• Title/Summary/Keyword: 공인인증서비스

Search Result 76, Processing Time 0.03 seconds

A Study on PKI Utilization through the Research on the Perception and Satisfaction about Electronic Signature (전자서명 이용활성화 방안 연구 - 전자서명 대국민 인식 및 만족도 조사를 중심으로 -)

  • 박추환;강원영;이석래
    • The Journal of Society for e-Business Studies
    • /
    • v.9 no.2
    • /
    • pp.51-68
    • /
    • 2004
  • The purpose of this article is to review the current status of PKI, and to check the major results of Electronic signature business in Korea by conducting face-to-face interview. It is expected that the main implications from the PKI users would be considered by the government for improving the environment of PKI utilization in the favor of users.

  • PDF

On the application of authorized certificate for cryptology (공인인증서의 암호학 활용에 관한 연구)

  • Kim, Daehak
    • Journal of the Korean Data and Information Science Society
    • /
    • v.28 no.1
    • /
    • pp.163-171
    • /
    • 2017
  • With the advance of function of smart phone system and internet services, mobile trade grows more popular in the area of e-business or banking. These environmental changes, it makes the needs of authorized certificates. Authorized certificate is not only important in these days but also future society. In 2015, 27 millions of Korean people used public key certificate, but most of them does not know the details on the public key certificate. Therefore, in this paper, we explain and investigate the characteristics on the public certificate and explain the relation ship between authorized certificate and public key encrytion. By investigating several papers, internet data, newspapers and books, we found the historical changes, substantial aspects, the encryption systems on the authorized certificate. Also we study the pros and cons of authorized certificate. Finally we predict the number of issued authorized certificate for the future society based on nonparametric statistical method.

Wireless Payment System using GVM and MobileC (GVM과 모바일 C를 이용한 무선 결제 시스템)

  • Eom, Eun-Bae;Shin, Hong-Seob;Oh, Se-Man
    • Proceedings of the Korea Information Processing Society Conference
    • /
    • 2004.05a
    • /
    • pp.527-530
    • /
    • 2004
  • 무선인터넷의 비약적인 발전에 힘입어, 이동통신 단말기를 위한 이동통신서비스가 급격히 증가하고 있다. 특히 온라인이나 오프라인상에서 물품을 판매하거나, 정보서비스를 제공하는 무선전자상거래 시장이 빠른 속도로 성장하고 있으며, 무선전자상거래가 성공적으로 이루어지기 위한 무선 결제 시스템이 요구되기 시작하였다. 기존의 무선 결제 시스템은 스마트 카드를 이동통신 단말기에 탑재하여 결제하는 방식이었으며, 반드시 스마트 카드를 이동통신 단말기에 탑재해야 하는 번거로움과 제 3 자에 의한 오남용을 막을 수 없는 단점을 지니고 있다. 본 논문에서는 소프트웨어 다운로드 솔루션을 기반으로 한 GVM(General Virtual Machine)상에서 실행될 수 있는 모바일 C 기반의 무선 결제 시스템을 제안하고자 한다. 제안하는 무선 결제 시스템은 모두 3 개의 모듈로 구성되어 있으며, 개인 정보 관리 모듈에서는 공인인증서와 개인의 신용정보를 단말기에 다운로드 받아 저장한다. 사용자 상호 작용 모듈에서는 유저 인터페이스를 통하여 결제금액과 개인 인증 번호를 입력 받으며, 암호화 모듈에서는 공인인증서의 암호화 알고리즘을 적용하여 결제금액과 개인 인증 번호를 암호화한 후 서버로 전송한다.

  • PDF

URC 로봇 인증제도 개발

  • Jeong, Sang-Guk;Park, Yong-Beom
    • TTA Journal
    • /
    • s.106
    • /
    • pp.59-64
    • /
    • 2006
  • 정보통신부의 ‘IT 839 전략’ 중 ‘9대 신성장 동력’에 포함된 지능형 로봇은 이제 막 태동을 시작한 단계이다. 지능형 로봇은 개개의 구성요소들이 결합되어 이루어진 기술 집약적인 완성품으로 로봇 산업을 활성화하기 위해서는 각기 다른 업체에서 개발한 구성요소들에 대한 표준과 인증이 필요하다. 또한 제품의 목표수준을 설정하기 위하여도 인증은 필수 사항이다. 따라서 TTA(한국정보통신기술협회)는 ’06년 8월부터 국민로봇 시범사업에 쓰이는 URC 로봇(지능형 로봇)에 대한 공인인증 시험서비스를 제공할 예정이며 이를 소개하고자 한다.

  • PDF

A Study on Service of Certified e-Document Authority System (공인전자문서보관소 서비스에 관한 연구)

  • Nam, Tae-Woo;Kim, Eun-Jeong
    • Journal of Information Management
    • /
    • v.40 no.2
    • /
    • pp.25-45
    • /
    • 2009
  • This study deals with a certified e-document authority system to securely archive e-documents by a government authorized third party. For this study, I have looked at three cases of certified e-document authority systems and compared then with the similar cases in the USA and Japan. In my conclusion, I suggest four ideas to improve the service of certified e-document authority system. First, the company providing the certified e-document authority system needs to expand to special services. Second, they need to concentrate on subject area of their business. Third, they should provide a consulting service for business archives with business customers. Finally, they can support additional services like document risk management and other digital contents archiving.

Secure Management Method for Private Key using Smartphon's Information (스마트폰 고유정보를 이용한 안전한 개인키 관리 방안)

  • Kim, Seon-Joo
    • The Journal of the Korea Contents Association
    • /
    • v.16 no.8
    • /
    • pp.90-96
    • /
    • 2016
  • The 3390 million people, around 83% of the adult population in Korea use smartphone. Although the safety problem of the certificate has been occurred continuously, most of these users use the certificate. These safety issues as a solution to 'The owner of a mobile phone using SMS authentication technology', 'Biometric authentication', etc are being proposed. but, a secure and reliable authentication scheme has not been proposed for replace the certificate yet. and there are many attacks to steal the certificate and private key. For these reasons, security experts recommend to store the certificate and private key on usb flash drive, security tokens, smartphone. but smartphones are easily infected malware, an attacker can steal certificate and private key by malicious code. If an attacker snatchs the certificate, the private key file, and the password for the private key password, he can always act as valid user. In this paper, we proposed a safe way to keep the private key on smartphone using smartphone's unique information and user password. If an attacker knows the user password, the certificate and the private key, he can not know the smart phone's unique information, so it is impossible to use the encrypted private key. Therefore smartphone user use IT service safely.

A Study on the PKI based Technology for Internet Banking Service in the Open Software Environment (공개 소프트웨어 환경에서의 인터넷 뱅킹 서비스를 위한 PKI 기반 기술에 대한 연구)

  • Han, Myung-Mook;Lee, Chul-Soo
    • Convergence Security Journal
    • /
    • v.6 no.2
    • /
    • pp.13-20
    • /
    • 2006
  • Since the domestic internet banking environment has established for Microsoft Internet Explorer (IE), the internet banking service is not able to use in the open operating system and web browser such as linux and freeBSD. To solve the :problem, we develop the digital signature system used the seed for the digital payment system in the open software environment. Because the domestic internet banking performs the certificate and digital signature verification through official certificate that the official certificate authority issues, we analyze and develop the verification of validity system for the official certificate. Since the virtual internet banking environment is already established in the web server developing under the self-abilities, the basic internet banking service can be performed installing the certificate in the client which has the mozilla porting the seed. Finally, we can confirm that the certificate and digital signature are performed normally through the experiment.

  • PDF

A Study on the Improvement of Personal Identity Proofing Service Using an Alternative Method for Resident Registration Number Based on Electronic Signature (전자서명 기반의 주민등록번호 대체수단을 사용한 본인확인서비스 개선 방안에 대한 연구)

  • Kim, Jong Bae
    • The Journal of the Convergence on Culture Technology
    • /
    • v.7 no.3
    • /
    • pp.453-462
    • /
    • 2021
  • As the status of public certificates expired due to the recent revision of the Electronic Signature Act, electronic signature-based public certificates were also lost in the means of replacing resident registration numbers(RRN). As a result, public certification institutions have recently been designated by the Korea Communications Commission as identity verification service providers through a review of the designation of personal identity proofing agency based on alternative means of RRN. However, unlike existing RRN replacements such as i-PIN, mobile phones, and credit cards, the personal identity proofing process for applicants for certificates is different from existing alternatives. The proposed method shows that it is possible to protect users' personal information and provide universal, reasonable, and safe identification services by applying improvements to electronic signature-based personal identity proofing services.

국내 상용 제품의 인증 취약성 분석

  • Jeon, Woong-Ryul;Won, Dong-Ho;Kim, Seung-Joo
    • Review of KIISC
    • /
    • v.19 no.4
    • /
    • pp.53-58
    • /
    • 2009
  • 초고속 인터넷이 널리 보급되면서 오프라인에서만 가능했던 많은 서비스들을 이제 온라인에서도 사용할 수 있게 되었다. 온라인 서비스는 상대방을 대면하지 않기 때문에 적절한 사용자 인증과정이 반드시 필요하다. 현재 사용자 인증은 패스워드를 비롯하여 공인인증서, 보안토큰 등 다양한 방법을 사용하여 구현되고 있다. 그러나 공격방법이 다양화되고 지능화되면서 인증과정 역시 많은 취약점을 드러내고 있으며, 이를 극복하기 위한 개선방안에 대한 연구가 현재까지 활발하게 진행되고 있다. 따라서 본 고에서는 성균관대학교 정보보호 인증기술 연구센터가 지난 2008년 12월 종료된 ITRC 과제를 수행하면서 발표한 다양한 인증 프로토콜 취약점과, 취약점 발표 이후 대응 결과에 대해 서술한다. 본 고에서 다루어진 모든 취약점들은 발표 후 모두 패치되어 해결되었다.

Authentication Model of PKI-based Security Gateway using Blockchain having Integrity (무결성이 보장된 블록체인 기술을 활용한 PKI 기반 보안 게이트웨이의 인증 모델)

  • Kim, Young Soo;Mun, Hyung-Jin
    • Journal of Digital Convergence
    • /
    • v.19 no.10
    • /
    • pp.287-293
    • /
    • 2021
  • Recently, public certificates issued by nationally-recognized certification bodies have been abolished, and internet companies have issued their own common certificates as certification authority. The Electronic Signature Act was amended in a way to assign responsibility to Internet companies. As the use of a joint certificate issued by Internet companies as a certification authority is allowed, it is expected that the fraud damage caused by the theft of public key certificates will increase. We propose an authentication model that can be used in a security gateway that combines PKI with a blockchain with integrity and security. and to evaluate its practicality, we evaluated the security of the authentication model using Sugeno's hierarchical fuzzy integral, an evaluation method that excludes human subjectivity and importance degree using Delphi method by expert group. The blockchain-based joint certificate is expected to be used as a base technology for services that prevent reckless issuance and misuse of public certificates, and secure security and convenience.