Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 26
No
1

A Novel Approach for Integrating Security in Business Rules Modeling Using Agents and an Encryption Algorithm

Houari, Nawal Sad, Taghezout, Noria

[Kisti 연계] 한국정보처리학회 Journal of information processing systems Vol.12 No.4 2016 pp.688-710

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Our approach permits to capitalize the expert's knowledge as business rules by using an agent-based platform. The objective of our approach is to allow experts to manage the daily evolutions of business domains without having to use a technician, and to allow them to be implied, and to participate in the development of the application to accomplish the daily tasks of their work. Therefore, the manipulation of an expert's knowledge generates the need for information security and other associated technologies. The notion of cryptography has emerged as a basic concept in business rules modeling. The purpose of this paper is to present a cryptographic algorithm based approach to integrate the security aspect in business rules modeling. We propose integrating an agent-based approach in the framework. This solution utilizes a security agent with domain ontology. This agent applies an encryption/decryption algorithm to allow for the confidentiality, authenticity, and integrity of the most important rules. To increase the security of these rules, we used hybrid cryptography in order to take advantage of symmetric and asymmetric algorithms. We performed some experiments to find the best encryption algorithm, which provides improvement in terms of response time, space memory, and security.

2

Network Based Public Key Method for Steganography SCOPUS

Samir Kumar Bandyopadhyay, Tai -Hoon Kim, Sarthak Parui

보안공학연구지원센터(IJCA) International Journal of Control and Automation vol.4 no.2 2011.06 pp.43-48

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Steganography (a rough Greek translation of the term Steganography is secret writing) has been used in various forms for 2500 years. It has found use in variously in military, diplomatic, personal and intellectual property applications. Briefly stated, steganography is the term applied to any number of processes that will hide a message within an object, where the hidden message will not be apparent to an observer. The original steganographic applications used “null ciphers”, or clear text. A null cipher conveys that the message has not been encrypted in any way, whether it is using basic character shifting, substitution or advanced modern day encryption algorithm. So, the message is often in plain view but for a reason can either not be detected as being present or cannot be seen once detected. As is common with cryptography, steganography has its roots in military and government applications and has advanced in ingenuity and complexity. In this paper, Network Based Public Key Method for Steganography is proposed under RSA cryptographic assumptions.

3

Securing Mobile Cloud Environment with Unified Reliable Encryption Algorithm, Security Key and Authentication

Buchanagandi Enock Nyamajeje, Huiqun Yu

보안공학연구지원센터(IJGDC) International Journal of Grid and Distributed Computing Vol.8 No.5 2015.10 pp.153-164

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Building applications on on-demand infrastructures instead of building applications on fixed and rigid infrastructures was provided by cloud computing providers. By simply positing into the cloud, it gains fast access to business applications or infrastructure resources with reduced Capital Expenditures (CAPEX). Dramatic increase in amount of information’s are placed into the cloud by individuals and industries, security issues are vital concern in mobile computing (MCC) and impends fast deployment of applications on the cloud. This work discus the different security issues that arises about how safe the mobile cloud computing environment is and provides a unified reliable security mechanism. There are two different types of the cloud users are: On-demand and Optimistic. On-demand is a non-preemptible for flexible leases given a user accessing to the resources within an interactive time of making the request and makes the resources available for an agreed-upon period of time, user can deploy any virtual machine (VM) compatible with the system. Optimistic is preemptible and pre-set contract gives a user access to resources at an indeterminate time and make resources available to the user for an insufficient amount of time. After that, this resources are initially (pre)-defined for the user by the cloud admin, that is the user cannot provide his or her own virtual machine (VM) based on defined access control for security.

4

Hybrid Lightweight and Robust Encryption Design for Security in IoT SCOPUS

Abhijit Patil, Gaurav Bansod, Narayan Pisharoty

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.9 No.12 2015.12 pp.85-98

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Pervasive computing is the emerging field that needs ultra lightweight secure designs. In this paper, we have proposed a robust hybrid structure by fusion of RECTANGLE, LED and SPECK. With the help of a hybrid design, we have improved the key scheduling aspect of LED and related key attacks which were neglected in the LED cipher. In this paper, we also aimed at providing robust architecture by reducing footprint area to as less as possible. By using the S-box of RECTANGLE and the bit slicing technique, clustering of linear and differential trails are avoided which also strengthens the cipher. S-box of RECTANGLE is perfectly interfaced with LED design as their combination results in a differential path probability which is has an upper bound of 2-50 in its first round. The use of Bit slicing technique in this hybrid design results in good differential and linear properties, which provide resistance to cache and timing attacks. LED cipher which uses S-box of PRESENT results in clustering of linear and differential trails as S-box of PRESENT is specifically designed for compact hardware implementation. Column wise substitution and robust S-box design of RECTANGLE will make LED design robust and secure and enables it to provide resistance against any type of attack. SPECK which is designed by NSA has compact key scheduling and is best suited for our hybrid design, which helps in improving key scheduling of LED. In this paper, we have introduced a novel approach for robust design by amalgam of S-box of RECTANGLE & LED structure, and key scheduling by SPECK. This hybrid cipher design is secure against linear and differential cryptanalysis.

5

Dual Layer Security of data using LSB Image Steganography Method and AES Encryption Algorithm

Satwinder Singh, Varinder Kaur Attri

보안공학연구지원센터(IJSIP) International Journal of Signal Processing, Image Processing and Pattern Recognition Vol.8 No.5 2015.05 pp.259-266

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

In today’s scenario security of data is very big challenge in any communication. Numerous data security and hiding algorithms have been developed in the last decade. The Digital image Steganography is science of hiding sensitive information in another transmission medium to achieve secure and secret communication. In this paper we present the dual layer of security to the data, in which first layer is to encode data using Least Significant Bit image steganography method and in the second layer encrypt the data using Advance Encryption Standard Algorithm. Steganography does not replace the encryption of data, instead it provides extra security feature to it. In our work secret text message is hiding behind the digital image file and this image file is then encrypted using AES encryption algorithm.

6

Due to potentially peer works going on to address the loopholes in the existing system research works in Internet Security is never likely to saturate. The degree of one's need of security on Internet varies with one's economical, organizational and political position and the sensitivity of the information itself. This thesis envisages a Virtual Internetworking Stack (VIS), achieved by augmentation of the TCP/IP stack to befool possible cyber vigilance on one’s activities over the Internet. The model prescribes a secure session set-up randomly by exchanging colored QR codes, where the wavelength of the color determines the phase of a sinusoid used to encrypt/decrypt a message, which is understood only by a compatible and intended VIS-stack. Since, the augmentation of TCP/IP layer is done in the Kernel of the user’s Operating System, any message that this VIS-stack sends to another VIS-stack across the Internet, will be meaningless to the routers and gateways in between which participate in cyber vigilance; and an attempt to steal one’s information will be fooled by the proposed security model. We also present a vulnerability study and performance evaluation of the augmented TCP/IP stack, obtained by results of physically performed experiments.

7

In the real world, especially for wearable context with the education information communicating, the diversified contexts need to be considered to apply the Attribute-Based Encryption. However, it is hard to design the optimized dynamic access structures because it is static access structures and properties of Attribute-Based Encryption. In this paper, we propose the attribute-based encryption using the algorithm of context-based service inference model to collect the attributes by data and to provide appropriate services by recognizing the situation. Especially it is analyzed that the students' answering process is sectionalized to several scenarios according to teachers' educational objective and plan in educational environment. And through the process it is described that the application of security policy and technology must be distinguished by tables.

8

Design and Analysis of Fast Image Encryption Algorithm based on Multiple Chaotic Systems in Real-time Security Car SCOPUS

Shuai Wang, Wei Sun, Yinan Guo, Haiqun Yang, Shuming Jiang

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.7 No.6 2013.11 pp.229-240

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

This paper takes intelligent security car as the research background, aiming to find a image encryption algorithm to realize the car in the image secure transmission of wireless transmission network based on open protocols, with good safety and high real-time. this passage is based on the analysis of the existing encryption algorithms of traditional and new image, select the digital image encryption technology based on chaotic system, And put forward a Multiple chaotic image encryption method which is fit for this project, After analysis and test, the algorithm satisfies the requirements of safety and real-time.

9

In this paper, we introduce a novel approach to enhance document security by integrating Computer Generated Hologram(CGH) encryption technology with a system for document encryption, printing, and subsequent verification using a smartphone application. The proposed system enables the encryption of documents using CGH technology and their printing on the edges of the document, simplifying document verification and validation through a smartphone application. Furthermore, the system leverages highresolution smartphone cameras to perform online verification of the original document and supports offline document decryption, ensuring tamper detection even in environments without internet connectivity. This research contributes to the development of a comprehensive and versatile solution for document security and integrity, with applications in various domains.

10

클라우드 컴퓨팅을 위한 준동형 암호 병렬화와 보안 응용 기술들 KCI 등재

김현성

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.11 No.4 2014.08 pp.287-298

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

최근 다양한 국내외 기관에서 클라우드 컴퓨팅을 주목해야 할 차세대 IT 전략 기술 중 하나로 선 정하고 있다. 하지만, 클라우드 컴퓨팅 기술을 위한 다양한 연구들에서 보안기법의 부재를 확인하였 고, 강력한 보안 기법을 제공하는 것 자체가 클라우드 컴퓨팅 상용화에 있어서 가장 어려운 문제 중 하나이다. 특히, 일부 클라우드 컴퓨팅 서비스에 있어서 서버에 저장되는 데이터를 암호화하여 데이 터 기밀성을 제공하고 있지만, 이는 데이터에 대한 검색을 포함한 데이터 활용 측면에서 큰 문제를 야기할 수 있다. 이러한 문제를 해결하기 위해서 클라우드 컴퓨팅 상의 암호화된 데이터에 대해 복호 화하지 않고 연산을 수행할 수 있는 준동형 암호가 제안되었다. 준동형 암호 관련 연구는 암호 시스 템 자체에 대한 연구보다는 기존의 준동형 암호 시스템을 클라우드 컴퓨팅에 어떻게 활용할지에 더 초점이 맞춰져 있다. 이에 본 논문에서는 클라우드 컴퓨팅을 위한 준동형 암호 기법에 대한 병렬화와 병렬화된 준동형 암호 기법에 기반 한 다양한 보안 응용들에 대한 연구 방향을 도출하고자 한다.

Recently, various national and international organizations select cloud computing as one of the most important next generation IT trends. However, there are lack of cloud computing researches focused on the security and providing a strong security mechanism is one of most difficult problems to commercialize cloud computing itself. Particularly some of the data stored in the cloud server provides confidentiality by encrypting data, but this could cause problems to use data in terms of data search. To solve this problem, homomorphic encryption has been proposed to perform operations to the encrypted data without applying decryption. However, the current research on this is focused on the usage of the encryption to the cloud computing service but not on the algorithm itself. Thereby, this paper proposes the research directions of the homomorphic encryption focused on the parallelization and security application concerns.

11

클라우드 컴퓨팅 보안을 위한 준동형 암호 기법 개발 및 응용들 KCI 등재

김현성, 이성운

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.10 No.2 2013.04 pp.213-224

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

클라우드 컴퓨팅 환경에서 민감한 개인정보를 보호하기 위한 데이터 암호는 필수적이다. 하지만 클라우드 컴퓨팅에서 효율적인 다양한 데이터 서비스를 제공하는 것은 기본적인 요구사항이다. 이러 한 문제를 해결하기 위해서 암호화된 자료를 복호화하지 않고도 다양한 클라우드 서비스를 제공할 수 있는 준동형 암호 기법과 다양한 보안 서비스들이 개발되었다. 본 논문에서는 클라우드 컴퓨팅 보 안을 위한 정수 기반의 준동형 암호 기법을 제안한다. 또한, 제안한 준동형 암호 기법 기반의 데이터 기밀성과 프라이버시를 제공하기 위한 클라우드 컴퓨팅 보안 응용으로서 검증 가능 계산 기법과 검 색 가능 암호 기법, 그리고 암호 데이터 공유 기법의 세가지 관점을 살펴본다.

To protect sensitive personal information, data in cloud computing environment should be stored in encrypted form. However, providing methods to support various data services is the very basic required functionality in cloud computing. To solve this problem, Homomorphic encryption and various security services are devised, which could support various cloud services from the encrypted data without applying decryption. First of all, this paper proposes a new homomorphic encryption scheme with integers as well as conceptual overview and simple review of research efforts. Addition to them, this paper reviews the concept and the research direction for the three cloud computing security applications including verifiable computation scheme, searchable encryption scheme and sharing encrypted data scheme to provide data confidentiality and privacy based on the proposed homomorphic encryption.

12

Towards Choosing Authentication and Encryption: Communication Security in Sensor Networks

Youn, Seongwook, Cho, Hyun-chong

[Kisti 연계] 대한전기학회 Journal of electrical engineering & technology Vol.12 No.3 2017 pp.1307-1313

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Sensor networks are composed of provide low powered, inexpensive distributed devices which can be deployed over enormous physical spaces. Coordination between sensor devices is required to achieve a common communication. In low cost, low power and short-range wireless environment, sensor networks cope with significant resource constraints. Security is one of main issues in wireless sensor networks because of potential adversaries. Several security protocols and models have been implemented for communication on computing devices but deployment these models and protocols into the sensor networks is not easy because of the resource constraints mentioned. Memory intensive encryption algorithms as well as high volume of packet transmission cannot be applied to sensor devices due to its low computational speed and memory. Deployment of sensor networks without security mechanism makes sensor nodes vulnerable to potential attacks. Therefore, attackers compromise the network to accept malicious sensor nodes as legitimate nodes. This paper provides the different security models as a metric, which can then be used to make pertinent security decisions for securing wireless sensor network communication.

13

Enhancing Installation Security for Naval Combat Management System through Encryption and Validation Research

Byeong-Wan Lee

[Kisti 연계] 한국컴퓨터정보학회 Journal of the Korea society of computer and information Vol.29 No.1 2024 pp.121-130

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 논문에서는 함정 전투체계 소프트웨어 설치 시 발생 가능한 데이터 이상을 확인하는 설치 방안을 제안한다. 최근 저궤도 위성 통신과 같은 무선 통신을 이용한 정보교환 방법이 대중화되며, 함정 전투체계에서도 무선망을 이용한 여러 활용 방안이 논의되고 있다. 활용 방안 중 하나로서 무선망 통신을 이용한 설치를 함정 전투체계에 적용함으로써 실시간으로 전투체계 성능을 향상시킬 수 있는 방법이 가능해질 것으로 기대한다. 하지만 무선망의 경우 유선망보다 상대적으로 보안상 취약하므로 더 많은 보안 대책이 강구된다. 본 논문에서는 암호화 방식을 통해 다수의 노드에 파일을 전송하고 파일 설치 이후 유효성 검사를 수행함으로써, 전송 도중 위/변조 여부를 판단하여 정상적으로 설치됨을 확인한다. 제안한 방법의 함정 전투체계 적용 가능성을 보이기 위하여 전송 성능 및 보안성, 안정성 등을 평가하였으며, 이를 바탕으로 함정 전투체계에 적용하기 충분한 수준의 결과물을 도출하였다.

In this paper, we propose an installation approach for Naval Combat Management System(CMS) software that identifies potential data anomalies during installation. With the popularization of wireless communication methods, such as Low Earth Orbit(LEO) satellite communications, various utilization methods using wireless networks are being discussed in CMS. One of these methods includes the use of wireless network communications for installation, which is expected to enhance the real-time performance of the CMS. However, wireless networks are relatively more vulnerable to security threats compared to wired networks, necessitating additional security measures. This paper presents a method where files are transmitted to multiple nodes using encryption, and after the installation of the files, a validity check is performed to determine if there has been any tampering or alteration during transmission, ensuring proper installation. The feasibility of applying the proposed method to Naval Combat Systems is demonstrated by evaluating transmission performance, security, and stability, and based on these evaluations, results sufficient for application to CMS have been derived.

14

CAN-FD 프로토콜에서 신뢰성과 보안성이 향상된 인증된 암호화 아키텍쳐 및 하드웨어 엔진의 설계

이동현, 장가현, 이성수

[Kisti 연계] 한국전기전자학회 Journal of IKEEE Vol.27 No.2 2023 pp.204-212

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 논문에서는 CAN-FD 프로토콜에서 인증된 암호화의 신뢰성과 보안성을 향상시키기 위한 아키텍쳐를 제안하고 이를 하드웨어로 구현하였다. 제안된 아키텍쳐는 병렬 처리에 용이하도록 AES-128과 HMAC에 기반한 Encrypt-and-MAC 방식을 사용하였으며 신뢰성을 향상시키기 위해 하드웨어 이중화를 적용했다. 또한 채널 간 전송 횟수를 기억하는 카운터를 도입하여 마치 추가 암호 키처럼 사용하여 하드웨어 부담을 최소화하면서도 보안성을 강화하였다. 제안된 아키텍쳐를 위한 하드웨어 엔진을 FPGA로 설계하고, CAN-FD 버스 상에서 동작하는 것을 확인하였다.

In this paper, an authenticated encryption architecture with improved reliability and security is proposed and implemented in hardware. The proposed architecture exploits Encrypt-and-MAC based on AES-128 and HMAC for easy parallelization. It exploits dual modular redundancy to improve reliability. It also exploits channel communication counter as additional encryption key, so security is improved with minimum additional hardware cost. Hardware engine of the proposed architecture was designed in FPGA, and it was verified to work correctly on CAN-FD bus.

15

암호화와 감사 로깅에서 보안 요건 정의 연구

신성윤, 이강호

[Kisti 연계] 한국컴퓨터정보학회 Journal of the Korea society of computer and information Vol.19 No.9 2014 pp.85-91

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

암호화란 정보를 의미를 알 수 없는 암호문으로 변환하여 불법적인 방법에 의해 데이터가 손실되거나 변경되는 것을 방지하는 방법이다. 감사 로깅이란 사용자의 활동, 예외사항, 정보보안사건에 대한 감사 로그를 생성하고, 조사와 접근통제 감시 지원을 위하여 일정 기간 동안 보존하는 것이다. 본 논문에서는 암호화에서는 중요 정보의 전송 또는 저장 시 정보의 기밀성과 무결성을 보장하여야 한다는 것을 제시한다. 암호화는 단방향 및 양방향 암호화를 적용하며 암호화 키는 안전성이 보장되어야 한다는 것도 제시한다. 또한, 감사 로그에서 부인 방지를 위해 모든 전자 금융 거래 관련 내역은 로깅 및 보관되어야 한다는 것도 제시한다. 그리고 어플리케이션 접속로그 및 중요 정보에 대한 조회 및 사용 내역은 로깅 및 검토되어야 한다는 것도 제시하도록 한다. 본 논문에서는 암호화 및 로그 감사에 관한 실제 예를 들어 설명하도록 하여 안전한 데이터 전송과 주기적인 검토가 이루어지도록 하였다.

Encryption is a method to convert information to no-sense code in order to prevent data from being lost or altered by use of illegal means. Audit logging creates audit log of users' activities, exceptions, and information security events, and then conserves it for a certain period for investigation and access-control auditing. Our paper suggests that confidentiality and integrity of information should be guaranteed when transmitting and storing important information in encryption. Encryption should consider both one-way encryption and two-way one and that encryption key should assure security. Also, all history related to electronic financial transactions should be logged and kept. And, it should be considered to check the details of application access log and major information. In this paper, we take a real example of encryption and log audit for safe data transmission and periodic check.

16

네트워크 계층에 강화된 보안 기능을 활용한 키 교환 암호 프로토콜 기반 데이터 시스템 및 암호화 방법

박재경

[Kisti 연계] 한국컴퓨터정보학회 한국컴퓨터정보학회 학술대회논문집 2024 pp.425-426

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 논문은 표준 TCP/IP 네트워크의 특징 및 암호 프로토콜의 특징을 결합하여 TCP Handshake 단계에서 암호 키 교환을 수행하고, 디바이스의 고유한 시그니처 정보를 사용하여, 암호 키 생성 데이터로 사용하여, 보안성을 강화하는 것을 특징 으로 하는 네트워크 계층에 강화된 보안 기능을 활용한 키 교환 암호 프로토콜 기반 데이터 시스템 및 암호화 방법에 관한 것으로 개발된 프로토콜을 키 교환 프로토콜로 대체할 경우보다 안전한 보안 프로토콜을 제공할 수 있다.

17

증권거래 패킷의 암복호화와 통합보안관제 분석

오원겸, 박대우

[Kisti 연계] 한국정보통신학회 한국정보통신학회 학술대회논문집 2013 pp.227-230

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

인터넷과 모바일 단말기를 이용한 금융거래가 활성화되면서, 인터넷과 모바일기기를 이용한 증권거래가 활성화되고 있다. 증권거래 관련 IT업무를 담당하고 있는 코스콤(증권ISAC)에서는 증권거래와 관련된 정보보안관련 취약점을 분석하며, 통합보안관제시스템을 가동하여 대응하고 있다. 온라인 증권거래는 개인정보보호법의 적용대상이며, 이와 관련 전산시스템들은 주요정보통신기반 시설로 지정되어 있으나, 사용자 부주의, 해킹 등으로 인한 금융상의 피해가 예상된다. 이에 따라 증권거래 패킷의 암복호화, 통합보안관제 및 보안이벤트에 대한 분석을 통해 증권업무와 관련된 정보보안 분야의 주요 취약점에 대한 연구가 필요하다.

Financial transactions using a mobile terminal and the Internet is activated, it is a stock exchange enabled using mobile devices and the Internet. Koscom in charge of IT operations of securities transaction-related in (securities ISAC), to analyze the vulnerability of information security related to securities transactions, which corresponds to running the integrated security control system. Online stock trading is a subject to the Personal Information Protection Act, electronic systems of related, has been designated as the main information and communication infrastructure to, damage financial carelessness of the user, such as by hacking is expected to are. As a result, research on the key vulnerabilities of information security fields related to securities business cancer decoding of the Securities and Exchange packet, through the analysis of security events and integrated security control is needed.

18

2-step 위상천이 디지털 홀로그래피를 이용한 비밀키와 데이터의 이중 광암호화 기법

김성량, 길상근, 전석희

[Kisti 연계] 한국광학회 한국광학회 학술대회논문집 2009 pp.10-11

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

19

무인증서 공개키 암호 기법의 재고: 안전성 모델 및 설계

김송이, 박승환, 이광수

[Kisti 연계] 한국정보통신학회 한국정보통신학회논문지 Vol.20 No.6 2016 pp.1109-1122

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

무인증서 공개키 암호(Certificateless Public Key Encryption scheme)는 사용자 ID를 공개키로 사용함으로써 공개키 암호 시스템의 인증서 관리 문제를 해결하고 ID기반 암호 기법의 키 위탁(key escrow) 문제를 해결할 수 있는 기술이다. 이에 대한 연구가 활발히 진행되었음에도 불구하고, 기존의 여러 무인증서 암호 기법들은 사용자가 선택한 비밀값과 복호화 키 노출 공격에 대한 안전성을 고려하지 않고 설계되었다. 비밀값과 복호화 키 노출 공격이란 한 번이라도 공개키가 교체된 이후 이전에 사용했던 비밀값과 복호화 키가 노출된다면 그로부터 ID에 대응하는 부분 개인키를 획득해 현재의 정당한 복호화 키를 연산할 수 있는 공격이다. 본 논문에서는 키 노출 공격에 대해 안전한 새로운 안전성 모델을 제안하고, 해당 안전성 모델에서 기존의 무인증서 공개키 암호 기법들이 안전하지 않음을 보인다. 또한, 제안한 모델에서 안전한 새로운 무인증서 공개키 암호 기법을 제시하고, DBDH(Decision Bilinear Diffie-Hellman) 가정을 기반으로 안전성을 증명한다.

Certificateless public key cryptography is a technique that can solve the certificate management problem of a public key cryptosystem and clear the key escrow issue of ID-based cryptography using the public key in user ID. Although the studies were actively in progress, many existing schemes have been designed without taking into account the safety of the secret value with the decryption key exposure attacks. If previous secret values and decryption keys are exposed after replacing public key, a valid private key can be calculated by obtaining the partial private key corresponding to user's ID. In this paper, we propose a new security model which ensures the security against the key exposure attacks and show that several certificateless public key encryption schemes are insecure in the proposed security model. In addition, we design a certificateless public key encryption scheme to be secure in the proposed security model and prove it based on the DBDH(Decisional Bilinear Diffie-Hellman) assumption.

20

안전한 스마트폰 애플리케이션 개발을 위한 보안 고려사항 및 국산암호알고리즘 적용 방안 연구

김지연, 전웅렬, 이영숙, 김미주, 정현철, 원동호

[Kisti 연계] 디지털산업정보학회 디지털산업정보학회논문지 Vol.7 No.1 2011 pp.51-61

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

A smartphone is a mobile phone that offers more advanced computing ability and connectivity than a contemporary basic feature phone. Unlike feature phone, a smartphone allows the user to install and run more advanced applications based on a specific platform. Smartphones run complete operating system software providing a platform for application developers. A smartphone will become the default computing method for many point activities in the not-too-distant future, such as e-mail, online shopping, gaming, and even video entertainment. For smartphone that contains sensitive information and access the Internet, security is a major issue. In the 1980s, security issues were hardly noticed; however, security is a major issue for users today, which includes smart phones. Because security is much more difficult to address once deployment and implementation are underway, it should be considered from the beginning. Recently our government recognized the importance of smartphone security and published several safety tips for using the smartphone. However, theses tips are user-oriented measures. Maintaining the security of a smartphone involves the active participation of the user. Although it is a important users understand and take full advantage of the facilities afforded by smarphone, it is more important developers distribute the secure smartphone application through the market. In this paper we describe some scenarios in which user is invaded his/her privacy by smartphone stolen, lost, misplaced or infected with virus. Then we suggest the security considerations for securing smartphone applications in respect with developers. We also suggest the methods applying domestic encryption algorithms such as SEED, HIGHT and ARIA in developing secure applications. This suggested security considerations may be used by developers as well as users (especially organizations) interested in enhancing security to related security incidents for current and future use of smartphones.

 
1 2
페이지 저장