Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 26
No
1

4,000원

U-Wellness Healthcare System(U-WHS)이란, 웰빙(wellbeing)과 피트니스(fitness)를 결합한 원격 건강 관리 시스템을 말한다. 이러한 시스템에서는 시간과 공간에 제약 없이 언제 어디서나 환자의 생체정보를 측정 및 관리 할 수 있는 것이다. 본 논문에서는 스마트모바일기기와 HIS(Hospital Information System)간 생체정보 전송시 암호화 모 듈이 통신 평가에 끼치는 영향을 알아보기 위해 수행하였다. U-WHS 모델의 경우 클라이언트는 iOS Xcode환경의 Objective-c 개발 언어를 이용하여 SEED, HIGHT 암호화 모듈 적용을 하였다. HIS의 경우 클라이언트와 서버간 통 신을 위하여 HTML5의 WebSocket API와 관계형 데이터베이스 관리 시스템인 MySQL를 적용하였다. 그리하여 WIFI 통신 환경에서 Wireshark를 사용, 분석하여 생체 정보의 데이터 전송율, 지연율, 손실율에 대한 평가를 확인하였다.

U-WHS refers to a means of remote health monitoring service to combine fitness with wellbing. U-WHS is a system which can measure and manage biometric information of patients without any limitation on time and space. In this paper, we performed in order to look into the influence that the encryption module influences on the communication evaluation in the biometric information transmission gone to the smart mobile device and Hospital Information System.In the case of the U-WHS model, the client used the Objective-c programming language for software development of iOS Xcode environment and SEED and HIGHT encryption module was applied. In the case of HIS, the MySQL which is the Websocket API of the HTML5 and relational database management system for the client and inter-server communication was applied. Therefore, in WIFI communication environment, by using wireshark, data transfer rate of the biometric information, delay and loss rate was checked for the evaluation.

2

4,000원

VPN (Virtual Private Network) is utilized for general outside users to communicate securely with inner users and the servers located inside by an encryption for safe communication. VPN has various techniques and functions on the layer 2 and 3, thus this study examined whether layer of VPN performed encryption of the data more securely and is more effective in the 2 layers of VPN techniques. Based on the results of the test, the layer 3 VPN technique was confirmed to communicate with inner space with faster speed than that of the layer 2. And in comparison with encryption protocol supporting in the layer 2 and 3, IPSec VPN of the layer 3 VPN technique was more superior in the function of encryption.

3

4,000원

In order to control the exposure of information outside using plain text communication between IoT devices on the MQTT protocol network, each device generates and shares a symmetric encryption key and then encrypts and decrypts communication messages with the key. We proposed, implemented, and verified an end-to-end encryption process that each device communicates with encrypting and decrypting only the payload of Publish Control Packet at MQTT protocol network.

4

4,000원

현재의 퍼블릭 블록체인은 누구나 원장의 내용을 볼 수 있도록 설계가 되어있다. 하지만 응용에 따라서 비밀 정보를 블록 체인에 저장해야 하는 경우도 있으나 이에 대한 연구는 아직 미진하다. 본 논문에서는 DPoS(Delegated Proof of Stack) 합의 방식을 사용하는 블록체인을 대상으로 공개 블록과 비공개 블록의 두 계층으로 이루어진 블록체인을 제안하고 비공개 블록의 암호화를 위한 요구사항을 도출하였다. 도출된 암호화 요구사항을 만족하는 dealer없는 t-of-n threshold 암호화를 제안하였다. 또한, DPoS의 대표노드들은 가입과 탈퇴가 발생할 수 있어서, 대표노드의 가입과 탈퇴에 따라서 키 조각을 재분배하는 효율 적인 방법을 제시하였다. 제안된 기법이 대표노드간의 공평성과 동일한 신뢰성을 만족하는 특징을 가진다.

In current public blockchain, any node can see every blocks, so that public blockchain provider transparent property. However, some application requires the confidential information to be stored in the block. Therefore, this paper proposes a multi-layer blockchain that have the public block layer and the private block for confidential information. This paper suggests the requirement for encryption of private block. Also, this paper shows the t-of-n threshold cryptosystem without dealer who is trusted third party. Moreover, the delegated node who has key information can be withdraw the delegated node group or a new delegated node can join in the delegated node group. Therefore, the paper proposes an efficient key information resharing scheme for withdraw and join. Finally proposed scheme satisfies the requirements for encryption and fairness.

5

동등한 권한을 가진 대표노드를 위한 비공개 블록 암호화 기법 KCI 등재

정승욱, 이후기

한국융합보안학회 융합보안논문지 제19권 제5호 2019.12 pp.11-18

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

현재의 퍼블릭 블록체인은 누구나 원장의 내용을 볼 수 있도록 설계가 되어있다. 하지만 응용에 따라서 비밀 정보를 블록 체인에 저장해야 하는 경우도 있으나 이에 대한 연구는 아직 미진한다. 본 논문에서는 DPoS(Delegated Proof of Stack) 합의 방식을 사용하는 블록체인을 대상으로 공개 블록과 비공개 블록의 두 개층으로 이루어진 블록체인을 제안하고 비공개 블록의 암호화를 위한 요구사항을 도출하였다. 도출된 암호화 요구사항을 만족하는 dealer없는 t-of-n threshold 암호화를 제안하였다. 제안된 기법이 대표노드간의 공평성과 동일한 신뢰성을 만족하는 특징을 가진다.

In current public blockchain, any node can see every blocks, so that public blockchain provider transparent property. However, some application requires the confidential information to be stored in the block. Therefore, this paper proposes a multi-layer blockchain that have the public block layer and the private block for confidential information. This paper suggests the requirement for encryption of private block. Also, this paper shows the t-of-n threshold cryptosystem without dealer who is trusted third party. Finally proposed scheme satisfies the requirements for encryption and fairness.

6

공장 자동화를 위한 RFID 경량 암호 프로토콜에 관한 연구 KCI 등재

황득영, 김진묵

한국융합보안학회 융합보안논문지 제16권 제7호 2016.12 pp.173-180

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

국내에서 공장자동화에 대한 관심이 증가하고 있으며, 이에 관한 개발이 활발하게 시도되고 있다. 특히, '제조업 혁신 3.0 전략'에 따라 중소기업의 제조 공장들에 대한 스마트화에 대한 관심이 급격히 증가하고 있다. 뿐만 아니라, 스마트 공장을 구 축하기 위한 정책적, 기술적, 전략적 접근 방법을 모색하고 있다. 하지만 이와 같은 스마트 공장 또는 공장 자동화 시스템을 도입하기 위해서는 제조 공장이 갖는 보안 취약점과 개인정보 보호 문제는 반드시 선결해야만 한다. 그러므로 우리는 공장 자 동화를 위해서 가장 많이 도입되고 있는 무선 통신 기술인 RFID 통신 프로토콜에 적용 가능한 경량 암호 프로토콜을 제안한 다. 본 논문에서 제안한 경량 암호 프로토콜은 기존의 공개키 기반 시스템이나 대칭키 암호 알고리즘과 비교해서 연산 횟수가 적고 처리 속도가 빠르다. 뿐만 아니라 낮은 전력 소비량과 저장 공간을 소비하도록 설계하였다.

There has been a growing interest in automation of factories in the country. And, the development in this regard has been actively attempted. In particular, on the basis of the "innovation 3.0 strategy of manufacturing industry", interest in the smart of the manufacturing plant of small and medium-sized enterprises has increased rapidly. As well as policy for building smart plant, technical, seeking a strategic approach. But, in order to introduce such a smart plant or factory automation systems, manufacturing plant security with vulnerability and personal information protection problems, it should always be top priority there. Accordingly, we provide the applicable lightweight secure protocols in RFID communication. It is a wireless communication technology that is most often introduced for factory automation. Our proposed lightweight secure protocol in this study, less the number of calculations in comparison with the existing public key-based and the symmetric key encryption algorithm. And it is fast in compare with the existing protocol. Furthermore, we design that it system can support to low power consumption and small consume the memory size.

7

최근 클라우드 컴퓨팅이 발전함에 따라 데이터베이스 아웃소싱에 대한 관심이 증가하고 있다. 그러나 데이터베이스 를 아웃소싱하는 경우, 데이터 소유자의 정보가 내부 및 외부 공격자에게 노출되는 문제점을 지닌다. 따라서 본 논 문에서는 프라이버시 보호를 지원하는 십진수 기반의 암호화 연산 프로토콜을 제안한다. 제안하는 프로토콜은 이진 수 기반의 암호화 연산 프로토콜과 달리 bit length 만큼 반복 연산을 수행하지 않기 때문에 연산의 효율성을 향상 시킨다. 아울러 십진수 기반의 암호화 연산 프로토콜을 이용한 kNN 질의처리 알고리즘을 제안한다. 제안하는 kNN 질의처리 알고리즘은 암호화 연산의 효율성을 향상시킨 십진수 기반의 프로토콜을 사용함으로써 높은 질의 처 리 성능을 제공한다. 한편 제안하는 알고리즘의 보안 분석을 수행하여, 데이터 보호, 질의 보호, 접근 패턴 보호를 지원함을 증명한다. 마지막으로 성능평가를 통해, 제안하는 kNN 질의처리 알고리즘이 기존 알고리즘에 비해서 약 5배의 질의처리 성능 향상이 있음을 보인다.

With the development of cloud computing, interest in database outsourcing has recently increased. However, when the database is outsourced, there is a problem in that the information of the data owner is exposed to internal and external attackers. Therefore, in this paper, we propose decimalbased encryption operation protocols that support privacy preservation. The proposed protocols improve operational efficiency compared to binary-based encryption operation protocols by eliminating the need for repetitive operations based on bit length. In addition, we propose a privacy-preserving kNN query processing algorithm using decimal-based encryption operation protocols. The proposed kNN query processing algorithm provides high query processing performance by utilizing efficient decimal-based protocols which enhance the efficiency of the encryption operations. Meanwhile, the security analysis of the proposed algorithm is performed to prove its data protection, query protection, and access pattern protection. Through our performance analysis, the proposed kNN query processing algorithm shows about 5 times better query processing performance, compared with the existing algorithms.

8

An Embedded Encryption Protocol for Healthcare Networks Security SCOPUS

Ndibanje Bruce, Won Tae Jang, Hoon Jae Lee

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.8 No.2 2014.03 pp.139-144

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Data availability service is now ubiquitously practical from the high-end systems such as routers, gateways, firewalls, and web servers to the low-end systems such as smart phone, tablet, etc…with the emerging growth of the embedded systems, there is parallel rapid increase in the amount of information flowing across intranets and the Internet. Hence, security has become an essential part of today’s computing world. This promise of universal connectivity for embedded systems creates increased possibilities for malicious users to gain unauthorized access to sensitive information. This paper presents a framework for HNS in which an embedded encryption protocol scheme enables negotiation between entities to specify authorization requirements that must be met before accessing the network and data.

9

An Enhanced Light-weight Anonymous Authentication and Encryption Protocol in Wireless Sensor Network

Jeong-Hyo Park, Yong-Hoon Jung, Kwang-Hyung Lee, Keun-Wang Lee, Moon-Seog Jun

보안공학연구지원센터(IJDTA) International Journal of Database Theory and Application Vol.5 No.1 2012.03 pp.1-20

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Until now, the interests of the research about sensor network security have been focused on the security services that provide authentication, confidentiality, integrity, and availability. However, the interest in the issue of actual identifier's exposure of sensor node is rapidly increasing. Also, the interest in the efficiency of creating encryption key that is used for the sensor network is increasing. Many schemes for providing node's anonymity in the existing Ad-Hoc network were suggested, but these schemes are not appropriate for sensor network that is energy-limited, so a scheme for providing anonymity that is suitable for sensor network's characteristics is required. Also, Sensor network maintains high limitation of resource because it performs many communications in order to create encryption keys. To solve these problems, this research suggests LA2EP Protocol. LA2EP Protocol can minimize resource and provide a new scheme for authentication and encryption that can provide anonymity of node for safe communication. To analyze the performance of the suggested protocols, a degree of anonymity that is provided by the scheme suggested by using an Entropy-based modeling was measured. As a result, when the suggested scheme was used, the degree of anonymity of sensor node was high. It showed that an important element to increase the degree of anonymity was to let the sensor's ID not known correctly. Also, as a result of calculating spaces for operation, communication, and storage while considering the characteristic of sensor network, which is limited in resource, it showed suitability for sensor network environment.

10

DCT and Homomorphic Encryption based Watermarking Scheme in Buyer-seller Watermarking Protocol

Seong, Teak-Young, Kwon, Ki-Chang, Lee, Suk-Hwan, Moon, Kwang-Seok, Kwon, Ki-Ryong

[Kisti 연계] 한국멀티미디어학회 멀티미디어학회논문지 Vol.17 No.12 2014 pp.1402-1411

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

Buyer-seller watermarking protocol is defined as the practice of imperceptible altering a digital content to embed a message using watermarking in the encryption domain. This protocol is acknowledged as one kind of copyright protection techniques in electronic commerce. Buyer-seller watermarking protocol is fundamentally based on public-key cryptosystem that is operating using the algebraic property of an integer. However, in general usage, digital contents which are handled in watermarking scheme mostly exist as real numbers in frequency domain through DCT, DFT, DWT, etc. Therefore, in order to use the watermarking scheme in a cryptographic protocol, digital contents that exist as real number must be transformed into integer type through preprocessing beforehand. In this paper, we presented a new watermarking scheme in an encrypted domain in an image that is based on the block-DCT framework and homomorphic encryption method for buyer-seller watermarking protocol. We applied integral-processing in order to modify the decimal layer. And we designed a direction-adaptive watermarking scheme by analyzing distribution property of the frequency coefficients in a block using JND threshold. From the experimental results, the proposed scheme was confirmed to have a good robustness and invisibility.

11

순열함수를 이용한 AR.Drone 2.0 제어메시지 암호화 프로토콜

정석원

[Kisti 연계] 한국지능시스템학회 Journal of Korean Institute of Intelligent Systems Vol.27 No.3 2017 pp.230-235

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

드론은 정보통신 기술의 발전으로 인하여 다양한 서비스 분야로 활용이 확대되고 있다. 그러나 무선환경은 드론의 제어 메시지를 그래도 노출하고 이에 따라 공격자에게 드론의 제어권을 넘겨주는 상황이 발생할 수 있다. 본 논문은 범용 암호 알고리즘에 비해 속도 면에서 효율적인 순열함수를 제어 메시지의 암호화를 위해 사용한다. AR.Drone 2.0에 대한 통신 프로토콜 중 제어 메시지에 대해 키 발급, 세션 키 등록, 제어 메시지 암호화 프로토콜을 제안한다. 제안하는 프로토콜은 도청공격, 제어 메시지 생성, 메시지 재전송 공격이 가능하지 않음을 보인다.

As developing information communication technologies, drones are wide applied to various service areas. Under the wireless environment, control messages for a drone are ease revealed to everyone and attacker can get the control privilege of a drone. In this paper, permutation functions are used to encrypt control messages, it is more efficient compare to performance than that of general purpose encryption algorithms. This paper suggests a key issuing protocol, a registration protocol of session key, and encryption protocol for control messages of the AR.Drone 2.0 communication protocols. It shows that eavesdropping attack, generation of control messages and message reply attack are not applied to the suggested protocol.

12

스마트폰을 이용한 VoIP 암호화 기술 연구

천우성, 박대우

[Kisti 연계] 한국정보통신학회 한국정보통신학회 학술대회논문집 2011 pp.281-284

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

스마트폰은 시간과 장소와 기기의 제한을 받지 않는 유비쿼터스 사회로의 전환과 업무에 도입되고 있다. 급속한 스마트폰의 사용 증가는 모바일 업무의 활성화와 행정기관에서도 스마트사회로 전환을 가져왔다. 최근 스마트폰을 이용한 VoIP서비스가 활성화 되고 있지만, 스마트폰과 VoIP가 가지는 무선인터넷 취약점에 노출되고 있다. 본 논문에서는 스마트폰을 이용한 VoIP서비스에 대한 보안성을 강화하기 위한 암호화 기술을 연구한다. 내 외부 신호 및 통화 암호화와 행정기관 인터넷전화 보안 규격을 연구한다. 스마트폰 VoIP서비스에 대한 기기 인증서 보안과 내부 신호 및 통화 암호화를 연구한다. 본 논문은 스마트 시대에 스마트폰 VoIP사용의 안전성과 사용성에 기여할 것이다.

Smart phone is being used in the job as the ubiquitous society will Without being restricted by the time and place and devices. The rapid increase in the use of smart phones has brought the activation of the mobile job. And government agencies have brought in the transition to a smart society. In this paper, using a Voice over Internet protocol(VoIP) service for your smart phones to enhance security is the study of encryption technologies. External and internal signals, and call encryption and security standards of administrative agencies is the study of VoIP. Smart phone VoIP service is a study that security of equipment certificate, the internal signal and call encryption. This paper will contribute what using smart phone VoIP security and usability In smart generation.

13

키 교환 암호 프로토콜 기반 데이터 보안 전송 시스템 및 방법

박재경

[Kisti 연계] 한국컴퓨터정보학회 한국컴퓨터정보학회 학술대회논문집 2024 pp.423-424

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 논문은 TCP/IP 네트워크 및 암호 프로토콜을 결합하여 CCTV 카메라 영상 데이터를 안전하게 전송하는 시스템에 관한 것이다. 특히, TCP Handshake에서 암호 키를 교환하고, 디바이스의 시그니처 정보를 활용하여 키를 생성하는 키 교환 암호 프로토콜을 도입한다. 이를 통해 CCTV 카메라의 영상 데이터를 암호화하여 전송하고, 수신 시 복호화하여 저장한다. 또한, 적어도 하나 이상의 CCTV 카메라에 대한 보안 인증과 네트워크 연결 상태를 제어하며, 중간자 공격을 방지하기 위한 안전한 키 교환을 수행한다. 이로써 안전성이 강화된 CCTV 카메라 시스템을 제공할 수 있다.

14

혼돈계의 단방향 동기화를 이용한 보안 프로토콜 설계

조창호, 임거수

[Kisti 연계] 한국전자통신학회 The Journal of the Korean institute of electronic communication sciences Vol.9 No.10 2014 pp.1125-1130

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

네트워크의 속도가 향상 되면서 정보를 담고 있는 콘텐츠의 양과 질이 급격히 증가 하고 있다. 이런 정보의 급격한 변화에 맞추어 콘텐츠를 통신상에서 보호할 수 있는 혼돈신호를 이용한 새로운 통신 프로토콜을 다음과 같이 제안한다. 혼돈시스템은 초기치 민감성과 발생된 신호가 잡음과 유사하여 예측이 불가능한 특성을 가지고 있다. 우리는 이런 특성을 갖고 있는 두 개의 혼돈시스템 $F(X_n,Y_n)$와 $G(A_n,B_n)$를 구성하고 F 혼돈시스템의 신호로 G 혼돈시스템을 동기화시켜 발생되는 동일한 혼돈신호를 대칭키로 사용하고, 이렇게 구성된 암호 채널로 데이터를 송수신 하는 방법을 설계 하였다. 제안된 방법을 검증하기 위해 이미지의 암호화 및 복호화로 그 결과를 보였다. 우리가 제안한 방법은 기존의 암호화 통신과 다른 방법으로 추후 관련 분야의 연구에 초석이 될 것으로 생각된다.

The quantity and quality of contents containing information are sharply increasing with the rising network speed. In line with this rapid growth of information volume, a new communication protocol using the chaotic signal that can protect contents in communication is proposed as follows. The chaos system has the characteristic of unpredictability due to the sensitive initial values and the similarity of the signals with noise. We configured two chaos systems $F(X_n,Y_n)$ and $G(A_n,B_n)$ that have such characteristics and designed a data communication method using as encryption channel the same chaos signals generated by synchronizing the chaos system G with the F signals. The proposed method was verified with the encryption and decryption of images. The proposed method is different from the existing encrypted communication methods and is expected to lay the foundation for future studies in related areas.is an example of ABSTRACT format.

15

일방향 전송 네트워크에서의 오류 제어 프로토콜 및 데이터 암호화 메커니즘

하재철, 김기현

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.26 No.3 2016 pp.613-621

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

데이터가 일방향으로 전송되는 네트워크 환경에서 데이터에 대한 오류 제어는 매우 민감하고 중요한 문제이다. 이 문제를 해결하기 위해서 전방향 오류 정정 부호 기법이나 수신 결과를 회신하여 데이터를 재전송하는 기법이 사용되고 있다. 본 논문에서는 데이터를 일방향으로 전송하는 채널과 수신 결과만 회신할 수 있는 별도의 채널이 있는 네트워크 환경에서 오류 제어 기법 및 연속 데이터 전송을 할 수 있는 프로토콜을 제안한다. 또한, 일방향 네트워크에서 사전 공유 키 분배 기법에 기반한 데이터 암호 및 키 업데이트 메커니즘을 제안하고 이를 구현하기 위한 응용 서비스 데이터 단위(ASDU) 구조를 제시한다.

Since the error control problem is a critical and sensitive issue in the one-way network, we can adopt a forward error correction code method or data retransmission method based on the response of reception result. In this paper, we propose error control method and continuous data transmission protocol in the one-way network which has unidirectional data transmission channel and special channel to receive only the response of reception result. Furthermore we present data encryption and key update mechanism which is based on the pre-shared key distribution scheme and suggest some ASDU(Application Service Data Unit) formats to implement it in the one-way network.

16

RADIUS 프로토콜의 개선된 패킷암호화 방식과 Larger Packets 전송 방안

김영세, 김기천

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2015 pp.409-412

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

사용자들을 인증하기 위한 대표적인 프로토콜 중에 RADIUS(Remote Authentication Dial-In User Service)가 있다. 기존 RADIUS 서버는 클라이언트가 전송하는 request packet의 크기가 일정크기 이상이면, silently discard하는 프로세스를 수행한다. 하지만, 보안관련 속성이 계속해서 추가될 수 있는 XML방식의 request packet은 Larger packet으로 분류가 되면서 자칫, 패킷 크기로 인해서 인증실패가 될 수 있는 문제가 있다. 본 논문에서는 RADIUS 프로토콜이 전송방식으로 TCP 프로토콜을 사용한다는 가정 아래, 4096옥텟 이상의 패킷(Larger Packets)을 처리하기 위한 방안을 제시하고자 한다.

17

동형 암호의 데이터 수집 프로토콜 적용 방안 연구

이종덕, 정명인, 유진철

[Kisti 연계] 한국콘텐츠학회 한국콘텐츠학회논문지 Vol.21 No.9 2021 pp.42-50

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

인터넷 사용 환경이 발전함에 따라 스마트폰과 각종 센서로부터 발생하는 대량의 데이터를 수집 및 분석하여 활용하는 데이터 기반 애플리케이션의 사용은 지난 10여 년간 폭발적으로 증가하였다. 그러나 이러한 사용자 데이터 기반의 애플리케이션을 사용하는 것은 언제든지 개인정보가 승인되지 않은 제3자에게 유출될 수 있다는 문제점을 내재하고 있다. 이러한 문제를 해결하기 위해 학자들은 데이터 교란과 암호화를 포함한 여러 기법을 사용해 왔다. 동형 암호는 암호화된 데이터를 복호화과정 없이 그대로 연산하더라도 결괏값이 보존되므로 원하는 연산을 수행할 때 개별 데이터를 복호화할 필요가 없어 기존의 방식보다 더 나은 개인정보보호를 제공한다. 본 연구에서는 개인정보를 보호하기 위해 사용되는 두 가지 알고리즘인 데이터 교란 방식과 전통 암호 방식 알고리즘을 구분하여 살펴보고, 두 가지 알고리즘의 단점을 보완할 수 있는 동형 암호를 이용한 데이터 수집 방법을 제안한다.

As the Internet environment develops, data-analysis-based applications have been widely and extensively used in the past decade. However, these applications potentially have a privacy problem in that users' personal information may be leaked to unauthorized parties. To tackle such a problem, researchers have suggested several techniques including data perturbation and cryptography. The homomorphic encryption algorithm is a relatively new cryptography technology that allows arithmetic operations for encrypted values as it is without decryption. Since original values are not required, we believe that this method provides better privacy protection than other existing solutions. In this work, we propose to apply a homomorphic encryption algorithm that protects personal information while enabling data analysis.

18

리소스 레코드 부분암호화를 이용한 DNS 변조공격 탐지 프로토콜 연구

심재화, 민재원, 최영현, 정태명

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2013 pp.683-686

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 인터넷을 이용한 금융거래가 활발해지면서 피싱이나 파밍과 같은 공격을 통한 개인정보 유출 사고가 빈번히 발생하고 있다. 특히 파밍의 경우, 공격자가 DNS 정보를 변조하여 사용자가 올바른 URL을 입력하더라도 악의적 사이트로 컴퓨터가 접속을 하기 때문에 위험성이 매우 높다. 이러한 공격들을 방지하기위하여 여러 연구가 진행되었지만, DNS 정보의 검증을 위한 추가적인 절차를 필요로 하거나 과도한 네트워크 트래픽을 유발할 수 있는 문제점을 가지고 있다. 따라서 본 논문에서는 이러한 문제점을 극복하고자 DNS 리소스 레코드(Resource Record)의 부분 암호화를 이용하여 DNS 변조 공격을 탐지 하는 프로토콜을 제안한다.

19

속성 기반 암호화 기법을 활용한 보안 MQTT 프로토콜

김남호, 홍충선

[Kisti 연계] 한국정보과학회 정보과학회논문지 Vol.45 No.3 2018 pp.195-199

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 사물인터넷(IoT)의 규모가 증가함에 따라 다량의 데이터가 발생하고 있고 이런 데이터를 이용한 다양한 서비스가 등장하고 있다. 이에 따라 빅 데이터들을 효율적으로 처리/전송 할 수 있는 사물 인터넷 환경에 적합한 프로토콜이 필요하다. MQTT는 사물인터넷환경을 위한 경량의 메시징 프로토콜이다. 그러나 MQTT 프로토콜은 보안성을 제공하기 위해서는 TLS를 사용할 수 있지만, TLS를 사용할 경우 Handshake 및 패킷 오버헤드가 증가하는 문제점을 갖는다. 따라서 본 논문에서는 MQTT 프로토콜에 경량화 암호화 알고리즘을 활용하여 보다 강한 보안성을 제공하는 Secure_MQTT 프로토콜을 제안한다.

Recently, with increasing scale of internet of Things (IoT), a large amount of data are generated and various services using such data are emerging. Therefore, a protocol suitable for IoT environment that can efficiently process / transmit big data is needed. MQTT is a lightweight messaging protocol for IoT environment. Although MQTT protocol can use TLS to provide security, it has a problem in that handshake and packet overhead will increase when TLS is used. Therefore, this paper proposed as Secure_MQTT protocol. It can provide stronger security by using lightweight encryption algorithm for MQTT protocol.

20

SSL을 이용한 암호 및 인증 서버/클라이언트의 구현

박영민, 강민섭

[Kisti 연계] 한국정보과학회 한국정보과학회 학술대회논문집 2003 pp.841-843

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

DRM(Digital Rights Management)은 디지털 컨텐츠의 저작권자 권리를 보호하고 인터넷상에서 안전한 거래를 보장하는 기술이다. DRM 기술에 있어서 암호 및 인증을 위한 서버 및 클라이언트 설계는 중요한 부분을 차지하여 SSL(Secure Socket Layer)은 늪은 안정성으로 인하여 네트워크 통신을 위한 프로토콜로 가장 많이 사용되고 있다. 본 논문에서는 DRM 유통 시스템에서 인증서를 기반으로 하는 SSL 보안 통신 메커니즘을 제안하고, 이를 기반으로 한 암호 및 인증 서버/클라이언트의 설계 및 구현에 관하여 기술한다. 본 논문에서 제안된 SSL보안 통신 메커니즘은 MS CryptoAPI를 사용하여 구현하였고, 인증서 기반의 보안이 필요한 다른 응용 프로그램 (Messenger. ftp)에도 쉽게 주용 시킬 수 있는 특징을 가진다.

 
1 2
페이지 저장