Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 6
No
1

4,000원

기존 스마트폰에서 사용된 PIN과 같은 인증기법은 디스플레이 구조의 변형 또는 화면 크기의 가변성에 대한 고려가 이루어지지 않아 최근의 가변 디스플레이 기반 스마트폰에 적용될 경우 비밀정보 입력부의 축소나 확대로 발생 가능한 취약 점과 같은 디스플레이 면적의 변형에 따른 사회공학 공격에 대한 취약점이 있다. 본 연구는 롤러블 및 벤더블 스마트폰과 같 이 디스플레이 크기 변화에 대응하는 보안 키패드를 제안한다. 이를 위해 우선 각 기존 인증기법에서 새로운 폼팩터에 적용될 경우 발생할 수 있는 보안 문제를 분석하였으며 이에 대응하는 보안 요구사항을 도출하였다. 제안하는 보안 키패드는 롤러블 및 벤더블 스마트폰의 디스플레이 크기에 따라 입력에 적합한 간격과 크기로 키의 배열 및 배치가 변형 가능하므로 화면 크기 가 작을 때 발생할 수 있는 키 입력 오류 문제를 고려하였다. 또한, 키 입력 좌표를 불규칙적으로 분산하여 사회공학 공격에 대한 입력 정보 유출 문제도 고려하였다. 제안 기법은 다양한 크기와 형태의 스마트폰에서 사용할 수 있어 기존 기법보다 더 나은 사용자 경험과 보안성을 제공한다.

Conventional methods like PIN used in conventional smartphone form factor have not considered the variation in display structure or screen size. As a result, when applied to recent variable display-based smartphones, the secret information input unit may get reduced or enlarged, leading to vulnerabilities for social engineering attacks due to deformation of the display area. This study proposes a secure keypad that responds to changes in display size in rollable and bendable smart phones. Firstly, the security problems that may arise when applying classical authentication methods to new form factors were analyzed, and corresponding security requirements were derived. The proposed security keypad addresses the key input error problem that can occur when the screen size is small. The arrangement and size of keys can be deformed with the spacing suitable for input depending on the display size of rollable and bendable smartphones. The study also considered the problem of leaking input information for social engineering attacks by irregularly distributing key input coordinates. The proposed method provides better user experience and security than existing methods and can be used in smartphones of various sizes and shapes.

2

스트레처블 디스플레이가 적용된 모바일 기기의 보안 키패드 연구 KCI 등재

최동민

국제문화기술진흥원 The Journal of the Convergence on Culture Technology (JCCT) Vol.10 No.3 2024.06 pp.885-890

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

본 연구는 스트레처블 디스플레이 기술이 적용된 모바일 기기의 화면 변화에 대응 가능한 보안 키패드 구조를 제안하였다. 이를 위해 우리는 현재의 리지드 폼 팩터 기반 스마트폰에 적용된 인증기법들을 스트레처블 디스플레이 기술의 전 단계에 해당하는 롤러블 및 벤더블 디스플레이 기술이 적용된 스마트폰에 적용된 인증기법들과 비교 분석 하였다. 이 분석 결과를 바탕으로 우리는 스트레처블 디스플레이가 적용될 모바일 응용제품 규격인 스마트 월렛, 멀 티태스킹, 스크린 확장 및 미디어 시청, 게임 및 엔터테인먼트용 폼팩터 구조에서 발생할 수 있는 사용자 편의성 문 제와 보안 안전성 문제를 도출하였고 이에 대응하는 보안 키패드 구조를 제안하였다. 제안하는 보안 키패드 구조는 기존의 리지드 디스플레이 기반 폼 팩터 및 롤러블, 벤더블 디스플레이 기반 폼 팩터의 스마트폰 환경에 적용된 구조 에 비해 더욱 향상된 사용자 편의성 및 보안 안전성을 제공한다.

This study proposes a secure keypad structure that can adapt to screen changes in mobile devices equipped with stretchable display. For this purpose, we compared and analyzed the authentication methods applied to current rigid form factor smartphones with those applied to rollable and bendable display based smartphones, which are the previous stages of stretchable display. Based on the results of this analysis, we identified potential user convenience and security safety issues that may arise in the form factor structure for smart wallets, multitasking, screen expansion and media viewing, and gaming and entertainment applications where stretchable displays will be applied, then proposed a security keypad structure for these form factors. Our keypad structure provides enhanced user convenience and security compared to the structures applied in the smartphone environment based on the conventional rigid display form factor and rollable, bendable display form factor.

3

입력 메시지 암호화를 통한 보안 키패드의 설계와 구현

서화정, 김호원

[Kisti 연계] 한국정보통신학회 한국정보통신학회논문지 Vol.18 No.12 2014 pp.2899-2910

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 논문에서는 기존의 가상 키보드 입력 방법에서 마지막 글자를 그대로 보여주는 대신 적합한 입력이 들어올 경우 화면에 올바른 입력이 되었음을 확인할 수 있는 기법을 제안한다. 이는 비밀정보에 대한 암호화를 통해 올바른 입력이 들어오는 경우에만 확인 메시지를 보여줌으로써 공격자가 입력창을 통해 쉽게 확인할 수 있었던 비밀번호 정보를 단순한 어깨너머 공격으로는 확인이 되지 않도록 하였다. 해당 키패드는 기존의 오자에 대한 확인역시 특정 메시지로 표시되는 피드백 정보를 통해 사용자가 오탈자를 확인할 수 있는 장점도 가진다. 해당 제안 기법은 실제로 안드로이드 폰 상에 구현 및 실험되었으며 기존의 기법에 비해 68.23% 향상된 보안성을 제공하며 100%의 정확도를 제공한다. 이와 더불어 기존의 기법과 유사한 신속성을 가진다. 이는 기존의 스마트폰 상에서의 보안 키보드를 안전하게 대체할 수 있는 기술로써 그 효용성이 매우 높다고 할 수 있다.

In this paper, we present method that verifies the validity of inputted message rather than showing last character on virtual keyboard. This encrypts password and valid input only can receive right feedback. This is implemented on Android phone and tested. This shows higher security than former method by 68.23% and accuracy shows 100%. This secure keypad is practical and secure so this can replace current input keypad without difficulty.

4

가속도 센서와 방향 센서를 이용한 패스워드 추측 공격에 대응하는 보안 키패드

김익수, 최종명

[NRF 연계] 한국지식정보기술학회 (사)한국지식정보기술학회논문지 Vol.9 No.4 2014.08 pp.483-491

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 연구들에 따르면 스마트폰에 내장된 가속도 센서와 방향 센서로부터 생성되는 데이터는 사용자의 패스워드를 유추하기 위해 사용될 수 있다. 현재 스마트폰 앱에서 사용되고 있는 보안 키패드는 센서 데이터를 이용한 패스워드 공격에 취약하다. 이에 본 논문에서는 가속도 센서와 방향 센서를 이용한 패스워드 추측공격에 대응하는 안전한 키패드를 제안한다. 제안 키패드 상의 행들은 사용자가 패스워드의 한문자를 입력할 때마다 임의로 위치가 변경된다. 따라서 해커는 가속도 센서와 방향 센서로부터 생성되는 데이터를 이용하여 사용자의 패스워드를 알아내는 것이 매우 어렵다. 또한, 속임수 키 버튼을 사용하여 공격 성공률을 더욱 낮출 수 있다. 사용자는 속임수 키를 기억할 필요가 없으며, 패스워드 입력 시 단지 속임수 키를 터치하기만 하면 된다. 해커는 사용자가 터치하는 속임수 키를 보통의 키와 구분할 수 없기 때문에 가속도 센서와 방향 센서를 이용한 패스워드 추측 공격이 불가능하다. 따라서 사용자는 다양한 서비스들을 안전하고 편리하게 이용할 수 있다.

According to recent studies, data generated from smartphone’s built-in accelerometer and gyroscope sensors can be used to infer users’ passwords. Currently, the secure keypad which is being used in smartphone apps is vulnerable to password attacks using sensor data. In this paper, we propose a secure keypad against password guessing attacks with accelerometer and gyroscope sensors. In the keypad, the rows of keys on the proposed keypad is randomly changed whenever a user inputs a letter of the password. Accordingly, it is very difficult to find out the user’ password using accelerometer and gyroscope sensor data. Moreover, the proposed keypad uses fake key buttons to further reduce the success rate of the attack. Users do not have to memorize fake keys. Users only need to touch the fake keys on the proposed keypad when they input their passwords. Because attackers cannot distinguish fake keys from touched keys, they cannot find out users’ passwords with accelerometer and gyroscope sensors. Therefore users can safely use a variety of internet services.

5

간접 패턴을 이용하는 스마트폰 보안 키패드 설계

최동민

[Kisti 연계] 한국멀티미디어학회 멀티미디어학회논문지 Vol.25 No.7 2022 pp.932-944

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Smartphones, are currently equipped with high-performance hardware to process large amounts of data and provide most of the functions provided by desktop PCs. In addition, the smartphones enable quick user authentication through biometric information collected from embedded sensors. However, the biometric authentication method is sometimes rejected due to social and cultural environment, security vulnerabilities, and misrecognition rate. Thus, conventional authentication methods such as PIN and pattern authentication are still mainly used. Consider the latest foldable and bendable smartphones. These devices may be vulnerable to social engineering attacks as they use conventional authentication methods without considering their form factors. In this study, therefore, we propose an authentication method using partial elements of PIN and pattern authentication as a way to increase the security of the conventional authentication methods and consider the recent form factors. According to the performance evaluation results, our method provides improved safety compared to the conventional methods.

6

키 터치로부터 패스워드를 추측하는 공격에 안전한 숫자 키패드

김익수

[NRF 연계] 한국지식정보기술학회 (사)한국지식정보기술학회논문지 Vol.15 No.5 2020.10 pp.591-598

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

현재 스마트폰은 전자결제, 주식, 모바일 뱅킹과 같은 다양한 온라인 서비스에 이용되고 있다. 지금까지 스마트폰의 패스워드 입력 시 발생할 수 있는 공격에 대응하기 위해 많은 연구가 진행되어왔다. 현재 대중적으로 사용되고 있는 보안 숫자 키패드는 기존 키패드의 보안성을 개선하기 위해 키 사이사이에 공백을 추가하거나 키의 순서를 뒤섞어 배치한다. 공백을 추가하는 방법은 터치된 키의 위치가 쉽게 노출되며, 키의 순서를 뒤섞는 방법은 패스워드가 같은 숫자로 구성되었을 때 공격자에게 쉽게 노출될 수 있다는 문제가 있다. 본 논문에서는 스마트폰에서 패스워드를 입력할 때 발생 가능한 패스워드 추측 공격에 대응하는 안전한 숫자 키패드를 제안한다. 제안하는 키패드는 키의 순서를 뒤섞어 배치하고, 같은 숫자로 구성된 패스워드가 공격자에게 쉽게 노출되지 않도록 터치된 키를 랜덤한 위치로 이동시킨다. 그 결과 사용자가 같은 숫자를 입력할 때 같은 위치를 터치하는 것을 피할 수 있다. 따라서 제안된 키패드는 패스워드를 입력할 때 발생하는 패스워드 추측 공격에 강인하다.

Currently, smartphones are used in various online services such as electronic payments, stocks, and mobile banking. So far, there have been many studies to counter attacks that can occur when entering a password on a smartphone. Secure numeric keypads, which are currently popularly used, add spaces between keys or shuffle the order of keys to improve the security of existing keypads. Keypads with spaces have a problem that the location of the touched key is easily exposed to the attacker, and the method of shuffling the order of the keys can easily be exposed to the attacker when the password consists of the same number. In this paper, we propose a secure numeric keypad against password guessing attacks that can occur when entering a password on a smartphone. The proposed keypad shuffles the order of the keys and moves the touched keys to a random location so that the password composed of the same numbers is not easily exposed to the attacker. As a result, it is possible to avoid touching the same location when entering the same numbers. Therefore, the proposed keypad is strong against the password guessing attack that can occur when entering a password on a smartphone.

 
페이지 저장