Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 42
No
1

4,000원

최근 센서를 이용한 장치들의 사용은 증가추세이다. 이런 센서 장치들은 이종무선 센서네트워크 환경에서 최신 기술 들과 연관 지어 폭발적으로 증가하고 있다. 이런 환경에서 센서디바이스의 사용은 우리에게 편리함을 제공하기는 하나 여러 형태의 보안위협이 도사리고 있는 실정이다. 무선선서네트워크를 이용하여 원격으로 접속하여 제공받는 서비스에 존재하는 보안위협 중 대부분은 전송되는 정보의 유출과 사용자, 센서, 게이트웨이 사이의 인증에 대한 손실이 대부분이 다. 2019년 Chen 등이 이종무선 센서 네트워크에 안전한 사용자 인증 프로토콜을 제안하였다. 그러나 Ryu 등이 제안한 논문에서 그들이 제안 프로토콜은 password guessing attack과 session key attack에 취약하다는 것을 주장하였다. 본 논문은 이전에 제안된 논문의 취약점을 개선하여 더욱 안전하고 효율적인 사용자 인증 프로토콜을 제안하였다.

Recently, the use of sensor devices is gradually increasing. As various sensor device emerge and the related technologies advance, there has been a dramatic increase in the interest in heterogeneous wireless sensor networks (WSNs). While sensor device provide us many valuable benefits, automatically and remotely supported services offered and accessed remotely through WSNs also exposes us to many different types of security threats. Most security threats were just related to information leakage and the loss of authentication among the involved parties: users, sensors and gateways. An user authentication protocol for wireless sensor networks is designed to restrict access to the sensor data only to user. In 2019, Chen et al. proposed an efficient user authentication protocol. However, Ryu et al. show that it’s scheme still unstable and inefficient. It cannot resist offline password guessing attack and session key attack. In this paper, we propose an improved protocol to overcome these security weaknesses by storing secret data in device. In addition, security properties like session-key security, perfect forward secrecy, known-key security and resistance against offline password attacks are implied by our protocol.

2

The Analysis of CCTV Hacking and Security Countermeasure Technologies : Survey KCI 등재

Sunghyuck Hong, Sae-Young Jeong

중소기업융합학회 융합정보논문지(구 중소기업융합학회논문지) 제8권 제6호 2018.12 pp.129-134

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

최근 부각되고 있는 사생활유출범죄 유형 중 CCTV 해킹을 이용한 범행에 대한 것이다. 요즘 CCTV를 사용이 증가함에 따라 악의적인 해커들은 CCTV를 사생활유출수단으로써 이용하고 있다. 그러나 이러한 CCTV 해킹을 통한 범죄 가 늘어나고 있는 반면 일반 사용자들의 보안의식 수준은 현저히 낮았고, 국가적 차원에서의 대응·대책 또한 부실한 상황이 다. 따라서 이번 연구논문을 통해 CCTV 해킹을 방지할 수 있는 여러 보안기술에는 중 사용자 인증 프로토콜, SSH 터널링 을 통한 원격접속, 미디어 암호화 알고리즘 등을 소개하고, 최근에 출시된 기술로는 우경정보기술사의 SecuWatcher for CCTV, 노르마사의 CCTV Care 앱, 마크애니사의 Password SAFERTM for CCTV 등을 분석하여 대응책을 제시하여 CCTV 해킹으로부터 피해를 줄이기 위한 제안을 하였다.

This is about the CCTV hacking which is one of the recently emerging privacy-spilling crime. Recently, the usage of CCTV is being increased, and Black Hat Hackers spill the individual’s privacy by hacking it. However, That crime is being increased. However, most users rarely fulfill the security management ,and the government’s measures are insufficient. Therfore, this research report implies some security technologies including user authentication protocols such as SSH Tunneling and Media Encryption Algorithm. and recently developed technologies including Wookyeong Information Technology’s SecuWatcher for CCTV, Norma’s CCTV Care App, and MarkAny’s Password SAFERTM for CCTV.

3

익명성을 보장하는 IoT 기반 헬스케어 사용자 인증 프로토콜의 취약점 분석 KCI 등재

성재현, 이학준, 최윤성

한국융합보안학회 융합보안논문지 제24권 제4호 2024.10 pp.49-58

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

인터넷의 발전으로 PC, 모바일을 넘어 다양한 사물과 통신하는 IoT의 시대에 이르렀다. 특히 의료 서비스에서의 활용은 웨 어러블 기기 시장의 성장과 맞물려 심박수, 운동량, 수면 패턴과 같은 다양한 건강정보를 쉽게 실시간으로 수집하고 의사는 이를 활용해 환자의 정보를 분석하여 진료와 처방하고 있다. 이 과정에서 통신 간의 환자의 개인정보와 수집한 생체 정보가 노출되지 않도록 하는 통신의 보안성 또한 중요하게 관리해야 하는 부분이 되었다. 그중 IoT 의료 시스템의 보안성을 위한 프 로토콜을 Masud 등이 제안하였다. 이후 Chen, Chien-Ming 등은 Masud 등이 제안한 프로토콜에 다양한 취약점이 있음을 확 인하고 중복된 매개 변수를 삭제하고 통신을 경량화하여 향상된 경량화 IoT 프로토콜을 제안하였다. 본 논문에서는 Chen, Chien-Ming 등이 제안한 프로토콜의 동작 과정과 취약점을 분석하여, Chen, Chien-Ming 등이 제안한 프로토콜이 Offline Password Guessing Attack, Lack of Perfect Forward Secrecy, Bit Mismatch, User Specific Error at multi User, Weak Anonymity at Update에 취약하다는 것을 밝혔다.

With the development of the Internet, we have reached the era of IoT that communicates with various things beyond P Cs and mobiles. In particular, its use in medical services,ㄴㄴ in line with the growth of the wearable device market, easil y collects various health information such as heart rate, exercise, and sleep patterns in real time, and doctors use it to ana lyze the patient's information and prescribe it for treatment. In this process, the security of communication that prevents t he patient's personal information and collected biometric information between communications has also become an importa nt part to be managed. Among them, Masud et al. proposed a protocol for the security of the IoT medical system. Since then, Chen Chien-Ming et al. have confirmed that there are various vulnerabilities in the protocol proposed by Masud et a l., and proposed an improved lightweight IoT protocol by deleting duplicate parameters and reducing communication. In thi s paper, by analyzing the operation process and vulnerabilities of the protocol proposed by Chen Chien-Ming et al., it was revealed that the protocol proposed by Chen Chien-Ming et al. is vulnerable to Offline Password Guessing Attack, Lack of Perfect Forward Secrecy, Bit Mismatch, User Specific Error at Multi User, and Weak Anonymity at Update.

4

이모빌라이저 시스템에서 스마트폰을 이용한 인증 프로토콜

신미예, 정윤수, 배우식, 이상호

중소기업융합학회 융합정보논문지(구 중소기업융합학회논문지) 제4권 제1호 2014.03 pp.41-45

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

이모빌라이저 시스템은 자동차 키에 저장된 코드와 자동차 엔진 ECU에 저장된 암호코드가 일치하는 경우에 만 자동차 시동이 걸리는 차량 도난방지 시스템이다. 이모빌라이저 시스템 자동차의 키 분실 및 차량이 도난당했을 경우 이에 대응하기 위해 스마트 폰 등을 이용 KDC와 KMC를 통하여 사용자 인증을 마친 후 새로운 비밀 번호를 부여받는 모델을 제안한다.

Only if the secret key stored in the engine ECU matches car key stored in the car, immobilizer system is a car anti-theft system that automobile engine takes. To take an action as soon in case of losing car key or being stolen, the ASPI protocol is proposed for assigning a new password after finishing user authentication by the smart phone etc. The shortcoming point of that directly bring the car to a service center in case of losing key can be complemented by the proposed protocol. In case of the car and key both are theft together, the car can be stopped soon.

5

본 논문에서는 RF 및 초음파를 이용한 새로운 무선 토큰 기반 사용자 인증 방법을 제안한다. 기존의 연구들에서는 RF를 통한 요청에 대해 초음파로 응답을 할 때 소요되는 시간을 통해 거리를 측정하였지만, 본 논문에서는 초음파를 통해 요청을 하고 RF로 응답을 함으로써 초음파로 전달하는 정보를 최소한으로 줄였으며 이를 통하여 거리를 속일 수 있는 공격의 성공 확률 또한 낮추었다. 본 논문에서는 다양한 환경에서의 인증 실험을 실시하였으며, 그 결과 제안 방법이 현실적인 환경에서는 매우 높은 인증 성공률을 보이고 극단적인 상황에서도 적절한 수준의 인증 성공률을 보임을 확인하였다.

We propose a novel user authentication protocol based on a wireless hardware token equipped with RF and ultrasound communication modules. While in previous protocols the server uses for distance bounding the time differences between an RF challenge and an ultrasonic response, we use ultrasonic challenges and RF responses. Thus we minimize the amount of information that should be transmitted through the ultrasonic channel, which reduces the possibilities of interference and vulnerabilities in distance estimation. According to our experimental results, the proposed protocol guarantees a very high success probability in a normal situation, and it shows a moderate success probability even in an extreme environment.

6

ECC 기반 원격 사용자 인증 프로토콜에 대한 취약점 분석 KCI 등재

허현준, 최윤성

한국EA학회 정보화연구 제18권 3호 2021.09 pp.229-238

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

무선 통신 기술이 급속하게 발전함에 따라 일상 생활에는 많은 변화가 일어나고 있다. IT 기술 및 인터넷 기술의 발전으로 무선 네트워크가 성장하면서 우리 생활에 많은 편의를 가져다 주었지만, IoT 기술이 다양한 온라인 위협과 공격으로부터 안전하지 않다는 것은 부정할 수 없는 상황이다. 다 양한 연구자들이 안전한 인증 및 통신을 위한 다양한 프로토콜을 제안하여 보안 문제를 개선하고 있 으며, 그 중 ECC(Elliptic Curve Cryptography)라는 상대적으로 계산량이 적으면서도 안전한 암호 방식이 사용되고 있다. 최근 Shafiq 등은 다양한 보안 취약점을 개선한 ECC 기반 원격 사용자 인증 프로토콜을 제안하면서, 제안된 프로토콜이 기존 프로토콜보다 다양한 공격에 더 효율적이고 안전하 다고 주장하였다. 본 논문에서는 Shafiq 등이 제안한 프로토콜에 대한 취약점 분석을 통하여, 이 프 로토콜이 smartcard stolen attack, lack of perfect forward secrecy, replay attack, waste of computational costs에 취약하다는 것을 밝혔다.

As wireless communication technology grows rapidly, many changes are taking place in daily life. Among them, while IoT technology has brought many conveniences to our lives as it grows wireless networks with technological advances, it cannot be denied that IoT technology is not safe from various online threats and attacks. Thus, various researchers have proposed many protocols for secure authentication and communication, improving security issues, among which a lightweight and secure cryptographic approach called Elliptic Curve Cryptography (ECC) has also been used. Recently, Shafiq et al. proposed an ECC-based remote user authentication protocol that improved various security vulnerabilities. They argued that their proposed protocol was more efficient and safe for a variety of attacks than conventional protocols. In this paper, we analyze the protocols proposed by Shafiq et al. and show that it has security problems such as smartcard stolen attack, lack of perfect forward secrecy, replay attack, and waste of computational costs.

7

사용자 편의성 및 안전성이 강화된 ZigBee 인증 프로토콜 KCI 등재

유호제, 김찬희, 임성식, 오수현

한국융합보안학회 융합보안논문지 제22권 제1호 2022.03 pp.81-92

※ 기관로그인 시 무료 이용이 가능합니다.

4,300원

빠르게 성장하고 있는 IoT 시장은 일반 가정에서뿐만 아니라 스마트홈이나 스마트시티까지 확대되고 있다. IoT에서 사용 하는 주요 프로토콜 중 ZigBee는 스마트홈의 도어락 시장에서 90% 이상 차지하고 있고 소형화된 센서 디바이스에서 주로 사 용하고 있어 프로토콜의 안전성이 매우 중요하다. 하지만, ZigBee를 사용하는 디바이스가 네트워크에 연결되는 인증과정에서 고정된 키를 사용하고 있어 전방향 안전성을 만족하지 못하고 있고, 최근에 개발한 ZigBee 3.0에서도 해결되지 못하였다. 본 논문에서는 ZigBee 인증 프로토콜에 전방향 안전성을 제공함과 동시에 기존 프로토콜에서도 빠르게 적용할 수 있는 설계방법 을 제안한다. 제안하는 개선된 ZigBee 인증 프로토콜은 IoT에서 연산량이 적고 전방향 안전성을 제공하는 ECDH를 적용하기 위해 최근 개발된 OWE 프로토콜을 분석 및 적용하였다. 이를 바탕으로 ZigBee 인증 프로토콜의 안전성을 제공하며, 별도의 인증서나 패스워드 입력이 필요하지 않아 사용자의 편의성 또한 제공할 수 있을 것으로 본다.

The rapidly growing IoT market is expanding not only in general households but also in smart homes and smart cities. Among the major protocols used in IoT, ZigBee accounts for more than 90% of the smart home's door lock market and is mainly used in miniaturized sensor devices, so the safety of the protocol is very important. However, the device using Zig Bee is not satisfied with the omnidirectional safety because it uses a fixed key during the authentication process that conn ects to the network, and it has not been resolved in the recently developed ZigBee 3.0. This paper proposes a design meth od that provides omnidirectional safety to the ZigBee authentication protocol and can be quickly applied to existing protoco ls. The proposed improved ZigBee authentication protocol analyzed and applied the recently developed OWE protocol to ap ply ECDH, which has low computational volume and provides omnidirectional safety in IoT. Based on this, it provides the safety of the ZigBee authentication protocol, and it is expected that it will be able to provide user convenience as it does not require a separate certificate or password input.

8

웹 사용자를 위한 통합 ID 인증 프로토콜에 관한 연구 KCI 등재

신승수, 한군희

한국디지털정책학회 디지털융복합연구 제13권 제7호 2015.07 pp.197-205

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

기존의 웹 인증방식은 주민등록번호를 이용하여 신용평가회사의 실명확인 데이터베이스를 통해서 인증 방식 과 주민등록번호를 이용한 인증 방식을 개선한 대체인증 수단인 아이핀 인증방식 등이 있다. 기존 인증 방식을 개선 하여 모든 웹에서 이용할 수 있는 통합 ID 인증 프로토콜을 제안한다. 제안한 인증 방식은 안전성을 높이기 위해서 사용자 검증값을 암호화하여 인증기관의 데이터베이스에 고유 식별번호로 저장한다. 그리고 해당 웹에 로그인하기 위 해 필요한 패스워드는 일회용 난수를 인증기관으로부터 수신하기 때문에 사용자가 패스워드를 따로 기억할 필요가 없고 스마트폰을 사용하여 난수를 수신한다. 웹은 데이터베이스에 사용자의 개인정보를 저장하지 않기 때문에 개인정 보 관리가 용이하며 사용자에게는 통합 ID 하나만 기억하고 매번 일회성 난수를 패스워드로 발급받아 여러 ID와 패 스워드를 기억하고 관리하지 않아도 되는 편리성을 제공해 준다.

Existing Web authentication method utilizes the resident registration number by credit rating agencies separating i-PIN authentication method which has been improved authentication using resident registration number via the real name confirmation database. By improving the existing authentication method, and it provides the available integrated ID authentication on Web. In order to enhance safety, the proposed authentication method by encrypting the user of the verification value, and stores the unique identifier in the database of the certificate authority. Then, the password required to log in to the Web is for receiving a disposable random from the certificate authority, the user does not need to remember a separate password and receives the random number by using the smart phone. It does not save the user's personal information in the database, and it is easy to management of personal information. Only the integration ID needs to be remembered with random number on every time. It doesn’t need to use various IDs and passwords if you use this proposed authentication methods.

9

Enhanced Biometric-based User Authentication Protocol Using Non-tamper Resistant Smart Cards SCOPUS

Minsu Park, Hyunsung Kim

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.9 No.12 2015.12 pp.129-136

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

This paper reviews An’s enhanced biometric-based user authentication protocol and shows that it is weak against the password guessing attack and has a problem of verification in the authentication phase. They are very important features to be secured to the user authentication protocol. Furthermore, this paper proposes an enhanced biometric-based user authentication protocol using non-tamper resistant smart cards to solve the problems in An’s protocol. The overall security analyses show that the proposed protocol could achieve the desired security goals.

10

User Authentication Protocol preserving Enhanced Anonymity and Untraceability for TMIS

Mi-Og Park

[Kisti 연계] 한국컴퓨터정보학회 Journal of the Korea society of computer and information Vol.28 No.10 2023 pp.93-101

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 논문에서는 2023년에 Chen-Chen이 제안한 ECC와 생체정보를 사용한 TMIS 인증 프로토콜을 분석한 결과, 사용자 가장 공격, 중간자 공격, 사용자 익명성 등의 안전성 문제가 있었다. 그러므로 본 논문에서는 이러한 문제를 해결하기 위하여 사용자 익명성을 제공하는 개선된 인증 프로토콜을 제안한다. 본 논문에서 제안한 프로토콜의 안전성 문제를 분석한 결과, 제안한 프로토콜은 오프라인 패스워드 추측 공격, 사용자 가장 공격, 스마트카드 분실 공격, 내부자 공격, 전방향 안전성, 재생 공격 등 여러 공격에 안전한 것으로 분석되었다. 또한 TMIS에서 반드시 보장해야 하는 사용자 익명성과 추적 불가능성도 함께 보장하여 사용자의 프라이버시를 보장하는 것으로 나타났다. 게다가 계산 복잡도에서도 크게 증가하지 않아 실행시간의 효율성도 달성하였다. 그러므로 본 논문에서 제안한 프로토콜은 TMIS에 적합한 사용자 인증 프로토콜이다.

In this paper, as a result of analyzing the TMIS authentication protocol using ECC and biometric information proposed by Chen-Chen in 2023, there were security problems such as user impersonation attack, man-in-the-middle attack, and user anonymity. Therefore, this paper proposes an improved authentication protocol that provides user anonymity to solve these problems. As a result of analyzing the security of the protocol proposed in this paper, it was analyzed to be secure for various attacks such as offline password guessing attack, user impersonation attack, smart-card loss attack, insider attack, perfect forward attack. It has also been shown to provided user privacy by guaranteeing user anonymity and untraceability, which must be guaranteed in TMIS. In addition, there was no significant increase in computational complexity, so the efficiency of execution time was achieved. Therefore, the proposed protocol in this paper is a suitable user authentication protocol for TMIS.

11

Design of Authentication Protocol for User Identification in IMT-2000

서동운, 남기모, 박재균, 강성용, 김정훈, 박석천

[Kisti 연계] 한국멀티미디어학회 한국멀티미디어학회 학술대회논문집 2000 pp.331-334

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

IMT-2000은 유선통신 시장에서 확고히 자리잡은 인터넷 서비스와 멀티미디어 고속 데이터정보를 무선으로 공급하고자 하는 사용자의 요구를 충족시키기 위해 등장하였다. 그러나 이러한 서비스는 무선망을 통하여 제공되기 때문에 그 특성상 전송로가 노출되어 있어 허가반지 않은 사용자에 의한 불법적인 절취사용과 악의를 가진 제3자가 공유된 전송매체를 통해 전파를 도청하기 쉽다는 문제점을 가지고 있다 따라서 이동 무선 환경에서의 보안과 인증문제는 필수적인 사항이라고 할 수 있다. 이를 위해 본 논문에서는 기존의 인증 방식을 분석하고 사용자의 식별을 위한 쌍방향 인증 프로토콜을 설계하고 그 효율성을 분석하였다.

12

Design and Evaluation of Authentication Protocol for User Identification in IMT-2000

정운영, 정선화, 김성주, 이준호, 박석천

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2001 pp.549-552

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

IMT-2000은 유선통신 시장에서 확고히 자리잡은 인터넷 서비스와 멀티미디어 고속 데이터 정보를 무선으로 공급하고자 하는 사용자의 요구를 충족시키기 위해 등장하였다. 그러나 이러한 서비스는 무선망을 통하여 제공되기 때문에 무선망의 특성상 전송로가 노출되어 허가 받지 않은 사용자에 의한 불법적인 절취사용과 공유된 전송매체를 통한 전파의 도청 등의 문제점을 가지고 있다. 이러한 문제를 해결하기 위해 본 논문에서는 IMT-2000에서 사용자 식별을 위한 쌍방향 인증 프로토콜을 설계하고 그 성능을 평가하였다.

13

강력한 개체인증 특성을 가지는 GSM 사용자 인증 프로토콜

박미옥, 김상근

[Kisti 연계] 한국멀티미디어학회 멀티미디어학회논문지 Vol.9 No.10 2006 pp.1314-1321

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

GSM(Global System for Mobile Communications)은 전 세계 이동통신 네트워크상의 와이드스프레드 로밍과 개인휴대통신을 지원하는 전 유럽 디지털 셀룰러 모바일 시스템이다. 그러나 보안기능 제공에도 불구하고, GSM에는 사용자인증과 같은 문제점들이 존재한다. 본고에서는 사용자인증문제 해결을 위해 각 네트워크 개체를 강력하게 인증하고 사용자의 프라이버시를 위해 익명성을 제공하는 향상된 사용자인증 메커니즘을 제안한다.

GSM(Global System for Mobile Communications) is a Pan-European digital cellular mobile system supporting widespread roaming and personal communication services in a worldwide wireless communication network. In suite of providing security capability, however, there are some problems like user authentication in GSM. In this paper, we propose the enhanced authentication mechanism to verify strongly each network entity to so]ye user authentication problem and support anonymity for user privacy.

14

원격인증서버 기반의 홈네트워크 사용자 인증 프로토콜 설계

최훈일, 장영건

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2007 pp.1113-1116

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

홈네트워크의 사용자 인증은 사용자가 홈네트워크 서비스를 이용할 때 안전한 홈네트워크 서비스를 제공하기 위해 필요한 과정이다. 사용자를 인증하기 위한 수단은 크게 ID/PW 기반, 인증서 기반, 생체인식 기반으로 분류할 수 있다. 본 논문에서는 다양한 인증 수단을 수용할 수 있도록 EAP와 TLS 프로토콜을 기반으로 원격인증서버를 이용한 홈네트워크 사용자 인증 프로토콜을 설계하였다.

15

효율적 사용자 인증을 위한 SRP 기반의 독립적 인증 프로토콜 설계

정경숙, 정태충

[Kisti 연계] 한국컴퓨터정보학회 Journal of the Korea society of computer and information Vol.8 No.3 2003 pp.130-137

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 논문은 클라이언트-서버 환경이 발달되어 있는 현재의 시스템들에서 사용자 인증을 효율적으로 할 수 있는 프로토콜 설계를 제안한다. 기존의 패스워드 기반 프로토콜들은 클라이언트와 서버 사이에 인증기관(CA)을 통하여 사용자를 인증하는 데에 반해, 본 논문에서는 사용자와 서버가 독립적으로 키 교환 및 인증을 하는 패스워드 기반 프로토콜을 제안함으로써 사용자 인증을 효율적으로 할 수 있도록 하였다. 패스워드는 충분한 랜덤성을 가지지 못할 뿐만 아니라 패스워드의 길이가 짧기 때문에 오로지 패스워드 만을 이용해 인증 및 키 교환을 하는 것은 많은 주의를 요한다. 그러므로 Diffie-Hellman 키교환 방식에 기반한 SRP 프로토콜과 ECDSA의 서명 기법을 적용하여 안전성이 높은 프로토롤을 제안한다. 또한 기존의 다른 프로토콜과의 라운드 횟수 및 해쉬 함수의 연산과 지수 연산의 횟수를 비교 분석함으로써 제안하는 프로토콜의 효율성을 설명하였다.

This paper proposes protocol design that can do user authentication efficiently in current systems that client-server environment is developed. And proposes a password-based authentication protocol suitable to certification through trustless network or key exchange. While the existing password-base protocols certify users through certification authority (CA) between client and server, the proposed protocol in this paper, users and server exchange keys and perform authentication without help of CA. To ameliorate the drawback of password-based protocols causing by the short length and randomness of password, the proposed protocol uses the signature techniques of ECDSA and the SRP protocol based on Diffie-Hellman key exchange method. Also, by with compare to round number and Hash function number and exponential operation of existing protocols, we explained efficiency of proposed protocol.

16

클라우드 컴퓨팅 환경에서 안전성이 향상된 사용자 인증 프로토콜

변연상, 곽진

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2013 pp.595-598

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

클라우드 컴퓨팅 환경은 다양한 IT 기술이 융합된 형태로 수많은 사용자들이 같은 인프라를 기반으로 서비스를 제공받는 환경이다. 이렇게 수많은 사용자들이 이용하는 클라우드 컴퓨팅 환경에서는 악성코드 유포, 개인정보 탈취 등과 같은 문제점이 발생할 수 있기 때문에 사용자를 인증할 수 있는 필요성이 대두되었다. 이러한 문제점을 해결할 수 있는 대응 방안이 많이 연구되고 있지만, 클라우드 컴퓨팅 환경의 특징을 고려하지 않고 개발되었기 때문에 적용하기에는 다소 문제점이 있을 것으로 예상된다. 이러한 문제점을 해결하기 위해 Lee 등은 2-factor 인증 기법을 제안하였다. 그러나 Lee 등이 제안한 인증 기법은 무결성, 기밀성을 보장하지 못하며, 도청에 취약한 것으로 분석되었다. 따라서 본 논문에서는 이러한 문제점을 해결할 수 있는 프로토콜을 제안한다.

17

클라우드 SNS상에서 Proxy Re-Encryption을 이용한 사용자 모바일 인증 프로토콜

조승현, 문종호, 남윤호, 전웅렬, 원동호

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2013 pp.607-609

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 분산 시스템의 기술이 발전하면서 소셜 네트워크 서비스(SNS)도 분산방식으로 전환해가는 추세이다. 특히, 모바일 기기 발전과 공급 확산으로 인해 모바일 기기의 분산 SNS에 대한 연구로 클라우드 컴퓨팅 기술을 응용한 모바일 클라우드 SNS가 연구되고 있다. 또한, 제 3자의 미인증 모바일 기기를 사용한 SNS 접속으로 인한 피해가 증가되고 있는 반면, 이를 방지하는 사용자 모바일 기기 인증에 대한 연구는 미흡하다. 따라서 본 논문은 Proxy Re-Encryption 기술을 응용하여 안전한 모바일 기기 인증 프로토콜을 제안한다.

18

Privileged-Insider 공격에 안전한 원격 사용자 인증 프로토콜

이성엽, 박요한, 박영호

[Kisti 연계] 한국멀티미디어학회 멀티미디어학회논문지 Vol.20 No.4 2017 pp.614-628

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Recently, Due to the rapid development of the internet and IT technology, users can conveniently use various services provided by the server anytime and anywhere. However, these technologies are exposed to various security threat such as tampering, eavesdropping, and exposing of user's identity and location information. In 2016, Nikooghadam et al. proposed a lightweight authentication and key agreement protocol preserving user anonymity. This paper overcomes the vulnerability of Nikooghadam's authentication protocol proposed recently. This paper suggests an enhanced remote user authentication protocol that protects user's password and provides perfect forward secrecy.

19

스마트카드를 이용한 ID기반의 사용자 인증 프로토콜

이원진, 김은주, 전일수

[Kisti 연계] 한국정보과학회 한국정보과학회 학술대회논문집 2005 pp.166-168

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 김등[1]은 스마트카드와 패스워드 그리고 지문 정보를 이용한 ID 기반의 사용자 인증 프로토콜을 제시하였다. 그러나 Scott[2]은 그 프로토콜이 보안에 취약함을 보였다. 본 논문에서는 Scott이 제안한 공격에 안전할 뿐만 아니라 다양한 공격에 안전한 패스워드와 스마트카드를 이용한 ID기반의 사용자 인증 프로토콜을 제안한다.

20

스마트카드를 이용한 ID기반의 사용자 인증 프로토콜

이원진, 김은주, 전일수

[Kisti 연계] 한국정보과학회 한국정보과학회 학술대회논문집 2005 pp.166-168

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 김등[1]은 스마트카드와 패스워드 그리고 지문 정보를 이용한 ID 기반의 사용자 인증 프로토콜을 제시하였다. 그러나 Scott[2]은 그 프로토콜이 보안에 취약함을 보였다. 본 논문에서는 Scott이 제안한 공격에 안전할 뿐만 아니라 다양한 공격에 안전한 패스워드와 스마트카드를 이용한 ID기반의 사용자 인증 프로토콜을 제안한다.

 
1 2 3
페이지 저장