Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 204
No
1

Cryptography in the Cloud: Advances and Challenges

Boyd, Colin

[Kisti 연계] 한국정보통신학회 Journal of information and communication convergence engineering Vol.11 No.1 2013 pp.17-23

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Cloud computing is a currently developing revolution in information technology that is disturbing the way that individuals and corporate entities operate while enabling new distributed services that have not existed before. At the foundation of cloud computing is the broader concept of converged infrastructure and shared services. Security is often said to be a major concern of users considering migration to cloud computing. This article examines some of these security concerns and surveys recent research efforts in cryptography to provide new technical mechanisms suitable for the new scenarios of cloud computing. We consider techniques such as homomorphic encryption, searchable encryption, proofs of storage, and proofs of location. These techniques allow cloud computing users to benefit from cloud server processing capabilities while keeping their data encrypted; and to check independently the integrity and location of their data. Overall we are interested in how users may be able to maintain and verify their own security without having to rely on the trust of the cloud provider.

2

Quantum Computing Cryptography and Lattice Mechanism

Abbas M., Ali Al-muqarm, Firas, Abedi, Ali S., Abosinnee

[Kisti 연계] 한국정보통신학회 Journal of information and communication convergence engineering Vol.20 No.4 2022 pp.242-249

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Classical cryptography with complex computations has recently been utilized in the latest computing systems to create secret keys. However, systems can be breached by fast-measuring methods of the secret key; this approach does not offer adequate protection when depending on the computational complexity alone. The laws of physics for communication purposes are used in quantum computing, enabling new computing concepts to be introduced, particularly in cryptography and key distribution. This paper proposes a quantum computing lattice (CQL) mechanism that applies the BB84 protocol to generate a quantum key. The generated key and a one-time pad encryption method are used to encrypt the message. Then Babai's algorithm is applied to the ciphertext to find the closet vector problem within the lattice. As a result, quantum computing concepts are used with classical encryption methods to find the closet vector problem in a lattice, providing strength encryption to generate the key. The proposed approach is demonstrated a high calculation speed when using quantum computing.

3

NIST Lightweight Cryptography Standardization Process: Classification of Second Round Candidates, Open Challenges, and Recommendations

Gookyi, Dennis Agyemanh Nana, Kanda, Guard, Ryoo, Kwangki

[Kisti 연계] 한국정보처리학회 Journal of information processing systems Vol.17 No.2 2021 pp.253-270

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

In January 2013, the National Institute of Standards and Technology (NIST) announced the CAESAR (Competition for Authenticated Encryption: Security, Applicability, and Robustness) contest to identify authenticated ciphers that are suitable for a wide range of applications. A total of 57 submissions made it into the first round of the competition out of which 6 were announced as winners in March 2019. In the process of the competition, NIST realized that most of the authenticated ciphers submitted were not suitable for resource-constrained devices used as end nodes in the Internet-of-Things (IoT) platform. For that matter, the NIST Lightweight Cryptography Standardization Process was set up to identify authenticated encryption and hashing algorithms for IoT devices. The call for submissions was initiated in 2018 and in April 2019, 56 submissions made it into the first round of the competition. In August 2019, 32 out of the 56 submissions were selected for the second round which is due to end in the year 2021. This work surveys the 32 authenticated encryption schemes that made it into the second round of the NIST lightweight cryptography standardization process. The paper presents an easy-to-understand comparative overview of the recommended parameters, primitives, mode of operation, features, security parameter, and hardware/software performance of the 32 candidate algorithms. The paper goes further by discussing the challenges of the Lightweight Cryptography Standardization Process and provides some suitable recommendations.

4

Speed Optimized Implementation of HUMMINGBIRD Cryptography for Sensor Network

Seo, Hwa-Jeong, Kim, Ho-Won

[Kisti 연계] 한국정보통신학회 Journal of information and communication convergence engineering Vol.9 No.6 2011 pp.683-688

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

The wireless sensor network (WSN) is well known for an enabling technology for the ubiquitous environment such as real-time surveillance system, habitat monitoring, home automation and healthcare applications. However, the WSN featuring wireless communication through air, a resource constraints device and irregular network topology, is threatened by malicious nodes such as eavesdropping, forgery, illegal modification or denial of services. For this reason, security in the WSN is key factor for utilizing the sensor network into the commercial way. There is a series of symmetric cryptography proposed by laboratory or industry for a long time. Among of them, recently proposed HUMMINGBIRD algorithm, motivated by the design of the well-known Enigma machine, is much more suitable to resource constrained devices, including smart card, sensor node and RFID tags in terms of computational complexity and block size. It also provides resistance to the most common attacks such as linear and differential cryptanalysis. In this paper, we implements ultra-lightweight cryptography, HUMMINGBIRD algorithm into the resource constrained device, sensor node as a perfectly customized design of sensor node.

5

An Enhanced Energy Efficient Lightweight Cryptography Method for various IoT Devices

Prakasam P., Madheswaran M., Sujith K.P., Md Shohel Sayeed

[NRF 연계] 한국통신학회 ICT Express Vol.7 No.4 2021.12 pp.487-492

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Internet of Things (IoT) is an auspicious technology that will connect more number of devices through an internet. The huge number of communication expected to transmit high data securely is an important problem in recent days. In this paper, an Enhanced Energy Efficient Lightweight Cryptography Method which utilizes 8 bit manipulation principle (E3LCM) has been proposed. The proposed method has been verified for speech signal using MATLAB. The hardware complexity has been validated using Sparten3E XC3S500E FPGA devices and it has been found that the proposed method consumes 202mW power and 0.9 Kbytes RAM and it outperforms other methods.

6

Robust ROI Watermarking Scheme Based on Visual Cryptography: Application on Mammograms

Benyoussef, Meryem, Mabtoul, Samira, El Marraki, Mohamed, Aboutajdine, Driss

[Kisti 연계] 한국정보처리학회 Journal of information processing systems Vol.11 No.4 2015 pp.495-508

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

In this paper, a novel robust medical images watermarking scheme is proposed. In traditional methods, the added watermark may alter the host medical image in an irreversible manner and may mask subtle details. Consequently, we propose a method for medical image copyright protection that may remedy this problem by embedding the watermark without modifying the original host image. The proposed method is based on the visual cryptography concept and the dominant blocks of wavelet coefficients. The logic in using the blocks dominants map is that local features, such as contours or edges, are unique to each image. The experimental results show that the proposed method can withstand several image processing attacks such as cropping, filtering, compression, etc.

7

A Design of Secure Communication Architecture Applying Quantum Cryptography

Shim, Kyu-Seok, Kim, Yong-Hwan, Lee, Wonhyuk

[Kisti 연계] 한국과학기술정보연구원 Journal of information science theory and practice : JISTaP Vol.10 No.no.spc 2022 pp.123-134

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Existing network cryptography systems are threatened by recent developments in quantum computing. For example, the Shor algorithm, which can be run on a quantum computer, is capable of overriding public key-based network cryptography systems in a short time. Therefore, research on new cryptography systems is actively being conducted. The most powerful cryptography systems are quantum key distribution (QKD) and post quantum cryptograph (PQC) systems; in this study, a network based on both QKD and PQC is proposed, along with a quantum key management system (QKMS) and a Q-controller to efficiently operate the network. The proposed quantum cryptography communication network uses QKD as its backbone, and replaces QKD with PQC at the user end to overcome the shortcomings of QKD. This paper presents the functional requirements of QKMS and Q-Controller, which can be utilized to perform efficient network resource management.

8

Design of Secure Information Center Using a Conventional Cryptography

최준혁, 김태갑, 고병도, 류재철

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.6 No.4 1996 pp.53-66

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

World Wide Web is a total solution for multi-media data transmission on Internet. Because of its characteristics like ease of use, support for multi-media data and smart graphic user interface, WWW has extended to cover all kinds of applications. The Secure Information Center(SIC) is a data transmission system using conventional cryptography between client and server on WWW. It's main function is to support the encryption of sending data. For encryption of data IDEA(International Data Encryption Algorithm) is used and for authentication mechanism MD5 hash function is used. Since Secure Information Center is used by many users, conventional cryptosystem is efficient in managing their secure interactions. However, there are some restrictions on sharing of same key and data transmission between client and server, for example the risk of key exposure and the difficulty of key sharing mechanisms. To solve these problems, the Secure Information Center provides encryption mechanisms and key management policies.

9

Authentication protocol for vehicular networks using Zero-Knowledge Proofs and Elliptic Curve Cryptography

Nai-Wei Lo, Chi-Ying Chuang, Jheng-Jia Huang, Yu-Xuan Luo

[NRF 연계] 한국통신학회 ICT Express Vol.11 No.4 2025.08 pp.636-642

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

With the rise of the Internet of Vehicles (IoV), secure and efficient authentication is essential to prevent cyber threats. This paper proposes a session key establishment protocol using Zero-Knowledge Proofs (zk-SNARKs) and Elliptic Curve Cryptography (ECC), including the Elliptic Curve Diffie?Hellman (ECDH) key exchange, to ensure privacy and efficiency. While zk-SNARK computations introduce additional verification overhead, our optimizations, such as precomputed proof parameters and lightweight session re-authentication, mitigate delays. Performance evaluation shows a 20% reduction in computation overhead and a 75% faster re-authentication time compared to existing methods, making it a secure and practical solution for real-world IoV applications.

10

4,000원

기술의 발전을 통해 기존 영상보안시스템들이 아날로드 방식의 CCTV에서 네트워크 기반 CCTV로 교체되어지고 있다. 이러한 기술 변화로 인해 네트워크를 이용한 도청 및 해킹에 대한 공격이 발생하게 되면 영상정보유출로 인해 개인 및 공공 기관에 대한 피해는 막대하다 할 수 있다. 따라서 이러한 피해발생을 해결하기 위해 본 논문에서는 데이터 통신 과정에서 영 상정보를 보호할 수 있는 ECC(Elliptic Curve Cryptography) scalar multiplication algorithm들을 비교 분석하여 영상시스템에 서 최적화된 ECC scalar multiplication algorithm을 제안하고자 한다.

Video security systems change from analog based systems to network based CCTVs. Therefore, such network based systems are always exposed not only to threats of eavesdropping and hacking, but to personal damage or public organizations’ damage due to image information leakage. Therefore, in order to solve the problem, this study conducts a comparative analysis on proposes the optimal ECC(Elliptic Curve Cryptography) scalar multiplication algorithms for image information protection in data communication process and thereby proposes the optimal operation algorithm of video security system.

11

4,000원

In this paper we study the Minimum Error Discrimination problem (MED) for ensembles of linearly independent (LI) pure states. By constructing a map from the set on those ensembles we show that the Pretty Good Measurement (PGM) and the optimal measurement for the MED are related by the map.

12

One way to solve the problem of presales of Ethereum : how to use public key cryptography.

Chan-Young Song, Sunghyuck Hong

ASCONS IJASC Volume 1 Number 2 2019.06 pp.27-31

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

Background/Objectives: Ethereum is a next-generation blockchain developed in 2014 by Vitalik Buterin, a cryptocurrency that can implement various smart contracts. Methods/Statistical analysis: When making any contract on a blockchain, the miner is given the corresponding compensation, the block, which is obtained earlier than the hash of the set size by applying a random nonce value and hash algorithm according to the prop-off-work method. In the case of Ethereum, the ETH will be given to the miner who uses more gas in addition to the work proof method. Findings: In this case, if the malicious miner increases the amount of gas first, obtains the priority for block generation, intercepts the value derived by the general miner and sends it to the miner, the miner will give the block to the malicious miner. As such, miner, a problem that arises due to the nature of blockchain, analyzes the problem of relying on transaction order that gives the miner a block option to the miner who uses more gas and proposes a solution. Improvements/Applications: we described how to solve the problem of pre-sales in the blockchain with public key cryptography using confidentiality. It is hoped that this approach will be fairer and safer.

13

양자 내성 암호 HAETAE에 대한 오류 주입 공격 및 대응 기법

이상원, 김윤성, 하재철

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.36 No.2 2026 pp.429-442

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

양자 위협에 대응해 경량화와 부채널 내성을 목표로 제안된 격자 기반 서명 스킴 HAETAE는 수학적 안전성과 별개로 실제 구현 시 오류 주입 공격에 취약할 수 있다. 특히 Fiat-Shamir with Aborts 기반의 Dilithium과 구조적으로 유사함에도, 전체 서명 구조 대상의 공격 지점 도출 및 하드웨어 실증 연구는 아직 학계에 보고된 바 없다. 본 논문에서는 HAETAE의 결정론적 서명 구조를 분석하여 LSB, 공개 행렬 언패킹, 부호 비트, 샘플링 시드 생성에 대한 오류 주입 공격 지점을 제시한다. 또한, 소프트웨어 및 하드웨어 실험을 통해 단일 또는 소수의 오류 주입만으로도 비밀 키 복구가 가능함을 확인하였으며, 본 연구에서 제시한 대응 기법이 5% 미만의 오버헤드로 이러한 공격을 효과적으로 완화할 수 있음을 입증한다.

A lattice-based signature scheme HAETAE, proposed to counter quantum threats with lightweight implementation and side-channel resistance, can be vulnerable to fault injection attacks in practical implementations regardless of mathematical security. In particular, despite its structural similarity to Dilithium-which is based on the Fiat-Shamir with Aborts framework-no studies have yet been reported in academia that systematically identify attack points across the entire signing structure and demonstrate them at the hardware level. In this paper, we analyze the deterministic signing structure of HAETAE and identify fault injection attack points targeting LSB processing, public matrix unpacking, sign-bit generation, and sampling-seed generation. Furthermore, through software and hardware experiments, we verify that secret-key recovery is achievable with only a single or a few fault injections. Finally, we demonstrate that the proposed countermeasures effectively mitigate these attacks with less than 5% overhead.

14

암호학 및 오류 수정 코드를 위한 부울 대수 가중치 연구

연용호, 강안나

[Kisti 연계] 한국항행학회 한국항행학회논문지 Vol.15 No.5 2011 pp.781-788

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Sphere-packing problem은 주어진 공간에 가능한 한 많은 구(sphere)를 채울 수 있는 배열을 찾는 문제이고 covering problem은 이에 쌍대적인 최적화의 문제로 코딩이론에 적용된다. 본 논문에서는 이진 코드이론에서의 가중치(weight)와 해밍거리(Hamming distance)에 대한 개념을 부울 대수(Boolean algebra)의 개념으로 일반화한다. 부울 대수에서의 가중치와 이를 이용하여 거리함수를 정의하고, 이들의 기본적인 성질들을 밝힌다. 또한, 부울 대수에서의 sphere-packing bound와 Gilbert-Varshamov bound의 정리를 증명한다.

A sphere-packing problem is to find an arrangement of the spheres to fill as large area of the given space as possible, and covering problems are optimization problems which are dual problems to the packing problems. We generalize the concepts of the weight and the Hamming distance for a binary code to those of Boolean algebra. In this paper, we define a weight and a distance on a Boolean algebra and research some properties of the weight and the distance. Also, we prove the notions of the sphere-packing bound and the Gilbert-Varshamov bound on Boolean algebra.

15

사물 인터넷 프로세서 8-bit AVR 상에서의 경량암호 TinyJAMBU 고속 최적 구현

권혁동, 엄시우, 심민주, 양유진, 서화정

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.33 No.2 2023 pp.183-191

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

암호 알고리즘은 많은 연산 자원을 요구하며 복잡한 수학적 원리를 통해 보안성을 가진다. 하지만 대부분의 사물인터넷 기기는 가용 자원이 한정적이며 그에 따라 연산 성능이 부족하다. 따라서 연산량을 적게 사용하는 경량암호가 등장하였다. 미국 국립표준기술연구소는 경량암호 표준화 공모전을 개최하여 경량암호의 원활한 보급을 꾀했다. 공모전의 알고리즘 중 하나인 TinyJAMBU는 순열 기반의 알고리즘이다. TinyJAMBU는 키 스케줄을 거치지 않는 대신 많은 순열 연산을 반복하며, 이때 시프트 연산이 주로 사용된다. 본 논문에서는 8-bit AVR 프로세서상에서 경량암호 TinyJAMBU를 고속 최적 구현하였다. 제안 기법은 시프트 연산을 반대 방향으로 하여 시프트 횟수를 최소화한 리버스 시프트 기법과 키와 논스가 고정인 환경에서 일부 연산을 사전 연산한 기법이다. 제안 기법은 순열연산에서 최대 7.03배, TinyJAMBU 알고리즘에 적용 시 최대 5.87배 성능 향상을 보였다. 키와 논스가 고정인 환경에서는 TinyJAMBU의 알고리즘이 최대 9.19배만큼 성능이 향상되었다.

Cryptographic algorithms require extensive computational resources and rely on complex mathematical principles for security. However, IoT devices have limited resources, leading to insufficient computing power. As a result, lightweight cryptography has emerged, which uses fewer computational resources. NIST organized a competition to standardize lightweight cryptography and TinyJAMBU, one of the algorithms in the competition, is a permutation-based algorithm that repeats many permutation operations. In this paper, we implement TinyJAMBU on an 8-bit AVR processor with a proposedtechnique that includes a reverse shift method and precomputing some operations in a fixed key and nonce environment. Our techniques showed a maximum performance improvement of 7.03 times in permutation operations and 5.87 times in the TinyJAMBU algorithm, improving up to 9.19 times in a fixed key and nonce environment.

16

GIFT-128에 대한 SITM 공격: NIST 경량암호 최종 후보 GIFT-COFB 적용 방안 연구

박종현, 김한기, 김종성

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.32 No.4 2022 pp.607-615

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

SITM (See-In-The-Middle) 공격은 부채널 정보를 활용한 차분 분석 기법 중 하나로, CHES 2020에서 제안되었다. 이 기법은 부분적으로 부채널 마스킹이 적용된 블록암호에서 부채널 마스킹이 적용되지 않은 중간 라운드의 전력 파형을 이용해 차분 분석을 진행한다. 블록암호 GIFT는 CHES 2017에 제안된 경량암호로, 블록암호 PRESENT에서 발견된 취약점을 보완하고 더욱 효율적인 구현이 가능하도록 설계되었다. 본 논문에서는 부분 마스킹이 적용된 GIFT-128에 대한 SITM 공격을 제안한다. 이 공격은 4-라운드와 6-라운드 부분 마스킹이 적용된 GIFT-128을 공격대상으로 하며, 공격에 필요한 시간/데이터 복잡도는 각각 2<sup>14.01</sup> /2<sup>14.01</sup>, 2<sup>16</sup> /2<sup>16</sup> 이다. 본 논문에서는 SITM 공격에서 사용 가능한 마스터키 복구 논리를 비교하여, 상황에 따라 더욱 효율적인 논리를 선택하는 기준을 성립한다. 마지막으로, NIST 표준 경량암호 공모사업 최종 후보 중 하나인 GIFT-COFB에 해당 공격을 적용하는 방안을 제시한다.

The SITM (See-In-The-Middle) proposed in CHES 2020 is a methodology for side-channel assisted differential cryptanalysis. This technique analyzes the power traces of unmasked middle rounds in partial masked SPN block cipher implementation, and performs differential analysis with the side channel information. Blockcipher GIFT is a lightweight blockcipher proposed in CHES 2017, designed to correct the well-known weaknesses of block cipher PRESENT and provide the efficient implementation. In this paper, we propose SITM attacks on partial masked implementation of GIFT-128. This attack targets 4-round and 6-round masked implementation of GIFT-128 and time/data complexity is 2<sup>14.01</sup> /2<sup>14.01</sup>, 2<sup>16</sup> /2<sup>16</sup>. In this paper, we compare the masterkey recovery logic available in SITM attacks, establishing a criterion for selecting more efficient logic depending on the situation. Finally, We introduce how to apply the this attack to GIFT-COFB, one of the finalist candidates in NIST lightweight cryptography standardization process.

17

양자 내성 암호 통합을 위한 실용적 암호 민첩성 미들웨어 프레임워크

이은민, 노현아, 양희재, 김다은, 김성민, 이주희

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.36 No.2 2026 pp.397-414

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 국내외 양자 내성 암호(Post-Quantum Cryptography, PQC) 표준화 과정이 진행되면서, 기존 공개키 암호 기반 시스템에 신규 암호 알고리즘을 효율적으로 적용·전환하는 능력인 암호 민첩성(crypto agility)의 중요성이 커지고 있다. 그러나 이에 대한 국제적 합의와 구현 프로토콜은 아직 초동 단계에 머물러 있다. 본 논문은 NIST 및 KpqC 공모전 채택 양자 내성 알고리즘을 분석하고, 이에 적합한 암호 민첩성의 정의와 시스템 설계 요구사항을 제시한다. 또한 암호 민첩성을 충족하며 사용자 보안 정책 기반으로 다양한 수학적 난제에 기반한 암호 시스템을 동적으로 지원하는 Crypto Agility Middleware Framework(CAMF)를 제안하였다. CAMF는 DSL(Domain-Specific Language)기반 정책 관리 구조를 통해 PQC 알고리즘을 지원하며, 기존 공개키 암호 알고리즘과의 Hybrid 형태도 지원하는 PQ-TLS 확장 구조를 설계하였다. 제안하는 프레임워크는 PQC 표준에 부합하는 암호 민첩성 정의와 실현 방안을 제시하고, 실제 프로토콜 설계를 통해 실현 가능성을 입증하였다.

With the ongoing standardization of Post-Quantum Cryptography (PQC) at both the domestic and international levels, the importance of crypto agility has become increasingly prominent. However, there is still no international consensus on the its definition, and protocols implementing it remain in their early stages. This paper analyzes PQC algorithms adopted in the NIST and KpqC competitions, and proposes a definition of crypto agility along with corresponding system-level design requirements. Furthermore, we propose the Crypto Agility Middleware Framework (CAMF), which fulfills crypto agility requirements, operates based on user-defined security policies, and dynamically supports cryptographic systems based on diverse mathematical hardness assumptions. CAMF incorporates a Domain-Specific Language (DSL) context-based policy management structure and we provides an extended PQ-TLS architecture supporting PQC algorithms as well as a hybrid mode combining them with existing public-key cryptographic algorithms. The proposed framework presents a definition and implementation approach for crypto agility aligned with PQC standards and demonstrates its feasibility through practical protocol design.

18

CSIDH 기반 암호에 대한 뒤틀린 몽고메리 곡선 사용

김수리

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.31 No.3 2021 pp.497-508

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 논문에서는 뒤틀린 몽고메리 곡선을 사용하는 대표적인 암호인 CSURF의 최적화 구현에 대해 분석한다. Projective 형태의 타원곡선 연산은 몽고메리 곡선보다 뒤틀린 몽고메리 곡선이 더 느려서, CSURF는 hybrid 형태의 CSIDH 보다 성능이 느리다. 하지만, square-root Velu 공식을 사용할 경우 타원곡선 연산량을 줄일 수 있으므로 최적화할 여지가 있다. 본 논문에서는 처음으로 뒤틀린 몽고메리 곡선에서의 square-root Velu 공식을 제안하고, 2-isogeny 공식을 최적화하였다. 본 논문의 결과, 제안하는 CSURF는 기존보다 23.3% 빠르고, CSIDH 보다는 10.8% 느리다. 또한, 제안하는 constant-time CSURF의 경우 constant-time CSIDH 보다 6.8% 느리다. 제안하는 결과 CSURF는 CSIDH 보다 느리지만, 기존 뒤틀린 몽고메리를 이용한 구현과 비교하면 상당한 향상으로, 향후 뒤틀린 몽고메리 곡선에 적합한 구현에 본 논문의 결과를 이용할 수 있을 것으로 전망한다.

In this paper, we focus on optimizing the performance of CSURF, which uses the tweaked Montgomery curves. The projective version of elliptic curve arithmetic is slower on tweaked Montgomery curves than on Montgomery curves, so that CSURF is slower than the hybrid version of CSIDH. However, as the square-root Velu formula uses less number of ellitpic curve arithmetic than the standard Velu formula, there is room for optimization We optimize the square-root Velu formula and 2-isogeny formula on tweaked Montgomery curves. Our CSURFis 14% faster than the standard CSURF, and 10.8% slower than the CSIDH using the square-root Velu formula. The constant-time CSURF is 6.8% slower than constant-time CSIDH. Compared to the previous implementations, this is a remarkable result.

19

양자내성암호 ML-DSA에 대한 오류 주입 공격 위협 평가 프레임워크 및 실험적 검증

이상원, 김수형, 하재철

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.36 No.1 2026 pp.1-12

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

양자 내성 암호(PQC) 표준으로 채택된 ML-DSA는 암호학적 안전성에도 불구하고 물리적 공격 중 하나인 오류 주입 공격에 취약할 수 있다. 특히 실제 하드웨어 구현을 위한 성능 최적화 과정에서 발생하는 알고리즘 변형으로 새로운 공격 지점이 발생할 수 있다. 따라서, 본 논문에서 공통 취약점 점수 시스템(CVSS)의 점수화 모델을 참고한 오류 평가 프레임워크를 통해 ML-DSA 헤지 모드(hedge mode)의 다양한 오류 주입 공격 시나리오를 평가하였다. 평가 결과, 개인 난수 시드 생성 과정이 단일 오류만으로 탐지 불가능한 키 복구를 가능하게 하는 가장 치명적인 취약점임을 식별하였다. 또한 ARM Cortex-M4 기반의 실제 하드웨어 환경에서 클럭 글리치 공격을 수행하여 해당 취약점을 성공적으로 비밀 키를 복구함으로써 평가의 타당성을 검증하였다.

ML-DSA, adopted as a standard for post-quantum cryptography (PQC), can be vulnerable to physical fault-injection attacks despite its cryptographic strengths. In this paper, we develop a fault-assessment framework-informed by the scoring model of the Common Vulnerability Scoring System (CVSS)-to evaluate multiple fault-injection scenarios against ML-DSA operating in hedge mode. Our evaluation identifies the per-instance random seed generation as the most critical weakness: a single fault can make key recovery undetectable. We validate the framework experimentally on an ARM Cortex-M4 platform by performing clock-glitch attacks that successfully recover the secret key, confirming the practical impact of the discovered vulnerability.

20

양자내성암호 NTRU에 대한 전력 부채널 공격 및 대응방안

장재원, 하재철

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.32 No.6 2022 pp.1059-1068

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

양자 컴퓨터의 계산 능력을 고려하여 설계된 양자 내성 암호 NTRU는 수학적으로 안전한 암호 조건을 만족하지만 하드웨어 구현 과정에서는 전력 분석 공격과 같은 부채널 공격 특성을 고려해야 한다. 본 논문에서는 NTRU의 복호화 과정 중 발생하는 전력 신호를 분석할 경우 개인 키가 노출될 가능성이 있음을 검증한다. 개인 키를 복구하는 데에는 단순 전력 분석 공격(Simple Power Analysis, SPA), 상관 전력 분석 공격(Correlation Power Analysis, CPA)과 차분 딥러닝 분석 공격(Differential Deep Learning Analysis, DDLA)을 모두 적용할 수 있었다. 이러한 전력 부채널 공격에 대응하기 위한 기본적인 대응책으로 셔플링 기법이 있으나 보다 효과적인 방법을 제안한다. 제안 방식은 인덱스별로 곱셈(multiplication)후 누산(accumulation)을 하는 것이 아니라 계수별로 누산 후 덧셈만 하도록 함으로써 곱셈 연산에 대한 전력 정보가 누출되지 않도록 하여 CPA 및 DDLA 공격을 방어할 수 있다.

A Post-Quantum Cryptographic algorithm NTRU, which is designed by considering the computational power of quantum computers, satisfies the mathematically security level. However, it should consider the characteristics of side-channel attacks such as power analysis attacks in hardware implementation. In this paper, we verify that the private key can be recovered by analyzing the power signal generated during the decryption process of NTRU. To recover the private keys, the Simple Power Analysis (SPA), Correlation Power Analysis (CPA) and Differential Deep Learning Analysis (DDLA) were all applicable. There is a shuffling technique as a basic countermeasure to counter such a power side-channel attack. Neverthe less, we propose a more effective method. The proposed method can prevent CPA and DDLA attacks by preventing leakage of power information for multiplication operations by only performing addition after accumulating each coefficient, rather than performing accumulation after multiplication for each index.

 
1 2 3 4 5
페이지 저장