Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 5
No
1

Yang-Yang-Wang의 스마트카드를 이용한 인증 스킴 공격의 오류 KCI 등재후보

권정옥, 황정연, 이동훈

국제인공지능학회(구 한국인터넷방송통신학회) 한국인터넷방송통신학회 논문지 제7권 제2호 2007.04 pp.43-47

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Yang-Shieh이 타임스탬프와 난수에 기반한 스마트카드를 이용한 패스워드 인증 스킴들을 제안한 이후로, 그 스킴들에 대한 공격들과 그것에 대한 대안들이 연이어 제시되었다. 2003년에 Shen-Lin-Wang은 Yang-Shieh의 타임스탬프에 기반한 인증 스킴이 사용자 로그인 메시지 위조공격에 안전하지 않음을 보이고, 이것을 개선하기 위한 스킴을 제안하였다. 2004년에 Yang-Yang-Wang은 Shen-Lin-Wang의 개선 스킴이 여전히 로그인 메시지 위조공격에 안전하지 않다고 주장하였다. 본 논문에서는 Yang-Yang-Wang이 지적한 Shen-Lin-Wang 스킴에 대한 공격이 잘못 되었음을 보인다. 즉, Yang-Yang-Wang의 로그인 메시지 위조공격이 가능하지 않음을 보인다. Yang-Yang-Wang의 메시지 위조 공격이 성공할 수 있으려면 RSA 법 n을 다항식 시간 안에 소인수 분해할 수 있는 알고리즘이 존재하여야 한다. 그러나 RSA 법인 n의 소인수 분해문제는 다항식 시간 내에 풀기 어려운 문제로 알려져 있기 때문에 공격자가 이전의 타임스탬프를 이용하여 유효한 로긴 메시지를 위조하는 것은 현실적으로 어렵다.

Since Yang and Shieh proposed timestamp-based and nonce-based schemes for password authentication using smart cards, a sequence of attacks on the schemes and the corresponding countermeasures has been presented. In 2003, Shen, Lin and Wang modified Yang and Shieh’s timestamp-based scheme to enhance security. In 2004, Yang, Yang and Wang pointed out that Shen et al.’s enhancement was still vulnerable to the forgery attack. In this letter, we show that Yang et al.’s forgery attack has a flaw, i.e., the attack cannot succeed because an adversary cannot forge a login request message. In order to success the forgery attack by Yang-Yang-Wang, we need to have a probabilistic polynomial Turing (PPT) machine to factor RSA modulus n. However it is considered that there is no PPT algorithm can solve the factoring problem. Thus it is difficult that an adversary forge a valid login request message.

2

Cryptographic Analysis and Improvement of the Structured Multi-Signature Scheme for P2P E-Services SCOPUS

JiYi Wu, Yuquan Zhang, Jun Zhang, WenJuan Li

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.8 No.3 2014.05 pp.49-62

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

So far, the trust data storage and transmission security problems are often neglected by researchers in P2P E-Service system. Burmester’s scheme and Harn’s scheme are two kinds of structured multi-signature schemes. They provided co-signers with different role/position have different management liability and authorization capability. This paper shows some insecurity in these schemes. There are two kinds of attacks on these schemes: (1) the schemes can’t resist the dishonest signer forgery attack by forging his own public key (2) everyone can forge some certain messages which to be sign and cannot detect by the signature verifier. Then a new structured signature scheme with verifying signature parameter and all the signers’ public keys was proposed. In this way, the new scheme can resist attacks as mentioned, and can be applied to the trust data security transmission in P2P E-Service system.

3

취근에, 멀티서버 환경을 위한 스마트 카드를 이용한 사용자 인증 방식이 실질적인 응용 분야에서 적용되고 있다. 2009년도에 Liao-Wang은 멀티서버를 위한 안전한 동적 ID 기반 원격 사용자 인증 방식을 제안하였다. 이 방식 은 여러 종류의 가능한 공격에 안전하면서 사용자 익명성 보장하였다. 본 논문에서 우리는 Liao-Wang의 방식에 대한 안정성을 분석하고, Liao-Wang의 방식이 위조 공격, 패스워트 추측 공격, 세션키 공격 그리고 내부자 공격에 취약하 다는 것을 보여준다. 추가로 Liao-Wang의 방식이 사용자와 서버간의 사용자 익명성 역시 제공하지 못한다는 것을 증 명한다.

Recently, user authentication schemes using smart cards for multi-server environment have been proposed for practical applications. In 2009, Liao-Wang proposed a secure dynamic ID based remote user authentication scheme for multi-server environment that can withstand the various possible attacks and provide user anonymity. In this paper, we analyze the security of Liao-Wang’s scheme, and we show that Liao-Wang’s scheme is still insecure against the forgery attack, the password guessing attack, the session key attack, and the insider attack. In addition, Liao-Wang’s scheme does not provide user anonymity between the user and the server.

4

A Friendly Password Mutual Authentication Scheme for Remote-Login Network Systems SCOPUS

Chin-Chen Chang, Chia-Yin Lee

보안공학연구지원센터(IJMUE) International Journal of Multimedia and Ubiquitous Engineering Vol.3 No.1 2008.01 pp.59-63

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

In 2000, Sun proposed a user authentication scheme without using a password table but the user’s password is assigned by the server. Due to this reason, Wu and Chieu proposed an improved scheme to overcome the drawback in 2003. Their scheme provides users to choose and change passwords freely. However, Yang and Wang has presented the possible attacks on Wu-Chieu scheme in 2004. In this article, we proposed an efficient scheme to avoid the weakness of Wu-Chieu scheme. Besides, our scheme provides the feature of mutual authentication between the user and the server.

5

새로운 인증-암호화 모드 NAE에 대한 위조 공격

정기태, 이창훈, 성재철, 홍석희, 이상진

[Kisti 연계] 한국정보보호학회 한국정보보호학회 학술대회논문집 2006 pp.497-500

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

신상욱 등은 JCCI 2003에서 새로운 인증-암호화 모드 NAE를 제안하였다. NAE는 CFB 모드와 CTR 모드를 결합시킨 변형된 형태로, 하나의 기반이 되는 블록 암호 키를 가지고 최소한으로 블록 암호를 호출하여 기밀성과 무결성을 모두 제공한다. 이 모드는 CBC 암호화 모드와 CBC-MAC이 결합된 CCM 인증-암호화 모드보다 효율적이며, 기제안된 다른 인증-암호화 기법들과 유사한 성능을 가진다. 그러나 본 논문에서는 단순 암호문 조작으로 유효한 암호문-태그 쌍을 생성할 수 있음을 보인다.

 
페이지 저장