DOI QR코드

DOI QR Code

A Study on a Secure Internet Service Provider Model Using Smart Secure-Pad

스마트 보안패드를 이용한 안전한 인터넷 서비스 제공 모델에 관한 연구

  • Lee, Jae-Sik (Department of Computer Science, Soongsil University) ;
  • Kim, Hyung-Joo (Department of Computer Science, Soongsil University) ;
  • Jun, Moon-Seog (Department of Computer Science, Soongsil University)
  • Received : 2013.02.13
  • Accepted : 2013.03.07
  • Published : 2013.03.31

Abstract

Services take place in Internet environment, a formation of the trust relationship between user and service provider for services. Different authentication schemes such as using Certificate of Public Key Infrastructure authentication and using ID/PW for a simple user authentication have been proposed for trust relationship. In addition, in the case of electronic financial transactions, transaction integrity and non-repudiation features are provided. These services are provided in Internet environment, use various measures to ensure service safety. However, it was difficult to prevent attacks using existing security technology because of emergence of MITB attack that manipulate the memory area of the Web browser and social engineering attacks such as phishing/pharming, requires application of new security technologies became. In this paper, we propose a concept of smart secure-pad, and utilize it safely formed a trust relationship between user and service provider, a model has been proposed to ensure safety of data transmission. Proposed model's security evaluation results show security against to MITB attack and phishing/pharming that can't be prevent attack using existing security technology. In addition, service provider can easily apply the model in safe environment can provide Internet service using provided representative services applying the proposed model.

인터넷 환경에서 이루어지는 서비스는 사용자와 서비스 제공자 사이에 신뢰관계를 형성하고 서비스를 제공한다. 이를 위하여 아이디/비밀번호와 같은 간단한 사용자 인증에서부터, 공개키 기반구조의 공인인증서를 이용한 인증까지 다양한 인증방안이 제안되고 있다. 또한, 전자금융거래의 경우 거래내역의 무결성 및 부인방지 기능도 제공하고 있다. 이처럼 인터넷 환경에서 제공되는 서비스들은 서비스의 안전성을 보장하기 위한 다양한 방법들을 활용하고 있다. 하지만 웹브라우저의 메모리영역을 조작하는 MITB 공격과 같은 기존의 보안기술을 이용하여 예방하기 어려운 공격들이 등장하고, 피싱/파밍과 같은 사회공학적 공격들이 등장하면서 새로운 보안기술의 적용이 필요하게 되었다. 본 논문에서는 스마트 보안패드라는 개념을 제안하고, 이를 활용하여 사용자와 서비스 제공자 사이에 신뢰관계를 안전하게 형성하고, 전송되는 데이터의 안전성을 보장하는 모델을 제안한다. 제안하는 모델은 보안성 평가 결과 기존의 보안기술이 예방하기 어려운 MITB 및 피싱/파밍과 같은 공격에 안전함을 보인다. 또한, 제안하는 모델을 적용한 대표적인 서비스 예시를 통하여 서비스를 제공하는 사업자가 쉽게 해당 모델을 적용하여 안전한 환경에서 인터넷 서비스를 제공할 수 있다.

Keywords

References

  1. Financial Security Agency, "A Research Paper for a New Authentication Technology on Electronic Finance", March, 2011.
  2. Korea Internet & Security Agency, "Research on security criteria for extension to electronic authentication method usage-based", December, 2011.
  3. Financial Security Agency, "A Report for Internet-Banking Security Current Status in Foreign Country", February, 2010.
  4. Financial Security Agency, "A Comprehension of interlocked transaction Authentication Technology", November, 2010.
  5. Hiltgen, A.; Kramp, T.; Weigold, T.; , "Secure Internet banking authentication," Security & Privacy, IEEE, vol.4, no.2, pp.21-29, March/April 2006 DOI: http://dx.doi.org/10.1109/MSP.2006.50
  6. Financial Security Agency, "A Guide for Application of End-to-End Cryptography", October, 2007.
  7. Young-Jae Maeng, Dong-Oh Shin, Sung-Ho Kim, Dae-Hun Nyang, Mun-Kyu Lee, "A Vulnerability Analysis of MITM in Online Banking Transactions in Korea", Internet and Information Security, Vol. 1, No. 2, pp. 101-118, 2010.
  8. Jae-Mo Seung, Su-Mi Lee, Seung-Ho Ahn, Bong-Nam Noh, "The End-to-End Encryption for Enhancing Safety of Electronic Financial Transactions", Journal of the Korea Academia-Industrial Cooperation Society, Vol. 10, No. 8, pp. 1920-1925, 2009. DOI: http://dx.doi.org/10.5762/KAIS.2009.10.8.1920
  9. Han-Na You, Jae-Sik Lee, Jung-Jae Kim, Jae-Pio Park, Moon-Seog Jun, "A Study on the Two-channel Authentication Method which Provides Two-way Authentication using Mobile Certificate in the Internet Banking Environment", J-KIVS vol.36, no.8, pp.939-946, August, 2011. DOI: http://dx.doi.org/10.7840/KICS.2011.36B.8.939
  10. Jae-Sik Lee, Han-Na You, Chang-Hyun Cho, Moon-Seog Jun, "A Design Secure QR-Login User Authentication Protocol and Assurance Methods for the Safety of Critical Data Using Smart Device", KICS vol.37C, no.10, September, 2012.
  11. Hyung-Woo Lee, Yeong-Joon Park, "A Design and Implementation of User Authentication System using Biometric Information", Journal of the Korea Academia-Industrial Cooperation Society, Vol. 11, No. 9, pp. 3548-3557, 2010. DOI: http://dx.doi.org/10.5762/KAIS.2010.11.9.3548