년 - 년
클라우드 컴퓨팅 환경에서 ECC 기반 사용자 인증 프로토콜의 공유 비밀 키 의존성 취약점 분석과 완전 순방향 비밀성 강화 방안 KCI 등재후보
한국융합학회 미래기술융합논문지 제5권 제3호 2026.06 pp.101-107
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
클라우드 컴퓨팅은 의료, 금융 등 다양한 분야의 핵심 인프라이나, 개방형 네트워크 환경에서 인증 및 세션 키 관리에 심각한 보안 위협이 존재한다. 본 연구에서 최근 개발된 ECC 기반 3요소 인증 및 세션 키 협상 프로토콜을 분석한 결과, 첫째, 서버 데이터베이스에 집중된 사전 공유 대칭 키 k가 단일 장애점으로 작용하여 서버 침해 시 모든 사용자의 인증 메시지 위조가 가능하다(V1). 둘째, 타임스탬프만으로 신선도를 검증하여 적대적 조작 시 서비스 거부(DoS) 공격이 발생한다(V2). 셋째, 서버 개인키 노출 시 과거 모든 세션 키가 복원되어 완전 순방향 비밀성(PFS)이 결여(V3)의 세 가지 구조적 취약점을 식별되었다. 본 연구에서는 개선 방안으로 사용자별 파생 키 적용, 타임스탬프-논스 결합 검증, 임시 ECDH 기반 세션 키 도출을 제안하였고, 모의실험을 통해 원본 대비 동등한 계산 비용 수준에서 세 취약점을 모두 해소함을 확인하였다. 또한 본 연구의 검증은 수식 기반 공격 추적과 시뮬레이션 비교에 기반하며, 형식적 안전성의 완전한 증명은 향후 과제로 남는다.
This paper identifies three structural vulnerabilities in Rangwani and Om’s ECC-based three-factor cloud authentication protocol: (1) a single point of failure from the globally shared secret k, (2) timestamp-only freshness checks enabling DoS attacks, and (3) lack of perfect forward secrecy (PFS) due to reliance on the server’s long-term private key. We propose user-specific derived keys, nonce-bound timestamp verification, and ephemeral ECDH-based session key establishment. Simulation results confirm that the improved protocol closes all vulnerabilities with computation cost equivalent to the original design.
사이버-물리 시스템 기반 IoT 환경에서 ECC 삼중 인증 프로토콜의 보안 취약점 모델링과 보안 개선 설계 KCI 등재
한국기계항공기술학회(구 한국기계기술학회) 한국기계항공기술학회지(구 한국기계기술학회지) 제28권 제3호 2026.06 pp.389-393
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
This study critically analyzed a lightweight ECC-based three-factor authentication protocol designed for IoT-enabled e-Health cloud systems. Through adversarial modeling and formal verification, three core vulnerabilities were identified: static identity inference via XOR-cancellation across sessions, ephemeral key reuse leading to session key replay, and insufficient biometric template binding enabling cross-system correlation. Countermeasures proposed include dual-nonce ephemeral key diversification, salted fuzzy extractor-based biometric binding, dual-ephemeral Diffie–Hellman key exchange for forward secrecy, and a permissioned blockchain audit layer. Simulation results on Raspberry Pi 4 and Intel i5 demonstrate 100% replay detection, per-session forward secrecy, eliminated biometric linkability, and end-to-end latency increase within 6.7%, confirming suitability for resource-constrained IoT healthcare deployments.
Analysis of Al-Saggaf et al's Three-factor User Authentication Scheme for TMIS
[Kisti 연계] 한국컴퓨터정보학회 Journal of the Korea society of computer and information Vol.26 No.9 2021 pp.89-96
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 논문에서는 Al-Saggaf 등이 제안한 TMIS(Telecare Medicine Information System)를 위한 사용자 인증 기법을 분석하였다. 2019년에 Al-Saggaf 등이 제안한 인증 기법은 생체정보를 이용한 인증 기법으로, Al-Saggaf 등은 그들의 인증 스킴이 매우 적은 계산 비용으로 다양한 공격에 대한 높은 비도를 보장한다고 주장하였다. 그러나 본 논문에서 Al-Saggaf 등의 인증 기법을 분석한 결과, Al-Saggaf 등의 인증 기법은 서버에서 사용자의 ID를 계산해내기 위해서 필요한 난수 s가 DB에서 누락되었고, 서버의 ID SID를 사용자에게 전달하는 방식이 부재하여 인증 기법의 설계 오류가 존재하였다. 또한 Al-Saggaf 등은 그들의 인증 기법이 다양한 공격에 안전하다고 주장하였으나, 로그인 요청 메시지와 스마트카드를 사용한 패스워드 추측 공격, 세션키 노출, 내부자 공격 등에 취약하였다. 또한 공격자는 추측한 패스워드를 사용하여, DB에 패스워드로 암호화하여 저장된 사용자의 생체정보까지 복호화할 수 있었다. 생체정보의 노출은 사용자의 개인정보에 대한 아주 심각한 침해이고, 이로 인하여 공격자는 사용자 가장 공격에 성공할 수 있다. 게다가 Al-Saggaf 등의 인증 스킴은 ID 추측 공격에도 취약하여, 그들이 주장했던 것과 달리 TMIS에서 중요한 사용자 익명성을 보장하지 못한다.
In this paper, we analyzed that the user authentication scheme for TMIS(Telecare Medicine Information System) proposed by Al-Saggaf et al. In 2019, Al-Saggaf et al. proposed authentication scheme using biometric information, Al-Saggaf et al. claimed that their authentication scheme provides high security against various attacks along with very low computational cost. However in this paper after analyzing Al-Saggaf et al's authentication scheme, the Al-Saggaf et al's one are missing random number s from the DB to calculate the identity of the user from the server, and there is a design error in the authentication scheme due to the lack of delivery method. Al-Saggaf et al also claimed that their authentication scheme were safe against a variety of attacks, but were vulnerable to password guessing attack using login request messages and smart cards, session key exposure and insider attack. An attacker could also use a password to decrypt the stored user's biometric information by encrypting the DB with a password. Exposure of biometric information is a very serious breach of the user's privacy, which could allow an attacker to succeed in the user impersonation. Furthermore, Al-Saggaf et al's authentication schemes are vulnerable to identity guessing attack, which, unlike what they claimed, do not provide significant user anonymity in TMIS.
일회용 패스워드를 기반으로 한 3-factor 인증 시스템
[Kisti 연계] 한국산학기술학회 한국산학기술학회 학술대회논문집 2008 pp.25-28
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
최근 인터넷과 같은 통신 기술 및 컴퓨터의 계산 능력이 급속도로 발전함에 따라, 많은 업무들이 온라인을 통해서 이루어지고 있다. 온라인 서비스의 편리함 이면에는, 전자 금융의 보안 허점을 노린 해킹시도가 끊이지 않고 있으며 금전적인 이득을 노린 금융 보안 사고들이 자주 발생하고 있다. 이러한 보안 사고를 막기 위해서 사용되는 기존의 인증 방식을 확인하고 인증 방식의 문제점을 분석한다. 본 논문에서 새로운 3-factor 인증 방식을 제안함으로써 기존의 인증 방식의 문제점을 해결하고, 기존 인증 방식보다 보안성이 강화된 인증 체계의 구현과 다양한 보안 서비스 제공, 안전한 금융 서비스 제공이 가능할 것으로 기대 된다.
다중 서버 환경을 위한 안전성이 강화된 ECC 기반 Three-factor 인증 스킴
[Kisti 연계] 한국IT서비스학회 한국IT서비스학회지 Vol.24 No.6 2025 pp.73-88
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
With the rapid expansion of mobile network services and the increasing number of users, single-server based authentication structures face limitations in scalability and efficiency. To address these issues, a multi-server environment, in which users register once with a single registration center and can then access multiple servers without separate registration procedures, has attracted considerable attention. This environment offers user convenience and service scalability but is also exposed to various security threats such as impersonation, replay, and man-in-the-middle attacks during inter-server communication and authentication processes. Consequently, several secure multi-server authentication schemes have been proposed. Although existing ECC-based three-factor authentication methods have demonstrated security against various attack scenarios, this paper analyzes their vulnerabilities and design limitations and proposes corresponding improvements. The proposed authentication scheme is efficient in terms of computational complexity, though it exhibits relatively high communication costs; nevertheless, it provides stronger security against various attacks compared to other authentication schemes.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.