거를 재구성하여 세 가지 구조적 취약점을 증명하였다. 기존의 Zheng 프로토콜은 서버 위장 및 위치 추적 공격에 채널 도청만으로 공격 가능함을 보였으며, Naeem 프로토콜은 비밀 식별자 역산 취약점에 노출됨을 본 연구에서 확인하였다. 개선된 프로토콜은 세션별 독립 난수 교차 결합과 인증 메시지 구조 개선을 통해 취약점을 해결하며 태그·서버 대칭적 계산 비용으로 효율성을 달성한다. 모의 실험 결과 비추적성 유지를 확인하였고, 본 연구의 개선된 설계는 AVISPA 형식 검증에서 안전성을 입증하였다.

As IoT expands, security demands for ECC-based RFID authentication protocols rise. This paper reconstructs the mathematical basis of Gabsi et al.'s analysis on Zheng and Naeem protocols to prove three structural vulnerabilities. Zheng's protocol was shown vulnerable to server impersonation and location tracking attacks via channel eavesdropping, while Naeem's protocol exposed secret identifier inversion vulnerabilities. The improved protocol resolves these via cross-combination of session-independent random numbers and authentication message structure improvements, achieving efficiency with symmetric computation costs for tags and servers. Simulation confirmed untraceability, and AVISPA formal verification proved safety.

8

자동차 보안시스템에서 장치간 상호인증 및 정형검증 KCI 등재

이상준, 배우식

한국디지털정책학회 디지털융복합연구 제13권 제4호 2015.04 pp.205-210

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

자동차산업의 발전과 함께 M2M(Machine-to-Machine)통신이 자동차 산업분야에서 많은 관심이 되고 있다. M2M은 기상, 환경, 물류, 국방, 농.축산 등에서 사용하기 시작하여 장비들이 자동으로 상황에 맞추어 통신을 하고 상황에 맞는 동작을 함으로써 운영해가는 시스템이다. 자동차에서도 차량내부 장치 간, 차대 차, 차와 교통시설물, 차와 주변의 환경 등에 적용되고 있다. 그러나 통신시스템의 특성상 전송구간에서 공격자의 공격에 대한 문제가 있으며 자동차의 운행, 제어계통 및 엔진제어 등에 공격자의 공격이 진행되면 안전에 심각한 문제가 발생하게 된다. 따라서 디바이스 간 보안통신에 대한 연구가 활발히 진행되고 있다. 본 논문에서는 차량의 디바이스간 안전한 통신을 위해 해시함수 및 수학적 복잡한 공식을 이용하여 프로토콜을 설계하였으며 프로토콜 정형검증 도구인 Casper/FDR을 이용하여 실험하였으며 제안한 프로토콜이 각종 공격에 안전하게 동작되며 실제 적용할 때 효과적임을 확인하였다.

The auto industry has significantly evolved to the extent that much attention is paid to M2M (Machine-to-Machine) communication. In M2M communication which was first used in meteorology, environment, logistics, national defense, agriculture and stockbreeding, devices automatically communicate and operate in accordance with varying situations. M2M system is applied to vehicles, specifically to device-to-device communication inside cars, vehicle-to-vehicle communication, communication between vehicles and traffic facilities and that between vehicles and surroundings. However, communication systems are characterized by potential intruders’ attacks in transmission sections, which may cause serious safety problems if vehicles’ operating system, control system and engine control parts are attacked. Thus, device-to-device secure communication has been actively researched. With a view to secure communication between vehicular devices, the present study drew on hash functions and complex mathematical formulae to design a protocol, which was then tested with Casper/FDR, a tool for formal verification of protocols. In brief, the proposed protocol proved to operate safely against a range of attacks and be effective in practical application.

9

M2M 환경에서 장치간 상호 인증 및 정형검증 KCI 등재

배우식

한국디지털정책학회 디지털융복합연구 제12권 제9호 2014.09 pp.219-223

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

최근 무선통신 시스템의 기술이 발전함으로 M2M(Machine-to-Machine)이 산업분야에서 관심이 되고 있다. 기기간 통신인 M2M은 재난, 안전, 건설, 보건복지, 기상, 환경, 물류, 문화, 국방, 의료, 농.축산 등 사람의 접근이 어 려운 공간 등에 설치되어 운용된다. 이는 사람을 대신해 장비들이 자동으로 상황에 맞추어 통신을 하고 어느 정도의 조치는 자동으로 취해지도록 함으로써 사람을 대신한 정보 관리 및 장비 운영을 할 수 있다. M2M이 디바이스간 통 신이 무선으로 이루어지는 경우 공격자의 공격에 노출되어 운영되는 보안적 문제로 정당한 장치인지 상호인증 등 적 절한 보안이 필요하다. 관련하여 최근 보안적으로 안전한 많은 프로토콜이 연구 되고 있으며 본 논문에서는 M2M 보안문제를 해결하기 위하여 SessionKey, HashFunction, 및 Nonce 를 적용하였으며 보안취약성을 보완한 안전한 프 로토콜을 제안한다. 제안프로토콜을 기존의 대부분의 연구처럼 수학적 정리증명으로 안전함을 주장하지 않고 Casper/ FDR을 이용하여 정형검증 하였으며 실험결과 제안프로토콜이 안전함이 확인되었다.

In line with the advanced wireless communication technology, M2M (Machine-to-Machine) communication has drawn attention in industry. M2M communication features are installed and operated in the fields where human accessibility is highly limited such as disaster, safety, construction, health and welfare, climate, environment, logistics, culture, defense, medical care, agriculture and stockbreeding. In M2M communication, machine replaces people for automatic communication and countermeasures as part of unmanned information management and machine operation. Wireless M2M inter-device communication is likely to be exposed to intruders’ attacks, causing security issues, which warrants proper security measures including cross-authentication of whether devices are legitimate. Therefore, research on multiple security protocols has been conducted. The present study applied SessionKey, HashFunction and Nonce to address security issues in M2M communication and proposed a safe protocol with reinforced security properties. Notably, unlike most previous studies arguing for the security of certain protocols based on mathematical theorem proving, the present study used the formal verification with Casper/FDR to prove the safety of the proposed protocol. In short, the proposed protocol was found to be safe and secure.

10

유한체를 사용한 RFID 상호인증 프로토콜 연구 KCI 등재후보

안효범, 이수연

한국융합보안학회 융합보안논문지 제7권 제3호 2007.09 pp.31-37

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

유비쿼터스 환경에서 개인 프라이버시를 보호하기위한 RFID 시스템 보안에 대한 많은 연구가 이루어지고 있다. RFID 시스템 보안 중 상호인증 방법으로 XOR 기반, 해쉬기반, 그리고 재암호화 기반의 프로토콜을 사용한다. 그러나 인증과 프라이버시를 보호하기위한 프로토콜은 좀 더 강화된 암호 시스템을 사용해야 한다. 공개키는 강력한 보안성을 제공하나, 비용이 많이 요구되어 RFID 시스템에서 사용하기에는 적합하지 않다. 따라서 본 논문에서는 상호 인증과 안전성을 위하여 유한체 을 이용한 인증 프로토콜을 제안하고 RFID 시스템에서의 여러 공격에 대하여 안전성 분석을 하였다.

There are many investigations about the security on RFID system to protect privacy. It is im-portant to mutual authentication of the security on RFID system. The protocol for mutual authentica-tion use light-weight such as XOR operation, hash function and re-encryption. However, the protocol for authentication and privacy is required more complicated cryptography system. In this paper, we propose a mutual authentication protocol using finite field for a authentication and are a safety analysis about various attacks.

11

사물인터넷 디바이스를 위한 AES 기반 상호인증 프로토콜 KCI 등재후보

오세진, 이승우

대한산업경영학회 산업융합연구(구 대한산업경영학회지) 제18권 제5호 2020.10 pp.23-29

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

사물인터넷(IoT)은 다양한 디바이스와 일상적인 물건을 인터넷 연결하여 인터넷을 확장한 것이며, 전자제품에는 인터넷 연결이 가능하고 다양한 형태의 하드웨어가 내장되어 있다. 이러한 사물인터넷은 디지털 생태계에 중대한 위험 을 초래한다. 이들 기기 중 상당수는 공격자의 공격을 막기 위한 보안 시스템이 내장되지 않은 상태로 설계되어 있기 때문이다. 본 논문에서는 사물인터넷 디바이스를 위한 대칭키 기반의 상호인증 프로토콜을 제안한다. 제안 프로토콜은 대칭키 암호 알고리즘을 사용하여 무선상에 전송되는 데이터를 안전하게 암호화한다. 아울러 암호화에 사용된 비밀키는 매 통신마다 디바이스가 생성하는 난수를 비밀키로 사용하여 고정적으로 사용되는 비밀키를 가변적으로 사용함으로써 보안성을 높였다. 제안 프로토콜은 무선상에서 데이터를 전송하기 전에 상호인증 과정을 거쳐 인증된 디바이스만 데이 터를 전송하기 때문에 공격자를 차단하고 정상적인 디바이스가 통신이 가능하도록 하였다. 마지막으로 제안된 프로토콜 을 공격유형별 시나리오를 통해 도청 공격, 위치추적, 재전송 공격, 스푸핑 공격, 서비스 거부 공격에 안전함을 확인하였다.

The Internet of things (IoT) is the extension of Internet connectivity into various devices and everyday objects. Embedded with electronics, Internet connectivity and other forms of hardware. The IoT poses significant risk to the entire digital ecosystem. This is because so many of these devices are designed without a built-in security system to keep them from being hijacked by hackers. This paper proposed a mutual authentication protocol for IoT Devices using symmetric-key algorithm. The proposed protocol use symmetric key cryptographic algorithm to securely encrypt data on radio channel. In addition, the secret key used for encryption is random number of devices that improves security by using variable secret keys. The proposed protocol blocked attacker and enabled legal deives to communicate because only authenticated devices transmit data by a mutual authentication protocol. Finally, our scheme is safe for attacks such as eavesdropping attack, location tracking, replay attack, spoofing attack and denial of service attack and we confirmed the safety by attack scenario.

12

4,000원

본 연구는 IoT 환경을 위해 제안된 상호 인증 프로토콜을 대상으로 그 아키텍처 설계와 암호학적 메커니즘을 비판적으로 평가하였다. 체계적인 취약점 평가를 통해서 본 연구에서는 정적 키 의존성, 상호 엔트로피 부재, 세션 추적 가능성 등 문제점을 식별하였다. 이러한 약점을 완화하기 위해, 본 연구는 에페메럴(단기) 키 생성, 신선도 검증, 신원 결합과 같은 강화 기법을 제안한다. 연구에서 시뮬레이션 결과, 제시된 개선 프로토콜은 최소의 계산 오버헤드로 강건한 보안 보장을 제공함을 확인하였다.

This study critically evaluated the architecture design and cryptographic mechanisms of mutual authentication protocols proposed for IoT environments. Through systematic vulnerability assessment, this study identified issues such as static key dependency, lack of mutual entropy, and session traceability. To mitigate these weaknesses, this study proposes enhancement techniques such as ephemeral (short-term) key generation, freshness verification, and identity binding. Simulation results confirm that the proposed improved protocol provides robust security guarantees with minimal computational overhead.

13

세션 키 동의를 제공하는 상호인증 패스워드 인증 스킴에 대한 취약점 공격 KCI 등재

서한나, 최윤성

한국융합보안학회 융합보안논문지 제22권 제4호 2022.10 pp.179-188

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

패스워드 인증 체계 (PAS)는 개방형 네트워크에서 안전한 통신을 보장하는데 사용되는 가장 일반적인 메커니즘이다. 인수 분해와 이산 로그 등의 수학적 기반의 암호 인증 체계가 제안되고 강력한 보안 기능을 제공하였으나, 암호를 구성하는데 필요 한 계산 및 메시지 전송 비용이 높다는 단점을 가지고 있었다. Fairuz et al.은 스마트 카드 체계를 이용한 세션 키 동의와 관 련하여 인수분해 및 이산 로그 문제를 기반으로 한 개선된 암호 인증 프로토콜을 제안했다. 하지만 본 논문에서는 취약성 분 석을 통하여, Fairuz et al.의 프로토콜이 Privileged Insider Attack, Lack of Perfect Forward Secrecy, Lack of User Anonymity, DoS Attack, Off-line Password Guessing Attack에 관한 보안 취약점을 가지고 있다는 것을 확인하였다.

Password authentication schemes (PAS) are the most common mechanisms used to ensure secure communication in open networks. Mathematical-based cryptographic authentication schemes such as factorization and discrete logarithms have been proposed and provided strong security features, but they have the disadvantage of high computational and message transmission costs required to construct passwords. Fairuz et al. therefore argued for an improved cryptographic authentication scheme based on two difficult fixed issues related to session key consent using the smart card scheme. However, in this paper, we have made clear through security analysis that Fairuz et al.'s protocol has security holes for Privileged Insider Attack, Lack of Perfect Forward Secrecy, Lack of User Anonymity, DoS Attack, Off-line Password Guessing Attack.

14

Mutual Authentication Scheme Between All AMI Entities in Smart Grid Environment SCOPUS

Young-Ae Jung

보안공학연구지원센터(IJMUE) International Journal of Multimedia and Ubiquitous Engineering Vol.11 No.3 2016.03 pp.411-424

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

These days, most of the important features of advanced metering infrastructure or AMI have already been developed and many AMI devices have been tested in the field as well. However, some security issues still remain unsolved. This paper presents an overview of AMI entities, smart meter, DCU, and MDMS, and then proposes mutual authentication scheme and data exchange schemes between them. More importantly, DCU has not been considered in any authentication scheme until this paper now. The proposed scheme can be adapted easily to the field-testing of the AMI components for enhancing their security.

15

Substitutive Mutual Authentication between Mobile Base Stations in Tactical Networks SCOPUS

Yu-Jin Son, Taeshik Shon, Young-Bae Ko

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.7 No.3 2013.05 pp.45-54

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

This paper proposes a cooperated mutual authentication scheme for mobile base stations (MBS) that construct a Wireless Mesh Network (WMN) in the Tactical Information Communication Networks (TICN). To enhance the fighting capabilities and survivability of soldiers in battlefields, it is crucial to secure the communication and commands between soldiers and commanders. To achieve this goal, a reliable mutual authentication method is required to approve between MBS and the soldiers in the network. We apply EAP-TLS (Extensible Authentication Protocol – Transport Layer Security) for mutual authentication between mobile base stations that each hold authentication servers [1]. Also, we propose a cooperative authentication scheme that can substitute the authentication process between MBS and ultimately reduce the authentication overhead. We evaluate the proposed scheme using the Qualnet 5.0 simulator to verify the performance of our proposed schemes in Tactical Networks.

16

Security Enhancements of a Password-Based Mutual Authentication Scheme Using Smart Cards SCOPUS

Younghwa An

보안공학연구지원센터(IJMUE) International Journal of Multimedia and Ubiquitous Engineering Vol.7 No2 2012.05 pp.53-62

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Password-based authentication scheme is one of the efficient authentication mechanics to protect resources from unauthorized access. Chang-Lee, in 2008, proposed a password-based mutual authentication scheme to overcome the security drawbacks of Wu-Chieu’s scheme. In this paper, we have shown that Chang-Lee’s scheme is vulnerable to various attacks known by literatures. Also we proposed an improved scheme to overcome the security drawbacks of Chang-Lee’s scheme. As a result of analysis, the proposed scheme not only withstands the various attacks, such as the user impersonation attack, the server masquerading, the man-in-the-middle attack, the off-line password guessing, the insider attack, but also provides mutual authentication between the user and the server. At the same time, the proposed scheme is more efficient than the related schemes in terms of the computational complexities.

17

Authentication with key agreement (AKA) protocols are implemented to provide identity authentication and session keys for communication entities. In order to reduce the heavy trust reliance on key generator center (KGC) in identity based AKA protocols, a certificateless based AKA (CLAKA) protocol for client-server environment without the third-party (i.e., KGC) is introduced in this paper. The proposed protocol is constructed based on elliptic curve cryptosystem (ECC) and multi-factor protections (such as password, biometrics, and smart card). Moreover, security proof based on BAN-logic is carried out and shows that our protocol can provide mutual authentication, user anonymity, dynamic identity and perfect forward security, and resist to user impersonation attack, server spoofing attack and privileged insider attack. Meanwhile, security and efficiency analysis shows that our proposed protocol outperforms the previous related ones.

18

최근 클라우드, 빅데이터, 인공지능 등 다양한 분야의 서버 플랫폼이 가상화 기술을 사용하고 있지만 지속적 으로 발생하는 구조적인 보안 취약성이 이슈화 되고 있다. 또한 대부분 가상화 보안 기술은 종류가 제한적이고 플랫폼 제공자에 의존적인 것으로 알려져 있다. 본 논문은 가상화 환경의 안전한 데이터 공유를 위한 다중 인스턴스간 상호인 증 기법에 대해 제안한다. 제안하는 기법은 다중 인스턴스 간에 독립적인 상호인증을 고려하여 보안 구조를 설계하고 키 체인 기법을 적용하여 데이터 공유에 보안 프로토콜의 안전성을 강화 시켰다. 성능분석 결과 기존 보안 구조와는 다른 방식의 안전한 가상화 인스턴스 세션을 생성하고, 상호인증 과정의 각 인스턴스에 대한 효율성이 우수 하다는 것 을 확인하였다.

Recent cloud, big data, there is a problem for the architectural security vulnerability to the server platforms of various fields such as artificial intelligence occurs consistently, but using the virtualization technology. In addition, most secure virtualization technology is known to be dependent on the type is limited and the platform provider. This paper presents a method for mutual authentication for secure data between multiple instances of a shared virtualized environment. The proposed method was designing a security architecture in consideration of the mutual authentication between multiple independent instances, and enhance the safety of a security protocol for sharing data by applying a key chain techniques. Performance analysis results and the existing security architecture demonstrated that protect each virtualized instances of the session and the other way, a compliance effectiveness for each instance of the mutual authentication process.

19

M2M 환경에서 안전한 데이터 공유를 위한 상호인증 및 키 교환 기법 KCI 등재

박중오, 김상근

국제인공지능학회(구 한국인터넷방송통신학회) 한국인터넷방송통신학회 논문지 제15권 제4호 2015.08 pp.33-41

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

기계간의 통신을 지칭하는 M2M(Machine to Machine) 환경은 최근 융합 서비스의 등장과 동시에, 수많은 장치의 활용으로 인한 전반적인 보안 요구사항이 증가하고 있으며, 관련 각 표준화단체는 이러한 장치간의 보안요구사 항을 충족하기 위해 각 영역별 보안기술에 대해 표준화를 진행 중에 있다. 본 논문에서는 다수의 M2M 장치들 간에 상호인증을 위한 키 관리 방법에 대해 제안한다. 본 논문에서 제안하는 방법은 M2M 디바이스와 서버 간에 상호인증 을 기반으로 서비스 영역이 다른 디바이스 간에 안전한 데이터 공유를 수행한다. 제안하는 기법은 현재 M2M 표준의 보안 요구사항에 따른 안전성을 충족하고, 기존 연구에서 제안된 인증기술보다 성능이 향상된 타원곡선 알고리즘 기반 프로토콜을 사용하여 효율성을 강화하였다.

With rapid rise of virtualization technology from diverse types of cloud computing service, security problems such as data safety and reliability are the issues at stake. Since damage in virtualization layer of cloud service can cause damage on all host (user) tasks, Hypervisor that provides an environment for multiple virtual operating systems can be a target of attackers. This paper propose a security structure for protecting Hypervisor from hacking and malware infection.

20

RFID 시스템을 위한 상호 인증 프로토콜

강부중, 임을규

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.5 No.5 2008.10 pp.371-380

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

RFID란 Radio Frequency Identification의 약자로 식품, 동물, 사물 등 다양한 개체의 정보를 관리, 사용자 인증, 요금 지불 등에 활용될 수 있는 차세대 기술이다. 하지만, RFID에서 사용되는 태그는 극히 제한적인 리소스만 사용할 수 있어, 기존의 보안 기법을 지원할 수 없다. 이런 이유로 현재의 RFID 태그는 잠재적으로 많은 위험성을 안고 있으며, 그 결과 태그 소지자의 개인 정보가 유출될 수 있으며 경제적인 손해를 입을 수도 있다. 이러한 보안상의 취약점을 해결하고자, 본 논문에서는 타임 스탬프를 이용하여 태그와 리더 그리고 후미 시스템 간의 상호 인증을 제공하는 프로토콜을 제안한 다. 이 프로토콜은 RFID 시스템의 객체인 태그와 리더 그리고 후미(back-end) 서버가 각자 서로를 인증하며, 인증된 객체들 사이에서만 데이터를 주고받음으로써 불필요한 정보 유출과 태그 복제 등을 방지할 수 있다.

Radio Frequency Identification(RFID) is a widely used technology to manage various items, to authenticate a person, or to make payments. A tag used for RFID has limited resources, and, as a result, general security mechanism cannot be directly applied. Attacks on RFID systems can cause revelation of privacy information or financial damages. This paper proposes a mutual authentication protocol for RFID systems. The proposed protocol can authenticate RFID tags and readers as well as back-end servers. The proposed mutual authentication protocol can prevent unnecessary revelation of data stored in tags, readers, and back-end servers.

 
1 2 3 4 5
페이지 저장