년 - 년
세션키 및 공개키를 이용한 RFID 보안 인증 프로토콜의 안전성 검증 KCI 등재
한국디지털정책학회 디지털융복합연구 제10권 제10호 2012.11 pp.325-332
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
RFID 시스템은 무선 구간의 통신 취약성으로 공격자의 공격 목표가 되며 도청, 정보노출, 트래픽분석, 스푸핑 등 보안상 다양한 문제점을 가지고 있다. 따라서 많은 연구자에 의해 여러 가지 방식의 프로토콜이 제안되고 있으나 구현부분이 까다로워 정리증명이나 검증의 수준에서 제안되고 있는 실정이다. 따라서 본 논문에서는 공개키, 세션키, 해시, XOR 및 난수 개념을 사용하여 각각 태그와 리더구간, 리더와 서버 구간에 안전한 RFID 보안 프로토콜을 제안한다. 보안상 가장 취약한 리더와 태그 구간에 타임스탬프와 해시를 적용하여 시간차가 있는 공격신호에 대하여 공격을 탐지하며, 마지막 세션에서도 태그 정보를 노출시키지 않기 위해 해시 연산 후 통신하고 있다. 끝으로 본 논문의 학문적 기여도는 실제 시스템에서 사용가능한 프로토콜을 설계하고 차별화된 Casper 정형검증기법을 도입하여 제안프로토콜의 보안성을 검증하는데 있다.
Due to its communication vulnerability resulting in a range of problems, e.g. eavesdropping, information exposure, traffic analysis and spoofing, RFID system becomes the target of attackers. Accordingly, many investigators have proposed various protocols to the extent of theorem proving or verification as the implementation is challenging. This paper thus proposes a safe RFID security protocol using public keys, session keys, hashes, XORs, and random numbers. Timestamps and hashes are applied to the most vulnerable section between readers and tags to detect attacks in attack signals with time difference. Also, to prevent tag information from being exposed in the last session, hash operation is adopted before communication. Finally, in this paper, we designed a RFID security protocol using public and session keys applicable to real systems and verified the security of the proposed protocol with a differentiated formal verification technique.
RFID 시스템에서 프라이버시 보호를 위한 인증 프로토콜 설계 KCI 등재
한국디지털정책학회 디지털융복합연구 제10권 제3호 2012.04 pp.155-160
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
본 논문에서는 RFID 시스템에서 무선으로 데이터를 주고받는 태그와 리더간의 통신보안을 해결하기 위하여 다양한 공격에 안전한 해시와 AES 기반의 인증프로토콜을 제안한다. 제안한 인증프로토콜은 기존의 해시기반 프로토콜의 취약점으로 대두 되어온 매 세션마다 동일한 식별 값에 대한 동일한 은닉 값이 생성되는 문제가 있었다. 이 때문에 태그의 식별정보를 완전히 감추기 위해 다수의 복잡한 연산을 해야 했지만 이런 연산을 줄이기 위해 AES 프로토콜을 이용하여 재전송 공격, 스푸핑 공격, 트래픽 분석, 도청공격 등에 대한 보안성을 강화하고 태그와 리더간 상호인증이 가능하도록 구성한 효과적인 방법을 제안한다.
This paper proposes an authentication protocol based on hash and AES safe from various types of attacks in order to assure the security of communication between tags and readers, which exchange data with each other wirelessly in a RFID system. The proposed authentication protocol resolves a problem in existing hash‐based protocols whereby the same hidden value is generated for the same identification in each session. In order to hide tag identification information a number of complicated calculations were required, but using the proposed AES protocol reduces such calculations, strengthens security against replay attack, spoofing attack, traffic analysis, eavesdropping, etc. and assure mutual authentication between tags and readers.
Chaotic‐Maps‐Based Hash Function and Its Application
한국어정보학회 한국어정보학 제9권 1호 2007.06 pp.30-35
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
A new hash algorithm with private key is proposed based on chaotic‐mapping, by reshaping a piece‐wise linear chaotic mapping. This algorithm based on the cipher block chain mode makes the iteration initial point as the private key, encrypts arbitrary length plaintext data to 128 bits hash value. The proposed algorithm encrypts multi‐bit at one time, which reduces the chaotic iterating times and improves the encryption speed. Through theoretical analysis and simulation results, the proposed hash function could satisfy the requirements of unidirectionality, initial value and key sensitivity, anti‐collision and real time, which could be applied to the identity authentication conveniently, safely and efficiently.
모바일 리더 사용자의 프라이버시를 위한 해쉬함수 기반의 RFID 검색 프로토콜 KCI 등재후보
한국차세대컴퓨팅학회 한국차세대컴퓨팅학회 논문지 Vol.6 No.6 2010.12 pp.4-15
RFID 태그 검색 프로토콜에서는 모바일 리더가 특정 태그를 찾기 위해 무선통신이 불가능한 지역에 가게 되었을 경우, 백-엔드-데이터베이스를 대신해서 특정한 태그의 검색이 가능해야한다. 또한 RFID 검색 프로토콜에서는 사용자가 태그가 아닌 모바일 리더를 소지하기 때문에 모바일 리더 사용자의 프라이버시가 고려되어야 한다. Tan 등에 의해 최초로 제안된 RFID 검색 프로토콜들은 모바일 리더의 ID 값을 공개된 형식으로 전송하기 때문에, 모바일 리더 소지자의 프라이버시에 심각한 문제가 발생할 수 있다. 본 논문에서는 이러한 문제를 해결하여, 모바일 리더 사용자의 프라이버시를 제공함과 동시에, 통신라운드의 횟수도 함께 개선한 향상된 RFID 태그 검색 프로토콜을 제안한다.
In RFID tag search system, handheld reader should search the specific tag without help of the back-end-database even though the handheld reader cannot connect with the back-end-database because of unreliable wireless connection or remote location. In addition, in RFID tag search system, the privacy of mobile users should be considered because users hold not the tag but the mobile reader. RFID tag search protocols were firstly discussed by Tan et al. can cause serious problem to the privacy of mobile reader users because the reader identifier is openly transferred. In this paper, we proposed a improved RFID tag search protocol that provides the privacy of mobile reader user by solving this problem and at the same time, also improves the number of communication rounds.
4,000원
최근 소셜 네트워크 서비스가 폭발적으로 증가하면서 빅데이터 분석 연구가 많이 진행되고 있 다. 이 중, 해쉬함수를 이용해서 빅데이터를 분석하는데 주로 이용되는 최소 완전 해쉬함수(MPHF) 방법은 이론적으로는 해쉬충돌이 일어나지 않지만 실제로 사용하면 잦은 충돌 문제가 발생한다. 이로 인해서 빅데이터 분석시간이 길어진다. MPHF의 단점이며 데이터의 양에 관계없이 해쉬 충돌이 일어 나지 않도록 하기위해서 본 논문에서는 해쉬함수를 병렬화에 있어서 Heuristic 알고리즘을 적용하여 해쉬 인덱스를 최적화하는 방안을 제안한다. 실험 부분에서는 본 제안방법의 착안점에 따른 우수성을 기존의 방법과 비교하여 보여준다.
According to explosive increase of social network service (SNS), big data analysis methods have been developed by many researchers. Out of the methods, Minimal Perfect Hash Function has been used in big data analysis. The method sometimes cause a hash collision in real applications and results in more analysis time. In order to solve the problem, we propose a Collision Free Indexing algorithm using parallel hash function. For developing our method, we optimize hash index by applying a heuristic concept. In the experimental section, we show an outperformance of out method comparing with an existing method.
안전한 이중 파이프 해쉬함수에 관한 연구 KCI 등재
국제인공지능학회(구 한국인터넷방송통신학회) 한국인터넷방송통신학회 논문지 제10권 제6호 2010.12 pp.201-208
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
고전적인 반복 해쉬함수는 다중 충돌 공격에 취약점을 가지고 있다. Gauravaram등은 일반적인 Merkle-Damgard Chain에 accumulation chain을 추가한 3C와 3C+ 해쉬함수를 제안하였다. 이 해쉬함수의 목표는 Joux의 일반적인 공격에 저항성을 갖도록 설계하는 것이다. 그러나 Joux's와 Tuma는 엄격하지 않다는 가정 하에서 다중 충돌 공격에 3C와 3C+ 스킴이 MD 스킴보다 안전성을 갖고 있지 않음을 보였다. 논문에서는 3C 해쉬함수의 안전성을 증대하기 위하여 accumulation chain에 메시지 블록 당 XOR와 XNOR연산을 효과적으로 사용하는 해쉬함수를 제안하였다. 이 방법은 Lucks의 이중 파이프 해쉬함수를 개선한 것이다. 또한, 제안한 이중 파이프 해쉬함수는 다중블록 충돌 공격, 고정점 공격, 그리고 원상공격에 저항성을 갖는다.
The classical iterated hash function is vulnerable to a multi-collision attack. Gauravaram et al. proposed 3C and 3C+ hash functions, in which an accumulation chain is added to usual Merkle-Damgard changing. Their goal is to design composition schemes resistant to generic attacks of Joux's type, but Joscak and Tuma have shown that 3C and 3C+ schemes are not better than Merkle-Damgard scheme in term of security against multi-collision attacks under some mild assumptions. In this dissertation, in order to increase security of 3C hash function, we proposed secure double pipe hash function which was effectively using XOR and XNOR operations per blocks of message. We seek to improve on the work of Lucks in a way. Proposed secure double pipe hash function takes resistance to multi-block collision, fixed point and pre-image attacks.
A Secure Score Report Implemented in a Spreadsheet without Privacy Concerns SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.3 2016.03 pp.139-150
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Students’ educational records such as exam score and academic achievement should be considered as sensitive information. According to the federal student privacy law, individual scores should not be posted publicly. If a secure online management system is well-equipped in the school, then it is easy to distribute individual data in a privacy preserving way. However, in general, such a centralized system costs high and is not flexible enough to be used for instant score report after each exam. In this paper, we propose a practical way for an instructor to post students’ individual exam scores online in a single file. By implementing a cryptographic hash function together with score data in an MS Excel file, we demonstrate a score report from which allows each student to retrieve his/her score with his/her own password. Based on our worksheet as a template, it is easy for instructors to write their own score reports without relying on any heavy management systems. Since our score report is implemented in MS Excel worksheets, students find out their scores with Excel program or viewers even in their mobile phones without installing any other programs or apps. Also, it is cryptographically as secure as underlying hash function SHA-256.
전자투표에서 익명성 보장을 위한 빠르고 안전한 방식 KCI 등재
국제인공지능학회(구 한국인터넷방송통신학회) 한국인터넷방송통신학회 논문지 제14권 제1호 2014.02 pp.245-251
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Mix 네트워크는 전자투표 시스템에서 익명성 보장을 위해서 중요한 역할을 담당하고 있으며 많은 mixnet 방 식들이 현재까지 제안되고 있다. 그러데, 기존의 방식들은 안전한 mixing 동작들을 구현하기 위해서 복잡하고 비용 부담이 있는 영지식 증명 방식을 사용하고 있다. 2010년도에 Sebé 등은 암호학적으로 안전한 해쉬 함수를 사용해서 효율적이고 비용 부담이 적은 mixnet 방식을 제안하였다. 본 논문에서 우리는 같은 가정하에서 Sebé의 방식보다 안전 하고 효율적이고 빠른 방식을 제안한다.
Mix network plays a key role in electronic voting to preserve anonymity and lots of mixnet schemes have been proposed so far. However, they requires complex and costly zero-knowledge proofs to provide their correct mixing operations. In 2010, Sebé et al. proposed an efficient and lightweight mixnet scheme based on a cryptographic secure hash function instead of zero-knowledge proofs. In this paper, we present a more efficient and faster mixnet scheme than Sebé et al.'s scheme under the same assumption. Also, our scheme is secure.
시간 기반 키 생성 방식을 이용한 안티 디버깅 기법 KCI 등재
보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.10 No.3 2013.06 pp.291-304
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
디버깅(debugging) 도구는 소프트웨어 개발 과정에서 논리 오류나 버그가 발생되었을 때 프로그램의 내부 상태와 동작 방식을 사용자에게 보여줌으로써 오류를 찾고 수정하는데 도움을 주는 도구이다. 반면에 지적재산권이 포함된 프로그램의 내부 알고리즘 추출이나 권한 상승과 같은 시스템 공격을 위한 취약성 분석에 디버깅 도구가 악용되고 있어 문제가 되고 있다. 이에 대한 대응 기술로 디버깅을 방지할 수 있는 안티 디버깅(anti-debugging) 기술이 적용되고 있으나 이를 우회하는 기술도 지속적으로 발전하고 있다. 본 논문에서는 기존의 우회 기법을 방지할 수 있는 시간 기반 키 생성 방식을 이용한 안티 디버깅 기법을 제안한다. 제안하는 기법은 기존 디버깅을 탐지 후 조건문 방식으로 응답 하는 방식이 아닌 프로그램 실행 시간의 차분 값과 특정 코드 영역의 해시 값으로 키를 생성하고 이를 키 값으로 다음 실행될 코드 영역을 암호화함으로써 우회 공격을 어렵게 하는 방법이다. 또한 단순히 프로그램의 특정 영역의 실행 시간으로 키 값을 유도하는 방식이 아닌 시프트(shift) 연산으로 실행 시간의 범위를 설정할 수 있게 하는 방식을 소개한다. 이는 시스템 하드웨어에 따라 발생할 수 있는 실행 시간의 오차 범위를 설정할 수 있게 함으로써 기법을 유연하게 적용할 수 있게 한다.
Debuggers are the tools which are helping the user to find out and correct the logic errors or bug by showing internal state and running mechanism while developing software. But it is also misused as vulnerability analysis for system attacks like extracting internal algorithm of program or privilege elevation. For this reason, anti-debugging techniques are applied to prevent debugging, but the techniques to bypass anti-debugging are keep developing. In this paper, we propose anti-debugging techniques by using time-based key generation method to prevent previous bypass techniques. The proposed techniques are difficult to bypass attack generate key by using hash value instead of not using previous method which is detecting previous debugging and respond in conditional method. We also introduce scheme that setting scope of the execution time by shift operation instead of simply induce the value of the key by specific area of the program’s execution time. It can set a range of run-time errors can be occurred by system hardware so scheme can be applied flexibly in the various environments.
Analysis of Hash Functions and Cellular Automata Based Schemes SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.7 No.3 2013.05 pp.303-316
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
In this paper, we summarize hash functions and cellular automata based architectures, and discuss some pros and cons. We introduce the background knowledge of hash functions. The properties and theory of cellular automata are also presented with typical works. We show that cellular automata based schemes are very useful to design hash functions with a low hardware complexity because of its logical operation attributes and parallel properties.
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.7 No.3 2013.05 pp.249-258
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Two-factor user authentication is an important research issue for providing security and privacy in hierarchical wireless sensor networks (HWSNs). In 2012, Das, Sharma, Chatterjee and Sing proposed a dynamic password-based user authentication scheme for HWSNs. In this paper, we show weaknesses of Das et al.'s scheme such as failing to prevent user clone and disclosing of base station's secret key. Therefore, we suggest a simple countermeasure to prevent proposed attacks while the merits of Das, et al.'s authentication scheme are left unchanged.
GPU Implementation of the Keccak Hash Function Family SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.5 No.4 2011.10 pp.123-132
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Hash functions are one of the most important cryptographic primitives. Some of the currently employed hash functions like SHA-1 or MD5 are considered broken today. Therefore, in 2007 the US National Institute of Standards and Technology announced a competition for a new family of hash functions. Keccak is one of the five final candidates to be chosen as SHA-3 hash function standard. In this paper, we present an implementation of the Keccak hash function family on graphics cards, using NVIDIA’s CUDA framework. Our implementation allows to choose one function out of the hash function family and hash arbitrary documents. In addition we present the first ready-to-use implementation of the tree mode of Keccak which is even more suitable for parallelization.
High-Speed Parallel Architecture of the Whirlpool Hash Function
보안공학연구지원센터(IJAST) International Journal of Advanced Science and Technology vol.7 2009.06 pp.21-26
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Whirlpool hash function should be capable of processing the input data streams at high speeds. We propose a fully synchronous parallel pipelined architecture with ten stages of pipelining between rounds, and internal pipelining within each round stage. The proposed architecture can tremendously improve the performance of Whirlpool hash function. Our final implementation can encrypt continuous bit streams seamlessly, achieving a throughput of 56.89 G bps, which is considerably high compared to existing implementations in literature.
Quantum Authentication of Classical Messages Using Non-orthogonal Qubits and Hash Function
보안공학연구지원센터(IJUNESST) International Journal of u- and e- Service, Science and Technology Vol.9 No.10 2016.10 pp.181-186
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Quantum authentication protocol can be used to authenticate classical messages in a secure manner. In this paper, by using the cryptographic hash function and non-orthogonal qubits, a quantum authentication protocol of classical messages is proposed. In our protocol, the classical messages and their corresponding tags are encoded as nonorthogonal qubits. The message receiver decodes the classical messages and their corresponding tags from the received qubits by using the authentication key. To verify the validity of the received classical messages, the message receiver verifies whether the hash values of the decoded classical messages are equal to the corresponding tags. Our scheme can be proved to be secure against forgery attack and measurement attack. On the other hand, the authentication key is a binary string, which can be securely obtained and easily saved. What is more, because the authentication key remains secure after executing the authentication protocol, it provides the possibility of reusing the authentication key.
Quantum Authentication Protocol for Classical Messages Based on Bell states and Hash Function SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.9 No.7 2015.07 pp.285-292
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Quantum authentication protocols can be used to authenticate both quantum messages and classical messages. In this paper, a new quantum authentication protocol of classical messages is proposed. In our protocol, a sequence of Bell states is shared by the message sender and the corresponding receiver. This sequence is used as the authentication key. Four different unitary operations U0, U1, U2 and U3 are used to encode a classical message m and its hash value h(m) into a sequence of Bell states. To authenticate the classical message, the message receiver extracts m and h(m) from the qubits owned by himself/herself, and verifies whether h(m) matches m. The adversary’s disturbance to the quantum channel can be detected by checking whether h(m) matches m. The transmitted message has the properties of both secrecy and authentication. Our quantum authentication protocol is secure against message attack and no-message attack.
Research on the Authentication of Radio Frequency Identification based on the Hash function SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.9 No.6 2015.06 pp.209-216
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
As a kind of accurate, rapid and real – time data acquisitions and processing technology, RFID can give unique identification to entity object, has been widely used in various industries, such as manufacturing, sales, transportation and so on. But with its widely application, many relevant problems, especially the safety issues of RFID system and the low cost issue of label have been raised more and more attention by people; therefore, a new and more appropriate security authentication protocol becomes necessary. In this paper, firstly introducing several now available security authentication protocols, and analyzing their strengths and drawbacks, then proposed a new authentication scheme based on Hash function, doing security properties and feasibility analysis of it in theory, and proving that the security properties of this scheme is more efficient, and it is more applicable to meet the needs of people through test at last.
GF(2*8)에서의 역원 역산을 이용한 해쉬 함수의 제안
국제인공지능학회(구 한국인터넷방송통신학회) 한국인터넷방송통신학회 논문지 제4권 제1호 2004.10 pp.33-38
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
국제인공지능학회(구 한국인터넷방송통신학회) 한국인터넷방송통신학회 논문지 제3권 제1호 2003.12 pp.71-78
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
전천 후 생활보조 시스템을 위한 카멜레온 해시 함수 기반의 안전한 인증 프로토콜 KCI 등재
국제인공지능학회(구 한국인터넷방송통신학회) 한국인터넷방송통신학회 논문지 제20권 제4호 2020.08 pp.73-79
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
인구 고령화와 저출산으로 인해 대부분의 국가는 고령화 문제에 직면해있다. 그 결과, 고령화에 대한 연구와 고령화 지원 수단은 전 세계 많은 정부의 우선순위가 되었다. 전천후 생활보조 접근법은 혁신적인 기술과 서비스의 개발 을 통해 건강 상태를 모니터링하고 노인들의 더 나은 삶의 상태를 보장하는 방법이다. 전천후 생활보조 기술은 노인을 위한 더 많은 안전을 지원하고, 응급 대응 수단과 낙상 감지 해결책을 제공할 수 있다. 하지만, 전천후 생활보조 시스템에 서 전송되는 정보는 매우 사적인 정보이므로, 이러한 데이터의 보안 및 개인 정보 보호는 해결해야 할 중요한 문제가 되고 있다. 본 논문에서는 전천후 생활보조 시스템을 위한 카멜레온 해시 기반의 안전한 인증 프로토콜을 제안한다. 제안 된 인증 프로토콜은 전천후 생활보조 시스템에 필요한 여러 가지 중요한 보안 요구 사항을 지원할 뿐만 아니라 다양한 유형의 공격으로부터 안전하다. 또한 보안 분석 결과를 통해 제안된 인증 프로토콜이 기존 프로토콜보다 더 효율적이고 안전하다는 것을 보여준다.
Due to the rapidly ageing population and low birth rates, most countries have faced with the problems of an ageing population. As a result, research into aging and the means to support an aging population has therefore become a priority for many governments around the world. Ambient Assisted Living(AAL) approach is the way to guarantee better life conditions for the aged and for monitoring their health conditions by the development of innovative technologies and services. AAL technologies can provide more safety for the elderly, offering emergency response mechanisms and fall detection solutions. Since the information transmitted in AAL systems is very personal, however, the security and privacy of such data are becoming important issues that must be dealt with. In this paper, we propose a Chameleon hash-based secure authentication protocol for AAL systems. The proposed authentication protocol not only supports several important security requirements needed by the AAL systems, but can also withstand various types of attacks. In addition, the security analysis results show that the proposed authentication protocol is more efficient and secure than the existing authentication protocols.
Hash Function Processor Using Resource Sharing for IPSec Chip
[Kisti 연계] 대한전자공학회 대한전자공학회 학술대회논문집 2002 pp.951-954
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
This paper presents the implementation of hash functions for IPSEC chip. There is an increasing interest in high-speed cryptographic accelerators for IPSec applications such as VPNs (virtual private networks). Because diverse algorithms are used in Internet, various hash algorithms are required for IPSec chip. Therefore, we implemented SHA-1, HAS-160 and MD5 in one chip. These hash algorithms are designed to reduce the number of gates. SHA-1 module is combined with HAS-160 module. As the result, the required logic elements are reduced by 27%. These hash algorithms have been implemented using Altera's EP20K1000EBC652-3 with PCI bus interface.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.