년 - 년
서버와 태그 비동기시에도 효율적으로 검색이 가능한 해시기반 RFID 인증 프로토콜
[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.21 No.5 2011 pp.71-82
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
RFID 시스템은 여러 장점을 가지며 다양한 곳에서 이용되고 있다. 그러나 현재의 RFID 시스템은 무선통신과 저가 태그의 사용으로 인해 도청, 재전송 공격, 메시지 탈취, 태그에 대한 물리적 공격에 취약하다. 이런 공격들은 태그와 리더 사칭, 태그 무능화를 통한 서비스 거부공격, 태그 소지자의 위치 추적등을 유발한다. 이런 취약점을 해결하기 위해 다수의 RFID 인증 프로토콜이 제안되었다. 특히 Weis, Sarma, Rivest, Engels이 해시 기반 RFID 인증 프로토콜을 제안한 이래로, 많은 해시 기반 RFID 인증 프로토콜이 제안되었고 최근의 해시 기반 프로토콜은 보안성과 만족할 만한 수준의 프라이버시를 제공한다. 그러나 보안성과 만족할 만한 수준의 프라이버시를 제공하는 동시에 서버에서의 태그 인식 시간을 줄이는 것은 여전히 풀리지 않는 문제다. 이에 우리는 태그가 이전 통신 상태에 따라 응답 메시지를 생성하는 프로토콜을 제안한다. 그 결과 보안성과 프라이버시를 보장하는 동시에 서버에서 합리적인 시간안에 태그를 인식할 수 있다. 구체적으로 제안하는 프로토콜은 세션키와 롱텀 고정키를 모두 사용해서 이전 세션이 비정상 종료 된 경우에 비슷한 수준의 안전성을 제공하는 기존의 연구결과에 비해 태그 인식시간이 50%로 절감한 효과를 제공한다.
The RFID system provides undeniable advantages so that it is used for various application. However recent RFID system is vulnerable to some attacks as eavesdropping, replay attack, message hijacking, and tag tampering, because the messages are transmitted through the wireless channel and the tags are cheap. Above attacks cause the tag and reader impersonation, denial of service by invalidating tag, and the location tracking concerning bearer of tags, A lot of RFID authentication protocol bas been proposed to solve the vulnerability. Since Weis, Sanna, Rivest, and Engel, proposed the bash-based RFID authentication protocol, many researchers have improved hash-based authentication protocol and recent bash-based authentication protocols provide security and desirable privacy. However, it remains open problem to reduce the tag identification time as long as privacy and security are still guaranteed. Here we propose a new protocol in which the tags generate the message depending on the state of previous communitions between tag and reader. In consequence, our protocol allows a server to identify a tag in a reasonable amount of time while ensuring security and privacy, To be specific, we reduced the time for the server to identify a tag when the last session finished abnormally by at least 50% compared with other bash-based schemes that ensure levels of security and privacy similar to ours.
RFID Mutual Authentication Protocol based on Synchronized Secret SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.7 No.4 2013.07 pp.37-50
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Radio Frequency Identification (RFID) tags, due to their ability to uniquely identify every individual item and low cost, are well suited for supply chain management and are expected to replace barcodes in the near future. However, unlike barcodes, these tags have a longer range in which they are allowed to be scanned, subjecting them to unauthorized scanning by malicious readers and to various other attacks, including cloning attacks. Privacy and security concerns inhibit the fast adaption of RFID technology for many applications. A number of authentication protocols that address these concerns have been proposed but real-world solutions that are secure and maintain low communication cost are still needed and being investigated. Recently, Cho et al. proposed a hash-based RFID mutual authentication protocol using a secret value. However, this paper shows that Cho et al.’s protocol is weak against desynchronization attack and proposes a remedy mutual authentication protocol, which offers a high level of security based on hash operation with synchronized secret. The protocol is applicable to resource, power and computationally constraint platforms such as RFID tags. Our investigation shows that it can provide mutual authentication and untraceability as well as resistance to replay, denial-of-service and man-in-the-middle attacks, while retaining a competitive computation cost.
Authentication Process between RFID tag and Mobile Agent Under U-healthcare System SCOPUS
보안공학연구지원센터(IJBSBT) International Journal of Bio-Science and Bio-Technology Vol.6 No.3 2014.06 pp.109-116
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
A variety of security and privacy threats to RFID authentication protocols with embedded healthcare system have been widely studied. The representative vulnerabilities include eavesdropping, replay attacks, denial of service attacks, tracking, and traceability. Considering this RFID security issues, we analyzed the security threats and open problems related to these matters. In ubiquitous system with sensor node, we use small and limited resources and low memory. Then the application with these kinds of have lots of vulnerabilities and attacks such RFID protocol in healthcare system. Even though, concerns about the disclosure of personal medical privacy in e-healthcare system have already appeared. In this paper, we analyzed and compared practical threat on U-healthcare system.
태그 ID를 이용한 RFID 상호인증 프로토콜 KCI 등재
보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.14 No.4 2017.08 pp.281-292
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
RFID(Radio Frequency Identification) 시스템은 무선을 이용한 데이터 전송 기술로써 사물인터넷의 다양한 분야에 활용되고 있다. 하지만 무선 주파수를 이용하여 데이터를 전송하기 때문에 보안 문제 가 있다. 본 논문에서는 수동형 태그에 적용 가능한 AES(Advanced Encryption Standard) 알고리즘 기반의 RFID 상호 인증 프로토콜을 제안한다. 제안 프로토콜은 대칭키 기반 RFID 프로토콜의 동일한 비밀키 사용 문제를 태그의 ID로 해결한다. 태그의 ID는 상호인증 과정에서 암·복호화 키로 사용하 며, 상호인증 과정에서 리더와 태그의 난수를 확인하여 RFID 환경에서 나타나는 다양한 공격문제를 해결한다. 아울러 제안 프로토콜은 Casper/FDR 도구를 이용하여 보안에 안전함을 정형적으로 검증한다.
The RFID(Radio Frequency Identification) System is data transmission technology using by radio frequency and used in various areas of IoT(Internet of Things). However, It has security problems because it transfer data using radio frequency between reader and tags. In this paper, we proposed AES (Advanced Encryption Standard) algorithm-based RFID mutual authentication protocol for passive RFID tags. The proposed protocol resolve fixed secret key of symmetric key based-RFID protocol using by tag’s ID because Tag’s ID is used as ecryption and decryption key in mutual authentication process. In addition, our scheme resolve various attacks to verify random number of reader and tags in RFID environment. We described our protocol and formally verified security using by Casper/FDR tool.
공격자의 저장정보 분석 공격에 안전한 전자태그 인증 기법에 관한 연구
[NRF 연계] 한국자료분석학회 Journal of The Korean Data Analysis Society Vol.7 No.2 2005.04 pp.665-675
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
RFID 시스템은 유비쿼터스 컴퓨팅 환경과 센서 네트워크 환경을 구현하는데 가장 기본이 되는 핵심 기술로 활발하게 연구되고 있다. 그러나 RFID 시스템이 많은 장점을 가지고 있는 반면, 사용자의 위치 추적과 사용자 개인정보 노출과 같은 새로운 문제점들도 가지고 있다.본 논문에서는 사용자의 위치 정보를 보호하기 위해 제안된 기존의 방식들을 고찰하고, 기존의 제안된 방식들이 가지고 있는 문제점에 대하여 연구한다. 또한 본 논문에서는 기존의 방식들이 내포하고 있는 문제점을 해결할 수 있는 보다 안전한 사용자의 위치 정보 보호 기능을 제공하는 RFID 시스템을 제안한다. 제안한 방식은 태그가 리더로부터 수신한 난수를 이용하여 또 다른 난수를 생성하고, 이를 이용하여 매 세션마다 다른 응답을 생성하여 전송하기 때문에 트래킹 공격과 재전송 공격 그리고 스푸핑 공격에도 안전하며, 또한 위치 트래킹에도 안전한 인증 시스템이다.
RFID systems have been studied actively in ubiquitous computing as main technology. While RFID systems have much benefits, however it may create new problems to the user's privacy concerned with location and private informations.In this paper, we presented a description of previously proposed mechanisms for protecting user's privacy and solving these problems in ubiquitous computing environments. Also, in oder to solve these problems, we proposed new and secure RFID systems offering location privacy protection in ubiquitous computing environments. The proposed system provides authentication securely because the tag generates another random number by using a received random number from the reader. Also, the proposed scheme provides location privacy against location tracking by an adversary.
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2006 pp.1011-1014
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
RFID(Radio Frequency Identification), 즉, 무선 주파수 인식 기술은 주파수를 이용하여 개별 상품을 식별하는 방식을 일컫는다. 바코드나 스마트카드에 비하여 우수한 특성에 의해 다양한 응용이 가능하여, 향후 유비쿼터스 환경을 구축하는 데 핵심적 역할을 할 것으로 보인다. 그러나 이러한 환경을 제대로 갖추기 위해서는 보안 기술이 필수적이다. 작고 가벼움을 필수조건으로 하는 RFID에서는 기존의 보안 기술을 그대로 적용하기 어렵기 때문에 보다 가볍고 안전한 RFID 보호 프로토콜이 요구된다. 본 논문에서는 태그와 리더가 각각 난수를 생성함으로써 기존의 인증 프로토콜보다 적은 연산만으로도 서로를 안전하게 인증하는 기법을 제시한다.
[Kisti 연계] 한국산학기술학회 한국산학기술학회 학술대회논문집 2006 pp.225-228
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
RFID 시스템에서 전자태그와 리더사이의 통신은 무선을 통해 이루어짐에 따라 현재 보안상 많은 취약점이 존재한다. 본 논문에서는 여러 보안 문제 중 프라이버시 보호를 위한 기존 기법의 취약점을 보완하여 태그가 리더로부터 수신한 난수로부터 매 세션마다 실시간으로 새로운 해쉬 함수를 생성하는 인증 프로토콜을 제안한다. 제안한 알고리즘은 RFID 무선 인증 시스템에서 다양한 유용성을 제공할 수 있으며, 기존의 알고리즘에 비해 계산량을 절감할 수 있는 장점이 있다. 또한 추후 예상되는 주변의 수많은 태그중 필요한 태그만 선별하여 사용하며, 시간 기반으로 불필요 태그의 동작을 종료시켜 서버부담을 줄이는 방법이 될 것으로 기대된다.
RFID Tag 보안을 위한 인증 프로토콜에 관한 연구
[Kisti 연계] 한국산학기술학회 한국산학기술학회 학술대회논문집 2008 pp.104-107
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 논문에서 제안하는 시스템은 기존의 RFID 시스템의 보안성을 높이기 위하여 2차원 배열 기법을 이용하여 안전성을 확보할 수 있게 되었다. 제안하는 시스템은 RFID Tag의 고유 ID 값인 UID값과 2차원 배열을 이용하여 태그와 리더간 인증을 하게 된다. 제안하는 시스템에서 암 복호화를 하기 위해서는 태그의 고유 ID값인 UID값과 관리자가 정의한 키셋을 이용한 암 복호화 과정에서의 안전성을 기존의 다른 시스템과의 비교를 통해 우수함을 입증한다.
얼굴 인식과 RFID를 이용한 실시간 객체 추적 및 인증 시스템
[Kisti 연계] 디지털산업정보학회 디지털산업정보학회논문지 Vol.4 No.4 2008 pp.51-62
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
In this paper, the proposal system can achieve the more safety of RFID System with the 2-step authentication procedures for the enhancement about the security of general RFID systems. After authentication RFID Tag, additionally, the proposal system extract the characteristic information in the user image for acquisition of the additional authentication information of the user with the camera. In this paper, the system which was proposed more enforce the security of the automatic entrance and exit authentication system with the cognitive characters of RFID Tag and the extracted characteristic information of the user image through the camera. The RFID system which use the active tag and reader with 2.4GHz bandwidth can recognize the tag of RFID in the various output manner. Additionally, when the RFID system have errors, the characteristic information of the user image is designed to replace the RFID system as it compare with the similarity of the color, outline and input image information which was recorded to the database previously. In the result of experiment, the system can acquire more exact results as compared with the single authentication system when it using RFID Tag and the information of color characteristics.
수동형 RFID 보안태그와 리더의 인증 및 데이터 보호 프로토콜 보안 취약점 분석
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2010 pp.1177-1179
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
RFID는 태그가 부착된 사물의 정보를 무선통신을 통해 인식하는 기술로써 바코드를 대체하는 등 다양한 영역으로 응용 범위가 확대되고 있다. 따라서 각 응용에 필요한 보안 문제도 중요시 되고 있다. 본 논문에서는 지금까지 RFID시스템의 보안 취약성을 해결하기 위해 제안된 많은 인증 프로토콜들 중 한국정보통신기술협회에서 제정한 잠정표준인 "수동형 RFID 보안태그와 리더의 인증 및 데이터 보호 프로토콜"에 대하여 프라이버시 침해, 위치추적, 비동기화 공격 가능 및 전방향 안전성을 만족하지 못하는 등의 보안 취약점이 있음을 보이고, 이에 대한 분석을 하였다.
수동형 RFID 보안태그와 리더의 인증 및 데이터 보호 프로토콜 보안 취약점 분석
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2010 pp.1177-1179
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
RFID는 태그가 부착된 사물의 정보를 무선통신을 통해 인식하는 기술로써 바코드를 대체하는 등 다양한 영역으로 응용 범위가 확대되고 있다. 따라서 각 응용에 필요한 보안 문제도 중요시 되고 있다. 본 논문에서는 지금까지 RFID시스템의 보안 취약성을 해결하기 위해 제안된 많은 인증 프로토콜들 중 한국정보통신기술협회에서 제정한 잠정표준인 "수동형 RFID 보안태그와 리더의 인증 및 데이터 보호 프로토콜"에 대하여 프라이버시 침해, 위치추적, 비동기화 공격 가능 및 전방향 안전성을 만족하지 못하는 등의 보안 취약점이 있음을 보이고, 이에 대한 분석을 하였다.
RFID/USN과 u-LBS기반 인체 부착식 태그 인식 모델
[Kisti 연계] 한국정보과학회 한국정보과학회 학술대회논문집 2005 pp.259-261
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
IT기술을 통한 유비쿼터스 기반기술의 발전은 가히 혁명적이라 할 수 있다. 특히 유비쿼터스 기반기술 중 최근 대두되고 있는 RFID/USN과 u-LBS 기술이야 말로 대표적인 예라 할 수 있다. 이러한 기술활용을 위해 다양한 연구와 투자가 전세계적으로 이뤄지고 있으며, 이 논문에서 제시하는 모델의 핵심기술이기도 하다. 본문에서는 이러한 기술을 통해 특정대상 즉, 치매노인, 유아/청소년에 대한 위치인식 기술모델을 제시함으로써 RFID/USN, u-LBS의 기술확산과 향후 고령화 저출산 사회문제의 해결을 도모하고자 한다.
RFID/USN과 u-LBS기반 인체 부착식 태그 인식 모델
[Kisti 연계] 한국정보과학회 한국정보과학회 학술대회논문집 2005 pp.259-261
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
IT기술을 통한 유비쿼터스 기반기술의 발전은 가히 혁명적이라 할 수 있다. 특히 유비쿼터스 기반기술 중 최근 대두되고 있는 RFID/USN과 u-LBS 기술이야 말로 대표적인 예라 할 수 있다. 이러한 기술활용을 위해 다양한 연구와 투자가 전세계적으로 이뤄지고 있으며, 이 논문에서 제시하는 모델의 핵심기술이기도 하다. 본문에서는 이러한 기술을 통해 특정대상 즉, 치매노인, 유아/청소년에 대한 위치인식 기술모델을 제시함으로써 RFID/USN, u-LBS의 기술확산과 향후 고령화 저출산 사회문제의 해결을 도모하고자 한다.
[Kisti 연계] 한국정보과학회 한국정보과학회 학술대회논문집 2005 pp.100-102
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
RFID/USN이 큰 이슈가 되면서 RFID 에 대한 각종 연구와 응용이 현재 활발히 진행 중이다. 유선 네트워크상에서의 보안은 지금까지의 연구와 개발로 신뢰적인 통신이 가능하다. 그러나 RFID는 Air Interface를 전송매체로 사용하기 때문에 유선의 상황보다 외부의 노출정도가 훨씬 크다. 따라서 외부의 공격에 쉽게 노출 될 수 있으며 이를 보완하기위해 Tag안에 ID를 직접 넣지 않고 DataBase에서만 ID를 관리하는 방식의 RFID 인증 프로토콜을 제안했다. 기존의 RFID 인중 프로토콜보다 Reader의 작업량을 줄였고, 태그로부터 정보를 탈취하여 복호화 한다 하더라도 ID가 없기 때문에 쓸모없는 정보가 된다.
안전한 RFID 환경을 위한 태그-리더 상호 인증 프로토콜
[Kisti 연계] 한국정보통신학회 한국정보통신학회논문지 Vol.19 No.2 2015 pp.357-364
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
RFID 환경에서는 태그-리더 사이에 무선으로 데이터를 송수신하기 때문에, 공격자가 물리적인 제약없이 네트워크에 참가할 수 있어 도청 및 데이터 위 변조와 같은 다양한 공격 기법에 쉽게 노출될 수 있다. 또한, RFID 태그의 자원 제약성이 높아 외부 공격에 방어하기 위한 보안 기술을 적용하는 것이 쉽지 않다. 본 논문에서는 스푸핑 공격, 재전송 공격, 트래픽 분석 공격, 위치 트래킹 공격과 같은 외부 사이버 공격에 대해 안전하게 RFID 태그 정보를 보호하고, 다양한 외부 공격에 견딜 수 있는 새로운 태그-리더 상호 인증 프로토콜을 제안한다. 제안된 상호 인증 프로토콜의 성능 평가를 수행하고 시뮬레이션 결과를 제시한다.
Tags and Readers is receiving and sending the data using the wireless communication in the RFID environment. Therefore, it could allow an attacker to participate in the network without the physical constraints, which can be easily exposed to a variety of attacks, such as taps and data forgery. Also, it is not easy to apply the security techniques to defend external attacks because the resource constraints of RFID tags is high. In this paper, new tag-reader mutual authentication protocol is proposed to protect the external cyber attacks such as spoofing attacks, replay attacks, traffic analysis attacks, location tracking attacks. The performance evaluation of the proposed mutual authentication protocol is performed and the simulation results are presented.
특정 태그 검색기능을 지원하는 향상된 안전성의 RFID 인증 프로토콜
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2008 pp.1096-1099
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 논문에서는 RFID시스템에서 일어날 수 있는 위험요소들을 나열하고, 이에 맞는 해결책으로 RFID 인증프로토콜을 제시하며, 일반적인 RFID 인증프로토콜에서 볼 수 없었던 RFID 검색 프로토콜에 관한 소개와 검색 프로토콜이 갖는 새로운 요구사항을 제시한다. 또한 기존에 제안된 RFID검색 프로토콜보다 향상된 보안성을 지원하는 프로토콜을 제안하며 앞으로 연구할 방향을 제시한다.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.