Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 63
No
1

모바일 환경에서 안전한 일회용 패스워드 인증 KCI 등재

김동률

한국디지털정책학회 디지털융복합연구 제11권 제12호 2013.12 pp.423-430

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

인터넷을 이용한 전자상거래 및 금융 분야가 활성화되어 사용자와 서비스 제공자들 간의 상호 인증이 매우 중요해졌다. ID와 패스워드 기반의 인증은 보안성이 낮기 때문에 일회용 패스워드 인증방식이 많이 사용되고 있다. 기존의 일회용 패스워드 인증방식인 S/Key 인증방식은 평문 전송 외에 여러 문제점이 있고, 김홍기 등의 방식은 세 션 키의 생성 및 분배 방법에 관한 제시가 없다는 문제점이 있다. 본 논문에서는 이러한 문제점을 해결하기 위한 프 로토콜을 제안하였다.

With the active Internet e-commerce and the financial sector, mutual authentication between users and service providers has become very important. Because ID- and password-based authentication is of low security, one-time password authentication methods are widely used. The existing one-time password authentication scheme of S/Key authentication method is fraught with a number of issues in addition to plain text transmission, and the method of Kim Gong-ki et al. does not offer suggestions for session key generation and distribution method. Proposed in this paper is a protocol that solves these problems.

3

사용자 인증에 적합한 OTP 생성 알고리즘에 관한 연구 KCI 등재

김동률

한국디지털정책학회 디지털융복합연구 제13권 제1호 2015.01 pp.283-288

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

일회용 패스워드는 정적인 패스워드 사용에 따른 위험을 해결하고 사용자 인증을 강화하기 위해 필요하다. 개인정보 유출에 따른 사용자를 인증을 강화하기 위해 OTP 생성 알고리즘이 중요시 되고 있다. 본 논문에서 제안하는 OTP 생성 알고리즘은 값과 값을 이용하여 256비트 크기의 OTP Data를 생성하게 된다. 생성한 OTP Data를 행렬로 나열하고 불규칙적으로 32비트의 값을 추출하게 되는 이 값이 최종적인 OTP값이 된다. OTP 생성 횟수가 많을수록 제안하는 알고리즘이 기존 알고리즘에 비해 충돌내성의 확률이 낮음을 알 수 있다.

A disposable password is necessary to avoid any danger by the use of a static password and reinforce the user's authentication. In order to prevent personal information from being exposed, OTP generation algorithm is regarded as important. The OTP generation algorithm we suggest in this thesis generates 256-bit-size OTP Data by using Seed value and Time value. This value that the generated OTP Data are arranged with a matrix and a 32-bit-value is extracted on an irregular basis becomes the final value. We can find out that the more OTP generation frequency we have, the lower probability of clash tolerance we get in our suggested algorithm, compared to the previous algorithm.

4

4,000원

비디오 콘텐츠는 사람의 시각과 청각을 이용함으로 다른 종류의 콘텐츠 보다 이해하기 쉽기 때문에 많은 사람들이 선호한다. 더불어 스마트폰의 보급으로 인터넷을 이용한 비디오 콘텐츠 서비스에 대한 수요가 급증하고 있다. 콘텐츠 거래 활성화를 위해서는 유료 가입자에 대한 인증과 유료 채널로 전송되는 데이터의 보호가 중요하다. 가입자 채널 보호를 위해서는 일반적으로 대칭키 암호 기술이 사용되는데, 안전성을 높이기 위해서 키 값을 주기적으 로 변경해야 한다. 또한 다른 사용자에 의한 콘텐츠 불법 이용을 방지하려면 대리 인증이 불가해야 한다. 본 논문에서 는 가입자의 바이오메트릭 데이터를 이용한 본인 인증 및 일회용 암호키를 생성하는 모델을 제안한다. 제안한 모델은 바이오메트릭 데이터 등록, 일회용 키 생성, 채널 암호화 및 복호화 단계로 구성된다. 기존의 케이블 TV 콘텐츠 인증 기술인 CAS (Conditional Access System)와의 차이점을 분석하고 인터넷 상거래에서의 응용 분야를 제시한다.

Most peoples are used to prefer to view the video contents rather than the other contents since the video contents are more easy to understand with both their eyes and ears. As the wide spread use of smartphones, the demands for the contents services are increasing rapidly. To promote the contents business, it’s important to provide security of subscriber authentication and corresponding communication channels through which the contents are delivered. Generally, symmetric key encryption scheme is used to protect the contents in the channel, and the session key should be upadated periodically for the security reasons. In addition, to protect viewing paid contents by illegal users, the proxy authentication should not be allowed. In this paper, we propose biometric based user authentication and one time key generation models. The proposed model is consist of biometric template registration, session key generation and chanel encryption steps. We analyze the difference and benefits of our model with existing CAS models which are made for CATV contents protection, and also provides applications of our model in electronic commerce area.

5

4,200원

스마트기기에서 스마트뱅킹, 인터넷쇼핑, 비접촉거래 등의 지급결제 거래가 급증함에 따라 모바일 OS의 취 약점, 인증서 오남용 문제 등의 보안상의 문제가 대두되며, 이에 대처할 수 있는 강력한 개인 인증 수단이 요구된다. 이와 같은 상황에 대처하기 위한 인증 수단으로 바이오인식정보와 더불어 PKI를 이용한 OTP를 적용하고자 한다. 바이오인식정보는 분실이나 도용의 위험이 적으며 OTP를 이용한다면 바이오인식정보만을 이용할 때 보다 보안성이 강화될 수 있다. 이에 본 논문에서는 모바일 기기에서 바이오인식정보와 OTP를 이용한 개인 인증 기법을 제안한다.

According to increasing of payment and settlements like smart banking, internet shopping and contactless transaction in smart device, the security issues are on the rise, such as the vulnerability of the mobile OS and certificates abuse problem, we need a secure user authentication. We apply the OTP using biometrics and PKI as user authentication way for dealing with this situation. Biometrics is less risk of loss and steal than other authentication that, in addition, the security can be enhanced more when using the biometric with OTP. In this paper, we propose a user authentication using biometrics and OTP in the mobile device.

6

Multifactor Authentication Using a QR Code and a One-Time Password

Malik, Jyoti, Girdhar, Dhiraj, Dahiya, Ratna, Sainarayanan, G.

[Kisti 연계] 한국정보처리학회 Journal of information processing systems Vol.10 No.3 2014 pp.483-490

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

In today's world, communication, the sharing of information, and money transactions are all possible to conduct via the Internet, but it is important that it these things are done by the actual person. It is possible via several means that an intruder can access user information. As such, several precautionary measures have to be taken to avoid such instances. The purpose of this paper is to introduce the idea of a one-time password (OTP), which makes unauthorized access difficult for unauthorized users. A OTP can be implemented using smart cards, time-based tokens, and short message service, but hardware based methodologies require maintenance costs and can be misplaced Therefore, the quick response code technique and personal assurance message has been added along with the OTP authentication.

7

피싱 방지 및 가용성 개선을 위한 PKI기반의 모바일 OTP(One Time Password) 메커니즘에 관한 연구

김태형, 이준호, 이동훈

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.21 No.1 2011 pp.15-26

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

IT기술 및 정보통신망의 발달은 온라인 금융거래를 활성화 시켰고 사용자들은 다양한 금융서비스를 받을 수 있게 되었다. 하지만 이러한 긍정적인 효과와는 다르게 2009년 7월 7일에 발생한 DDoS(Distribute Denial of Service)공격과 같이 사용자들에게 피해를 주는 부정적인 효과도 초래하였다. 온라인 금융거래에서도 피싱(Phishing) 사이트와 같이 인증절차를 우회할 수 있는 예측 불가능한 공격이 발생하게 되었으므로 OTP(One Time Password)인증과 같이 온라인 금융거래에 이용되는 인증기술에 대해서도 다각도로 안전성을 검토해야한다. 따라서 OTP 인증의 안전성을 높이기 위해 본 논문에서는 PKI기반의 모바일 OTP 메커니즘을 제안한다. 제안하는 메커니즘은 PKI기반에서 운용되므로 사용자와 인증서버의 디지털서명과 공개키 암호화를 통하여 OTP 생성을 위한 비밀 값은 안전하게 전송되고 생성된 OTP는 사용자가 웹사이트에 입력하는 것이 아니라 모바일 단말기에서 인증서버로 직접 전송(Direct Transmission)되기 때문에 2006년에 발생한 시티은행 피싱 사이트에서 드러난 OTP 인증방식의 문제점이 해결되고 사용자의 가용성(편의성)을 높이게 된다.

The development of IT technology and information communication networks activated to online financial transactions; the users were able to get a variety of financial services. However, unlike the positive effect that occurred on 7 July 2009 DDoS(Distribute Denial of Service) attacks, such as damaging to the user, which was caused negative effects. Authentication technology(OTP) is used to online financial transaction, which should be reviewed to safety with various points because the unpredictable attacks can bypass the authentication procedure such as phishing sites, which is occurred. Thus, this paper proposes mobile OTP(One Time Password) Mechanism, which is based on PKI to improve the safety of OTP authentication. The proposed Mechanism is operated based on PKI; the secret is transmitted safely through signatures and public key encryption of the user and the authentication server. The users do not input in the web site, but the generated OTP is directly transmitted to the authentication server. Therefore, it is improvement of the availability of the user and the resolved problem is exposed from the citibank phishing site(USA) in 2006.

8

4,000원

최근 대규모 개인정보 유출 사고로 인해 Credential Stuffing 공격이 급증하고 있다. 기존의 TOTP(Time-based One-Time Password) 기반 이중 인증 기법은 비밀번호 재사용 공격을 완화하는 데 효과적이지만, HMAC-SHA 기반 구조는 장기적으로 양자 컴퓨팅 환경에서 보안 강도가 저하될 수 있다. 본 논문에서는 격자 기반 및 해시 기반 양자 내성 암호 구조를 적용한 PQ-TOTP(Post-Quantum TOTP) 인증 기법을 제안한다. 제안 기법은 디바이스 바인딩과 세션 난수 결합 메커니즘을 통해 Credential Stuffing 공격의 성공 확률을 이론적으로 감소시킨다. 보안성 분석 결과, 제안 기법은 기존 TOTP 대비 양자 공격 저항성과 재사용 공격 방어 측면에서 향상된 보안 수준을 제공함을 확인하였다.

Credential stuffing attacks have significantly increased due to large-scale credential leaks. Conventional Time-based One-Time Password (TOTP) mechanisms mitigate password reuse attacks; however, HMAC-SHA-based constructions may suffer reduced security strength in the presence of quantum adversaries. This paper proposes a Post-Quantum TOTP (PQ-TOTP) scheme leveraging lattice-based and hash-based post-quantum cryptography. The proposed mechanism incorporates device binding and session randomness to reduce the success probability of credential stuffing attacks. Security analysis demonstrates that the proposed scheme provides enhanced resistance against quantum attacks and replay-based credential reuse compared to conventional TOTP mechanisms.

9

4,000원

Credential Stuffing 공격의 2단계 인증에 사용되는 TOTP(Time based One Time Password)는 일회성 비밀번호(OTP)를 시간 기반으로 생성하는 간편하고 널리 사용되는 인증 방식이지만, 유효 시간 내 동일 OTP를 재사용할 수 있어 재사용 공격에 취약하다는 한계가 있다. 따라서 본 논문에서는 이러한 보안 취약점을 보완하기 위해 경량 자료 구조인 Counting Bloom Filter(CBF)를 결합하여 OTP 사용 이력을 추적하여 재사용 여부를 효 율적으로 검출할 수 있는 방법을 제안하였다. 결론적으로 제안한 CBF+TOTP 방식은 기존 TOTP의 재사용 공격 과 같은 보안 취약점을 보완하면서도 경량성과 확장성을 유지할 수 있는 효과적인 인증 기법이다.

Credential stuffing attacks exploit reused or compromised credentials to gain unauthorized access to user accounts. As a countermeasure, Time-Based One-Time Passwords (TOTP) are widely used in two-factor authentication (2FA) systems. However, TOTP remains vulnerable to replay attacks, as the same OTP can be reused within its valid time window. To address this limitation, we propose an enhanced authentication method that combines TOTP with a Counting Bloom Filter (CBF), a lightweight and space-efficient data structure. By recording hashed OTPs in the CBF, the system can efficiently detect and prevent OTP reuse without the need for persistent storage. In conclusion, the proposed CBF+TOTP scheme effectively addresses security vulnerabilities of traditional TOTP, such as susceptibility to replay attacks, while maintaining lightweight operation and scalability.

10

OTP를 이용한 PKI 기반의 개인키 파일의 안전한 관리 방안

김선주, 조인준

[Kisti 연계] 한국콘텐츠학회 한국콘텐츠학회논문지 Vol.14 No.12 2014 pp.565-573

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

인터넷이 활성화되면서 우리는 PC나 스마트폰에서 온라인 뱅킹, 주식 거래, 쇼핑 등의 다양한 전자상거래를 한다. 인터넷 상에서 거래 당사자 간의 신원확인 및 부인방지를 위한 주요 수단으로 공인인증서를 주로 활용한다. 하지만, 2005년 이후로 공인인증서 사용자에 대한 공격이 증가하고 있다. 즉, 공격자는 사용자 PC로부터 탈취한 공인인증서와 개인키 파일을 가지고, 은행 계좌 조회/이체나 전자상거래에 정당한 사용자로 위장하여 사용하게 된다. 이때, 개인키 파일은 사용자의 비밀번호로 암호화되어 저장되고, 필요할 때마다 복호화 되어 사용한다. 만약, 사용자의 비밀번호가 공격자에게 노출된다면 암호화된 개인키 파일을 쉽게 복호화 할 수 있다. 이러한 이유로 공격자는 사용자 PC에 트로이목마, 바이러스 등의 악성코드를 설치하여 사용자 인증서, 개인키 파일, 비밀번호를 탈취하려고 한다. 본 논문에서는 개인키 파일을 OTP 인증기술을 이용하여 암호화함으로써 안전하게 관리할 수 있는 방안을 제안한다. 그 결과, 암호화된 개인키 파일이 외부에 노출되더라도 일회용 패스워드와 사용자 비밀번호가 노출되지 않으므로 암호화된 개인키 파일은 안전하게 보관된다.

We have various e-commerce like on-line banking, stock trading, shopping using a PC or SmartPhone. In e-commerce, two parties use the certificate for identification and non-repudiation but, the attack on the certificate user steadily has been increasing since 2005. The most of hacking is stealing the public certificate and private key files. After hacking, the stolen public certificate and private key file is used on e-commerce to fraud. Generally, the private key file is encrypted and saved only with the user's password, and an encrypted private key file can be used after decrypted with user password. If a password is exposed to hackers, hacker decrypt the encrypted private key file, and uses it. For this reason, the hacker attacks user equipment in a various way like installing Trojan's horse to take over the user's certificate and private key file. In this paper, I propose the management method to secure private key of PKI using One Time Password certification technique. As a result, even if the encrypted private key file is exposed outside, the user's private key is kept safely.

11

4,000원

최근 인터넷 기반 서비스에서 사용자 인증 과정의 취약점을 이용한 공격이 급증하고 있다. 특히, 인터넷 뱅킹과 인터넷전화가 많이 보급됨에 따라 보안사고가 급증하고 있으며 공격자들의 공격 수법도 점차 지능화 되고 있다. 결국 인터넷뱅킹과 인터넷전화 등의 서비스에서 바이오메트릭 정보와 같이 사용자가 소유하고 있는 개인 고유 정보 등을 이용하여 보다 강화된 인증을 제공할 필요가 있다. 따라서 본 연구에서 제시하는 B-OTP 기술은 바이오 메트릭 정보(Biometric Data)를 OTP 방식과 접목하는 기술로 기존 인터넷 서비스에서의 사용자 인증을 강화시킬 수 있는 방법이다. 사용자가 입력한 바이오메트릭 정보를 이용하여 생성된 B-OTP 값을 이용할 경우 인터넷뱅킹과 인터넷전화 서비스 등의 보안성을 높일 수 있을 것으로 기대된다.

Diverse kind of attack using the vulnerability of user authentication on Internet service is announced recently. Especially, security accidents on the Internet banking service and Internet telephony service(SIP) are increased rapidly. Attack skills are also evolved into intelligent mechanism. Therefore, more enhanced authentication mechanism is required on existing Internet banking and telephone services for preventing those kinds of attacks using personal identity information such as biometric data. In this research, the proposed B-OTP mechanism can be used to enhance security on a user authentication procedure by combining biometric data with existing OTP mechanism. As a result, the security on internet banking and Internet telephone service will be more improved by using proposed B-OTP mechanism.

12

디지털인감이란 사용자 인증을 위한 데이터가 포함되어 있는 바코드를 스캔하면, 바코드 데이터와 비밀키 그리고 HOTP 알고리즘을 이용하여 HOTP Tag를 LCD에 출력해주는 보안 도구이다. 이 논문에서는, 디지털인감을 이용 한 안전한 비밀번호 인증 프로토콜을 제안한다. 사용자는 자신의 아이디, 랜덤챌린지, 디지털인감을 이용하여 로그 인을 시도할 때마다 일회용 비밀번호 역할을 하는 HOTP Tag를 생성하여 인증을 할 수 있다. 이를 통해 사용자는 비밀번호를 기억할 필요가 없으며, 여러 웹사이트에 등록된 비밀번호를 일일이 관리하지 않아도 된다는 사용성 측면 의 이점을 얻을 수 있다. 또한 MitM, MitB 공격을 방어할 수 있고, 안전하게 비밀키를 사용할 수 있다는 보안성 측면의 이점을 얻을 수 있다.

DigitalSeal is a security tool that scans a barcode which includes information for authentication, and then prints HOTP Tag on LCD using the barcode data, a secret key and HOTP algorithm. In this paper, we propose a secure password authentication protocol using DigitalSeal. A user can generate HOTP Tag when trying to login on a website using a ID, a random challenge and DigitalSeal. Then, the user can authenticate on the website using HOTP Tag that serves as an one-time password. As a result, the user can get benefit of usability aspect because it does not have to remember a password and manage a password on multiple websites. In addtion, this protocol is strong against MitM, MitB attacks and a secret key can be more securely managed.

13

Development of ICT technologies leads exponential growth of various sharing economy over the last couple of years. The intuitive advantage of the sharing economy is efficient utilization of idle goods and services, but there are safety and security concerns. In this paper, we propose a onetime password based access control system to support secure accommodation sharing service and show the implementation results. To provide a secure service to both the provider and the user, the proposed system issues a onetime access password that is valid only during the sharing period reserved by the user, thereafter access returns to the accommodation owner. Especially, our system provides secure user access by merging the two elements of speaker recognition using voice and a one-time password to open and close the door lock. In this paper, we propose a secure system for accommodation sharing services as a use-case, but the proposed system can be applicable to various sharing services utilizing security-sensitive facilities.

14

Weaknesses and Improvements of a One-time Password Authentication Scheme

Mijin Kim, Byunghee Lee, Seungjoo Kim, Dongho Won

보안공학연구지원센터(IJFGCN) International Journal of Future Generation Communication and Networking vol.2 no.4 2009.12 pp.29-38

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Authentication of communicating entities and confidentiality of transmitted data are fundamental procedures to establish secure communications over public insecure networks. Recently, many researchers proposed a variety of authentication schemes to confirm legitimate users. Among the authentication schemes, a one-time password authentication scheme requires less computation and considers the limitations of mobile devices. The purpose of a one-time password authentication is to make it more difficult to gain unauthorized access to restricted resources. This paper discusses the security of Kuo-Lee's one-time password authentication scheme. Kuo-Lee proposed to solve the security problem based on Tsuji-Shimizu's one-time password authentication scheme. It was claimed that their proposed scheme could withstand a replay attack, a theft attack and a modification attack. Therefore, the attacker cannot successfully impersonate the user to log into the system. However, contrary to the claim, Kuo-Lee's scheme does not achieve its main security goal to authenticate communicating entities. We show that Kuo-Lee's scheme is still insecure under a modification attack, a replay attack and an impersonation attack, in which any attacker can violate the authentication goal of the scheme without intercepting any transmitted message. We also propose a scheme that resolves the security flaws found in Kuo-Lee's scheme.

15

An Extension of Firmware-based LFSR One-Time Password Generators

HoonJae Lee, ByungGook Lee

국제인공지능학회(구 한국인터넷방송통신학회) The International Journal of Advanced Smart Convergence Volume 13 Number 2 2024.06 pp.35-43

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

In this paper, we propose two 127-bit LFSR (Linear Feedback Shift Register)-based OTP (One-Time Password) generators. One is a 9-digit decimal OTP generator with thirty taps, while the other is a 12-digit OTP generator with forty taps. The 9-digit OTP generator includes only the positions of Fibonacci numbers to enhance randomness, whereas the 12-digit OTP generator includes the positions of prime numbers and odd numbers. Both proposed OTP generators are implemented on an Arduino module, and randomness evaluations indicate that the generators perform well across six criteria and are straightforward to implement with Arduino.

16

Out-of-band Authentication Using Image-Based One Time Password in the Cloud Environment SCOPUS

Abderrahim Abdellaoui, Younes Idrissi Khamlichi, Habiba Chaoui

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.9 No.12 2015.12 pp.35-46

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Authentication can be considered as the first wall of protection from unauthorized access of any system and most notably cloud environment. Its aim is to verify user’s identity and thus the user’s legitimacy of access to services. Nowadays, The most used method for policing user access is text password. However, Several studies have shown the inadequacy of this method due to the growth of network threats. In order to mitigate the deficiency of text password scheme, we propose an image-based one-time password scheme for the cloud environment called (imOTPc). The scheme uses an image as one-time password and mobile network, which makes the system more robust and, therefore, can withstand common types of attacks. The security of the proposed scheme is based on the one-way hash function, secret extraction and the IMEI.

17

Cryptanalysis and Improvement on Lee-Chen’s One-Time Password Authentication Scheme SCOPUS

Chun-Li Lin, Ching-Po Hung

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.2 No.2 2008.04 pp.1-8

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Yeh et al., in 2002, proposed a one-time password authentication scheme using smart cards. Subsequently, Tsuji et al. and Ku et al. respectively showed that Yeh et al.’s scheme is vulnerable to stolen-verifier attacks. Recently, Lee and Chen proposed an improvement of Yeh et al.’s scheme. Lee and Chen claimed that their improvement can effectively withstand the stolen-verifier attack and is as efficient as Yeh et al.’s scheme. This paper, however, will point out that Lee and Chen’s improvement is still vulnerable to a masquerade attack. And, a simple improvement is given to resist the masquerade attack.

18

디지털 홈 네트워크에서 안전한 원격접속을 위한 일회용 비밀번호 인증 기법

유일선

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.2 No.2 2005.11 pp.136-140

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

19

S/Key 방식을 이용한 변형 일회용 패스워드 시스템에 관한 연구

김행곤, 이덕규, 김태훈

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.5 No.3 2008.06 pp.55-72

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

사용자와 서비스 제공자가 인증을 수행할 경우 사용자의 신원이 노출되는 문제가 사회의 큰 이슈로 떠오르고 있으며, 이러한 문제점을 해결하기 위해서 신원 위탁 방식이 제시되었다. 신원 위탁 방식에서는 사용자의 정확한 신원을 가지고 있는 발행자가 사용자에게 익명 인증 정보를 안전하게 전송하고, 사용자는 이것을 이용해 익명성을 유지한 채로 서비스 제공자와 인증 단계를 수행하게 된다. 본 논문에서는 신원 위탁 방식의 안전성과 신뢰성을 위한 요구사항을 제시하고 이를 만족할 수 있는 새로운 메커니즘을 제안한다. 또한 서비스 제공자가 사용자에게 컨텐츠를 안전하게 전달할 수 있는 방안과 동일 도메인 내 사용자들 간의 키 동의에 의해 생성된 키를 이용한 암호화 통신 시 키 복구를 지원하는 향상된 메커니즘을 제안한다.

In case certification between user and service provider is achieved, problem that user's identity is revealed is occurring by social issue, so it was presented identity escrow scheme to solve these problem. In identity escrow scheme, the issuer who have correct user's identity transmits securely anonymity authentication information to user, and user achieves authentication phase with service provider keeping oneself anonymity using this. In this paper, we present requirement for security and trusty of identity escrow scheme and propose new mechanism that can security this. Also, propose method that service provider can deliver securely contents to user and propose mechanism that improve that support key recovery at encryption communication that using secret key that it was generated by key agreement between users.

20

One-Time Password를 이용한 사용자 인증 시스템 설계에 관한 연구

윤석현, 정경숙, 정태충

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2000 pp.1473-1476

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

정보화 사회로의 진전으로 웹 환경에서의 다양한 서비스가 요구되고 있다. 그 용도가 점차적으로 증가추세에 있는 웹 환경에서의 다양하고 중요한 정보에 대한 서비스를 위해서는 안전한 사용자 인증과 데이터의 무결성 등이 이러한 서비스에 대하여 필수적이라고 할 수 있다. 현재에는 SET이나 SSL과 같은 안전한 암호화 통신을 위한 많은 프로토콜이 연구 개발되고 있다. 하지만, 본 논문에서는 현재 그 중요성이 대두되고 있는 사용자 인증과 서버와 클라이언트간의 보다 신뢰할 수 있는 안전성을 위한 암호화 통신을 위해서 보안상 안전한 웹 시스템 환경을 설계하고자 한다.

 
1 2 3 4
페이지 저장