년 - 년
4,000원
스마트 기기가 보급화 됨에 따라서 사용자는 다양한 방법을 이용하여 인증 서비스를 이용할 수 있게 되었다. 인증 서비스로는 아이디와 비밀번호를 이용한 인증, 문자 메시지를 이용한 인증, OTP(One Time Password)와 같은 일회용 비밀 번호를 이용한 인증 등이 있다. 본 논문은 광학문자인식 기술을 이용하여 지식기반 인증의 보안성 문제를 해결하고 쉽고 빠르게 사용자를 인증할 수 있는 인증 시스템을 제안한다. 제안하는 인증 시스템은 사용자가 업로드한 이미지에서 문자를 추출하고 추출된 문자 정보를 이용하여 사용자를 인증한다. 제안하는 인증 시스템은 외부로 쉽게 노출되거나 분실 위험이 있는 비밀번호나 OTP를 사용하지 않으며 정확한 사진을 사용하지 않으면 인증이 불가능하다는 장점을 가진다. 제안한 인증 시스템은 플랫폼에 구애받지 않으며 사용자 인증 및 파일 암호화, 복호화에도 활용이 가능하다.
As smart devices become popular, users can use authentication services in various methods. Authentication services include authentication using an ID and a password, authentication using a sms, and authentication using an OTP(One Time Password). This paper proposed an authentication system that solves the security problem of knowledge-based authentication using optical character recognition and can easily and quickly authenticate users. The proposed authentication system extracts a character from an uploaded image by a user and authenticates the user using the extracted character information. The proposed authentication system has the advantage of not using a password or an OTP that are easily exposed or lost, and can not be authenticated without using accurate photographs. The proposed authentication system is platform independent and can be used for user authentication, file encryption and decryption.
FIDO 시스템에서 EEG 신호를 이용한 사용자 인증 방법 KCI 등재
한국융합학회 한국융합학회논문지 제9권 제1호 2018.01 pp.465-471
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 IT기슬과 금융 시스템의 융합으로 생체인식 기술이 사용되기 시작하였다. 이러한 생체 인식 기술인 FIDO(Fast Identity Online) 기술을 이용하여 삼성과 애플은 삼성페이와 애플페이 서비스를 시작하였다. FIDO 인증 기술은 패스워드와 같은 기존 인증 방법을 대체하고 있다. 생체 인식 기술 중 지문인식 기술은 비교적 저렴한 가격의 디바이스와 사용자 거부 반응을 최소화 할 수 있다는 점 때문에 주목받고 있다. 그러나 지문정보의 경우 사용자가 가지고 있는 수가 제한적이며, 외부 공격자에 의해 지문정보가 유출될 경우 재사용할 수 없다는 단점이 있다. 그러므로 본 논문에서는 생체 인식 기술 중 하나인 EEG 신호를 이용하여 사용자를 인증할 수 있는 방법을 제안한다. 제안 논문에서는 기존의 다채널 EEG 디바이스를 사용하지 않고 단채널 EEG 디바이스를 사용하여 편리성을 높였으며, EEG 신호 측정값을 FIDO 시스템에 사용할 수 있는 방법을 제안하였다. 제안 논문에서는 특정 개체 인식 전·후의 EEG 신호를 측정하여 사용자가 특정 개체를 인식하였을 때의 EEG 신호를 사용자 인증 수단을 활용할 수 있는 방법을 제안하였다.
Recently, biometric technology has begun to be used as a fusion of IT technology and financial system. Using this biometric technology, FIDO(Fast Identity Online) technology, Samsung and Apple started Samsung Pay and Apple Pay service. FIDO authentication technology replaces existing authentication methods such as passwords. Among the biometric technologies, fingerprint recognition technology is attracting attention because it can minimize the device and user rejection at a relatively low price. However, fingerprint information has a limited number of users and it can not be reused if fingerprint information is leaked by an external attacker. Therefore, in this paper, we propose a method to authenticate a user using EEG signal which is one of biometrics technologies. W propose a method to use EEG signal measurement value in FIDO system by using convenience channel by using short channel EEG device. And propose a method to utilize EEG signal when the user recognizes a specific entity by measuring the EEG signal before and after recognizing a specific entity.
중소기업융합학회 융합정보논문지(구 중소기업융합학회논문지) 제4권 제3호 2014.09 pp.21-31
※ 기관로그인 시 무료 이용이 가능합니다.
4,200원
스마트기기에서 스마트뱅킹, 인터넷쇼핑, 비접촉거래 등의 지급결제 거래가 급증함에 따라 모바일 OS의 취 약점, 인증서 오남용 문제 등의 보안상의 문제가 대두되며, 이에 대처할 수 있는 강력한 개인 인증 수단이 요구된다. 이와 같은 상황에 대처하기 위한 인증 수단으로 바이오인식정보와 더불어 PKI를 이용한 OTP를 적용하고자 한다. 바이오인식정보는 분실이나 도용의 위험이 적으며 OTP를 이용한다면 바이오인식정보만을 이용할 때 보다 보안성이 강화될 수 있다. 이에 본 논문에서는 모바일 기기에서 바이오인식정보와 OTP를 이용한 개인 인증 기법을 제안한다.
According to increasing of payment and settlements like smart banking, internet shopping and contactless transaction in smart device, the security issues are on the rise, such as the vulnerability of the mobile OS and certificates abuse problem, we need a secure user authentication. We apply the OTP using biometrics and PKI as user authentication way for dealing with this situation. Biometrics is less risk of loss and steal than other authentication that, in addition, the security can be enhanced more when using the biometric with OTP. In this paper, we propose a user authentication using biometrics and OTP in the mobile device.
스마트 그리드 기반 엣지 컴퓨팅 환경에서 블록체인을 이용한 사용자 인증 기법 KCI 등재
한국융합보안학회 융합보안논문지 제22권 제1호 2022.03 pp.71-79
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
정보기술과 전력 공급 시스템을 결합하여 전력 공급자와 소비자 간의 실시간 정보 교환을 통해 에너지 효율을 극대화하는 스마트 그리드 시스템이 등장했습니다. 최근 스마트 그리드 시스템에서 다양한 인증 기법이 제안되고 있다. 스마트 그리드를 위한 중앙 클라우드 서버와 IoT 기기 간의 전력 관련 정보를 수집 및 저장하고 데이터를 처리하는 블록체인 기술과 엣지 서 버의 아키텍처. 스마트 그리드 환경에서 보안을 강화하기 위해 인증 방식이 제안되고 있지만 여전히 많은 취약점이 보고되고 있다. 본 논문은 블록체인을 이용한 엣지 컴퓨팅 기반의 스마트 그리드에서 사용자의 프라이버시와 익명성을 보장하기 위한 새로운 상호 인증 기법을 제시한다. 제안된 방식에서는 키 자료 업데이트 및 폐기와 같은 키 관리의 효율성을 위해 스마트 계 약을 사용합니다. 마지막으로 제안하는 기법이 사용자의 스마트 그리드-IoT 기기와 에지 서버 간의 세션 키를 안전하게 설정 함과 동시에 익명성을 보장함을 증명한다.
The smart grid system has emerged to maximize energy efficiency through real-time information exchange between power providers and consumers by combining information technology and power supply systems. Recently, various authentication schemes in a smart grid system have been proposed. Blockchain technology and an edge server's architecture to collect and store electric power-related information and process data between a central cloud server and IoT devices for the smart grid. Although authentication schemes are being proposed to enhance security in the smart grid environment, many vulnerabilities are still reported. This paper presents a new mutual authentication scheme to guarantee users' privacy and anonymity in a smart grid based on edge computing using blockchain. In the proposed scheme, we use the smart contract for the key management's efficiency, such as updating and discarding key materials. Finally, we prove that the proposed scheme not only securely establishes a session key between the smart grid-IoT device of the user and the edge server but also guarantees anonymity.
u-health 시스템을 이용한 사용자 인증 프레임워크 설계 KCI 등재
한국디지털정책학회 디지털융복합연구 제13권 제5호 2015.05 pp.219-226
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
OTP(One Time Password)는 인터넷 뱅킹 등에서 사용자의 인증을 위해서 많이 사용되는데 이를 위해 사용 자는 OTP 발생기 또는 보안 카드 등을 소지하여야 한다. 또한 OTP 발생기 또는 보안 카드를 분실하였을 경우 OTP 가 노출될 수 있는 가능성이 있다. 본 논문은 사용자 인증을 위해 사용되는 OTP 분실 및 복제에 대한 단점을 대체 하기 위해서 USN의 한 분야인 u-Health의 다양한 기술을 이용하여 수집된 개인의 건강 정보를 활용한 사용자 인증 프레임워크를 제안한다. 본 논문에서 제안하는 사용자 인증 프레임워크는 분실 위험이 없으며, 개인의 건강 상태가 매일 달라지기 때문에 여러 가지 항목들을 조합한다면 충분히 OTP로서의 활용 가치가 있다. 또한 제안하는 프로토 콜은 신뢰하는 기관들의 인증서로 암호화되어 서비스 제공자에게 전달되기 때문에 노출에 안전하며 OTP 생성을 위 한 기기 및 카드를 소지할 필요가 없기 때문에 기존 OTP를 사용하는 은행, 쇼핑몰, 게임 사이트 등에서 유용하게 사용할 수 있다.
OTP(One Time Password) is for user authentication of Internet banking and users should carry their security card or OTP generator to use OTP. If they lost their security card or OTP generator, there is at risk for OTP leak. This paper suggests a new User Authentication Framework using personal health information from diverse technology of u-Health. It will cover the problem of OTP loss and illegal reproduction A User Authentication Framework is worthy of use because it uses various combinations of user’s physical condition which is inconstant. This protocol is also safe from leaking information due to encryption of reliable institutes. Users don’t need to bring their OTP generator or card when they use bank, shopping mall, and game site where existing OTP is used.
멀티 클라우드 환경을 위한 OpenID 기반의 사용자 인증 기법 KCI 등재
한국디지털정책학회 디지털융복합연구 제11권 제7호 2013.07 pp.215-223
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
클라우드 컴퓨팅이 활성화됨에 따라 다양한 클라우드 서비스가 보급되고 있다. 하지만 각각 서로 다른 클라우드 서비스를 사용하려면 각각의 서비스에 개별적인 사용자 인증과정을 수행해야만 한다. 따라서 절차가 번거로울 뿐만 아니라 거듭된 인증 과정 수행으로 인한 비밀번호 노출, 각 클라우드 서버마다 사용자의 인증 정보를 소유해야 하는 데이터베이스의 과부하, 서비스마다 각기 다른 인증방법과 개인정보 입력방법으로 인한 피싱공격 등의 보안 문제점이 발생할 가능성이 높다. 따라서 다양한 클라우드 서비스를 사용하고자 할 때 사용자의 자격증명을 신뢰할 수 있는 ID제공업체에 의해 티켓을 제공받아 안전하게 멀티 클라우드 환경에 적용이 가능한 OpenID 기반의 사용자 인증 기법을 제안한다.
As cloud computing is activated, a variety of cloud services are being distributed. However, to use each different cloud service, you must perform a individual user authentication process to service. Therefore, not only the procedure is cumbersome but also due to repeated authentication process performance, it can cause password exposure or database overload that needs to have user's authentication information each cloud server. Moreover, there is high probability of security problem that being occurred by phishing attacks that result from different authentication schemes and input scheme for each service. Thus, when you want to use a variety of cloud service, we proposed OpenID based user authentication scheme that can be applied to a multi-cloud environment by the trusted user's verify ID provider.
4,200원
IoT에서 무선 센서 네트워크는 데이터를 실시간으로 수집하고 전송하는 중요한 역할을 한다. 무 선 센서 네트워크는 소형의 센서 노드들이 무선 통신을 통해 상호 연결되어 데이터를 수집하고 전송하 는 형태의 네트워크이다. 이러한 무선 센서 네트워크는 센서 노드를 주로 응용 환경에 배치하고, 자율 적으로 네트워크를 형성한 후, 센서 노드로부터 얻은 물리적 정보들을 무선으로 수집하여 감시, 제어 등의 용도로 활용하는 기술이다. 하지만 센서 노드는 무선 통신을 사용하기 때문에 공격자가 도청, 중 간자 공격 등을 사용해서 센서 노드에서 데이터를 가져갈 수 있다. 따라서 무선 센서 네트워크의 사용 자 인증 및 키 합의 프로토콜은 중요한 연구 분야이다. 본 논문에서는 Tyagi 등이 제안한 무선 센서 네 트워크의 취약점을 보완한 인증 방식을 제안하고, 이에 대한 보안 분석을 한 결과 Stolen smart card attack, Offline password guessing attack, Identity guessing attack, Insider attack, User forgery attack 등 여러 공격에 안전하고, 제안한 프로토콜은 계산 비용, 통신 비용 측면에서도 효율적이다.
In IoT, Wireless Sensor Networks (WSNs) play a crucial role in the real-time collection and transmission of data. A wireless sensor network is a network in which small sensor nodes are interconnected through wireless communication to collect and transmit data. This wireless sensor network is a technology primarily deployed by situating sensor nodes in various application environments. After autonomously forming a network, it collects physical information wirelessly from sensor nodes and utilizes it for purposes such as monitoring and control. However, since sensor nodes use wireless communication, attackers can potentially eavesdrop on or intercept data from sensor nodes using methods such as man-in-the-middle attacks. Therefore, user authentication and key agreement protocols in wireless sensor networks stand out as crucial areas of research. In this paper, we propose an authentication method that addresses vulnerabilities identified by Tyagi et al. in wireless sensor networks. The security analysis results demonstrate that the proposed protocol is resilient against various attacks, including stolen smart card attack, offline password guessing attack, identity guessing attack, insider attack, and user forgery attack. Furthermore, the proposed protocol proves to be efficient in terms of computational and communication costs.
협업을 위한 클라우드 스토리지에서의 사용자 인증과 데이터 보호에 관한 연구 KCI 등재
한국디지털정책학회 디지털융복합연구 제12권 제9호 2014.09 pp.153-158
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
협업을 위한 클라우드 스토리지란 협업에 참여하는 사용자들이 클라우드 스토리지를 공유하여 이용하는 것 을 말한다. 협업에 이용되는 클라우드 스토리지는 여러 사람이 새로운 데이터를 저장하고 다른 사용자의 저장된 데 이터를 읽을 수 있기 때문에 협업에 참여하는 사용자에 대한 인증과 데이터 보호의 문제가 일반의 그것보다 더 중 요하다 할 것이다. 이에 본 논문에서는 협업을 위한 클라우드 스토리지를 공유하는 사용자에 대한 인증 방법과 저장 된 데이터를 보호하는 방법을 제안하고자 한다.
The Collaborative Cloud Storage is that several members of collaborating group together use data stored in a storage. Therefore, it is obvious that it is more complicated and important to protect data stored in the sharing storage than general cloud storage, not Collaborative Cloud Storage. this paper proposes a method for user authentication and data protection.
모바일 상거래 플랫폼에 적합한 음성 템플릿 기반의 사용자 인증 기법 KCI 등재
한국디지털정책학회 디지털융복합연구 제10권 제5호 2012.06 pp.215-222
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
전화 기능과 컴퓨터 기능을 갖는 스마트폰의 보급으로 장소에 구애받지 않는 모바일 상거래에 대한 수요가 급증하고 있다. 상거래 서비스는 인증 기법을 적용하여 거래 내용과 거래 당사자에 대한 법적 구속력을 갖는 증거를 남겨야 한다. 스마트폰은 개인용 컴퓨터와 달리 개인정보 노출의 위험이 있고 기기 분실 및 도용에 따른 대리 인증이 상대적으로 쉽다. 기존의 패스워드 및 토큰 기반의 인증 기법은 사용자와 아이디를 물리적으로 연결시키지 못하므로 대리 인증 문제를 해결할 수 없다. 따라서 스마트폰을 모바일 상거래 플랫폼으로 활용하기 위해서는 법적 구속력이 있고 대리 인증이 어려운 새로운 사용자 인증 기법에 대한 연구가 필요하다. 본 논문에서는 사용자 고유 음성 정보와 스마트폰 USIM 정보를 접목한 모바일 ID를 생성하고 이에 기반을 둔 사용자 인증 기법을 설계 및 구현하였다.
A smart phone has functions of both telephone and computer. The wide spread use of smart phones has sharply increased the demand for mobile commerce. The smart phone based mobile services are available anytime, anywhere. In commercial transactions, a digital signature scheme is used to make legally binding signature to prove both integrity of commercial document and verification of the signer. Smart phones are more risky compared with personal computers on the problems of how to protect privacy information. It’s also easy to let proxy user to authenticate instead of the smart phone owner. In existing password or token based schemes, the ID is not physically bound to the owner. Thus, those schemes can not solve the problem of proxy authentication. To utilize the smart phone as the platform of mobile commerce, a study on the new type of authentication scheme is needed where the scheme should provide protocol to get legally binding signature and not to authenticate proxy user. In this paper, we create the mobile ID by using both the USIM and voice template of the smart phone owner. We also design and implement the user authentication scheme based on the mobile ID.
모바일 환경에서 OTP기술과 얼굴인식 기술을 이용한 사용자 인증 개선에 관한 연구 KCI 등재후보
한국융합보안학회 융합보안논문지 제11권 제3호 2011.06 pp.75-84
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
모바일 기술의 급격한 발전으로 스마트폰 사용이 확산되고 있다. 미래의 모바일 뱅킹 시장 활성화를 위해서 무엇보다 중요하고 우선시되는 것은 안전한 금융 거래이다. 그러나, 스마트폰 확산에 비례하여 검증되지 않은 많은 앱들이 개발되고 있는 상황에서 보안 위협은 높아질 수 밖에 없다. 현재 스마트폰 금융 거래 방식은 기존 공인인증서나 OTP기술을 그대로 모바일 환경에 적용하고 있으나, 많은 보안 문제점이 꾸준히 지적되고 있다. 본 논문은 다단계 인증 방법을 통해 보안성을 강화하고 물리적 부인방지 기능을 제공함으로써 기존의 인증 방식의 보안성을 개선하고자 한다.
With the rapid development of mobile technology the use of smartphone is spreading. In order to activate mobile banking and market in the future, the most important key is a secure financial transactoin. However, because many apps are developed without security check in proportional to the spread of smartphone, security threat is inevitably high. Current smartphone banking is processed as the way of the existing public certificate or OTP technique in the mobile environment, but many security hole about current technology is pointed out steadily. Therefore, in this paper we are to improve a existing security hole by reinforcing the security through multi-factor authentication and providing a physical non-repudiation.
스마트카드 및 동적 ID 기반 전기 자동차 사용자 인증 스킴 KCI 등재
한국디지털정책학회 디지털융복합연구 제11권 제7호 2013.07 pp.141-148
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
스마트그리드는 정보통신기술을 이용하여 전력공급자와 소비자의 양방향통신을 가능하게 한다. 또한 동적인 전력 공급이 가능하기 때문에 전기 자동차 기술과 접목시킬 경우 전기 자동차 충전 인프라를 활성화시키고 전기 자동차의 배터리를 가정용 축전지로 활용하여 재판매할 수도 있다. 이러한 전기 자동차 충전 인프라는 가정, 아파트, 건물, 기타 충전소 등에 고정적으로 위치하여 있고 사용자만 유동적으로 서비스를 이용한다. 만약 유동적으로 서비스를 이용하는 사용자에 대해 인증이 이루어지지 않을 경우 전력 서비스의 불법적인 사용, 전력 정보 유출, 불법적인 전력 요금 변경 등의 피해가 발생할 수 있다. 본 논문에서는 스마트그리드 환경에서 안전하게 전기 자동차 관련 서비스를 이용하기 위해 스마트카드 및 동적 ID 기반 사용자 인증 스킴을 제안한다.
Smart grid can two-way communication using ICT(Information & Communication Technology). Also, smart grid can supply to dynamic power that grafted to electric vehicle can activate to electric vehicle charging infrastructure and used to storage battery of home. Storage battery of home can resale to power provider. These electric vehicle charging infrastructure locate fixed on home, apartment, building, etc charging infrastructure that used fluid on user. If don't authentication for user of fluid user use to charging infrastructure, electric charging service can occurred to illegal use, electric charges and leakgage of electric information. In this paper, we propose smartcard and dynamic ID based user authentication scheme for used secure to electric vehicle service in smart grid environment.
사용자 인증을 위한 딥러닝 기반 얼굴인식 기술 동향 KCI 등재후보
대한산업경영학회 산업융합연구(구 대한산업경영학회지) 제17권 제3호 2019.09 pp.23-29
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
차이가 나는 물체를 구별하는 물체인식과 달리, 얼굴인식은 유사한 패턴을 가진 얼굴의 Identity를 구별한다. 이에 따라 LBP, HOG, Gabor과 같은 특징 추출 알고리즘이 딥러닝 기반으로 대체되고 있다. 딥 러닝 기술을 활용하여 머신러닝으로 얼굴을 식별할 수 있는 기술이 발전하면서 다양한 분야에서 얼굴인식 기술이 활용되고 있다. 특히, 금융 거래 외에도 사용자 식별이 필요한 다양한 오프라인 환경에서 활용되어 세밀하고 개인에 적합한 서비스가 제공될 수 있다. 얼굴 인식 기술은 스마트 미러와 같은 장치를 통해 손쉽게 사용자 인증을 하고, 식별이 된 사용자에게 서비스를 제공할 수 있는 기술로 발전할 수 있다. 본 논문에서는 사용자 인증의 다양한 기법 중에서 얼굴인식 기술에 대한 조사 및 파이썬으로 작성된 얼굴인식 사례 소스 분석과 얼굴인식 기술을 활용한 다양한 서비스의 가능성을 제시하고자 한다.
Object recognition distinguish objects which are different from each other. But Face recognition distinguishes Identity of Faces with Similar Patterns. Feature extraction algorithm such as LBP, HOG, Gabor is being replaced with Deep Learning. As the technology that identify individual face with machine learning using Deep Learning Technology is developing, The Face Recognition Technology is being used in various field. In particular, the technology can provide individual and detailed service by being used in various offline environments requiring user identification, such as Smart Mirror. Face Recognition Technology can be developed as the technology that authenticate user easily by device like Smart Mirror and provide service authenticated user. In this paper, we present investigation about Face Recognition among various techniques for user authentication and analysis of Python source case of Face recognition and possibility of various service using Face Recognition Technology.
스마트 폰에서 레코딩 공격에 강한 입력된 PIN의 마지막 문자 표시 기법 KCI 등재
대한산업경영학회 산업융합연구(구 대한산업경영학회지) 제23권 제6호 2025.06 pp.59-66
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
스마트 폰의 보급으로 PC 대신 모바일 단말기를 정보 검색 및 금융 등 다양한 서비스가 제공되고 있다. 특히, 금 융거래와 같은 서비스는 거래 주체 확인을 위한 사용자 인증이 반드시 선행되어야 한다. 단말기에 다양한 센서가 부착 되어 다양한 인증 수단을 통해 인증을 하고 있다. 생체인증과 같은 인증기법은 잘못된 인증 가능성이 존재하기 때문에 PIN과 같이 사용자만이 알 수 있는 정보를 통해 인증을 추가로 요구한다. 공동인증서나 비밀번호, PIN 등의 인증 정보 를 입력할 때 단말기의 터치스크린의 크기 제한으로 잘못된 문자를 입력할 수 있다. 잘못된 입력을 막기 위해 마지막 비밀번호 문자를 사용자에게 보여주고 있지만 이것으로 인해 훔쳐보기나 레코딩 공격이 가능하다. 현재는 한 줄로 입력 한 문자가 표시되지만 제안 기법에서는 2줄 이상의 출력 영역에 입력된 문자와 그 주변 문자를 출력하는 기법이다. 디스플레 이 영역에 2~3개 줄로 마지막 문자를 보여줌으로 사용자가 옳게 입력했는지 바로 확인할 수 있지만 공격자는 2~3개의 문자 가 보이기 때문에 어느 문자를 터치한 것인 확률적으로 일부만 알 수 있어 훔쳐보기나 레코딩 공격으로부터 안전한 인증이 가능하다.
With the widespread adoption of smartphones, mobile devices have increasingly replaced PCs in providing various services such as information retrieval and financial transactions. In particular, services involving financial transactions require user authentication to verify the identity of the transaction party. Modern devices are equipped with various sensors that support diverse authentication methods. However, biometric authentication methods can be prone to errors, and therefore often require an additional layer of authentication using information known only to the user, such as a PIN. When entering authentication information such as certificates, passwords, or PINs on mobile devices, the limited screen size of the touchscreen may lead to incorrect input. To reduce input errors, the last character of the password is typically displayed to the user. However, this approach makes shoulder surfing and recording attacks more feasible. Unlike conventional systems that display characters in a single line, the proposed method displays the entered character along with its surrounding characters across two or more lines. This layout allows users to easily verify whether they have entered the correct character while making it more difficult for attackers to identify the touched key, as only a few possible candidates are shown. As a result, the proposed method enhances the security of the authentication process against shoulder surfing and recording attacks.
핀테크 환경에서 모바일 단말기의 PIN 입력에 대한 기술 동향 분석
삶의질정보학회(구 삶의질연구회) 삶의 질 향상 연구 제1권 제1호 2023.04 pp.33-38
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
스마트 폰의 대중적인 보급으로 인해 많은 서비스가 모바일 단말기 환경에서 제공되고 있다. 특히, 스마트 폰 의 사양이 급속하게 성장하고, 통신 속도를 제공함에 따라 기존 PC 환경보다 더 빠른 처리가 가능하게 되었다. 언제 나 손 안에서 사용할 수 있는 편리성으로 인해 금융거래를 비롯한 게임, 엔터테인먼트 등 다양한 서비스를 제공하고 있다. 금융거래를 비롯한 양질의 서비스를 제공하기 위해 사용자 식별이 무엇보다 중요하다. 사용자 식별 및 인증을 위해 생체인증을 비롯한 다양한 기술이 사용되고 있다. 사용자 식별 및 인증을 위한 간단한 방법으로 PIN과 같은 패스워드 인증이 사용되고 있다. PIN이나 패스워드를 입력 하는 과정에서 훔쳐보기나 레코딩 공격 등 사회공학적 공격이 가능하다. 이를 해결하기 위해 다양한 보안 키패드 기 법들이 제안되고 있다. 안전한 보안 키패드 연구를 지속적으로 수행하기 위해 관련 논문과 관련 기술을 분석하고 그 결과를 기술하고자 한다.
Due to the popular diffusion of smartphones, many services are provided on mobile devices. Especially, as smartphone specifications have rapidly increased and communication speeds have been provided, faster processing than the existing PC environment has become possible. Various services such as finance, games, and entertainment are provided for the convenience of being able to use them in the palm of your hand. To provide quality services, especially for financial transactions, user identification is more important than anything else. Various technologies, including biometric authentication, are used for user identification and authentication. Simple methods such as password authentication like PIN are also used for user identification and authentication. social engineering attacks such as theft or recording attack are available during the process of entering a PIN or password. There are many secure keypad methods are suggested to prevent these. This study analyzes related papers and related methods to study on safe secure keypads continually.
Linux 환경에서 사용자 행위 모니터링 기법 연구 KCI 등재
한국융합보안학회 융합보안논문지 제22권 제2호 2022.06 pp.3-8
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
보안 위협은 외부에서 발생하기도 하지만 내부에서 발생하는 비율이 더 높다. 특히 내부 사용자는 정보 서비스에 대한 정 보를 인지하고 있기에 보안 위협에 의한 피해는 더욱 커진다. 이러한 환경에서 중요 정보 서비스에 접근하는 모든 사용자의 행위는 실시간으로 모니터링되고 기록되어야 한다. 그러나 현재 운영체제는 시스템과 Application 실행에 대한 로그만을 기록 하고 있어, 사용자의 행위를 실시간으로 모니터링하기에는 한계가 있다. 이러한 보안 환경에서는 사용자의 비인가 행위로 인 한 피해가 발생할 수 있다. 본 연구는 이러한 문제점을 해결하기 위하여, Linux 환경에서 사용자의 행위를 실시간으로 모니터 링하는 아키텍처를 제안한다. 제안하는 아키텍처의 실효성을 확인하기 위하여 기능을 검증한 결과, 운영체제에 접근한 모든 사용자의 console 입력값과 출력값을 모두 실시간으로 모니터링하고 이를 저장한다. 제안한 아키텍처의 성능은 운영체제에서 제공하는 식별 및 인증 기능보다는 다소 늦지만, 사용자가 인지할 수준은 아닌 것으로 확인되어, 충분히 실효적이라고 판단되었다.
Security threats occur from the outside, but more often from the inside. In particular, since the internal user knows abo ut the information service, the security threat damage caused by the internal user is greater. In this environment, the actio ns of all users accessing information services should be monitored and recorded in real-time. However, the current operati ng system records only the logs of system and application execution, so there is a limit to monitoring user behavior in rea l-time. In such a security environment, damage may occur due to user's unauthorized actions. To solve this problem, this study proposes an architecture that monitors user behavior in real-time in a Linux environment. As a result of verifying t he function to confirm the effectiveness of the proposed architecture, the console input values and output angles of all user s who have access to the operating system are monitored in real-time and stored. Although the performance of the propos ed architecture is somewhat slower than the identification and authentication functions provided by the operating system, i t was confirmed that the performance was not at a level that users would recognize, and thus it was judged to be sufficie ntly effective. However, since this study focuses on monitoring the console behavior, it is impossible to monitor the behavi or of user applications running in the background, so additional research is needed.
5G 이동망과 ATSC 3.0 방송망 연동 동향 및 방안 KCI 등재
한국융합보안학회 융합보안논문지 제20권 제3호 2020.09 pp.47-52
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
방송 분야에서의 가상화 기술도입은 방송산업 생태계 전반에 걸쳐 IT 자원의 효과적인 운영을 기반으로 방송 서비스 자동화 및 지능화가 활발하게 진행되고 있다. 최근에는 방송망 인프라의 네트워크 가상화를 통해 다양한 방송 자원의 유연성을 높이고 다른 망과의 연동 효율성을 높이고자 하는 관심이 높아지고 있다. 방송망에서 IP 패러다임으로의 근본적인 변환은 인터넷 기반 서비스 플랫폼들과 5G 망과의 효과적인 연동과 신규 융합 서비스 개발을 위한 여러 가지 문제를 해결해야 하는 상황에 직면하고 있다. 즉, 이처럼 ATSC 3.0으로 대표되는 차세대 방송망과 5G 대표되는 이동통신망, 인터넷과의 유기적, 효과적인 연동을 위해서는 수많은 난제를 해결해야 하는 상황이다. 본 논문에서는 ATSC 3.0 방송망과 5G로 대표되는 이동통신망과의 융합을 위한 기본 기술 및 현황을 살펴보고, ATSC 3.0 방송망과 5G 망이 서로 망대 망으로 연동하려는 방안에 관해서 기술하였다.
The introduction of virtualization technology in the broadcasting field is actively progressing broadcasting service auto mation and intelligence based on the effective operation of IT resources throughout the broadcasting industry ecosystem. In recent years, there is increasing interest in increasing the flexibility of various broadcasting resources and increasing t he efficiency of interworking with other networks through network virtualization of the broadcasting network infrastructu re. The fundamental transformation from the broadcasting network to the IP paradigm is facing a situation where it is ne cessary to solve various problems for the effective interworking of Internet-based service platforms and 5G networks and the development of new convergence services. In other words, for organic and effective interworking with the next-gener ation broadcasting network represented by ATSC 3.0, a mobile communication network represented by 5G, and the Intern et, a number of difficulties must be solved. In this paper, the basic technology and status for the convergence of ATSC 3. 0 broadcasting network and mobile communication network represented by 5G was examined, and a plan for the ATSC 3.0 broadcasting network and 5G network to interwork with each other as a network was described.
Key-Stroke 기반 Two-Factor 인증 기술 KCI 등재
한국융합보안학회 융합보안논문지 제20권 제3호 2020.09 pp.29-37
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
ID/Password 기반 인증기술은 간편하면서 일정한 보안수준을 제공하기에 대부분의 시스템에서 사용되고 있 으나, 이미 무수히 많은 개인정보 노출사고가 있었으며, 무엇보다 한번 노출된 패스워드를 회수하기 어렵다. 이 에, 다양한 two-factor 인증기법들이 도입되었으나, 이들은 많은 비용이 필요하며, 무엇보다 사용자의 불편함을 초래하게 된다. 본 논문에서는 기존과 같이 단 한번의 ID/Password 인증과정에서 사용자마다 고유한 Key-Stroke를 동시에 인증하여 비용대비 효과적이면서, 사용자의 불편함을 초래하지 않고, ID/Password 노출 시에도 Key Stroke Dynamics 패턴이 달라 실패하여 높은 보안성을 보장할 수 있는 기술을 제안한다. 본 논문의 제안 모델은 시스템으로 구축하여 효과성을 확인하였다.
Password based authentication technology is yet certain and id to provide a level of security being used in most systems, but already a myriad of personal information exposure to the accident. Above all, and once exposed, it is difficult to recover the password. Thus, the various authentication techniques - factor two was introduced, but they are expensive and discomfort to users, to lead. In this paper, the existing unique to users in such a single accreditation process / password id key - stroke, user authentication and cost effectively and at the same time. And not cause discomfort, suggested technologies that can also ensure high security exposure, password id. This paper's proposals and determine the effectiveness of the system to build model.
전염성 확산 차단을 위한 음성인식 기반의 출입통제시스템 설계 KCI 등재
한국융합학회 한국융합학회논문지 제11권 제7호 2020.07 pp.19-24
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
WHO는 3월 11일 코로나 19에 대한 세계적 대유행, 팬더믹(pandemic)을 선언하였다. 하지만 경제 및 사회적 활동으로 인하여 면대면 교육이나 세미나를 위해 건물 출입을 해야하는 상황이 발생한다. 코로나 19의 감염여부의 1차 체크 방법으로 체온 측정이 있어 근거리 체온 측정을 통해 1차적인 출입 차단을 실시하고 있다. 그로 인해 일일이 직접 체크하는 것이 번거롭기 때문에 열화상 카메라를 건물 입구에 설치하고, 적외선 카메라를 이용하여 간접적으로 체온을 측정하여 출입 통제를 하고 있다. 중고교나 대학 및 평생교육의 경우 출석체크 등과의 연동이 가능하고, 마스크 착용 여부를 자동으로 인식하고, 수강생의 인증이 가능한 시스템이 필요하다. 제안시스템은 스마트미러에 탐재된 카메라로 마스크 착용 여부를 확인하고, 음성인식 기술을 활용하여 건물안으로 들어오고자 하는 사용자의 목소리 인식을 통해 사용자를 인증하고, 출입 여부를 결정하는 시스템을 제안하고자 한다. 제안 시스템은 근거리 온도 측정과 수강생의 스마 트 폰의 출석체크 APP와 연동을 하게 되면 출석체크도 가능하다.
WHO declared a global pandemic on March 11th for Corona 19. However, there is a situation where you have to go to building for face-to-face education or seminars for economic and social activities. The first check method of COVID-19 infection is to measure body temperature, so the primary entrance and exit is blocked for near-field body temperature measurement. However, since it is troublesome to check directly, thermal camera is installed at the entrance of the building, and body temperature is measured indirectly using the infrared camera to control access. In case of middle and high schools, universities, and lifelong education center, we need a system that is possible to interoperate with attendance checks and automatically recognizes whether to wear masks and can authenticate students. We proposed the system that is to confirm whether to wear a mask with a camera that is embedded in a smart mirror, and that authenticates the user through voice recognition of the user who wants to enter the building by using voice recognition technology and determines whether to enter them or not. The proposed system can check attendance if it is linked with near-field temperature measurement and attendance check APP of student's smart phone.
무작위적인 그래픽 코드를 이용한 인증 알고리즘 KCI 등재
한국융합학회 한국융합학회논문지 제10권 제12호 2019.12 pp.63-69
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
스마트폰을 이용하면 쉽고 빠르게 인증과 결제가 가능하다. 하지만 스마트폰 보안 위협이 다양하고 새로운 해킹 기술로 진화하고 있고 모바일 환경에 특화된 공격 형태로 변화하고 있다. 따라서 모바일 환경에 적합한 인증방법이 요구 되고 있다. 현재 지식기반 인증의 보안 취약점을 해결하기 위한 방법으로 금융, 게임, 로그인 등 인증 서비스를 제공하기 위해서 많은 업체에서 일회용 비밀번호(One Time Password)와 같은 2단계 인증 서비스를 제공하고 있다. OTP 서비 스는 사용하기 쉽지만 난수표에 대한 복제가 용이하며 제한시간 내에는 유효한 값으로 사용되기 때문에 재사용이 가능 한 단점이 존재한다. 본 논문에서는 스마트폰의 전용 애플리케이션을 통해 특수 문자를 인식한 인증 방법을 이용하여 이용자가 높은 보안성을 가지고 쉽고 빠르게 인증을 진행할 수 있는 매커니즘에 대해서 제안한다.
Using a smartphone allows quick and easy authentication and payment. However, smartphone security threats are evolving into a variety of new hacking technologies, and are changing to attacks specific to the mobile environment. Therefore, there is a demand for an authentication method suitable for a mobile environment. In order to solve security weaknesses in knowledge-based authentication, many companies provide two-step authentication services such as OTP(One Time Password) to provide authentication services such as finance, games, and login. Although OTP service is easy to use, it is easy to duplicate random number table and has a disadvantage that can be reused because it is used as valid value within time limit. In this paper, we propose a mechanism that enables users to quickly and easily authenticate with high security using the authentication method that recognizes special characters through smartphone's dedicated application.
사물인터넷 환경에서 MQTT Broker를 활용한 지속-재인증 프로토콜 설계 KCI 등재
한국차세대컴퓨팅학회 한국차세대컴퓨팅학회 논문지 Vol.15 No.4 2019.08 pp.69-79
사물인터넷이 발전함에 따라 시대가 지날수록 이용하는 기기들의 수는 기하급수적으로 늘어나고 있다. 이러한 기기 들은 서로 데이터를 주고받으며 유용한 정보를 사용자에게 제공한다. 그러나 사물인터넷 기기들은 소형화 및 저전력 형태로 설계하기 때문에 연산능력에 한계가 있어 기존의 보안기술을 적용시키기 어렵다. 이로 인해 사물인터넷 환경 의 이용자나 기기에 대한 안전한 인증기술에 대한 연구가 활발히 진행되고 있다. 본 논문에서는 사용자가 설정한 방 식에 맞추어 지속적으로 사물인터넷에 지속-재인증하는 프로토콜에 대해 기술한다. 사용자는 게이트웨이를 통해 사 물인터넷 기기에 연결하기 위한 Access Token과 Refresh Token을 발급받은 후 토큰을 활용하여 지속적으로 재 인증하여 신뢰된 사용자인지 검증받도록 한다. 이 프로토콜을 활용하면 Access Token이 만료되어도 처음부터 재 발급하는 과정을 거치는 것이 아니라 Refresh Token을 활용하여 Access Token을 계속 사용할 수 있도록 만듦으 로써 기존의 연결을 지속해서 이어나갈 수 있다.
As the Internet of Things develops, the number of devices used increases exponentially. These devices exchange data with each other and provide useful information to users. However, it is difficult to apply existing security technologies as Internet of Things devices are designed in the form of miniaturization and low power. As a result, research on security authentication technology of users and devices is being carried out actively in the Internet of Things environment. This paper describes the protocol that continuously refortifies the Internet of Things according to the method set by the user. Users receive access tokens and refresh tokens to connect to IoT devices through a gateway, and continually re-certify the token to see if the user is a trusted user. This protocol allows you to continue with existing connections by making the access token available continuously using the refresh token instead of running the process again, even if the access token expires.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.